Advertisement
Advertisement
Skip to content
Follow Us on
Advertisement
TOP STORIES
Income Tax

Form 166 and the Foreign TIN Problem: What the Revised CBDT Guidance Note Changes for Reporting Financial Institutions

#AD

Form 166 and the Foreign TIN Problem: What the Revised CBDT Guidance Note Changes for Reporting Financial Institutions

The CBDT released a revised Guidance Note on FATCA and CRS on 24 July 2026. It replaces the note first issued in August 2015, and it is the first full rewrite since India moved to the Income-tax Act, 2025. For anyone preparing the annual statement of reportable accounts, the headline changes are known by now: Form 166 replaces Form 61B from 1 April 2026, the obligations sit in Rules 238 to 240 of the Income-tax Rules, 2026, and the statement is still due by 31 May.

Less discussed is what the note asks of the data that goes into Form 166, and in particular of one field that has caused trouble since 2017: the taxpayer identification number of the account holder.

Advertisement

Why the TIN in Form 166 is almost always a foreign number

Under CRS, an Indian reporting financial institution reports accounts held by persons who are tax resident in other jurisdictions. The TIN it must report is therefore not a PAN. It is the number issued by the account holder’s country of residence: a UK Unique Taxpayer Reference or National Insurance number, a Canadian Social Insurance Number, a Singapore NRIC or FIN, a German Steuer-ID, and so on across the more than 120 jurisdictions that the Guidance Note says now participate in CRS exchange.

The note accepts a functional equivalent where a country issues no TIN as such, for example a social security or national insurance number, which widens the range of formats further. This is where the process is weakest. The number is written on a self-certification by the customer, often at a branch, and keyed in by staff who have never seen a Canadian SIN and have no way to tell whether the nine digits in front of them could be one. A PAN has a format every Indian banker recognises on sight. A foreign TIN does not, so an error at account opening usually survives until the reporting file is prepared, or until the partner jurisdiction cannot match the record.

The common errors are ordinary ones. A digit dropped or transposed. An Indian PAN or Aadhaar number entered in the foreign TIN field. The passport number given instead of the tax number. A number in the right format but for the wrong country, when the customer holds residence in one place and citizenship in another.

What the revised note adds

Three parts of the revised note make this more pressing.

The first is scope. From 1 January 2026 the definition of Depository Institution in Rule 238(3) covers any entity holding specified electronic money products or central bank digital currency for customers. The FAQs leave little room for doubt: digital payment platforms, mobile wallet operators and e-money issuers that hold such products for customers are reporting financial institutions, unless they qualify as non-reporting, and must report in Form 166. A prepaid payment instrument is not automatically in scope, each product has to be tested against the five conditions in Rule 238(10), but the note expects RBI-regulated PPIs redeemable at par to generally meet the decisive one. Many of these entities have strong KYC processes built for RBI purposes and no history of collecting tax residence at all. Crypto-asset service providers have a parallel obligation under CARF, reported in Form 167, with a rule to avoid reporting the same gross proceeds twice.

The second is the reporting fields. The note incorporates the new mandatory fields that come with the amended CRS, including additional account and controlling-person information, with a transitional window for certain controlling-person and equity-interest-holder roles up to 31 December 2027. More fields means more places for a self-certification to be incomplete.

The third is the self-certification standard itself. The note requires the self-certification to be tested for reasonableness against the information obtained at account opening and through AML/KYC

procedures. Where it is unreliable or inconsistent with what the institution knows, a valid self-certification or documentary evidence has to be obtained before the institution relies on it. The note also covers correction of information previously furnished that turns out to be inaccurate, which is the expensive end of the same problem.

The note also allows institutions to use third-party service providers for due diligence and reporting, while keeping the responsibility with the institution. That is worth keeping in mind when an outside tool or agency does part of the checking.

What can be checked at account opening

Most jurisdictions publish the structure of their TINs, and many include a check digit. The OECD collects this information jurisdiction by jurisdiction. A number that does not fit its country’s structure cannot be a valid TIN of that country, whoever wrote it on the form. It can be sent back to the customer while they are still at the counter or on the onboarding screen, which is the cheapest moment to correct it.

Such a check has a limit, and it should be stated clearly. It tells you the number can be a TIN of the declared country. It does not tell you the foreign tax authority issued it, or issued it to this customer. That remains a matter for the reasonableness test against the KYC documents. A format check is not proof of identity and should not be treated as one. What it does is remove the class of error that should never reach Form 166: numbers that cannot exist.

It also helps with a question the reasonableness test raises in practice. If a customer declares residence in the UK and gives a number that matches the Canadian SIN format and not any UK format, the inconsistency is itself a reason to go back to the customer, whatever the explanation turns out to be.

A practical sequence

For institutions updating their processes around the revised note, the steps at account opening are modest compared to the rest of the reporting cycle.

Validate each foreign TIN against the structure of the declared jurisdiction when it is captured, and record that the check was made and with what result. Where no TIN is given, check that one of the note’s exceptions actually applies, either the country does not issue TINs or its domestic law does not require them to be collected, and record which one, instead of accepting a placeholder number. Route failures back to the customer before the account is activated, rather than to the reporting team eleven months later. And for the new e-money and wallet entities, build tax residence collection into onboarding now, since the obligation already applies to 2026 accounts.

None of this makes a self-certification reasonable by itself. It makes the reasonableness test start from data that is at least possible, which is a better place than most Form 61B files started from.

Open Automation’s OpenTIN API checks the structure of individual and entity tax identification numbers for 107 jurisdictions that issue them, and is available on AWS Marketplace and Azure Marketplace. Learn more at open-automation.io/opentin-api.

Advertisement

Join TaxGuru's Network for the latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Reply

Your email address will not be published. Required fields are marked *