FATF Report Highlights Institutional Access Points into DeFi Multiply Despite Regulatory Gaps
The Financial Action Task Force (FATF) has released a report highlighting the growing accessibility of decentralized finance (DeFi) for traditional financial institutions. According to the report, only two out of 142 surveyed jurisdictions have licensed or registered a DeFi arrangement, leaving the responsibility on institutions to identify who controls these arrangements before using them.
The FATF's framework categorizes DeFi arrangements into three tiers: those with identifiable controllers, those that are centralized in practice but hard to pin down, and genuinely decentralized arrangements. Institutions must conduct customer due diligence on the arrangement itself for the first two categories, while for decentralized arrangements, they must apply anti-money laundering and combating the financing of terrorism (AML/CFT) measures directly to the underlying customers.
The report also notes that institutional infrastructure simplifies technical access to DeFi but complicates legal consequences. Despite the operational benefits of VASPs and DeFi arrangements, including automated settlement, cross-border reach, 24/7 availability, and higher yields, institutions must still adhere to their existing AML/CFT responsibilities.
The gap in identification is a recurring issue, with some attempts to solve it by building identification into DeFi protocols from the start. However, gateway products like Fireblocks Earn have widened access to broader, less curated pools, requiring institutions to perform identification work on a case-by-case basis.