Custodial providers are in scope as reporting CASPs. Here's the due-diligence and reporting obligation for a custodian, including the transfer edge cases.

Hold crypto for users and move it on their behalf, and you're a reporting CASP under CARF and DAC8. Your version of the obligation looks a bit different from a trading venue's. Most of what you do is hold and move assets, not match trades. This guide walks through what that means, and where the awkward parts hide.
For a custodian, the in-scope question almost always lands on yes. Holding crypto and moving it for users is exactly the service CARF was written to catch. Your reporting country comes from where the business is based rather than where users sit, so most custodians file in just one. The nexus guide walks through that test.
Your compliance rests on the same onboarding checks every CASP runs. A self-certification, collected and reasonableness-checked. The tax ID, validated. Controlling persons captured for company accounts. All of it logged as an audit trail. That workflow is laid out in self-certification and TIN validation, and it's precisely what the report draws on.
Since custody is really about holding and moving assets, your hard cases are the transfers. Withdrawals to wallets you don't control. Retail payments above the reportable threshold. CARF marks some transfers as reportable so value doesn't vanish the moment it leaves the regulated system. We work through those in CARF edge cases.
None of this calls for a custom engine. Our CARF and DAC8 platform captures the due diligence, sorts transfers and payments correctly, holds the audit trail, and files in each authority's format. To see where it fits, read exchanges and custodians, or book a demo.
Like any CASP, you file in one country and the data moves onward from there. Even so, the file has to match the exact format each authority accepts, from the OECD schema down to a national variant. Building the right file straight from your custody records, then checking it before submission, is the final step. For what the file actually contains, see the CARF XML schema.
Usually yes. Hold crypto and move it for users, and you're a reporting CASP under CARF and DAC8, carrying the same due-diligence and reporting duties as any other CASP.
Transfers. Withdrawals to wallets outside the regulated system, and retail payments above the reportable threshold. CARF counts some transfers as reportable, so you have to catch and record them.
No. A platform like Kryptos handles the self-certification and due diligence, sorts transfers and payments, holds the audit trail, and files each authority's format. Nothing for you to build.

Brokers face a global layer (CARF/DAC8) and a US domestic layer (1099-DA and backup withholding). Here's how to meet both from one data layer.

Advising a CASP toward CARF and DAC8 readiness? The assessment framework, the common gaps, and how to hand clients a working pipeline, not a slide deck.

Exchanges have users across dozens of jurisdictions. Here's the CARF and DAC8 obligation for a centralised venue, and why buying beats building it.
Generate an audit-ready report aligned to your jurisdiction. No credit card required.