CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FATF DeFi Report: Regulatory Gaps and the Compliance Priorities for Accounting Firms and CFOs

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING FATF DeFi Report: Regulatory Gaps andthe Compliance Priorities forAccounting Firms and CFOs

The Financial Action Task Force has published a dedicated report on the regulatory challenges posed by decentralised finance, and Japan's Financial Services Agency has formally announced the release. The document identifies structural features of DeFi that frustrate conventional anti-money-laundering controls and sets out the directions in which FATF expects national authorities and the private sector to move. For accounting firms, auditors, and CFOs with any digital asset exposure, this is a reference document that shapes how regulators globally are thinking about DeFi oversight, and it will directly influence domestic rules in FATF member jurisdictions including Japan.

FATF DeFi Report: Regulatory Gaps and the Compliance Priorities for Accounting Firms and CFOs

What the FATF Report Covers

FATF's report focuses on the specific features of DeFi that make the application of its existing Recommendations difficult in practice. The core tension is straightforward: the Recommendations were designed around identifiable obliged entities that can be licensed, supervised, and held accountable. DeFi protocols, by design, often lack a single controlling party that fits cleanly into that framework.

The Absence of a Clear Obliged Entity

In a traditional financial services context, the regulated entity is obvious: a bank, a broker, a payment institution. In DeFi, the protocol may be governed by a decentralised autonomous organisation, a dispersed set of token holders, or simply by immutable smart contract code with no living operator. FATF's report examines how jurisdictions are grappling with the question of who, if anyone, should be treated as the Virtual Asset Service Provider for AML purposes when a protocol has no identifiable central actor.

The report does not conclude that DeFi is beyond regulation. Instead, it maps the range of approaches that member jurisdictions are testing, from regulating the developers and deployers of protocols, to focusing on the fiat on-ramps and off-ramps that almost all DeFi activity still touches, to imposing obligations on front-end interface providers even where the underlying protocol is permissionless.

Pseudonymity and Transaction Monitoring

A second structural challenge the report highlights is pseudonymity at the transaction layer. On-chain activity is transparent in the sense that all transactions are recorded on a public ledger, but wallet addresses are not inherently linked to real-world identities. Traditional transaction monitoring depends on knowing who the customer is. DeFi activity, particularly in liquidity pools, automated market makers, and cross-chain bridges, can involve complex, multi-hop flows that are difficult to attribute even with sophisticated blockchain analytics tools.

The report notes that the Travel Rule, which requires originating VASPs to pass customer identity information to beneficiary VASPs, is especially hard to implement in DeFi because there may be no VASP on one or both sides of a transaction. This is not a new observation, but the report is significant because it represents FATF's most systematic treatment of the problem to date.

Cross-Chain Activity and Bridges

Cross-chain bridges receive specific attention. These protocols allow assets to move between different blockchain networks, and they have been the site of some of the largest thefts in the digital asset space. From an AML perspective, bridges can obscure the origin of funds, since a chain-of-custody that is clear on one network may become opaque once assets cross to another. The report identifies bridge activity as a high-risk area requiring closer attention from both regulators and compliance teams.

Japan's Position and the FSA's Role

Japan's FSA published the announcement of this FATF report on 21 July 2026, consistent with its role as an active FATF member and one of the jurisdictions that has gone furthest in regulating crypto asset service providers domestically. Japan has operated a registration regime for crypto asset exchange service providers since 2017 and has progressively tightened AML requirements in line with FATF standards. The FSA's decision to formally publicise this report signals that it will be used as a reference point in domestic policy discussions.

Implications for Japan-Connected Businesses

For businesses operating in or connected to Japan, the FSA announcement is a practical indicator that DeFi-related activity will face greater regulatory scrutiny. Japanese exchanges and crypto businesses that offer any DeFi-adjacent products, whether that is access to liquidity protocols, wrapped asset services, or cross-chain functionality, should expect the FSA to use the FATF report's framework when assessing their compliance obligations. The FSA has historically moved from FATF guidance to domestic rule changes within a relatively short cycle.

Accounting and Audit Implications

The FATF report is primarily an AML policy document, but its implications extend directly into accounting and audit practice. Any firm that audits or advises a client with material DeFi exposure needs to understand what the report signals about regulatory trajectory.

Client Risk Assessment and AML Procedures

Accounting firms carrying out AML due diligence for crypto clients, or acting as the nominated officer in a regulated entity, must now factor the FATF DeFi report into their risk assessment frameworks. If a client's treasury strategy includes participation in DeFi protocols, yield farming, or liquidity provision, the firm should document how the client's activity maps against the risk areas the report identifies: undefined obliged entities, pseudonymous counterparties, and cross-chain flows. The absence of a clear regulatory hook for a given DeFi protocol does not mean the risk is zero; it means the risk is less well-mitigated by the counterparty's own controls.

Audit Evidence and On-Chain Verification

For auditors, DeFi positions present a recognised evidence challenge. Smart contract balances, accrued protocol fees, and governance token holdings all require on-chain verification. The FATF report's emphasis on the opacity of cross-chain activity is directly relevant to the completeness assertion: can the auditor obtain sufficient appropriate evidence that all DeFi positions have been captured, including those that have moved across chains? Firms should review whether their current procedures address multi-chain exposure and whether their crypto accounting software produces audit trails that cover all relevant networks.

Financial Reporting Considerations

Under IFRS, crypto assets held in DeFi protocols are not automatically treated differently from exchange-held assets: the classification depends on the nature of the asset and the entity's business model. However, assets locked in liquidity pools or staking contracts may carry contractual restrictions that affect their classification and the disclosures required. Where a client's DeFi positions are material, the auditor should consider whether the financial statements adequately describe the nature of the exposure and the regulatory environment in which it sits. The FATF report, once absorbed into domestic guidance, will form part of that environment.

CFO Action Points

For CFOs at businesses with DeFi exposure, the report has three near-term implications.

Treasury Policy Review

Any corporate treasury policy that permits DeFi participation should be revisited in light of the FATF report. The document makes clear that regulatory treatment of DeFi activity is unsettled globally and is likely to tighten. A treasury policy written two years ago may not reflect the direction of travel that FATF has now articulated. CFOs should ensure the policy records how DeFi risk is assessed, what approval thresholds apply, and how positions are monitored on an ongoing basis.

Digital Asset Accounting Software and Data Capture

One practical gap the FATF report highlights, even if indirectly, is the data challenge. If regulators require businesses to demonstrate that they know who their counterparties are in DeFi transactions and can trace the provenance of funds, the underlying data infrastructure must be capable of supporting that. CFOs should confirm that their digital asset accounting software captures multi-chain activity, records smart contract interactions at a granular level, and can produce transaction histories suitable for a regulatory examination or an audit. Software that only tracks centralised exchange activity will not be adequate for entities with active DeFi positions.

Engagement with External Advisers

Given that the regulatory perimeter around DeFi is still being defined, CFOs should not rely solely on internal assessments. Engaging an accounting firm with FATF-standard AML expertise and genuine DeFi technical knowledge, not just general crypto familiarity, is the appropriate response to a document of this significance. The FATF report is likely to be cited by regulators in enforcement actions and licensing decisions, making it a live compliance reference rather than a theoretical policy paper.

What Comes Next

FATF reports of this nature typically precede updates to the Recommendations themselves or to the guidance notes that accompany them. Member jurisdictions then transpose those updates into domestic law and regulatory guidance, often within one to two years. Given the FSA's track record, Japan is likely to be among the faster movers. Businesses in other FATF member jurisdictions, across the EU, the UK, the US, Singapore, and elsewhere, should monitor how their domestic regulators respond to the report.

For firms and CFOs, the most important near-term action is documentation: ensuring that existing DeFi-related activity is assessed against the risk categories the report identifies and that the assessment is on record before regulators start asking questions. The firms best positioned in any enforcement or licensing review are those that anticipated the regulatory direction and acted before being compelled to.

The FATF VASP targeted update published earlier in July 2026 is directly relevant context here; our earlier analysis of the FATF VASP targeted update: July 2026 compliance implications covers the broader VASP framework changes that sit alongside this DeFi-specific report. Separately, for firms thinking through the technical dimension of DeFi screening, our piece on DeFi AML screening and what accounting firms must assess examines emerging approaches to on-chain compliance at the protocol level.

FATF DeFi Report: Regulatory Gaps and the Compliance Priorities for Accounting Firms and CFOs

FAQ

What is the FATF DeFi report and why does it matter?

FATF has published a dedicated report examining the regulatory challenges that decentralised finance presents for its anti-money-laundering Recommendations. It matters because FATF standards are adopted by over 200 jurisdictions, and this report will shape how domestic regulators, including Japan's FSA, update their rules for crypto businesses and DeFi-adjacent activity.

Does the FATF report mean DeFi is going to be banned?

No. The report does not call for a ban. It maps the challenges of applying existing AML obligations to DeFi and explores how jurisdictions are developing regulatory approaches, including regulating developers, deployers, and front-end providers. The direction of travel is toward greater accountability, not prohibition.

How should an accounting firm update its client risk assessments after this report?

Firms should identify which clients have material DeFi exposure, document how that exposure maps against the risk areas FATF identifies (undefined obliged entities, pseudonymous counterparties, cross-chain activity), and update their AML risk ratings accordingly. Clients whose DeFi activity involves high-risk areas such as cross-chain bridges or permissionless liquidity pools warrant enhanced scrutiny.

What does this mean for auditors verifying DeFi positions?

Auditors need to consider whether their evidence procedures cover multi-chain positions and smart contract interactions. The FATF report's focus on the opacity of cross-chain flows is directly relevant to the completeness assertion. Audit firms should review whether their crypto bookkeeping software and analytics tools can produce sufficiently granular on-chain evidence across all relevant networks.

How does this report affect Japan-based crypto businesses specifically?

Japan's FSA formally published the FATF DeFi report and is an active FATF member with a track record of moving relatively quickly from FATF guidance to domestic rule changes. Japanese crypto businesses offering DeFi-adjacent products or services should treat the report as an early indicator of forthcoming regulatory expectations and review their compliance frameworks now rather than waiting for formal FSA guidance.

Source: Japan Financial Services Agency

GLOBALJP#defiProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
FATF VASP Targeted Update July 2026: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
FATF: Centralised Elements in DeFi Must Be Regulated as VASPs
AML/KYC & Licensing
Dubai VARA Rolls Out Digital Asset Framework Including Privacy Coin Ban
AML/KYC & Licensing
Elliptic and Zama Bring AML Screening to Confidential DeFi: What Accounting Firms and CFOs Must Assess Now