CARF: the OECD's Crypto-Asset Reporting Framework
CARF is not a filing obligation that lands on your company. It is a standard that requires crypto asset service providers to report, every year, to their own country's tax authority. Data collection started January 1, 2026, and the first automatic exchange between countries arrives in 2027.
Until recently, whether a Latin American company holding stablecoin balances showed up on a foreign tax authority's radar depended almost entirely on what that company chose to declare in its own country. The OECD's Crypto-Asset Reporting Framework changes that logic: it turns crypto reporting into an automatic flow between countries, with the crypto asset service provider as the source of the data, not the company.
In Soulbit Academy we already covered what providers report to DIAN under Resolution 000240 in Colombia and the broader regulatory landscape for crypto assets across Latin America. This article is the starting point for both: what CARF actually is, what data it collects, who reports it, and what a finance team at a Latin American company with US clients or counterparties should do now that the clock is already running.
What CARF is and why it took effect in 2026
CARF, the Crypto-Asset Reporting Framework, is the OECD standard for automatic exchange of tax information on crypto assets between the tax authorities of different countries. It took effect on January 1, 2026: from that date, crypto asset service providers covered by the framework began collecting identification and transaction data on their users.
CARF comes from the same body and follows the same logic as the Common Reporting Standard (CRS), which the OECD has used for traditional bank accounts for more than a decade. The difference is the object it covers: instead of bank balances, CARF covers crypto asset transactions, an asset class that had until now sat outside CRS because it does not necessarily pass through a financial entity regulated under the traditional rules.
Why does this matter to a company that does not treat crypto as its core business?
It matters because CARF does not distinguish between crypto-native companies and companies that simply hold or receive part of their treasury in stablecoins. Any legal entity that is a client of a crypto asset service provider covered by the framework falls, in principle, within the scope of that provider's report. The trigger is the relationship with the provider, not the company's line of business.
What data CARF collects and who reports it
CARF collects four data blocks per user: identification, the type of crypto asset involved, its fair value, and the number of transactions carried out during the period. The party that reports that data to the tax authority is the crypto asset service provider, never the client company.
CARF's reporting mechanism mirrors, at an international scale, the scheme Colombia's DIAN Resolution 000240 implemented domestically. The provider identifies its reportable users and sends the data; the company is not involved. The table below summarizes what changes under CARF compared with the previous model, where a company's own decision to declare was the only source of the data.
| Aspect | Before CARF | Under CARF |
|---|---|---|
| Who reports to the tax authority | The company, only if it chooses to declare its crypto assets | The crypto asset service provider, on a mandatory basis |
| What data travels | Whatever the company includes in its own filing | User identification, type of crypto asset, fair value, and number of transactions |
| Geographic reach | Only the jurisdiction where the company files | Exchanged between every jurisdiction that signed the CARF-MCAA |
| How often the data gets cross-checked | Only during a targeted audit | Systematically, every year, starting with the 2027 exchange |
The report does not distinguish between dollar-backed stablecoins such as USDC or USDT and more volatile crypto assets: CARF's definition of a crypto asset covers both equally. A company holding operational balance in stablecoins falls, for reporting purposes, into the same category as one trading crypto assets as an investment. This is the same logic of data traveling with the transaction that we cover in our piece on the FATF travel rule for companies handling crypto payments: different bodies, the same goal of making the counterparty and the amount visible to authorities on both ends.
CARF's timeline: from 2026 data collection to the first exchange in 2027
CARF's timeline has three concrete milestones: it took effect January 1, 2026, data collection runs through all of 2026, and the first automatic exchange between countries happens in 2027. There is no retroactive reporting on activity from before 2026.
This timeline is not the same for every signatory jurisdiction. The OECD grouped countries into waves based on their commitment date: a first wave exchanging data already in 2027, on data collected in 2026, and a second wave starting to exchange in 2028, on data it collects during 2027. For a Latin American company, what matters is which wave the country where it files taxes falls into, and which wave the country where its crypto provider operates falls into.
| Milestone | Date |
|---|---|
| CARF takes effect | January 1, 2026 |
| Data collection period by providers | All of 2026 |
| First automatic exchange between countries (first wave) | 2027 |
| Second automatic exchange between countries (second wave) | 2028 |
| Colombia signs the CARF-MCAA | October 31, 2024 |
| Brazil signs the CARF-MCAA | November 21, 2024 |
How many countries signed CARF, and why the count keeps changing
According to the OECD, 75 jurisdictions carry a political commitment to implement CARF: 52 exchanging by 2027, and a second group by 2028. The count changes from one source to another because each one counts something different. The two reference documents are the OECD's joint statement of signatories and its 2025 monitoring and implementation update.
That figure of 75 is not the same one that shows up in press coverage citing 48, 53, or 67 jurisdictions. The gap comes from what gets counted: a political commitment to adopt the framework is not the same as having actually signed the Multilateral Competent Authority Agreement (CARF-MCAA), the specific legal instrument that activates real exchange between two countries. A country can announce its commitment without yet having signed the bilateral or multilateral agreement that puts it into motion with each counterpart.
For Latin America, the confirmed CARF-MCAA signatories with dates are Colombia (October 31, 2024), Brazil (November 21, 2024), Costa Rica (November 26, 2024), and Chile (October 21, 2025). Brazil already regulates who can operate as a crypto asset provider domestically through the central bank's VASP authorization regime, which will likely double as the local vehicle for identifying CARF-reportable providers there. This guide gets updated as new signatures come in; always verify the current list against the OECD's monitoring report before assuming any single country's status.
What the US does instead of CARF, and why it matters for a company with US clients
The United States has not signed the CARF-MCAA and is not building its crypto reporting regime through CARF at all. Instead, the IRS created its own domestic reporting form, Form 1099-DA, Digital Asset Proceeds From Broker Transactions, which brokers use to report digital asset dispositions to the IRS and to their customers.
For a Latin American company that invoices US clients, pays US contractors, or runs stablecoin activity through a US-based platform, this means two separate reporting tracks can apply at once: CARF on the Latin American side, through the company's own country's signatory status, and 1099-DA on the US side, through any US-based broker the company or its counterparties use. Coordination between the two frameworks for cross-border transactions is still developing, so a company operating on both sides should not assume one framework substitutes for the other.
Should a company with US clients treat CARF and 1099-DA as the same obligation?
No. CARF and 1099-DA are separate legal instruments run by different authorities, and a company can fall under both at once without either one canceling the other out. A Colombian company paying a US-based contractor in stablecoins may have its Colombia-linked activity reported under CARF by a Colombian provider, while the US-based broker involved in the same transaction reports separately to the IRS under 1099-DA rules.
What a finance team at a Latin American company should do now
A finance team should do three concrete things before the first 2027 exchange: confirm whether its crypto asset service providers fall under CARF, check that the company's own tax filing matches what those providers are likely reporting, and keep an internal record of every transaction with its date, counterparty, and value.
The first step is asking the provider directly whether it falls within CARF's scope in its jurisdiction, since there is no single public registry of reporting entities. The second is an internal review: if the fair value or transaction count a provider reports does not match what the company already filed, the company is the one that has to explain the mismatch, not the provider. The third is preventive: an internal, dated record of transactions is the strongest defense against a cross-check that does not line up on the first pass.
None of these three steps replaces a qualified tax advisor's judgment. CARF is an information-reporting framework, not a rule about which operations are taxable or how much a company owes; that part of each country's tax regime stays exactly what it was before CARF.
What Soulbit delivers around CARF and what it does not
Soulbit currently offers institutional custody with MPC technology for stablecoin balances such as USDC and USDT, conversion to local currency, mass payroll disbursement, payment links, and a collection QR code, with local bank rails in Colombia and KYB and AML/KYT checks on every transaction. Those controls generate, by design, a traceable record of date, amount, and counterparty that is useful for a company's own internal documentation ahead of any CARF-related cross-check.
What Soulbit does not do is publicly determine whether it counts as a reporting crypto asset service provider under CARF in any given jurisdiction, or prepare and file a client's tax return. That classification depends on the local CARF framework in each country and should be confirmed directly with a compliance contact. It also does not replace the reconciliation a company must run between its stablecoin activity and its own books, which we cover in detail in our guide on DIAN and crypto for a company in Colombia. Confirming any provider's reporting status, Soulbit included, is a matter for a qualified tax advisor.
Frequently asked questions
What is the OECD's Crypto-Asset Reporting Framework (CARF)?
CARF is the OECD standard for automatic exchange of tax information on crypto assets between countries. It requires crypto asset service providers, not the companies that use them, to identify their users and report their activity to the local tax authority, which then exchanges that data with other signatory jurisdictions. CARF took effect on January 1, 2026.
Does my company have to file anything directly under CARF?
No. CARF places the reporting duty on the crypto asset service provider, not on the company using the service. A Colombian company, for example, still declares its crypto assets to DIAN under the general rules covered in our article on DIAN Resolution 000240. What changes under CARF is that the company's own filing can now be cross-checked against an international report that arrives independently of anything the company submits.
Why does the count of countries that signed CARF differ between sources?
Because different sources count different things. Some count jurisdictions with a political commitment to implement CARF, others count only those that have already signed the Multilateral Competent Authority Agreement (CARF-MCAA), the legal instrument that actually activates data exchange between two countries. That is why figures of 48, 53, 67, or 75 jurisdictions circulate depending on the cutoff and the OECD report consulted.
When does the first automatic exchange of crypto data between countries start?
The first automatic exchange between tax authorities of signatory jurisdictions in the first wave is scheduled for 2027, covering data providers collected during 2026. A second wave of jurisdictions, committed for 2028, will start exchanging data a year later, on data collected during 2027.
Does Soulbit report to any tax authority under CARF?
Soulbit does not publicly determine its status as a reporting crypto asset service provider in each jurisdiction where it operates; that classification depends on the local CARF framework and should be confirmed with a compliance contact. What Soulbit provides today is institutional custody with MPC technology, conversion between stablecoins and local currency, mass payroll disbursement, and local Colombian bank rails, with KYB and AML/KYT checks on every transaction.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist