In-house counsel face a period of converging shifts: several filing deadlines have seen temporary extensions or clarified timing, while crypto regulatory and tax regimes across jurisdictions continue to crystallize. This moment requires a focused, practical review of reporting calendars, contractual obligations, and controls to avoid surprises from late filings, cross-border exchanges, or new disclosure duties.

The checklist below synthesizes recent developments and practical steps counsel should take now: confirm extended deadlines and their conditions, reassess crypto reporting obligations under emerging frameworks (DAC8/CARF, MiCA, UK rules), align financial disclosure practices with securities and tax expectations, shore up AML/CFT and data controls, and prepare for audits, enforcement, and litigation risk.

Confirm filing deadline extensions and conditions

Start by compiling all extended or recalibrated deadlines that affect your group: corporate income tax filings, information returns, securities periodic reports and local statutory filings. Some tax authorities have reiterated that extensions require active requests or payments by the original due date, so a calendar-based assumption is risky.

For public companies, review whether recent regulatory commentary or proposals affect the application of extension mechanisms (for example, staff guidance and rule interpretations that clarify when an extension is permitted and what it does not cover). Extensions do not uniformly excuse disclosure obligations delivered through other channels (such as Form 8-K or earnings releases).

Document who within legal, tax and finance owns each extension request and any payment or certification requirement. Confirm whether any extension affects downstream covenants, debt reporting, investor communications, or filing-based shelf registrations, and plan remedial actions if an extension is denied or rescinded.

Reassess crypto reporting obligations under DAC8 and CARF

EU-level reporting obligations for crypto have materially advanced: the DAC8 / Crypto-Asset Reporting Framework (CARF) obligations are in force for reporting years beginning in 2026, with the first exchanges of information scheduled to begin in 2027. In-house counsel should verify whether entities in the group qualify as reportable crypto-asset service providers (RCASPs) or have reportable sellers among their clients.

Practical steps include mapping crypto product types to the CARF/DAC8 definitions, confirming which legal entities and jurisdictions within the corporate group are captured, and identifying gaps in KYC/tax residency data needed for accurate reporting. Expect harmonised electronic templates and technical formats to drive how data must be produced.

Coordinate with exchanges, custodians and any third-party providers to obtain reporting-ready data and confirm contractual rights to receive the information. Where the group operates or uses cross-border platforms, consider whether local implementation laws or guidance impose earlier or additional obligations beyond DAC8/CARF.

Align corporate disclosure and securities reporting practices

Review the interaction between newly extended filing dates and continuous disclosure obligations. Even when a periodic filing can be extended, material events still usually require prompt public disclosure under securities laws,so governance must ensure that extensions do not defer investor-facing duties. Examine internal escalation criteria and Form 8-K (or equivalent) triggers to avoid gaps.

For groups with token-related products or treasury holdings in crypto-assets, assess whether accounting, valuation, and disclosure frameworks have changed under recent supervisory guidance (for example, MiCA-related reporting templates and issuers’ responsibilities to CASPs). Ensure finance and audit teams can reconcile operational crypto records with the numbers reported to regulators and tax authorities.

Update disclosure checklists and quarter-end closing procedures to reflect both deadline adjustments and the need to capture crypto-specific metrics (custody arrangements, asset categorization, impairment/valuation policies). Legal should partner with finance to document judgments to support filings in case of later review.

Strengthen AML/CFT and supervisory compliance in light of regime shifts

Global AML/CFT expectations for virtual assets have been elevated recently; FATF monitoring continues to identify implementation gaps in many jurisdictions and to press for stronger controls by VASPs. In-house counsel must verify that the group’s AML policies, transaction monitoring and suspicious activity reporting are aligned with the latest FATF and local supervisory expectations.

In the UK, the FCA’s cryptoasset regime and policy statements have broadened the perimeter for regulation and clarified firm obligations; firms should be ready for gateway and operational requirements, consumer protections, and future guidance on DeFi and operational resilience. Counsel should read the FCA statements and adjust governance, registration and consumer-facing processes accordingly.

Practical tasks include: updating customer due diligence for crypto counterparties, embedding transaction monitoring rules that reflect token typologies and mixing/obfuscation risks, ensuring suspicious activity escalation paths are tested, and confirming that vendor onboarding for custody or exchange services meets AML expectations.

Audit data, controls, and vendor arrangements for crypto operations

Regimes like MiCA and CARF emphasise standardized reporting and data submission, which means data lineage and integrity are now a compliance priority. Counsel should coordinate with IT, finance and third-party vendors to perform a data-gap analysis focusing on wallet ownership records, transaction histories, counterparty IDs, timestamps, and tax residence indicators.

Revisit vendor contracts with exchanges, custodians and analytics providers to ensure they deliver the data fields required for both tax reporting and supervisory returns, and include audit rights and SLA provisions for timely data delivery. Where vendors resist scope changes, document mitigation steps and consider alternative providers.

Elevate internal controls around privileged access, multi-signature custody, reconciliation routines and independent attestations. Insist on test evidence that reporting extracts match source systems and that reconciliations occur before any regulatory submission.

Prepare for audits, enforcement, and cross-border information exchange

The expansion of automatic information exchange for crypto and intensified AML/CFT oversight increase the likelihood of cross-border queries and audits. Counsel should inventory historical crypto activity and assemble contemporaneous support, transaction logs, KYC records, tax residency declarations, and communications with service providers, to shorten response times to tax authorities or supervisors.

Develop a coordinated response playbook that identifies legal privilege boundaries, the lead jurisdiction for requests, and media/ investor communications roles. Conduct tabletop exercises with tax, compliance, and finance so the organization can respond within statutory deadlines and with consistent positions across jurisdictions.

Consider whether voluntary disclosures, amended returns or remediation programs are advisable for prior periods where reporting was incomplete. Early engagement with tax authorities or supervisors can materially reduce penalties and shape outcomes in cross-border cases.

As reporting deadlines shift and crypto regimes evolve, in-house counsel must convert regulatory change into actionable checklists. Prioritise mapping obligations to entities, verifying data flows, and documenting decisions that will support filings and defend positions in audits or enforcement actions.

Finally, treat this as an interdisciplinary program: legal, tax, finance, compliance, IT and external advisers should meet regularly until the new routines for deadlines and crypto reporting are embedded. The combined effect of deadline changes and expanded crypto reporting creates both operational risk and an opportunity to improve control environments for the long term.