AEOI Reporting
CARF / DAC8 · first reporting period is calendar 2026

AEOI reporting for organisations that aren't banks.

Collect self-certifications, validate your data and generate OECD-schema XML — CARF/DAC8, DAC7, CESOP, CRS and FATCA on a single engine. Free validators, no sign-up. Paid plans start at EUR 59 a month, and the price is on this page.

  • Hosted in the EU
  • GDPR processor, DPA on request
  • Validators run entirely in your browser

CARF XML validator

carf-report-2026.xml · 3.2 MB · never leaves your browser

local
  • Schema structure (CARF v1.5)valid
  • DocRefID uniqueness1 842 records
  • TIN format by jurisdiction6 to review
  • Controlling persons — role codesvalid
  • Transaction containers (8 categories)2 errors

Report generated locally · no file upload · no account

2026
First reporting period
Calendar year, data collected now
31 Jan 2027
UK registration deadline
Reporting crypto-asset service providers
31 May 2027
First UK submission
Full 2026 dataset in OECD XML
67+
Committed jurisdictions
CARF rollout through 2027–2028

Why we exist

Every vendor in this market hides behind “contact sales”.

Taxbit, Ledgible, Sovos, Regnology and the rest are built for banks, funds and fund administrators. None of them publishes a price. A ten-person crypto-asset service provider is not economically interesting to them — the sales cycle costs more than the deal. So tens of thousands of small reporting entities are served by nobody.

Six-figure contracts, six-month rollouts

Enterprise AEOI platforms are sold as implementation projects with consultants attached. You need a file that validates, not a programme of work.

Spreadsheets and a nervous accountant

The realistic alternative today is manual collection in a spreadsheet and hand-built XML. It works right up to the moment a submission is rejected.

Nobody publishes a number

You cannot budget for what you cannot price. We publish every tier, every limit and every add-on — before you talk to anyone.

One engine, five regimes

The same core, a module per regime.

Identity capture, escalation, audit log, validation, XML generation and corrections are shared. A regime module is a field set, its code lists, its schema and the filing rules of the jurisdiction.

CARF / DAC8

Files end to end

Crypto-asset service providers, OTC desks, ATM operators, brokers

  • Code lists CARF401–404, CARF501–509, CARF601–606
  • Eight transaction containers, controlling persons CARF801–813
  • EU DAC8 and UK filing rules

DAC7

Files end to end

Marketplaces, rentals, transport, personal services, goods

  • DPI schema v1.0, whole-unit consideration
  • Quarterly Cons/Numb/Fees/Tax cross-checks
  • Assumed reporting, EU nexus RPONEX1–5

CESOP

Files end to end

EU payment service providers

  • Quarterly submission, UUID v4 references
  • IBAN mod-97, BIC and refund-sign checks
  • Findings name the CESOP error code

CRS

Files end to end

Banks, funds, trusts, insurers, asset managers

  • Amended schema v3.0, self-certification codes
  • Passive-NFE controlling person handshake
  • Transitional “not reported” codes flagged

FATCA

Files end to end

Foreign financial institutions reporting to the IRS

  • Schema v2.0, GIIN format and routing
  • Void, correct and amend as distinct intents
  • Substantial owners, pool and nil reports

Add a regime, not a project.

Identity capture, escalation, the audit log, validation, XML generation and corrections are shared across every regime. A second regime on an active subscription is EUR 49 a month.

See pricing

How it works

Four steps, no implementation project.

  1. 01

    Collect

    Hosted self-certification forms under your own brand. Tax residence, TIN with per-country format validation, date and place of birth, controlling persons with control-type coding.

  2. 02

    Chase

    The escalation engine sends two reminders over 60 days and raises an account-restriction flag. Every step is timestamped in an immutable audit log.

  3. 03

    Validate

    Structural and business rules from the OECD schemas run against your dataset before you file — the same engine that powers the free validators.

  4. 04

    File and correct

    Generate the submission XML with stable DocRefIDs, then handle corrections and deletions bound to the original reference when something changes.

Pricing

The number is on the page.

Per organisation, per regime. Every plan below collects, validates, generates the submission XML and handles corrections — the difference is volume. Annual billing takes 20% off, and a second regime on an active subscription is EUR 49 a month.

Free during early access

Billing is not connected yet, so there is nothing to pay and no card to enter. Every account created now gets the Standard feature set — corrections, multiple jurisdictions, CSV import, webhooks, branding and export — across all five regimes. The prices below are what they will be; we will give notice before any of them starts applying to you.

The validators and the readiness checks stay free forever, with no account. The plans below are for collecting, filing and correcting.

Essential

EUR 59per month

Up to 500 reportable persons, one jurisdiction.

  • Hosted self-certification forms
  • TIN validation by jurisdiction
  • Controlling persons (UBO)
  • Reminders and escalation
  • Submission XML generation
  • Immutable audit log
Create an account

Standard

Best fit

EUR 149per month

Up to 5 000 reportable persons.

  • Everything in Essential
  • Corrections and deletions
  • Multiple jurisdictions
  • CSV import and webhooks
  • Your branding on the forms
  • Data export on demand
Create an account

Pro

EUR 399per month

Up to 50 000 reportable persons.

  • Everything in Standard
  • Full REST API
  • White-label on your domain
  • Multi-entity structures
  • Priority support
  • Beyond 50 000: EUR 99 per further 25 000
Talk to us

What we are not.

We are a tool, not an advisor. Being explicit about the line is part of the product.

  • We do not give tax advice.
  • We do not determine your nexus or classify your entities for you.
  • We do not calculate your tax.
  • We do not keep data we do not need to file — retention is policy-driven with automatic deletion.

FAQ

The questions compliance officers ask first.

Does my file get uploaded when I use a validator?

No. The parser, the schema descriptions and every business rule are plain JavaScript that runs in your tab — the same code the server runs before a filing, with no network call in between. Nothing is transmitted, nothing is stored, and you do not need an account. This is an architectural decision rather than an optimisation: it removes the security question from the first interaction.

Do I need an account to use a validator?

No, and that is deliberate. Asking a regulated firm to register with an unknown vendor before it can check a file turns a two-minute task into an internal approval. The validators stay open: no account, no email wall, the full report on screen. We only ask for an address if you want the report emailed to you as a file you can forward.

Where is the data hosted?

In the EU. We process personal data belonging to your customers, so the database stays in the European Union and we act as a processor under the GDPR. A DPA template and a subprocessor list are available before you sign anything.

Who is behind this?

DTech SIA, a Latvian company. The product is built and run by a small team rather than a sales organisation — which is why the price is published and there is no demo to book.

Are you a substitute for my tax adviser?

No. We generate a technically valid submission from the data you provide and flag what looks wrong. Scope determination, entity classification and the tax positions themselves stay with you and your adviser.

What happens if a submission is rejected?

The corrections workflow binds each amendment or deletion to the original DocRefID, so a resubmission is a normal operation rather than a rebuild. On paid plans we work through the first rejection with you.

What does it cost right now?

Nothing. Billing is not connected, so there is no card to enter and no trial to expire. An account created today gets the Standard feature set across all five regimes — corrections, multiple jurisdictions, CSV import, webhooks, branding and export. The published prices are what they will be, and we will give notice before any of them starts applying to you.

What if I only need one regime, once a year?

That is the common case, and the monthly price is deliberately low enough that it is not worth arguing about. Annual billing takes another 20% off, and you can add a second regime later for EUR 49 a month.

Contact

Write to the people who built it.

There is no sales team, no qualification call and no demo to book — the price is on the page and the account is self-serve. This form reaches the people who wrote the code. If what you need is the API, your own domain, or multiple entities, say so: those are the Pro features, they are not built yet, and what people ask for here is what decides the order they arrive in.

Or write directly to info@aeoireporting.com.

We use this to answer you. It is not added to a mailing list and there is nothing to unsubscribe from.