CARF Readiness: Determining Scope and Taking First Steps

September 24, 2026 00:21:20
CARF Readiness: Determining Scope and Taking First Steps
A&M Tax Talks: Tax Policy Updates
CARF Readiness: Determining Scope and Taking First Steps

Sep 24 2026 | 00:21:20

/

Show Notes

For crypto-asset businesses that have not yet started implementing CARF, the first step is not necessarily to build a reporting engine. It is to determine whether the business is in scope, which entities and products require analysis, and what information is needed to support a defensible conclusion.

In this episode, Mercy Joseph, Managing Director in Singapore, and Chris Kotarba, Managing Director in the United States, discuss practical steps for assessing CARF readiness. They explore how to identify whether a business may be a Reporting Crypto-Asset Service Provider, why contractual labels and product names can be misleading, and why businesses should follow the full transaction chain when determining reporting obligations.

The discussion also considers the interaction between CARF, CRS 2.0 and Form 1099-DA, including the need for a common customer and transaction-data foundation while maintaining separate rules and reconciliation processes for each regime. Mercy and Chris also highlight the importance of governance, including clear accountability across Tax, Compliance, Legal, Operations, Data and Technology.

View Full Transcript

Episode Transcript

[00:00:00] Speaker A: Foreign. [00:00:04] Speaker B: For those of you who have not yet started implementing calf, listen in for more information on how to tell whether CALF applies to you and what you can do. If you are starting only now, the good news is that you do not need to start with a fully built reporting engine. The more practical starting point is to understand whether you are in scope, whether your obligations might arise, and what information you need to support that conclusion. I'm Mercy Joseph, a Managing Director with A and M in Singapore. [00:00:38] Speaker A: And I'm Chris Kattarba, Managing Director with A and M in the US Today [00:00:43] Speaker B: we are going to work through that assessment in a practical way how to identify whether a crypto business may be a botting crypto asset service provider, why transaction chains and product labels can be misleading, how CAF interacts with Form 1099DA in the US and what late starters should prioritize now. [00:01:05] Speaker A: Mercy if a business is starting only now, what's the first question it should ask? [00:01:11] Speaker B: The first question is whether the business or any entity in its group could be a reporting crypto asset service provider or rcas, that is the person or entity that may have due diligence or reporting obligations under CUFF because of the role it plays in effectuating relevant crypto asset transactions. A smaller broker, OTC desk, intermediary or platform may not think of itself as an exchange. It may not hold customer assets and it may use a third party exchange or custodian to execute or settled transactions. But if it is receiving customer instructions, arranging or routing transactions, acting as a counterparty, or otherwise playing a substantive role in bringing the transaction about, its position requires proper examination. So a late starter should not begin by asking are we regulated? It should ask what role do we actually play in the transaction? A license may tell us that an entity is authorized to conduct a particular regulated activity. It does not necessarily tell us whether that entity is effectuating exchange transactions for or on behalf of customers for CAF purposes. Similarly, having strong AML and KYC controls does not itself determine whether an entity is an RCASP or satisfy all the tax, due diligence and reporting requirements that may apply. [00:02:45] Speaker A: Being smaller, regulated or non custodial does not create an automatic exemption exactly. [00:02:52] Speaker B: It may ultimately be outside the reporting definition. But that conclusion should come from a documented analysis of its activities, not from its size, license, or the assumption that the business is already above board. CAF is not intended only for businesses that are unregulated or difficult to identify. The framework asks whether what services the entity performs and what role it plays in the relevant transactions. [00:03:19] Speaker A: Once a business has looked at its own role. What is the next mistake late starters should avoid? [00:03:26] Speaker B: The next mistake is assuming that another party in the transaction chain will take care of the reporting. Imagine that a customer is onboarded by Entity A. Entity A receives the customer's instructions and routes the order to an external exchange. The assets are held by a third party custodian, while another provider processes the fiat payment. The customer may see one seamless service, but the transaction involves several different parties performing different functions. The existence of the external exchange does not automatically relieve Entity A equally the involvement of the custodian does not mean that the custodian necessarily has the reporting obligation. We need to look at each participant [00:04:12] Speaker A: separately and for a business that has not yet started, how should it break down that analysis? [00:04:21] Speaker B: I would frame the analysis around whether each party is as a business providing a service that effectuates relevant crypto asset transactions for or on behalf of customers. In practical terms, that means looking at four connected areas. First, the customer relationship who onboards the customer, receives the instructions, has the contractual relationship. Second, the transaction function who accepts, routes, matches, executes, settles, or acts as a principal in the exchange or transfer Third, the control and information position who has visibility over the customer, wallet, asset, transaction, and valuation data needed for due diligence and reporting and fourth, the commercial role who earns the fee, spread, commission, or other consideration for making the transaction happen. A provider that merely supplies generic outsourced technology, hosting software, or back office support may be in a different position from a provider that is substantively involved in effectuating the transaction. But we should be careful not to stop at contractual descriptions. The documented analysis should compare the agreements, operating model, system flows, and data records to determine what each participant actually does and whether duplicate reporting, relief, reliance provisions, or domestic implementation rules may apply. [00:05:55] Speaker A: More than one participant potentially fall within the definition? [00:06:00] Speaker B: Potentially, yes, depending on the respective functions and the applicable domestic rules. The answer is not necessarily that everyone reports, but neither should one participant assume that another person's involvement removes its own obligations. The analysis should also examine whether any domestic relief, reliance provision or approach to preventing duplicate reporting applies. The most useful question is not simply who touches the crypto, it is what does each participant do to bring the transaction about? [00:06:38] Speaker A: How should a business capture this? Practically, if it's starting from a blank [00:06:41] Speaker B: page, I would say start with a transaction map. A conventional funds flow diagram is helpful, but for CAF it may not be enough. The map should show the movement of fiat and crypto, but it should also capture the four themes we just discussed. Customer instruction, contracts, execution and settlement, custody and data and the fee or spread earned by each participant. The contractual position must then be compared with the operating reality. The customer agreement may name one service entity, but transaction and system records may show that another entity accepts the order, sets the price, or acts as the counterparty. That is where detailed examination frequently produces a different answer from the one initially assumed. [00:07:31] Speaker A: If the business concludes that another intermediary is responsible, [00:07:38] Speaker B: it should retain a documented basis for that conclusion. This would include the relevant agreements, role and transaction analysis, jurisdictional nexus assessment, and the legal basis for any reporting, relief or reliance on another participant someone else will report is not a control. The business needs to establish who that person is, why that person is responsible, and whether the first business retains any obligations of its own. [00:08:10] Speaker A: Great after the transaction chain has been mapped, what should late starters do next? [00:08:17] Speaker B: They should classify the entities involved, but not by relying on names, licenses, or group structure alone. Within the same group, one entity may operate a platform, another may issue a token. A third may provide custody. Another may act as principal in OTC transactions. They may also be separate technology company or customer facing service entity. Each entity must be considered according to its own activities and the jurisdictions in which it has a relevant nexus. We should ask is the entity an rcas? Does it have a separate entity classification under cafe? Could it also be a reporting financial institution under CRS 2.0? In which jurisdiction or jurisdictions might it have registration, due diligence, or reporting obligations? Does the entity perform more than one role? Are activities performed directly through a branch or through another group company, and does the contractual allocation of functions match what is happening in practice? [00:09:27] Speaker A: What you're saying is even identifying an RCASP doesn't complete the assessment. [00:09:33] Speaker B: That's right. RCASP status is the beginning of the obligations analysis, not the end. The group still needs to determine the relevant jurisdiction products, services, customers, and transactions, as well as how any overlapping CAF and CRS 2.0 obligations should be managed. [00:09:54] Speaker A: And does the same approach apply when a business is trying to work out which products are in scope? [00:10:01] Speaker B: Very much so. Take a stablecoin. The business may assume that the word stablecoin determines the reporting treatment, but it is a commercial label, not the final tax reporting classification. The analysis may require us to consider whether the token references a single fiat currency, whether it is redeemable at par, whether redemption is available at any time, which entity carries the redemption obligation, et cetera. That conclusion can affect whether the product falls under CAF, CRS 2.0, or potentially outside both regimes. Broadly, CAF is aimed at tax relevant information on relevant crypto asset transactions, while the amended CRS brings certain electronic money products, central bank digital currencies, and indirect crypto exposures through derivatives or investment vehicles into the CRS framework. So the classification exercise should not ask only is this a crypto asset. It should ask whether the product is a relevant crypto asset for CAF, a financial account or covered product for CRS 2.0, a specified electronic money product or something that requires a documented out of scope conclusion. The same principle applies to tokenized financial assets, custody, staking, lending and other digital services. The product name tells us how it is marketed. Its rights, functions and legal terms tell us how it may be reported. That product discussion also leads naturally to the broader multi regime challenge. A single digital asset product may need to be considered Under CAF CRS 2.0 and where there is U.S. exposure, Form 1099DA if a group has U.S. customers, U.S. brokers, U.S. entities, or U.S. transaction flows, it may also need to consider the Form 1099 DA rules alongside CAF and CRS 2.0 analysis. So Chris, when a business looks at CAF and form 1099DA side by side, is it fair to think of form 1099DA as simply the US version of CAF? [00:12:23] Speaker A: The tempting shortcut, Especially because both regimes are concerned with digital asset information reporting and both depend on good customer and transaction data. But the two regimes should not be treated as interchangeable. Form 1099BA is a US information return under the Digital Asset Broker Reporting Rules. HARF is an international reporting and automatic exchange framework that will be implemented through participating jurisdictions. Unlike CARF, where the first deadlines aren't until 2027, Form 1099 DA reporting is already well underway under the US rules, gross proceeds reporting applies to relevant digital asset sales from January 1, 2025. Basis reporting applies to certain covered assets for transactions from January 1, 2026. But cost basis is not the only difference. The regimes can differ in their definitions of the reporting provider, the customers in scope, the customer information collected, transaction categories, transfers, aggregation, and the information reported. [00:13:32] Speaker B: So the practical point is not just whether the product is in scope under caf. It is whether the same product, customer or transaction may have to be analyzed Under CAF CRS 2.0 and for US connected activity, form 1099DA. If a group is starting now and also has US exposure, what should it avoid? [00:13:55] Speaker A: It should avoid two extremes building two completely disconnected processes or forcing form 1099 DA and CARF into one rulebook simply because both relate to digital assets. The better model is a common governed customer and transaction Data foundation followed by separate rule layers for Form 1099 DA and CARF. The group should then be able to identify transactions reported only on Form 1099DA, transactions reported only under CARF, transactions covered by both, and transactions captured by neither together with the reason. A comparison of final totals tells you that the two reports differ. A rules based reconciliation tells you whether they differ for the correct reasons. Now Mercy if a business is starting only now, governance can feel like a later issue. Should it be? Or should tax and compliance ownership be decided at the beginning? [00:14:56] Speaker B: In fact, it should be decided at the beginning. There should be one clearly accountable owner and that person may sit in either tax or compliance depending on the organization, but the program cannot be implemented successfully by either function working alone. Tax is normally best placed to lead technical interpretation, entity and product classification, jurisdictional nexus, valuation and reporting methodology. Compliance usually controls customer onboarding, kyc, self certification collection, customer remediation and change in circumstance process. Legal understands a customer agreement's intermediary arrangement, outsourcing model and the allocation of functions between entities. Operations manages the daily workflow and exceptions. Technology and data control the source systems, data lineage, reporting rules and system changes. [00:15:55] Speaker A: And what does joint tax and compliance governance look like? [00:15:59] Speaker B: Practically, it means agreeing decisions and connecting every technical conclusion to an operational response. Suppose Tax concludes that the new token is a relevant crypto asset. That conclusion should trigger a defined workflow. Compliance assesses whether the customer documentation and onboarding process are adequate operations identifies affected customers and any remediation required technology activates the relevant transaction and reporting logic. Data confirms the required information is available, complete and traceable. Legal determines whether customer terms, privacy notices or intermediary agreements require amendment. The decision should be recorded in a controlled classification register containing the relevant facts, technical basis approval, effective date, and the system and process. Effective If a technically correct conclusion remains in a memorandum and never reaches the onboarding process or reporting system, governance has failed. [00:17:09] Speaker A: One person should be accountable, but several functions must be responsible for delivery exactly. [00:17:16] Speaker B: Joint governance does not mean vague collective ownership. It means one accountable owner supported by clearly allocated responsibilities and escalation routes. [00:17:30] Speaker A: Many businesses will still be waiting for final domestic rules or detailed guidance. If they are only starting now, what should they realistically prioritize? [00:17:41] Speaker B: I would prioritize three work streams. First, understand your footprint. Create an inventory of legal entities, crypto related activities and relevant jurisdictions and map the most important customer transaction journeys across internal and external intermediaries. Second, classify what you do. Assess the principal products, services and roles based on their actual terms and functions, not commercial labels or assumptions about how the business is perceived. Third, test whether the data and process exist to support the conclusion. Customer tax documentation, transaction data, valuation information, wallet or asset identifiers, change in circumstance process and reporting controls. CRS may provide a useful foundation for tax resident certification, tin collection, reasonableness testing and change in circumstance procedures. AML KYC may provide identity data, customer contract channels and remediation workflows, but businesses should not simply copy those frameworks. Tax residence is not the same as nationality, legal residence or NAML country classification. Existing CRS systems may also lack wallet addresses, digital asset identifiers, unit transaction categories or appropriate valuation data. The principle should be reuse the infrastructure but not the assumptions. Finally, establish the governance structure now, nominate the accountable owner, define the roles of tax and compliance involves legal operations, data and technology, and create a process for approving and implementing classification decisions. Waiting for the reporting portal or final schema is too late if the underlying customer and transaction data has never been collected. [00:19:44] Speaker A: Thanks Mercy. Let's close with three takeaways. [00:19:49] Speaker B: I would start with first, being small, regulated or transparent does not automatically place a crypto asset service provider outside cuf. Second, the involvement of another exchange broker or custodian does not automatically transfer the reporting obligation. Follow the complete transaction chain and determine the role of each participant. [00:20:16] Speaker A: And third, for groups with US and international exposure, build a common data foundation for Form 1099BA and Carface, but retain separate rules and a reconciliation that explains [00:20:28] Speaker B: the differences and from a governance perspective, identify one accountable owner but implement CAF jointly across tax compliance, legal operations, data and technology. If you have not yet started, the key is not to wait for the first reporting deadline. Start with scope, roles, products, data and governance. The first CAF return may still be some distance away from for many organizations, but the decisions that determine whether it will be correct need to be made much earlier. For more information on A&M's work supporting CAF, CRS 2.0 and digital asset reporting, please feel free to reach out to us. I'm Mercy Joseph and I'm Chris Kattarba. Thank you for listening.

Other Episodes

Episode 20

June 11, 2026 00:16:04
Episode Cover

The Evolving Global Tax Dispute Resolution Architecture

In this episode Lucy Sauvage and Craig Aspinall discuss how global tax dispute resolution is evolving from traditional bilateral MAP processes to more complex,...

Listen

Episode 15

March 12, 2026 00:18:31
Episode Cover

Risk-Oriented Approach to SbS Pillar 2 Compliance and Reporting

In this episode, Jayde Thompson, Managing Director and Ed Raza, Senior Director break down the OECD’s Side‑by‑Side (SbS) Safe Harbour regime through a commercial,...

Listen

Episode 4

November 05, 2025 00:09:53
Episode Cover

Reducing VAT Complexity: Rethinking Indirect Taxes and Compliance in Evolving European Business Models

In this episode, Anastasia Buettner, Managing Director from A&M Australia bring you insights into Reducing VAT Complexity: Rethinking Indirect Taxes and Compliance in Evolving...

Listen