FATCA CRS Compliance: Complete BCP Exam Guide 2026
FATCA CRS compliance is one of the highest-yield topics in the entire Banking Compliance Professional (BCP) syllabus, and getting it right separates candidates who pass comfortably from those who lose easy marks. Every Indian bank that holds, manages or pays out on financial accounts has cross-border tax-reporting obligations, and the compliance function owns the controls that make that reporting trustworthy. This guide walks you through exactly what the Foreign Account Tax Compliance Act and the Common Reporting Standard require, how the two regimes fit together, who is accountable inside the bank, and how an examiner expects you to reason about due diligence, classification and reporting.
Treat this as both a concept explainer and a revision blueprint. Read it once to understand the architecture, then come back to the tables, the common-mistakes list and the FAQ in the days before your exam to lock the high-frequency points into memory.

Key takeaways
- FATCA is United States legislation implemented in India through an Inter-Governmental Agreement (IGA); it targets US persons and US-source income.
- CRS is the OECD's multilateral Common Reporting Standard, covering tax residents of more than 100 partner jurisdictions.
- Both regimes are operationalised in India under the Income-tax Rules (Rules 114F to 114H) and reported to the CBDT, which exchanges data with foreign authorities.
- The operational core is identifying each account holder's tax residency using self-certification, documentary evidence and indicia checks.
- The Chief Compliance Officer (CCO) owns the framework and is accountable to the board; the three lines of defence keep it auditable.
- Reportable accounts are filed annually, typically via Form 61B; inaccurate or missing statements attract penalties and reputational damage.
What FATCA and CRS actually require
FATCA and CRS are often spoken about in the same breath, and for good reason: they share a purpose, much of their plumbing, and most of their day-to-day operational steps. But they have different origins, and an examiner will reward you for keeping them distinct.
The shared purpose is simple to state — stop tax evasion through undisclosed offshore accounts. Strong FATCA CRS compliance means a bank can reliably identify the tax residency of every account holder and report every reportable account accurately to the authorities. Where they differ is in scope and legal source.
- FATCA is US legislation, brought into Indian practice through an Inter-Governmental Agreement. Its lens is narrow: US persons and US-source income.
- CRS is the OECD's multilateral standard. Its lens is wide: tax residents of more than 100 partner jurisdictions, not a single country.
- Both are operationalised in India under the Income-tax Rules — notably Rules 114F to 114H — and reported to the CBDT, which then exchanges the data with treaty partners.
If you want the regulatory context behind these obligations laid out alongside the wider compliance mandate, the deep-dive on the compliance function in banks: FATCA, CRS and RBI expectations is a useful companion read.
Why the BCP syllabus weights this topic so heavily
Reporting failures carry withholding consequences, monetary penalties and serious reputational damage, which is precisely why the compliance function owns the control rather than the business line. The syllabus rewards candidates who can confidently distinguish a Reportable Account from a non-reportable one, a Financial Institution from a non-financial entity, and an Active from a Passive Non-Financial Entity (PNFE). Get those definitions crisp and a large slice of the exam's questions become straightforward.
The core vocabulary you must master
FATCA CRS compliance is, more than anything, a vocabulary discipline. The exam tests whether you can apply a handful of precise terms to a scenario. The table below summarises the terms candidates most often confuse.
| Term | What it means | Why it matters in the exam |
|---|---|---|
| Reportable Account | An account held by one or more reportable persons (or a passive entity with reportable controlling persons). | It is the trigger for the entire reporting obligation. |
| Financial Institution | A custodial institution, depository institution, investment entity or specified insurance company. | Determines whether an entity reports or is merely reported on. |
| Passive NFE | A non-financial entity that is not active — often earning mainly passive income. | Forces a look-through to its controlling persons. |
| Self-certification | The customer's formal declaration of tax residence and TIN. | The primary evidence of residency at onboarding. |
| Indicia | Signals (foreign address, phone, US place of birth) suggesting foreign tax residency. | Triggers enhanced checks and possible curing. |
Want to drill these definitions until they are automatic? The BCP match-the-pairs revision game is built for exactly this kind of vocabulary recall.
Governance: who owns FATCA CRS compliance in a bank
Effective FATCA CRS compliance is never a back-office afterthought. It is anchored in the bank's compliance governance structure, with clear accountability flowing up to the board. The Chief Compliance Officer is accountable for the framework, reports functionally to the board (or its Audit or Risk Committee), and ensures that onboarding, operations and IT teams execute the controls consistently.
- The board approves the compliance policy and reviews material breaches, including any FATCA or CRS reporting failures.
- The CCO independently oversees the due-diligence rules, escalation and regulator interaction, with direct access to the board.
- Business and operations units own day-to-day account classification, self-certification collection and indicia checks.
- Internal audit independently tests whether the reporting actually meets the legal standard.
This separation of duties is what makes the framework auditable and defensible to a regulator. For the broader picture of how the compliance function is structured and supervised, see the complete BCP guide to the compliance function in banks and the focused notes on RBI guidelines, the CCO role and FATCA/CRS.
Customer due diligence and self-certification
The operational heart of FATCA CRS compliance is determining each account holder's tax residency — at onboarding and on an ongoing basis. Banks rely on self-certification supported by documentary evidence, reinforced by indicia checks run against existing KYC records.
Key due-diligence concepts
- Self-certification: the customer declares their country or countries of tax residence and Taxpayer Identification Number (TIN). A fresh certification is required when indicia change.
- Indicia: signals such as a foreign address, a foreign phone number, standing instructions to a foreign account, or a US place of birth that trigger enhanced checks.
- Account thresholds: due-diligence intensity differs for individual versus entity accounts, and for pre-existing versus new accounts.
- Curing: if indicia appear, the bank must obtain documentation to cure them, or otherwise treat the account as reportable.
The principle to carry into the exam is that the framework is only as strong as the KYC data feeding it, so ongoing remediation of stale or incomplete records is a genuine compliance obligation, not a clerical nicety.
Three lines of defence and the compliance risk cycle
Examiners love to test how FATCA CRS compliance maps onto the bank's wider risk architecture. The three lines of defence model assigns clear ownership so that no control depends on a single team, and the compliance risk assessment cycle keeps that ownership honest over time.
| Line of defence | Who | FATCA/CRS role |
|---|---|---|
| First line | Business and operations | Own the risk; collect self-certifications and classify accounts. |
| Second line | Compliance and risk | Set policy, monitor, and independently challenge the first line. |
| Third line | Internal audit | Provide independent assurance to the board that the first two lines work. |
The risk assessment cycle
A Risk and Control Self-Assessment (RCSA) follows a repeatable loop: identify the compliance risks, assess their likelihood and impact, control them with policies and system checks, monitor through testing and metrics, and report residual risk to the board. This cycle is exactly how a bank demonstrates, year after year, that its reporting is reliable rather than merely hopeful. For a structured drill on these governance layers, work through a set of timed BCP practice tests and review where the classification logic trips you up.
Reporting, penalties and common pitfalls
Once accounts are classified, the bank files its statement of reportable accounts — Form 61B in the Indian framework — with the income-tax authorities, who then exchange it under the relevant treaties. Robust FATCA CRS compliance turns on getting both the data and the deadlines right.
- Reporting obligation: reportable accounts must be filed annually, and nil reporting is also required in many cases.
- Accuracy: incorrect TINs, missing self-certifications and mis-classified entities are the most common audit findings.
- Penalties: inaccurate or non-furnished statements can attract penalties under the Income-tax Act, plus regulatory and reputational consequences.
- Data quality: the framework is only as good as the KYC data feeding it, so ongoing remediation matters.
Because procedural details — live forms, thresholds and due dates — are updated periodically, always confirm them against the latest released notification at exam time rather than relying on a figure you memorised months earlier. As per the latest IIBF schedule and CBDT notifications, the precise filing deadlines can shift, so verify on the official IIBF notification and primary tax-authority sources.

A practical study plan for this topic
You do not need weeks to master FATCA CRS compliance — you need a focused, layered approach. Here is a four-step plan that mirrors how the questions are actually set.
- Lock the vocabulary first. Spend your first session on the definitions table above until you can place any term in a sentence without hesitation.
- Map the governance. Draw the board → CCO → first/second/third line chain from memory. Most governance questions collapse to a single diagram.
- Practise classification scenarios. Take ten worked examples — an individual with a foreign phone number, a passive entity with US controlling persons — and decide reportable or not, then check yourself.
- Time yourself. Finish with mock tests under exam conditions so definitions and judgement become reflexive.
If you are building a wider revision schedule around the certification, the BCP syllabus 2026 with free PDF and the timeline in this BCP exam-date guide will help you sequence your weeks. You can also browse every guide for this paper on the BCP blog hub or explore the Banking Compliance Professional course.
Common mistakes candidates make
- Treating FATCA and CRS as identical. They share mechanics but differ in scope (US-only versus 100-plus jurisdictions) and legal source (an IGA versus the OECD standard).
- Forgetting the look-through for passive entities. A Passive NFE forces you to examine its controlling persons — skip this and you misclassify the account.
- Ignoring indicia and curing. An account with unresolved indicia and no documentation should be treated as reportable, not waved through.
- Confusing accountability with execution. The CCO is accountable for the framework, but the first line executes the controls; the exam tests whether you can tell these apart.
- Quoting outdated forms or deadlines. Procedural specifics change; cite the principle and confirm the current figure from the official notification.
Frequently Asked Questions
What is the difference between FATCA and CRS?
FATCA is United States legislation implemented in India through an Inter-Governmental Agreement, and it focuses specifically on US persons and US-source income. CRS is the OECD's multilateral standard covering tax residents of more than 100 partner jurisdictions. Both are reported to the CBDT under the Indian Income-tax Rules, but they differ in scope and origin.
Who is responsible for FATCA CRS compliance in a bank?
The Chief Compliance Officer owns the framework and is accountable to the board or its Audit/Risk Committee. Business and operations teams execute the day-to-day due diligence, while internal audit provides independent assurance. This three-lines-of-defence split keeps the control auditable and independent of any single team.
What is self-certification under these rules?
Self-certification is the customer's formal declaration of their country or countries of tax residence and their Taxpayer Identification Number. Banks validate it against KYC records and indicia such as a foreign address or US place of birth. A fresh certification is required whenever those indicia change, so that the account classification stays accurate over time.
What are indicia and why do they matter?
Indicia are signals that an account holder may be tax-resident abroad — for example a foreign address, a foreign phone number, standing instructions to a foreign account, or a US place of birth. When indicia appear, the bank must run enhanced checks and obtain documentation to cure them. If they cannot be cured, the account is treated as reportable.
How are reportable accounts filed in India?
After classification, the bank files a statement of reportable accounts, generally Form 61B, with the income-tax authorities, who exchange the information under the relevant treaties. Reporting is annual, and nil reporting is also required in many cases. Always confirm the live form, thresholds and due date from the official notification, as these procedural details are updated periodically.
How is this topic tested in the BCP exam?
Expect conceptual questions on definitions — reportable account, financial institution, passive NFE and indicia — alongside questions on governance roles, the three lines of defence, and the reporting and penalty framework. Classification scenarios are common, so practising worked examples and timed mock tests is the most reliable way to score. Confirm any live procedural figures from official sources before exam day.
Conclusion: master compliance reporting before exam day
Strong FATCA CRS compliance ties together due diligence, governance, the three lines of defence and accurate reporting — a combination that rewards structured revision far more than rote memorisation. Get the vocabulary precise, draw the governance chain from memory, and rehearse classification under time pressure, and this becomes one of the most dependable scoring areas in the paper. For authoritative guidance, you can always refer to the official resources of the Indian Institute of Banking and Finance. Now go and turn this understanding into marks.
Related Guides
📚 Free Learning Sessions resources — connect & crack your exam
- 📝 Free mock tests — chapter-wise, exam-pattern, with instant solutions
- 🎮 Matching games — gamified revision of key terms & concepts
- 📄 Study notes & PDFs — downloadable chapter material
- 🎥 Video classes on YouTube — subscribe to @learningsessions
💬 Want the full course? WhatsApp your course name to 8360944207 and our team will set you up.
📱 Study on the go — get our iOS & Android app at iibf.store/app.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading