Summary
- A tax-information treaty does not by itself make a jurisdiction an appropriate recipient. The Global Forum’s AEOI framework requires legal limits on use and disclosure, a functioning information-security-management system, and enforcement when safeguards fail.
- In 2026, annual monitoring joins pre-exchange, post-exchange and later assessments. The design makes the right to receive tax data depend on maintained assurance, while capacity-building is meant to help more administrations qualify rather than simply exclude them.
The most important word in automatic exchange of information is not “automatic.” It is “receive.”
Under the OECD Global Forum’s published terms, a jurisdiction can receive information only if it meets the confidentiality and data-safeguard requirement. The standard calls the qualified recipient an “Appropriate Partner.” That condition changes the usual picture of tax cooperation. A treaty or multilateral agreement supplies a legal route for data to travel, but it does not make the destination trustworthy by itself. The recipient must be able to show that the information will remain protected and will be used only under the terms that authorized the exchange.
The Global Forum’s AEOI system covers the Common Reporting Standard (CRS) for financial accounts and the Crypto-Asset Reporting Framework (CARF) for crypto-asset transactions. These are recurring exchanges between tax authorities, not one-off document requests. A route that moves sensitive information every year creates a continuing question: can the receiving administration protect the data after it arrives, across its staff, systems, contractors, records and decisions?
The agreement is a route, not a security system
The safeguard framework has three connected parts. First comes law: domestic rules must preserve confidentiality and restrict access, use and disclosure to the purposes allowed by the applicable international instrument. Second is information security management (ISM): the authority needs policies, responsibilities, risk controls, technical measures and operational processes that protect the information throughout its lifecycle. Third is enforcement: suspected or actual misuse must be reportable, investigated and subject to appropriate remedies or sanctions.
This is broader than a firewall or a secure transfer channel. The Terms of Reference for the Confidentiality and Data Safeguards Assessment call for senior-management ownership, defined security roles, personnel and contractor controls, physical protection, system security, least-privilege access, and procedures for handling, storing, retaining and destroying information. They also address monitoring, logs, vulnerability and incident management, audit, penalties, remediation and notification of other competent authorities.
That lifecycle approach matters because a secure arrival is only the first link. Treaty-protected data can pass through several offices, databases, analytical tools and vendors. If the treaty’s limits are not carried through those hand-offs, the international promise can be weaker than the system that receives the file. The framework therefore asks about an administration’s governance arrangements as well as its technical environment. It also allows operational scope to vary: authorities must explain how their information lifecycle works so the assessment can examine the actual path the data takes.
Assurance has more than one checkpoint
The Global Forum’s public description identifies a sequence rather than a single admission test. A jurisdiction starting AEOI undergoes a pre-exchange assessment, followed by a post-exchange assessment. After the post-exchange stage, a third round began in response to changing technology and cyber-security conditions. Assessments are carried out by teams of information-security experts from member jurisdictions, supported by the Global Forum Secretariat. Where they identify issues, they can make recommendations. Serious issues may lead to suspension of clearance to receive AEOI data until the issues are assessed as addressed.
From 2026, an annual monitoring process adds oversight of whether jurisdictions are maintaining appropriate safeguards. The public framework says Global Forum ISM experts may provide targeted follow-up where appropriate. It separately says that an apparent breach or safeguard failure that indicates exchanged information could be at risk may lead to suspension of AEOI with that jurisdiction while assurance is re-established through a targeted assessment.
Those are consequential powers, but the distinctions matter. A pause in clearance to receive data because serious assessment issues remain is not the same thing as suspending an existing exchange after an apparent breach or failure. The published language describes conditional possibilities; it does not say either action occurred in any particular jurisdiction. Nor does “annual monitoring” mean that every country receives a full repeat peer review every year. The OECD says the process provides annual oversight with targeted expert follow-up, but does not publish the metrics, case-selection rules or country-level results.
A gate can also be an on-ramp
An assurance requirement can look like a barrier to entry, especially where a tax authority has limited staff, legacy systems or a small security budget. The Global Forum’s support programme suggests a different institutional logic: build readiness before the formal gate, then maintain the standard after exchange begins.
The OECD’s 2025 Information Security Management Maturity Assessments report records that 21 eligible jurisdictions accepted a preliminary maturity assessment in 2024. Seventeen proceeded to a more detailed phase, whose reports were completed by November 2025. The Secretariat described all 21 as viable candidates to set 2027 as a start year; one participant later made a political commitment to begin CRS exchanges in 2028. These were readiness assessments and planning milestones, not formal clearance or proof that all participants began exchanging.
The report also records that seven additional developing countries began AEOI exchanges in 2024–25, bringing the cumulative developing-country total to 43. The numbers do not prove that technical support alone caused participation, but they do show a model in which assurance and assistance are linked. Maturity assessments identify gaps, help administrations coordinate legal, information-security, procurement, human-resources and tax-exchange teams, and produce implementation plans. The formal safeguard assessment remains a separate step.
On 6 October 2026, the Global Forum launched Safeguarding Tax Information, a practical guide that builds on its earlier toolkit and reflects current information-security, cyber-security, governance and risk-management practices. The OECD says it is designed to help authorities assess, develop and continuously improve their ISM capacity. It is guidance and capacity-building, not a new treaty, a new certification or a substitute for the existing assessment framework.
What the public can—and cannot—verify
The framework balances two forms of trust. Exchange partners need credible assurance that their data will be protected. Taxpayers need confidence that sensitive information will not be used or disclosed outside the legal purpose. Yet the Global Forum says the detailed assessments and framework are not published because they are confidential. This protects sensitive operational information, but it also limits public scrutiny of how the gate is applied and whether remediation is predictable.
That visibility gap is not evidence that the process is arbitrary or ineffective. It does, however, make the public architecture important. The Global Forum’s published framework identifies the legal condition, assessment stages, expert role, possible consequences and annual monitoring. Its assistance programme and earlier 2020 toolkit show that the system is also intended to develop capacity.
Tax transparency and data protection are often presented as competing goals: exchange more, or protect more. The Global Forum’s model rejects that simple choice. It treats secure handling and treaty-bounded use as prerequisites for legitimate exchange. Whether that balance works in practice will depend on the quality of the safeguards and on how fairly and clearly the gate is maintained. A passport for tax data is credible only if it proves both sides of the bargain: the information may travel, and the recipient remains accountable for what happens after it arrives.
Sources
- Global Forum CDS requirements, assessments and annual monitoring
- Terms of Reference for the Confidentiality and Data Safeguards Assessment
- 6 October 2026 practical-guidance launch
- 2025 ISM maturity-assessment outcomes
- Confidentiality and data-safeguards assistance
- 2020 confidentiality and ISM toolkit
- Global Forum on Transparency and Exchange of Information for Tax Purposes
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
