Who Controls a DeFi Protocol? What FATF's 2026 Framework Means for AML Compliance

Featured

Nearly 93% of jurisdictions that report have yet to adopt the FATF Standards for qualifying DeFi arrangements. According to FATF findings from July 2026, 132 of 143 jurisdictions still face this situation, even as capital locked across DeFi protocols reached $86.6 billion in May 2026. 

Alarmingly, only two of the 142 jurisdictions that responded indicated that they were actually licensing or registering a DeFi arrangement. This highlights that the issue is not a lack of FATF rules on DeFi. Instead, regulators and compliance professionals still struggle to identify who controls these arrangements.

FATF Recommendation 15 already addresses situations where an individual or legal entity exercises control or considerable influence over a DeFi arrangement. The Updated Guidance from 2021 laid the foundation for this approach, while the 2026 report further develops the assessment with practical indicators covering governance, technology, economics, and infrastructure.

The key question is not whether a protocol claims to be decentralized, but rather whether identifiable parties can still exert influence over its significant functions.

Key Takeaways

FATF’s 2026 DeFi framework places less emphasis on whether a protocol calls itself decentralised than on whether identifiable people or entities exercise control or sufficient influence.

  • Decentralization doesn't inherently eliminate AML obligations: Governance rights, upgrade keys, parameter-setting authority, oracle control, infrastructure technical access and the economic benefits can indicate meaningful influence.
  • Attribution plays a crucial role in DeFi compliance: Regulators must assess whether control is present, identify its location, and determine if the responsible parties can be recognized.
  • On-chain analysis alone is not sufficient: Treasury signatories, development teams, foundations, front-end operators and public communications can help connect technical control with identifiable parties.
  • Unclear attribution does not eliminate risk: Compliance attention should shift toward wallets, counterparties, VASPs, on-ramps, and off-ramps.
  • Wallet screening and transaction monitoring are crucial for identifying potential sanctions exposure, unlawful activities, and other cryptocurrency-related risks, even when a protocol's ownership is not clearly defined.
  • DeFi risk assessments need regular reassessment because governance, voting power, upgrade authority and infrastructure can change over time.

Why “Decentralised” Does Not Automatically Mean Outside FATF's Scope

A protocol can decentralise transaction execution while retaining concentrated control over administration, upgrades, governance or economic benefits. FATF's 2026 report therefore takes a functional approach rather than accepting a project's own description of its architecture.

Recommendation 15 is based on an arrangement's actual operations and the individuals who can influence it. The mere presence of governance tokens alone does not automatically lead to the decentralization of a protocol. Similarly, a DAO structure, open-source code, or unrestricted access alone does not ensure a positive outcome. 

This idea was emphasized in the FATF's 2021 guidelines, which explain that decentralized finance (DeFi) arrangements may be subject to Recommendation 15 if an individual exercises control or can materially affect the arrangement. The 2026 report further develops the analysis with indicators that help practical indicators for supervisors to evaluate.

A protocol can have thousands of wallets interacting with it while a handful of addresses retain decisive governance power. The visible community can therefore be broad while effective control remains concentrated.

Control Does Not Always Mean Direct Control

FATF's approach is broader than identifying a person with unilateral technical authority. Sufficient influence can arise through governance rights, economic interests, development authority or authority over the supporting infrastructure. A protocol therefore does not need a single administrator with the power to change every relevant smart contract for a person or entity to be relevant to the Recommendation 15 analysis.

Centralised vs Truly Decentralised DeFi Under FATF

FATF does not determine whether a DeFi arrangement falls within Recommendation 15 based only on whether it describes itself as centralised or decentralised. The assessment focuses on whether a natural or legal person exercises control or sufficient influence and whether that person or entity can be identified.

When DeFi Remains Controlled

A DeFi arrangement can retain meaningful control even when it uses open-source smart contracts, governance tokens or a DAO structure. Identifiable parties may influence important functions through upgrade keys, administrative privileges, governance rights, parameter-setting authority or control over supporting infrastructure.

Where control or sufficient influence exists and the responsible person or entity can be identified, the arrangement may be subject to relevant FATF requirements under Recommendation 15. Decentralised technology therefore does not automatically remove identifiable control. A protocol may have thousands of users while decision-making authority remains concentrated among administrators, developers or governance participants.

When DeFi Is Truly Decentralised

The analysis differs where no identifiable natural or legal person exercises control or sufficient influence over the arrangement. In such cases, there may be no person or entity to whom the relevant Recommendation 15 obligations concerning control can be attributed.

However, this does not eliminate AML/CFT risk. Financial institutions and VASPs may still interact with the arrangement through wallets, customers, counterparties, on-ramps and off-ramps.

The key FATF question is therefore not whether a protocol claims to be decentralised, but whether meaningful control exists, where it sits and whether it can be attributed to an identifiable person or entity.

Three DeFi Control Scenarios Emerging From FATF's Framework

Three DeFi Control Scenarios Emerging From FATF's Framework

The centralised versus truly decentralised distinction does not capture every DeFi arrangement. FATF's framework also considers situations where control exists but the person or entity exercising that control cannot be identified. This creates three practical scenarios for compliance teams: identifiable control, control that cannot be attributed, and arrangements where no identifiable person exercises control or sufficient influence.

no identifiable person exercises control or sufficient influence

  • The First Category

Administrators may hold upgrade keys, governance participants may control proposals or developers’ teams may also retain authority over protocol infrastructure. Where a natural or legal person exercises control or sufficient influence and can be identified, the arrangement may fall within the relevant FATF requirements.

  • The Second Category

A protocol can have obvious control points without revealing the individuals behind those addresses. FATF recognises this distinction because technical evidence may establish that control exists even when legal attribution remains unresolved. That creates a regulatory gap rather than a genuine absence of risk. A protocol can remain functionally centralised while becoming practically difficult to supervise.

  • The Third Category

It represents cases in which no identifiable person exercises control or sufficient influence. In such cases, the arrangement may fall outside Recommendation 15's application to a person controlling or sufficiently influencing the DeFi arrangement. That does not remove the need for risk-based controls at relevant financial and virtual-asset access points.

This model is operational. Compliance teams can move from asking whether a protocol is decentralised to testing whether control exists, where it sits and whether its holder can be identified.

How Regulators Can Identify Control On-Chain

The 2026 FATF report provides practical indicators for examining control. These indicators matter because blockchain infrastructure often exposes authority more clearly than corporate documents do.

Upgradeability and administrative privileges

Upgradeability and administrative privileges

Upgrade functions provide one of the clearest signals of control. An administrator who can modify deployed contracts retains authority over protocol behaviour after launch.

Proxy architecture may leave the same result. The underlying contract may appear fixed while an administrator retains control over the implementation contract or upgrade mechanism. Pause functions and emergency controls can also indicate operational influence.

Parameter-setting authority

Protocol settings can indicate control without any direct ability to move treasury funds. Fee levels, collateral requirements, liquidation thresholds and risk limits can materially change the protocol's effect on user activity.

The person having authority over these settings can therefore influence the protocol's economic operation. This is especially relevant for lending markets and derivatives platforms, where parameter adjustments can rapidly alter user exposure.

Oracle control

Oracle architecture can also reveal concentrated influence. A party that selects trusted price feeds or controls oracle configuration may influence collateral valuations and liquidation decisions.

Recent DeFi incidents also illustrate why privileged administrative and oracle-related controls deserve scrutiny. Where an attacker or unauthorised party obtains such privileges, control over protocol parameters can translate into rapid and substantial asset losses.

Protocol-critical infrastructure

Deployment keys, executor networks along with supporting infrastructure can expose operational control. A protocol may present governance as community-led while essential technical functions can remain dependent on a small technical group.

These layers can include servers, application programming interfaces and privileged deployment systems. Evidence from these systems can therefore supplement on-chain analysis when assessing who exercises practical influence over a protocol.

Fee flows and economic benefits

FATF also points toward economic influence. Repeated fee distributions, liquidation rebates, or other protocol revenues flowing to identifiable addresses can provide clues about who benefits from the arrangement.

Economic benefit alone does not necessarily prove control. Combined with administrative rights or governance influence, however, it can strengthen the attribution case.

Governance token concentration

Token ownership can create formal decentralisation without meaningfully dispersing voting power. A large holder count may therefore conceal a small group controlling proposals, quorum or veto rights.

A holder count can therefore create a misleading picture. Hundreds of thousands of wallets may hold governance tokens while a small group controls proposals, quorum or veto rights.

Delegated voting

Delegated voting therefore requires tracing connections within the token-holder base and delegates to determine whether voting influence is genuinely distributed. Blockchain intelligence can help compliance teams map these connections and evaluate effective governance power.

Why On-Chain Evidence Is Not Enough

On-chain evidence rarely provides the complete attribution picture. FATF therefore considers off-chain factors that can connect technical authority with the identifiable people or the entities.

Treasury wallet signatories can reveal who controls protocol funds. Development teams are also able to identify individuals with authority over upgrades, infrastructure or roadmap decisions.

Foundations and development companies can also employ core contributors even when the protocol itself has no obvious corporate owner. Front-end operators can also influence access and user interaction, even without ownership of the underlying contracts.

Branding and communications authority can provide another useful connection. Official websites, documentation, governance forums, and public communications can provide insights into who leads protocol development or acts as the external representative for the arrangement.

These off-chain connections can therefore turn technical evidence of control into an attribution assessment relevant to regulatory and compliance decisions.

What DeFi Enforcement Cases Reveal About Attribution

What DeFi Enforcement Cases Reveal About Attribution

FATF’s approach to DeFi attribution is supported by enforcement history. Regulatory and criminal cases have repeatedly shown that decentralised structures can still have identifiable individuals, concentrated control and accountable operators.

Enforcement Can Reach Decentralised Structures

The Ooki DAO case provides one of the clearest examples. The Commodity Futures Trading Commission (CFTC) pursued Ooki DAO, alleging that it operated an illegal trading platform and acted as a futures commission merchant. A federal court held that Ooki DAO could be sued as an unincorporated association and treated it as a person under the Commodity Exchange Act.

This case illustrates how DeFi AML compliance functions in practice. A DAO structure does not inherently protect a protocol or its participants from regulatory oversight. The key consideration is who is responsible for operating, controlling, or influencing how the arrangement functions.

The earlier bZeroX case supports the same conclusion, as the Identifiable individuals exercised administrative authority before control shifted toward token holders. This structure illustrates why historical control can remain significant, even as governance frameworks evolve over time.

Public Claims of Decentralisation Do Not Replace Control Analysis

The SafeMoon case further illustrates why compliance reviews should examine actual operations rather than a project's public characterisation.

The Securities and Exchange Commission has filed charges against SafeMoon and several members of its executive team. The commission accuses them of fraud and failing to register their offering. According to the complaint, insiders maintained the ability to direct critical operations and mishandled over $200 million in cryptocurrency assets.

The case highlights why compliance teams should examine:

  • Who controls key protocol functions
  • Who benefits economically from the arrangement
  • Who makes operational decisions
  • Whether control is concentrated among identifiable individuals or entities

Smart Contracts Do Not Always Obscure the People Behind a Service

The Forsage case highlights another critical aspect of attribution in the cryptocurrency realm. The SEC has charged eleven individuals linked to a pyramid scheme that reportedly raised over $300 million from millions of investors. The complaint outlines how the founders ran a website that enabled transactions executed through smart contracts across various blockchains.

Samourai Wallet provides a further example. Its founders were identifiable, allowing prosecutors to connect the service with specific operators. The case demonstrates that pseudonymous blockchain infrastructure does not necessarily prevent investigators from identifying the people behind a crypto service.

These cases show why blockchain analysis should be combined with off-chain information such as company records, public communications, development activity and infrastructure ownership.

When Control Is Compromised, Attribution May Not Be Enough

FATF’s reporting on the April 2026 DeFi incidents highlights another challenge. Two major attacks accounted for approximately 76% of annual virtual-asset hacking losses, with combined proceeds exceeding $570 million.

Once compromised assets move across multiple networks, services and liquidity venues, identifying the original controller may no longer provide sufficient visibility into the risk.

Compliance teams may therefore need to shift their focus toward:

  • Wallets receiving or transferring compromised assets
  • Counterparties and transaction relationships
  • Cross-chain movements
  • VASPs and other regulated access points
  • Sanctions and illicit-activity exposure

The Compliance Lesson

These cases point to a wider compliance point in FATF’s 2026 framework. Attribution helps determine where regulatory responsibility may sit, but it is not the only source of AML visibility.

When governance, development or service operations connect a DeFi arrangement to identifiable parties, that evidence can support the compliance assessment. When attribution remains uncertain, wallet screening, transaction monitoring and counterparty analysis become increasingly important for identifying exposure.

The result is a more practical approach to DeFi compliance. Rather than asking only whether a protocol is decentralised, firms need to assess who can influence it, whether that influence can be attributed and where risk remains visible when attribution fails.

Where the Compliance Burden Lands When Attribution Fails

FATF's 2026 report shifts attention toward the points where financial institutions and virtual asset service providers can still identify customers, counterparties and transactions.

When Identifiable Controllers Remain in Scope

Where controllers are identifiable, relevant FATF requirements remain applicable according to the nature of the relationship. Recommendation 10 establishes customer due diligence requirements while Recommendation 13 addresses correspondent banking relationships. FATF also states that financial institutions and VASPs should refrain from interacting with DeFi arrangements where they cannot comply with the FATF Standards. This makes assessing protocol exposure and identifying appropriate control points for onboarding, transaction monitoring, and ongoing risk assessment relevant.

This means compliance teams should assess identified administrators, governance participants, corporate entities, and treasury signatories based on their exposure and regulatory obligations.

Sanctions screening becomes particularly important when identifiable controllers, counterparties, or transaction participants have links to sanctioned persons, entities, or jurisdictions. When a controller cannot be identified, the compliance question changes. The focus moves toward the access points that remain visible.

Wallet Screening as a DeFi Control Point

Wallet Screening as a DeFi Control Point

These points include stablecoin issuers, VASP on-ramps and off-ramps, front-end operators and the wallets interacting with the protocol. That is where crypto wallet screening becomes an important control for DeFi exposure.

AML Watcher's crypto compliance capabilities support sanctions screening, wallet risk assessment and continuous monitoring, with coverage across more than 215 sanctions regimes. Wallet screening therefore complements controller analysis by providing a separate view of risk exposure at the transaction and counterparty level.

A wallet can still reveal interaction with sanctioned entities, illicit services or other risk indicators even when the protocol's ownership structure remains uncertain. AML Watcher describes crypto wallet intelligence across more than 415 risk categories, including ransomware, darknet markets, mixing services and sanctions.

The Travel Rule adds another checkpoint, as highlighted in the FATF's seventh targeted update for 2026. This report indicates that 83% of the jurisdictions surveyed have now enacted legislation to implement the Travel Rule, an increase from 73% in 2025. For VASPs, regulated on-ramps and off-ramps therefore remain important points for identifying transaction participants and assessing risk. AML Watcher's crypto Travel Rule solution supports originator and beneficiary information exchange alongside risk screening.

Speed Matters When Funds Move Across Networks

KelpDAO demonstrates why rapid action matters.. Once stolen assets cross multiple networks and enter additional liquidity venues, the opportunity to freeze or recover funds can narrow rapidly.

Yet screening at scale creates another operational constraint. False-positive volumes remain a persistent operational challenge for AML teams, particularly when screening large numbers of transactions and wallets. AML Watcher's published testing reports a 44% reduction in false positives and a 15% reduction in false negatives.

These figures should be read as AML Watcher's reported testing results rather than as industry-wide benchmarks. These broader operational challenges make it important to reduce unnecessary alerts without losing meaningful risk signals.

Why DeFi Monitoring Needs a Risk-Based Approach

Not every DeFi protocol presents the same level of exposure. Protocol activity, governance concentration, administrative privileges, jurisdictional links, sanctions exposure and interaction with regulated financial institutions can all influence the level of scrutiny required. A risk-based approach can therefore prioritise protocols, wallets and counterparties where governance concentration, administrative privileges or transaction exposure indicate higher risk.

A stronger approach connects controller analysis with wallet-level monitoring. Attribution determines where regulatory responsibility may sit, while wallet screening helps identify exposure when that responsibility remains uncertain.

What FATF's 2026 Framework Means for DeFi AML Compliance

For compliance officers, this creates a practical workflow.

First, determine whether a person or entity exercises control or sufficient influence through governance, technology, economics or infrastructure. Then assess whether that person or entity can be identified and determine the relevant regulatory obligations in the applicable jurisdiction.

If attribution remains unresolved, the compliance process should not stop. Attention should shift toward wallets, customers, counterparties, front-end access points, on-ramps, off-ramps and VASP interfaces where identity and transaction information may still be available.

The framework also suggests that compliance teams should document why a protocol was classified in a particular category. Governance can change. Voting concentration can shift. Upgrade keys can be transferred. Treasury signatories can change.

A classification that was accurate at one point can therefore become outdated after a governance proposal, a transfer of upgrade authority, a change in voting concentration, or an infrastructure migration.

FATF's approach makes periodic reassessment particularly relevant for institutional firms interacting with DeFi. Control should be treated as an observable characteristic that can change rather than a permanent label attached to a protocol.

From DeFi Attribution to Actionable AML Controls

From DeFi Attribution to Actionable AML Controls

DeFi activity continues to expand while implementation of the FATF Standards remains uneven across jurisdictions. FATF's 2026 findings show that the regulatory challenge is no longer simply understanding whether DeFi is decentralised. It is determining whether identifiable people or entities exercise control or sufficient influence over the arrangement.

Where such persons or entities can be identified, attribution can inform the relevant compliance response. Where attribution remains unresolved, the compliance program still needs other visibility points.

Controller identification and wallet-level monitoring therefore serve different but complementary purposes. Attribution helps determine where regulatory responsibility may sit, while wallet and transaction screening provides visibility when protocol ownership or governance remains unclear. AML Watcher's crypto wallet screening, sanctions screening and Crypto Travel Rule capabilities support these downstream compliance needs.

For firms evaluating their crypto compliance infrastructure, AML Watcher's buyer's guide offers a broader framework for assessing solutions. A demo can also show how wallet and transaction screening can fit within an existing compliance program.

Strengthen Crypto Compliance When DeFi Attribution Is Unclear

As DeFi protocols become harder to attribute, financial institutions and VASPs need compliance controls that can identify risk even when ownership and governance structures remain unclear. 

AML Watcher helps businesses strengthen crypto compliance with wallet screening, sanctions screening and Crypto Travel Rule solutions that provide visibility across wallets, transactions and counterparties. For a broader view of crypto compliance requirements and solution considerations, explore AML Watcher’s buyer’s guide. 

Request a Demo to see how AML Watcher can support crypto risk monitoring within an existing compliance program.

Access Premium Content

Register once. Get unlimited access to exclusive AML insights and expert industry analysis, all in one place.

Your information is secure and will not be shared.