Resource center · Digital Assets

Which providers are reporting entities under CARF?.

The definition turns on effecting exchange transactions for or on behalf of customers. Not on holding assets, not on holding a licence, and not on where the software runs.

Q & A CARF / DAC8 · Multi-jurisdiction · reporting perimeter

The definition

A reporting crypto-asset service provider is, in substance, any individual or entity that as a business effects exchange transactions in relevant crypto-assets for or on behalf of customers. Three elements do the work: as a business, effects, and for or on behalf of customers.

None of them refers to holding assets, to being licensed, or to operating an order book. A business that stands between a customer and an exchange transaction, in a way that makes the transaction happen, is inside the definition even where the assets never touch its balance sheet.

Why custody is not the test

Custody is the mental model most firms bring, because it is how the financial account standard works — an institution holds something for someone. The crypto framework was drafted knowing that much of the market does not hold anything. Building the perimeter on custody would have exempted a large share of the activity the framework exists to observe.

Practical consequence. An assessment that concludes “we are not in scope because we never hold customer assets” is not an assessment against the definition. It needs to address whether the business effects exchange transactions for customers.

Non-custodial and decentralised models

The framework’s interpretative material has addressed non-custodial providers directly: they can be reporting providers where they exercise sufficient control over the arrangement through which transactions are effected. Control is assessed on the substance of the arrangement rather than on how it is described.

Indicators that weigh towards being inside the perimeter include the ability to influence or set the terms on which transactions occur, the ability to charge for them, the ability to prevent or restrict access, and the maintenance of a customer relationship. A model where none of these is present is a stronger case for being outside — but the assessment has to be made and documented, because the boundary is being interpreted actively and the answer can change without the business changing.

Resolving nexus

Once a provider is inside the perimeter, nexus decides where it reports. The connecting factors run in a sequence: tax residence; then incorporation or legal personality; then place of management; then regular place of business; and then the jurisdiction from which transactions are effected.

Nexus in practice
SituationEffect
One entity, one jurisdictionReports there. The straightforward case, and the least common at scale.
Group with entities in several jurisdictionsEach entity resolves nexus separately; the group can hold several reporting obligations covering overlapping customers.
No residence or incorporation anywhere relevantThe later factors bite, and a provider can be in scope in a jurisdiction where it has no legal presence.
Reporting already made elsewhereRelief can apply where the same information is reported under an equivalent regime, but it is checked per jurisdiction and per customer population.

The Union overlay

Council Directive (EU) 2023/2226 implements the framework inside the Union and aligns its perimeter with the Union’s own crypto-asset regime, so a provider authorised under that regime is inside the reporting population by construction. That removes the perimeter question for authorised providers and leaves it live for everyone else operating into the Union without authorisation.

Official sources

Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.

  1. OECD — release of the CARF and amended CRS XML schemas and interpretative guidance, including treatment of non-custodial providersOECD · scope of reporting providers
  2. Council Directive (EU) 2023/2226 (DAC8) amending Directive 2011/16/EU on administrative cooperation in the field of taxationEUR-Lex · Directive · the Union implementation and its perimeter
  3. OECD — Crypto-Asset Reporting Framework, Section I definitions, and the accompanying frequently asked questionsOECD · the definition itself · consult the current edition

Questions, answered

We never hold customer assets. Are we outside the framework?

Not on that ground alone. The test is whether the business effects exchange transactions in relevant crypto-assets for or on behalf of customers. Non-custodial providers can be reporting providers where they exercise sufficient control over the arrangement through which transactions are effected.

We only provide software. Does that keep us outside?

It depends on what the software does and what the business retains. Where the provider can influence the terms on which transactions occur, charge for them, restrict access, or maintains a customer relationship, the case for being outside weakens considerably. Document the assessment against the definition rather than against the business model label.

Can we be in scope in a jurisdiction where we have no entity?

Yes. The connecting factors run past residence and incorporation to place of management, regular place of business, and the jurisdiction from which transactions are effected. A provider with no legal presence can still resolve nexus somewhere.

Does reporting in one jurisdiction relieve us elsewhere?

Relief can apply where the same information is reported under an equivalent regime and reaches the jurisdiction that would otherwise receive it. It is assessed per jurisdiction and per customer population, so expect a residual group the relief does not cover.

REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Keep reading

More on this framework, and the module that produces the filing.

All digital assets resources

Settle the perimeter, then build once.

Where you are in scope in several jurisdictions, one aggregation pipeline produces every file. Start with a free test report.