Summary
The control failure was a mismatch between a refund decision and the evidence available at that decision. A withholding-tax refund is legitimate only when the claimant satisfies the governing legal requirements. In the Cum-Ex cases addressed by German criminal courts, claims were made for tax that had not in fact been withheld. A certificate, settlement entry or custody statement could not safely be treated as proof of a unique tax payment without reconciliation to the revenue authority's collection record.
Trading around a dividend date is not one undifferentiated offence. Dividend arbitrage, securities lending, short selling and cross-border investment can have lawful forms. Actor-specific criminal liability depends on the governing law, the transaction, knowledge, intent and forum. Cum-Ex findings about false refund claims must not be casually extended to every Cum-Cum arrangement, every dividend trade, every intermediary or every jurisdiction.
Fragmentation created the operating opportunity. The seller, buyer, short seller, borrower, fund, custodian, sub-custodian, settlement system, certificate issuer, adviser, lender and tax office could each possess a valid-looking fragment. Accountability failed when no control joined beneficial ownership, dividend entitlement, tax collection, settlement timing and prior claims into one decision record.
Professional gatekeepers were not interchangeable. Banks could finance, trade, settle, custody, certify or submit claims; lawyers and tax advisers could design, opine or document; fund managers could approve or market; public officials could process or investigate. Responsibility must follow the act and evidence, not the job title or institutional category alone.
Court decisions converted a disputed narrative into actor- and transaction-specific law. Germany's Federal Court of Justice confirmed that claiming credit or reimbursement for capital-yield tax not actually withheld through the Cum-Ex short-sale transactions before it amounted to false tax-relevant information and an unjustified tax advantage. Later judgments addressed other defendants and confiscation questions. Each ruling remains limited to its record.
Recovery is not the same as prevention. Confiscation, reassessment and civil recovery can return value, but they arrive after public money, investigative capacity and trust have been consumed. Prevention requires a unique payment-to-relief identifier, custody-chain reporting, beneficial-owner evidence, transaction-risk flags, protected cross-border exchange and a documented human decision for exceptions.
Reform must protect legitimate investors as well as revenue. Slow, inconsistent refund systems impose real costs and can discourage cross-border investment. The EU's FASTER framework attempts to join speed with traceability through digital residence evidence, certified intermediaries, reporting and risk-based exclusions. Its accountability test will be whether data are complete and usable before relief, not merely collected after payment.
The event boundary: one tax payment cannot support multiple relief decisions
Dividend withholding systems solve a genuine administrative problem. A company paying a dividend may withhold tax at source, while a non-resident investor may qualify under domestic law or a treaty for a lower rate. The investor then needs relief at source or a refund of excess withholding. A legitimate system must prevent double taxation without turning documentary fragmentation into duplicate public payment.
The OECD's Dividend Tax Fraud report explains the basic Cum-Ex risk in operational terms. Rapid transactions around the ex-dividend and record dates could create an appearance that several parties were entitled to reimbursement even though the underlying withholding occurred once. That description is a model, not proof about every real transaction. It identifies the evidence problem that authorities must resolve: who owned or was entitled to the dividend under applicable rules, what tax was withheld, which institution issued which record, and whether another claim used the same payment.
It is important to separate the family of practices. “Dividend stripping” can describe multiple strategies with different legal consequences. Cum-Ex, as adjudicated in German cases involving refunds of tax not withheld, is not a synonym for every transaction labelled Cum-Cum. The OECD's professional-enablers report discusses how advisers and intermediaries can enable tax and white-collar crime, but its general policy analysis cannot establish the guilt of a particular professional. A governance system therefore needs typologies for detection and exact evidence for attribution.
The public-law objective can be stated as an invariant: every granted credit or refund must map to a valid entitlement and an identifiable amount of tax collected, and that collected amount must not be relieved more than the law permits. The invariant sounds simple. The operating environment is not. Securities may trade on-market or over the counter, settle after the trade date, be borrowed and returned, sit through chains of nominees, and generate manufactured payments that resemble the economic amount of a dividend without being the dividend itself. Different institutions may record the same event under different identifiers and timestamps.
A certificate is consequently an assertion that requires provenance. The authority should know who issued it, under what legal capacity, from which upstream record, with which transaction and tax-payment identifiers, and whether it was amended or cancelled. The claimant should supply the beneficial-ownership and holding evidence required by the relevant law. The custodian should not certify what it cannot observe. An adviser should not convert assumptions about settlement or tax collection into an unqualified conclusion. The tax office should not treat formal completeness as substantive proof when risk indicators show possible duplication.
This framing avoids two errors. The first is to describe the case as a purely technical loophole that absolves human decision-makers. Complex systems still have owners, approval points and choices about uncertainty. The second is to imply that all entities in a market chain shared the same knowledge or intent. Evidence may show deliberate coordination in one case, inadequate controls in another and no wrongdoing in a third. Accountability requires both system analysis and actor specificity.
How fragmentation became a control weakness
The German Bundestag's resolution establishing its Cum-Ex inquiry set out the central public question: how practices involving short sales and multiple tax certificates developed, why they were not stopped earlier, what damage occurred, what public bodies knew, and whether countermeasures were timely and sufficient. An inquiry mandate identifies questions; it does not itself answer them or adjudicate criminal liability. Its value is to show that the event implicated legislation, tax administration, public banks and supervisory governance rather than one refund form.
At trade execution, controls should link the order, economic purpose, counterparty, position, financing and intended tax treatment. A high volume of tightly timed, circular or economically offsetting trades around dividend dates may be legitimate market activity, but it deserves an explanation proportionate to the public-money exposure. Surveillance should look beyond price abuse. It should also identify patterns in which expected profit depends materially on more tax relief being obtained than tax economically borne.
At settlement, the system needs a consistent account of which securities and cash moved, when, and between which accounts. Trade date, contractual settlement date and actual settlement date are different facts. A failed or delayed delivery can change which party's books show a dividend, a compensation payment or a receivable. If tax evidence is created from one party's record without reconciling the complete settlement chain, two internally coherent accounts can support incompatible external claims.
At custody, each intermediary should preserve upstream and downstream identifiers rather than substituting its own reference with no durable link. Omnibus accounts create efficiency but can obscure the beneficial-owner allocation unless sub-ledgers are controlled and auditable. A downstream custodian must know whether an upstream payment was a dividend net of withholding, a manufactured dividend, a contractual adjustment or another cash flow. Labels should follow legal and economic substance and should not be inferred merely from equal amounts.
At certification, maker-checker controls are not enough if both people rely on the same incomplete data. The certifier needs positive evidence of tax collection or a trusted link to a party that has it. The certificate should state its scope and should be electronically unique. Cancellation and correction must propagate through the chain. If a certificate supports a refund application, the tax authority should be able to lock the associated tax-payment capacity so a later claim triggers a duplicate alert.
At the fund or investor, governance should test the strategy's source of return. A return that appears independent of market direction may still depend on tax assumptions, counterparty performance, settlement timing and authority acceptance. Investment committees should see scenario analysis: what happens if claims are rejected, payments reclaimed, advisers' opinions challenged, counterparties fail or proceedings begin? Financing arrangements and fee waterfalls may reveal whether promoters, managers and intermediaries are paid before legal uncertainty is resolved.
At the adviser, the question is not whether an opinion exists but what it proves. An opinion may be limited to facts supplied by the client, a defined jurisdiction and a legal question. It may contain assumptions about beneficial ownership, tax withholding or transaction purpose that the adviser did not independently verify. Governance must surface those assumptions to the decision-maker. A legal conclusion cannot repair false facts, and a divided opinion should not be presented as institutional approval.
At the tax authority, workflow design matters. A refund team may be rewarded for speed and backlog reduction while fraud investigators see cross-claim patterns later. Regional offices may apply different checks or lack access to national data. Tax secrecy rules protect legitimate confidentiality, but system designers must create lawful ways to match collection and relief records. A case-management system that stores documents without linking their underlying economic events is an archive, not a control.
The Bundestag's final-report handover record documents an extensive inquiry and also records disagreement among parliamentary groups about causes, response and estimated damage. Those disagreements should remain visible. Parliamentary reports can establish institutional scrutiny, testimony and political conclusions. They do not replace final court findings, and an estimate discussed in one period should not be combined with later cross-European figures as if both measured the same trades, years and jurisdictions.
What the courts established—and what they did not
The clearest German criminal-law anchor is the Federal Court of Justice's 28 July 2021 judgment. Its headnotes state that claiming tax credit or reimbursement for capital-yield tax not actually withheld, on the basis of the Cum-Ex short-sale transactions before the court, constituted false information about tax-relevant facts and produced unjustified tax advantages when approved. The ruling also addressed confiscation. This was a final judicial statement about specified conduct and defendants; it is not a declaration that any trade with a similar nickname automatically satisfies every element of German tax evasion.
That boundary has practical consequences for writing and controls. A firm should not wait for certainty that a transaction exactly matches a decided criminal case before escalating it. Risk controls may be deliberately broader than the criminal law. But investigators, boards and journalists must distinguish a control alert from a legal finding. “Potential duplicate-refund pattern” is an appropriate risk description. “Tax evasion” should be tied to an admission, final judgment or careful statement of an authority's allegation and procedural status.
Later cases show why the record must remain actor-specific. The Federal Court's 18 September 2024 judgment concerned a defendant convicted of two tax-evasion counts and a prosecution appeal concerning confiscation of more than six million euros. The court remitted the confiscation issue. That procedural outcome should not be rewritten as a new conviction on matters not before the appellate court, nor should the amount sought be described as recovered cash.
The Federal Court's 2025 press release on two London fund managers reports that their appeals were rejected, making the Bonn Regional Court judgment final. The release describes the roles found, the approximately EUR92 million tax damage in that case, sentences and confiscated remuneration. Those measures belong to that case. They should not be used as a denominator for total European loss or proof about uncharged investors, service providers or other funds.
Confiscation deserves its own measurement dictionary. A court may confiscate the proceeds of an offence, the value of proceeds, a entity's remuneration or an asset subject to another statutory rule. A tax authority may separately reassess or secure funds. “Damage,” “benefit,” “refund,” “profit,” “fee,” “asset frozen,” “amount ordered” and “cash recovered” are not synonyms. A recovery dashboard must record the legal basis, obligor, beneficiary, date, gross order, offsets, appeals and cash collected.
The same discipline applies to investigations and charges. A search, interview, indictment or trial is not a conviction. An acquittal of a person does not prove that the underlying control environment was sound. A guilty plea by one actor does not establish another actor's state of mind. Cross-border cases may allocate prosecution based on evidence, jurisdiction, limitation periods and cooperation; the absence of proceedings in a country cannot safely be treated as a merits ruling.
Gatekeeper accountability follows the function performed
The Bundestag recorded expert evidence about the role of coordination in a 2016 public hearing. The institutional lesson is not that every professional in the chain was an enabler. It is that a complex transaction can depend on coordinated performance of individually ordinary functions. Control ownership must follow the particular function.
A trading desk owns order rationale, position limits, trader communications and the accuracy of data sent to operations. A desk head should be able to explain why the strategy earns money after financing, hedging, fees and plausible tax outcomes. If the economics require several parties to obtain relief from one withholding event, the strategy should fail approval regardless of how polished its legal presentation appears.
Operations owns trade confirmation, settlement status and exception resolution. It should not convert a contractual expectation into a statement that securities or cash actually moved. Persistent fails near dividend dates deserve a specialised review. Manual adjustments must retain the original entry, reason, approver and supporting evidence. Reconciliations should occur across legal entities and not stop at the boundary of the desk that benefits.
Custodians own the integrity of asset and cash records within their role. They need controlled classifications for dividends and manufactured payments, evidence of upstream withholding, and a rule against issuing duplicate or unsupported certificates. Where a custodian lacks upstream evidence, the correct output is a qualified status or refusal, not an assumption designed to keep processing fast.
Fund directors and managers own strategy approval, delegation and investor disclosure. They should understand dependencies on counterparties, tax rulings, opinions, leverage and liquidity. Independent directors need access to references and specialist advice independent of the promoter. Valuation and net-asset-value processes should reserve disputed tax receivables rather than recognise them as certain simply because an application was filed.
Banks may occupy several roles at once: lender, counterparty, custodian, certificate issuer and claim agent. Governance must identify those conflicts. Revenue earned by one unit should not suppress concerns held by tax, compliance, operations or legal staff elsewhere. Group-level committees require a consolidated view of exposure, not separate presentations in which each unit appears small.
Lawyers, accountants and tax advisers own the accuracy of their work within the agreed scope and professional rules. Engagement letters and opinions should identify the facts supplied, facts tested, legal uncertainty, contrary authority and permissible reliance. Transaction promoters should not selectively circulate a favourable paragraph while withholding assumptions and reservations. Firms need acceptance controls for strategies whose commercial purpose depends on public refunds and for clients unwilling to disclose the complete chain.
Tax administrations own the decision to release public money. They also depend on legislatures for powers, funding and information access. A reviewer should see a machine-generated reconciliation of the claim to tax collected, related claims, custody chain, residence certificate and risk flags, followed by a human reason for approval where exceptions exist. Supervisors should sample both approvals and rejections, because a team can produce low measured fraud by deterring legitimate claimants or high measured speed by missing duplication.
Legislatures and finance ministries own the design of the legal and data environment. They must respond when market infrastructure changes make existing certificate rules unreliable. Consultation with industry is necessary because rules must work operationally, but comments and draft language should be transparent enough to expose conflicts. A claim that a change would impair market liquidity should be tested against data and alternative control designs, not accepted as a reason to leave the payment invariant unenforced.
Cross-border evidence and the danger of aggregate claims
The European Parliament's 2018 Cum-Ex resolution called for investigation, information exchange, recovery and stronger coordination. The resolution cited publicly reported aggregate loss estimates and acknowledged difficulty calculating maximum harm. That qualification is essential. Different public figures may combine Cum-Ex and Cum-Cum, different years, tax systems, discovered transactions, extrapolations and opportunity-cost assumptions. A large number can communicate scale while remaining unsuitable for accounting or case attribution.
An evidence ledger should therefore store a measure definition alongside every amount. For a refund case, the basic fields include amount requested, amount approved, amount paid, tax actually collected, tax legally due, amount reassessed, amount secured, judgment amount, confiscation order, settlement amount and cash recovered. Each needs currency, valuation date and source. Cross-country aggregation should occur only after definitions are aligned and duplicates removed.
Jurisdiction also determines legal meaning. Beneficial ownership, dividend entitlement, certificate rules, limitation periods, professional duties and criminal elements differ. A transaction found unlawful under one country's record cannot be mechanically transferred to another. At the same time, different legal rules do not prevent risk-based cooperation. Authorities can share transaction identifiers, parties, dates and typologies subject to law, then make their own decisions.
The OECD's Germany 2023 survey connected Cum-Ex and Cum-Cum losses with weaknesses including decentralised administration, information infrastructure and separate payment and refund procedures. An economic survey synthesises policy evidence; it is not a criminal case record. Its accountability value is architectural: fragmentation inside government can mirror fragmentation in the custody chain.
Cross-border coordination needs a case identity that survives translation between systems. Names and account numbers alone are unreliable. Authorities should use legal-entity identifiers where available, security identifiers, trade and settlement references, payment dates, certificate identifiers and refund-claim identifiers. Matching rules should accommodate corrections without erasing history. Access must be role-based, logged and limited to a lawful purpose because tax and financial data are highly sensitive.
Data localisation and sovereignty constraints are design requirements, not excuses for blindness. A federated query can return a risk match without copying a complete taxpayer file. A member state might answer whether a certificate or transaction identifier has appeared in another claim, while retaining the detailed record until a lawful request follows. Governance must define which authority can initiate a query, the threshold, response time, retention and challenge rights.
Professional secrecy and legal privilege also require precision. They protect important interests but do not make every transactional record unavailable. Systems should classify documents, separate legal advice from underlying facts and transaction data, and use established judicial or statutory mechanisms where access is contested. Overbroad collection can undermine legitimacy; underbroad collection can make public-money controls performative. The correct balance must be documented and reviewable.
From detection after payment to prevention before relief
The European Parliament's 2018 information paper distinguished dividend arbitrage concepts and summarised the cross-border concern at that time. An information paper is contextual, not adjudicative. It nevertheless points to the need for a control model that can operate across securities and tax terminology.
The first preventive control is relief at source where feasible. Applying the correct treaty rate at payment reduces the amount that must later be refunded. It does not eliminate fraud risk: residence, beneficial ownership and arrangement evidence still need verification. But it moves the decision closer to the payment event, when the chain is easier to observe.
The second is a unique withholding event. The issuer or paying agent should create a controlled identifier for the dividend and tax withheld. Allocations through custodians must conserve quantity and tax: downstream entitlements cannot exceed the upstream event. Each relief or refund consumes an authorised portion, and corrections restore or reallocate it through logged transactions.
The third is certified-intermediary accountability. Certification should depend on governance, technical ability, record retention and supervision. An intermediary that submits or supports claims should report the chain and accept consequences for reckless or false data within its responsibility. Certification must not become a safe-harbour badge that shifts all risk to the authority.
The fourth is transaction-level risk analysis. Indicators may include acquisition close to the record date, securities lending, unsettled trades, manufactured payments, multiple custodians, rapid disposal, derivatives that transfer economic exposure, refund value disproportionate to investment return, repeated counterparties and prior corrections. No single indicator proves abuse. Their combination should determine whether fast processing is appropriate.
The fifth is negative confirmation and duplicate prevention. Before payment, the authority should determine whether the tax collection exists and whether another relief has consumed it. If the chain cannot provide that proof, the claim can enter a standard examination route rather than being automatically denied. That preserves legitimate rights while refusing to convert uncertainty into immediate public payment.
The sixth is retrospective sampling. Fraud controls degrade as market entities adapt. Authorities should select paid claims using network analysis and compare certificates, counterparties, advisers and settlement patterns. Findings should feed rule design and intermediary supervision. Sampling results need careful interpretation: discovery rates depend on selection and are not population estimates without a valid method.
The seventh is protected escalation. Operations staff, custody specialists, tax reviewers and advisers may notice inconsistencies before leadership. Reporting channels must reach an independent function, preserve records and protect good-faith reporters. Incentives should not reward only completed trades, issued certificates or refund throughput. Compensation and promotion decisions should incorporate control behaviour.
The OECD's tax-and-crime policy page places tax crime within a wider financial-crime and public-trust context. The operational implication is coordination among tax, criminal, financial-supervisory and anti-money-laundering authorities without collapsing their mandates. A suspicious-transaction report is not a tax assessment; a tax adjustment is not a criminal conviction. The records can inform one another while retaining separate legal tests.
FASTER: making speed conditional on traceability
The European Commission's FASTER initiative page explains the policy response: a common digital tax-residence certificate, certified financial intermediaries, standardised reporting, relief-at-source or quick-refund procedures, and safeguards intended to combat abuse. The framework responds to a real dual failure. Legitimate investors can face costly, slow and inconsistent refund procedures, while weakly connected systems can pay unsupported claims.
The Commission's impact assessment is evidence of the problem definition, options and expected effects. It is not proof that the chosen design will achieve those effects. Impact assessments depend on data, assumptions and implementation. Post-implementation evaluation must test actual processing times, false positives, prevented duplicates, intermediary compliance, data quality and taxpayer challenges.
The Parliament's report on the proposal considered reporting and anti-abuse measures, including information about holding periods and linked financial arrangements. Parliamentary amendments show the policy debate; the final legal obligations must be read from the adopted directive and national transposition. This distinction prevents a proposed safeguard from being described as already operative.
The Council's May 2024 agreed text documented the political agreement stage. That record is useful for tracing design choices, including reporting through the securities payment chain and circumstances for additional checks. It should not be confused with implementation, which depends on later adoption, transposition, technical rules and operating systems.
The Council's December 2024 adoption announcement states that member states must transpose the directive by the end of 2028 and apply national rules from 1 January 2030. Those dates make present-tense claims especially important. Adoption is a legal milestone, not evidence that every national refund system already has a digital certificate or complete chain reporting.
The final Council Directive (EU) 2025/50 is the controlling EU legal text. It establishes the framework, including national registers of certified financial intermediaries, reporting and fast-track procedures. National law, administrative practice and technical formats will determine much of the operating reality. A compliance programme should map each obligation to the exact entity, market and effective date rather than invoke “FASTER compliance” as a generic claim.
The system's success should be measured in pairs. Speed should be paired with evidence completeness. Refund volume should be paired with duplicate-risk outcomes. Intermediary registration should be paired with supervision and sanctions. Digital residence certificates should be paired with beneficial-owner and arrangement evidence. Data collection should be paired with actual usability. Fraud detection should be paired with legitimate-claimant error and appeal outcomes.
A control architecture for boards, intermediaries and authorities
The board of a bank, custodian or investment manager should receive a dividend-tax risk map. It should identify roles performed, countries, products, claim volumes, tax receivables, external advisers, certificate issuance, settlement exceptions and investigations. Aggregate values are not enough. Concentrations by strategy, desk, client, custodian and adviser can reveal a dependency hidden in group totals.
Every material strategy should have an accountable business owner and independent control owner. Approval should state the legal basis, facts required to remain true, systems that verify those facts and stop conditions. Renewal is necessary when law, settlement practice, counterparties or scale changes. A historic opinion should not authorise new structures indefinitely.
Data lineage should run from trade to tax return. The firm should reproduce which source systems created every field, who changed it and how it reconciled. Spreadsheets and manual uploads require controlled versions, access logs and independent totals. A dashboard that cannot drill down to the underlying transaction may create confidence without evidence.
Third-party management should cover economic function, not only procurement. A tax adviser, arranger, custody provider, claim agent or technology vendor may be central to the control chain. Due diligence should identify ownership, competence, conflicts, remuneration and regulatory history. Contracts need data-access, audit, retention, correction and cooperation rights. Fees contingent on refund success deserve enhanced review because they can amplify incentives.
Communications surveillance should be targeted and lawful. Firms need to preserve business communications on approved channels and monitor indicators consistent with their risk assessment. Euphemisms, discussions of certificate availability, allocation of refund proceeds or avoidance of particular jurisdictions may be relevant in context. A phrase alone proves nothing; investigators must connect communication, role, transaction and outcome.
Tax authorities need equivalent governance. Product owners should be accountable for refund-system integrity; fraud teams should influence design; cyber and privacy teams should protect sensitive data; legal teams should define permissible exchange; and operational teams should have capacity to resolve exceptions. Ministers and senior officials should see backlogs, payments, risk flags and resource constraints without turning operational tax decisions into political preferences.
Independent assurance should test end-to-end cases. Auditors can select a withholding event and trace it through custody allocation, claim, authority decision and payment, then select a refund and trace backward to collected tax. They should test duplicates, cancellations, late settlement, amended residence data and cross-border chains. Passing policy design is not the same as passing transaction testing.
Measurement, redress and institutional legitimacy
Public-revenue harm has more than one component. An unsupported refund is a direct cash outflow. Investigation, litigation and recovery consume resources. Legitimate taxpayers may bear delays as controls tighten. Market confidence may fall, and public belief in equal treatment can be damaged when sophisticated entities appear able to monetise complexity unavailable to ordinary taxpayers.
Redress and recovery should be transparent without compromising proceedings or taxpayer rights. Authorities can publish definitions, aggregate orders and cash receipts, litigation status and administrative improvements. They should explain revisions to estimates. A lower revised estimate need not mean the original concern was invented; a higher estimate need not prove the additional amount in court. Measurement maturity includes admitting uncertainty.
Institutions should also disclose control outcomes, not only enforcement totals. Useful measures include the share of claims linked to a verified tax event, unmatched certificates, duplicate alerts resolved before payment, average age of standard and enhanced reviews, intermediary reporting errors, appeal outcomes, amounts prevented, amounts wrongly delayed and recurrence findings. Targets should avoid incentives to reject valid claims merely to show low loss.
For financial firms, remediation evidence includes strategy closure, accountability decisions, revised approvals, data lineage, certificate controls, independent testing and clawback where lawful. Training completion is only an input. A firm proves change when a risky transaction is challenged, escalated and stopped despite attractive revenue, and when senior decision-makers can see that event.
For government, remediation evidence includes statutory clarity, interoperable systems, lawful information exchange, resources, specialist capability and feedback from cases into design. A new database is not automatically a solution. If identifiers are optional, upstream data are unreliable or reviewers cannot interpret the result, digitisation can accelerate the wrong decision.
The accountability test
Operating scenarios that should be tested before launch
A credible control framework should be rehearsed against difficult scenarios rather than only the clean, expected path. In the first scenario, a purchase settles late and the buyer receives a manufactured payment while the seller's custody chain records the original dividend. The system should prevent both records from becoming unrestricted evidence of withholding. Operations must preserve the fail, the payment classification and the later correction, while the tax-control layer keeps the total relief capacity within the original amount collected.
In a second scenario, an investor changes custodian after the dividend date but before filing a claim. The receiving custodian may hold the current account yet lack the payment history. Transfer procedures must move the provenance record or clearly state that no certification can be made. A customer request for speed cannot justify reconstructing tax evidence from the current position alone.
In a third scenario, a claim is corrected after partial approval. The original claim, the consumed tax capacity, the correction reason and any repayment must remain linked. Deleting the first version creates a new duplicate risk. Systems should use reversals and controlled amendments, with human approval when a change increases the amount payable or alters beneficial-owner identity.
In a fourth scenario, two member states ask about the same security, date and chain but apply different legal tests. The exchange should return facts and provenance without purporting to decide the other state's law. Each authority records its own entitlement analysis, while a shared match prompts coordination about possible double use.
In a fifth scenario, a certified intermediary repeatedly sends technically valid reports that arrive too late for pre-payment matching. Supervision should treat timeliness as a control outcome, not a clerical metric. Remediation might require enhanced sampling, restricted fast-track access or enforcement under the applicable national rules.
Finally, firms and authorities should run a “known contradiction” exercise. Seed a record in which the certificate amount exceeds the upstream tax allocation, a settlement identifier is duplicated, or a residence claim changes without explanation. The test is not merely whether software produces an alert. It is whether an accountable person investigates, stops payment where appropriate, preserves lawful claimant rights and feeds the lesson back into design. That operating evidence is stronger than a policy attestation because it shows how the institution behaves when speed, revenue or backlog pressure conflicts with proof.
Testing should also include governance failure rather than only data failure. A desk may produce a technically complete approval pack while omitting a dissenting operations view. The exercise should ask whether the dissent reaches the independent control owner, whether the commercial sponsor can override it, and whether the override is visible to senior management. A control that works only when business and compliance already agree is not a meaningful line of defence.
Capacity stress is another necessary scenario. Dividend seasons concentrate claims, market activity and operational exceptions. Authorities should model what happens when queues exceed forecast, specialist reviewers are absent or an external data feed becomes unavailable. Pre-agreed contingency rules should identify which claims can still follow a fast route, which require enhanced review and who may accept residual risk. Backlog pressure must not silently lower the evidence threshold. Equally, a contingency should prevent indiscriminate suspension of legitimate claims when a narrower control would protect revenue.
Finally, assurance teams should test whether management information preserves uncertainty. A claim awaiting upstream confirmation should not appear as “cleared” merely because no adverse match was returned. A certificate correction should remain visible after the error is fixed. Reports should distinguish alerts generated, alerts investigated, claims stopped, claims later approved and confirmed false positives. Those categories allow boards and public leaders to judge both protection and fairness.
Collapsing them into a single number can reward superficial closure and conceal the difficult cases in which the system needs investment, legal clarification or cross-border cooperation.
Cum-Ex shows how an institution can process a formally complete fragment while missing the truth of the whole chain. The lasting question is therefore not whether authorities and firms can describe the scheme after years of litigation. It is whether they can prove entitlement before money moves and assign responsibility when the evidence is incomplete.
For a tax authority, the test is direct: can every relief decision be connected to a unique, valid withholding event and to the claimant's legal entitlement? For a custodian: can it show the provenance and limits of every certificate? For a bank or fund: can it explain the strategy's return without assuming unsupported public payment? For an adviser: can it distinguish verified facts from client assumptions? For a board: can it see the whole chain across entities and incentives? For legislators: can the law support both efficient investment and enforceable traceability?
No answer should rely on a label. “Cum-Ex,” “arbitrage,” “certified intermediary,” “legal opinion” and “digital process” are categories, not evidence. The evidence is the tax collected, the entitlement, the trade and settlement chain, the unique certificate, the claim history, the decision record and the operating response to contradiction.
The institutional standard is one payment, one controlled evidence lineage and no relief beyond lawful entitlement. Achieving it requires legal clarity, technical interoperability, professional scepticism and human ownership. It also requires restraint: allegations must remain allegations, individual judgments must remain individual, and aggregate estimates must retain their definitions. That combination—strong controls and careful attribution—is what turns a scandal narrative into durable tax governance.

