OECD CRS XML schema v2.0
Schema-validated generation aligned with the 2026-mandatory CRS XML v2.0, with CARF readiness for crypto-asset service providers.
ComplianceSuite turns the OECD Common Reporting Standard into a one-button workflow. Capture digital self-certifications, run continuous indicia detection, validate TINs, generate schema-validated CRS XML v2.0 and submit to 120+ partner jurisdictions — with four-eyes approvals and an immutable audit trail.
What is the Common Reporting Standard?
The Common Reporting Standard (CRS) is the OECD's global framework for the automatic exchange of financial-account information between tax authorities. Reporting financial institutions in 120+ participating jurisdictions identify accounts held by non-resident tax payers, classify entities under the OECD decision tree (Active NFE, Passive NFE, Financial Institution) and submit annual CRS XML returns containing balances, income and gross proceeds. Local tax authorities then exchange the files with the account-holder's jurisdiction of tax residence.
From the 2026 exchange cycle, the amended CRS XML schema v2.0 becomes mandatory, and the parallel Crypto-Asset Reporting Framework (CARF) adds reporting obligations for crypto-asset service providers. ComplianceSuite supports both today.
CRS reporting capabilities
Schema-validated generation aligned with the 2026-mandatory CRS XML v2.0, with CARF readiness for crypto-asset service providers.
Per-jurisdiction validation rules, nil-return logic, transmission channels and authority error-code mapping out of the box.
Digital CRS/FATCA self-certifications, continuous indicia detection and a built-in curing workflow with reviewer sign-off.
Format and check-digit validation for 100+ jurisdictions' tax identification numbers — catch errors before the authority does.
Per-legal-entity, per-jurisdiction deadlines, breach alerts and four-eyes approval queues — one calendar for the whole group.
Every classification decision, self-certification, indicia hit, reviewer action and submission XML preserved in the encrypted, immutable vault.
How CRS reporting works in ComplianceSuite
Classify
Customers and entities are classified at onboarding — Reportable Person, Active NFE, Passive NFE, Financial Institution — using the OECD decision tree.
Certify
Digital CRS and FATCA self-certifications are collected and re-collected on every change of circumstance, with version history.
Detect indicia
Continuous rules look for residence, address, telephone, standing-instruction and hold-mail indicia across the entire customer book.
Cure
Detected indicia open a curing case that requests fresh evidence, routes to a reviewer, and updates reportable status before the next cycle.
Validate
Account balances, income and proceeds are merged with classification data and pre-validated against the OECD CRS XML v2.0 schema.
Submit & resubmit
Files are submitted to the local tax authority via API or portal upload; rejections flow into the remediation queue with versioned corrections.
CRS jurisdictions
ComplianceSuite covers the full set of CRS XML v2.0 reportable jurisdictions, with validated submission flows for the authorities below — and configurable validation, transmission and nil-return rules for every other CRS partner.
Don't see your jurisdiction? Talk to us — new jurisdictions are added on a rolling basis.
CRS vs FATCA
CRS and FATCA share most of their customer-due-diligence surface — but most teams still run them in separate spreadsheets and submit through different toolchains. ComplianceSuite unifies them: one digital self-certification, one indicia engine, one TIN validator — feeding both OECD CRS XML v2.0 and FATCA Form 8966 (IDES) outputs.
Running CRS and FATCA on separate systems is the #1 source of duplicate classification errors we see in regulator inspections. A single source of truth eliminates it.
FAQ
CRS (Common Reporting Standard) reporting is the annual exchange of financial-account information between tax authorities under the OECD's global tax-transparency framework. Reporting financial institutions (banks, custodians, investment entities, certain insurers) identify reportable accounts held by tax residents of CRS partner jurisdictions and submit account-balance, income and proceeds data to their local tax authority in OECD CRS XML format. The local authority then exchanges the file with the account-holder's jurisdiction of tax residence.
Custodial institutions, depository institutions, investment entities and specified insurance companies in any of the 120+ CRS-participating jurisdictions must report. Reportable accounts are those held by individuals tax-resident in a CRS partner jurisdiction, or by passive non-financial entities (NFEs) with controlling persons tax-resident in a partner jurisdiction. Nil returns are required in many jurisdictions even when no reportable accounts exist.
CRS XML schema v2.0 is the OECD's updated reporting schema that becomes mandatory for exchanges from 2026 onward (covering 2025 reporting year data in most jurisdictions). It adds fields for account type, joint-account flagging, role-based controlling-person classification and pre-existing-account indicators. CARF — the Crypto-Asset Reporting Framework — is a parallel OECD framework for crypto-asset service providers, with its own XML schema, that runs alongside the amended CRS from 2026. ComplianceSuite supports CRS v2.0 today and is CARF-ready.
Self-certifications (CRS and FATCA) are collected through a configurable digital form at onboarding and at every change of circumstance. Indicia rules — residence indicia, address-of-record, telephone, standing-instruction and hold-mail indicia — run continuously over the customer book. When indicia are detected the platform opens a curing workflow that requests fresh evidence, routes to a reviewer for sign-off and updates the reportable-status flag before the next reporting cycle.
Out of the box we support the full set of CRS XML v2.0 reportable jurisdictions and have validated submission flows for the most active reporting authorities — including Cyprus (Tax Department), Luxembourg (ACD), Ireland (Revenue), the Netherlands (Belastingdienst), the UK (HMRC), Germany (BZSt), France (DGFiP), the UAE (MoF), Singapore (IRAS), Hong Kong (IRD) and Canada (CRA). Local validations, transmission rules and nil-return handling are configured per jurisdiction.
FATCA is the US-specific regime requiring non-US financial institutions to identify and report US-person accounts to the IRS (via IDES, on Form 8966). CRS is the multilateral equivalent, covering tax residents of 120+ jurisdictions. Customer due diligence overlaps significantly, so ComplianceSuite runs one self-certification and indicia workflow that feeds both CRS XML and FATCA Form 8966 outputs — eliminating duplicate classification and reconciliation work.
Rejections from the local tax authority land in the error-remediation queue with the authority's error codes mapped to plain-language explanations and the specific account record highlighted. Reviewers correct the record, re-validate against the OECD schema and resubmit — with every action versioned in the immutable audit trail and a corrected-record indicator set on the resubmission.
Yes. AES-256 encryption at rest with optional customer-managed KMS, TLS 1.3 in transit, role-based access with maker-checker controls, and an immutable audit log of every read, write and submission. ComplianceSuite is ISO 27001, ISO 9001 and ISO 22301 certified, GDPR-aligned, and offers EU, UK, US and APAC data-residency options.
Bring an anonymised customer extract — we'll classify it, simulate indicia detection, generate the CRS XML v2.0 and walk you through validation in 30 minutes.
We use essential cookies to make ComplianceSuite work. With your consent, we'll also use analytics and marketing cookies to improve the site and measure campaign performance. You can change your choice at any time. Read our Privacy Policy and Cookie Notice.