FATF: Centralised Elements in DeFi Must Be Regulated as VASPs
The Financial Action Task Force has issued a clear signal to global regulators: the decentralised label attached to many DeFi protocols does not eliminate the need for anti-money laundering controls. In a position published on 22 July 2026, FATF stated that centralised elements "frequently persist" inside supposedly decentralised finance arrangements, and that those elements should be subject to the same Virtual Asset Service Provider obligations that apply to centralised exchanges. For accounting firms, auditors, and CFOs with digital asset clients, this is a material compliance development, not a distant regulatory curiosity.
What FATF Actually Said
FATF's position is grounded in its existing framework for virtual assets, which requires member jurisdictions to ensure that VASPs conduct customer due diligence, monitor transactions, and file suspicious activity reports. The challenge with DeFi has always been attribution: when a protocol is governed by a smart contract and there is no obvious operator, who bears the VASP obligations?
The "Frequently Persist" Finding
FATF's answer is that the purely operator-free DeFi protocol is rarer than the industry claims. Centralised elements, meaning identifiable persons or entities that exercise control or sufficient influence over a protocol, frequently persist. These can take several forms. A founding team that retains admin keys or upgrade rights is one example. A DAO governance structure where a small group of token holders commands a supermajority vote is another. Fee recipients, front-end operators, and liquidity deployers with privileged access all fall into the same category in FATF's view.
Where such elements exist, FATF's position is that the responsible party should be treated as a VASP and regulated accordingly. This is not a new conceptual argument: FATF's 2021 updated guidance on virtual assets already flagged this issue. What the July 2026 statement does is reinforce and sharpen that position, signalling to national regulators that enforcement discretion should not be used to exempt DeFi projects from the VASP framework simply because they carry a decentralised label.
Scope: Which Protocols Are in Scope
FATF does not name specific protocols. Instead, it describes the characteristics that bring a DeFi arrangement into scope. The key test is whether a natural person or legal entity has the ability to set or alter the rules of the protocol, collect fees, or otherwise exercise control. Decentralisation is treated as a spectrum, not a binary state. A protocol may be decentralised in its execution layer while remaining centralised in its governance layer, and it is the governance layer that FATF is focused on.
This matters practically for firms that service DeFi clients. A fund investing in DeFi protocol tokens, a treasury that deploys assets through a DeFi yield aggregator, or an accounting firm that audits a DAO all need to understand where their client sits on that spectrum.
Why This Matters for Accounting Firms and CFOs
The direct regulatory impact falls on jurisdictions that are FATF members, which covers the overwhelming majority of OECD economies. National regulators are expected to implement FATF recommendations into domestic law. The July 2026 statement gives regulators explicit cover to apply VASP registration, KYC, and transaction monitoring requirements to DeFi operators who were previously operating in a grey zone.
Client Onboarding and KYC Obligations
If a client is itself a DeFi operator with centralised characteristics, the accounting firm or auditor takes on an exposure that goes beyond standard professional indemnity risk. The client may be operating as an unregistered VASP. Firms should revisit their client acceptance procedures and ensure that their onboarding questionnaires capture whether the client operates, controls, or derives fee income from a DeFi protocol. Where the answer is yes, enhanced due diligence and legal sign-off on the client's regulatory status are the minimum sensible steps.
For CFOs at companies that interact with DeFi protocols, whether through treasury management, yield strategies, or token holdings, the FATF position raises counterparty risk questions. If the DeFi protocol a company is using is later found to be an unregistered VASP in the firm's home jurisdiction, the transaction history with that protocol could attract regulatory scrutiny. Robust crypto accounting software that captures the full transaction record, including protocol identity, transaction type, and counterparty wallet where known, becomes a compliance asset rather than just a bookkeeping tool.
AML Program Design for DeFi Exposure
Firms that already have AML programs covering centralised exchange activity need to extend those programs to cover DeFi exposure. FATF's position implies that regulators will expect transaction monitoring to cover on-chain DeFi activity, not just off-ramp events. This has direct implications for how firms configure their digital asset accounting software: transaction classification needs to distinguish between centralised exchange trades and DeFi protocol interactions, because the AML risk profile and potential reporting obligations differ.
Key steps for AML program updates include: mapping all DeFi protocol interactions in client portfolios or company treasuries; assessing whether the protocol operators meet the FATF centralisation test; and documenting that assessment in the AML file. Where a protocol operator is identifiable and not registered as a VASP in any relevant jurisdiction, that fact should be escalated to the compliance officer and, depending on the firm's risk appetite, to legal counsel.
Audit and Financial Reporting Implications
For auditors, the FATF position introduces a new going-concern and contingent liability consideration. A DeFi protocol token held by an audit client may represent an investment in an entity that is, under FATF's framework, operating as an unregistered financial intermediary. If the relevant national regulator moves to enforce VASP obligations against that protocol operator, the token value and the client's ability to continue using the protocol could be materially affected.
This is not a remote hypothetical. FATF member jurisdictions have been progressively tightening crypto enforcement, as seen in recent actions across multiple OECD markets. Auditors should consider whether DeFi protocol exposure warrants specific disclosure in the notes to financial statements, particularly for clients where the exposure is material relative to net assets.
From a crypto bookkeeping software perspective, the practical requirement is that every DeFi interaction needs to be logged with enough metadata to support a subsequent regulatory review: the protocol name, the smart contract address, the transaction type (swap, liquidity provision, borrowing, staking), the amounts in and out, and the fair value at the transaction date. If the client's current systems do not capture this level of detail, closing that gap is now a compliance priority, not just a reporting nicety.
The Global Regulatory Picture
FATF's statement does not create law directly, but it sets the expectation for how member jurisdictions should interpret and apply their existing VASP frameworks to DeFi. Several OECD regulators had already been moving in this direction before the July 2026 statement. The statement gives them a multilateral anchor for enforcement actions that might otherwise have been challenged as regulatory overreach.
Implications for OECD Jurisdictions
In the European Union, the Markets in Crypto-Assets Regulation already imposes obligations on crypto-asset service providers, and the European Banking Authority and ESMA have been developing technical standards that touch on DeFi. The FATF position is consistent with the direction of MiCA's future reviews, which are expected to examine whether DeFi arrangements should be brought within the regulated perimeter. Accounting firms advising EU clients should track those reviews closely.
In the United Kingdom, the Financial Conduct Authority has signalled openness to regulating DeFi where identifiable operators exist, a position that maps directly onto FATF's framework. In the United States, the debate over DeFi regulation has been more contested, but FATF's reinforced position adds international pressure to domestic policymakers. For firms with cross-border DeFi client exposure, the patchwork of national implementations means that a single client engagement may implicate multiple regulatory regimes simultaneously.
Firms should not wait for their national regulator to issue specific DeFi guidance before acting. FATF's position is clear enough to inform a prudent risk assessment now. Updating client onboarding questionnaires, extending AML transaction monitoring to cover DeFi activity, and ensuring that the firm's digital asset accounting software captures the metadata needed for regulatory review are all steps that can be taken without waiting for domestic legislation to catch up.
Practical Next Steps for Firms
The FATF statement calls for a structured response rather than a wait-and-see posture. Below is a prioritised action list for accounting firms and CFOs.
Immediate Actions
First, review all existing and prospective clients that have any involvement with DeFi protocols, whether as operators, investors, or users. Document the nature of that involvement and assess whether any client could be characterised as operating a VASP under the FATF centralisation test.
Second, check whether your AML policy explicitly covers DeFi transaction monitoring. Most AML policies written before 2024 will not. An addendum or updated risk assessment that addresses DeFi is a minimum requirement in most FATF member jurisdictions now that FATF has made its position explicit.
Third, audit your crypto bookkeeping software configuration. Can it tag DeFi protocol interactions separately from centralised exchange trades? Does it record smart contract addresses? Does it capture fair value at the transaction date for each DeFi event? If not, work with your software provider to close those gaps.
Fourth, brief your audit and advisory teams on the going-concern and contingent liability angles described above. The risk is not just the client's risk; it is also a professional liability risk for the firm if a known regulatory exposure was not identified and disclosed.
Frequently Asked Questions
Does FATF's position mean all DeFi protocols are now regulated as VASPs?
No. FATF's position is that DeFi protocols where identifiable persons or entities exercise control or sufficient influence should be treated as VASPs. Protocols that are genuinely decentralised with no identifiable controlling party remain a grey area, though FATF acknowledges such protocols are less common in practice than the industry suggests.
How does this affect an accounting firm's client acceptance process?
Firms should add DeFi-specific questions to their onboarding questionnaires. If a client operates, controls, or earns fees from a DeFi protocol, the firm needs to assess whether that client is operating as an unregistered VASP in any relevant jurisdiction before accepting or continuing the engagement. Where the risk is unclear, legal counsel should be involved.
What does this mean for transaction monitoring in AML programs?
AML programs that currently monitor only centralised exchange activity need to be extended to cover DeFi interactions. FATF's position implies that regulators will expect monitoring of on-chain DeFi activity, not just fiat on- and off-ramp events. Digital asset accounting software should be configured to support this level of monitoring by capturing protocol-level metadata for every DeFi transaction.
Are there audit disclosure implications for clients with DeFi token holdings?
Yes. If a client holds tokens in a DeFi protocol whose operator may be characterised as an unregistered VASP, auditors should consider whether that exposure warrants disclosure as a contingent liability or a going-concern factor, particularly where the holding is material. The risk is that regulatory enforcement against the protocol operator could impair the client's ability to access or realise the holding.
Which jurisdictions are most likely to act on FATF's position first?
FATF member jurisdictions with active crypto regulatory programs are the most likely early movers. Within the OECD, the EU (through MiCA reviews and AMLA guidance), the UK (through FCA enforcement), and jurisdictions with existing VASP registration regimes are best positioned to act quickly. Firms with clients operating across multiple OECD jurisdictions should monitor each domestic regulator's response rather than waiting for a single global implementation.
Source: Decrypt
