TWC's 4Rs: Regulation, Reporting, Risk & RegTech

CARF: A 2026 Implementation Checklist for Crypto-Asset Service Providers

Written by TWC Staff | Tue, Jul 28, 2026

The OECD Crypto-Asset Reporting Framework went live in committed jurisdictions on 1 January 2026. First reports cover calendar-year 2026 data, with first international exchanges of information in 2027. The window between "the rules are now law" and "your first report is due" is short, and most Reporting Crypto-Asset Service Providers (RCASPs) are now mid-implementation.

This guide is a practical, step-by-step CARF implementation checklist for compliance teams at exchanges, brokers, custodians, dealers, ATM operators, and traditional financial institutions that have added crypto products. It covers the OECD framework, EU DAC8, UK CARF, and US 1099-DA, the data requirements, and a five-phase implementation path that ships a working program by Q4 2026.

The 2026 status check

CARF live, no slippage. The OECD's CARF rules came into effect from 1 January 2026 in committed jurisdictions, with first reporting and exchange of information in 2027 covering calendar-year 2026 data (OECD, CARF 2025 Monitoring and Implementation Update, November 2025).

Approximately 76 committed jurisdictions, staggered. 46 jurisdictions are committed to first exchanges by 2027 (UK, all EU-27, Japan, Canada, Switzerland, Cayman, Jersey, Guernsey, and others); approximately 29 by 2028 (Singapore, Hong Kong (China), UAE, Bahamas, BVI, Türkiye); the United States targeting 2029. See the full list of jurisdictions that have signed the CARF Multilateral Competent Authority Agreement (OECD, Jurisdictions Committed to Implement the CARF).

EU DAC8 transposition deadline 31 December 2025; uneven Member-State compliance. EU Member States were required to transpose DAC8 by 31 December 2025 and apply it from 1 January 2026; first reporting period is FY2026 with reports due by 31 January 2027 and competent-authority exchange by 30 September 2027. 

The implication for compliance leaders: there is no longer headroom on the timeline. The 2026 program is the program.

Who is in scope: RCASPs

A Reporting Crypto-Asset Service Provider is any individual or entity providing services that effectuate exchange transactions in relevant crypto-assets for or on behalf of customers. The OECD's CARF FAQ articulates the scope and the carve-outs.

Inside scope:

  • Centralised crypto exchanges
  • Brokers and dealers
  • Custodial wallet providers
  • Crypto ATM operators
  • Certain DeFi intermediaries that exercise sufficient control over the transaction

Outside scope:

  • Non-custodial wallet software with no service layer
  • Pure peer-to-peer protocols without an intermediary
  • Closed-loop crypto-assets (single-merchant networks)

The boundary between custodial-and-in-scope and non-custodial-and-out-of-scope is the most important determination most RCASPs will make early in their implementation. Get it wrong and the program is either over-scoped (cost) or under-scoped (penalty exposure).

What gets reported: assets, users, transactions

Reportable crypto-assets

CARF applies to crypto-assets that can be held and transferred in a decentralised manner using cryptographically secured distributed ledger technology.

  • Inside CARF: cryptocurrencies, stablecoins (unless they qualify as e-money under CRS 2.0), tradeable NFTs that fail the OECD four-part test in the FAQ
  • Outside CARF, but reported under amended CRS 2.0: Specified Electronic Money Products (SEMPs) and Central Bank Digital Currencies (CBDCs)
  • Excluded entirely: closed-loop crypto-assets that can only be redeemed with a single merchant

Reportable users

For each User the RCASP must capture:

  • Name, address, jurisdiction(s) of residence
  • TIN(s) and issuing country
  • Date of birth (individuals)
  • Legal name, business address, entity registration number, and Controlling Person information (entities)

Reportable transactions and amounts

For each transaction type, separately:

  • Crypto-to-fiat acquisitions and disposals — aggregate gross amounts and number of units
  • Crypto-to-crypto exchanges — aggregate gross amounts and number of units
  • Reportable Retail Payments above USD 50,000 — aggregate gross amounts and number of units
  • Transfers — aggregate fair-market-value by transfer type (wallet, airdrop, hard fork, staking reward, loan), and number of units

Fair market value must be determined at transaction time in fiat in a consistent manner across asset classes, with stored evidence of the pricing source. 

How CARF, CRS 2.0, FATCA, MiCA, and 1099-DA interact

CARF was designed to interoperate with the amended CRS rather than overlap with it.

CRS 2.0 closes the gaps CARF leaves. The OECD's June 2023 amendments expand CRS to include SEMPs and CBDCs as Depository Accounts, add new due-diligence requirements, and harmonise XML schemas with CARF. Anti-overlap rules: gross-proceeds reporting under CRS is switched off where the same data is reported under CARF; CRS due diligence may be relied on for CARF and vice versa.

MiCA and the Travel Rule sit alongside. EU MiCA sets prudential and authorisation requirements for crypto-asset service providers. The FATF Travel Rule mandates originator and beneficiary information accompany crypto transfers above thresholds. Neither replaces CARF reporting.

1099-DA in the United States. The US committed to first CARF exchanges in 2029, but Form 1099-DA reporting begins with 2026 transactions for digital-asset brokers. Standard IRC §6721/§6722 information-return penalties apply, currently around USD 310 per return capped in the multi-million range.

For multi-jurisdiction RCASPs, the practical consequence is that one customer transaction can produce reporting obligations under CARF, CRS, 1099-DA, and a MiCA filing — each with different schemas. A single underlying ledger that maps to all four output formats is the only sustainable architecture.

Penalty exposure

EU / DAC8. Member States must set "effective, proportionate, dissuasive" penalties; the directive's recitals reference fines in the EUR 20,000 to EUR 500,000 range, with several Member States layering turnover-percentage fines and MiCA passport revocation.

United Kingdom. Up to GBP 300 per inaccurate, incomplete, or unverified user record; further penalties for due-diligence, record-keeping, and late-filing failures; users supplying wrong information also face up to GBP 300 fines.

United States. No CARF-specific penalty yet; standard 1099-DA penalties apply.

The five-phase CARF implementation checklist

This is the sequence that ships a working CARF program by the end of 2026.

Phase 1 — Scope and governance (now, Q2 2026)

  1. Confirm RCASP status in every jurisdiction where you have nexus (residence, place of effective management, branch, regular business). Apply the OECD nexus tie-breaker to avoid duplicate filings.
  2. Map products to CARF asset categories: cryptocurrency, stablecoin, tradeable NFT, in-scope DeFi. Document carve-outs (CBDCs, SEMPs, closed-loop, OECD NFT four-part test) with legal sign-off.
  3. Register with the relevant tax authority — UK (HMRC), each EU Member State of nexus, and other CARF-committed jurisdictions where you operate.
  4. Appoint a CARF Responsible Officer; document governance, RACI, and board reporting.

Phase 2 — Due diligence and onboarding (Q2–Q3 2026)

  1. Update onboarding flows to capture CARF-compliant self-certifications (tax residence, TIN and issuing country, DOB, entity Controlling Persons).
  2. Re-paper pre-existing users; the deadline in most jurisdictions is within 12 months of CARF entry into force, i.e., 31 December 2026.
  3. Integrate AML/KYC reasonableness checks; build a remediation queue for inconsistent self-certifications.
  4. Build curing workflows for missing or invalid TINs, leveraging the OECD TIN portal.

Phase 3 — Data, systems, and vendor (Q2–Q4 2026)

  1. Build a unified transaction ledger covering centralised exchange, custody, on-chain, and fiat rails — with line-by-line data lineage.
  2. Implement fair-market-value pricing logic per asset class with multi-source reference and stored evidence.
  3. Classify on-chain events (transfers, airdrops, hard forks, staking rewards) against CARF transfer types.
  4. Select a CARF/DAC8 reporting vendor or build a CARF XML Schema v1.0 generator with validation.
  5. Map fields for overlap with CRS 2.0, FATCA, MiCA, the Travel Rule, and 1099-DA to avoid duplicate engineering.

Phase 4 — Reporting and controls (Q4 2026 – Q2 2027)

  1. Run a 2026 dry-run report by Q4 2026; reconcile to financial books and on-chain data.
  2. Submit first reports: UK 31 May 2027; EU Member State deadlines vary, most by 31 January 2027; jurisdiction-specific deadlines elsewhere.
  3. Establish a multi-jurisdiction filing calendar and the user-notification regime DAC8 requires (notifying users their data is being reported).
  4. Stand up exception-handling, penalty-mitigation playbooks, and SAR-style escalation for repeated due-diligence failures.

Phase 5 — Continuous compliance (ongoing)

  1. Monitor OECD updates (next Monitoring Update expected late 2026), CRS 2.0 amendments, and US 1099-DA divergences.
  2. Annual control attestation; internal audit review of CARF data pipelines; refresh self-certifications on change-of-circumstances triggers.

How TWC supports CARF readiness

CARF is, structurally, a CRS-style reporting regime applied to crypto. The data model — self-certification, controlling-person look-through, jurisdiction-specific schema, audit trail, error-correction loop — is the same shape as FATCA and CRS.

Trans World Compliance's CRS/FATCA One platform was built for that data model, and the architecture maps to CARF and DAC8 reporting workflows. Institutions that already run CRS and FATCA on a unified platform have a substantial head start on CARF: the classification engine, audit trail, validation rules, and multi-jurisdiction reporting layer carry over.

For groups operating in NTJ jurisdictions where economic substance overlaps with crypto activities — Cayman, BVI, Bahamas, Bermuda — TACS handles the substance side on the same data foundation.

Frequently asked questions

When does CARF start and when is the first exchange? CARF data collection began 1 January 2026 in committed jurisdictions. The first reports cover calendar-year 2026 data, with first international exchanges of information in 2027.

How many jurisdictions have committed to CARF? Approximately 67. Around 52 jurisdictions are committed to first exchanges by 2027 (UK, all EU-27, Japan, Canada, Switzerland, Cayman, Jersey, Guernsey, others), approximately 15 by 2028 (Singapore, Hong Kong (China), UAE, Bahamas, BVI, Türkiye), and the United States is targeting 2029.

Who has to report under CARF? Reporting Crypto-Asset Service Providers — centralised exchanges, brokers and dealers, custodial wallet providers, crypto ATM operators, and certain DeFi intermediaries that exercise sufficient control over the transaction. Non-custodial wallet software and pure peer-to-peer protocols without a service layer are generally outside scope.

What is DAC8 and how does it relate to CARF? DAC8 is the EU directive that transposes CARF into EU law. Member States were required to transpose DAC8 by 31 December 2025 and apply it from 1 January 2026. First reports are due by 31 January 2027 covering FY2026 data, with competent-authority exchange by 30 September 2027.

What is the UK CARF deadline? The UK Reporting Cryptoasset Service Providers Regulations 2025 came into force 1 January 2026. First reports are due 31 May 2027.

Are NFTs reportable under CARF? Tradeable NFTs are reportable. The OECD provides a four-part test in its CARF FAQ to identify out-of-scope NFTs (e.g., used solely as collectibles, not as an investment or payment instrument). CBDCs and Specified Electronic Money Products are excluded from CARF and instead reported under the amended CRS.

What are the penalties for CARF non-compliance? EU DAC8 references fines in the EUR 20,000 to EUR 500,000 range, with several Member States layering turnover-percentage fines and MiCA passport revocation. The UK applies up to GBP 300 per inaccurate, incomplete, or unverified user record, with further penalties for due-diligence, record-keeping, and late-filing failures.