Decentralized Application (DApp)
A decentralized application, or DApp, is a software application that runs on a blockchain or peer-to-peer network rather than on a centralized server controlled by a single company. Instead of relying on a central operator, DApps typically operate through self-executing code called smart contracts, and many are managed by a community rather than one owner. From a compliance perspective, this distributed and often ownerless structure can raise questions about who, if anyone, is responsible for controls such as customer due diligence.
A decentralized application (DApp) is a software application that combines a smart contract backend with a frontend user interface and executes on a decentralized blockchain or peer-to-peer network rather than on centralized infrastructure. DApps can operate autonomously via smart contract logic and are frequently community-managed rather than administered by a single identifiable operator. This entry is technological and descriptive rather than a legal or regulatory definition: the term itself is not defined by the FATF Recommendations, EU AML instruments, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations. Whether a particular DApp, or a person exercising control or influence over it, falls within an AML/CFT regime depends on the specific activity performed and how the applicable jurisdiction interprets concepts such as virtual asset service provider (VASP) or obliged entity; classifications and obligations vary and should be confirmed against the relevant regulation. The degree of decentralization in practice may also differ from a project's self-description, and this should be assessed on the facts rather than assumed.
Why it matters
For AML/CFT professionals, DApps present a structural challenge that centralized financial services do not: because a DApp typically runs on a blockchain or peer-to-peer network and may operate autonomously through smart contract code, it can be difficult to identify a single responsible party who owes obligations such as customer due diligence or transaction monitoring. Where a traditional obliged entity has an identifiable operator, a community-managed or ostensibly ownerless application may not present an obvious counterparty for regulators or investigators to engage. This does not mean such activity is automatically outside regulatory scope, but it complicates the attribution of responsibility.
The term "DApp" is technological and descriptive; it is not defined by the FATF Recommendations, EU AML instruments, the US Bank Secrecy Act and FinCEN rules, or the UK Money Laundering Regulations. Whether a particular DApp, or a person who exercises control or influence over it, falls within an AML/CFT regime depends on the specific activity performed and on how the applicable jurisdiction interprets concepts such as virtual asset service provider (VASP) or obliged entity. These classifications vary across regimes and should be confirmed against the relevant regulation rather than assumed from the label "decentralized" alone.
A further consideration is that the degree of decentralization claimed by a project may differ from its operation in practice. A self-described DApp may in fact retain identifiable persons or entities that exercise meaningful control, which can be relevant to how obligations are assessed. Compliance and investigative professionals should therefore evaluate decentralization on the facts of each case rather than treating a project's own characterization as determinative.
Who it's relevant to
Inside DApp
Common questions
Answers to the questions practitioners most commonly ask about DApp.