FIAU warns about growing financial crime risks in Crypto and DeFi

FIAU Draws Attengtion to FATF Reports

The Financial Intelligence Analysis Unit has drawn attention to two international reports examining the growing financial-crime risks associated with crypto-assets and decentralised finance.

Published by the Financial Action Task Force, the reports assess how jurisdictions and regulated entities are responding to money-laundering, terrorist-financing and proliferation-financing risks arising from rapidly developing technologies.

Regulatory Gaps

The first report reviews the implementation of FATF standards governing virtual assets and virtual-asset service providers. Although several jurisdictions have strengthened licensing, supervision and enforcement, important weaknesses remain. These include incomplete risk assessments, inconsistent application of the Travel Rule and difficulties supervising businesses operating across national borders.

FATF also identifies risks linked to stablecoins, unhosted wallets, peer-to-peer transactions, offshore service providers and cross-chain activity. These risks can affect not only crypto-asset service providers but also traditional financial institutions whose customers or transactions have direct or indirect exposure to digital assets.

Decentralised Finance Under Scrutiny

The second report examines decentralised finance. It notes that some arrangements described as decentralised may still involve individuals or entities exercising substantial control or influence. This distinction is important when determining whether existing regulatory requirements apply.

DeFi platforms may also facilitate rapid cross-border transfers, pseudonymous participation and movement between different blockchain networks. FATF highlights techniques such as chain-hopping, cross-chain bridges and the use of decentralised protocols to obscure criminal funds.

Implications for Subject Persons

The FIAU has encouraged subject persons to consider these findings when reviewing their risk assessments, transaction-monitoring systems, policies and internal controls. Firms should evaluate how crypto-related exposure may arise through their customers, products and business relationships, even when they do not provide crypto services directly.