Traditional financial institutions are gaining easier access to decentralized finance, but regulators are making it clear that better infrastructure does not remove existing compliance obligations.

The Financial Action Task Force (FATF) says virtual asset service providers (VASPs) and DeFi arrangements can deliver significant operational benefits, including automated settlement, global reach, round-the-clock availability, and access to potentially higher yields.

However, those advantages do not exempt banks, brokers, fintech companies, or other regulated institutions from their existing anti-money laundering and counter-terrorist financing (AML/CFT) responsibilities.

According to FATF’s latest guidance, financial institutions considering DeFi integrations must determine who controls or exercises influence over a protocol before interacting with it. That requirement applies regardless of whether the project describes itself as decentralized or how its technical architecture is structured.

FATF Divides DeFi Into Three Categories

FATF’s framework broadly separates DeFi arrangements into three groups.

  • Protocols where identifiable individuals or organizations exercise sufficient control.
  • Arrangements that appear centralized in practice but where identifying the responsible parties is difficult.
  • Genuinely decentralized systems where no clear controller can be identified.

The classification does not eliminate an institution’s AML/CFT duties. Instead, it determines how those responsibilities should be carried out.

When an identifiable controller exists, regulated institutions and VASPs are expected to conduct due diligence on the DeFi arrangement itself.

That process can include determining whether the entity is properly licensed or registered where required, evaluating the quality of regulatory supervision, and reviewing its AML/CFT controls.

When no controller can be identified, including genuinely decentralized protocols, FATF expects institutions to apply appropriate AML/CFT controls directly to customers interacting through the arrangement.

This creates a significantly more complex compliance challenge for financial companies looking to access permissionless DeFi markets.

Blockchain Analytics Alone May Not Be Enough

Blockchain monitoring and transaction analytics can help institutions assess the risk associated with DeFi activity.

However, FATF does not view blockchain analytics as a complete replacement for traditional AML/CFT procedures.

On-chain tools can identify suspicious transaction patterns, exposure to sanctioned wallets, interactions with mixers, or connections to previously flagged addresses. But regulated companies may still need additional information about customers and counterparties.

If an institution cannot meet its regulatory obligations through either protocol-level due diligence or customer-level controls, FATF’s position is straightforward: it should consider avoiding the DeFi arrangement altogether.

That could become increasingly important as institutional access to decentralized markets expands.

Institutional DeFi Access Is Growing

The regulatory question is becoming more relevant because infrastructure providers are rapidly lowering the technical barriers separating traditional finance from DeFi.

Fireblocks, a digital asset custody and infrastructure platform widely used by institutional clients, launched Fireblocks Earn in April 2026.

The service gives institutional customers access to on-chain lending opportunities, including markets powered by major DeFi protocols such as Aave and Morpho.

Infrastructure providers can simplify many operational challenges associated with DeFi participation. They can manage transaction signing, approval processes, wallet security, policy controls, and position monitoring from a single institutional interface.

But simplifying the technical process does not necessarily transfer the underlying regulatory responsibility.

The FATF framework effectively places the burden on the regulated institution to determine whether its AML/CFT obligations are being satisfied when it connects customers or capital to decentralized protocols.

DeFi Gateways Create a New Compliance Challenge

The distinction matters because institutional gateways can make accessing DeFi resemble interaction with conventional financial infrastructure.

Behind the interface, however, institutions may still be dealing with open protocols containing participants that have not undergone the same identification procedures expected in traditional finance.

Neither infrastructure convenience nor automated smart contracts necessarily answers the central regulatory question: who are the relevant counterparties, and who is responsible for controlling the arrangement?

For banks and brokers, that means integration through a professional custody or infrastructure provider may solve wallet management and operational security without fully resolving compliance risk.

The easier DeFi becomes to access, the more important this distinction may become.

Aave Arc Tried to Solve the Identification Problem

The challenge of bringing regulated institutions into DeFi is not new.

Aave Arc, launched in 2022 with Fireblocks serving as a whitelister, attempted to solve part of the problem by restricting participation to approved institutions.

Unlike permissionless Aave markets, access to Aave Arc required participants to complete identity verification and KYC procedures before entering the liquidity pool.

This created a controlled environment where institutional participants could use DeFi infrastructure while interacting only with previously approved counterparties.

A similar approach appeared in Singapore’s Project Guardian.

Project Guardian Combined DeFi With Verified Identities

A 2022 Project Guardian pilot involving JPMorgan’s blockchain division, now known as Kinexys, along with DBS and SBI Digital Asset Holdings, explored institutional transactions using public blockchain infrastructure.

The project used a modified version of Aave Arc together with W3C Verifiable Credentials.

The goal was to preserve some benefits of blockchain-based settlement while ensuring that only authorized participants could interact with the system.

Both Aave Arc and the Project Guardian pilot essentially addressed the identification issue before transactions occurred.

Participants entered a controlled environment only after satisfying predefined requirements.

The newer generation of institutional DeFi gateways is different.

Products that provide access to broader permissionless markets can dramatically increase the number of investment and lending opportunities available to institutions, but they may also shift more compliance work back onto the institution using the gateway.

Permissionless DeFi Makes Due Diligence Harder

The difference between permissioned institutional DeFi and permissionless markets could become increasingly significant.

In a closed system, every participant may already have completed KYC and other checks.

In an open DeFi protocol, liquidity can come from thousands of unrelated wallets distributed across multiple jurisdictions.

Determining the identity, regulatory status, and risk profile of all relevant participants can therefore be much more difficult.

That tension highlights one of the biggest unresolved questions surrounding institutional DeFi adoption: traditional finance increasingly wants the efficiency of permissionless markets while regulators continue to expect traditional compliance standards.

Global DeFi Regulation Remains Limited

Institutions cannot necessarily rely on national licensing frameworks to solve the problem either.

FATF’s survey highlights how early DeFi regulation remains across many jurisdictions.

FATF Survey Metric Result
Jurisdictions responding to the survey 142
Jurisdictions that assessed DeFi-related risks 26
Jurisdictions that had not identified a qualifying DeFi arrangement 132
Jurisdictions with licensing or registration requirements 4
Jurisdictions that had actually licensed or registered an arrangement 2

Those figures demonstrate how limited the regulatory infrastructure surrounding DeFi remains internationally.

Banks May Have to Make Their Own DeFi Risk Decisions

The absence of mature licensing systems means banks, brokers, fintech companies, and other regulated firms cannot always depend on governments to determine whether a particular DeFi protocol is suitable for institutional use.

Instead, much of that responsibility remains with the institutions themselves.

They may need to identify controllers, evaluate protocol governance, examine AML/CFT controls, analyze blockchain activity, understand how customers interact with the protocol, and determine whether sufficient information is available to satisfy regulators.

If those questions cannot be answered, institutions may ultimately have to avoid interacting with the protocol.

That creates an important divide between technological access and regulatory access.

TradFi’s Path Into DeFi Is Getting Easier — Technically

Institutional infrastructure is making DeFi considerably easier to use.

Custody platforms, transaction-policy engines, institutional wallets, smart-contract integrations, and automated reporting tools are removing many of the operational obstacles that once prevented banks and asset managers from participating directly in decentralized markets.

But FATF’s framework suggests that compliance obligations are not disappearing alongside those technical barriers.

In some cases, easier access to permissionless DeFi could actually create more complicated regulatory questions.

For traditional financial institutions, the next phase of DeFi adoption may therefore depend less on whether they can connect to decentralized protocols and more on whether they can prove that doing so complies with existing AML/CFT rules.

The infrastructure connecting TradFi and DeFi is rapidly improving. The responsibility for managing the risks, however, still rests largely with the institution choosing to use it.

Leave a Reply

Your email address will not be published. Required fields are marked *

© Copyright 2026 DeFi Master
Powered by WordPress | Mercury Theme