CRS reporting software · OECD CRS XML v2.0 ready

    CRS reporting, automated end-to-end.

    ComplianceSuite turns the OECD Common Reporting Standard into a one-button workflow. Capture digital self-certifications, run continuous indicia detection, validate TINs, generate schema-validated CRS XML v2.0 and submit to 120+ partner jurisdictions — with four-eyes approvals and an immutable audit trail.

    What is the Common Reporting Standard?

    CRS in one paragraph.

    The Common Reporting Standard (CRS) is the OECD's global framework for the automatic exchange of financial-account information between tax authorities. Reporting financial institutions in 120+ participating jurisdictions identify accounts held by non-resident tax payers, classify entities under the OECD decision tree (Active NFE, Passive NFE, Financial Institution) and submit annual CRS XML returns containing balances, income and gross proceeds. Local tax authorities then exchange the files with the account-holder's jurisdiction of tax residence.

    From the 2026 exchange cycle, the amended CRS XML schema v2.0 becomes mandatory, and the parallel Crypto-Asset Reporting Framework (CARF) adds reporting obligations for crypto-asset service providers. ComplianceSuite supports both today.

    • OECD CRS XML schema v2.0 — mandatory from 2026
    • CARF (Crypto-Asset Reporting Framework) readiness
    • Reportable Person, Active NFE, Passive NFE & FI classification
    • Self-certification capture for CRS and FATCA in one flow
    • Continuous indicia detection with curing workflow
    • TIN format and check-digit validation for 100+ jurisdictions
    • Pre-submission schema validation & error remediation queue
    • Multi-entity, multi-jurisdiction filing calendar with deadline alerts

    CRS reporting capabilities

    Built for every step of a CRS cycle.

    OECD CRS XML schema v2.0

    Schema-validated generation aligned with the 2026-mandatory CRS XML v2.0, with CARF readiness for crypto-asset service providers.

    120+ CRS jurisdictions

    Per-jurisdiction validation rules, nil-return logic, transmission channels and authority error-code mapping out of the box.

    Self-certification & indicia engine

    Digital CRS/FATCA self-certifications, continuous indicia detection and a built-in curing workflow with reviewer sign-off.

    TIN validation

    Format and check-digit validation for 100+ jurisdictions' tax identification numbers — catch errors before the authority does.

    Multi-entity filing calendar

    Per-legal-entity, per-jurisdiction deadlines, breach alerts and four-eyes approval queues — one calendar for the whole group.

    Audit-ready trail

    Every classification decision, self-certification, indicia hit, reviewer action and submission XML preserved in the encrypted, immutable vault.

    How CRS reporting works in ComplianceSuite

    From onboarding to submission — one workflow.

    1. 1

      Classify

      Customers and entities are classified at onboarding — Reportable Person, Active NFE, Passive NFE, Financial Institution — using the OECD decision tree.

    2. 2

      Certify

      Digital CRS and FATCA self-certifications are collected and re-collected on every change of circumstance, with version history.

    3. 3

      Detect indicia

      Continuous rules look for residence, address, telephone, standing-instruction and hold-mail indicia across the entire customer book.

    4. 4

      Cure

      Detected indicia open a curing case that requests fresh evidence, routes to a reviewer, and updates reportable status before the next cycle.

    5. 5

      Validate

      Account balances, income and proceeds are merged with classification data and pre-validated against the OECD CRS XML v2.0 schema.

    6. 6

      Submit & resubmit

      Files are submitted to the local tax authority via API or portal upload; rejections flow into the remediation queue with versioned corrections.

    CRS jurisdictions

    File CRS in the jurisdictions that matter to you.

    ComplianceSuite covers the full set of CRS XML v2.0 reportable jurisdictions, with validated submission flows for the authorities below — and configurable validation, transmission and nil-return rules for every other CRS partner.

    Cyprus · Tax Department
    Luxembourg · ACD
    Ireland · Revenue
    Netherlands · Belastingdienst
    United Kingdom · HMRC
    Germany · BZSt
    France · DGFiP
    Spain · AEAT
    Italy · Agenzia delle Entrate
    Malta · CfR
    Switzerland · FTA
    UAE · Ministry of Finance
    Saudi Arabia · ZATCA
    Singapore · IRAS
    Hong Kong · IRD
    Australia · ATO
    Canada · CRA
    South Africa · SARS

    Don't see your jurisdiction? Talk to us — new jurisdictions are added on a rolling basis.

    CRS vs FATCA

    One self-certification. Two regimes.

    CRS and FATCA share most of their customer-due-diligence surface — but most teams still run them in separate spreadsheets and submit through different toolchains. ComplianceSuite unifies them: one digital self-certification, one indicia engine, one TIN validator — feeding both OECD CRS XML v2.0 and FATCA Form 8966 (IDES) outputs.

    CRS

    • · Multilateral OECD standard
    • · 120+ participating jurisdictions
    • · OECD CRS XML schema v2.0 (mandatory 2026)
    • · Reports tax residents of CRS partner jurisdictions
    • · Filed with local tax authority for onward exchange

    FATCA

    • · US-specific regime (IRC chapters 4 / 1471–1474)
    • · Reports US-person accounts
    • · Form 8966 submitted via IDES
    • · Model 1 IGAs route via local tax authority
    • · Shares self-certification & indicia with CRS

    Running CRS and FATCA on separate systems is the #1 source of duplicate classification errors we see in regulator inspections. A single source of truth eliminates it.

    FAQ

    CRS reporting, answered.

    What is CRS reporting?

    CRS (Common Reporting Standard) reporting is the annual exchange of financial-account information between tax authorities under the OECD's global tax-transparency framework. Reporting financial institutions (banks, custodians, investment entities, certain insurers) identify reportable accounts held by tax residents of CRS partner jurisdictions and submit account-balance, income and proceeds data to their local tax authority in OECD CRS XML format. The local authority then exchanges the file with the account-holder's jurisdiction of tax residence.

    Who has to file CRS reports?

    Custodial institutions, depository institutions, investment entities and specified insurance companies in any of the 120+ CRS-participating jurisdictions must report. Reportable accounts are those held by individuals tax-resident in a CRS partner jurisdiction, or by passive non-financial entities (NFEs) with controlling persons tax-resident in a partner jurisdiction. Nil returns are required in many jurisdictions even when no reportable accounts exist.

    What is CRS XML schema v2.0 — and what changes with CARF?

    CRS XML schema v2.0 is the OECD's updated reporting schema that becomes mandatory for exchanges from 2026 onward (covering 2025 reporting year data in most jurisdictions). It adds fields for account type, joint-account flagging, role-based controlling-person classification and pre-existing-account indicators. CARF — the Crypto-Asset Reporting Framework — is a parallel OECD framework for crypto-asset service providers, with its own XML schema, that runs alongside the amended CRS from 2026. ComplianceSuite supports CRS v2.0 today and is CARF-ready.

    How does ComplianceSuite handle self-certifications and indicia?

    Self-certifications (CRS and FATCA) are collected through a configurable digital form at onboarding and at every change of circumstance. Indicia rules — residence indicia, address-of-record, telephone, standing-instruction and hold-mail indicia — run continuously over the customer book. When indicia are detected the platform opens a curing workflow that requests fresh evidence, routes to a reviewer for sign-off and updates the reportable-status flag before the next reporting cycle.

    Which jurisdictions can we file CRS in from ComplianceSuite?

    Out of the box we support the full set of CRS XML v2.0 reportable jurisdictions and have validated submission flows for the most active reporting authorities — including Cyprus (Tax Department), Luxembourg (ACD), Ireland (Revenue), the Netherlands (Belastingdienst), the UK (HMRC), Germany (BZSt), France (DGFiP), the UAE (MoF), Singapore (IRAS), Hong Kong (IRD) and Canada (CRA). Local validations, transmission rules and nil-return handling are configured per jurisdiction.

    How does CRS differ from FATCA?

    FATCA is the US-specific regime requiring non-US financial institutions to identify and report US-person accounts to the IRS (via IDES, on Form 8966). CRS is the multilateral equivalent, covering tax residents of 120+ jurisdictions. Customer due diligence overlaps significantly, so ComplianceSuite runs one self-certification and indicia workflow that feeds both CRS XML and FATCA Form 8966 outputs — eliminating duplicate classification and reconciliation work.

    What happens if a CRS submission is rejected?

    Rejections from the local tax authority land in the error-remediation queue with the authority's error codes mapped to plain-language explanations and the specific account record highlighted. Reviewers correct the record, re-validate against the OECD schema and resubmit — with every action versioned in the immutable audit trail and a corrected-record indicator set on the resubmission.

    Is CRS reporting data secure?

    Yes. AES-256 encryption at rest with optional customer-managed KMS, TLS 1.3 in transit, role-based access with maker-checker controls, and an immutable audit log of every read, write and submission. ComplianceSuite is ISO 27001, ISO 9001 and ISO 22301 certified, GDPR-aligned, and offers EU, UK, US and APAC data-residency options.

    See ComplianceSuite file a CRS return.

    Bring an anonymised customer extract — we'll classify it, simulate indicia detection, generate the CRS XML v2.0 and walk you through validation in 30 minutes.