CARF Compliance Software
From Day-1 Wallet-Holder Self-Certification to Transaction Reporting Zero Remediation
Welcomed by the G20. 75+ jurisdictions committed. 740M+ crypto owners (end of 2025, Crypto.com). CARF-specific self-certification at onboarding. Real-time TIN validation. Transaction classification across 3 reportable transaction types. Automated curing. CARF XML reporting. One OS.

Whatever You Operate The OS Is Configured for It
One OS for CARF compliance for crypto exchanges and for financial institutions offering crypto services.
Centralized Exchanges
Mandatory TIN collection and validation at onboarding. Transaction-level reporting across all three transaction types. The OS handles exchange-scale volume from Day 1.
Custodial Wallet Providers
Same CARF obligations as exchanges. Self-certification collection, TIN validation, and transfer-to-unhosted-wallet reporting — automated inside the onboarding flow.
Staking & Yield Platforms
Staking rewards and similar receipts are reported as transfers. The OS classifies each reward event, collects user self-certifications, and reports per jurisdiction.
DeFi & NFT Platforms
DeFi platforms with identifiable users and NFT platforms where NFTs constitute financial instruments fall under CARF. Centralized front-ends trigger the same reporting obligations as exchanges.
Three Changes. Three Failure Points One Connects Them All
Transaction Classification
Failure Point 1Three reportable transaction types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. Each one is classified per user, per asset, per jurisdiction. Exchange-scale volume.
Due Diligence Problem
Failure Point 2KYC verifies identity. CARF demands tax due diligence — per user, per jurisdiction. Most platforms collect first, review later. That gap becomes a remediation backlog growing with every user registered.
Due Diligence
75+ Jurisdiction Reporting
Failure Point 3First exchanges in 2027, 2028 and 2029. Varying local rules. Aggregate and transaction-by-transaction modes. Different deadlines by jurisdiction. Disconnected tools = incomplete filings.
The OS for Global Tax Identity & Transparency Two Layers
Real-time identity validation and automated compliance intelligence, from the moment a crypto user registers to the moment CARF XML is filed across 75+ jurisdictions.
Global Tax Identity Infrastructure
Crypto users don't carry corporate structures or financial intermediaries — their TIN is the only reliable identifier. The TaxDo identity layer validates it in real time against official issuing-country sources at the moment of onboarding.
CARF Compliance Intelligence
Automated due diligence across every user and transaction — detecting discrepancies, classifying transactions, resolving exceptions, and producing clearance records.
- Automated indicia detection across user identity and transaction data
- Transaction classification across all 3 CARF reportable transaction types
- In-session auto-cure — 95%+ resolved before onboarding completes
- Immutable clearance record per user — automated, audit-ready
- Enforcement compliance — full 2-reminder workflow of at least 60 days where applicable
- Aggregate and transaction-by-transaction reporting from one data layer
- 95%+ of CARF exceptions auto-cured before onboarding completes
From Self-Certification to CARF Reporting. One OS
Today, enterprises juggle four or more vendors for tax identity, AML screening, regulatory compliance, and indirect tax — separate contracts, separate data, separate problems. TaxDo replaces them all with one connected operating system.
Forensic Due Diligence — At Registration
During self-certification, the Forensic Engine detects indicia, validates against sources, auto-cures discrepancies in real time. KYC checks identity. Engine resolves tax residency. 95%+ users cleared before registration.
Transaction Classification Engine
Automated classification of every reportable transaction into the three CARF types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers. Transfers of crypto-assets include reportable retail payments above USD 50,000, and staking rewards and similar receipts, reported by type where known. One engine, three types.
Real-Time TIN Validation
Every TIN validated against official government sources in 130+ countries at onboarding. Syntax validation for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the session ends.
CARF XML Reporting
75+ jurisdictions. Aggregate and transaction-by-transaction modes. CARF XML v1.0 generation, validation, and submission-ready output. Local variations handled per jurisdiction in a single pass.
Digital Self-Certification
Guided, jurisdiction-aware collection designed for crypto-native users. Full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons. One flow covers CARF and DAC8.
Crypto Asset Classification
Classify every reportable asset: crypto-asset, stablecoin, e-money token, or NFT (where classified as a financial instrument). Classification determines reporting category and jurisdiction-specific treatment.
Enforcement Compliance
Two-reminder workflow of at least 60 days tracked and logged automatically. Within the EU (via DAC8), account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported.
Portfolio Remediation
Scan, prioritise, and auto-remediate your existing user base. Missing self-certifications, invalid TINs, unresolved discrepancies. New users and legacy cleanup from one platform.
End-to-End CARF Lifecycle
Reduction in Crypto Due Diligence Cost
Forensic due diligence runs inside self-certification — not after it. The 95% is not a target. It is a measured result.
Tax Residency Resolved — Not Just KYC
KYC checks identity. The Forensic Engine resolves tax residency via indicia detection and auto-curing.
75+ Jurisdictions. Three Start Dates.
Reporting for the 2027, 2028 and 2029 groups handled from one data layer. One engine, every jurisdiction.
Auto-Cured at Registration
Discrepancies resolved before the user finishes onboarding. No manual queues. No back-office backlog.
Clearance Record per User
Immutable audit trail. Every validation, resolution, and classification — timestamped and retained.
The remediation teams, the spreadsheets, the user re-contact campaigns — gone.
Not an additional cost. A replacement for the one you already carry.
Every Obligation. Automated
You know what CARF requires. Here is how the OS handles each obligation across 75+ jurisdictions.
User Self-Certification
Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.
TIN Validation
Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.
Crypto-to-Fiat Reporting
Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.
Crypto-to-Crypto Reporting
Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.
Unhosted Wallet Transfers
Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.
Staking & Rewards Reporting
Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.
User Self-Certification
Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.
TIN Validation
Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.
Crypto-to-Fiat Reporting
Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.
Crypto-to-Crypto Reporting
Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.
Unhosted Wallet Transfers
Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.
Staking & Rewards Reporting
Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.
User Self-Certification
Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.
TIN Validation
Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.
Crypto-to-Fiat Reporting
Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.
Crypto-to-Crypto Reporting
Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.
Unhosted Wallet Transfers
Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.
Staking & Rewards Reporting
Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.
User Self-Certification
Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.
TIN Validation
Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.
Crypto-to-Fiat Reporting
Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.
Crypto-to-Crypto Reporting
Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.
Unhosted Wallet Transfers
Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.
Staking & Rewards Reporting
Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.
Retail Payment Reporting
Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.
Crypto Asset Classification
Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.
Indicia Detection & Curing
Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.
CARF XML v1.0 Generation
OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.
Enforcement Compliance
Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.
Annual Re-Verification
Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.
Retail Payment Reporting
Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.
Crypto Asset Classification
Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.
Indicia Detection & Curing
Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.
CARF XML v1.0 Generation
OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.
Enforcement Compliance
Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.
Annual Re-Verification
Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.
Retail Payment Reporting
Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.
Crypto Asset Classification
Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.
Indicia Detection & Curing
Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.
CARF XML v1.0 Generation
OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.
Enforcement Compliance
Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.
Annual Re-Verification
Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.
Retail Payment Reporting
Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.
Crypto Asset Classification
Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.
Indicia Detection & Curing
Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.
CARF XML v1.0 Generation
OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.
Enforcement Compliance
Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.
Annual Re-Verification
Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.
75+ Jurisdictions. Per-User Liability Cumulative Exposure
Jurisdiction-Specific Penalties
Each jurisdiction sets its own penalty regime. Non-compliant CASPs face fines per unreported user, per missing TIN, and per incomplete filing, compounding across every jurisdiction where they operate.
Enforcement Disrupts Trading
Within the EU (via DAC8), a crypto-asset user who has not self-certified after two reminders and at least 60 days is blocked from reportable transactions. Outside the EU, jurisdictions determine enforcement.
KYC Does Not Equal CARF
KYC verifies identity. CARF requires self-certification, TIN validation per jurisdiction, transaction-level reporting, and a documented cure workflow. Most exchanges have KYC — not CARF infrastructure.
User Attrition at Scale
Crypto users have near-zero switching costs. A blocked account or poorly executed self-certification flow sends users to a competitor permanently. Compliance failures are retention failures.
Cross-Border Scrutiny
Operating across 75+ jurisdictions means non-compliance in one triggers attention in others. Cross-border information exchange means regulators see the full picture, and act on it.
Public Enforcement Actions
The crypto industry is under heightened regulatory scrutiny. Enforcement actions are public, amplified, and permanent. Institutional partners and banking relationships are at stake.
The Global Scale of Crypto Compliance
Sources: OECD (jurisdictions, 14 Sep 2026; CARF-MCAA signatories, 3 Mar 2026), Crypto.com Market Sizing Report 2025, CoinGecko 2026 Q2 Crypto Industry Report.
75+ Jurisdictions Committed to CARF
Major economies have committed to implementing CARF, the first global standard for crypto-asset regulatory compliance. Tax authorities start exchanging data in 2027, 2028 or 2029, depending on the group. In the UK, HMRC's Cryptoasset Reporting Framework rules apply from 1 January 2026, and the first reports, covering 2026, are due between 1 January and 31 May 2027.
First Exchanges By 2027 (46 Jurisdictions)
First Exchanges By 2028 (27 Jurisdictions)
First Exchanges By 2029 (4 Jurisdictions)
Source: OECD Global Forum, jurisdictions committed to implement the Crypto-Asset Reporting Framework (last updated 14 September 2026). El Salvador, Georgia, India and Viet Nam have not yet committed. Subject to national legislative implementation.
Questions from Compliance Teams
We will respond to you at any time. Just use our help center or contact us.
CARF is the OECD Crypto-Asset Reporting Framework — a global standard for tax transparency in digital assets. Welcomed by G20 leaders at the Bali summit in November 2022 and finalized in 2023. It requires Reporting Crypto-Asset Service Providers (RCASPs) to collect self-certifications, validate TINs, classify transactions, and report to tax authorities. 75+ jurisdictions have committed to implementation, with data collection beginning 1 January 2026 in the EU and UK.
Reporting Crypto-Asset Service Providers (RCASPs): centralized exchanges, custodial wallet providers, crypto brokers and dealers, crypto payment processors, staking, lending, and yield providers, DeFi platforms where the operator can identify users, and NFT platforms where NFTs are classified as financial instruments. If you facilitate crypto transactions and can identify your users, CARF likely applies.
A Reporting Crypto-Asset Service Provider must do the following under CARF. 1) Identify users: obtain a self-certification from every individual and entity user when the relationship starts (existing users within the transition period), and for entities identify the controlling persons. 2) Check it: confirm the self-certification is reasonable against other information held, including AML/KYC documents, and obtain a new one if circumstances change. 3) Collect the data: name, address, tax residence, date of birth for individuals, and the TIN for each reportable jurisdiction, unless that jurisdiction issues no TIN or does not require it to be collected. 4) Track relevant transactions: exchanges against fiat currency or other crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. 5) Report once a year to the tax authority where you have your reporting nexus, aggregated by type of crypto-asset, with amounts in fiat currency. 6) Keep documentation and data for at least five years after the reporting deadline.
CARF is the OECD's global standard, and 75+ jurisdictions have committed to implement it. DAC8 (Council Directive (EU) 2023/2226) is the EU's implementation of both CRS 2.0 and CARF into European law, covering 27 EU member states. Outside the EU, each jurisdiction brings CARF into its own law, as the UK did with its Cryptoasset Reporting Framework regulations. The due diligence requirements are aligned, but reporting schemas and local enforcement vary.
CARF is an OECD standard, so there is no fixed member list. A jurisdiction takes part by committing to implement it, and the OECD Global Forum on Transparency and Exchange of Information for Tax Purposes publishes the list of jurisdictions that have committed, grouped by the year they will start exchanging information. EU member states implement CARF through DAC8 (Directive (EU) 2023/2226), which applies from 1 January 2026, and the United Kingdom through its own regulations in force from the same date. The list changes as jurisdictions commit, so check the OECD page for the current position.
Three reportable transaction types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. Staking rewards and similar receipts are reported as transfers, by type, where known. Each transaction must be classified by type, asset, and user, then reported per jurisdiction in either aggregate or transaction-by-transaction format.
Data collection began 1 January 2026 in the EU and UK. On the OECD list of 14 September 2026, 46 jurisdictions are due to start exchanging information by 2027, 27 by 2028 and 4 by 2029. The 2027 group includes the UK, Norway, Iceland, Liechtenstein, Brazil, Japan, New Zealand and South Africa, and every EU member state except Cyprus, which the OECD lists for 2028. The 2028 group includes Australia, Canada, Hong Kong, Israel, Singapore, Switzerland and the UAE. Platforms report to their own tax authority first: in the UK the first reports, covering 2026, are due between 1 January and 31 May 2027. CASPs must be operationally ready from Day 1 of data collection.
CARF itself (the OECD standard) does not mandate account blocking — that is a DAC8/EU-specific enforcement mechanism. Within the EU (via DAC8), if a user fails to provide a valid self-certification after two formal reminders, and at least 60 days after the first request, the crypto-asset service provider must block them from reportable transactions. Outside the EU, enforcement actions are determined by each jurisdiction's national implementation of CARF.
No. KYC verifies user identity for anti-money-laundering purposes. CARF requires CARF-specific self-certification (including all tax residency jurisdictions and TINs), mandatory TIN validation against the issuing jurisdiction, transaction-level reporting, and a documented cure workflow. KYC is a prerequisite — not a substitute.
Per OECD guidance, DeFi platforms where the operator can identify users (centralized front-end) and NFT platforms where NFTs are used as financial instruments are in scope. Platforms with centralized front-ends, login requirements, or user accounts trigger the same reporting obligations as exchanges. The scope is designed to capture any intermediary that facilitates reportable crypto transactions with identifiable users.
Yes. Wallet-holder self-certification, real-time TIN validation across 75+ jurisdictions, transaction classification across the 3 reportable transaction types, automated curing, enforcement compliance, and CARF XML reporting, all from one OS with shared identity infrastructure. Deployed in weeks.
CARF Is One Engine Inside the OS. Everything Else Connects.
Global Tax Identity
The identity foundation that powers every framework. TIN validation, business registry verification, and entity intelligence across 210+ countries. Layer 1 of the OS.
Regulatory Compliance Intelligence & Reporting
CRS 2.0, CARF, DAC8, DAC7, FATCA — same OS, same identity layer, regime-specific output.
Global Indirect Tax
VAT/GST determination, US Sales Tax, and cross-border indirect tax compliance — connected to the same entity and identity data that drives transparency reporting.
Ready to Replace Separate Tools with One OS?
From self-certification to CARF XML reporting: every CARF obligation automated through real-time TIN validation, transaction classification, automated curing, and enforcement compliance across 75+ jurisdictions. Deployed in weeks.
