CARF crypto tax reporting: prepare your VASP for 2027 OECD exchange deadlines
The cryptocurrency market has long operated outside full tax oversight, but this is rapidly changing. The OECD is introducing a new global standard – the Crypto-Asset Reporting Framework (CARF), which requires crypto service providers to disclose user and transaction data for automatic exchange between countries. In the coming years, companies will need to collect, store, and report tax-related client information in a standardized format. With key deadlines approaching, preparation for CARF is becoming critical. Errors or delays may lead to serious regulatory and financial consequences. In this article, we examine the requirements introduced by CARF, who they apply to, and how VASPs can prepare for the new tax reporting rules.
What is CARF and why it matters for crypto businesses
The Crypto-Asset Reporting Framework (CARF) is a global tax reporting standard for crypto-assets developed by the Organisation for Economic Co-operation and Development (OECD). Its main objective is to enable the automatic exchange of information on crypto transactions between jurisdictions and reduce tax evasion.
Conceptually, CARF is similar to the Common Reporting Standard (CRS), but adapted specifically for the crypto industry, which has historically been less regulated than traditional financial markets.
For crypto businesses, this marks a shift to a new level of transparency. VASPs and other service providers can no longer be viewed as purely technical platforms – they become participants in a global tax reporting system.
Under CARF, companies are required to:
- Identify users and determine their tax residency
- Collect data on crypto transactions
- Store and process information in a standardized format
- Report to tax authorities
CARF applies not only to traditional crypto exchanges but also to a broad range of market participants, including brokers and intermediaries involved in executing or facilitating crypto transactions.
A key feature of CARF is its international scope. Data collected in one country will be automatically shared with tax authorities in other jurisdictions where the user is tax resident.
CARF timeline: what happens between 2026 and 2027
The implementation of CARF is phased, and the coming years are critical for crypto businesses. Although the framework is already developed, its practical rollout takes time — both for governments and VASPs.
The current focus is on preparing for the first reporting periods starting in 2026.
Key CARF milestones include:
- 2025–2026 – legislative alignment and national implementation
- 2026 – start of data collection on users and crypto transactions
- 2027 – first reporting and launch of automatic data exchange
This means companies have limited time to prepare internal processes, IT systems, and compliance procedures.
It is also important to note that CARF does not operate in isolation. Its implementation is aligned with other international standards, increasing the compliance burden on businesses.
In preparation for 2026–2027, VASPs should:
- Review onboarding and KYC procedures
- Implement mechanisms to determine tax residency
- Set up systems for data collection and storage
- Ensure readiness for reporting
Special attention should be given to cross-border operations. Companies serving clients in multiple countries must account for different implementation timelines and requirements across jurisdictions.
Who is in scope: which VASPs must comply
One of the key questions for crypto businesses is whether a company falls within the scope of CARF. Unlike narrower regulatory regimes, CARF covers a broad range of market participants involved in processing or facilitating crypto transactions.
The main criterion is not the legal form of the company, but its actual role in the ecosystem. If a business is involved in transferring, exchanging, or holding crypto-assets on behalf of users, it is likely to be subject to CARF.
Exchanges and custodial platforms
Traditional crypto exchanges and custodial platforms are the primary targets of CARF. They interact directly with users, process transactions, and have access to key data.
These include:
- Centralized exchanges (CEX)
- Custodial wallets
- Platforms holding assets on behalf of clients
Such entities will be required to collect the most comprehensive data and report it to tax authorities.
Brokers and intermediaries
CARF also applies to brokers and other intermediaries involved in executing or arranging crypto transactions. Even without direct custody of assets, a company may still be in scope if it plays an active role.
This may include:
- Brokers executing trades for clients
- Liquidity aggregation platforms
- Services facilitating crypto exchanges
Therefore, the absence of custody does not exempt a company from CARF obligations.
DeFi (when control exists)
Decentralized finance presents a more complex case. While many DeFi protocols lack a central operator, CARF introduces the concept of “control.”
If a person or group:
- Manages the protocol
- Receives economic benefits
- Controls key platform functions
Such a structure may be treated as a reporting entity under CARF.
As a result, CARF significantly expands the range of companies required to comply with tax reporting rules. Even participants previously considered outside regulation may fall within scope depending on their actual role.
What exactly must be reported under CARF
CARF sets clear requirements on what data crypto companies must collect and report to tax authorities. Unlike broader regulatory frameworks, it focuses on specific types of information that must be standardized and ready for automatic exchange between jurisdictions.
For VASPs, this means not only expanding data collection but also building systems capable of properly processing and structuring information.
User identification and tax residency
A key element of CARF is identifying users and determining their tax residency. This requires a deeper level of verification than standard AML/KYC procedures.
Companies must collect:
- User name and identification details
- Residential address
- Tax residency
- Tax identification number (TIN), where applicable
Importantly, this data must not only be collected but also verified, as errors can lead to incorrect reporting and regulatory risks.
Types of reportable transactions
CARF covers a wide range of crypto-asset transactions, not just interactions with fiat. This significantly expands reporting scope compared to traditional financial instruments.
Reportable transactions include:
- Crypto-to-fiat exchanges
- Crypto-to-crypto exchanges
- Transfers between users
- Transactions via brokers and intermediaries
As a result, most economically relevant crypto transactions may fall within reporting scope.
Due diligence requirements
CARF introduces due diligence obligations similar to the banking sector, adapted for crypto businesses.
Companies must:
- Verify the accuracy of client data
- Regularly update customer information
- Identify changes in tax residency
- Maintain documentation for audits
This means one-time onboarding checks are no longer sufficient – continuous monitoring and data updates are required.
Key compliance challenges for VASPs
Despite the formal clarity of CARF requirements, their practical implementation creates significant operational and legal challenges for VASPs. The main issue is that crypto businesses must redesign existing processes that were not built for this level of tax reporting.
In many cases, this involves not minor adjustments but a full transformation of how client data and internal controls are managed.
Key challenges include:
- Data collection and verification – obtaining more detailed client information, including tax residency, and ensuring accuracy
- KYC adaptation – existing procedures often do not meet CARF requirements and need upgrades
- Cross-border reporting – managing requirements across jurisdictions and allocating data correctly
- IT infrastructure – implementing systems to store, process, and transmit large volumes of data
- Internal policy updates – developing new procedures and control mechanisms
- Risk of errors and penalties – even minor inaccuracies may trigger regulatory consequences
An additional challenge is that the crypto industry has historically operated in a less regulated environment. Many firms lack compliance functions comparable to those in banking, making the transition to CARF particularly demanding.
At the same time, regulators are aligning crypto oversight with traditional finance. As a result, VASP requirements are increasingly resembling banking standards in terms of control, reporting, and accountability.
How CARF differs from CRS and existing AML/KYC frameworks
CARF does not operate in isolation – it complements existing international standards such as the Common Reporting Standard (CRS) and AML/KYC requirements. However, there are key differences that directly affect internal VASP processes.
Understanding these differences is essential to properly design a compliance system and avoid overlaps or gaps in control.
CARF vs CRS
CRS has long been used for automatic exchange of financial information between countries, but it did not originally cover crypto-assets. CARF was introduced to close this gap.
Key differences include:
- CRS applies to traditional financial institutions, while CARF targets the crypto sector
- CARF covers crypto transactions, including crypto-to-crypto, which are outside CRS scope
- CARF data requirements are tailored to digital assets
As a result, CARF extends the global reporting system to a new asset class.
CARF vs AML/KYC
AML and KYC procedures are already mandatory for crypto companies, but their objectives differ from CARF.
Key distinctions:
- AML/KYC focus on preventing money laundering and terrorist financing
- CARF focuses on tax transparency and cross-border data exchange
- AML processes do not always require determining tax residency
- CARF requires standardized reporting and data submission to authorities
This means existing AML/KYC processes cannot be used as-is – they must be expanded and adapted.
How to prepare your VASP for CARF compliance
Preparing for CARF requires a structured approach and cannot be handled at the last minute. For most VASPs, this means reviewing existing processes, introducing new procedures, and adapting IT infrastructure to tax reporting requirements.
Data collection and onboarding updates
The first step is updating onboarding and data collection processes. Standard KYC procedures usually do not cover all CARF requirements, especially regarding tax residency. Companies must collect more detailed client information, including tax identification numbers, and implement verification mechanisms. Errors at this stage may lead to incorrect reporting and regulatory consequences.
Internal compliance procedures
The next step is building an internal compliance framework. This involves developing policies and procedures for data handling, defining responsibilities, and implementing control mechanisms. Staff must understand CARF requirements and apply them correctly. Without a structured system, even technically prepared companies may fail to comply.
Technology and reporting systems
IT infrastructure becomes a critical element of CARF readiness. Companies must be able to process and store large volumes of data and generate reports in the required format. This often requires upgrading existing systems or implementing new solutions. Special attention should be given to data protection due to the sensitivity of the information.
Cross-border alignment
For companies operating internationally, aligning requirements across jurisdictions is essential. Differences in CARF implementation timelines, reporting formats, and interaction with tax authorities require coordination across the business. Without this, companies risk reporting errors or non-compliance in certain jurisdictions.
How Key2Law helps VASPs prepare for CARF
Implementing CARF requires crypto companies not only to understand new requirements but also to transform internal processes, including data collection, compliance, and IT infrastructure. Without professional support, preparation can be time-consuming and prone to errors that may lead to sanctions.
Key2Law team helps VASPs and fintech companies build a comprehensive CARF compliance strategy and prepare for cross-border tax data exchange. We support clients at every stage: from assessing current processes to implementing changes and interacting with regulators.
Our experts provide end-to-end business support, including:
- Conducting legal audits of existing processes and identifying CARF gaps
- Developing and implementing internal data collection and processing policies
- Adapting KYC and onboarding procedures to tax reporting requirements
- Assisting with tax residency determination and proper TIN handling
- Supporting implementation of IT solutions for data collection, storage, and reporting
- Building internal control and monitoring frameworks
- Handling cross-border issues and multi-jurisdiction coordination
- Preparing for audits and reducing sanction risks
If you are preparing for CARF or have already started adapting your processes, it is essential to ensure your model meets international requirements and is ready for data exchange in 2027. Contact the Key2Law team to receive expert support and build an effective compliance system that protects your business and ensures sustainable growth.