Skip to content
EU-wide

CARF explained — the OECD crypto-asset reporting framework, and how it lines up with DAC8

Fintech Passport
August 16, 2026 · 12-min read
CARF explained — the OECD crypto-asset reporting framework, and how it lines up with DAC8

Most crypto firms in the EU are building for DAC8 and assuming that covers everything. It does not. DAC8 is the EU’s copy of an OECD standard — the Crypto-Asset Reporting Framework — and the copy governs only the EU leg. The moment a group has an entity, a branch, a management team or a support office outside the Union, the OECD text and its separate exchange machinery decide where else it files. Below: what CARF requires, how its scope rules differ from DAC8’s, and where the two give different answers for the same business.

1. What CARF is, and what it is not

The Crypto-Asset Reporting Framework was approved by the OECD on 8 June 2023 as part of International Standards for Automatic Exchange of Information in Tax Matters — Crypto-Asset Reporting Framework and 2023 updates to the Common Reporting Standard, endorsed by the G20 in the New Delhi Leaders’ Declaration of 9–10 September 2023 and adopted by the Global Forum as an international standard. In practice “the CARF” means four things read together: the rules, their Commentary, the CARF Multilateral Competent Authority Agreement (CARF MCAA), and its Commentary.

CARF is not itself law anywhere. It is a template each committed jurisdiction writes into its own legislation, plus a mechanism through which those jurisdictions exchange what their firms report. DAC8 — Council Directive (EU) 2023/2226 — is the European version: Annex VI reproduces the CARF rules for the 27 member states, with a handful of EU-specific additions. A firm operating only inside the Union can work from DAC8 alone. A firm with any presence outside it cannot, because the jurisdiction that captures it may not be one the EU rules reach.

2. Who is a Reporting Crypto-Asset Service Provider

Section IV.B(1) of the CARF defines a Reporting Crypto-Asset Service Provider as any individual or entity that, as a business, provides a service effectuating Exchange Transactions for or on behalf of customers — including by acting as a counterparty to those transactions, by acting as an intermediary to them, or by making available a trading platform. Three features of that definition catch people out.

  • It covers individuals, not only entities. A sole trader running an over-the-counter desk is inside.
  • It is functional, not licence-based. Nothing turns on holding an authorisation. A firm that is not a crypto-asset service provider under Regulation (EU) 2023/1114 and not a virtual asset service provider under the FATF Recommendations can still be an RCASP — a dealer in certain non-fungible tokens is the standard illustration.
  • It is wider than the CRS population. The Common Reporting Standard applies to Financial Institutions; CARF to RCASPs. The sets overlap but neither contains the other, and many RCASPs have never collected tax information from a customer.

3. Nexus — the rule that decides where you file

This is the part with no DAC8 equivalent for non-EU territory, and the part most often got wrong. Section I of the CARF makes an RCASP subject to due diligence and reporting in a jurisdiction on any of four grounds, and where more than one applies the criteria are ranked in the order in which they appear.

RankNexus criterionWhat it turns on
1Resident for tax purposes in the jurisdictionEntity or individual; ordinary tax residence
2Incorporated or organised under the laws of the jurisdiction and either has legal personality there or must file tax or tax-information returns there on its own incomeBoth limbs required — incorporation alone is not enough
3Managed from the jurisdictionDeliberately broader than “place of effective management”
4Has a regular place of business in the jurisdictionDeliberately broader than “principal place of business”; a standing customer-support site can qualify

Section I also carries a tie-break where the same nexus arises in two or more Partner Jurisdictions, and special rules for an RCASP that effectuates Relevant Transactions through a branch. The consequential point, which the OECD states plainly, is that CARF requires fewer connections to a jurisdiction than the traditional tests for tax residence or permanent establishment. An RCASP can therefore owe CARF reporting to a jurisdiction it pays no tax in and files nothing else with.

Facts: a crypto exchange is incorporated and tax-resident in an EU member state, files DAC8 there, and runs a 30-person customer-support and trade-surveillance office in a third country that has committed to CARF. Rule: the primary nexus is tax residence in the member state, so that is where reporting sits; but the third-country office is capable of being a “regular place of business” under criterion 4, and a lower-ranked nexus still has to be resolved rather than ignored. What the team does: maps every location where staff sit or management decisions are taken against the four criteria, records the ranking analysis in writing, and checks the third country’s implementing law for how it applies the hierarchy where a higher-ranked nexus exists elsewhere. Outcome: a documented single filing jurisdiction, and a defensible answer if the third-country authority asks why it never received a return.

4. What gets reported

CARF is transaction-based — its sharpest structural difference from the CRS, which asks annually for account balances, payments and sale proceeds. CARF asks for transactions, reported per user, aggregated by type of Relevant Crypto-Asset and split by transaction type. DAC8 reproduces the taxonomy in Annex VI.

CategoryCoversReported as
Exchange Transaction — against fiatAcquisitions and disposals of reportable crypto-assets against fiat currencyAggregate gross amount paid or received, aggregate units, number of transactions
Exchange Transaction — crypto for cryptoExchanges between one or more forms of reportable crypto-assetAggregate fair market value, aggregate units, number of transactions
TransfersMovements to or from an address or account not maintained by the provider for the same userAggregate fair market value and units, subdivided by transfer type where known
Reportable Retail Payment TransactionsTransfers in consideration of goods or services above USD 50 000 (or the equivalent in another currency)A separate category of aggregate information

Two details inside the retail-payment line do real work. If the provider acts as the merchant’s agent, the movement is reported as an ordinary transfer, not a Reportable Retail Payment Transaction. But if the provider is required by domestic anti-money-laundering rules to verify the identity of the merchant’s customers, it must treat those customers as its own Crypto-Asset Users and report the transaction as a retail payment transaction with respect to them. Transfers below the threshold are not dropped: they roll into the ordinary transfer aggregates.

DAC8 adds a line with no CARF counterpart in the same words. Annex VI, Section II, requires the aggregate fair market value and number of units of transfers the provider effectuates to distributed-ledger addresses, within the meaning of Regulation (EU) 2023/1114, not known to be associated with a virtual-asset service provider or a financial institution — an unhosted-wallet exposure figure inside a tax return. Firms already tagging counterparty wallets for travel-rule purposes have most of the classification logic.

5. Due diligence and self-certification

Identification runs on self-certifications: the user states tax residence and tax identification numbers, the provider tests that statement for reasonableness against what it already holds, including its AML/KYC file, and treats users as Reportable Users on that basis. Entities are pushed through to controlling persons, assessed in their own right. The parallel with the CRS is deliberate: a firm that is both a Financial Institution and an RCASP should run one identity file, not two.

Facts: a payments group operates an e-money institution and, in a separate subsidiary, a crypto brokerage. The EMI already holds CRS self-certifications for its customers; the brokerage has onboarded most of the same people with AML documentation only. Rule: CARF and DAC8 both permit reliance on validly obtained self-certifications, and the CRS due-diligence file is built to the same identity concepts. What the team does: reconciles the two customer books, identifies the population with a CRS self-certification and no CARF one, and runs targeted re-papering rather than full re-onboarding — confirming the existing certifications cover the entity that will file. Outcome: a much smaller outreach exercise and a documented reliance position. See CRS for EMIs for the financial-institution side of the same test.

6. The timetable, and who is actually on it

Fifty-nine jurisdictions adhered to a Joint Statement declaring their intent to implement CARF in time to begin exchanges in 2027. By the 2024 Global Forum plenary, around 60 had committed to exchange in 2027, or in 2028 where they face particular challenges with the earlier date. That two-speed reality matters: a 2028-track jurisdiction has a later domestic go-live, and an exchange relationship needs both ends.

The OECD’s sequencing rule is the one to plan against: domestic law has to be in place and take effect from the start of the calendar year before the first year the jurisdiction commits to exchange. For a 2027 exchange, that means rules effective from the beginning of 2026 — exactly what the EU has done.

DateWhat happensSource
31 December 2025Member states adopt and publish the implementing laws; the Commission establishes the Crypto-Asset Operator registerArt 2(1) DAC8; Art 8ad(10)
1 January 2026DAC8 provisions apply; first reporting period beginsArt 2(1) DAC8
Calendar year 2027First reports filed — the directive requires annual reporting in the calendar year following the year reported on; the exact domestic filing date is set by each member stateAnnex VI, Section II, para D
Within nine months of year-endCompetent authorities exchange the information on the standard computerised form — so by end-September 2027 for 2026 dataArt 8ad(6) DAC8

On the OECD side, exchange relationships are not automatic. The CARF MCAA works like the CRS MCAA: it is multilateral, but each bilateral relationship activates only where both jurisdictions have the Convention on Mutual Administrative Assistance in Tax Matters in force and in effect, have lodged the required CARF MCAA notifications with the Co-ordinating Body Secretariat, and have each listed the other as an intended exchange partner. Until that last step, a committed jurisdiction is still not a partner.

7. Where CARF and DAC8 diverge for an EU firm

The reporting content is deliberately aligned, so the divergences are structural rather than field-level.

  • Registration for non-EU operators. DAC8 requires crypto-asset operators outside the scope of Regulation (EU) 2023/1114 that report on Union-resident users to register in one single member state. That member state allocates an individual identification number and notifies it electronically to every other member state. There is no CARF analogue — the OECD text relies on nexus alone.
  • De-registration as an enforcement tool. Where such an operator fails to report after two reminders, the member state of single registration must revoke the registration — not later than 90 days, but not before 30 days, after the second reminder. Member states also coordinate enforcement, with preventing the operator from operating in the Union named as a last resort.
  • The third-country equivalence route. Under Article 8ad(11), the Commission determines by implementing act whether information exchanged under an agreement between a member state and a non-Union jurisdiction corresponds to what Annex VI requires. Where an effective qualifying competent authority agreement is in place with a Qualified Non-Union Jurisdiction, an operator can report on Union-resident users to that jurisdiction instead, and it passes the data on. That is the mechanism preventing the same customer being reported twice — check it before assuming a group needs parallel filings.
  • The schema. The OECD publishes a CARF XML Schema and User Guide, updated in July 2025, plus a separate CARF Status Message XML Schema for responses. These are built for authority-to-authority exchange, but jurisdictions may also mandate them for domestic reporting by RCASPs — so whether you build to the OECD schema or a national variant is a question for the implementing law. Our DAC8 XML reporting piece covers the EU-side data build.

8. What to do, today

  • Run the nexus test on the group, not the entity. List every place where staff sit, where management meets and where the business is organised; rank against the four Section I criteria and write the conclusion down.
  • Check the equivalence position before designing parallel filings. A Qualified Non-Union Jurisdiction route for your non-EU entity changes the architecture entirely.
  • Confirm the single-registration obligation. If any group entity reports on Union-resident users without falling under Regulation (EU) 2023/1114, pick the member state of registration deliberately — it becomes your enforcement counterparty.
  • Reconcile the CRS and CARF customer books now. Self-certification gaps take months to close and cannot be compressed into the filing quarter.
  • Build the four transaction buckets into the ledger, including the USD 50 000 retail-payment split and the unhosted-address aggregate. Both are classification problems in the transaction pipeline, not report-writing problems.
  • Track your partner list, not just your own status. An exchange relationship needs notifications and mutual listing at both ends.

9. FAQ

Is CARF the same thing as DAC8?

No. CARF is the OECD standard; DAC8 (Council Directive (EU) 2023/2226) is the EU’s implementation of it in Annex VI. The reporting content is deliberately aligned, but DAC8 adds EU-specific machinery — single-member-state registration for non-MiCA operators, the Commission’s Crypto-Asset Operator register, and the Qualified Non-Union Jurisdiction route — and it only governs the Union leg.

When do the first CARF exchanges happen?

The first group of jurisdictions is expected to begin exchanging in 2027, with some on a 2028 track where they face particular implementation challenges. In the EU, DAC8 applies from 1 January 2026, reports are filed in the following calendar year, and competent authorities exchange within nine months of year-end.

We hold a MiCA authorisation. Does that settle whether we are an RCASP?

Not by itself. The RCASP definition is functional — providing a service effectuating Exchange Transactions as a business — and is broader than both the MiCA CASP perimeter and the FATF virtual-asset-service-provider definition. A MiCA authorisation does mean you fall outside the separate DAC8 category of crypto-asset operators required to register in a single member state.

What is the USD 50 000 threshold for?

It separates Reportable Retail Payment Transactions — transfers in consideration of goods or services above that value — from ordinary transfers, and they are reported as a distinct category. Transfers below the threshold are not excluded; they fold into the general transfer aggregates.

Can we rely on our existing CRS self-certifications?

Often, in part. CARF and the CRS use the same identity concepts, so a valid self-certification can support both — but confirm it was obtained by the entity that will make the CARF filing and covers the required tax residences and identification numbers. The practical exercise is a reconciliation of the two customer books plus targeted outreach, not a full re-onboarding.

Our group has an office outside the EU but no legal entity there. Are we exposed?

Possibly. Nexus criteria 3 and 4 — managed from the jurisdiction, or a regular place of business there — are drafted more broadly than the tests for effective management or permanent establishment, and the OECD is explicit that a provider can owe CARF reporting to a jurisdiction it does not otherwise pay tax in.


Related: DAC8 explained · DAC8 XML reporting · CRS for EMIs · DAC7 platform reporting

Related reads.