Concept
The client question about crypto-assets has shifted over the past two years. It used to be how much tax is due; it is now what the authorities already know. These are different questions with different answers: substantive taxation is governed by the law of the jurisdiction of residence and is covered separately in crypto tax by country, while the reporting circuit is supranational, operates regardless of whether tax arises, and is already being populated with 2026 data.
The circuit has three layers, and conflating them is expensive. The first is the Crypto-Asset Reporting Framework, a standalone OECD standard covering direct transactions in crypto-assets through a service provider. The second is the amended Common Reporting Standard, which captures crypto exposure wrapped inside an ordinary financial product. The third consists of national obligations that have no connection to international exchange and exist either before it or instead of it. Each layer answers its own question, and none of them answers the question of how much of an asset a person holds today.
The division between the layers is set out in the standard itself. Paragraph 28 of the CARF introduction lists four points of interaction with the CRS: specified electronic money products and central bank digital currencies are excluded from the definition of Relevant Crypto-Asset because reporting on them is ensured under the CRS; for assets that qualify both as a Relevant Crypto-Asset and as a Financial Asset — shares issued in crypto form, for example — the CRS contains an optional provision switching off gross proceeds reporting where the information is already reported under CARF; indirect investments in crypto-assets through traditional financial products, derivatives and interests in investment vehicles are covered by the CRS; and the due diligence procedures are aligned with the CRS to the extent possible, allowing a provider that is also a Reporting Financial Institution to rely on new-account due diligence already performed.
The CARF perimeter: who counts as an operator
The obliged person under the standard is the Reporting Crypto-Asset Service Provider, defined functionally: any individual or Entity that, as a business, provides a service effectuating Exchange Transactions for or on behalf of customers. Licence, regulatory status and technology are irrelevant to the classification — paragraph 28 of the Commentary on Section IV(B) states this directly: the technology involved in providing the service does not determine whether a person is a Reporting Crypto-Asset Service Provider.
The nexus to a jurisdiction is built as a cascade in Section I(A): tax residence of the provider; incorporation or organisation under the laws of the jurisdiction where the entity has legal personality or an obligation to file tax or tax information returns; place of management; regular place of business. A fifth link sits separately — Section I(B) attributes to the jurisdiction those Relevant Transactions effectuated through a branch located there. Sections I(C) to (H) remove duplication: where the same requirements are completed in a Partner Jurisdiction under a stronger nexus, they need not be completed elsewhere, and Section I(H) allows the obligation to be discharged by lodging a notification confirming that the requirements are completed under the rules of a Partner Jurisdiction pursuant to a substantially similar nexus.
The boundaries of the perimeter matter more than the definition itself, because every argument about whether a given platform is a provider is fought there.
| Figure | Inside the perimeter | Authority |
|---|---|---|
| Exchange, broker, dealer trading for its own account, market maker taking a bid-ask spread, operator of a crypto-asset ATM | Yes | Paragraph 25 of the Commentary on Section IV(B) |
| Person purchasing an asset directly from an issuer to resell and distribute it to customers | Yes | Paragraph 25; the sole creation and issuance of an asset is not itself such a service |
| Validator of distributed ledger transactions | No | Paragraph 24: validation is not carried out for or on behalf of customers, even where it is remunerated |
| Platform offering only bulletin board functionality — posting buy, sell or conversion prices | No | Paragraph 26: no service allowing users to effectuate Exchange Transactions |
| Developer that solely creates or sells software or an application | No, so long as it does not itself use them to provide the service | Paragraph 26 |
| Investment fund investing in crypto-assets | No under CARF | Paragraph 23: investors in the fund do not effectuate Exchange Transactions through it. Such a structure is reported under the CRS |
Paragraph 27 deserves separate attention. A person is treated as making available a trading platform to the extent it exercises control or sufficient influence over that platform, allowing it to comply with the due diligence and reporting obligations; whether such control exists is assessed in a manner consistent with the 2012 FATF Recommendations as amended in June 2019 in respect of virtual assets and virtual asset service providers. In the contested zone, therefore, the CARF perimeter is drawn by the same test that determines VASP status rather than by a self-standing tax criterion. For a platform engineered so that no one holds sufficient influence, this is simultaneously a defence against CARF and the principal source of regulatory risk on a different axis.
The practical consequence for a pure software supplier is that the line runs through use, not development. A team that has released a protocol and provides no service through it sits outside the perimeter; the same team that launches an interface through which customers effectuate exchanges, and retains control over it, sits inside.
What goes into the file and what does not
Section II(A) of the standard fixes the content of the report as a closed list, and visibility should be assessed against that list rather than against intuition.
Client identification covers name, address, all jurisdictions of residence, TIN, and date and place of birth. Where the client is an Entity that, after the due diligence procedures, is identified as having one or more Controlling Persons who are Reportable Persons, the file carries the Entity's details, the full data set for each such person, and the role by virtue of which each person is a Controlling Person. The role travels as a separate field: settlor, trustee and protector no longer dissolve into a single undifferentiated category.
The transactional part is aggregated and broken down by type of crypto-asset. For acquisitions and disposals against Fiat Currency, and for acquisitions and disposals against other Relevant Crypto-Assets, three figures are reported: the amount (gross amount paid, gross amount received, or aggregate fair market value), the aggregate number of units, and the number of Relevant Transactions. Reportable Retail Payment Transactions form a separate line — Transfers of Relevant Crypto-Assets in consideration of goods or services for a value exceeding USD 50 000. Transfers not caught by the preceding categories are reported in two further lines, inbound and outbound, subdivided by transfer type where known to the provider.
The final line, subparagraph A(3)(i), exists specifically to trace the part of the picture that is otherwise invisible: for Transfers the provider effectuated to wallet addresses not known to be associated with a virtual asset service provider or financial institution as defined in the FATF Recommendations, the aggregate fair market value and the aggregate number of units are reported. There is no transaction count in this line, and that is deliberate: paragraph 25 of the Commentary on Section II lists exactly two figures. Paragraph 26 adds the point that is usually missed: the address itself is not exchanged, but the provider must collect it and retain it in its records for not less than five years, precisely so that a tax administration can obtain it later through a follow-up request. The rationale is stated in paragraph 21 of the introduction: the aggregate on withdrawals to unhosted wallets exists to indicate the volume that has left observation, and where that gives rise to compliance concerns, the detail can be requested through existing exchange of information channels.
What is absent from the file is an equally closed list. There is no year-end balance for any asset: CARF is built on transactions rather than on positions. There are no wallet addresses. There is no tax basis and no gain or loss. There is no transaction-level history — only annual totals by asset type.
Hence the defining property of this data: it shows turnover and does not show position. A tax administration receiving the file knows how much a person bought and how much they sold, and does not know what remains. The position is reconstructed from a sequence of annual reports, tax returns and comparison with other sources — which is why a discrepancy is the only genuinely operative signal.
Commitment waves and the exchange mechanism
Commitments are recorded by the Global Forum in a dedicated list, and three things within it must not be conflated: a political commitment, a signature to the multilateral agreement, and an activated exchange relationship.
Under the commitment list as at 23 June 2026, 76 jurisdictions have committed to implement CARF.
| Year of first exchange | Jurisdictions | Who is inside |
|---|---|---|
| 2027 | 46 | Twenty-six EU Member States; the United Kingdom, Norway, Iceland; the Cayman Islands, Guernsey, Jersey, the Isle of Man, Liechtenstein, San Marino, the Faroe Islands; Brazil, Chile, Colombia, Indonesia, Japan, Kazakhstan, Korea, New Zealand, South Africa, Uganda |
| 2028 | 29 | Cyprus — the twenty-seventh EU Member State; Switzerland, Hong Kong (China), Singapore, the United Arab Emirates, Türkiye, Australia, Canada, Israel, Mexico, Malaysia; the Bahamas, Bermuda, the British Virgin Islands, Gibraltar, Panama, the Seychelles, Mauritius, Barbados, Belize, Saint Vincent and the Grenadines; Azerbaijan, Bahrain, Costa Rica, Kenya, Mongolia, Nigeria, the Philippines, Thailand |
| 2029 | 1 | The United States — the only jurisdiction in this category |
| No commitment | 5 | Argentina, El Salvador, Georgia, India, Viet Nam — identified as relevant to the CARF but not yet committed |
The last row carries qualifications, and they appear in the footnotes to the list itself. Argentina has adhered to the Joint Statement on the CARF, which includes an intent to work towards swiftly transposing the standard into domestic law and activating exchange agreements in time for exchanges to commence by 2027, subject to national legislative procedures. India is in the process of making a political commitment and expects to make it in due course. El Salvador, Georgia and Viet Nam appear without footnotes.
The multilateral mechanism is the CARF-MCAA, a competent authority agreement based on Article 6 of the Convention on Mutual Administrative Assistance in Tax Matters. As at 3 March 2026 it had 56 signatories; the United States is not among them. As alternatives to that agreement, the standard recognises bilateral competent authority agreements based on double tax treaties or tax information exchange agreements, the Convention itself, a self-standing intergovernmental agreement, and regional legislation covering both the reporting obligations and the exchange modalities — the last of these being the route taken by the European Union.
A signature to the CARF-MCAA does not by itself create a flow of data. The preamble reproduces the structure of Article 6 of the Convention: two or more Parties may mutually agree to exchange information automatically, but the actual exchange takes place on a bilateral basis, and relationships are activated by the submission of notifications. Between "the jurisdiction has signed" and "a file moves from jurisdiction A to jurisdiction B" sits a separate administrative step, and it must be checked for the specific pair of countries on the specific date. The national mechanics of the waves — provider registration deadlines, reporting and penalties — are set out in CARF in practice.
The European layer: DAC8
In the European Union the standard is implemented by a Union-level instrument — Council Directive (EU) 2023/2226 of 17 October 2023, which inserted a new Article 8ad and Annex VI into the DAC. The timetable is set by Article 2 of the directive: Member States were to adopt and publish the necessary measures by 31 December 2025 and apply them from 1 January 2026. Article 8ad(6) sets the exchange deadline at nine months following the end of the calendar year to which the reporting requirements relate, with the first information communicated for the reporting period from 1 January 2026. The date of the first exchange within the Union follows: by 30 September 2027 for the 2026 reporting year.
Two features of the directive should be held separately. The first is the definition of the obliged person by reference to MiCA: Annex VI defines Crypto-Asset Service Provider by reference to Article 3(1), point (15), of Regulation (EU) 2023/1114, and Crypto-Asset Service by reference to Article 3(1), point (16), of the same regulation, expressly including staking and lending. A provider authorised under MiCA is automatically within the DAC8 perimeter. The second is the Crypto-Asset Operator — a provider of crypto-asset services other than an authorised CASP — for which a single registration in one Member State is introduced, with an individual identification number and a revocation mechanism that operates after two reminders, no later than 90 days and no earlier than 30 days after the second. A non-EU provider serving European clients falls here.
Transposition has lagged materially behind the directive. On 30 January 2026 the Commission sent letters of formal notice to twelve Member States that had failed to transpose DAC8 on time — Belgium, Bulgaria, Cyprus, Czechia, Estonia, Greece, Luxembourg, Malta, the Netherlands, Poland, Portugal and Spain — with two months to respond; the same package included procedures on DAC9 against ten Member States. Several have since adopted implementing legislation. The practical effect of the delay lies beyond the sanction: the field set a provider actually collects for 2026 still differs across the Union, and a client whose platform sits in a lagging jurisdiction will see first-year data reported incompletely or on a shifted timetable.
The amended CRS: what it takes instead
The same directive, through amendments to Annex I of the DAC, introduced the amended version of the CRS into the European Union from the same date, 1 January 2026. The crypto elements of those amendments close precisely the gaps CARF left open by design.
Specified electronic money products and central bank digital currencies are carved out of CARF and brought under the CRS through definitions. Electronic Money is defined by five features — a digital representation of a single Fiat Currency, issued on receipt of funds for the purpose of making payment transactions, represented by a claim on the issuer denominated in the same Fiat Currency, accepted in payment by a person other than the issuer, and redeemable at any time and at par value by virtue of regulatory requirements — with an exclusion for products created for the sole purpose of facilitating the transfer of funds and a sixty-day holding test that delimits that exclusion. Central Bank Digital Currency is defined as any digital Fiat Currency issued by a Central Bank or other monetary authority. Both concepts sit inside the definition of Fiat Currency, while Reportable Crypto-Asset is defined as any Crypto-Asset other than a CBDC, Electronic Money, or a Crypto-Asset for which the provider has adequately determined that it cannot be used for payment or investment purposes. Depository Institution now includes an Entity that holds E-money or Central Bank Digital Currencies for the benefit of customers. A de minimis applies to e-money depository accounts: such an account is not reportable where the rolling average over 90 days of the end-of-day aggregate balance did not exceed USD 10 000 on any day during the calendar year.
Indirect exposure is brought under the CRS by two definitional amendments, both quieter than their effect. Reportable Crypto-Asset was added to the definition of Financial Asset: a Financial Asset now includes any interest — including a futures or forward contract or option — in a Reportable Crypto-Asset. A bitcoin derivative held with a broker is, from that point, an ordinary financial asset in an ordinary account. In the definition of Investment Entity, crypto-assets were added to both limbs: to the list of what an Entity invests, administers or manages on behalf of other persons, and to the test under which gross income is primarily attributable to investing, reinvesting or trading in Financial Assets or Reportable Crypto-Assets where the Entity is managed by another financial institution.
The difference in what is transmitted is material. Crypto exposure that lands in the CRS travels together with the year-end account balance, because it sits in an ordinary financial account with all the standard apparatus. The same economic position taken directly through an exchange travels under CARF with no balance at all. The general mechanics of the CRS and the full content of its report are set out in CRS and automatic exchange.
The United States: a circuit that collects and does not yet share
US digital asset reporting has no connection to international exchange and is structured as ordinary broker information reporting.
Form 1099-DA was introduced in two steps, both set out in the IRS instructions. For 2025 the rule is mandatory gross proceeds and voluntary basis: for each digital asset sale a broker effected for a customer in 2025 the form must be completed, but the broker is not required to report basis information, and where it reports basis voluntarily it is not subject to penalties under sections 6721 or 6722 for failure to report the information correctly. From 2026 the "2026 and beyond" regime applies: mandatory reporting of gross proceeds for all digital assets, mandatory reporting of basis information for digital assets that are covered securities, and voluntary reporting of basis for noncovered securities. For the purposes of the form, a covered security is a digital asset acquired after 2025 for cash, stored-value cards, different digital assets, or any property or services the disposition of which the broker is required to report — acquired in an account for which the broker provided custodial services and held in that account until the broker effects the disposition (Instructions for Form 1099-DA, rev. 18 February 2026).
That definition produces a consequence rarely anticipated: the practical reach of basis reporting builds slowly. An asset acquired in 2024 and sold in 2027 remains a noncovered security, and no basis for it reaches the IRS — or it is reported voluntarily with box 9 checked, which removes the broker's penalty exposure. The instructions also carry thresholds: a broker using the optional reporting method for qualifying stablecoins need not report designated sales unless the customer's aggregate gross proceeds from such sales for the year exceed USD 10 000, and a USD 600 de minimis applies to processors of digital asset payments. Separately, only a US digital asset broker is generally required to report on the form.
The second US storyline is the fate of the DeFi broker rule, and it is of interest for its procedure rather than its outcome. Rule TD 10021, "Gross Proceeds Reporting by Brokers That Regularly Provide Services Effectuating Digital Asset Sales", was published on 30 December 2024 and brought the figure of the digital asset middleman providing a facilitative service within the definition of broker. The House of Representatives passed the joint resolution of disapproval H.J.Res.25 under the Congressional Review Act on 11 March 2025, the Senate on 26 March, and the President signed it into law as Public Law 119-5 on 10 April 2025. The Federal Register publication of 11 July 2025 states the consequences in terms: the rule has no force or effect, and under the CRA a rule that takes effect and is later made of no force or effect by enactment of a joint resolution is treated as though it had never taken effect; the text of the section 6045 regulations was reverted to the text in effect immediately prior to the rule.
The procedural consequence lies in the Congressional Review Act itself and survives any change of administration. Section 801(b)(2) of title 5 of the United States Code: a rule that does not take effect, or does not continue, under a joint resolution of disapproval may not be reissued in substantially the same form, and a new rule that is substantially the same may not be issued, unless the reissued or new rule is specifically authorised by a law enacted after the date of the resolution. Treasury and the IRS therefore cannot restore DeFi broker reporting through their own rulemaking; a new Act of Congress is required.
Meanwhile there are no US CARF implementing regulations at all. A check against the Federal Register API for the term "Crypto-Asset Reporting Framework" filtered to the IRS returns three documents, all of them the broker rules of 2023 and 2024; neither a proposed nor a final CARF regulation has been published. The US commitment on the Global Forum list is a first exchange by 2029, and the CARF-MCAA is unsigned. The asymmetry is the same as FATCA against the CRS: a US platform collects data inward and does not send it out. For a non-US person this is temporarily the least transparent node relative to their home administration; for a US taxpayer the position is reversed.
The United Kingdom: rules and letters
The United Kingdom is in the first wave and implemented CARF through a dedicated statutory instrument — the Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025, SI 2025/744, made on 24 June 2025 and in force from 1 January 2026. The regulations incorporate the CARF rules and commentary by reference, subject to reading the reporting period as a calendar year only, with HMRC publishing the lists of reportable and partner jurisdictions by separate notice.
The timetable and the sanctions are set out precisely.
| Obligation | Deadline | Penalty |
|---|---|---|
| Report to HMRC for a calendar year (reg. 6) | On or before 31 May following; the first by 31 May 2027 for 2026 | Up to £5,000, plus up to £600 for each subsequent day the failure continues after notice of assessment (reg. 14) |
| Registration with HMRC (reg. 10) | The later of 31 May 2027 and 31 January following the first calendar year in which the person falls within the definition | Up to £1,000, plus up to £300 per day (reg. 18) |
| Notification to the user that the information will be reported to HMRC and may be transferred to another jurisdiction (reg. 8) | On or before 31 January following the first reportable year for that user | Up to £100 per person, plus up to £100 per day (reg. 16) |
| Record-keeping of due diligence steps and information collected (reg. 4(2)–(3)) | Five years beginning with the day after the end of the calendar year | Up to £5,000 for each calendar year in which failures occurred (reg. 12) |
| Obtaining a valid self-certification (reg. 4(1)) | Per the Section III procedures of the rules | Up to £300 on the provider per person (reg. 11(2)); up to £100 for other due diligence failures (reg. 11(1)) |
| Provision of a self-certification by the user or a controlling person (reg. 5) | On request by the provider | Up to £300 on the user personally where the failure is deliberate or due to a failure to take reasonable care (reg. 13) |
Two provisions of this instrument stand out. Regulation 13 places a penalty on the user: the UK rules are a rare instance in which an unanswered self-certification is not the platform's problem alone. Regulation 26 is an anti-avoidance rule: where a person enters into arrangements the main purpose, or one of the main purposes, of which is to avoid any obligation under the regulations, the regulations have effect as if the arrangements had not been entered into. It reaches both a client's relocation and a restructuring of the provider itself.
Alongside the legislative layer HMRC works case by case. The department runs a one to many campaign, writing to individuals it believes have disposed of cryptoassets without declaring the resulting gains or income; the letter directs the recipient to the Cryptoassets Disclosure Service and invites anyone who believes nothing is owed to contact HMRC, explain why and provide supporting information. The scale is growing quickly. On figures published by the accountancy firm UHY Hacker Young based on HMRC data, around 65,000 letters were issued in tax year 2024/25 against 27,700 the year before — a 134% increase; the same firm reports approximately 81,000 for the year ended 5 April 2026. These figures do not come from an HMRC publication and should be treated as a professional-firm estimate. What is independently confirmed is that a further wave of letters is being issued between July 2026 and March 2027 — precisely in the interval between the start of CARF data collection and the first provider report due on 31 May 2027.
The chronology is the substance here. The letters go out before HMRC has received a single CARF report: today's campaign rests on data obtained by other means — information requests to platforms, banking flows, earlier voluntary disclosures. The first CARF file will arrive at a department that has already built its list of addressees.
Spanish forms: a different volume of data
Spain is in the first CARF wave, but its own reporting circuit predates it and operates independently. It is instructive because it gives the administration considerably more than the international standard does.
Modelo 172 is the annual information return on balances in virtual currencies. It is filed by persons resident in Spain and permanent establishments of non-residents that provide services safeguarding private cryptographic keys on behalf of third parties, whether as their principal activity or in connection with another. The content is set by Article 39 bis of the General Regulation on tax management and inspection procedures: identification of every person to whom the assets belonged at any point in the year as holder, authorised person or beneficiary, and the balances as at 31 December for each type of virtual currency in units and in euro, stating the quotation used, together with the balances of fiat funds held on behalf of third parties. The filing period is January of the following year.
Modelo 173 is the annual return on transactions. Those obliged to file are persons providing exchange services between virtual currencies and fiat or between different virtual currencies, intermediating in such transactions in any manner, or safeguarding private keys. The key departure from CARF sits in Article 39 ter: the information is given for each transaction — type of transaction, date, type and number of units acquired, transferred, exchanged or moved, the value of the transaction in euro and, where applicable, the associated fees and expenses. The deadline is the same January. The Spanish counterpart to the perimeter carve-out is expressly drafted: the obligation does not extend to persons whose activity is limited to advising on virtual currencies, merely putting interested parties in contact, or simply handling fiat collection and payment orders.
Modelo 721 is the holder's own return on virtual currencies located abroad, under Article 42 quater of the same regulation. The obligation falls on resident individuals and legal persons, permanent establishments of non-residents and entities without separate legal personality; it extends to holders, beneficiaries, authorised persons, persons with power of disposal and beneficial owners within the meaning of the anti-money laundering law. Balances as at 31 December are declared for each type of asset in units and in euro; a person who ceased to hold that status during the year reports as at the date on which it ceased. The threshold is EUR 50,000 in aggregate, and once it is exceeded all assets must be declared. The filing period runs from 1 January to 31 March of the following year, and in subsequent years the return is required again only where the aggregate balance has increased by more than EUR 20,000 against the figure that triggered the previous filing. The forms were approved by Orders HFP/886/2023 and HFP/887/2023 of 26 July 2023.
Setting the Spanish forms against CARF shows how far resolution can vary within a single reporting circuit. CARF gives annual aggregates without balances; Modelo 172 gives balances and Modelo 173 gives transaction-level detail with dates and fees. A client of a Spanish platform is already visible to the administration in detail the international exchange does not contemplate, and the Modelo 721 obligation rests on the holder personally regardless of whether anyone has reported on their behalf.
What the data shows and where visibility ends
| Visible | Not visible in the standard exchange |
|---|---|
| Identity of the client, all jurisdictions of residence, TIN, date and place of birth | Nothing: identification is the most complete part of the file |
| Entity details and each Controlling Person with the role stated | Ownership structure above the level of Controlling Persons |
| Annual turnover by asset type: amounts, units, number of transactions | Individual transactions, dates, counterparties |
| Crypto-to-crypto exchanges at the fair market value of both sides | The gain or loss on them |
| Payments for goods and services exceeding USD 50 000 | Payments below the threshold |
| Value and number of units transferred to wallets not associated with a VASP or financial institution | The recipient address — retained by the provider for five years and available on request |
| Balances — for crypto exposure captured by the CRS, and under Spanish Modelos 172 and 721 | Wallet balances in the CARF file itself |
| Whether a valid self-certification was obtained — under the amended CRS | Tax basis and cost of acquisition |
The temptation to read the right-hand column as a zone of invisibility is strong, and it is the most expensive mistake in this area. The standard is built the other way round: what is absent from the file is either collected and held by the provider or reconstructible from adjacent data.
The wallet address is not exchanged, but it is collected and retained for five years specifically for follow-up requests — paragraph 26 of the Commentary on Section II says so in terms. The balance is not exchanged, but it is derived from the sequence of annual turnover figures set against the tax returns. An individual transaction is not exchanged under CARF, but it is reported under Spanish Modelo 173 where the platform is Spanish. The interval between a withdrawal to a self-hosted wallet and the eventual return to fiat genuinely sits outside the perimeter — but both ends, entry and exit, are observable, and the volume that left is recorded on a separate line for the express purpose of making that interval measurable.
The real limits of the circuit lie elsewhere: where no commitment exists at all, or where an exchange relationship has not been activated. Five jurisdictions identified as relevant have not committed; the United States joins last and has not signed the multilateral agreement; a signature to the CARF-MCAA is not the same as an activated relationship with a particular country. Those limits are dated and shrinking on a published schedule, whereas the "invisibility" of particular fields inside a functioning circuit is a property of the report format rather than a protection.
The presumption layer: what tests good faith
A discrepancy between the tax return and the platform data is the most natural audit trigger, because it is the only signal a tax administration receives automatically and without analysis. The CARF file arrives already sorted by jurisdiction of residence and is matched against the filed return mechanically. The UK one to many campaign is built on exactly that logic and is running already, before the first exchange: the addressee is a person whose disposal the administration can see and whose corresponding declaration it cannot.
The indicators below are orientation points rather than a finished verdict; each is tested against the facts and the law of the relevant jurisdiction.
| Supports good faith | Reads against the position |
|---|---|
| The self-certification on every platform is current, lists all jurisdictions of residence with tax identification numbers, and contains an undertaking to notify changes | The residence declared to the platform years ago has diverged from the actual position — the file travels to the wrong country and leaves a gap in the right one |
| Independent records of basis and transaction history are maintained separately from the platforms and cover the years before exchange began | No basis records exist; against gross proceeds in the file, the entire turnover becomes taxable by default |
| Crypto-to-crypto exchanges are reflected in the return as disposals at the fair market value of both sides | The return reflects only fiat exits and omits crypto-to-crypto exchanges, which appear in the file on their own line |
| Large disposals have a previously declared acquisition history | A large disposal with no trace of acquisition in prior periods |
| Transaction history exports were collected in advance, before a platform left the market or an account was closed | The archive was lost with the platform, leaving nothing to evidence acquisition |
| National returns are filed on time where the obligation rests on the holder personally, as with Spanish Modelo 721 | The holder's own obligation is left unperformed on the assumption that the provider will report |
| Prior-year discrepancies are resolved through a voluntary disclosure mechanism before the data arrives | Disclosure begins after a letter or an enquiry — by which point the mechanism has spent its value |
The asymmetry runs one way and is worth stating plainly. Gross amounts reach the administration on their own; the cost of acquisition reaches it through none of the three circuits and is produced only by the holder. Independent record-keeping remains the only available means of turning turnover into a result.
Q/A
Perimeter and obliged persons
We build a non-custodial protocol and hold no client funds. Are we caught by CARF?
Solely creating or selling software or an application does not make a person an obliged person — paragraph 26 of the Commentary on Section IV(B) says so directly, subject to the qualification "as long as it is not using such software or application for the provision of a service effectuating Exchange Transactions for or on behalf of customers". Validating distributed ledger transactions is also outside the perimeter under paragraph 24, even where the validation is remunerated. The contested zone opens where the same team launches an interface through which customers effectuate exchanges: under paragraph 27 a person is treated as making available a trading platform to the extent it exercises control or sufficient influence over it, and whether such influence exists is assessed in a manner consistent with the FATF Recommendations on virtual assets. The tax question is therefore decided by the same test as VASP status, and the two answers should agree.
A fund holds crypto-assets. Who reports — the fund or its administrator?
Neither, in that capacity, under CARF: paragraph 23 of the Commentary states that the activities of an investment fund investing in Relevant Crypto-Assets do not constitute a service effectuating Exchange Transactions, since they do not permit investors in the fund to effectuate such transactions. That does not take the structure out of reporting; it moves it to another layer. The amended CRS added crypto-assets to both limbs of the Investment Entity definition — to the list of what an Entity manages on behalf of other persons, and to the test on the primary source of gross income where the Entity is managed by another financial institution. An investor in the fund is reported as an Equity Interest holder, and that interest travels with the year-end balance.
The platform is established in a second-wave jurisdiction but serves us through an EU branch. When does reporting start?
For transactions through the EU branch, from the first wave. Section I(B) of the standard attributes a provider to a jurisdiction in respect of Relevant Transactions effectuated through a branch located there, irrespective of where it is resident; in the European Union the DAC8 rules apply from 1 January 2026. Sections I(C) to (H) remove duplication in the other direction — they relieve the provider from reporting under a weaker nexus where the same requirements are completed in a Partner Jurisdiction under a stronger one, and Section I(H) allows the obligation to be discharged by notification that the report is filed under the rules of a Partner Jurisdiction. The outcome depends on the particular combination of nexus points, so the legal entity, its residence, its place of management and the branch through which the service is provided all need to be checked.
Content of the data
Will my exchange account balance as at 31 December be exchanged?
Not under CARF. Section II(A) sets out the content of the report as a closed list: identification of the client and of Controlling Persons with their roles, plus annual aggregates by asset type and transaction category. There is no balance field in that list, and this is a structural difference from the CRS, where the year-end balance is the core of the report. The corollary is that zeroing the position by 31 December changes nothing, because the report is built on transactions across the whole year. Balances may still travel on other grounds — under the CRS where the exposure is wrapped in a financial product, and under national rules such as Spanish Modelo 172.
I move assets to my own wallet. What exactly will the platform report?
The aggregate fair market value and the aggregate number of units transferred to addresses not known to the platform to be associated with a virtual asset service provider or financial institution as defined in the FATF Recommendations. There is no transaction count in that line. The address itself is not part of the standard exchange, but under paragraph 26 of the Commentary on Section II the provider must collect and retain it for not less than five years, precisely so that a tax administration can obtain it later through a follow-up request. The purpose of the line is stated in paragraph 21 of the introduction to the standard: to indicate the volume that has left observation, so that detail can be requested where concerns arise.
The account is held by a company. Will I be identified personally?
Yes, where after the due diligence procedures the company is identified as an Entity with Controlling Persons who are Reportable Persons and is neither an Active Entity nor an Excluded Person. The file carries the company's details and, for each Controlling Person, name, address, jurisdictions of residence, TIN, date and place of birth — plus the role by virtue of which the person is a Controlling Person. The role travels as a separate field, and that detail matters: the receiving administration sees a settlor, a trustee or a protector rather than an undifferentiated "controlling person".
United States, United Kingdom, Spain
The DeFi broker rule was repealed. Can it come back?
Not by the same route. H.J.Res.25 passed the House on 11 March 2025 and the Senate on 26 March, and was signed as Public Law 119-5 on 10 April; in the Federal Register publication of 11 July 2025 Treasury and the IRS record that the rule has no force or effect and that, under the Congressional Review Act, it is treated as though it had never taken effect. Section 801(b)(2) of title 5 of the United States Code prohibits reissuing a rule disapproved in that way in substantially the same form and issuing a substantially similar new rule, unless specifically authorised by a law enacted after the date of the resolution. A return is therefore possible only through an Act of Congress, not through agency rulemaking.
Will a US exchange report my cost basis to the IRS?
From 2026, yes, but only for covered securities. The Instructions for Form 1099-DA define a covered security as a digital asset acquired after 2025 in an account for which the broker provided custodial services and held in that account until the broker effects the disposition. For 2025 basis was reported voluntarily. Hence a practical inertia: an asset acquired before 2026 remains noncovered whatever the sale date, and no basis for it reaches the IRS unless the broker reports it voluntarily with box 9 checked. It is also worth remembering that only a US broker is generally required to file, and that this is domestic reporting — the United States has not signed the CARF-MCAA and joins the exchange in 2029.
HMRC has written to me, but there has been no CARF exchange yet. Where does the data come from?
From other sources. The one to many campaign has been running since 2021 and is addressed to persons whose disposals of cryptoassets HMRC can see without a corresponding declaration; the letter points to the Cryptoassets Disclosure Service and invites anyone who believes nothing is owed to explain why and provide supporting information. The first CARF report from UK providers is not due until 31 May 2027 for 2026, while the current wave of letters is being issued between July 2026 and March 2027 — that is, ahead of it. The first CARF file will therefore arrive at a department whose list of addressees has already been assembled by other means.
A Spanish platform — is that also just annual aggregates?
No, substantially more. Modelo 172, under Article 39 bis of the General Regulation on tax management and inspection procedures, requires balances as at 31 December for each type of virtual currency in units and in euro, plus balances of fiat funds held for third parties. Modelo 173, under Article 39 ter, requires information on each transaction: type, date, type and number of units, value in euro, fees and expenses. Both are filed in January. Separately, Modelo 721 is the holder's own return on virtual currencies located abroad where the aggregate balance at 31 December exceeds EUR 50,000, filed between 1 January and 31 March; a repeat filing is required only where the aggregate balance has increased by more than EUR 20,000 against the previous one.
What to do about it now
The exchange is not retrospective. Can prior years be left alone?
Nothing will be transmitted automatically for 2021 to 2025: the first reporting year in the first wave is 2026. But the 2026 picture will be read against the history, and a large disposal with no previously declared acquisition is a ready-made question whatever year the acquisition falls in. National obligations are not limited to the forward period either: Spanish Modelo 721 has applied since the 2023 reporting year, and the UK letter campaign has worked on prior periods since 2021. Voluntary disclosure mechanisms retain their value only until the data has reached the administration, and the interval before the first exchange is that window.
What exactly should be assembled in advance?
Three things, none of which reconstructs well. An inventory of the perimeter: every platform, custodian, payment service and wallet provider, with two answers for each — is it an obliged person and in which jurisdiction — and a check on the residence declared in the self-certification. Basis records: gross amounts reach the administration on their own, while the cost of acquisition reaches it through no circuit and is produced only by the holder. And transaction history exports — some platforms are leaving the European market under MiCA, and the archive leaves with them.
The residence I gave an exchange three years ago is out of date. How much does that matter?
It is the address to which the file will travel. Section III of the standard requires the provider to obtain a self-certification and confirm its reasonableness on the basis of the information available, including documentation collected under AML/KYC procedures; on a change of circumstances that causes the provider to know, or have reason to know, that the original self-certification is incorrect or unreliable, it may no longer rely on it and must obtain a valid one or a reasonable explanation with supporting documentation. The amended CRS additionally introduced a reporting field recording whether a valid self-certification was obtained. An out-of-date certification produces a double effect: the data reaches a country where the person is no longer resident and does not reach the one where they must declare. The UK regulations add a penalty of up to £300 on the user personally for a deliberate failure to provide a self-certification or a failure to take reasonable care.