Decentralised finance has nearly doubled in size since 2023. Total Value Locked across DeFi protocols reached USD 86.6 billion by May 2026, up from USD 46.9 billion just three years earlier. Yet almost 93% of jurisdictions worldwide have done nothing to bring DeFi within the scope of their AML frameworks. On 21 July 2026, the FATF published its Targeted Report on Regulatory Challenges from Decentralised Finance, laying bare the scale of this gap and the growing criminal exploitation it enables.
For compliance teams, VASPs and financial institutions, DeFi AML compliance 2026 is no longer a theoretical exercise. The FATF has made clear that qualifying DeFi arrangements already fall within existing standards. This article examines the report’s key findings and sets out practical steps to manage DeFi-related risks before regulators catch up.
| Compliance area | Key finding | Why it matters |
|---|---|---|
| Regulatory implementation | 93% of jurisdictions have not implemented AML standards for DeFi | Criminal activity flows to unregulated spaces |
| Licensing | Only 2 of 142 jurisdictions have licensed a DeFi arrangement | Regulatory engagement with DeFi remains near zero |
| Criminal exploitation | DPRK cyberattacks on DeFi caused 76% of annual VA hacking losses | State-sponsored actors target DeFi as a primary vector |
| Control indicators | Many “decentralised” arrangements retain centralised control elements | The FATF control test can bring DeFi within VASP scope |
| Geographic concentration | North America and Europe account for 60% of DeFi transactions | Regulatory efforts should target jurisdictions with highest activity |
What the FATF’s DeFi report reveals about regulatory gaps
The FATF’s targeted report updates its 2021 analysis of DeFi, reflecting the sector’s substantial expansion and evolution over the past five years. It draws on survey responses from 142 jurisdictions and presents a comprehensive assessment of how governments have or have not, addressed DeFi within their AML/CFT frameworks.
However, the numbers are stark. Of 142 reporting jurisdictions, 132 have not implemented the FATF Standards in relation to qualifying DeFi arrangements. Only four jurisdictions have imposed any form of licensing or registration requirement. In fact, just two have actually licensed or registered a DeFi arrangement in practice.
Risk assessments tell a similar story. Only 18% of jurisdictions have assessed DeFi-related money laundering and terrorist financing risks. A further 9% report assessments in progress. Consequently, the remaining 73% have conducted no assessment at all, leaving most jurisdictions without even the foundational understanding needed to develop proportionate regulation.
Furthermore, the report finds that 93% of jurisdictions have not identified any DeFi arrangements operating in their territory that would qualify as VASPs under the FATF Standards. This does not mean such arrangements do not exist. It simply means jurisdictions have not looked for them.
How criminals exploit DeFi for money laundering
The FATF report documents a range of sophisticated techniques that criminals use to move illicit funds through DeFi. These include chain-hopping, cross-chain bridges, decentralised exchanges, mixers and governance manipulation. Together, these methods enable the layering and co-mingling of illicit funds within legitimate financial flows.
State-sponsored actors represent the most significant threat. In April 2026 alone, two major cyberattacks on DeFi platforms attributed to the Democratic People’s Republic of Korea accounted for roughly 76% of all annual losses from virtual asset hacking incidents. Combined proceeds exceeded USD 570 million. As a result, the DPRK has become one of the most prolific state-sponsored exploiters of DeFi protocols, using stolen funds to finance weapons programs.
Fraud remains another major concern. For example, the report highlights the SafeMoon Token Scheme and the Forsage Case as illustrations of how criminals exploit seemingly legitimate DeFi platforms. In both cases, perpetrators secretly retained control over key technical functionalities, allowing them to manipulate operations and divert substantial funds. These cases demonstrate that even platforms marketed as fully decentralised can harbour centralised points of control.
Similarly, professional money laundering networks rely on DeFi infrastructure. Ransomware operators use DeFi protocols to convert and obscure ransom payments. For compliance teams monitoring exposure to DeFi, these typologies should inform transaction monitoring rules and risk assessments. Our earlier guide on stablecoin compliance programs covers related risks in the stablecoin ecosystem.
DeFi AML compliance requirements under FATF standards
A common misconception is that DeFi sits outside existing regulatory frameworks. However, the FATF report directly addresses this. Qualifying DeFi arrangements already fall within the scope of Recommendation 15, which covers virtual assets, where a natural or legal person exercises control or sufficient influence over the arrangement.
Financial institutions and VASPs that interact with or provide services to DeFi arrangements should comply with three key recommendations. Recommendation 15 covers new technologies and requires firms to identify and assess risks. Under Recommendation 10, firms must conduct customer due diligence, including identifying customers and verifying their identity. Additionally, Recommendation 13 addresses correspondent banking relationships and requires firms to assess the adequacy of their counterparty’s AML/CFT controls.
The FATF goes further with a clear warning. Where compliance with these standards cannot be achieved, firms should refrain from interacting with such DeFi arrangements altogether. This guidance applies regardless of whether a jurisdiction has enacted specific DeFi legislation.
For VASPs and financial institutions, the practical implication is significant. Firms cannot treat DeFi interactions as unregulated simply because their jurisdiction has not yet legislated on the topic. In practice, the FATF Standards already apply and regulators will expect firms to demonstrate compliance.
The control test: when a DeFi arrangement becomes a VASP
One of the report’s most practical contributions is its analysis of control indicators. Many DeFi arrangements present themselves as decentralised in terms of governance. However, the FATF finds that centralised elements frequently persist in practice.
The report identifies several on-chain and off-chain indicators of control. These include governance token concentration, where a small group holds enough tokens to determine protocol outcomes. Administrative privileges, such as the ability to pause, upgrade or modify smart contracts, also indicate control. Other markers include significant economic benefits flowing to identifiable parties, influence over development roadmaps and control over critical infrastructure like front-end interfaces or oracle feeds.
When these indicators are present, the FATF considers that a natural or legal person exercises sufficient control or influence to bring the arrangement within the definition of a VASP. As a result, this triggers the full range of AML/CFT obligations, including customer due diligence, transaction monitoring, suspicious transaction reporting and Travel Rule compliance.
Therefore, for compliance teams assessing exposure to DeFi, the control test provides a useful framework. Rather than asking whether a protocol claims to be decentralised, firms should examine who holds governance tokens, who can modify smart contracts, who controls front-end access and who benefits economically from the arrangement. These questions determine whether a DeFi protocol should be treated as a regulated counterparty.
Regional concentration and where regulators should focus
The report highlights significant geographic concentration in DeFi activity. North America and Europe together account for approximately 60% of global DeFi transactions. By contrast, the Middle East and Africa contribute less than 10%. Consequently, this concentration has direct implications for regulatory prioritisation.
The FATF recommends that jurisdictions with more significant DeFi activity should allocate more resources to understanding, supervising and developing approaches to mitigate the associated risks. Moreover, the top 20 DeFi protocols represent more than 70% of total DeFi activity, so regulatory and supervisory efforts should target the largest and most systemically relevant protocols first.
In addition, the report sets out practical recommendations for jurisdictions seeking to develop DeFi frameworks. These include developing regulatory approaches that incorporate smart contract certification, enhancing cooperation between financial regulators and law enforcement, establishing public-private partnerships, creating dedicated cryptocurrency investigation teams and sharing information between financial intelligence units through channels like the Egmont Secure Web.
For firms operating in jurisdictions with significant DeFi activity, this concentration data reinforces the need for proactive compliance. Regulators in North America and Europe are the most likely to act first and firms in those markets should therefore expect supervisory attention on their DeFi exposure.
What compliance teams and VASPs should do now
The FATF’s DeFi report provides a clear framework for action, even in the absence of jurisdiction-specific legislation. These are the priority steps for compliance teams and VASPs.
- Assess your DeFi exposure. Map all interactions with DeFi protocols across your operations. This includes direct protocol interactions, customer transactions involving DeFi and indirect exposure through counterparties or service providers that interact with DeFi.
- Apply the control test. For each DeFi protocol you interact with, evaluate the indicators of control. Determine whether any natural or legal person exercises sufficient control or influence to qualify the arrangement as a VASP. Document your assessment accordingly.
- Implement risk-based due diligence. Apply customer due diligence standards to DeFi interactions where a qualifying VASP has been identified. Where you cannot obtain adequate information about a DeFi arrangement’s governance and controls, consider restricting or exiting the relationship.
- Update your risk assessments. Incorporate DeFi-specific typologies into your enterprise-wide risk assessment. In particular, cover chain-hopping, cross-chain bridges, mixers, governance manipulation and the DPRK cyber theft typology documented by the FATF.
- Monitor regulatory developments. The FATF has signalled that jurisdictions should act. Because regulatory frameworks for DeFi will develop unevenly across markets, firms operating across borders need to track these developments closely.
The direction is clear. DeFi is not outside the regulatory perimeter. The FATF Standards already apply to qualifying arrangements and the report gives jurisdictions the tools to enforce them. Firms that build DeFi compliance frameworks now will therefore avoid the disruption of reactive remediation later.
Conclusion
The FATF’s July 2026 DeFi report is a wake-up call for the compliance industry. With 93% of jurisdictions lacking any AML implementation for DeFi and criminal exploitation growing in sophistication, the gap between risk and regulation has never been wider.
The report makes one thing clear. DeFi arrangements where identifiable parties exercise control already fall within the scope of existing FATF Standards. Compliance teams cannot wait for jurisdiction-specific legislation to act. Instead, the FATF expects firms to apply Recommendations 15, 10 and 13 to qualifying DeFi interactions today.
At Compliance7, we help VASPs, crypto exchanges and financial institutions build robust AML/CFT programs that address emerging risks including DeFi. If your organization needs support navigating these challenges, book a free consultation with our team.
This article is for informational purposes only and does not constitute legal or regulatory advice. For guidance specific to your business, consult a qualified compliance professional.


