CRS v3.0: what changes for reporting in 2027
The OECD’s CRS v3.0 introduces crypto-asset reporting and tighter due-diligence. A practical summary for firms administering cross-border structures.
A broader net
The OECD's Common Reporting Standard has been the backbone of cross-border tax transparency since 2017. Over 100 jurisdictions exchange financial account information annually under it. CRS v3.0, finalised in 2024 and phasing in from 2027, is the most significant expansion since inception.
For a Trust & Corporate Services Provider, the headline change is scope: CRS v3.0 brings crypto-assets and electronic money into the reporting perimeter, tightens due-diligence on entity accounts, and closes several long-standing avoidance pathways. If your firm administers structures with any digital-asset exposure — even indirectly through a holding company — the 2027 reporting cycle will look different.
This article is a practical summary. It is not legal advice; for entity-specific guidance, consult your regulatory counsel.
The four changes that matter
1. Crypto-asset reporting (the Crypto-Asset Reporting Framework, CARF, merged into CRS)
CRS v3.0 integrates the Crypto-Asset Reporting Framework. Reporting Financial Institutions must now report crypto-asset exchanges and transfers involving Reportable Persons. The definition is broad: any digital representation of value that can be digitally traded or transferred, and can be used for payment or investment.
For a TCSP, this means:
- If a trust or holding company you administer holds crypto-assets through a hosted wallet provider, those positions are now in scope.
- If the entity itself effects crypto-asset exchanges (even occasionally, even through an exchange), you may need to report those transactions.
- Indirect exposure — a portfolio company that holds crypto — may trigger reporting depending on the structure.
2. Wider definition of a Financial Institution
The definition of a Reporting Financial Institution has been tightened. The key change for TCSPs: the "Investment Entity" category now explicitly catches entities that invest or administer assets on behalf of others, regardless of whether they are professionally managed. Some structures that previously fell outside the FI definition — particularly family investment vehicles — are now in scope.
3. Tighter due-diligence on entity accounts
For entity accounts (trusts, companies, partnerships), the due-diligence requirements are stricter:
- Beneficial ownership: the threshold for identifying controlling persons is effectively lowered. The previous 25% bright-line is supplemented by a "any other natural person exercising control" catch-all, aligned with FATF guidance.
- Self-certification reliability: self-certifications must now be confirmed against the platform's own records. A self-certification that contradicts the entity's known structure is not acceptable — you must resolve the discrepancy.
- Documented rationale: the reason a particular classification was applied must be recorded, not just the classification itself.
4. Closed avoidance pathways
CRS v3.0 addresses several structures that were used to dilute reporting under v2:
- Portfolio interest exemption structures designed to route income through non-reporting jurisdictions are explicitly caught.
- Controlling-person misalignment — where the controlling persons of an Investment Entity are in a different jurisdiction than the entity itself — is now resolved in favour of the controlling persons' jurisdiction.
- Custodial chain reporting closes the gap where an account was held through an intermediary in a non-reporting jurisdiction.
What a TCSP needs to do before 2027
The first reporting cycle under CRS v3.0 begins in 2027, covering calendar year 2026. That sounds like time, but the due-diligence changes need to be in place for the 2026 account population — which means your systems need to be ready by early 2026 at the latest.
Four practical steps:
1. Re-scope your account population
Identify every entity you administer with any crypto-asset exposure, even indirect. This includes entities where a portfolio company or underlying holding holds digital assets. Your platform should be able to surface this by querying the asset master, not by manually reviewing each entity.
2. Re-classify your Investment Entities
Review every entity classified as an Investment Entity under CRS v2 and assess whether the tighter definition catches it. Pay particular attention to family investment vehicles and any entity that was previously classified as a Non-Reporting Financial Institution on the basis of professional management.
3. Strengthen your beneficial-ownership data
The lowered threshold for controlling persons means your beneficial-ownership records need to be complete, current, and internally consistent. This is where most firms will find the hardest gap: the data exists, but it lives in a spreadsheet that is reconciled manually and not cross-checked against the entity record.
4. Document your classification rationale
For every entity, record not just the CRS classification but the reasoning behind it. This is a new requirement. If your platform writes this automatically (based on the entity's structure, asset mix, and controlling persons), you are in good shape. If you are doing it in a spreadsheet column, you are not.
The platform question, again
CRS v3.0 exposes the same structural issue that privacy-first AI does: if your client data lives in a governed ledger, compliance is a query. If it lives in a patchwork of spreadsheets and legacy systems, compliance is a project — and it is a project that recurs every reporting cycle.
The firms that will handle the 2027 transition cleanly are the ones whose platform can already answer three questions in real time: "which of my entities have crypto exposure?", "what is the complete beneficial-ownership chain for each entity?", and "what is the documented rationale for this entity's CRS classification?". If your current tooling cannot answer all three without a manual reconciliation, that is the gap to close before 2027.
Where to go for more
- The OECD's CRS v3.0 publication and the Crypto-Asset Reporting Framework commentary are the primary sources.
- Your local tax authority will publish jurisdiction-specific guidance; for Mauritius-administered structures, the Mauritius Revenue Authority (MRA) is the competent authority.
- For entity-specific interpretation, consult your regulatory counsel — this article is a practical summary, not advice.
Keep reading
What privacy-first AI actually means for a TCSP
The EU AI Act is now live. Here is how a trust company should evaluate AI tooling against the fiduciary standard — and why most generic copilots fall short.
Read articlePlatformOne golden record: ending the reconciliation tax
Why the “one relationship, one record” model collapses months of reporting work into days — and the data architecture that makes it possible.
Read articleGet the briefing
Quarterly analysis on fiduciary technology, regulation and the Foundation One roadmap. No spam — unsubscribe anytime.