CARF and DAC8 for crypto custodians: compliance without a build
Custodial providers are in scope as reporting CASPs. Here's the due-diligence and reporting obligation for a custodian, including the transfer edge cases.

Hold crypto for users and move it on their behalf, and you're a reporting CASP under CARF and DAC8. Your version of the obligation looks a bit different from a trading venue's. Most of what you do is hold and move assets, not match trades. This guide walks through what that means, and where the awkward parts hide.
Yes, you're a reporting CASP
For a custodian, the in-scope question almost always lands on yes. Holding crypto and moving it for users is exactly the service CARF was written to catch. Your reporting country comes from where the business is based rather than where users sit, so most custodians file in just one. The nexus guide walks through that test.
The full due-diligence workflow, with an audit trail
Your compliance rests on the same onboarding checks every CASP runs. A self-certification, collected and reasonableness-checked. The tax ID, validated. Controlling persons captured for company accounts. All of it logged as an audit trail. That workflow is laid out in self-certification and TIN validation, and it's precisely what the report draws on.
Transfers are the tricky part
Since custody is really about holding and moving assets, your hard cases are the transfers. Withdrawals to wallets you don't control. Retail payments above the reportable threshold. CARF marks some transfers as reportable so value doesn't vanish the moment it leaves the regulated system. We work through those in CARF edge cases.
No build needed
None of this calls for a custom engine. Our CARF and DAC8 platform captures the due diligence, sorts transfers and payments correctly, holds the audit trail, and files in each authority's format. To see where it fits, read exchanges and custodians, or book a demo.
Report once, in the right format
Like any CASP, you file in one country and the data moves onward from there. Even so, the file has to match the exact format each authority accepts, from the OECD schema down to a national variant. Building the right file straight from your custody records, then checking it before submission, is the final step. For what the file actually contains, see the CARF XML schema.



