FATF’s DeFi COSI Test: AML Oversight Framework Explained

The FATF has published its first DeFi-specific report, proposing how jurisdictions should apply existing AML/CFT rules to decentralized finance using a “control or sufficient influence” (COSI) test. The core message: calling a protocol “decentralized” is not enough to avoid oversight. The report classifies DeFi protocols into three groups: (1) centralized with identifiable controllers (in-scope like VASPs), (2) centralized but with unidentified controllers (also in-scope), and (3) truly decentralized (out-of-scope, but still requiring risk-based mitigation). To measure control or sufficient influence, FATF points to indicators such as governance token concentration, administrative privileges (e.g., upgrade keys, pausing), and fee/treasury control, plus relevant off-chain factors like front-end interfaces and development repositories. Blockchain analytics is positioned as the key capability to make the framework operational. Key statistics cited: illicit flows into DeFi protocols rose 343% year-on-year. For stablecoins, the report notes they account for 84% of all illicit transaction volume, and calls for freeze/burn capabilities as a baseline—while warning that criminals are designing stablecoins to resist freezing. For enforcement readiness, the FATF says 93% of jurisdictions have not identified qualifying DeFi protocols, with only four applying licensing requirements and just one taking enforcement action. Priorities include continuous blockchain analytics (tracing, wallet clustering, network analysis), oversight of front-ends and oracle operators, and stronger cybersecurity + AML convergence. Market-facing implications: DeFi counterparties—especially those touching bridges, mixers, and cross-chain tools—may face higher compliance scrutiny and enhanced due diligence, while compliance controls could become a market differentiator.
Neutral
The FATF DeFi report is primarily a regulatory framework, not an immediate trading catalyst. In the short term, it can raise uncertainty for DeFi tokens and venues tied to protocols with unclear governance/control, because enhanced AML/CFT scrutiny and continuous on-chain monitoring may increase compliance overhead and affect access (e.g., risk-based partner onboarding, tighter thresholds for flags). However, the report also explicitly encourages embedded safeguards (pause/kill switches, front-end screening, sanctions checks), which can reduce tail risks for legitimate users and may attract institutional capital to better-controlled protocols. Historically, similar “framework-first” actions (e.g., FATF guidance waves in prior years, or major regulatory clarification on stablecoin rules) often cause short-lived sentiment swings, but long-term outcomes depend on implementation speed and how markets price compliance risk. Here, the cited gaps—93% of jurisdictions have not identified qualifying DeFi protocols—suggest slower near-term enforcement, making the effect more gradual than abrupt. Stablecoins are the main linkage to price-sensitive flows: with illicit stablecoin volume highlighted (84%), any expectation of stricter freeze/burn compliance could influence stablecoin selection and liquidity routes. Still, because the framework is tech-neutral and risk-based, the overall market impact is likely neutral, with selective re-pricing among higher-risk cross-chain/bridge interactions versus protocols adopting stronger governance transparency and monitoring.