The Inland Revenue Authority of Singapore (IRAS) has issued an e-Tax Guide setting out the implementation requirements for Singapore’s Crypto-Asset Reporting Framework (CARF), following the introduction of the Income Tax (International Tax Compliance Agreements) (Crypto-Asset Reporting Framework) Regulations 2026.

The CARF requirements will apply from 1 January 2027. Information relating to the 2027 calendar year is expected to be included in Singapore’s first international exchange of CARF information in September 2028.

Who may be affected

The framework applies to Reporting Singaporean Crypto-Asset Service Providers (Reporting SGCASPs).

Broadly, a business may fall within this category where it facilitates crypto-asset exchange transactions for, or on behalf of, customers and has a sufficient connection with Singapore.  Relevant connections may include:

  • being tax resident in Singapore;
  • being incorporated or registered under Singapore law;
  • being managed from Singapore;
  • maintaining a regular place of business in Singapore; or
  • operating through a Singapore branch that carries out relevant crypto-asset transactions.

Businesses operating digital-asset platforms, exchanges, brokers or other arrangements that facilitate crypto-asset transactions should therefore assess carefully whether their activities bring them within the reporting regime.

Scope of crypto-assets covered

CARF applies to Relevant Crypto-Assets, subject to specified exclusions.  Assets generally outside the framework include:

  • central bank digital currencies;
  • qualifying specified electronic money products; and
  • crypto-assets that the service provider has adequately established cannot be used for payment or investment purposes.

The classification of an asset will depend on its actual characteristics and use, rather than merely its name or how it is marketed.

This is particularly relevant for non-fungible tokens (NFTs). An NFT is not automatically excluded from CARF. Its treatment will depend on factors such as its economic function, transferability and whether it is capable of being used for investment or payment-related purposes.

Impact on compliance and reporting

Customer tax-residency due diligence

Reporting SGCASPs will be required to establish the tax residence of their crypto-asset users.  For entity users, additional work may be required to identify and determine the tax residence of their controlling persons, unless the entity falls within an applicable exclusion or qualifies as an Active Entity.

This represents a significant extension of customer information requirements for crypto businesses that may previously have focused mainly on anti-money laundering, sanctions and know-your-customer procedures.

Self-certification requirements

A valid tax-residency self-certification should generally be obtained when a new customer relationship is established.

For existing customers, Reporting SGCASPs will need to obtain appropriate self-certifications and complete the required reasonableness checks by 31 December 2027.  Businesses with large existing customer bases may therefore face a substantial remediation exercise during the first year of implementation.

Annual registration and reporting obligations

A person that becomes a Reporting SGCASP must generally register with IRAS by 31 March of the year following the year in which it first becomes reportable.

CARF information returns will then be due annually by 31 May following the relevant calendar year.  Businesses should also note that a filing obligation may continue to apply even where there are no reportable transactions for the period, including through the submission of a nil return where required.

More detailed transaction-data requirements

CARF reporting extends beyond customer identification information.  Reportable data may include:

  • customer identification particulars;
  • jurisdiction or jurisdictions of tax residence;
  • applicable tax identification numbers;
  • crypto-to-fiat transactions;
  • crypto-to-crypto exchanges;
  • transfers of crypto-assets; and
  • qualifying retail payment transactions.

For many service providers, this will require information to be drawn from customer onboarding systems, transaction engines, wallets, accounting records and compliance databases.

Practical issues

Determining whether the business is in scope

The first challenge will often be establishing whether an entity is in fact a Reporting SGCASP.  Businesses operating across several jurisdictions may need to assess:

  • where relevant activities are conducted;
  • where management and key decision-making take place;
  • whether Singapore branches or offices participate in transaction execution; and
  • whether overlapping reporting obligations arise in more than one jurisdiction.

A documented scoping analysis will be important, particularly for international groups.

Mapping crypto-assets to the CARF definitions

Businesses will need a defensible methodology for determining which digital assets constitute Relevant Crypto-Assets.  Particular care may be required for:

  • NFTs;
  • tokenised securities;
  • utility tokens;
  • payment tokens;
  • stablecoins; and
  • emerging digital products with mixed functions.

The analysis should focus on substance and functionality rather than product labels.

Remediation of existing customer records

Legacy customer files may not contain all the information required for CARF reporting.  Potential gaps may include:

  • incomplete tax-residency information;
  • missing tax identification numbers;
  • inadequate entity classification;
  • incomplete controlling-person information; or
  • self-certifications that no longer reflect current circumstances.

Reporting SGCASPs should consider starting the remediation process well before the 31 December 2027 deadline.

System and data changes

CARF is likely to require substantial data integration.  Businesses may need to modify systems so that they can:

  • capture the required customer data at onboarding;
  • monitor changes in customer circumstances;
  • identify reportable transactions;
  • aggregate transactions by customer and asset type;
  • preserve supporting documentation;
  • perform data-quality checks; and
  • generate information in the format required for filing.

Where several platforms or service providers are involved, reconciling information between operational systems and regulatory reporting records may be particularly challenging.

Governance and control

CARF compliance should not be treated solely as an IT or tax-reporting exercise.  Management should establish clear responsibility for:

  • determining reporting scope;
  • approving asset classifications;
  • validating customer classifications;
  • reviewing exceptions;
  • overseeing data quality; and
  • approving the annual CARF submission.

A documented control framework will also assist businesses in demonstrating how reporting conclusions were reached.

Accounting and audit considerations

Although CARF is fundamentally an international tax-transparency regime, its implementation may have wider implications for finance and assurance functions.  Finance teams may need to reconcile reported transaction information against:

  • accounting ledgers;
  • customer balances;
  • transaction-fee income;
  • digital-asset holdings; and
  • settlement records.

Auditors may also need to understand management’s CARF processes where deficiencies could indicate broader weaknesses in customer data, transaction completeness, regulatory compliance or information-system controls.

Businesses should therefore consider aligning CARF implementation with existing tax governance, AML/KYC, financial reporting and internal-control frameworks rather than building a standalone reporting process.

Action points

Crypto-asset businesses with a Singapore connection should begin preparing before the regime takes effect on 1 January 2027.  Priority actions include:

  • assessing whether the business falls within the definition of a Reporting SGCASP;
  • identifying which products and assets are within CARF;
  • reviewing existing customer due-diligence information;
  • identifying gaps in tax-residency and controlling-person data;
  • updating onboarding and self-certification procedures;
  • mapping reportable transaction data across operational systems;
  • establishing internal ownership and review controls; and
  • planning for the first registration and annual reporting deadlines.

Early implementation will be particularly important for businesses with large customer populations or complex crypto-asset transaction flows, as the quality of information collected during 2027 will directly affect the first reporting cycle and the subsequent international exchange of information.

Source: IRAS, 11 August 2026.