TaxDo
Engine 3 — Regulatory Compliance Intelligence & Reporting

CRS, CARF, DAC7, DAC8 & FATCA Reporting Regulatory Compliance

From Day-1 Self-Certification to Regulatory XML Filing

Zero Remediation

Forensic due diligence, automated self-certification, multi-category indicia detection, intelligent curing, reasonableness testing, and regulatory reporting — across CRS 2.0, DAC8, CARF, DAC7, and FATCA. Account holders never fill forms. Compliance officers never chase documents.

TaxDo regulatory compliance dashboard
Built for Regulated Financial Institutions

Your Institution Type Your Framework Obligations.

Tier-1 Banks

Face all five frameworks simultaneously. CRS 2.0 expanded scope covers previously excluded products. DAC8 adds crypto exposure. FATCA applies to any US-connected account. TaxDo runs one due diligence process and produces five framework outputs.

CRS 2.0DAC8CARFFATCA

Crypto Exchanges & CASPs

New entrants to the Regulatory Compliance regime. DAC8 and CARF impose first-time self-certification and TIN validation, and DAC8 adds blocking of users who do not self-certify. Most CASPs have no existing compliance infrastructure. TaxDo deploys a complete pipeline from scratch.

DAC8CARFCRS 2.0

Insurers & Investment Entities

Cash-value insurance and investment vehicles carry CRS and FATCA obligations. Entity classification — active vs. passive, financial vs. non-financial — determines reporting scope. TaxDo automates the controlling person cascade that manual processes routinely miss.

CRS 2.0FATCA

Neo-Banks & e-Money

CRS 2.0 brings e-money institutions into scope for the first time. Digital-first onboarding demands digital-first compliance. TaxDo embeds self-certification into the account opening flow — Day-1 readiness is native, not retrofitted.

CRS 2.0DAC8FATCA

Fund Managers & Wealth Platforms

Multi-jurisdictional fund structures with complex entity hierarchies. Controlling person identification cascades through multiple layers. TaxDo traces the cascade to its end, classifies every relevant person, and reports to every applicable jurisdiction.

CRS 2.0FATCACARF

Platforms & Marketplaces

DAC7 requires digital platforms to identify, verify, and report seller income across four activity categories. Payment thresholds, seller classification, and cross-border reporting rules vary by jurisdiction. TaxDo handles the jurisdictional complexity.

DAC7CRS 2.0
Five Frameworks

One Engine. Five Regulatory Outputs

Each framework has its own scope, classification rules, and reporting schema. TaxDo handles the differences so your compliance team does not.

EU From Jan 2026

CRS 2.0

130+ Jurisdictions

The OECD Common Reporting Standard, extended to cover e-money, crypto-assets, and indirect real estate holdings. 130+ jurisdictions, annual automatic exchange.

Learn More
Enforced Jan 2026

DAC8

Blocking Powers Active

EU crypto-asset reporting directive. CASPs must report, verify TINs, and block crypto-asset users who do not self-certify. Penalties are set by each member state.

Learn More
Rolling Out 2026

CARF

75+ Jurisdictions

The OECD Crypto-Asset Reporting Framework. Global standard for reporting crypto transactions — exchanges against fiat or other crypto-assets, and transfers, including reportable retail payments.

Learn More
Enforced 2023

DAC7

EU-27 + EEA

EU platform economy directive. Digital platforms must collect, verify, and report seller income across goods, services, accommodation, and transport.

Learn More
Active

FATCA

113 IGA Jurisdictions

US Foreign Account Tax Compliance Act. FFIs must identify US account holders, validate W-forms, detect US indicia, and file with the IRS via IGA channels (113 IGA jurisdictions, US Treasury list).

Learn More
Why Regulatory Compliance Demands an OS

Two Layers. Five Frameworks One Outcome

Regulatory compliance is not a reporting problem — it is an identity and intelligence problem. The reporting is the output. The identity infrastructure and forensic intelligence are the engine.

Layer 1The Foundation

Global Tax Identity Infrastructure

CRS 2.0 introduced mandatory TIN validation for the first time: not optional, not best-effort. With 130+ jurisdictions committed to CRS exchanges, every TIN must be checked against official issuing-country sources. TaxDo's identity layer does this in real time, at the point of self-certification.

130+Countries Real-Time TIN Lookup
1000+Tax ID Types Syntax Validation
210+Countries Tax ID Coverage
120+Countries Business Registry
Layer 2The Intelligence

Forensic Intelligence Engine

The analytical layer that transforms identity data into due diligence outcomes across all five frameworks simultaneously.

  • Multi-category indicia detection across all framework requirements
  • Automated Reasonableness Test against tiered trust hierarchy
  • Intelligent curing with multiple resolution methods
  • Real-time entity classification and controlling person cascade
  • Cross-framework due diligence — one process, five frameworks
Foundation + Intelligence = Result

95%+

Reduction in Manual Compliance Cost

When tax identity infrastructure and forensic intelligence operate as one system, due diligence resolves itself. Less than 5% of accounts require human intervention across all five frameworks.

Day-1 ReadinessForensic Due DiligenceIntelligent CuringFull Audit TrailRegulatory XML<5% Escalation Rate
Core Capabilities

Six Capabilities One Due Diligence Pipeline

Each capability is a distinct function in the compliance lifecycle — from the moment an account holder is onboarded through regulatory filing.

Intelligent Self-Certification

Account holders answer plain-language questions — not forms. The system classifies entity type, determines applicable frameworks, validates answers in real time, and begins due diligence before the interview ends. Day-1 compliance starts at account opening.

Forensic Due Diligence Engine

Multi-category indicia detection across every framework requirement — TIN signals, address and residency indicators, entity classification markers, controlling person cascades, and behavioural patterns. Goes beyond checkbox compliance to catch what manual review misses.

Native Identity Verification

Because the Global Tax Identity engine is built into the OS, TIN validation, business registry checks, and document verification run as part of due diligence automatically. No third-party integration. No data handoffs. No latency between verification and classification.

Reasonableness & Risk Intelligence

Cross-references self-declared information against multiple independent signals from authoritative, documentary, and institutional sources. Automated risk classification based on a tiered trust hierarchy. Self-certifications that do not pass are flagged, not filed.

Intelligent Curing

Resolves discrepancies through automated methods — auto-correction from authoritative sources, targeted holder prompts, document requests, entity re-classification. 95%+ resolve without human intervention. The remaining <5% are escalated with full context.

Regulatory Reporting & Audit Trail

Schema-compliant XML generation for all five frameworks. Per-jurisdiction formatting, XSD validation, submission tracking, and a complete evidence chain from self-certification through filing. Every reported data point links to its source, classification, and due diligence outcome.

The Compliance Experience

Account Holders Never Fill Forms

The intelligent self-certification interview replaces every tax form with a conversational Q&A. Behind the scenes, the OS validates, classifies, and begins due diligence in real time.

How It Works

  1. 1

    Bank sends link

    branded white-label URL, no app installation, accessible on any device

  2. 2

    One question at a time

    plain-language questions with real-time answer validation and adaptive branching

  3. 3

    Due diligence runs behind the scenes

    TIN validation, entity classification, indicia detection, reasonableness check

  4. 4

    Pre-populated form appears

    the correct regulatory form, pre-filled from Q&A answers, ready for review

  5. 5

    Review + digital signature

    legally binding e-signature, audit trail, and submission confirmation

What Happens Behind the Scenes

TIN Validated

Real-time against official sources in 130+ countries

Entity Classified

Active NFE, Passive NFE, Financial Institution, or individual

Indicia Scanned

Multi-category signals detected across all applicable frameworks

Reasonableness Tested

Self-declared info cross-referenced against independent signals

Frameworks Determined

CRS, DAC8, CARF, DAC7, FATCA — applicable regimes identified

Curing Triggered

Discrepancies auto-resolved or escalated before completion

<8 minAverage Completion
Day-1Compliance Readiness
White-LabelBank-Branded Experience
ResumableSession Persistence
Compliance Dashboard

Your Portfolio. Every Framework. One View

The shared compliance dashboard gives banks and CASPs real-time visibility into certification status, due diligence outcomes, and reporting readiness across all five frameworks.

Portfolio Overview

Real-time certification status across all account holders. Filter by framework, entity type, risk level, or due diligence outcome. Identify gaps before reporting deadlines.

Account Drill-Down

Full audit trail per account holder — self-certification answers, validation results, indicia detected, curing actions taken, and reporting status. Every decision documented.

Batch Operations

Bulk re-certification campaigns, portfolio-wide reasonableness runs, and mass curing triggers. Manage remediation at scale without individual account intervention.

Risk Management

Accounts flagged by indicia, failed reasonableness, or pending curing are surfaced with full context. Officers see risk concentration by framework and jurisdiction.

Reporting Pipeline

Track XML generation, XSD validation, and submission status for each jurisdiction. See which accounts are reporting-ready and which need resolution before filing deadlines.

Regulatory Evidence

Complete evidence chain from initial self-certification through final filing. Auditors see every data point, every validation step, every classification decision and its source.

Role-Based Access Control — each role sees what it needs, nothing more

AdminCompliance OfficerAnalystAuditor
Deployment

Your Infrastructure. Your Terms

Regulatory compliance data includes account holder PII, TINs, and due diligence records. TaxDo deploys where your data sovereignty and regulatory requirements demand.

Cloud

Multi-Tenant SaaS

Fully managed infrastructure with enterprise-grade security, encryption at rest and in transit. Fastest deployment path.

Private

Dedicated Single-Tenant

Isolated infrastructure with dedicated resources. Your data, your tenant, your compliance boundary — managed by TaxDo.

Sovereign

On-Premise Air-Gap

Deploy within your own data centre. Air-gapped, fully isolated, zero external data transmission. For institutions with the strictest regulatory mandates.

Regulatory Compliance FAQ

Questions from Compliance Teams

We will respond to you at any time.
Just use our help center or contact us.

Tax transparency reporting refers to the regulatory obligation for financial institutions to identify, classify, and report account holder tax residency information to tax authorities. It encompasses frameworks including CRS, DAC8, CARF, DAC7, and FATCA — each targeting specific asset classes, institution types, and reporting jurisdictions. The scope has expanded dramatically since 2023, with crypto-assets, e-money, and platform economies now in scope.

TaxDo supports five tax transparency frameworks through one unified engine: CRS 2.0 (OECD Common Reporting Standard), DAC8 (EU crypto-asset reporting), CARF (Crypto-Asset Reporting Framework), DAC7 (EU platform economy reporting), and FATCA (US Foreign Account Tax Compliance Act). One self-certification process, one identity verification layer, one reporting engine — five framework outputs.

The Reasonableness Test cross-references self-declared information against multiple independent signals from authoritative, documentary, and institutional sources. It determines whether an account holder's self-certification can be accepted as reliable, or whether discrepancies require further due diligence and curing. This is the step where surface-level compliance separates from forensic compliance.

Intelligent curing resolves discrepancies between self-declared information and independent signals through multiple automated resolution methods — auto-correction from authoritative sources, targeted account holder prompts, document requests, and entity re-classification. Over 95% of discrepancies resolve without human intervention. The remaining cases are escalated with full context so compliance officers act on information, not guesswork.

Yes — but only if the platform is built as an operating system, not a point solution. Each framework has different classification rules, indicia requirements, and reporting schemas. TaxDo's shared identity infrastructure handles the commonalities (TIN validation, entity classification, self-certification), while framework-specific modules handle the differences (regime-specific indicia, jurisdiction-specific XML, framework-specific blocking and withholding rules).

Day-1 readiness means due diligence begins at the moment of account opening — not retroactively. The intelligent self-certification interview collects, validates, and classifies account holder information in real time during onboarding. Every new account enters the compliance pipeline fully documented from its first day. No remediation campaigns. No retrospective data collection.

Under DAC8, a crypto-asset service provider must stop a crypto-asset user from making reportable transactions if the user has not provided a valid self-certification after two reminders and at least 60 days from the first request. TaxDo tracks certification status against regulatory timelines, triggers escalation workflows before deadlines, and provides the audit trail needed to enforce or document blocking decisions. The platform ensures CASPs can demonstrate to regulators that they took appropriate action.

Forensic due diligence goes beyond checkbox compliance. It applies multi-category indicia detection across TIN signals, address and residency indicators, entity classification markers, controlling person cascades, and behavioural patterns — identifying tax residency obligations that surface-level checks miss. The distinction is critical: checkbox compliance catches what the form asks; forensic due diligence catches what the regulation requires.

Banks, custodians, insurers, crypto exchanges and CASPs, neo-banks, e-money institutions, fund managers, investment entities, and digital platforms and marketplaces. Each faces different framework obligations depending on licence type, asset classes held, and operating jurisdictions. CRS 2.0 expanded scope means previously excluded institution types (e-money issuers, certain investment advisors) are now reporting entities.

TaxDo generates schema-compliant XML for all five frameworks with per-jurisdiction formatting, XSD validation, submission tracking, and a complete evidence chain from self-certification through filing. Each filing links back to the underlying due diligence — the data source, the classification logic, the reasonableness outcome, and any curing actions taken. Auditors can trace any reported data point to its origin.

Your Next Framework Deadline Is Closer Than You Think

CRS 2.0 applies in the EU and DAC8 is enforced. CARF is rolling out. FATCA reporting runs every year. One platform handles all five — from Day-1 self-certification through regulatory XML filing.