
Crypto is becoming harder to keep outside the traditional tax-reporting system.
The OECD’s Crypto-Asset Reporting Framework (CARF) was developed to bring greater tax transparency to cryptoassets by requiring relevant service providers to collect and report tax-related information about their users and transactions. The UK has implemented CARF from 1 January 2026, with the first international exchanges of information planned for 2027.
For crypto exchanges and other affected service providers, this creates a practical challenge that goes beyond generating an annual report.
Before you can report the right tax information, you need to know exactly who your customers are, where they are tax resident, and whether the information attached to their accounts is complete and reliable.
And for platforms with large existing customer bases, that may be the difficult part.
What CARF changes for crypto platforms
CARF creates a standardized system through which tax authorities can receive and exchange information about cryptoasset users and transactions.
In the UK, Reporting Cryptoasset Service Providers are required to undertake due diligence and report relevant transactional information to HMRC annually.
This means crypto platforms need processes capable of connecting transactions to identifiable, reportable customers.
The required customer data can include information such as their name, address, date of birth, tax residence and tax identification number, alongside information concerning relevant cryptoasset transactions.
The tax-reporting obligation therefore starts much earlier than the point at which a report is submitted to HMRC.
It starts with customer data collection and verification.
Crypto tax compliance starts with knowing who owns the account
Transaction records are only useful for tax reporting when a platform can reliably associate them with the correct customer.
That sounds simple, but crypto platforms can have millions of accounts created at different stages of the industry’s development and under different onboarding requirements.
Some users may have provided limited information when registering. Others may have moved countries, changed tax residence or have outdated personal information attached to their accounts.
That creates an important question for compliance teams:
Is the customer information you already hold sufficient for today’s tax-reporting requirements?
For some businesses, CARF may therefore become not only a reporting project but also a customer remediation project.
Existing users may need to provide missing information, confirm their tax residence or complete additional verification before their records can confidently be used for reporting.
Tax residence makes customer data more important
One particularly important part of CARF is determining where a cryptoasset user is reportable.
This matters because CARF is designed around the exchange of tax-relevant information between participating jurisdictions. HMRC’s guidance requires service providers to carry out due diligence to establish whether users are reportable and collect the required information.
For platforms serving customers internationally, that means identity information, address data and tax information cannot exist as disconnected pieces of information.
They need to form a reliable customer record.
And when information is missing or inconsistent, the platform needs a practical way to obtain or verify it.
Where identity verification fits into crypto tax reporting
Identity verification does not calculate a customer’s tax liability, and it does not replace tax-reporting systems.
Its role comes earlier.
A reliable verification process can help establish that:
the customer is who they claim to be;
the information belongs to the correct person;
relevant customer details can be collected consistently;
and additional information can be requested when existing records are incomplete.
For crypto platforms preparing for CARF, that foundation becomes increasingly important.
Identomat allows businesses to combine identity verification, liveness checks, address verification, KYC questionnaires and AML screening within configurable verification workflows.
For example, a new crypto customer could complete identity verification while providing the additional information required by the platform.
An existing customer whose identity has already been established may instead be asked only for missing information.
And where the customer is a company rather than an individual, KYB processes can be used to collect information about the business, its representatives and beneficial owners.
That is particularly relevant when crypto platforms need to bring older customer records up to today’s compliance standards without unnecessarily forcing every user through the same onboarding journey again.
From crypto tax reporting to better customer data
CARF is fundamentally a tax transparency framework.
But its implementation highlights a broader issue for crypto businesses: regulatory reporting is only as reliable as the customer information behind it.
A platform may have excellent transaction records, but if those transactions cannot be confidently connected to the right customer, tax residence and identifying information, reporting becomes significantly more difficult.
This is why crypto tax compliance should not be treated solely as an end-of-year reporting exercise.
It requires the right customer-data infrastructure throughout the relationship.
As tax authorities gain greater visibility into crypto activity, crypto platforms will increasingly need to make sure they can answer two questions equally well:
What did this customer do?
and
Who exactly is this customer?
Identomat helps crypto businesses build configurable verification workflows around that second question.
Need to prepare your customer verification process for evolving crypto compliance requirements?


