With respect to the transparency and exchange of information on request (EOIR) standard, the confidentiality and data safeguards requirements are assessed as part of the EOIR monitoring and peer review processes.
With respect to the Automatic Exchange of Information (AEOI) standards – the Common Reporting Standard (CRS) and the Crypto Asset Reporting Framework (CARF) – the Global Forum has dedicated Confidentiality and Data Safeguards (CDS) monitoring and peer review frameworks. This is to provide assurance to jurisdictions engaging in AEOI on the particular CDS risks arising in the context of the annual automatic exchange of electronic information.
Jurisdictions commencing AEOI undergo an assessment prior to commencing exchanges (a pre-exchange assessment), followed by a post-exchange assessment. In the context of the rapidly evolving technology and cybersecurity environments, a third round of assessments commenced for jurisdictions upon completing of their post-exchange assessments.
CDS assessments are carried out by assessment teams comprising Information Security Management (ISM) experts drawn from members, supported by the Global Forum Secretariat. Where issues are identified, recommendations are made. If serious issues are identified, a jurisdiction’s clearance to receive AEOI data may be suspended, until the issues are assessed as addressed.