Skip to main content
Category: Virtual Assets and Technology

Decentralized Finance (DeFi)

Also known as: DeFi, decentralized finance, defi
Simply put

Decentralized finance, or DeFi, refers to financial products and services, such as lending, borrowing, and trading, that are provided directly through software running on blockchain networks rather than through a traditional financial company acting as a middleman. Transactions are typically executed automatically by code (often described as algorithms or smart contracts), and services are generally available at all times without conventional paperwork or a central operator. This model differs from traditional finance, and its lack of an identifiable intermediary can raise particular challenges for oversight and compliance.

Formal definition

DeFi is a collective term for financial activities and services facilitated by cryptocurrency and built on blockchain or distributed ledger technology (historically concentrated on Ethereum, though implementations vary across networks). Rather than relying on a regulated financial institution as intermediary, these services are generally executed by algorithms or automated code operating on-chain, which the sources describe as functioning without a financial services company, owners, or downtime. From a financial crime perspective, practitioners should note that the absence of a clearly identifiable obliged entity or intermediary complicates the application of customer due diligence, transaction monitoring, and related AML/CFT obligations; the degree to which any given DeFi arrangement falls within a regulatory perimeter is fact-specific and depends on the applicable jurisdiction and how the relevant authority characterizes the activity and its participants. The characterization of DeFi services as 'anonymous' in one source reflects a marketing or operational description and should not be read as a legal conclusion; scope and definitions vary and should be confirmed against the applicable regulatory framework.

Why it matters

DeFi presents a distinct challenge for AML/CFT frameworks because these frameworks are generally built around obliged entities, regulated intermediaries such as banks, exchanges, and money services businesses that owe customer due diligence, transaction monitoring, and reporting obligations. Where financial services are provided directly by code running on a blockchain, as the sources describe, there may be no clearly identifiable financial services company, owner, or central operator to whom such obligations can be attached. This complicates the application of established controls and means the extent to which any given DeFi arrangement falls within a regulatory perimeter is fact-specific, depending on the jurisdiction and how the relevant authority characterizes the activity and its participants.

For compliance professionals, the practical significance lies in the mismatch between conventional AML/CFT tools and DeFi's operating model. Services that are described as available at all times, without paperwork and without a middleman, do not fit neatly into a framework premised on onboarding customers, verifying identity, and monitoring an account relationship. Practitioners should be cautious about the description of certain DeFi services as 'anonymous' in some sources: this reflects a marketing or operational characterization rather than a legal conclusion, and blockchain transactions are frequently pseudonymous and recorded on a public ledger rather than truly anonymous.

Because definitions, scope, and the treatment of DeFi participants vary considerably across regimes, exposure to DeFi should be assessed as a matter of risk rather than assumed to be either wholly outside or wholly inside any single regulatory perimeter. Institutions with indirect exposure, for example, through customers who interact with DeFi protocols, may need to consider how their existing risk-based measures address activity that originates from or moves through these arrangements. Exact obligations should always be confirmed against the applicable regulatory framework.

Who it's relevant to

AML/CFT compliance officers
Compliance teams at regulated institutions need to understand how, and whether, their customers' interactions with DeFi protocols fit within their risk-based controls. Because DeFi arrangements may lack an identifiable intermediary, officers cannot assume that conventional customer due diligence and transaction monitoring translate cleanly to this context, and should assess exposure as a matter of risk while confirming applicable obligations against the relevant framework.
Financial intelligence analysts and investigators
Analysts tracing funds may encounter activity that moves through DeFi services executed by on-chain code rather than through a conventional intermediary. Understanding that these services are frequently pseudonymous, recorded on a public ledger rather than truly anonymous despite some marketing descriptions, is important when analyzing flows and attributing activity, though a transaction record alone does not establish wrongdoing.
Legal, risk, and policy professionals
Those advising on regulatory perimeter questions must grapple with the fact-specific and jurisdiction-dependent characterization of DeFi. Whether a given arrangement or participant is treated as within scope varies across regimes, so definitions and obligations should be confirmed against the applicable regulatory framework rather than assumed to be uniform.
Virtual asset service providers and their compliance functions
Firms operating in the crypto ecosystem may interface with DeFi protocols directly or serve customers who do. They should consider how their existing risk-based measures address activity originating from or passing through DeFi arrangements, recognizing that the absence of a central operator does not by itself resolve whether obligations apply.

Inside DeFi

Smart Contracts
Self-executing code deployed on a blockchain that automates financial functions such as lending, borrowing, swapping, or yield generation without a traditional intermediary. The code, rather than a regulated institution, governs how transactions execute, which complicates the identification of a responsible obliged entity in many jurisdictions.
Decentralized Exchanges (DEXs)
Protocols that allow users to trade crypto-assets directly from self-hosted (unhosted) wallets, typically through automated liquidity pools rather than an order book operated by a central party. The absence of a centralized operator raises questions about who, if anyone, bears customer due diligence and monitoring obligations under applicable regimes.
Liquidity Pools and Automated Market Makers (AMMs)
Pooled crypto-asset reserves that supply liquidity for trades, with pricing set algorithmically rather than by a broker or dealer. Participants who deposit assets may receive tokens representing their share, and the pooled, pseudonymous nature can obscure the source of funds.
Governance and Utility Tokens
Tokens that may confer voting rights over a protocol's parameters or provide access to services. Governance arrangements are often distributed among token holders, sometimes organized as decentralized autonomous organizations (DAOs), which affects how accountability and control are assessed.
Self-Hosted (Unhosted) Wallets
Wallets controlled directly by a user rather than held by a custodian. Interactions between DeFi protocols and self-hosted wallets fall outside the customer relationship model that underpins traditional CDD, and treatment of transfers involving such wallets varies by jurisdiction.
Degree of Decentralization
A spectrum rather than a binary state. Some arrangements labeled 'DeFi' retain identifiable persons or entities that exercise control or profit from the service, which may bring them within the scope of virtual asset service provider (VASP) definitions in certain regimes; genuinely decentralized arrangements may fall outside them. Classification is fact-specific.

Common questions

Answers to the questions practitioners most commonly ask about DeFi.

Is DeFi completely anonymous and therefore outside the reach of AML obligations?
This is a common misconception. DeFi is more accurately described as pseudonymous rather than anonymous, because transactions are typically recorded on public, transparent ledgers that can be analyzed, even where the parties are identified only by wallet addresses. Whether AML obligations attach depends on the applicable regime and on whether an identifiable person or entity performs a regulated activity. The FATF Guidance on virtual assets and VASPs, for example, indicates that where a party maintains control or sufficient influence over a DeFi arrangement, that party may fall within the definition of a virtual asset service provider, even if the protocol markets itself as decentralized. The label 'DeFi' does not by itself remove an activity from scope, and this should be assessed against the specific rules in the relevant jurisdiction.
Because a DeFi protocol has no central operator, does that mean no one can be an obliged entity?
Not necessarily. The absence of a traditional central operator does not automatically mean that no person bears regulatory obligations. Regimes generally look to substance over labels, and FATF guidance suggests that persons who retain control or sufficient influence over a so-called decentralized arrangement may be treated as VASPs regardless of how the protocol is described. The degree of actual decentralization varies significantly between protocols, and characterizing a specific arrangement as fully decentralized is a factual and legal question rather than a given. Whether a developer, governance token holder, or other participant qualifies as an obliged entity should be determined against the definitions and thresholds in the applicable regime, as approaches differ across jurisdictions.
How can a compliance team approach customer due diligence when interacting with DeFi arrangements?
Where an obliged entity in your organization interacts with DeFi arrangements, CDD is generally applied to the identifiable counterparties and customers within your control, consistent with the CDD obligations under the applicable regime, rather than to the protocol itself. Because DeFi typically involves wallet-based, pseudonymous interactions, teams often rely on blockchain analytics to attribute risk to wallet addresses and to understand counterparty exposure, alongside conventional identity verification where a customer relationship exists. The feasibility and required depth of these measures depend on your role in the transaction chain and on the specific requirements of your jurisdiction, so scope should be confirmed against the rules that apply to your entity.
What role does blockchain analytics play in monitoring DeFi-related activity?
Blockchain analytics is commonly used as a measure to detect, assess, and manage risk associated with DeFi activity by tracing flows across public ledgers and attributing risk indicators to wallet addresses and protocols. It can support transaction monitoring, sanctions and exposure assessment, and investigation, but it is a risk-management tool rather than a guarantee of prevention, and results are typically probabilistic attributions rather than definitive proof of wrongdoing. Analytics findings generally inform, but do not by themselves establish, any conclusion about illicit conduct. Its effectiveness varies with data coverage, the use of privacy-enhancing techniques, and the particular protocols involved.
How should DeFi exposure be reflected in a risk-based approach?
Under a risk-based approach, DeFi exposure is generally treated as one factor within the entity's broader risk assessment, informing the calibration of controls such as monitoring intensity, counterparty risk analysis, and, where warranted, enhanced due diligence. Because levels of transparency, decentralization, and counterparty identifiability vary across DeFi arrangements, the associated risk is typically assessed case by case rather than uniformly. Controls should be understood as measures to mitigate and manage risk rather than to eliminate it, and the specific expectations for documenting and calibrating that assessment depend on the applicable regime.
When may a suspicious activity report or suspicious transaction report be relevant to DeFi activity?
Where an obliged entity identifies activity involving DeFi that gives rise to knowledge or suspicion meeting the reporting threshold under its applicable regime, the relevant reporting obligation may be triggered in the same way as for other activity. Depending on the jurisdiction, this is filed as a SAR or an STR, and the terminology and precise trigger differ across regimes, so the applicable standard should be confirmed against local rules. Filing a report reflects a suspicion and a compliance obligation; it does not establish that any underlying offense has occurred. The obligation attaches to the reporting entity and to activity within its scope, not to the DeFi protocol as such.

Common misconceptions

Because DeFi is decentralized, no AML/CFT obligations can ever apply to it.
Decentralization exists on a spectrum. Guidance from standard-setters such as the FATF indicates that where a natural or legal person maintains control or sufficient influence over a DeFi arrangement, or profits from the service, that person may fall within the definition of a virtual asset service provider and be subject to AML/CFT obligations in jurisdictions that have implemented such standards. Whether obligations apply is a fact-specific assessment, and treatment varies by jurisdiction. The label 'DeFi' does not by itself determine regulatory status.
DeFi transactions are anonymous and therefore untraceable.
Most public blockchain transactions are pseudonymous rather than anonymous, and are typically recorded on a transparent, immutable ledger. This can allow blockchain analytics to trace flows, though linking on-chain addresses to real-world identities remains challenging, and privacy-enhancing tools can further complicate attribution. Traceability should not be assumed to be either complete or impossible.
Activity on a DeFi protocol, or an analytics alert flagging an address, establishes that money laundering has occurred.
Interacting with a DeFi protocol is lawful in many contexts, and an analytics flag, risk indicator, or typology match is an operational signal that may warrant further review, not proof of criminal conduct. Money laundering as a criminal-law matter requires the elements defined in the applicable jurisdiction's law to be established through due process; compliance signals do not, by themselves, establish wrongdoing.

Best practices

Assess each DeFi arrangement on its facts to determine the actual degree of decentralization and whether any identifiable person exercises control or profits from the service, since this may affect whether VASP-type obligations apply under the relevant regime rather than relying on the 'DeFi' label.
Confirm regulatory treatment against the specific applicable framework (for example, FATF guidance as a standard, the EU regime, or US or UK rules), recognizing that classification, obligations, and the treatment of self-hosted wallet transfers diverge across jurisdictions.
Use blockchain analytics as a risk-management measure to detect and investigate suspicious flows, while treating alerts and address matches as investigative leads to be corroborated rather than as evidence of criminal conduct.
Apply a risk-based approach when a firm's regulated on-ramps or off-ramps interact with DeFi, including enhanced scrutiny of exposure to mixers, high-risk protocols, and self-hosted wallets, understanding that such controls mitigate rather than eliminate risk.
Document the rationale for how a given protocol or counterparty is classified and how associated risks are assessed and managed, so that decisions can be evidenced to regulators and revisited as arrangements evolve along the decentralization spectrum.
Monitor developments in guidance and law, since regulatory expectations for DeFi are still maturing and definitions, scope boundaries, and thresholds should be confirmed against the applicable regulation before relying on them.