TaxDo
OECD Common Reporting Standard: CRS 2.0 Applies in the EU From 1 January 2026

CRS 2.0 Compliance Software

From Day-1 Self-Certification to CRS XML Reporting Zero Remediation

CRS 2.0 makes TIN validation mandatory. 130+ jurisdictions committed to CRS exchanges. Strengthened Reasonableness Test. CBI/RBI enhanced due diligence. Digital self-certification with intelligent curing. CRS XML v3.0 reporting. One OS, every CRS 2.0 obligation, from onboarding to reporting.

See How It Works
TaxDo CRS 2.0 compliance dashboard
Built for Your Institution

Whatever You Operate The OS Is Configured for It

One OS for CRS reporting for financial institutions, fintechs and neo-banks, and crypto exchanges. For US accounts, see FATCA.

Retail & Commercial Banks

Mandatory TIN validation at onboarding, strengthened Reasonableness Test on every account, and CRS XML v3.0 reporting — automated from day one across every jurisdiction where you operate.

Investment Entities

Passive NFE detection, controlling person look-through with specified role assignment, and entity classification — handled inside the onboarding flow. Digital assets now explicitly in scope.

Insurance & Wealth Managers

Cash-value insurance products and custodial accounts under the same indicia detection, TIN validation, and Reasonableness Test as banking. One OS for all account types.

Neo-Banks & e-Money

E-money institutions are now explicitly in scope under CRS 2.0. Same self-certification, TIN validation, and reporting infrastructure as established banks — from Day 1, with no transitional period.

Why Separate Tools Fail at CRS 2.0

Three Changes. Three Failure Points One Connects Them All

Validation Problem

Failure Point 1

Mandatory TIN validation across 130+ jurisdictions, and syntax alone is no longer sufficient. Official lookup is now required where available. Best efforts eliminated.

Unvalidated TIN
→
Per-Account Penalty

Due Diligence Problem

Failure Point 2

Every self-certification must be cross-checked against all information on file. Most tools collect first, review later. That gap becomes a remediation backlog — growing with every account opened.

Collection without
Due Diligence
→
Permanent Remediation Cost

Scale Problem

Failure Point 3

130+ jurisdictions. Multiple due diligence procedures. New and pre-existing accounts. Digital assets in scope. One reporting deadline per jurisdiction.

130+ Jurisdictions
→
Manual Process Impossible
This is why TaxDo is built as an Operating System

The OS for Global Tax Identity & Transparency Two Layers

Real-time identity validation and automated compliance intelligence, from the moment an account opens to the moment CRS XML v3.0 is filed across 130+ jurisdictions.

Layer 1The Foundation

Global Tax Identity Infrastructure

CRS 2.0 introduced mandatory TIN validation for the first time: not optional, not best-effort. With 130+ jurisdictions committed to CRS exchanges, every TIN must be checked against official issuing-country sources. TaxDo's identity layer does this in real time, at the point of self-certification.

130+Countries Real-Time TIN Lookup
1000+Tax ID Types Syntax Validation
210+Countries Tax ID Coverage
120+Countries Business Registry
Layer 2The Intelligence

CRS 2.0 Compliance Intelligence

Automated due diligence across every account — running the strengthened Reasonableness Test, detecting indicia, and resolving exceptions in real time.

  • Automated indicia detection across all account data
  • Strengthened Reasonableness Test — automated, audit-ready
  • In-session auto-cure — 95%+ resolved before onboarding completes
  • CBI/RBI enhanced due diligence — automated high-risk screening
  • Controlling person look-through with specified role assignment
  • Immutable clearance record per account holder
See What the OS Does

From Onboarding to Reporting One OS. Every CRS 2.0 Obligation. Covered

Today, enterprises juggle four or more vendors for tax identity, AML screening, regulatory compliance, and indirect tax — separate contracts, separate data, separate problems. TaxDo replaces them all with one connected operating system.

Forensic Due Diligence — At Onboarding

During self-certification, the Forensic Intelligence Engine runs the strengthened Reasonableness Test, detects indicia across multiple dimensions, and auto-cures discrepancies, all in real time. 95%+ of accounts resolved before onboarding completes. Across 130+ jurisdictions. No manual review.

Digital Self-Certification

Guided, jurisdiction-aware collection for individuals and entities. Automatic controlling person cascade for passive NFEs: identify, collect, validate, and report each natural person with specified role. Digital signature. One flow covers all 130+ jurisdictions.

Multi-Jurisdiction Reporting

CRS XML v3.0 reports generated from one shared data layer. 130+ jurisdictions, new mandatory fields, account type flags, and controlling person roles, all populated automatically. One platform, one reporting pass.

Pre-Existing Account Remediation

Bulk validation of your existing portfolio against CRS 2.0 requirements. Lower-value, higher-value, individual, and entity accounts handled under their respective procedures. Gaps identified, discrepancies resolved.

End-to-End CRS 2.0 Lifecycle

Self-CertificationDigital collection at opening
2
TIN ValidationOfficial source lookup in real time
3
Reasonableness TestCross-check against all data on file
4
Auto-Cure95%+ resolved in-session
5
Reports filed per jurisdictionCRS XML v3.0
The Result
95%+

Reduction in Cross-Border Due Diligence Cost

Forensic due diligence runs inside self-certification — not after it. The 95% is not a target. It is a measured result.

Indicia Detected at Onboarding

Every indicium identified in real time, during self-certification, across 130+ jurisdictions.

Strengthened Reasonableness Test

Cross-checked against all information on file. Automated. Audit-ready from Day 1.

Auto-Cured in the Same Session

Discrepancies resolved before the account holder finishes onboarding. No manual queues.

Clearance Record per Account

Immutable audit trail per account. Every validation, resolution, and decision retained.

The remediation teams, the spreadsheets, the year-end scramble — gone.

Not an additional cost. A replacement for the one you already carry.

Full CRS 2.0 Coverage

Every Obligation. Automated

You know what CRS 2.0 requires. Here is how the OS handles each obligation across 130+ jurisdictions.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the self-certification is submitted.

Automated

Self-Certification Collection

Digital collection at account opening: full legal name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons for passive NFEs, and digital signature.

Automated

Strengthened Reasonableness Test

Cross-check every self-certification against all information on file — not just a subset. Self-certifications known or suspected to be incorrect are flagged and escalated automatically.

Automated

CBI/RBI Enhanced Due Diligence

Citizenship-by-investment and residence-by-investment programmes trigger automated enhanced due diligence. High-risk jurisdictions and schemes systematically identified and flagged.

Automated

CRS XML v3.0 Reporting

Backward-incompatible schema changes handled automatically. New mandatory fields — account type flags, new/pre-existing status, controlling person roles — populated from the shared data layer.

Automated

Controlling Person Roles

CRS 2.0 requires specified controlling person role — not just identification. The OS assigns and reports the correct role per natural person within each passive NFE structure.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the self-certification is submitted.

Automated

Self-Certification Collection

Digital collection at account opening: full legal name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons for passive NFEs, and digital signature.

Automated

Strengthened Reasonableness Test

Cross-check every self-certification against all information on file — not just a subset. Self-certifications known or suspected to be incorrect are flagged and escalated automatically.

Automated

CBI/RBI Enhanced Due Diligence

Citizenship-by-investment and residence-by-investment programmes trigger automated enhanced due diligence. High-risk jurisdictions and schemes systematically identified and flagged.

Automated

CRS XML v3.0 Reporting

Backward-incompatible schema changes handled automatically. New mandatory fields — account type flags, new/pre-existing status, controlling person roles — populated from the shared data layer.

Automated

Controlling Person Roles

CRS 2.0 requires specified controlling person role — not just identification. The OS assigns and reports the correct role per natural person within each passive NFE structure.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the self-certification is submitted.

Automated

Self-Certification Collection

Digital collection at account opening: full legal name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons for passive NFEs, and digital signature.

Automated

Strengthened Reasonableness Test

Cross-check every self-certification against all information on file — not just a subset. Self-certifications known or suspected to be incorrect are flagged and escalated automatically.

Automated

CBI/RBI Enhanced Due Diligence

Citizenship-by-investment and residence-by-investment programmes trigger automated enhanced due diligence. High-risk jurisdictions and schemes systematically identified and flagged.

Automated

CRS XML v3.0 Reporting

Backward-incompatible schema changes handled automatically. New mandatory fields — account type flags, new/pre-existing status, controlling person roles — populated from the shared data layer.

Automated

Controlling Person Roles

CRS 2.0 requires specified controlling person role — not just identification. The OS assigns and reports the correct role per natural person within each passive NFE structure.

Automated

TIN Validation

Validated via official government sources in 130+ countries at onboarding. Syntax checked for 1,000+ tax ID types across 210+ countries. Invalid TINs caught before the self-certification is submitted.

Automated

Self-Certification Collection

Digital collection at account opening: full legal name, address, date of birth, all tax residency jurisdictions, TIN per jurisdiction, entity type, controlling persons for passive NFEs, and digital signature.

Automated

Strengthened Reasonableness Test

Cross-check every self-certification against all information on file — not just a subset. Self-certifications known or suspected to be incorrect are flagged and escalated automatically.

Automated

CBI/RBI Enhanced Due Diligence

Citizenship-by-investment and residence-by-investment programmes trigger automated enhanced due diligence. High-risk jurisdictions and schemes systematically identified and flagged.

Automated

CRS XML v3.0 Reporting

Backward-incompatible schema changes handled automatically. New mandatory fields — account type flags, new/pre-existing status, controlling person roles — populated from the shared data layer.

Automated

Controlling Person Roles

CRS 2.0 requires specified controlling person role — not just identification. The OS assigns and reports the correct role per natural person within each passive NFE structure.

Automated

Entity Classification

Every entity classified as FI, active NFE, or passive NFE automatically. Passive NFEs trigger mandatory controlling person look-through with specified role assignment. Full audit trail per decision.

Automated

Indicia Detection & Auto-Curing

Every regulatory indicium scanned at account opening. Intelligent automated resolution resolves tax residency status in the same session. 95%+ resolved before onboarding completes.

Automated

New vs Pre-Existing Accounts

Due diligence procedures differ by account type: new individual, new entity, pre-existing lower value, pre-existing higher value, pre-existing entity. Each handled under its respective CRS 2.0 procedure.

Automated

Digital Assets in Scope

Crypto-assets, e-money products, and CBDCs now explicitly covered under CRS 2.0. Same self-certification, TIN validation, and reporting obligations as traditional financial accounts.

Automated

Data Retention & Evidence

Minimum 5-year data retention. Self-certifications, validation evidence, due diligence records, and reporting submissions stored with immutable audit trails. Evidence producible on request.

Automated

Portfolio Remediation

Scan, prioritise, and auto-remediate your existing book. Missing TINs, expired self-certifications, unresolved indicia. New accounts and legacy cleanup from one platform.

Automated

Entity Classification

Every entity classified as FI, active NFE, or passive NFE automatically. Passive NFEs trigger mandatory controlling person look-through with specified role assignment. Full audit trail per decision.

Automated

Indicia Detection & Auto-Curing

Every regulatory indicium scanned at account opening. Intelligent automated resolution resolves tax residency status in the same session. 95%+ resolved before onboarding completes.

Automated

New vs Pre-Existing Accounts

Due diligence procedures differ by account type: new individual, new entity, pre-existing lower value, pre-existing higher value, pre-existing entity. Each handled under its respective CRS 2.0 procedure.

Automated

Digital Assets in Scope

Crypto-assets, e-money products, and CBDCs now explicitly covered under CRS 2.0. Same self-certification, TIN validation, and reporting obligations as traditional financial accounts.

Automated

Data Retention & Evidence

Minimum 5-year data retention. Self-certifications, validation evidence, due diligence records, and reporting submissions stored with immutable audit trails. Evidence producible on request.

Automated

Portfolio Remediation

Scan, prioritise, and auto-remediate your existing book. Missing TINs, expired self-certifications, unresolved indicia. New accounts and legacy cleanup from one platform.

Automated

Entity Classification

Every entity classified as FI, active NFE, or passive NFE automatically. Passive NFEs trigger mandatory controlling person look-through with specified role assignment. Full audit trail per decision.

Automated

Indicia Detection & Auto-Curing

Every regulatory indicium scanned at account opening. Intelligent automated resolution resolves tax residency status in the same session. 95%+ resolved before onboarding completes.

Automated

New vs Pre-Existing Accounts

Due diligence procedures differ by account type: new individual, new entity, pre-existing lower value, pre-existing higher value, pre-existing entity. Each handled under its respective CRS 2.0 procedure.

Automated

Digital Assets in Scope

Crypto-assets, e-money products, and CBDCs now explicitly covered under CRS 2.0. Same self-certification, TIN validation, and reporting obligations as traditional financial accounts.

Automated

Data Retention & Evidence

Minimum 5-year data retention. Self-certifications, validation evidence, due diligence records, and reporting submissions stored with immutable audit trails. Evidence producible on request.

Automated

Portfolio Remediation

Scan, prioritise, and auto-remediate your existing book. Missing TINs, expired self-certifications, unresolved indicia. New accounts and legacy cleanup from one platform.

Automated

Entity Classification

Every entity classified as FI, active NFE, or passive NFE automatically. Passive NFEs trigger mandatory controlling person look-through with specified role assignment. Full audit trail per decision.

Automated

Indicia Detection & Auto-Curing

Every regulatory indicium scanned at account opening. Intelligent automated resolution resolves tax residency status in the same session. 95%+ resolved before onboarding completes.

Automated

New vs Pre-Existing Accounts

Due diligence procedures differ by account type: new individual, new entity, pre-existing lower value, pre-existing higher value, pre-existing entity. Each handled under its respective CRS 2.0 procedure.

Automated

Digital Assets in Scope

Crypto-assets, e-money products, and CBDCs now explicitly covered under CRS 2.0. Same self-certification, TIN validation, and reporting obligations as traditional financial accounts.

Automated

Data Retention & Evidence

Minimum 5-year data retention. Self-certifications, validation evidence, due diligence records, and reporting submissions stored with immutable audit trails. Evidence producible on request.

Automated

Portfolio Remediation

Scan, prioritise, and auto-remediate your existing book. Missing TINs, expired self-certifications, unresolved indicia. New accounts and legacy cleanup from one platform.

The Cost of Getting It Wrong

CRS 2.0 Applies in the EU From 1 January 2026 The Consequences Are Jurisdiction-Specific

Validation Failure

TIN Validation Penalties

Mandatory TIN validation replaces best efforts. Every unvalidated TIN is a reportable deficiency. Jurisdictions impose penalties per account for missing, invalid, or unverified taxpayer identification numbers.

Due Diligence Failure

Reasonableness Test Failures

Accepting self-certifications known or suspected to be incorrect is a due diligence violation. The strengthened Reasonableness Test requires cross-checking against all information on file.

Reporting Failure

Data Quality & Schema Non-Compliance

CRS XML v3.0 introduces mandatory fields not present in v2.0. Missing account type flags, unspecified controlling person roles, or incorrect status codes trigger reporting rejections.

Operational

Multi-Jurisdiction Exposure

Operating across multiple CRS jurisdictions multiplies compliance risk. Each jurisdiction independently assesses penalties, conducts audits, and enforces remediation.

Reputational

Regulatory Scrutiny & Peer Review

The OECD Global Forum conducts peer reviews of CRS implementation. Compliance failures trigger enhanced monitoring, reputational damage, and potential exclusion from exchange agreements.

Operational

The Year-End Scramble

Manual remediation cycles cannot clear a global account portfolio before reporting deadlines. Every account not validated in-session becomes a year-end liability that scales with your customer base.

Committed Across 130+ Jurisdictions. CRS 2.0 in the EU From 2026

130+Committed Jurisdictions
€12TAssets in Accounts Exchanged, 2022
123M+Financial Accounts Exchanged, 2022
2026CRS 2.0 in the EU
Global Coverage

Committed Jurisdictions. One Standard

Every jurisdiction below has committed to the annual automatic exchange of financial account information under the CRS. CRS 2.0 adds mandatory TIN validation and a strengthened Reasonableness Test. In the EU, the CRS 2.0 amendments apply through DAC8.

Albania
Andorra
Armenia
Austria
Azerbaijan
Belgium
Bulgaria
Croatia
Cyprus
Czechia
Denmark
Estonia
Faroe Islands
Finland
France
Georgia
Germany
Gibraltar
Greece
Greenland
Guernsey
Hungary
Iceland
Ireland
Isle of Man
Italy
Jersey
Latvia
Liechtenstein
Lithuania
Luxembourg
Malta
Moldova
Monaco
Montenegro
Netherlands
Norway
Poland
Portugal
Romania
Russia
San Marino
Slovak Republic
Slovenia
Spain
Sweden
Switzerland
Ukraine
United Kingdom

Source: OECD Global Forum, status of commitments for the automatic exchange of financial account information (last updated 30 September 2026). Some listed jurisdictions have yet to start exchanging. Subject to national legislative implementation.

CRS 2.0 Regulatory FAQ

Questions from Compliance Teams

We will respond to you at any time. Just use our help center or contact us.

CRS 2.0 is the amended OECD Common Reporting Standard — the global framework under which financial institutions identify the tax residency of their account holders and report those accounts to their own tax authority for automatic exchange with other jurisdictions. The amendments were approved by the OECD Council in August 2023, and apply in the EU from 1 January 2026 through DAC8; other jurisdictions set their own start dates. Against CRS 1.0 it makes TIN validation mandatory rather than best efforts, strengthens the Reasonableness Test, requires CBI/RBI enhanced due diligence, and brings digital assets — crypto, e-money and CBDCs — explicitly into scope.

An account is reportable when a financial institution maintains it and it is held by a Reportable Person, meaning someone tax resident in a Reportable Jurisdiction, or by a passive non-financial entity with a controlling person who is one. Financial accounts cover depository and custodial accounts, equity and debt interests in investment entities, and cash value insurance and annuity contracts. Excluded accounts, such as qualifying retirement and pension accounts, are out of scope, and listed companies, governments and financial institutions are not Reportable Persons. TaxDo runs indicia detection and controlling person look-through at onboarding so each account is classified before reporting.

Reporting Financial Institutions do: any financial institution in a participating jurisdiction that is not a Non-Reporting Financial Institution. Under the standard a financial institution is a custodial institution, depository institution, investment entity or specified insurance company, so it covers banks, brokers and custodians, funds, and insurers that issue cash value or annuity contracts. CRS 2.0 also treats institutions holding e-money products or central bank digital currencies for customers as depository institutions. Governmental entities, central banks and certain pension funds are Non-Reporting. Reporting is annual, in the calendar year after the one the information relates to. TaxDo covers self-certification, TIN validation and CRS XML v3.0 reporting.

The amendments were approved by the OECD Council in August 2023. CRS 2.0 introduces mandatory TIN validation (replacing best efforts), a strengthened Reasonableness Test requiring cross-checks against all information on file, mandatory CBI/RBI enhanced due diligence, explicit inclusion of digital assets (crypto, e-money, CBDCs), new account type flags, specified controlling person roles, new/pre-existing account status requirements, 5-year data retention, and a backward-incompatible CRS XML Schema v3.0.

Yes. CRS 1.0 allowed best-efforts TIN collection. Under CRS 2.0, TIN validation is mandatory. Financial institutions must validate every TIN against the issuing jurisdiction's format and issuance rules. Syntax-only checks are no longer sufficient — official lookup is required where available. Institutions cannot accept self-certifications with TINs that are known or reasonably suspected to be invalid.

Under CRS 2.0, the Reasonableness Test requires financial institutions to cross-check every self-certification against all information held on file — not just a subset of fields. Institutions cannot accept self-certifications that are known or reasonably suspected to be incorrect or unreliable. This is a significant upgrade from CRS 1.0, which allowed more limited cross-referencing.

CRS 2.0 mandates enhanced due diligence for account holders who obtained citizenship or residence through investment programmes (CBI/RBI). Financial institutions must systematically identify high-risk schemes, flag accounts linked to CBI/RBI jurisdictions, and apply additional scrutiny to self-certifications and tax residency claims from these account holders.

Yes. CRS 2.0 explicitly brings crypto-assets, e-money products, and central bank digital currencies (CBDCs) into scope. Investment entities, e-money institutions, and platforms dealing in digital assets are now reporting entities under CRS with the same self-certification, TIN validation, and due diligence requirements as traditional financial institutions.

CRS XML Schema v3.0 was published by the OECD alongside the amended CRS standard. It is backward incompatible with CRS XML v2.0, introducing backward-incompatible changes to the header structure, adding mandatory NewOrPreExistingAccountType and AccountType elements, and requiring controlling person role specification. Additional mandatory fields include account type flags (Depository, Custodial, DebtEq, CashValue, Other) and new/pre-existing account status. Existing reporting infrastructure requires migration.

The OECD publishes the authoritative list. Its status of commitments groups participating jurisdictions by the year they committed to start exchanging financial account information, from 2017 onward, and it is updated as new jurisdictions join. The countries you report on depend on the Reportable Jurisdictions list your own jurisdiction publishes. The United States is not on the OECD commitments list: it has exchanged account information under FATCA since 2015 through intergovernmental agreements instead. Check the OECD automatic exchange of information portal for the current list. TaxDo validates TINs against official issuing-country sources at self-certification.

As of 30 September 2026, 130+ jurisdictions have committed to CRS exchanges (OECD Global Forum). In 2022, information on over 123 million financial accounts, covering around €12 trillion in assets, was exchanged automatically (OECD Global Forum). The OECD list has five jurisdictions committed to start exchanges by 2025: Armenia, Morocco, Rwanda, Senegal, and Uganda. The CRS 2.0 amendments apply in the EU from 1 January 2026 through DAC8; other jurisdictions bring them in through their own legislation and timetable, with jurisdiction-specific penalty frameworks and reporting variations.

A CRS self-certification is a statement from the account holder that gives their tax residence and the other details the institution needs for due diligence and reporting. Institutions usually collect it on a self-certification form, often as part of account opening, and must check it for reasonableness against the other information they hold. For a new individual account it is valid only if signed or positively affirmed, dated, and showing name, residence address, tax residence, TIN for each Reportable Jurisdiction (unless an exception applies) and date of birth. The OECD publishes sample forms, but none is mandatory. TaxDo provides guided digital self-certification for individuals and entities.

Paper and PDF self-certifications cannot support mandatory real-time TIN validation, cannot trigger the strengthened Reasonableness Test automatically, and cannot produce structured audit trails required for 5-year data retention. While CRS 2.0 does not explicitly ban paper, the mandatory validation and cross-checking requirements make digital self-certification the only operationally viable approach at scale.

Ready to Replace Separate Tools with One OS?

From self-certification to CRS XML v3.0 reporting: every CRS 2.0 obligation automated through mandatory TIN validation, strengthened Reasonableness Test, and intelligent curing across 130+ jurisdictions. Deployed in weeks.