a16z Crypto: A New Approach to On-Chain Financial Institutions

CN
链捕手
Follow
1 hour ago

Author: Rebecca, COO and Chief Legal Officer of Jito Labs

Compiled by: Jiahua, ChainCatcher

Many financial institutions are leveraging one of the most innovative advancements in blockchain technology: permissionless networks.

Franklin Templeton began utilizing permissionless blockchain to record the share information of its on-chain U.S. government money fund as early as 2021, and included Solana into its supportive network in February 2025. BlackRock will issue tokenized money market fund shares on Ethereum starting March 2024. In January 2025, Apollo also began offering tokenized investment channels for its Diversified Credit Fund on six permissionless networks.

Announcements from traditional financial institutions deploying products on permissionless networks appear almost every week.

However, some traditional financial institutions still believe that permissionless networks are " inaccessible." Conversely, many banks, broker-dealers, and asset management firms are gradually shifting towards permissioned networks. In these systems, gatekeepers or consortia decide who can validate transactions, who can use or participate in the network, and what purposes the network can be used for.

These institutions choose permissioned networks because they mistakenly believe this is a prerequisite for compliance requirements. The logic behind this is that only a set of clearly defined and verified participants can meet the requirements of financial compliance laws, including anti-money laundering (AML) and counter-terrorist financing (CFT) regulations under the Bank Secrecy Act (BSA), as well as U.S. sanctions laws.

To be blunt, institutional compliance departments believe that permissionless networks are incompatible with the Bank Secrecy Act and sanctions laws.

Our newly released paper titled “Compatibility of Permissionless Networks with Financial Compliance: A Practical Guide for Financial Institutions” points out that financial institutions can indeed build products and conduct transactions on permissionless blockchain networks. Concerns about financial compliance laws should not hinder institutions from using these networks, as current laws are already capable of addressing related issues.

Financial institutions can fulfill their obligations through appropriate, risk-based compliance frameworks and implement control measures at points where they can practically control.

From both regulatory and other perspectives, financial institutions are not obliged to own the underlying infrastructure, nor do they need to screen, review, or restrict the infrastructure that supports their financial transactions and related communications. In fact, regulators have clearly acknowledged that financial institutions can adjust their financial compliance systems based on the technological innovation of "permissionlessness."

Are Permissionless Networks Really Incompatible with Financial Compliance Requirements?

The Bank Secrecy Act and sanctions laws require financial institutions to implement reasonable controls on risks and take measures to mitigate these risks, but do not require the complete elimination of risk. The latter is an impossible standard to meet.

According to the Bank Secrecy Act, financial institutions' anti-money laundering and counter-terrorist financing programs should focus on identifying, recording, and curtailing illegal financial activities. These programs are neither intended to completely stop money laundering or terrorist financing, nor could they achieve this.

The U.S. federal banking regulators and the Financial Crimes Enforcement Network (FinCEN) have made it clear that the key to financial compliance is the establishment of a "reasonably designed" anti-money laundering program, which should include "effective processes for identifying, measuring, monitoring, and controlling risks."

FinCEN further clarified in itsEnforcement Statement issued in August 2020 that regulators do not enforce the Bank Secrecy Act merely to catch institutions on some isolated errors.

The U.S. Treasury's report on “de-risking” also directly addressed the concerns of financial institutions. Banks often believe that any internal control problems may expose them to significant fines. However, regulators pointed out that relevant fines are uncommon and usually occur in the context of an overall failure of the anti-money laundering and counter-terrorist financing systems, rather than due to occasional localized inadequacies in a risk-based approach.

The sanctions compliance regime follows similar logic.

The U.S. Treasury's Office of Foreign Assets Control (OFAC) has outlined five core components of effective sanctions compliance programs in theCompliance Commitment Framework: management commitment, risk assessment, internal controls, testing and auditing, training.

OFAC adjusts the specific execution requirements for compliance measures based on the size of the institution, type of products, customer demographics, and geographic business locations.

“Economic Sanctions Enforcement Guidelines” will also take into account whether there is intentional behavior, whether the institution is aware of relevant activities, the harm caused to sanctioned targets by the activities, and whether the compliance programs are adequate when handling suspected violations.

The enforcement regimes and historical practices of regulatory bodies support a "risk-balanced, not zero-tolerance" approach. The enforcement focus of FinCEN and OFAC is on systemic flaws that institutions can reasonably identify, rather than incidental individual errors.

This enforcement orientation is directly related to financial institutions' concerns about permissionless networks.

Whether in anti-money laundering, counter-terrorist financing, or sanctions regimes, the requirements are for control measures that match the identified risks, and such controls can be fully realized on permissionless networks. Violations caused by indirect paths or unintentional actions should not automatically constitute grounds for financial institutions to bear corresponding compliance risks.

Do Financial Institutions Need to Identify and Screen Every Validator?

Financial institutions should regard permissionless networks as a kind of infrastructure, just as they do with public internet and telephone networks.

Public internet and telephone networks are shared systems, and financial institutions neither know nor screen other users and operators within them. For permissionless networks, financial institutions should adopt a compliance approach that matches this.

Currently, financial institutions are cautious about permissionless networks mainly due to the concern of unintentionally interacting with sanctioned entities or those engaged in illegal activities without their knowledge or active selection.

For instance, financial institutions may worry about paying network fees to validators that operate sanctioned entities, unknowingly transacting with sanctioned entities, or receiving and trading cryptocurrencies that have previously interacted with illegal entities.

However, unintentionally interacting with validators or other network participants located in sanctioned jurisdictions is not the behavior that sanctions laws aim to regulate.

This issue is not solely about geographical location. A validator may be a sanctioned entity operating anywhere, but financial institutions have not actively chosen that validator, have not entered into contracts with it, have not exported goods or services to it, nor have they engaged in transactions with it in any other way.

The network fees ultimately reaching a validator occur because the network protocol applies the same rules to all users.

Regulators have confirmed this.

For instance, in November 2025, the Office of the Comptroller of the Currency (OCC) issued “Interpretive Letter 1186,” confirming that banks may pay network fees on blockchain networks and may hold in their own name the cryptocurrencies needed to pay those fees.

This interpretive letter followed the OCC's “Interpretive Letter 1174” issued in January 2021. The latter found that banks could run nodes to validate, store, and record payment transactions. Since banks can run nodes and participate in transaction records, it is a natural extension of this conclusion that they can charge network fees earned through nodes.

The interpretive letter uses Ethereum as an example. Ethereum is a permissionless network whose protocol selects validators in a pseudo-random manner. This series of interpretive letters made no distinction between permissioned and permissionless networks.

When financial institutions initiate a transaction over a permissionless network, the protocol assigns the block proposal rights containing that transaction to a single validator. Typically, this process occurs in a pseudo-random manner and is proportional to the amount staked by the validator.

The network protocol determines the corresponding fees based on network demand and the computational resources consumed by the transaction. Therefore, financial institutions cannot choose the validators processing their transactions, cannot negotiate fees with validators, and cannot know which specific validator processed the transaction before or after it occurs.

All users on the network must adhere to the same rules.

This relationship is somewhat akin to the relationship between email senders and router operators that carry the mail, as well as the relationship between telephone callers and switch operators responsible for completing the call connections.

If an internet protocol data packet sent by a U.S. financial institution passes through infrastructure located in a sanctioned jurisdiction, it would not be deemed a violation of sanctions solely for that reason. The same "neutral, protocol-automated transmission" analysis can apply to the consensus layer of permissionless networks.

The Bank Secrecy Act itself also recognizes this distinction. The Act expressly excludes from its regulatory definition those entities that “only provide delivery, communication, or network access services used to facilitate the transfer of funds” to support funds transfer services.

The Bank Secrecy Act distinguishes neutral transmission from transactional behavior, and sanctions analysis similarly focuses on whether there is active selection, instruction, or transactional behavior in the relationships between parties.

While it is true that financial institutions may have some contact with un-screened network operators when transacting on permissionless networks, such contact differs from the behaviors regulated by sanctions laws.

In the latter case, neither party involved has actively chosen the other.

On a broader note, nearly five years have passed since OFAC released its “Sanctions Compliance Guidance for the Virtual Currency Industry.” During this time, there have been no enforcement actions based on the presence of transactions involving sanctioned entities in blocks proposed by validators, nor have there been any enforcement actions due to market participants paying network fees at the protocol layer.

Can Public Ledgers Balance Privacy and Compliance?

The second concern raised by institutions is about privacy: Can banks conduct transactions on public ledgers without exposing customer positions, trading partners, and trading strategies to competitors?

The main argument for early support of permissionless ledgers was that comprehensive transparency could in itself become a compliance asset.

However, the actual demands of financial compliance are narrower: necessary information should be verifiable by financial institutions, trading partners, and regulators or supervisory bodies.

Today, cryptographic technology has progressed sufficiently to allow institutions to prove compliance-related facts without disclosing all the data underlying that proof.

For example, institutions can demonstrate that a trading partner is not on the Specially Designated Nationals (SDN) list and can prove reserves exceed liabilities without disclosing ledger content and trading partner identities.

Source verification allows one party to prove that an asset originates from a recognized set of illegal assets without needing to disclose the complete picture of trading relationships.

Confidential transfer schemes can encrypt the amounts and balances on the ledger while retaining a viewing key to provide to auditors during review.

These cryptographic technologies can provide regulators with stronger verification assurances than closed systems, without disclosing any information to competitors.

Thus, privacy no longer poses a barrier to using permissionless networks; instead, it may become a reason for financial institutions to choose such networks.

Some of these technologies are already in use, while others are still under development.

Address rotation and account abstraction have already been practically applied. Aggregate accounts and hierarchical custodial structures can also maintain customer-level detailed information outside the ledger. Meanwhile, relevant message protocols can transmit “travel rule” data during on-chain transfers.

Confidential transfer schemes with audit keys have started to be deployed, but their current application in institutional business remains limited.

Proposals for proving non-sanctioned status as well as asset source verification for specific lists are still in pilot and research stages.

However, relevant solutions indeed exist. For instance, Privacy Cash is a privacy protocol deployed on Ethereum and Solana that uses zero-knowledge proofs to support confidential transfers and exchanges.

How to Establish a Compliance Framework?

We propose a financial compliance framework applicable to activities on permissionless networks, consisting of nine components.

Among them, transaction-level control measures primarily target the institution’s customers and trading partners, with forms similar to the controls currently used by financial institutions; network-level control measures focus on the underlying infrastructure itself.

These measures do not require financial institutions to identify validators, nor to enter into service level agreements with any protocol, let alone apply for network membership from any gatekeeper. These are typical characteristics of permissioned networks, but existing financial compliance laws do not impose these requirements.

a16z Crypto: New Ideas for Financial Institutions on the Blockchain

This framework is also consistent with the recently passed “GENIUS Act” in the U.S.

The “GENIUS Act” adopts a similar framework: anti-money laundering, counter-terrorist financing, and sanctions control measures should be placed at the application layer, to be enforced by entities that understand customer identities and can control assets.

This Act requires issuers permitted to issue payment stablecoins to demonstrate that they have established anti-money laundering and sanctions compliance programs, and possess the technical capacity to freeze or destroy circulating stablecoins under lawful orders as identifiable regulated entities in the application layer.

These obligations fall on stablecoin issuers, not on the permissionless networks where stablecoins circulate.

Decades ago, regulated financial institutions faced an open, global permissionless network. Anyone could join this network, which carried the communication traffic of both legitimate and illegitimate users.

Financial institutions ultimately built their operations on the open protocols of the internet and established corresponding control measures at the application layer.

Today, permissionless networks can adopt a similar approach.

Avoiding permissionless networks is not a financial compliance strategy; it relinquishes the role that U.S. financial institutions have long played in enhancing the resilience, information transparency, and risk management capabilities of the U.S. dollar financial system.

In fact, activities priced in dollars are already occurring on permissionless networks, and will continue to develop regardless of whether U.S. financial institutions participate.

Whether U.S. financial enforcement can effectively cover these activities depends on regulators' ability to see financial flows. Additionally, the institutional design, execution, and enforcement behind financial compliance law also rely on U.S. financial institutions proactively observing and monitoring these activities.

If financial institutions choose to avoid permissionless networks due to a misreading of relevant laws or concerns about past regulatory stances, what they will ultimately lose is the opportunity to provide more products and services to customers using open networks.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink