What is a Crypto-Asset Service Provider, and how does it differ from the common assumption that "it's just another word for exchange"?
Most people hearing the term CASP (Crypto-Asset Service Provider) intuitively understand it as "just another way of saying exchange" — this understanding isn't entirely wrong, but it's too narrow. Regulatory frameworks like CARF and DAC8 define CASP with a scope broader than the common understanding of "exchange" — beyond centralized exchanges, it also includes crypto-asset custody service providers, some wallet providers offering exchange services, and even certain intermediaries providing crypto-asset transfer services may fall within the CASP definition.
This breadth of definition matters because it determines the boundary of the reporting obligation — if a service is determined to be a CASP, it needs to fulfill due diligence and data reporting obligations; if it isn't determined to be a CASP (such as a purely decentralized protocol or a smart contract with no centralized operating party), it doesn't fall within this reporting mechanism's direct scope. This means "I don't use an exchange, I use a different kind of service" doesn't automatically mean you're unaffected by the regulatory framework — what matters is whether that service's actual operating pattern meets the CASP definition.
Why do regulatory frameworks need to clearly define who counts as a CASP, and where does this determination logic come from?
The core operating logic of a cross-border tax information reporting mechanism (like CARF) is finding an intermediary role "capable of collecting user data and executing reporting," rather than directly requiring every investor to report to every relevant country's tax authority themselves (which is practically infeasible). The CASP definition is essentially answering the question of "which entities have both the capability and the responsibility to play this intermediary role" — entities like centralized exchanges and custodians are naturally suited to being assigned this intermediary responsibility, since they already hold user identity information and transaction records.
This also explains why decentralized protocols typically aren't included in the CASP definition — a protocol with no centralized operating party, purely executed automatically by smart contracts, has no clear "entity" in practice that can bear the due diligence and reporting obligation, even if that protocol itself facilitates a large volume of transactions. This gap in the definition remains a challenge regulatory frameworks haven't fully resolved yet, and it's also why cross-border reporting mechanisms' coverage is currently still concentrated on centralized or semi-centralized service providers, rather than the entire crypto ecosystem.
How does the CASP definition actually work, and how do different types of services differ?
There are three common scenarios:
The most common source of confusion in practice is that "non-custodial" and "not a CASP" aren't the same thing — a service can market itself as non-custodial (the user holds their own private key) and still be determined a CASP, required to fulfill corresponding obligations, as long as it provides a core service function like exchange or trade matching.
What does the CASP definition actually mean for me, and what risks should I watch for?
The most direct impact is that you can't simply assume you're completely unaffected by cross-border reporting mechanisms based on labels like "I use a non-custodial wallet" or "I use a decentralized protocol" — you need to specifically confirm whether the service you actually use falls within the CASP definition based on its real functionality. Many wallet products offer both storage and exchange functionality simultaneously, and the classification determination for this kind of hybrid service can be less intuitive than for a purely centralized exchange, making it easy for users to misjudge whether the service they use is covered by the regulatory framework.
Another easily overlooked risk is that the CASP definition itself may be adjusted as regulatory frameworks evolve, especially the determination standard for hybrid services (with some decentralized and some centralized functionality coexisting), which remains under continuous development — a service previously determined not to be a CASP may be brought into scope in the future due to a definition adjustment. In practice, it's advisable to periodically monitor whether the service provider you use has published updates regarding its regulatory classification, rather than assuming a service that isn't regulated today will never be regulated in the future.
A user long used a crypto wallet app marketed as "non-custodial." Beyond storage, this app also had a built-in token exchange service, letting users complete swaps between different tokens directly within the app. Because of this exchange feature, the company operating this app might be classified as a CASP under some regulatory frameworks, required to fulfill due diligence and data reporting obligations, even though the user always held their own private key — a typical example of "non-custodial" and "not covered by the regulatory framework" not being the same thing.
The advantage of defining CASP by function rather than by name is avoiding service providers evading regulation through renaming or marketing repackaging, keeping the determination standard closer to substantive economic function; the drawback is that hybrid services require case-by-case classification assessment, less immediately obvious than a purely centralized exchange, making it easy for users to misjudge whether the service they use is covered — and purely decentralized protocols currently remain outside the definition's scope, forming a gap the regulatory framework hasn't yet fully reached.