The FIAU would like to draw subject persons’ attention to two recent publications issued by the Financial Action Task Force (FATF), both of which focus on developments within the virtual asset sphere and the related money laundering and terrorist financing.
These publications are particularly relevant in view of the continued international focus on the effective implementation of AML/CFT requirements in relation to virtual assets, virtual asset service providers (VASPs), decentralised finance arrangements, stablecoins, unhosted wallets and other emerging technologies. The terms virtual assets and virtual asset service providers, as used in the FATF Standards, may be understood as crypto-assets and crypto-asset service providers (CASPs).
Subject persons are encouraged to consider these publications in light of their own business models, customer relationships, products, services and transaction monitoring frameworks, particularly where they may have direct or indirect exposure to crypto-asset-related risks.
Seventh Targeted Update on Implementation of the FATF Standards on Virtual Assets/VASPs
The FATF has published its Virtual Assets Targeted Update on Implementation of the FATF Standards on Virtual Assets and Virtual Asset Service Providers. The report provides an overview of the implementation of the FATF Standards applicable to virtual assets and virtual asset service providers, particularly Recommendation 15, across the FATF Global Network.
The report highlights that progress has been made since 2025, with jurisdictions increasingly taking measures to regulate, supervise and enforce requirements relating to virtual assets and VASPs. This includes work on risk assessments, licensing or registration frameworks, supervision, enforcement, and implementation of the Travel Rule.
At the same time, the FATF highlights that significant challenges remain. These include identifying and assessing ML/TF risks connected to virtual assets and VASPs, developing and implementing regulatory frameworks, licensing or registering VASPs, conducting effective supervision, taking enforcement action, and operationalising Travel Rule-related requirements.
Of particular relevance is the report’s overview of emerging and persistent risks within the crypto-asset ecosystem. It refers to risks associated with stablecoins, decentralised finance arrangements, peer-to-peer transactions, unhosted wallets, offshore VASPs and the use of virtual assets in predicate offences, money laundering, terrorist financing and proliferation financing.
The FATF also identifies areas of relevance for CASPs and subject persons exposed to crypto-asset activity. These include the need to implement AML/CFT requirements, including Travel Rule requirements, and to apply appropriate controls and monitoring measures in relation to higher-risk activity involving stablecoins, unhosted wallets, DeFi-related exposure and cross-chain transactions.
The report may assist subject persons in assessing whether their AML/CFT frameworks adequately identify and mitigate exposure to crypto-assets, CASPs, stablecoin arrangements, unhosted wallets, DeFi-related activity and other emerging virtual asset-related risks. This may be relevant not only for entities directly operating in the crypto-asset sector, but also for those whose customers, transactions, products or services may create indirect exposure to such risks.
For further information, subject persons and other interested parties may access the publication through the FATF’s website or via the FIAU’s website under the “FATF” section.

the FATF Standards on Virtual Assets and
Virtual Asset Service Providers
Targeted Report on Regulatory Challenges from Decentralised Finance
The FATF has also published its Targeted Report on Regulatory Challenges from Decentralised Finance (DeFi). The report examines the characteristics and vulnerabilities of DeFi arrangements, the financial crime risks and typologies associated with them, and the challenges faced by jurisdictions in applying the FATF Standards to such arrangements.
Although DeFi still represents a relatively small portion of the broader virtual asset market, the report notes that its significance has increased due to the growth of the ecosystem, participation by institutional investors, interaction with VASPs and regulated financial institutions, and potential exposure to money laundering, terrorist financing and proliferation financing risks.
The FATF highlights that DeFi arrangements may have distinct technological features, including automation, composability, cross-border accessibility and the use of smart contracts. However, these features may also create vulnerabilities, particularly where arrangements allow pseudonymous participation, unrestricted access, rapid movement of funds, interaction across protocols, or the commingling of legitimate and illicit funds.
A key theme of the report is the distinction between arrangements that are genuinely decentralised and those that present themselves as decentralised while still involving persons or entities exercising control or sufficient influence.
The report distinguishes between three broad categories of DeFi arrangements: those with identifiable controllers or sufficient influence; those where controllers or sufficient influence cannot be readily identified; and those that are truly decentralised. This distinction is important in determining whether and how the FATF Standards may apply, while recognising that arrangements falling outside direct regulatory application may still present risks requiring alternative, risk-based mitigation measures.
The publication is particularly informative in its description of DeFi-related risks and typologies. The FATF refers to the misuse of DeFi through techniques such as chain-hopping, cross-chain bridges, ransomware-related activity, fraud, and the use of decentralised or insufficiently controlled environments to launder proceeds or obscure the movement of funds.
Subject persons are encouraged to review the report and assess its implications for their own risk assessments, policies, procedures, controls and monitoring frameworks. The publication serves as a reminder that DeFi-related risks should not be assessed solely by reference to how an arrangement describes itself, but by considering its actual governance, control features, functionality, accessibility and potential exposure to ML/TF risks.
For further information, subject persons and other interested parties may access the publication through the FATF’s website or via the FIAU’s website under the “FATF” section.

from Decentralised Finance (DeFi)
