134 lines
6.1 KiB
Markdown
134 lines
6.1 KiB
Markdown
|
|
---
|
|||
|
|
id: RISK-F-0012
|
|||
|
|
type: finding
|
|||
|
|
title: "The estate cannot show it receives and retains EN 16931 e-invoices"
|
|||
|
|
status: open
|
|||
|
|
owner: risk-nexus
|
|||
|
|
reported_by: risk-nexus
|
|||
|
|
reported_via: risk-nexus
|
|||
|
|
routed_by: risk-nexus
|
|||
|
|
date_reported: "2026-09-22"
|
|||
|
|
date_filed: "2026-09-22"
|
|||
|
|
source_policy: RISK-POL-0012
|
|||
|
|
system: qonto-assistant
|
|||
|
|
environment: production
|
|||
|
|
fix_owner: qonto-assistant
|
|||
|
|
fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it"
|
|||
|
|
fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22"
|
|||
|
|
closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive"
|
|||
|
|
severity: medium
|
|||
|
|
severity_at_production: medium
|
|||
|
|
impact: I2
|
|||
|
|
likelihood: L3
|
|||
|
|
fidelity_modifier: false
|
|||
|
|
production_rescore: false
|
|||
|
|
disclosure: public
|
|||
|
|
escalation: none
|
|||
|
|
last_checked: "2026-09-22T08:00:00Z"
|
|||
|
|
next_check: "2026-09-22T08:00:00Z"
|
|||
|
|
cadence: instant
|
|||
|
|
clean_streak: 0
|
|||
|
|
waiting_on:
|
|||
|
|
- who: qonto-assistant
|
|||
|
|
what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read"
|
|||
|
|
since: "2026-09-22"
|
|||
|
|
would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state"
|
|||
|
|
default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed"
|
|||
|
|
default_at: "2026-10-06"
|
|||
|
|
graded_by: risk-nexus
|
|||
|
|
ruling: RISK-RULING-2026-09-22-B
|
|||
|
|
checked_by: "claude-code/risk-nexus"
|
|||
|
|
---
|
|||
|
|
|
|||
|
|
# RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices
|
|||
|
|
|
|||
|
|
## What is true
|
|||
|
|
|
|||
|
|
Since 2025-01-01 a German business must be able to receive a structured
|
|||
|
|
electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received
|
|||
|
|
invoice is an accounting voucher: it must be kept for eight years in the form in
|
|||
|
|
which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an
|
|||
|
|
XRechnung is not the invoice.
|
|||
|
|
|
|||
|
|
The policy record has said since 2026-08-20 that this duty is live and has no
|
|||
|
|
named owner in the estate. The 2026-09-22 review found that still true. A duty
|
|||
|
|
reviewed on a cadence with no owner and no grade can stay open indefinitely, so
|
|||
|
|
this finding moves it onto the findings track.
|
|||
|
|
|
|||
|
|
Not established, in either direction:
|
|||
|
|
|
|||
|
|
- whether the Qonto account already accepts structured invoices, and in which
|
|||
|
|
formats;
|
|||
|
|
- whether any structured invoice has already been received, and what happened
|
|||
|
|
to its XML;
|
|||
|
|
- whether qonto-assistant can retrieve the structured original through the Qonto
|
|||
|
|
API rather than only a rendering;
|
|||
|
|
- where the original is kept, by whom, and for how long. Qonto's own document
|
|||
|
|
retention is a provider's commitment, not estate custody, until someone
|
|||
|
|
decides to rely on it and records that decision.
|
|||
|
|
|
|||
|
|
## How it was found
|
|||
|
|
|
|||
|
|
A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No
|
|||
|
|
system was probed and no Qonto data was read.
|
|||
|
|
|
|||
|
|
## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B)
|
|||
|
|
|
|||
|
|
`medium` (`I2` × `L3`), public, no escalation.
|
|||
|
|
|
|||
|
|
**`I2`: one system's records, recoverable.** If a structured invoice is lost or
|
|||
|
|
kept only as a rendering, one class of voucher fails its retention duty. That
|
|||
|
|
exposes the business to a tax-audit objection and to a challenge to the input-VAT
|
|||
|
|
deduction on that invoice. It is confined to the bookkeeping records and can
|
|||
|
|
usually be recovered by asking the supplier to re-issue. No data crosses a
|
|||
|
|
boundary and no recovery is removed for a system, so this is not `I3`.
|
|||
|
|
|
|||
|
|
**`L3`: expected in the normal course.** Suppliers are now entitled to send
|
|||
|
|
structured invoices and increasingly do. Nothing in the estate has to go wrong
|
|||
|
|
for this to happen: an ordinary supplier invoice arriving is enough. It is not
|
|||
|
|
graded `L4` because receipt of a structured invoice is not on record.
|
|||
|
|
|
|||
|
|
**Public.** Describing a compliance gap in invoice handling does not shorten any
|
|||
|
|
attack path. Publication handover is not requested until the finding has an
|
|||
|
|
owner workplan, so that the published page can say what is being done.
|
|||
|
|
|
|||
|
|
**No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4
|
|||
|
|
(unowned) is answered before it fires. Everything else is below the triggers.
|
|||
|
|
|
|||
|
|
**Issuing is not graded here.** The duty to *issue* e-invoices phases in on
|
|||
|
|
2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates
|
|||
|
|
are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a
|
|||
|
|
separate one, once qonto-assistant says whether Qonto also covers issuing.
|
|||
|
|
|
|||
|
|
## Suggested measures
|
|||
|
|
|
|||
|
|
These are suggestions. `qonto-assistant` owns the measures and their order.
|
|||
|
|
|
|||
|
|
1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving
|
|||
|
|
is active for the account, which formats it accepts (XRechnung UBL/CII,
|
|||
|
|
ZUGFeRD/Factur-X), and whether the API returns the structured original.
|
|||
|
|
2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its
|
|||
|
|
embedded XML) unaltered, record its hash, and archive it under estate control.
|
|||
|
|
Alternatively, record an explicit decision to rely on Qonto's retention, with
|
|||
|
|
its term and what happens if the account closes.
|
|||
|
|
3. **Retention and expiry.** Keep it eight years from the end of the calendar
|
|||
|
|
year of receipt, retrievable and not rewritable, with deliberate deletion at
|
|||
|
|
expiry (`RISK-POL-0009`, `RISK-POL-0002`).
|
|||
|
|
4. **Demonstrate.** Receive one real structured invoice end to end and retrieve
|
|||
|
|
it from the archive. This is the closure condition.
|
|||
|
|
5. **Say what already happened.** If structured invoices have already arrived,
|
|||
|
|
say where their originals are now.
|
|||
|
|
|
|||
|
|
## Re-evaluation
|
|||
|
|
|
|||
|
|
The register re-grades this finding when:
|
|||
|
|
|
|||
|
|
- the workplan exists (tracking only, grade unchanged);
|
|||
|
|
- measure 1 answers whether invoices have already been received. Receipt with
|
|||
|
|
the original lost would make the likelihood `L4` and the grade `high`;
|
|||
|
|
- the closure condition is met, and the finding becomes fixed.
|
|||
|
|
|
|||
|
|
## Reviews
|
|||
|
|
|
|||
|
|
- **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.
|