Release notes

TRSuite 26.02.0.2 – Release Notes

Everything that changed in this version of TRSuite.

Release date 17 September 2026DeutschEnglish

TRSuite 26.02.0.2 is a maintenance release for 26.02. It contains corrections and one addition, the validator for Aruba: no new schema versions and no changes to the file formats. Several corrections affect the content of generated reports or the result of a validation. Please read the section "Upgrade Notes" and check the reports you created with 26.02.0.1 where a correction applies to you.

Regulatory Changes

USA – IRS FATCA / IDES

  • The IRS replaces its public encryption key for FATCA filings on 24 September 2026, 9:00 am EDT. The IRS had not yet published the new certificate when 26.02.0.2 was released, so this release still ships with the current one. From that date on, download the new certificate from the IRS IDES support site and enter the file in the field "Path to IRS Public Key" on the IDES tab. This applies to 26.02.0.2 and to every earlier version. The new certificate will be part of release 26.03. TRSUIT-219

Aruba – DIMP (CRS)

  • New validator "Aruba" for the CRS delivery to the Departamento di Impuesto (DIMP) through the MDES portal. Aruba receives the plain OECD CRS XML, currently in schema version 2.0; select CRS version 2.0 in the CRS configuration. The validator presets country AW and currency AWG and generates the MessageRefId and every DocRefId in the form required by DIMP: AW + reporting year + registration number of the delivering financial institution (Sending Company IN). "Validate" checks this prefix, blanks in reference IDs, duplicate DocRefIds within the file, transmitting and receiving country AW, the residence country of the reporting FI and the character sequences --, /* and &#, which MDES rejects. TRSUIT-219

Bug Fixes

Switzerland – FTA (CRS)

  • The Swiss character check reported every amount with decimals, for example 1000.00, as a "CRMT" error, and the sending company IN as well. Amounts and the sending company IN are exempt from that check again. Real violations are still reported, now with the DocRefId of the affected record instead of "N/A". This error was introduced with release 26.02. TRSUIT-219

USA – IRS FATCA (Form 8966)

  • Nil reports wrote an intermediary into the sponsor element. The intermediary is now reported as intermediary. TRSUIT-219
  • Pool reports: the finished DocRefId was passed through the generator a second time and came out malformed (GIIN followed by two UUIDs). From the second pool report onwards, pool DocRefIds could also collide with those of the reporting FI or sponsor. Both are corrected. TRSUIT-219
  • Sponsor: every export generated a new DocRefId for the sponsor, and the CorrDocRefId was never written, so a correction of the sponsor did not refer to the earlier report. The sponsor now behaves like the intermediary: an existing DocRefId is kept and a correction carries the CorrDocRefId. TRSUIT-219
  • The running number of the DocRefId was advanced by the number of reporting FIs instead of the numbers actually used, which could produce duplicate DocRefIds. The numbering now continues from the last number used by the account, pool and nil reports. TRSUIT-219
  • "Split and Save by Reporting FI" and "Export BBDM" ignored a test licence and wrote production document types (FATCA1 instead of FATCA11). Both now honour the licence type. TRSUIT-219

OECD – CRS (generic)

  • Reporting FI form: "Generate DocRefID" always used the IN of the first reporting FI in the list. With several reporting FIs, the DocRefIds of the second and every further FI were built with the wrong IN (formats that include the FI's IN, for example Germany, Austria, Chile, Costa Rica). The IN of the FI being edited is used now. TRSUIT-219
  • Germany (BZSt) and Australia (BBDM) export: errors during writing or signing were not shown, and the dialog always reported success. Errors are now listed; a file that was saved without a signature is reported as "File saved, but not signed". TRSUIT-219
  • Export in CRS version 2.0: the fields introduced with CRS 3.0 (self-certification, due diligence procedure, account type, joint account, equity interest type, more than one controlling person type) were written into the 2.0 file whenever the data carried them, for example after an import from the Excel template 2601 or after loading a 3.0 file. The export then ended with schema errors such as "Invalid content was found starting with element 'crs:SelfCert'". A 2.0 export now leaves these fields out; a 3.0 export is unchanged. Values that exist in schema 3.0 only, for example the account number type OECD606, are not changed by TRSuite and are still reported by the schema check. This error was introduced with release 26.02. TRSUIT-219
  • Excel import with the template "CRS Basic 2601 with DocRefIDs": the Document Reference ID of the reporting FI entered on the General sheet was not imported, and TRSuite generated a new one instead. The account DocRefIds were not affected. The value is imported again, as it was with the 1902 templates. TRSUIT-219

Curaçao

  • "Validate CRS" always answered "No errors found" because no check was executed. The button now runs the checks of the report sections; the nil report takes the GIIN from the configuration instead of ending in an internal error. See "Known Limitations". TRSUIT-219
  • In the installed program, a Curaçao export with an account number type was checked against an outdated copy of the schema and could be rejected although the file was correct. The installation now contains the correct schema. TRSUIT-210

Switzerland – FTA (SEI)

  • "Update FATCA" removed all substantial owners from the FATCA-XML of an information package when no matching SEI person was assigned. Substantial owners are now kept, assigned ones are updated, and unassigned ones are reported. TRSUIT-219
  • When a saved update delivery was loaded, the "update" flag of the delivery was not restored, so the delivery was created as an initial delivery. TRSUIT-219
  • A reporting FI rebuilt by "Update FATCA" takes the document type indicator of the file instead of a fixed production value. TRSUIT-219

Delivery packages and country modules

  • Malaysia, Uruguay and Macau: a successful configuration check overwrote the result of the mandatory field checks, so that a delivery package could be created with empty metadata. All checks now count; Uruguay shows the missing fields instead of doing nothing. TRSUIT-219
  • Malaysia, Macau and IDES: a package was reported as "successful" although moving or copying the result had failed, and a deselected ZIP step placed the result in the failed folder. The result of each file operation is now evaluated and reported. TRSUIT-219
  • IDES: the length rules for the sender metadata were never checked. They are now checked in "Check Configuration" and before a run. A missing certificate is reported clearly, without the misleading additional message "certificate error: null" (IDES and Malaysia). TRSUIT-219
  • Macau: "Add data" from XML or Excel ended in an internal error. TRSUIT-219
  • China, Curaçao, Hong Kong, Macau and SEI: importing a password-protected Excel file failed before the password dialog appeared. TRSUIT-219

General

  • The error viewer of the CARF dashboard showed an internal object description instead of the message text. It now shows the message. TRSUIT-219

Security & Dependencies

  • BouncyCastle upgraded from 1.85 to 1.86. The upgrade resolves CVE-2026-18040 and CVE-2026-71889, which were published after 26.02.0.1. TRSuite does not use the affected functions; the dependency vulnerability scan again reports no HIGH finding. TRSUIT-219
  • Key material next to encrypted archives: during the Swiss CRS export, the IDES transmission and the Malaysia and Macau delivery, TRSuite left files with key material in the output folder, next to the encrypted archive. These files are no longer written, temporary key files are deleted after the last step, and leftovers from earlier runs in the same folder are removed by the next run. See "Upgrade Notes" for the clean-up of existing folders. TRSUIT-219
  • Log files: keys, passwords and API keys are no longer written to the log file, not even at debug level. The log records only metadata such as algorithm and length. TRSUIT-219
  • Bundled configuration samples removed: the program package no longer contains sample configuration files. They were not used by the application. TRSUIT-219
  • Third-party notices: the installation now contains THIRD-PARTY-NOTICES.md with the licence notices of all third-party source code and fonts that are part of TRSuite. The software bill of materials (SBOM, CycloneDX JSON) lists these components as well. The SBOM is published as JSON only. TRSUIT-219
  • Fonts and a command line tool that were shipped but never used have been removed from the program package. TRSUIT-219

Upgrade Notes

  • Check your reports (Switzerland CRS): if 26.02.0.1 reported "CRMT" errors for amounts, validate again with 26.02.0.2. No change to your data is needed.
  • Check your reports (FATCA): if you created nil reports with an intermediary, pool reports, or files with several reporting FIs using an earlier version, compare the sponsor/intermediary element and the DocRefIds before the next submission or correction. A correction must reference the DocRefId that was actually submitted.
  • Check your reports (CRS with several reporting FIs): in files created with an earlier version, verify the DocRefIds of the second and every further reporting FI.
  • Curaçao: validate existing reports again; earlier versions did not report any findings.
  • Clean up output folders: delete files ending in .KEY_HEX, .IV_HEX, .HEX and _PlainKey, and any keys folder next to an upload folder, from the output folders of earlier exports. Remove them from copies of these folders on shared drives and in backups as well.
  • Log files: log files written by earlier versions at debug level may contain key material. Delete them or restrict access to them.
  • Configuration files: the settings of the FATCA, China, Hong Kong, Macau, Curaçao, Malaysia delivery and Uruguay delivery modules are now stored in %USERPROFILE%\AppData\Local\TRSuite\app, like the settings of the other modules. An existing file in the program's working directory is taken over once at the first start. No action is needed.
  • IDES: from 24 September 2026, 9:00 am EDT, only the new IRS certificate is valid. Download it from the IRS IDES support site and enter the file in the field "Path to IRS Public Key" on the IDES tab before your first transmission after that date. If the field already holds a certificate file of your own, replace that file. See "Known Limitations".

Known Limitations

  • Curaçao: "Validate CRS" checks the nil report. The checks for account reports and the reporting FI are not yet active and follow with release 26.03; the schema validation on export is not affected.
  • IDES: the bundled IRS certificate is the one valid until the key change on 24 September 2026. TRSuite does not warn when the bundled certificate has expired; a package encrypted with the old certificate is rejected by IDES. The new certificate and an expiry warning follow with release 26.03.
  • FATCA Form 8966: with a test licence, "Check" still validates against the production document types, while the export correctly writes test document types.
  • The known limitations of 26.02 continue to apply; see the release notes of 26.02.