TaxDo
OECD Crypto-Asset Reporting Framework: 75+ Jurisdictions, In Force in the EU and UK from 1 January 2026

CARF Compliance Software

From Day-1 Wallet-Holder Self-Certification to Transaction Reporting Zero Remediation

Welcomed by the G20. 75+ jurisdictions committed. 740M+ crypto owners (end of 2025, Crypto.com). CARF-specific self-certification at onboarding. Real-time TIN validation. Transaction classification across 3 reportable transaction types. Automated curing. CARF XML reporting. One OS.

See How It Works
TaxDo CARF compliance dashboard
Built for Your Institution

Whatever You Operate The OS Is Configured for It

One OS for CARF compliance for crypto exchanges and for financial institutions offering crypto services.

Centralized Exchanges

Mandatory TIN collection and validation at onboarding. Transaction-level reporting across all three transaction types. The OS handles exchange-scale volume from Day 1.

TIN ValidationEnforcementTransaction Reporting

Custodial Wallet Providers

Same CARF obligations as exchanges. Self-certification collection, TIN validation, and transfer-to-unhosted-wallet reporting — automated inside the onboarding flow.

Wallet TransfersUnhosted WalletSelf-Certification

Staking & Yield Platforms

Staking rewards and similar receipts are reported as transfers. The OS classifies each reward event, collects user self-certifications, and reports per jurisdiction.

Staking RewardsYield ReportingPer-Jurisdiction

DeFi & NFT Platforms

DeFi platforms with identifiable users and NFT platforms where NFTs constitute financial instruments fall under CARF. Centralized front-ends trigger the same reporting obligations as exchanges.

DeFi ProtocolsNFT PlatformsIdentifiable Users
Why Separate Tools Fail at CARF

Three Changes. Three Failure Points One Connects Them All

Transaction Classification

Failure Point 1

Three reportable transaction types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. Each one is classified per user, per asset, per jurisdiction. Exchange-scale volume.

Unclassified Transactions
→
Filing Gaps

Due Diligence Problem

Failure Point 2

KYC verifies identity. CARF demands tax due diligence — per user, per jurisdiction. Most platforms collect first, review later. That gap becomes a remediation backlog growing with every user registered.

KYC without Tax
Due Diligence
→
Permanent Remediation Cost

75+ Jurisdiction Reporting

Failure Point 3

First exchanges in 2027, 2028 and 2029. Varying local rules. Aggregate and transaction-by-transaction modes. Different deadlines by jurisdiction. Disconnected tools = incomplete filings.

Separate Tools
→
Data Breaks
This is why TaxDo is built as an Operating System

The OS for Global Tax Identity & Transparency Two Layers

Real-time identity validation and automated compliance intelligence, from the moment a crypto user registers to the moment CARF XML is filed across 75+ jurisdictions.

Layer 1The Foundation

Global Tax Identity Infrastructure

Crypto users don't carry corporate structures or financial intermediaries — their TIN is the only reliable identifier. The TaxDo identity layer validates it in real time against official issuing-country sources at the moment of onboarding.

130+Countries Real-Time TIN Lookup
1000+Tax ID Types Syntax Validation
210+Countries Tax ID Coverage
120+Countries Business Registry
Layer 2The Intelligence

CARF Compliance Intelligence

Automated due diligence across every user and transaction — detecting discrepancies, classifying transactions, resolving exceptions, and producing clearance records.

  • Automated indicia detection across user identity and transaction data
  • Transaction classification across all 3 CARF reportable transaction types
  • In-session auto-cure — 95%+ resolved before onboarding completes
  • Immutable clearance record per user — automated, audit-ready
  • Enforcement compliance — full 2-reminder workflow of at least 60 days where applicable
  • Aggregate and transaction-by-transaction reporting from one data layer
  • 95%+ of CARF exceptions auto-cured before onboarding completes
See What the OS Does

From Self-Certification to CARF Reporting. One OS

Today, enterprises juggle four or more vendors for tax identity, AML screening, regulatory compliance, and indirect tax — separate contracts, separate data, separate problems. TaxDo replaces them all with one connected operating system.

Forensic Due Diligence — At Registration

During self-certification, the Forensic Engine detects indicia, validates against sources, auto-cures discrepancies in real time. KYC checks identity. Engine resolves tax residency. 95%+ users cleared before registration.

Transaction Classification Engine

Automated classification of every reportable transaction into the three CARF types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers. Transfers of crypto-assets include reportable retail payments above USD 50,000, and staking rewards and similar receipts, reported by type where known. One engine, three types.

Real-Time TIN Validation

Every TIN validated against official government sources in 130+ countries at onboarding. Syntax validation for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the session ends.

CARF XML Reporting

75+ jurisdictions. Aggregate and transaction-by-transaction modes. CARF XML v1.0 generation, validation, and submission-ready output. Local variations handled per jurisdiction in a single pass.

Digital Self-Certification

Guided, jurisdiction-aware collection designed for crypto-native users. Full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons. One flow covers CARF and DAC8.

Crypto Asset Classification

Classify every reportable asset: crypto-asset, stablecoin, e-money token, or NFT (where classified as a financial instrument). Classification determines reporting category and jurisdiction-specific treatment.

Enforcement Compliance

Two-reminder workflow of at least 60 days tracked and logged automatically. Within the EU (via DAC8), account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported.

Portfolio Remediation

Scan, prioritise, and auto-remediate your existing user base. Missing self-certifications, invalid TINs, unresolved discrepancies. New users and legacy cleanup from one platform.

End-to-End CARF Lifecycle

Self-CertificationDigital collection at registration
2
TIN ValidationValidated via official sources
3
ClassificationTransactions typed & categorized
4
Auto-Cure95%+ resolved in-session
5
ReportingCARF XML filed
The Result
95%+

Reduction in Crypto Due Diligence Cost

Forensic due diligence runs inside self-certification — not after it. The 95% is not a target. It is a measured result.

Tax Residency Resolved — Not Just KYC

KYC checks identity. The Forensic Engine resolves tax residency via indicia detection and auto-curing.

75+ Jurisdictions. Three Start Dates.

Reporting for the 2027, 2028 and 2029 groups handled from one data layer. One engine, every jurisdiction.

Auto-Cured at Registration

Discrepancies resolved before the user finishes onboarding. No manual queues. No back-office backlog.

Clearance Record per User

Immutable audit trail. Every validation, resolution, and classification — timestamped and retained.

The remediation teams, the spreadsheets, the user re-contact campaigns — gone.

Not an additional cost. A replacement for the one you already carry.

Full CARF Coverage

Every Obligation. Automated

You know what CARF requires. Here is how the OS handles each obligation across 75+ jurisdictions.

Automated

User Self-Certification

Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.

Automated

Crypto-to-Fiat Reporting

Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.

Automated

Crypto-to-Crypto Reporting

Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.

Automated

Unhosted Wallet Transfers

Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.

Automated

Staking & Rewards Reporting

Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.

Automated

User Self-Certification

Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.

Automated

Crypto-to-Fiat Reporting

Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.

Automated

Crypto-to-Crypto Reporting

Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.

Automated

Unhosted Wallet Transfers

Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.

Automated

Staking & Rewards Reporting

Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.

Automated

User Self-Certification

Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.

Automated

Crypto-to-Fiat Reporting

Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.

Automated

Crypto-to-Crypto Reporting

Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.

Automated

Unhosted Wallet Transfers

Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.

Automated

Staking & Rewards Reporting

Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.

Automated

User Self-Certification

Digital collection at onboarding: full name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, and controlling persons. Required for every user on the platform.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Bad TINs caught before the session ends.

Automated

Crypto-to-Fiat Reporting

Every fiat off-ramp transaction classified, associated with the validated user identity, and mapped to the correct reporting jurisdiction. Aggregate or transaction-by-transaction — one data layer supports both.

Automated

Crypto-to-Crypto Reporting

Cross-asset swaps classified by asset pair and transaction value. Each trade linked to the user's self-certification and reported per the applicable jurisdiction's mode.

Automated

Unhosted Wallet Transfers

Transfers to non-custodial wallets flagged and reported as required under CARF. Transaction value, asset type, and user identity captured and mapped to reporting obligations.

Automated

Staking & Rewards Reporting

Staking rewards, lending interest, and yield distributions — each classified as a reportable event. Per-user, per-jurisdiction allocation from one engine.

Automated

Retail Payment Reporting

Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.

Automated

Crypto Asset Classification

Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.

Automated

Indicia Detection & Curing

Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.

Automated

CARF XML v1.0 Generation

OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.

Automated

Enforcement Compliance

Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.

Automated

Annual Re-Verification

Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.

Automated

Retail Payment Reporting

Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.

Automated

Crypto Asset Classification

Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.

Automated

Indicia Detection & Curing

Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.

Automated

CARF XML v1.0 Generation

OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.

Automated

Enforcement Compliance

Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.

Automated

Annual Re-Verification

Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.

Automated

Retail Payment Reporting

Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.

Automated

Crypto Asset Classification

Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.

Automated

Indicia Detection & Curing

Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.

Automated

CARF XML v1.0 Generation

OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.

Automated

Enforcement Compliance

Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.

Automated

Annual Re-Verification

Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.

Automated

Retail Payment Reporting

Retail payments above USD 50,000 using crypto-assets captured and classified. Transaction value recorded at point-of-sale and mapped to the payer's reportable jurisdiction.

Automated

Crypto Asset Classification

Every reportable asset classified: crypto-asset, stablecoin, e-money token, or NFT (where financial instrument). Classification determines reporting category and jurisdiction-specific treatment.

Automated

Indicia Detection & Curing

Systematic detection of discrepancies between declared tax residence and observable data. Each indicium investigated, documented, and cured or escalated. Full audit trail per user.

Automated

CARF XML v1.0 Generation

OECD-published schema compliant. Aggregate and transaction-by-transaction modes generated from one data layer. Jurisdiction-specific deadlines tracked automatically.

Automated

Enforcement Compliance

Two-reminder workflow of at least 60 days. Within the EU (via DAC8), mandatory account blocking after two reminders and at least 60 days. Outside the EU, jurisdiction-specific enforcement actions supported. Every step logged.

Automated

Annual Re-Verification

Automated re-verification when circumstances change. Annual review cycle confirms accuracy of self-certifications, TINs, and declared tax residency jurisdictions across the user base.

The Cost of Getting It Wrong

75+ Jurisdictions. Per-User Liability Cumulative Exposure

Financial

Jurisdiction-Specific Penalties

Each jurisdiction sets its own penalty regime. Non-compliant CASPs face fines per unreported user, per missing TIN, and per incomplete filing, compounding across every jurisdiction where they operate.

Operational

Enforcement Disrupts Trading

Within the EU (via DAC8), a crypto-asset user who has not self-certified after two reminders and at least 60 days is blocked from reportable transactions. Outside the EU, jurisdictions determine enforcement.

Common Mistake

KYC Does Not Equal CARF

KYC verifies identity. CARF requires self-certification, TIN validation per jurisdiction, transaction-level reporting, and a documented cure workflow. Most exchanges have KYC — not CARF infrastructure.

Retention

User Attrition at Scale

Crypto users have near-zero switching costs. A blocked account or poorly executed self-certification flow sends users to a competitor permanently. Compliance failures are retention failures.

Regulatory

Cross-Border Scrutiny

Operating across 75+ jurisdictions means non-compliance in one triggers attention in others. Cross-border information exchange means regulators see the full picture, and act on it.

Reputational

Public Enforcement Actions

The crypto industry is under heightened regulatory scrutiny. Enforcement actions are public, amplified, and permanent. Institutional partners and banking relationships are at stake.

The Global Scale of Crypto Compliance

75+Committed Jurisdictions
740M+Crypto Owners (End of 2025)
55+CARF-MCAA Signatories
$2.1TCrypto Market Cap (End of Q2 2026)

Sources: OECD (jurisdictions, 14 Sep 2026; CARF-MCAA signatories, 3 Mar 2026), Crypto.com Market Sizing Report 2025, CoinGecko 2026 Q2 Crypto Industry Report.

Global Adoption

75+ Jurisdictions Committed to CARF

Major economies have committed to implementing CARF, the first global standard for crypto-asset regulatory compliance. Tax authorities start exchanging data in 2027, 2028 or 2029, depending on the group. In the UK, HMRC's Cryptoasset Reporting Framework rules apply from 1 January 2026, and the first reports, covering 2026, are due between 1 January and 31 May 2027.

First Exchanges By 2027 (46 Jurisdictions)

Austria
Belgium
Bulgaria
Croatia
Czechia
Denmark
Estonia
Faroe Islands
Finland
France
Germany
Greece
Guernsey
Hungary
Iceland
Ireland
Isle of Man
Italy
Jersey
Latvia
Liechtenstein
Lithuania
Luxembourg
Malta
Netherlands
Norway
Poland
Portugal
Romania
San Marino
Slovak Republic
Slovenia
Spain
Sweden
United Kingdom

First Exchanges By 2028 (27 Jurisdictions)

Cyprus
Gibraltar
Switzerland

First Exchanges By 2029 (4 Jurisdictions)

Azerbaijan

Source: OECD Global Forum, jurisdictions committed to implement the Crypto-Asset Reporting Framework (last updated 14 September 2026). El Salvador, Georgia, India and Viet Nam have not yet committed. Subject to national legislative implementation.

CARF Compliance FAQ

Questions from Compliance Teams

We will respond to you at any time. Just use our help center or contact us.

CARF is the OECD Crypto-Asset Reporting Framework — a global standard for tax transparency in digital assets. Welcomed by G20 leaders at the Bali summit in November 2022 and finalized in 2023. It requires Reporting Crypto-Asset Service Providers (RCASPs) to collect self-certifications, validate TINs, classify transactions, and report to tax authorities. 75+ jurisdictions have committed to implementation, with data collection beginning 1 January 2026 in the EU and UK.

Reporting Crypto-Asset Service Providers (RCASPs): centralized exchanges, custodial wallet providers, crypto brokers and dealers, crypto payment processors, staking, lending, and yield providers, DeFi platforms where the operator can identify users, and NFT platforms where NFTs are classified as financial instruments. If you facilitate crypto transactions and can identify your users, CARF likely applies.

A Reporting Crypto-Asset Service Provider must do the following under CARF. 1) Identify users: obtain a self-certification from every individual and entity user when the relationship starts (existing users within the transition period), and for entities identify the controlling persons. 2) Check it: confirm the self-certification is reasonable against other information held, including AML/KYC documents, and obtain a new one if circumstances change. 3) Collect the data: name, address, tax residence, date of birth for individuals, and the TIN for each reportable jurisdiction, unless that jurisdiction issues no TIN or does not require it to be collected. 4) Track relevant transactions: exchanges against fiat currency or other crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. 5) Report once a year to the tax authority where you have your reporting nexus, aggregated by type of crypto-asset, with amounts in fiat currency. 6) Keep documentation and data for at least five years after the reporting deadline.

CARF is the OECD's global standard, and 75+ jurisdictions have committed to implement it. DAC8 (Council Directive (EU) 2023/2226) is the EU's implementation of both CRS 2.0 and CARF into European law, covering 27 EU member states. Outside the EU, each jurisdiction brings CARF into its own law, as the UK did with its Cryptoasset Reporting Framework regulations. The due diligence requirements are aligned, but reporting schemas and local enforcement vary.

CARF is an OECD standard, so there is no fixed member list. A jurisdiction takes part by committing to implement it, and the OECD Global Forum on Transparency and Exchange of Information for Tax Purposes publishes the list of jurisdictions that have committed, grouped by the year they will start exchanging information. EU member states implement CARF through DAC8 (Directive (EU) 2023/2226), which applies from 1 January 2026, and the United Kingdom through its own regulations in force from the same date. The list changes as jurisdictions commit, so check the OECD page for the current position.

Three reportable transaction types: exchanges between crypto-assets and fiat currencies, exchanges between crypto-assets, and transfers of crypto-assets, including reportable retail payments above USD 50,000. Staking rewards and similar receipts are reported as transfers, by type, where known. Each transaction must be classified by type, asset, and user, then reported per jurisdiction in either aggregate or transaction-by-transaction format.

Data collection began 1 January 2026 in the EU and UK. On the OECD list of 14 September 2026, 46 jurisdictions are due to start exchanging information by 2027, 27 by 2028 and 4 by 2029. The 2027 group includes the UK, Norway, Iceland, Liechtenstein, Brazil, Japan, New Zealand and South Africa, and every EU member state except Cyprus, which the OECD lists for 2028. The 2028 group includes Australia, Canada, Hong Kong, Israel, Singapore, Switzerland and the UAE. Platforms report to their own tax authority first: in the UK the first reports, covering 2026, are due between 1 January and 31 May 2027. CASPs must be operationally ready from Day 1 of data collection.

CARF itself (the OECD standard) does not mandate account blocking — that is a DAC8/EU-specific enforcement mechanism. Within the EU (via DAC8), if a user fails to provide a valid self-certification after two formal reminders, and at least 60 days after the first request, the crypto-asset service provider must block them from reportable transactions. Outside the EU, enforcement actions are determined by each jurisdiction's national implementation of CARF.

No. KYC verifies user identity for anti-money-laundering purposes. CARF requires CARF-specific self-certification (including all tax residency jurisdictions and TINs), mandatory TIN validation against the issuing jurisdiction, transaction-level reporting, and a documented cure workflow. KYC is a prerequisite — not a substitute.

Per OECD guidance, DeFi platforms where the operator can identify users (centralized front-end) and NFT platforms where NFTs are used as financial instruments are in scope. Platforms with centralized front-ends, login requirements, or user accounts trigger the same reporting obligations as exchanges. The scope is designed to capture any intermediary that facilitates reportable crypto transactions with identifiable users.

Yes. Wallet-holder self-certification, real-time TIN validation across 75+ jurisdictions, transaction classification across the 3 reportable transaction types, automated curing, enforcement compliance, and CARF XML reporting, all from one OS with shared identity infrastructure. Deployed in weeks.

Ready to Replace Separate Tools with One OS?

From self-certification to CARF XML reporting: every CARF obligation automated through real-time TIN validation, transaction classification, automated curing, and enforcement compliance across 75+ jurisdictions. Deployed in weeks.