UK CARF Enters the Operational Phase: How Service Providers Report and What It Means for Investors
UK CARF's first data year is underway: filed in 2027, built in 2026. Who reports, what's reported, and what non-compliance costs.

Introduction
The UK has entered its first data-collection year under CARF. UK reporting cryptoasset service providers (RCASPs) must report the user identity and transaction data collected in 2026 to HMRC no later than 31 May 2027, and the UK plans to begin its first round of information exchanges by 30 September of that year.
At first glance, the first report is not due until 2027. In practice, however, the work service providers need to complete is already taking place in 2026: obtaining tax self-certificates at onboarding, identifying users’ jurisdictions of tax residence, organising transactions in accordance with CARF reporting categories, recording transfers to external wallets, and retaining complete data for subsequent registration, notifications and XML reporting. CARF is not a form to be filled in at year-end; it is a reporting regime embedded throughout the year’s operations.
As of 23 June 2026, the OECD Global Forum’s formal commitment list covered 76 jurisdictions, of which 46 jurisdictions, including the UK, had committed to first exchanges in 2027. A “commitment to first exchange” refers to the implementation timetable; it does not mean that all 46 jurisdictions will exchange all data with one another in the first round. Specific exchange relationships still depend on the entry into force of local legislation, competent authority notifications and the activation of partner relationships.
This article examines the rules from four perspectives. It first considers which entities that, as a business, effectuate or facilitate cryptoasset transactions and have the required nexus to the UK fall within the scope of UK RCASPs. It then explains what user identity and transaction data platforms need to collect. Next, it outlines how HMRC can use the data domestically in the UK and, once exchange relationships are effective, transmit it to other jurisdictions. Finally, it reviews penalty risks across due diligence, self-certification, record-keeping, registration, user notification and annual reporting.
1 What Is CARF, and How Does It Give Tax Authorities Visibility into Cross-Border Cryptoasset Transactions?
CARF stands for the Crypto-Asset Reporting Framework, a global standard for the automatic exchange of tax-relevant information on crypto-assets introduced by the Organisation for Economic Co-operation and Development (OECD) in 2022.
At its core, reporting cryptoasset service providers (RCASPs) collect information on customers and relevant transactions, report it to the tax authority in the jurisdiction where they report, and the information is then exchanged across borders between tax authorities. This is similar to the Common Reporting Standard (CRS) in traditional finance, but CARF mainly covers exchanges between cryptoassets and fiat currencies, exchanges between different cryptoassets, and transfers of relevant cryptoassets.
CARF reports “who carried out which cryptoasset transactions”; it does not calculate tax for users. Once tax authorities receive the information, they still need to apply domestic tax law to determine whether a transaction is taxable, what the relevant cost basis is, and the amount of taxable income or gains ultimately arising.
Suppose a UK tax resident uses an overseas cryptoasset platform that is subject to CARF reporting. The platform reports the data to its local tax authority, which may then share the data with HMRC. HMRC can thereby obtain information on the UK tax resident’s cryptoasset transactions on the overseas platform. Conversely, data on non-UK residents using a UK cryptoasset platform may also be exchanged by HMRC with other jurisdictions.
2 How the UK Is Implementing CARF
2.1 Legal Basis and Key Timeline
The core UK CARF rules are set out in the Reporting Cryptoasset Service Providers (Due Diligence and Reporting Requirements) Regulations 2025 (SI 2025/744). The Regulations came into force on 1 January 2026 and establish obligations relating to due diligence, record-keeping, annual reporting, user notifications, registration and penalties.

The first task on the timeline is to obtain valid user self-certificates. New users should provide a valid self-certificate when establishing a relationship with an RCASP, and the RCASP should obtain it before effectuating transactions for the user. For users whose relationship with the RCASP existed before 1 January 2026, the process must be completed by 31 December 2026 at the latest. UK service providers must also register with HMRC by 31 January 2027 and notify relevant users that their information will be reported to HMRC and may be exchanged with partner jurisdictions.
The first report covers the period from 1 January to 31 December 2026 and must be submitted between 1 January and 31 May 2027. In subsequent years, data for the previous calendar year must be reported by 31 May. Reports will be submitted as dedicated XML files. At present, the online service for filing the reports is not yet live.
2.2 Who Must Report: Assess the Business Activity First, Then the UK Nexus
Determining whether an entity is a UK RCASP involves two steps. First, does it, as a business, effectuate or facilitate cryptoasset transactions for users? Second, does it have one of the prescribed nexus connections to the UK?

HMRC applies the nexus hierarchy in the following order: UK tax residence, UK incorporation, UK management, and a regular place of business or branch in the UK. Where the same entity has nexus of equal standing in multiple CARF jurisdictions, it may make an election under Section I(H) of CARF to complete due diligence and international reporting in one jurisdiction, thereby avoiding duplicate reporting obligations. However, the election does not affect the UK’s domestic CARF reporting requirements. If the entity is a UK RCASP, it must still perform the relevant due diligence and reporting to HMRC for UK tax-resident users even if it elects to complete CARF due diligence and reporting in another CARF jurisdiction. In addition, a third party may submit the XML file on its behalf, but the RCASP remains responsible for the accuracy and completeness of the report.
2.3 Reportable Information: Identity and Transaction Data
UK RCASPs must carry out due diligence procedures on individual users, entity users and relevant persons. Reportable users include UK tax residents and tax residents of CARF reportable jurisdictions listed by the UK. UK RCASPs report to HMRC the identity information collected for reportable users, together with the related cryptoasset transaction information. The specific reportable information is shown below:

Under HMRC rules, transaction information is aggregated annually for each reportable user and then further grouped by “relevant cryptoasset – transaction type”. In other words, different cryptoassets held or transacted by the same user must be classified separately, and within each cryptoasset, acquisitions and disposals against fiat currency, crypto-to-crypto exchanges, transfers to and from the user, and transfers to external wallets must be aggregated under the relevant transaction categories.
Each transaction type follows its own reporting rules. Acquisitions and disposals against fiat currency mainly require reporting the net fiat amount paid or received for the relevant cryptoasset over the year. Crypto-to-crypto exchanges require the fair market values of both the disposal and acquisition sides to be reported. Other transfers to or from the user are generally aggregated by total fair market value, total number of units and number of transactions and, where the RCASP knows the nature of the transaction, may be further identified as airdrops, staking income, mining income, cryptoasset loans, collateral and other categories. For transfers to external wallets that are not known to be associated with a VASP or financial institution, the aggregate fair market value and aggregate number of units of the relevant cryptoasset are reported separately.
2.4 Where Does the Information Go After HMRC Receives It?

The OECD CARF framework is primarily designed for cross-border exchange, but UK domestic law extends it to domestic reporting. UK CARF information therefore flows through three channels:
1. Domestic use: UK RCASPs report data on UK-resident users to HMRC, which may use the data directly for domestic tax compliance checks.
2. Outbound exchange: UK RCASPs report data on non-UK-resident users to HMRC. Once the relevant exchange relationship is effective, HMRC sends the data to the users’ jurisdictions of tax residence.
3. Inbound exchange: Data generated by UK tax residents at overseas RCASPs may first be reported to the local tax authority and then exchanged by that authority with HMRC.
Accordingly, a platform’s reporting to HMRC and HMRC’s exchange of information with foreign tax authorities are not the same action. The former is the RCASP’s submission of data to HMRC under UK domestic law; the latter is a cross-border exchange between tax authorities and remains subject to conditions including partner jurisdictions and activated exchange relationships.
2.5 Penalty Regime
UK CARF penalties do not apply only to failures to file the annual report. Separate penalties may arise in relation to due diligence, self-certification, record-keeping, user notifications, report filing and registration. The table below sets out the statutory maximum amounts. HMRC will decide whether to impose a penalty and the amount by reference to the nature of the conduct, any reasonable excuse and the steps taken to remedy the failure.

3 What CARF Means for Service Providers and Investors
3.1 For Service Providers: Existing KYC Is Not Enough — Additional Tax Information and Transaction Classification Are Required
The most immediate change brought by CARF is the integration of tax due diligence and transaction reporting into service providers’ day-to-day operations. Service providers can reuse some KYC information, but anti-money laundering identity data cannot simply replace a CARF self-certificate. The jurisdiction in which a user is tax resident, whether the tax identification number (TIN) information meets the requirements, how an entity is classified, and whether controlling persons need to be identified all require separate consideration.

Although the first report is due in 2027, service providers cannot wait until the reporting service goes live before organising historical data. If self-certificates for pre-existing users, external wallet records or annual transaction information are missing at source, it may be difficult to prepare a complete report later.
3.2 For Investors: Platform-Reported Aggregates Are Not the Same as Taxable Income
CARF does not change existing taxes or tax-computation rules, and data reported by a platform is not a tax calculation. Platforms may report aggregated data on acquisitions and disposals against fiat currency, crypto-to-crypto exchanges and transfers to external wallets, while individual tax filings must still apply UK tax law to determine the nature of each transaction and calculate costs and gains. Transfers between a user’s own wallets where the user retains beneficial ownership generally do not constitute a disposal for Capital Gains Tax purposes, even if the platform includes the transfer in CARF data.

HMRC has stated that CARF information will be used to link cryptoasset activity to taxpayers’ tax records. Investors should retain records of the type of cryptoasset, transaction dates, number of units, sterling value on the transaction date, purchase and sale records, bank statements and wallet addresses, together with supporting evidence for cost, expense and valuation calculations.
3.3 Overseas Platforms and External Wallets Are Not Information Blind Spots
When UK tax residents use overseas RCASPs participating in CARF, relevant data may reach HMRC through cross-border exchange. Transfers from a UK RCASP to an external wallet not known to be associated with a VASP or financial institution may also be reported by the platform on an aggregated basis as transfers to external wallet addresses. For investors, the key issue should not simply be whether a particular transaction can be seen by a platform, but whether tax residence information, self-certificates, transaction records and personal tax filings can be reconciled and explained consistently. CARF reports “what transactions occurred”; tax law then determines “how much taxable income or gain those transactions generated.”
Conclusion
The UK CARF first-reporting deadline is not until May 2027, but the quality of that report will be determined by the user and transaction data service providers create and retain throughout 2026. Scope determinations, tax self-certificates, transaction classification, external wallet identification and evidence retention all need to be addressed before the filing window opens.
For service providers, CARF is a year-round data and compliance requirement. For investors, CARF itself does not change existing tax rules, but it creates a more direct reconciliation link among platform data, cross-border information exchange and individual tax filings. CARF reporting by service providers and individual tax reporting serve different purposes and use different calculation methodologies; the specific tax treatment still depends on the facts of the transaction and the applicable tax law.
Send this FinTax note to your team.