FATCA reporting software · Form 8966 & IDES-ready

    FATCA reporting, automated end-to-end.

    ComplianceSuite turns the US Foreign Account Tax Compliance Act into a one-button workflow. Capture W-8 / W-9 self-certifications, run continuous US-indicia detection, validate TINs, generate schema-validated Form 8966 XML and submit via IDES — directly or through Model 1 local authorities — with four-eyes approvals and an immutable audit trail.

    What is FATCA?

    FATCA in one paragraph.

    The US Foreign Account Tax Compliance Act (FATCA) requires foreign financial institutions to identify accounts held by US persons and US-owned passive non-financial entities, and report them to the IRS. Reporting is filed on Form 8966 and transmitted through the International Data Exchange Service (IDES) — either directly to the IRS (Model 2 and non-IGA jurisdictions) or via the local tax authority (Model 1 IGAs). FFIs that fail to register and report face 30% withholding on US-source income.

    FATCA and CRS share most of their customer-due-diligence surface. ComplianceSuite runs them on a single self-certification, indicia and TIN-validation workflow — so one cycle of work feeds both Form 8966 and OECD CRS XML v2.0 outputs.

    • Form 8966 XML generation aligned with IRS schema
    • IDES-ready PKI-encrypted package creation
    • Model 1 (via local authority) and Model 2 (direct to IRS) routing
    • W-9 / W-8BEN / W-8BEN-E / W-8IMY self-certification capture
    • Continuous US-indicia detection with curing workflow
    • US TIN validation and missing-TIN handling (IRS Notice 2023-11)
    • GIIN tracking against IRS FFI list
    • Pre-submission schema validation & rejection remediation
    • Per-entity, per-jurisdiction filing calendar with deadline alerts

    FATCA reporting capabilities

    Built for every step of a FATCA cycle.

    Form 8966 XML & IDES packages

    Schema-validated FATCA Form 8966 generation and IDES-ready PKI-encrypted package creation with acknowledgement tracking.

    Model 1 & Model 2 IGAs

    Per-jurisdiction routing, schema variants and validation rules — from US direct (Model 2) to local-authority transmission (Model 1).

    US-indicia engine

    Continuous detection of US-indicia (place of birth, address, telephone, standing instructions) with built-in curing workflow.

    TIN validation & missing-TIN handling

    US TIN format validation plus IRS Notice 2023-11 missing-TIN code application and annual solicitation tracking.

    Per-entity filing calendar

    Per-FFI, per-jurisdiction FATCA deadlines, breach alerts and four-eyes approval queues across the group.

    Audit-ready trail

    Every classification, self-certification, indicia hit, reviewer action, IDES upload and acknowledgement preserved in the immutable vault.

    How FATCA reporting works in ComplianceSuite

    From onboarding to IDES — one workflow.

    1. 1

      Classify

      Customers and entities classified at onboarding — Specified US Person, Active NFFE, Passive NFFE, Participating FFI, Non-Participating FFI — using the FATCA decision tree.

    2. 2

      Certify

      Digital W-9 / W-8BEN / W-8BEN-E / W-8IMY self-certifications collected and refreshed on every change of circumstance.

    3. 3

      Detect US-indicia

      Continuous rules look for US place of birth, US address, US telephone, US standing instructions and hold-mail indicia across the entire book.

    4. 4

      Cure

      Detected indicia open a curing case that requests fresh evidence, routes to a reviewer and updates reportable status before the next reporting cycle.

    5. 5

      Validate

      Account balances and income are merged with classification data and pre-validated against the FATCA XML schema and IRS business rules.

    6. 6

      Submit & acknowledge

      Form 8966 is signed, encrypted to IDES standards and submitted (directly or via local authority); IDES notifications and rejections flow into the remediation queue.

    FATCA jurisdictions

    File FATCA from any IGA jurisdiction — or direct.

    ComplianceSuite supports both Model 1 (file with local tax authority) and Model 2 (file directly with the IRS via IDES) routing — with per-jurisdiction validation, transmission and nil-return rules.

    United States · IRS (IDES direct)
    Cyprus · Tax Department (Model 1)
    Luxembourg · ACD (Model 1)
    Ireland · Revenue (Model 1)
    United Kingdom · HMRC (Model 1)
    Germany · BZSt (Model 1)
    France · DGFiP (Model 1)
    Spain · AEAT (Model 1)
    Italy · Agenzia delle Entrate (Model 1)
    Malta · CfR (Model 1)
    Switzerland · FTA (Model 2)
    Japan · NTA (Model 2)
    UAE · Ministry of Finance (Model 1)
    Singapore · IRAS (Model 1)
    Hong Kong · IRD (Model 2)
    Canada · CRA (Model 1)
    Australia · ATO (Model 1)
    South Africa · SARS (Model 1)

    Don't see your jurisdiction? Talk to us — new jurisdictions are added on a rolling basis.

    FATCA vs CRS

    One self-certification. Two regimes.

    FATCA and CRS share most of their customer-due-diligence surface — but most teams still run them in separate spreadsheets and submit through different toolchains. ComplianceSuite unifies them: one digital self-certification, one indicia engine, one TIN validator — feeding both FATCA Form 8966 (IDES) and OECD CRS XML v2.0 outputs.

    FATCA

    • · US-specific regime (IRC chapters 4 / 1471–1474)
    • · Reports US-person accounts
    • · Form 8966 submitted via IDES (PKI-encrypted)
    • · Model 1 IGAs route via local tax authority
    • · 30% withholding for non-compliant FFIs

    CRS

    • · Multilateral OECD standard
    • · 120+ participating jurisdictions
    • · OECD CRS XML schema v2.0 (mandatory 2026)
    • · Reports tax residents of CRS partner jurisdictions
    • · Filed with local tax authority for onward exchange

    Running FATCA and CRS on separate systems is the #1 source of duplicate classification errors in regulator inspections. A single source of truth eliminates it.

    FAQ

    FATCA reporting, answered.

    What is FATCA reporting?

    FATCA (the US Foreign Account Tax Compliance Act, IRC chapters 4 and 1471–1474) requires non-US foreign financial institutions (FFIs) to identify accounts held by US persons and US-owned passive non-financial entities, and report them to the IRS. Reporting is filed on Form 8966 and transmitted through the IRS International Data Exchange Service (IDES), either directly (Model 2 IGAs and non-IGA jurisdictions) or via the local tax authority (Model 1 IGAs).

    Who has to file FATCA reports?

    Any foreign financial institution — banks, custodians, broker-dealers, investment entities, specified insurance companies — that has registered with the IRS for a Global Intermediary Identification Number (GIIN) and holds reportable US accounts. Many jurisdictions also require a nil return where no reportable accounts exist.

    What is Form 8966 and how is it filed via IDES?

    Form 8966 is the FATCA Report — the XML record describing each reportable US account, including the account holder's US TIN, name, address, account balance and income. The completed XML is signed, encrypted to IDES standards (PKI certificate-based) and uploaded either directly to IDES (Model 2 / non-IGA) or to the local tax authority's portal for onward transmission (Model 1). ComplianceSuite generates schema-validated Form 8966 XML, builds the IDES-ready encrypted package and tracks acknowledgements end-to-end.

    What's the difference between Model 1 and Model 2 IGAs?

    Model 1 Intergovernmental Agreements route FATCA reports through the local tax authority, which then exchanges with the IRS — used in most EU jurisdictions, Canada, the UK and many others. Model 2 IGAs require the FFI to report directly to the IRS via IDES (Japan, Switzerland and Bermuda are the most common). ComplianceSuite is configured per jurisdiction so the routing, schema variant and validation rules apply automatically.

    How does FATCA reporting differ from CRS?

    FATCA is US-specific and reports US-person accounts to the IRS. CRS is the OECD's multilateral equivalent and reports tax residents of 120+ partner jurisdictions to their local tax authority. Customer due diligence (self-certification, indicia, TIN validation) overlaps significantly, so ComplianceSuite runs one workflow that feeds both FATCA Form 8966 and CRS XML v2.0 outputs — eliminating duplicate classification and reconciliation work.

    What happens when an FFI loses GIIN status or has missing TINs?

    ComplianceSuite tracks GIIN status against the IRS FFI list and flags counterparty changes that could affect classification. Missing-TIN cases follow IRS Notice 2023-11 procedures — recording the reason code, attempting annual TIN solicitation and applying the appropriate missing-TIN code on the FATCA Report — with every step preserved in the audit trail.

    How are FATCA submissions secured?

    AES-256 encryption at rest, TLS 1.3 in transit, IDES-grade PKI encryption for outgoing packages and role-based access with maker-checker controls. ComplianceSuite is ISO 27001, ISO 9001 and ISO 22301 certified and GDPR-aligned, with EU, UK, US and APAC residency options for FATCA data.

    What happens if the IRS or local authority rejects a FATCA submission?

    Rejections — IDES notifications or local-authority error files — land in the error-remediation queue with error codes mapped to plain-language explanations and the specific account record highlighted. Reviewers correct the record, re-validate against the FATCA XML schema and resubmit as a corrected, amended or void record, with every action versioned in the immutable audit log.

    See ComplianceSuite file a FATCA Form 8966.

    Bring an anonymised customer extract — we'll classify it, simulate US-indicia detection, generate the Form 8966 XML and walk you through IDES packaging in 30 minutes.