Crypto Law Profile

IOSCO Policy Recommendations for Decentralized Finance (2023)

IOSCO’s 2023 DeFi recommendations set nine global policy expectations for securities regulators covering regulatory perimeter analysis, responsible persons, risk controls, disclosures, enforcement, and cross-border cooperation.

International In force Global standard

At a glance

Jurisdiction International standard for IOSCO member securities regulators.
Status Final report published Dec. 19, 2023; not a statute.
Scope Nine recommendations for DeFi products, services, activities, and arrangements.
Implementation IOSCO shifted to monitoring, capacity building, and technical assistance.

Overview

The IOSCO Policy Recommendations for Decentralized Finance (DeFi) are a final 2023 global standard for securities regulators, published by the Board of the International Organization of Securities Commissions on Dec. 19, 2023. The recommendations are not a statute or directly enforceable market-participant rule. They are directed to relevant authorities and are intended to support member jurisdictions as they apply existing frameworks or develop new approaches for DeFi products, services, activities, and arrangements.

What the IOSCO DeFi recommendations cover

The final report sets out nine recommendations designed to address market integrity and investor protection concerns arising from DeFi. IOSCO frames the report around the principle of “same activity, same risk, same regulation/regulatory outcome,” emphasizing that regulatory analysis should look at the function and economic substance of an arrangement rather than only its technology, label, or degree of claimed decentralization.

The recommendations apply to arrangements that self-identify as decentralized or are identified by a regulator as decentralized. IOSCO notes that DeFi can involve financial products and services comparable to those in traditional markets, even when delivered through distributed ledger technology, smart contracts, decentralized interfaces, or governance structures.

Key policy expectations for regulators

  • Analyze DeFi arrangements: assess the products, services, activities, and technical features within a jurisdiction to determine the appropriate regulatory response.
  • Identify responsible persons: locate persons or entities with control or sufficient influence over a DeFi arrangement that may be subject to regulatory frameworks.
  • Target common regulatory outcomes: pursue investor protection and market integrity outcomes comparable to traditional financial markets.
  • Address conflicts and risks: consider conflicts of interest, operational risk, smart-contract risk, oracle risk, bridge risk, governance risk, and other material risks.
  • Require clear disclosures: seek disclosures that are accurate, comprehensive, non-technical where appropriate, and not misleading.
  • Strengthen enforcement and cooperation: use supervisory powers, enforcement tools, information sharing, and cross-border mechanisms for DeFi activity.

IOSCO also asks regulators to understand interconnections among DeFi, the broader crypto-asset market, stablecoins, centralized platforms, and traditional financial markets. That focus is intended to help authorities identify spillover risks, regulatory touchpoints, and areas where existing oversight tools may need technical adaptation.

Responsible persons and regulatory perimeter

Recommendation 2 is especially important for DeFi because it asks authorities to identify “Responsible Persons” with control or sufficient influence over a DeFi product, service, or activity. IOSCO indicates that such persons may include actors involved in governance, administrative keys, user interfaces, promotions, custody or effective control of assets, or fee extraction, depending on the facts and jurisdiction.

Relationship to crypto-asset market standards

The DeFi recommendations should be read with IOSCO’s companion Crypto and Digital Asset Markets recommendations and the Umbrella Note. The Umbrella Note explains that the CDA recommendations are aimed at centralized crypto-asset service providers, while the DeFi recommendations focus on arrangements that self-identify, or are identified by a regulator, as decentralized. IOSCO states that where a DeFi arrangement, or a part of it, is conducted by a crypto-asset service provider, the CDA recommendations may also apply.

Status and implementation

As of July 21, 2026, the DeFi recommendations remain a finalized IOSCO global standard rather than a standalone legal regime. Implementation depends on how securities, commodities, banking, AML/CFT, consumer-protection, cybersecurity, and other authorities in individual jurisdictions map DeFi arrangements into existing or new frameworks.

IOSCO’s 2025 thematic review of crypto and digital asset implementation confirms that the IOSCO Board agreed in December 2023 to monitor and promote timely implementation of both its CDA and DeFi recommendations. The initial public review focused on selected CDA recommendations, but the roadmap is relevant context for this DeFi profile because it signals ongoing capacity building, implementation monitoring, and consistency work across IOSCO member jurisdictions.

Key provisions

Assess DeFi arrangements

Regulators should analyze DeFi products, services, activities, and technical features within their jurisdiction to determine the appropriate regulatory response.

Regulatory perimeter Source

Identify Responsible Persons

Authorities should identify persons or entities with control or sufficient influence over a DeFi arrangement that could be subject to regulatory frameworks.

Responsible Persons Source

Common regulatory outcomes

Regulatory approaches should be functionally based and target investor protection and market integrity outcomes comparable to traditional finance.

Common outcomes Source

Conflicts and material risks

Responsible Persons should identify and manage conflicts and material risks, including operational, technology, oracle, bridge, and smart-contract risks.

Conflicts & risks Source

Disclosures and marketing

Regulators should seek clear, accurate, comprehensive disclosures and fair, non-misleading marketing for users and investors.

Disclosure Source

Enforcement and cooperation

The recommendations call for supervisory and enforcement powers, information sharing, and cooperation across jurisdictions for DeFi activity.

Enforcement Source

Interconnections monitoring

Regulators should assess links among DeFi, broader crypto markets, stablecoins, centralized platforms, and traditional financial markets.

Interconnections Source

Timeline

  1. Consultation report published

    IOSCO opened consultation on proposed DeFi policy recommendations.

    Under consultation Source
  2. Comment period closed

    IOSCO's consultation deadline for public responses closed.

    Under consultation Source
  3. Final report published

    IOSCO finalized nine DeFi policy recommendations.

    Enacted Source
  4. Implementation monitoring announced

    IOSCO said it would shift to implementation monitoring, capacity building, and technical assistance.

    Enacted Source
  5. Implementation review published

    IOSCO's thematic review referenced the roadmap to monitor CDA and DeFi recommendations.

    Enacted Source

Who it affects

Actors

Fintech Task Force, IOSCO, IOSCO Board, Securities regulators

Asset classes

Crypto assets, Stablecoins

Official sources

Editorial note

Non-binding IOSCO global standard. Profile as a policy framework for securities regulators, not as a directly enforceable statute or market-participant rule. Domestic legal effect depends on implementation by individual jurisdictions.