Identifying RCASPs Under CARF: Standards and Eight Common Business Models
As Singapore, New Zealand and the UK issue RCASP guidance, this article examines how CARF identifies Reporting Crypto-Asset Service Providers and applies across eight common crypto business models.

On August 11, 2026, Singapore formally issued the Income Tax (International Tax Compliance Agreements) (Crypto-Asset Reporting Framework) Regulations 2026. The rules will take effect on January 1, 2027, with Singapore planning to conduct its first exchanges of information under CARF in September 2028. At present, multiple jurisdictions, including EU Member States, Hong Kong, China, Japan, Singapore, and the Cayman Islands, have committed to implementing CARF, and some have already entered the domestic implementation and data collection stage. Globally, CARF is gradually moving from rulemaking and implementation commitments into actual implementation, while the rules continue to be refined.

CARF (Crypto-Asset Reporting Framework) is an OECD framework for the automatic exchange of tax-relevant information on crypto-assets. It is designed to collect relevant user and transaction information through crypto-asset service providers and automatically exchange that information between jurisdictions with exchange relationships, thereby improving tax transparency in the crypto-asset sector.
In broad terms, CARF sets out:
1. the scope of crypto-assets covered;
2. the entities and individuals subject to data collection and reporting obligations, namely Reporting Crypto-Asset Service Providers (RCASPs);
3. the transactions that must be reported and the information to be reported in relation to those transactions;
4. due diligence procedures for identifying Crypto-Asset Users and their relevant tax jurisdictions, so that reporting and information exchange requirements can be met.
The identification of RCASPs directly determines which parties must take on CARF data collection and reporting obligations. Although the OECD has defined and explained the concept of an RCASP, implementing jurisdictions may further refine the identification criteria based on local rules, regulatory frameworks, and business practices. As crypto business models continue to evolve, however, determining whether a particular party is an RCASP can still be complex. The discussion below reviews the key identification logic and how CARF applies to common business models.
Official Definition and Guidance for RCASPs
The OECD defines an RCASP as any individual or Entity that, as a business, provides a service effectuating Exchange Transactions for or on behalf of customers, including by acting as a counterparty or intermediary to such Exchange Transactions, or by making available a trading platform.
CARF takes a clearly substance-based approach to RCASP identification. The decisive factors are the business activities a person actually conducts and the functions it performs in Relevant Crypto-Asset transactions, rather than its name, technical architecture, or whether it uses a custodial model. In practice, business models and transaction arrangements are often complex, making it difficult to draw accurate boundaries from a single definition alone. Some implementing jurisdictions have therefore released further RCASP guidance or self-review tools to clarify the scope for different business scenarios.
1. New Zealand
New Zealand Inland Revenue has published the IR1127 Work out if you are a Reporting Crypto-Asset Service Provider (RCASP) flowchart, providing general guidance for businesses on determining RCASP status. The flowchart reduces the analysis to three consecutive questions: do you provide a service effectuating Exchange Transactions; do you provide that service for customers or on their behalf; and do you provide the service as part of a business? If all three conditions are met, the relevant individual or Entity will generally be identified as an RCASP.

2. Singapore
Compared with New Zealand's relatively concise flowchart, Singapore provides more comprehensive official guidance for identifying RCASPs. The Inland Revenue Authority of Singapore has issued a Crypto-Asset Reporting Framework e-Tax Guide and an accompanying RCASP self-review tool, covering the RCASP definition, conditions for application, and common business scenarios. The guide breaks down the core elements of the RCASP definition and then explains, by business type, which parties may fall within scope, helping businesses conduct their own initial assessment.

3. United Kingdom
HM Revenue & Customs (HMRC), in its International Exchange of Information Manual, breaks the RCASP definition into several separate factors. These mainly include whether the activity is carried on as a business, whether the person provides a service effectuating Exchange Transactions, whether it participates in the transaction as a counterparty or intermediary, whether it makes available a trading platform, and whether it exercises control or sufficient influence over a trading platform. Each part supplements the scope of the RCASP definition through explanations of the definitions, typical examples, and references to the relevant rules.
Taken together, the OECD guidance and official guidance issued by implementing jurisdictions provide a basic analytical path and illustrate some scenarios through practical examples. Because the RCASP definition is functional, however, the final conclusion still depends on how the business actually operates. More complex arrangements, especially those where responsibilities or control relationships are unclear, require further technical analysis based on the specific facts.
How to Assess RCASP Status
In practice, professional analyses of RCASP status generally start with scope definition and business mapping. First, the elements of the RCASP definition are broken down under CARF. Specific products, services, and transaction flows are then mapped against those elements to identify the functions actually performed by each party and determine the boundary by reference to typical inclusion and exclusion scenarios. For more complex arrangements, such as trading platforms, decentralized businesses, and payment services, the analysis also needs to consider platform control, customer relationships, and the allocation of responsibilities where multiple parties are involved.
Once RCASP status has been determined, nexus rules—including tax residence, place of incorporation or registration, place of management, and regular place of business—are applied to determine the jurisdiction in which the RCASP must actually perform due diligence and reporting obligations.

Once the general logic for identifying an RCASP is clear, it becomes possible to assess whether common crypto-industry business types fall within the RCASP scope and how CARF applies to them.
1. Centralized Exchanges
Generally an RCASP.
In this article, a centralized exchange refers to a platform with an identifiable operator that continuously provides customers with services for exchanging Relevant Crypto-Assets for Fiat Currency, or one Relevant Crypto-Asset for another. The RCASP definition covers three main operating roles—acting as a counterparty, acting as an intermediary, and making available a trading platform—and a centralized exchange will typically perform one or more of them.
When a platform matches customer buy and sell orders, it performs the trading platform function. When it executes transaction instructions on behalf of customers, it performs an intermediary function. If it uses its own assets to quote prices or provide liquidity to customers, it may itself become the counterparty. As long as the relevant person, as a business, effectuates these Exchange Transactions for or on behalf of customers, it may meet the core conditions for being an RCASP.
2. Decentralized Exchanges
May be an RCASP.
If there is an individual or Entity behind a decentralized exchange that exercises control or sufficient influence over the platform, and that control or influence is sufficient to allow it to comply with CARF due diligence and reporting obligations, that person may be treated as making available the trading platform. If it also continuously effectuates Exchange Transactions involving Relevant Crypto-Assets for customers as a business, it may constitute an RCASP. Control or sufficient influence may be exercised by a single person or jointly by multiple persons. However, the OECD's FAQ updated in December 2025 clarifies that, for DeFi arrangements, an implementing jurisdiction may defer application of the 'control or sufficient influence' test until further interpretative guidance is issued. Decentralized businesses therefore also need to check whether the relevant implementing jurisdiction has adopted this transitional treatment.
If no individual or Entity exercises that level of control or sufficient influence over the platform, and no other person effectuates Exchange Transactions for customers as a counterparty, intermediary, or provider of a trading platform, developers, governance participants, or technical service providers do not become RCASPs merely because they are involved in developing, maintaining, or governing the platform. Providing software, smart contracts, or other technical infrastructure alone likewise does not create RCASP status.
3. OTC Dealers, Brokers, and Crypto ATMs
Generally an RCASP.
In this article, an OTC dealer mainly refers to a person that continuously buys or sells Relevant Crypto-Assets to customers in its own name and for its own account. A broker accepts customer instructions and executes purchases or sales of Relevant Crypto-Assets on their behalf. A crypto ATM operator uses physical terminals to provide customers with exchanges between Fiat Currency and Relevant Crypto-Assets, or between different Relevant Crypto-Assets. Although these three types of businesses do not necessarily operate a full trading platform, each directly participates in customer Exchange Transactions.
An OTC dealer trades with customers using its own assets and therefore acts as a counterparty. A broker finds counterparties or executes orders on behalf of customers and therefore acts as an intermediary. A crypto ATM provides the same type of exchange service through a physical terminal; where the operator is actually responsible for the asset exchange, it is providing an exchange service to customers. A person that only supplies ATM equipment, premises, maintenance, or other technical support, without actually participating in the exchange service, does not become an RCASP merely by taking part in the ATM business chain.
4. Crypto Payment and Card-Issuing Providers
May be an RCASP.
Whether a crypto payment or card-issuing business falls within the RCASP scope depends on whether the institution actually effectuates a crypto-asset exchange for the customer as part of the payment or settlement process. If a customer spends from a crypto-asset balance and the institution converts the Relevant Crypto-Asset into Fiat Currency before settling with the merchant, or if the institution performs the conversion between Relevant Crypto-Assets and Fiat Currency when the merchant receives payment, the institution is substantively participating in the customer's Exchange Transaction and may be an RCASP. For crypto card arrangements, it is necessary to identify whether the conversion is actually performed by the card issuer, payment service provider, or another participant.
If the institution only provides the payment rail, account management, card issuance, or a transfer of Relevant Crypto-Assets, while an independent third party performs the exchange, the institution itself does not become an RCASP merely by participating in the crypto payment chain. Retail payments or transfers of Relevant Crypto-Assets may later be reportable transaction types for an RCASP, but those transactions do not, by themselves, determine whether a payment institution is an RCASP. Status still depends on whether the institution actually performs the function of effectuating Exchange Transactions for customers.
5. Wallet and Custody Service Providers
May be an RCASP.
A person that only provides wallet or custody services will generally not be an RCASP. These services primarily involve safeguarding crypto-assets, managing private keys, and carrying out on-chain transfers. They do not, by themselves, effectuate exchanges between Relevant Crypto-Assets and Fiat Currency, or between different Relevant Crypto-Assets, for customers, and therefore do not meet the core RCASP condition of effectuating Exchange Transactions.
If a wallet or custody service also offers buying, selling, or exchange functions, the actual role of the relevant person in the exchange process must be assessed. A service provider may be an RCASP if it directly executes customer transactions, acts as the counterparty to an exchange, or uses a trading function under its control to enable customers to complete exchanges. If it only provides custody and an independent party provides the trading service, the functions performed by each participant should be assessed separately.
6. Token and Stablecoin Issuers and Distributors
May be an RCASP.
Creating and issuing a crypto-asset alone does not make the issuer an RCASP. If the issuer only creates the token, carries out the initial issuance, or mints tokens under a predetermined mechanism, without subsequently providing crypto-asset exchange services to customers, it does not meet the core condition of 'effectuating Exchange Transactions for or on behalf of customers.' The focus should be on the business arrangements after issuance, rather than on the issuance itself.
If the issuer or an affiliated party also handles subscription, redemption, resale, or distribution and, in doing so, actually effects an exchange between Fiat Currency and Relevant Crypto-Assets or between different Relevant Crypto-Assets, it may be an RCASP.
For stablecoins, the first step is to determine the asset classification. Stablecoins that qualify as Specified Electronic Money Products are not treated as Relevant Crypto-Assets under CARF and instead fall within the scope of the amended CRS. Other stablecoins still need to be assessed under the CARF definition of a Relevant Crypto-Asset, including their issuance, redemption, and trading arrangements.
7. Crypto Funds
Generally not an RCASP, but may fall within the reporting scope of the amended CRS.
A crypto fund pools capital into fund assets, and the fund or its manager invests those assets in Relevant Crypto-Assets on a centralized basis. Buying, selling, allocation, and rebalancing are performed to manage the fund's own investment portfolio, not to provide fund investors with a crypto-asset exchange service. Investors acquire fund units or other interests rather than using the fund to exchange specific crypto-assets. A fund therefore does not become an RCASP merely because it invests in, holds, or trades crypto-assets.
The amended CRS has brought Relevant Crypto-Assets within the definition of an 'Investment Entity.' Specifically, an Investment Entity includes both an Entity that, as a business, conducts activities such as investing or managing Financial Assets, Relevant Crypto-Assets, or money for or on behalf of a customer, and an Entity whose gross income is primarily attributable to investing, reinvesting, or trading in Financial Assets or Relevant Crypto-Assets and that is managed by a Financial Institution. A crypto fund whose primary business is investing in Relevant Crypto-Assets and that is managed by a professional manager may therefore be classified under the existing Investment Entity criteria in the amended CRS. A qualifying fund will be treated as a Financial Institution, and interests such as fund units will accordingly be treated as Financial Accounts subject to CRS due diligence and reporting.
8. Derivatives Platforms
Primarily within the reporting scope of the amended CRS, but may also be an RCASP under certain business arrangements.
For common products such as perpetual contracts, futures, and options, investors acquire contractual rights linked to the price of Relevant Crypto-Assets such as BTC or ETH. Trading and settlement are generally carried out through account entries or in Fiat Currency, without directly acquiring or transferring the underlying Relevant Crypto-Assets. These products provide indirect crypto-asset exposure through financial instruments, and the amended CRS has brought derivative interests linked to Relevant Crypto-Assets within the scope of Financial Assets. The relevant platform or operating entity must therefore further assess its due diligence and reporting obligations under the Financial Institution classification rules of the amended CRS.
If a derivative offered by the platform is itself issued in the form of a crypto-asset that can be independently held and transferred, the related transactions may still constitute crypto-asset Exchange Transactions covered by CARF. In that case, the key question is whether the platform, as a business, effectuates the relevant Exchange Transactions for customers. If the RCASP conditions are met, the corresponding CARF obligations will still apply.
Conclusion
Although jurisdictions continue to refine CARF rules and clarify the boundaries of their application, determining status in complex business scenarios still requires a professional analysis of the specific facts. Relevant businesses can also start screening their activities early, identify potential areas of application, and make the necessary preparations.
At present, a number of boundary issues in CARF implementation are still being refined through FAQs, domestic consultations, and industry feedback. These include the allocation of due diligence responsibilities when multiple RCASPs participate in the same transaction, duplicate reporting under cross-jurisdiction nexus rules, control or sufficient influence over decentralized platforms, branch nexus points, and the boundary between CARF and the amended CRS for tokenized Financial Assets. The OECD's latest FAQs have provided additional clarification on several of these issues, while the UK's earlier implementation consultation also highlighted many practical application challenges.
RCASP assessments therefore should not be a one-off classification based only on business labels such as 'exchange,' 'wallet,' or 'payment institution.' For hybrid platforms, a more practical approach is to assess each product and transaction flow separately, identifying the exchange function, customer relationship, the party exercising control, and the reporting nexus, and to update the conclusion whenever the product structure or entity arrangement changes.
Send this FinTax note to your team.