CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FATF DeFi Report 2026: What the COSI Test Means for Your Firm

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING FATF DeFi Report 2026: What the COSITest Means for Your Firm

The Financial Action Task Force has released a 49-page report on decentralised finance, and the central message is unambiguous: calling a protocol 'decentralised' is not sufficient to place it outside the scope of anti-money laundering and counter-terrorist financing obligations. Published in July 2026, the report introduces a structured framework for determining when DeFi arrangements must be treated as regulated Virtual Asset Service Providers, and it names blockchain analytics as the primary tool for making that determination operational. For accounting firms running crypto compliance and reporting engagements, and for CFOs with balance-sheet or treasury exposure to DeFi protocols, the implications are immediate.

FATF DeFi Report 2026: What the COSI Test Means for Your Firm

Why FATF Is Addressing DeFi Now

DeFi protocols offer genuine operational advantages: automated settlement, programmable financial logic, and continuous availability without the need for a central intermediary. Those same features, however, complicate the question of who bears responsibility for compliance. Traditional AML frameworks assume an identifiable obliged entity. DeFi governance structures frequently blur or deliberately obscure that entity.

The FATF acknowledges that institutions want to use DeFi infrastructure and that jurisdictions should enable those interactions responsibly. At the same time, the properties that attract legitimate users also attract illicit ones. The report cites a sharp year-on-year rise in illicit flows into DeFi protocols, making risk mitigation rather than outright restriction the stated policy objective.

The practical compliance gap is striking. A FATF mutual evaluation published alongside the DeFi report found that 93% of jurisdictions have not identified any qualifying DeFi protocols in their territory. Only four jurisdictions have imposed licensing requirements on DeFi arrangements, and just one has taken enforcement action. The new report is a direct response to that gap.

The Control or Sufficient Influence Test

The analytical centrepiece of the report is the 'control or sufficient influence' test, referred to throughout as COSI. The test determines whether a person or entity exercises enough authority over a DeFi protocol to be treated as a VASP under FATF Standards. The framework does not apply a single binary answer. Instead, it places protocols into one of three categories based on the outcome of the COSI assessment.

Category One: Identifiable Control

Where persons or entities clearly exercise control or sufficient influence over a protocol, that protocol falls within the scope of FATF Standards and must be treated as a VASP. Licensing, registration, customer due diligence, transaction monitoring, and suspicious activity reporting all apply in full.

Category Two: Controllers Not Yet Identified

Some protocols are effectively controlled by identifiable persons, but those persons have not been publicly disclosed. The FATF places these arrangements within scope and instructs supervisors to work with domestic authorities, foreign counterparts, and blockchain analytics providers to identify who is actually behind them. The burden of investigation sits with the supervisor, not with an assumption of non-applicability.

Category Three: Genuinely Decentralised

Where no person or entity exercises control or sufficient influence, the protocol sits outside the formal scope of FATF Standards. This does not mean the risk disappears. The report explicitly calls for alternative, risk-based mitigation measures to address the residual risks these arrangements present to the broader financial system.

Indicators Used in the COSI Assessment

The report sets out specific on-chain and off-chain indicators that supervisors and regulated entities should use when conducting a COSI assessment. These indicators translate an abstract legal question into concrete analytical tasks, many of which require crypto accounting software or blockchain analytics tools to execute reliably.

On-Chain Indicators

Governance token concentration is the first on-chain signal. Where a small number of wallets hold enough governance tokens to direct a protocol's financial operations, control may be present even if the arrangement is formally structured as a decentralised autonomous organisation. The FATF specifically calls on supervisors to examine wallet clustering and on-chain voting behaviour to detect hidden patterns of control. Concentration alone is not conclusive evidence of centralisation, but it is a material factor in the analysis.

Private key authority is the second indicator. Possession of keys that allow smart contract upgrades, parameter changes, protocol pauses, or access control modifications is treated as a strong indicator of control. A developer or team that retains upgrade rights over a live protocol is, in functional terms, exercising authority over the financial services that protocol provides.

Treasury and fee flows provide a third data source. Tracing where protocol revenues and treasury assets move, across DeFi protocols, bridges, and decentralised exchanges, can reveal the real-world entities that benefit from and therefore arguably control a protocol's economic output.

Off-Chain Indicators

The COSI framework is not limited to on-chain data. The report identifies control over front-end interfaces, development repositories, and public communications about the ability to modify a protocol as relevant off-chain factors. A team that controls the user-facing website through which most participants access a protocol exercises a form of influence that is economically significant even if the underlying smart contracts are immutable.

What the FATF Expects from Supervisors

The report is explicit about the supervisory toolkit. Three capabilities are identified as complementary and necessary for effective DeFi oversight.

Continuous Blockchain Analytics

The FATF recommends that supervisors conduct ongoing blockchain analytics, including transaction tracing, wallet clustering, and network analysis, to identify controllers and monitor high-risk protocols. This is not a one-time exercise. The governance structures of live protocols can change through governance votes, token distributions, or code upgrades, requiring continuous rather than point-in-time analysis.

Collaboration with Analytics Providers

Where controllers of a nominally centralised protocol cannot be readily identified through public information, the report instructs supervisors to engage blockchain analytics firms that may hold additional identifiers. This public-private partnership model is explicitly endorsed and reflects a broader FATF theme of collaborative enforcement across the public and private sectors.

Cross-Border Cooperation

DeFi protocols do not respect national borders. The report calls on jurisdictions to collaborate with foreign counterparts when investigating protocols that operate across multiple legal systems. For accounting firms advising multinational clients, this signals that a DeFi counterparty assessed as low-risk in one jurisdiction may attract scrutiny from a foreign supervisor, with implications for consolidated AML risk assessments.

Firms already tracking APAC crypto AML compliance risks and licensing realities will recognise this pattern: regulators are increasingly pooling intelligence across jurisdictions, and a compliance gap in one territory can become an enforcement problem in another.

Implications for Financial Institutions and Regulated Entities

The report addresses not only supervisors but also financial institutions, whether they operate in traditional finance or as licensed crypto entities. All regulated firms with DeFi counterparty exposure are expected to conduct risk-based due diligence that covers three dimensions: the governance structure of the protocol, the effectiveness of any AML and CFT controls the protocol has implemented, and the protocol's ability to manage operational risks including smart contract vulnerabilities and exploits.

Where higher risks are identified, enhanced due diligence is required. The report specifically cites exposure to bridges, mixers, and cross-chain tools as factors that should trigger deeper analysis of fund flows and lower thresholds for flagging suspicious activity. Protocols that have implemented limited or no compliance controls are treated as higher-risk counterparties by definition.

One nuance worth noting for CFOs and compliance officers: the FATF actively encourages protocols to implement security features such as kill switches and pause mechanisms, and AML controls such as front-end screening and sanctions checks. The regulatory framework is designed to assess control over financial services, not to penalise good-practice safeguards. A protocol that has implemented a sanctions screening layer at the front end is not, on that basis alone, treated as centrally controlled.

Stablecoin issuers are specifically flagged in the report as carrying distinct obligations. Given that many DeFi protocols rely on stablecoins as their primary unit of account, firms with stablecoin treasury positions that interact with DeFi liquidity pools should review whether those interactions create counterparty exposure to protocols that have not yet been assessed for COSI status.

Accounting and Audit Considerations for Firms

The FATF report has direct consequences for how accounting firms structure crypto engagements and how CFOs design internal controls around DeFi activity.

Counterparty Classification in the Books

If a DeFi protocol falls into Category One or Two under the COSI framework, transactions with that protocol may carry VASP-equivalent compliance obligations. Firms using crypto accounting software or digital asset accounting software to record DeFi transactions need to tag counterparties with their COSI classification status, particularly once domestic supervisors begin publishing lists of protocols they have assessed. That classification will affect how transactions are treated in AML audit trails and, potentially, in disclosures to regulators.

Enhanced Due Diligence Workflows

For clients that provide liquidity to DeFi protocols, lend through DeFi money markets, or hold governance tokens as treasury assets, the standard customer due diligence workflow is no longer adequate. Firms need a protocol-level due diligence procedure that covers governance token distribution, upgrade key custody, treasury flow analysis, and evidence of AML controls. Crypto bookkeeping software that cannot produce a structured audit trail for these data points will need to be supplemented with blockchain analytics output before those files are signed off.

Sanctions Exposure Monitoring

The report's emphasis on bridges and cross-chain tools as elevated-risk infrastructure aligns with existing sanctions enforcement trends. Firms already managing OFAC sanctions exposure on Shelbit and Aban Tether will be aware that cross-chain routing can obscure the origin of funds. The FATF framework now gives supervisors a structured basis for requiring firms to trace those flows as part of standard AML monitoring, not just in response to a specific red flag.

Audit File Documentation

Where a client has material DeFi exposure, audit files should now include documented evidence of the COSI assessment for each protocol used. That means recording which category the protocol falls into, what indicators were reviewed, and what blockchain analytics output supported the conclusion. As domestic supervisors begin implementing the FATF framework, firms that cannot produce this documentation on request will face significant regulatory exposure.

FATF DeFi Report 2026: What the COSI Test Means for Your Firm

What Firms Should Do Now

The 93% figure is the most operationally significant number in the report. Nine in ten jurisdictions have not yet formally assessed any DeFi protocol in their territory. That gap will close as the FATF's new framework filters into national supervisory guidance and mutual evaluation follow-up. Firms that begin their own protocol assessments now will be ahead of the regulatory curve rather than scrambling to catch up when domestic rules land.

Practically, that means four immediate actions. First, inventory all DeFi protocol interactions across your client base or your own balance sheet. Second, apply a preliminary COSI screen to each protocol using publicly available governance data, on-chain analytics, and published documentation. Third, upgrade internal AML workflows to include protocol-level due diligence as a standard step for any DeFi counterparty. Fourth, confirm that the digital asset accounting software used across your practice can produce the audit trail documentation that supervisors will eventually require.

The FATF has provided the framework. Domestic supervisors will now translate it into enforceable obligations. The firms best positioned for that transition are the ones treating protocol governance analysis as a compliance function today, not a future consideration.

Source: Chainalysis

GLOBALOECD#defi#stablecoinsAdoptedAML/KYC & Licensing

FAQ

What is the FATF COSI test and why does it matter for accounting firms?

The 'control or sufficient influence' test is the FATF's framework for determining whether a DeFi protocol must be treated as a regulated Virtual Asset Service Provider. It matters for accounting firms because transactions with a protocol that meets the COSI threshold may carry the same AML and CFT obligations as transactions with a licensed crypto exchange, affecting how those transactions are documented, monitored, and reported.

Does a DeFi protocol that implements a kill switch or sanctions screening become automatically regulated?

No. The FATF report is explicit that the COSI test assesses control over financial services, not the presence of good-practice compliance features. A protocol that implements front-end screening or pause mechanisms is actively encouraged to do so, and those features do not by themselves constitute evidence of the centralised control that would bring the protocol within scope.

What on-chain data should a firm collect when assessing a DeFi counterparty under the COSI framework?

The FATF points to governance token concentration, wallet clustering patterns, on-chain voting behaviour, private key authority over smart contract upgrades, and treasury and fee flows as the primary on-chain indicators. Firms need blockchain analytics output covering these data points for each protocol assessed, and that output should be retained as part of the audit file.

How should stablecoin interactions with DeFi liquidity pools be treated under this framework?

The report singles out stablecoin issuers as carrying distinct obligations. Where a client holds stablecoins and deploys them into DeFi liquidity pools, the firm should assess the governance structure of each pool under the COSI framework. If the pool falls into Category One or Two, the interaction may attract VASP-equivalent due diligence requirements, which should be reflected in transaction records and AML monitoring logs.

What is the enforcement timeline firms should plan for?

The report does not set a fixed deadline, but the accompanying FATF mutual evaluation data shows that most jurisdictions are starting from a near-zero baseline. Enforcement is likely to follow the standard FATF cycle: the framework is now published, national supervisors will incorporate it into domestic guidance, and mutual evaluations will then assess compliance. Firms that begin implementing COSI-based counterparty assessments now will have documented evidence of good-faith effort before that evaluation cycle completes.

Related articles

AML/KYC & Licensing
FATF 7th Targeted Update: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
FATF's 7th Crypto Report Card: The Enforcement Gap Is Now the Central Problem
AML/KYC & Licensing
FATF: Centralised Elements in DeFi Must Be Regulated as VASPs
AML/KYC & Licensing
FATF Urges Faster Crypto AML Enforcement as Stablecoin Crime Grows