Taxbit Blog

The CARF & CRS Compliance Wall: One Wave of Regulation, Not Two Deadlines

Written by Taxbit Team | Sep 25, 2026, 6:31:00 PM

Before either acronym matters, there's a simpler question: is your business in scope for CARF, for CRS 2.0, both, or not in scope for either just yet? The two regimes impact entities differently, so it isn't automatic just because a business touches digital assets or cross-border accounts. A crypto exchange or custodian is typically thinking about CARF while a bank, e-money issuer, or fund administrator with reportable financial accounts is typically thinking about CRS 2.0. A growing number of platforms doing both end up owing determinations under each.

While the two regimes are legally distinct, the work preparing and executing them should not be. Automatic exchange of financial account information between countries has been expanding for more than a decade, from traditional accounts to digital assets now. CARF and CRS 2.0 are the latest expansion, arriving as two pieces of legislation instead of one. They aren't the only pieces of that wall, but they're the two that share an OECD process, a start date, and, in practice, a project plan that usually gets split in two anyway.

The timelines don't match, and that's the point

Two clocks are running here, not one:

    • January 1, 2026 — Documentation commences for both CARF and CRS 2.0, across every Wave 1 adopting jurisdictions.
    • 2027 — Wave 1 reporting and cross-border exchanges begin.
    • 2027 — Documentation commences for both CARF and CRS 2.0, across every Wave 1 adopting jurisdictions.
    • 2028 — Wave 2 reporting and cross-border exchanges begin.

To see where you stand on CARF and to view adoption status, reporting timelines, registration requirements, and enforcement details, use our regulatory tracker.

CARF and CRS 2.0 were negotiated together but adopted independently by each jurisdiction. A business operating across borders can be in scope for CARF in one country and CRS 2.0 in another, on different clocks, for products sitting in the same internal system. No single date covers both regimes everywhere, so waiting for "the deadline" isn't a plan. A current map of products, data, and ownership applies to whichever framework a given jurisdiction and asset combination actually triggers, instead of getting rebuilt every time a new date arrives.

Start with the product, not the framework name

Rather than asking whether the company is in scope for CARF or CRS 2.0, effective scoping requires breaking the analysis down into at least three distinct steps:

    • Jurisdiction: Map every location where the entity operates, holds licenses, or serves customers. Obligations change based on local implementations of CARF and CRS 2.0.
    • Type of Entity: Categorize the legal structure of each business unit (e.g., Reporting Financial Institution, Crypto-Asset Service Provider, or Investment Entity). One parent company often operates multiple distinct entities, each carrying separate reporting duties.
    • Product Activity: Inventory the specific functions of every product and service offered—such as custodial exchange, stablecoin issuance, or crypto fund exposure. A single company may handle multiple products, and each requires its own classification based on what it actually does.

Only after mapping these three variables can you determine which compliance framework applies and what specific reporting is required.

One data foundation, two reporting outputs

Once the product-to-obligation mapping is done, both frameworks draw on the same underlying data:

    • Customer Data: data collected via the required self-certifications collected at onboarding, and monitored downstream throughout the year.
    • Transaction or Account Balance information: data related to products and associated platform activity.

Given the nature of these filings and source data, a business can have clean data for one report and still be incomplete for another. A shared foundation removes the duplicate collection effort, not the need to file two distinct reports.

Shared operational readiness

The readiness sequence holds no matter which framework hits first in a given jurisdiction.

Data collection requirements are already running, so the first challenge is already underway. The next step will be to ensure there is clarity and visibility on where the relevant transaction data lives, and assign ownership for the upcoming filing deadlines across teams. An important step towards readiness will also be understanding the variation between the OECD standard itself, from what's locally required.Testing the complete reporting workflow and its output end-to-end well before the deadline is critical, as an unexecuted workflow remains an unproven compliance risk.

The first filing deadlines start in early 2027. A second wave of compliance actions follow a year behind in early 2027 with data collection and filing for Wave 2 jurisdictions. The same workflow should be replicated, without rebuilding what the first wave already proved out.

Document how each classification and reporting decision got made while the reasoning is still fresh. That record is what a team points to when a regulator asks how a determination was reached, and it's harder to reconstruct after the fact than to capture as the decision is made.

This wave won’t be the last

The data collection clock is already running. The first reporting cycle commences in 2027 for Wave 1 jurisdictions. Automatic exchange of information hasn't stopped expanding since 2014, and there's no reason to expect CARF and CRS 2.0 are the last stop.

A shared view of products, data, and ownership outlasts this particular cycle. It's the same thing teams will need the next time this expansion reaches a part of the business it hasn't reached yet.