TradFi Is Getting Easier Access to DeFi. FATF Says Institutions Still Own the Risk

Institutional infrastructure simplifies technical access to DeFi and complicates legal consequences of using it.
FATF’s recent report admits that VASPs and DeFi arrangements bring lots of operational benefits including automated settlement, cross-border reach, 24/7 availability and generally higher yields.But none of this moves institutions outside their existing AML/CFT responsibilities.
Brokers, banks and other regulated financial institutions must identify who controls a DeFi protocol before using or integrating it into their systems — regardless of how the arrangement is structured or marketed.
Three Tiers, One Duty
The report sorts DeFi arrangements into three categories: those with identifiable controllers, those that are centralised in practice but whose controllers are hard to pin down, and those that are genuinely decentralised.
The category does not change the obligation but determines the amount of paperwork the companies will have to perform before they enter into business relations with the DeFi entity.
If a controller can be identified, financial institutions and VASPs must conduct customer due diligence on the arrangement itself: confirm whether it’s licensed or registered where applicable, assess whether it’s adequately supervised, and review its AML/CFT framework.
If a controller can’t be identified, and for genuinely decentralised arrangements, institutions must apply AML/CFT measures directly to the underlying customers using the arrangement.
Blockchain analytics can support that work, but FATF treats it as a supplementary tool. If the obligations can’t be met under either path, FATF recommends to refrain from interacting with the DeFi protocol or solution at all.
Why the Question Is Live Now
Institutional access points into DeFi are multiplying. Fireblocks is a custody platform used by banks and brokers to access digital-asset infrastructure. In April 2026, it launched Earn, giving institutional customers on-chain lending access through Aave and Morpho.
Fireblocks describes the approval workflows, signing and position tracking on its side; however, there is no mention that Fireblocks, Aave or Morpho perform KYC on every underlying user of those protocols.
That gap is exactly what FATF’s framework puts back on the institution to close, not the platform providing the gateway.
The Identification Problem Isn’t New
Institutions have tried to solve this before by building the identification in from the start. Aave Arc, launched with Fireblocks as a whitelister in 2022, restricted its pool to institutions that had already passed KYC.
Project Guardian’s 2022 pilot, involving JPMorgan’s Kinexys, DBS and SBI Digital Asset Holdings, used a modified Aave Arc alongside W3C Verifiable Credentials to limit access to authorised participants while still settling on public blockchain infrastructure.
Both were ways of front-loading the controller question. Gateway products like Fireblocks Earn widen access to broader, less curated pools. It means that the institution using them will have to do the identification work on a case-by-case basis.
Regulators Haven’t Caught Up Either
FATF’s own survey data lay out how thin the regulatory backstop still is. Out of 142 jurisdictions that responded, only 26 had assessed DeFi-related risks, and 132 had not identified a single qualifying DeFi arrangement operating in their territory.
Only four jurisdictions had implemented licensing or registration requirements for such arrangements, and only two had actually licensed or registered one in practice.
That leaves the controller-identification duty resting on individual institutions. When it comes to their DeFi, brokers, fintech platforms, and banks, they can defer to the licensing regime they can defer to.
They will have to bear the burden of AML/CFT compliance or refrain from dealing with decentralised solutions altogether.