The CARF 60-day rule: reminders, cure periods, and blocking users
Under CARF, a user who won't self-certify can't transact forever. Here's the reminder cadence, the cure period, and when you have to block the account.

CARF won't let a user sit in limbo. Say someone opens an account and never hands over a valid self-certification. You can't keep letting them trade and hope they'll come around. The framework hands you a defined path, and a restriction waits at the end of it.
The cadence
When a self-certification is missing or fails validation, you chase it. In practice that's at least two reminders across a 60-day window. The clock and those reminders become the documented trail you point to if a regulator asks why an account was restricted, or why it wasn't.
The cure period
Those 60 days are a cure period, the user's chance to close the gap. A valid certification inside the window and nothing changes; they carry on as normal. The goal comes down to a binary. Either you hold the tax data CARF requires, or you've stopped the reportable activity that depends on it.
The block
If the cure period lapses and there's still no valid certification, you have to stop the user from making further reportable transactions until they comply. Certify, and the restriction lifts on the spot. A gate, then, rather than a permanent bar.
Why automation matters here
This workflow runs per user, on a per-user clock, and it never stops. Do it by hand across a large book and something slips, and a missed block is precisely the kind of gap an audit surfaces. The self-certification and validation that feed it are covered in our CARF onboarding workflow piece. Our CARF and DAC8 reporting platform runs the full cadence. It tracks each user's certification status, sends the reminders, blocks reportable transactions once the window closes, and clears the block the instant a valid certification lands. For where this sits in a venue's stack, see exchanges and custodians, and the OECD exchange-of-information hub for the source framework.



