CARF2026-09-09 02:26:16What RCASPs Must Report Under CARF and How Local Rules Change the FilingFinTax has published a detailed breakdown of what crypto platforms must actually report under the Crypto-Asset Reporting Framework, or CARF, after the questions of who reports and where they report have already been settled. Under the OECD standard, a Reporting Crypto-Asset Service Provider (RCASP) must identify reportable users and relevant controlling persons through due diligence, classify their crypto transactions, and submit three main categories of information: RCASP data, user data, and transaction data. The article says the OECD framework sets a common international baseline, but final filing obligations are shaped by local law and technical guidance in each jurisdiction. That creates practical differences in several areas, including whether domestic tax residents must be reported, which fiat currency must be used for valuation, whether the $50,000 retail payment threshold is converted into a local-currency standard, how tax identification numbers are defined, and whether nil returns are required when no reportable information exists. FinTax also argues that CARF preparation cannot be left to the filing deadline. For RCASPs, compliance work needs to be built into customer management, KYC and tax due diligence, valuation methods, and transaction data architecture. For firms operating across borders, the same customer and transaction set may need to be configured differently for different jurisdictions when annual CARF reports are prepared.440
Japan2026-08-07 08:55:53Japan FSA Moves to Unify Cybersecurity Report Formats, Including for Crypto Asset ExchangesJapan's Financial Services Agency (FSA) has published a partial revision to its Comprehensive Supervision Guidelines for Major Banks, etc., a move reported by CoinPost. The proposed amendment would standardize cybersecurity incident report formats across 17 regulatory fields, a group that includes crypto asset exchange service providers. Under the revised regime, affected operators would file using a single common template. The draft also introduces a new “Common Format for Other Cyberattack Incidents,” which complements the existing dedicated formats for DDoS attacks and ransomware. Together, the three formats form a reporting system that distinguishes among the main incident categories. A transitional arrangement is in place: until the end of March 2027, operators that are not designated as social infrastructure providers may continue to use the old report forms rather than the new template. The FSA is inviting comments on the draft revision and will accept submissions from interested parties until September 7, 2026.1970