This is the third part of our three-part series on unintended consequences of the FASTER Directive. You can read our earlier articles here and here.
The FASTER Directive will generate enormous volumes of structured tax reporting data. At first glance, that appears to be the biggest implementation challenge. It isn’t. The real challenge is ensuring that data remains accurate, complete and trustworthy as it moves through increasingly complex payment chains.
How much data will FASTER generate?
I have spoken anecdotally on many occasions about the fact that the data volumes involved will be large, certainly into the terabyte per year range and that the nature of the data will make it an extremely tempting target for cyber-criminals. Processing power and security are therefore important considerations in FASTER.
While precise modelling of data volumes is currently not possible, some range estimates may be useful for discussion between technical, operations and compliance functions.
Annual FASTER reporting volume (A) = number of reportable registered owner/payment records (R) x average payload size (P) x reporting chain multiplier (Cm)
𝐴=𝑅 𝑥 𝑃 𝑥 𝐶𝑚
Where:
R = one claim of relief for one registered owner, on one ISIN, for one dividend payment date, in one SMS
P = average size of each record
Cm = the average number of intermediaries in the chain of payment (1-1.5 for direct reporting and 2-4+ for indirect reporting).
For the purpose of modelling I assume:
| Item |
Low |
Base |
High |
| EU dividend-paying listed issuers |
2,500 |
3,500 |
5,000 |
| Average dividend payments per year |
1.2 |
1.5 |
2.0 |
| Issuer-level dividend events |
3,000 |
5,250 |
10,000 |
I note here that FASTER applies to both dividends and interest but I am using dividend modelling only. FESE3 data indicates that EU exchanges had over 7,000 listed companies in 2025, although not all are EU companies, not all pay dividends and many pay only annually or semi-annually. In other words, these are very rough estimates and only the required post-FASTER implementation review will reveal the truth.
Estimating the scale of FASTER reporting
S&P Global estimated European dividends at €486.1 billion4 in 2025, excluding special dividends. That is not a pure EU-only FASTER figure, but it is a useful scale indicator for European dividend flows. The European Commission also notes that non-domestic investors held $10.7 trillion of securities in the EU in 2019, which supports the assumption that cross-border dividend flows are very large. I think a workable first-pass range would be:
| Scenario |
Reportable records per year |
Rationale |
| Low adoption / institutional-heavy |
25–50 million |
Fast-track relief mainly used by larger institutional investors and global custodians. |
| Base case |
75–150 million |
Meaningful use by banks, brokers, asset managers and retail platforms across major dividend markets. |
| High adoption / retail & fund platforms |
200–300 million+ |
Broad platform adoption, many small investors, high use of relief-at-source and quick refund. |
This aligns with industry concerns. The Nordic finance sector has already warned that the amount and frequency of FASTER reporting could be “truly enormous”, especially because reporting is live within two months of payment rather than annual as in some existing systems.
Using the Annex to the Directive, a minimal structured record may be 2-4Kb. An XML style record may be 5-8Kb while a heavy record including long addresses references and metadata could be 8-12Kb. If eTRC certificate payloads are included and repeatedly embedded (not expected), the payload may reach 20-50Kb
Taking a median position using a 6Kb base record, I present three scenarios – low, base and high.
In a low scenario, we would expect around 30 million records with an annual payload of around 180GB (200-500GB with indirect reporting).
In a base scenario we would expect around 100 million records with an annual payload of around 600GB (1-2TB with indirect reporting).
In a high scenario we would expect around 250 million records with an annual payload of 1.5TB (3-6TB with indirect reporting).
Data quality is the real challenge
Probably the largest data headache is not volume, but quality. Those at the top of the payment are, by far, the most sophisticated and have custom built digital banking systems. Those at the bottom of the payment chain are much less sophisticated and often manage much smaller data packages. They will often use spreadsheets to aggregate data across multiple systems with little or no interoperability. This feeds into more general concerns over FASTER surrounding some of the more practical components. This might include the efficiency with which eTRCs are obtained and signed declarations and the consistency with which due diligence is performed before tax relief is granted. These all feed into concerns, at every level, about risk and liability.
FASTER thus creates a significant data quality challenge. The issue is not merely whether a CFI can submit a technically valid report, but whether data collected and transmitted across a multi-party custody and payment chain remains accurate, complete, consistent and reconcilable by the time it reaches the Source Member State Competent Authority. In the indirect reporting model, data received from downstream CFIs and N-CFIs may be validated, aggregated, reformatted and passed further up the chain before it is ultimately reported. This creates a risk that errors in investor identity, tax residence, TIN, payment amount, ISIN, record date, entitlement basis or intermediary role are replicated or compounded as the data moves upwards. It also creates a matching problem for the SMSCA, which must distinguish between duplicate claims, multiple reports about the same payment, legitimate multi-intermediary chains and genuinely inconsistent data.
Why chain integrity matters
The FASTER data quality problem is therefore a chain integrity problem. The value of the reporting framework will depend on whether each party in the chain can preserve the lineage of the data: who supplied it, what checks were performed, whether it was altered or enriched, when it was transmitted, and whether any later correction was made. Without strong data lineage, validation standards and correction workflows, the SMSCA may receive large volumes of data that are formally complete but operationally difficult to trust. In that scenario, FASTER risks becoming data-rich but assurance-poor.
One of the missing components in the Directive, as I have noted, is the lack of definition in what constitutes an operable tax relief system. The US qualified intermediary system by contrast uses a cascade of documentation and formalised withholding statements that serve to protect financial institutions, allow for effective relief and place risk and liability where it belongs – with the requestor. FASTER does not contain those elements. So, from a data perspective, while the reporting is structured according to an OECD XML schema, the operational matter preceding the reporting, the standardisation, is being left to the industry which, historically, has preferred ISO standards due to its greater governance, control and standards release methodologies. The data quality issue noted in the preceding paragraph would, to a large extent be resolved with a submission to the ISO Registration Authority (RA) for a sequence of messages designed to address each situation.
Could tokenisation and DLT help?
One other possible way to address this chain-integrity problem would be to separate the reported tax data from the evidence of its movement through the chain. For example, registered-owner data, eTRC evidence, declarations and payment-entitlement records could be represented by secure tokens or cryptographic references rather than repeatedly transmitting the same underlying personal data to every party in the chain. Similarly, distributed ledger technology, or DLT style architecture, could be used to create a tamper-evident record of who supplied the data, when it was validated, what changes were made, when it was transmitted and whether a correction was later submitted.
The point would not be to place personal data on a blockchain. That would create obvious GDPR, confidentiality and retention problems. The more realistic use case would be a permissioned, private, financial-market infrastructure in which hashes, tokens, timestamps, validation events and correction references are recorded, while the underlying personal data remains off-chain under the control of the relevant CFI or authorised platform. Used in that way, tokenisation or DLT could support data minimisation, auditability, non-repudiation and reconciliation without turning FASTER into an uncontrolled data-sharing network.
Difficult choices for Member States
From these observations it’s clear that direct reporting in FASTER is a secure reporting channel issue while indirect reporting is a multi-party custody chain data governance issue. So, while many prefer the indirect reporting model, SMSCAs should consider the risks and reliability associated with receiving the entire payment chain data after it has gone through multiple counterparties, each of which will have had to do some manipulation of the data, consolidation and error checking before moving it upstream. The less risky model would be the direct reporting model which, although it would require more work from the SMSCA if they really want to re-create an entire payment chain, would result in more reliable data that has not been manipulated to such a high degree.
As with CRS and FATCA reporting, the nature and transmission mechanisms of FASTER means that the data is of extremely high sensitivity and high risk not just for the financial institutions that have to gather it, but also for any financial institution acting as a CFI and certainly for the SMSCAs that are receiving it. While the purpose may be to deter tax evasion by registered owners and provide them with the treaty relief to which they are entitled, we must recognise that these efforts also paint a clear cyber-target on the industry.
A big question is about value extraction i.e., once the industry has invested the not insignificant effort to deliver all this reporting data, again presuming that, for the most part, the purpose was to provide more efficient treaty relief to those that were entitled, what would the SMSCAs be doing with all that data?
Four possibilities present themselves:
- validate quick refunds
- reconstructing the payment chain
- running anti-abuse and risk analytics
- monitoring of CFIs
I suspect that anti-abuse is what it’s really all about, using the reconstructed payment chain as the source data. This kind of analysis should reveal any duplicate claims being made by the same registered owner on the same payment as well as the same registered owner appearing through multiple CFIs or N-CFIs. This is not currently possible in the US model for example, due to pooled reporting by qualified intermediaries
The monitoring of CFIs, which is already taking place in CRS, FATCA and QI, can also shine a light on intermediary capability at an operational level. This will probably lead to the use of the optional components of reporting in the Directive Annex II(E) and Annex II(F) derived from Article 10(2) especially in markets that have already suffered such abuse such as Germany’s cum-ex dividend scandal.
A major issue for SMSCAs will not be whether they can hold the data, it will be whether they can build a reliable pattern matching, validation, exception management and risk scoring system for the data. I suspect that artificial intelligence companies will have a particular interest in that market.
FASTER gives SMSCAs the possibility of moving from a document-based withholding tax relief model to a data-driven control model. That, in principle, means the data can be used to validate relief claims, reconstruct payment chains, detect duplicate or abusive claims, supervise CFIs, identify high-risk intermediaries and produce management information on cross-border withholding tax relief all at significant scale.
However, the value of the data will depend on whether the SMSCA can consume, match, validate, reconcile and risk-score large volumes of registered owner, payment, security and intermediary chain data. The challenge is therefore not merely one of storage capacity, but of data quality, entity resolution, chain reconstruction, exception handling, privacy, auditability and operational resilience. In the indirect model, the SMSCA may receive a more complete chain-level report, but the data will be more concentrated and potentially much more complex. In the direct model, the data may be less concentrated at submission point, but the SMSCA will need stronger matching tools to reconstruct the chain from multiple CFI reports. If Member States build modern data pipelines and analytics engines, they can cope. If they rely on legacy refund infrastructure or manual review, FASTER could produce more data than they can use effectively.
Finally, a chain is only as strong as its weakest link. The weakest link in this case is the quality of data acquired and manged by financial institutions. As regulation and Directives become increasingly invasive to how financial institutions are operating rather than merely what they do, the cracks will just get larger exposing the difference between the larger firms and the smaller.
Data quality will determine FASTER’s success
FASTER has the potential to transform withholding tax administration by moving from a document-based model to a data-driven control model. Whether that succeeds will depend less on reporting volume than on the quality, integrity and governance of the underlying data.
Without strong validation, lineage and reconciliation, FASTER risks becoming data-rich but assurance-poor.