CARF in 2026: What the New Crypto Reporting Standard Means for Exchangers

iEXExchanger
CARF in 2026: What the New Crypto Reporting Standard Means for Exchangers

CARF is the OECD's new standard for automatically sharing crypto transaction data between tax authorities. From 2026, exchangers must collect client data and report it annually — here's what changes and how to prepare.

CARF is the OECD's new framework for automatically exchanging crypto transaction data between tax authorities worldwide. Dozens of countries start rolling it out from 2026, and if you run an exchanger, this isn't background news — it's a new operational duty: collect client data, report it, repeat every year. Here's what actually changes and what to do about it.

What CARF Actually Is, and Why It's Suddenly Everywhere

The Crypto-Asset Reporting Framework was adopted by the OECD back in 2022, but it only starts biting now: the first countries begin collecting 2026 data to exchange with partner jurisdictions in 2027. The logic mirrors CRS, the existing standard for bank accounts — except now it's applied to crypto. The platform that processes a transaction has to identify the client and report the deal to its local tax authority, which then forwards the data to wherever that client actually pays tax.

Who It Targets — the Trader or the Platform

CARF isn't aimed at the person holding a wallet; it targets the business standing between that person and the blockchain. Exchanges, brokers and — this is the part that matters for you — exchangers all fall under the definition, as long as they process trades between crypto and fiat or between different crypto assets on behalf of clients. If your exchanger operates as a registered business and serves clients from CARF-adopting countries, you're very likely inside the reporting perimeter, regardless of whether you call yourself an "exchanger", an "exchange" or a "platform".

How It Actually Works in Practice

The mechanics look a lot like KYC with an extra reporting layer bolted on. The platform collects the client's tax identification number, country of tax residence, and transaction data — amounts, dates, asset types. Once a year, that data goes to the local tax authority, which automatically forwards it to the client's home country, no request needed. Compare that to today, where a tax office has to specifically ask for crypto transaction records. After CARF, that becomes a background process — not unlike a bank statement landing in a government mailbox.

What Exchangers Should Do Right Now

Waiting for the final deadline is a risky plan — the data pipeline needs to be built well before the reporting month, not during it.

  • Check whether your jurisdiction, and the jurisdictions your clients live in, have committed to CARF, and by which date.
  • Add tax ID and tax-residence fields to client onboarding if you don't already collect them.
  • Store transaction history in a structured, exportable format — not scattered across chat logs and spreadsheets.
  • Talk to a tax lawyer in each key jurisdiction, since thresholds and timelines differ from country to country.

Limits and Common Mistakes

CARF isn't a single global law enforced identically everywhere. The list of participating countries keeps growing, but it's not universal, and the first reporting dates vary by jurisdiction. That's not a reason to relax: clients from early-adopting countries end up in the reporting pipeline even if your own jurisdiction hasn't joined yet. A common mistake is assuming that calling your business an "exchanger" instead of an "exchange" keeps you outside the rules — in practice, function decides, not the label. Another is betting you can "sort it out later": reconstructing a year of transaction history from scattered spreadsheets costs far more than building the data pipeline from day one.

Conclusion

CARF changes the rules for the platform standing between the trader and the blockchain, not for the trader itself. The sooner an exchanger builds client-data collection and storage into its daily process, the less likely reporting season turns into a scramble. If you're choosing or upgrading the engine behind your exchanger, it's worth checking how ready it is for this kind of reporting out of the box — with iEXExchanger, that's one of the things worth comparing before launch.

Questions and answers

Frequently asked questions about this article

What is CARF?

CARF (Crypto-Asset Reporting Framework) is the OECD's standard for automatically exchanging crypto transaction data between tax authorities in different countries. It works like CRS, the existing standard for bank accounts, but applied to crypto assets. Platforms that process such transactions must collect client data and report it to their local tax authority, which then shares it with other jurisdictions.

Does CARF apply to all countries at the same time?

No. The list of countries adopting CARF is growing in stages, and each jurisdiction has its own timeline for the first data exchange. That's no reason to delay preparation, though: if any of your clients are residents of early-adopting countries, their data will be reported regardless of when your own jurisdiction joins.

How is CARF different from regular KYC?

KYC helps a platform confirm who its client is, and the data usually stays inside the company. CARF adds the next step: once a year, that data has to go to a tax authority, which automatically shares it with other countries. In effect, CARF turns part of your KYC data into recurring external reporting rather than just an internal check.

What happens to an exchanger that ignores CARF?

The specific penalties are set by each jurisdiction's own law, not by CARF itself, and range from fines to operating restrictions. But the more practical risk is having to reconstruct past transaction history under deadline pressure — which costs far more than a process built in advance.

Where should an exchanger start preparing for CARF?

Start with an audit: check which CARF jurisdictions apply to your clients and by what deadlines, and identify the gaps in your current onboarding and data storage. Then add the missing fields to client registration and move your transaction history into a structured, exportable format — that's the foundation any further automation depends on.