File and grade RISK-F-0012: e-invoice receipt and retention
Moves the unowned RISK-POL-0012 receiving duty onto the findings track: medium (I2 x L3), public, no escalation. The founder assigned qonto-assistant as fix owner; workplan requested with suggested measures, default 2026-10-06. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
parent
5a7e4ac2d4
commit
228116926b
4 changed files with 144 additions and 2 deletions
|
|
@ -2,14 +2,15 @@
|
|||
|
||||
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22.
|
||||
|
||||
2 live of 11 findings; 3 notes below the floor.
|
||||
3 live of 12 findings; 3 notes below the floor.
|
||||
|
||||
## Findings
|
||||
|
||||
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|
||||
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
||||
| [RISK-F-0012](findings/RISK-F-0012-e-invoice-receipt-and-retention.md) | The estate cannot show it receives and retains EN 16931 e-invoices | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** |
|
||||
| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** |
|
||||
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z |
|
||||
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | **due** |
|
||||
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** |
|
||||
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z |
|
||||
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** |
|
||||
|
|
@ -35,6 +36,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
|
|||
|
||||
| Finding | Who | What would change | Default if silent | On |
|
||||
| --- | --- | --- | --- | --- |
|
||||
| RISK-F-0012 | qonto-assistant | fix_tracking is set and the finding is tracked on the owner's own workplan state | the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed | 2026-10-06 |
|
||||
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
|
||||
|
||||
## Notes (below the floor)
|
||||
|
|
|
|||
1
STATE.md
1
STATE.md
|
|
@ -54,6 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub.
|
|||
| ID | Sev | Status | Disclosure | Cadence | System |
|
||||
| --- | --- | --- | --- | --- | --- |
|
||||
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
|
||||
| `RISK-F-0012` | medium | open | public (handover after workplan) | instant | qonto-assistant |
|
||||
| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform |
|
||||
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
|
||||
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core |
|
||||
|
|
|
|||
|
|
@ -69,3 +69,9 @@ not been re-read against the current text. Confirm it before planning to it.
|
|||
## Reviews
|
||||
|
||||
- **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.
|
||||
|
||||
**2026-09-22 — filed as a finding.** The unowned receiving duty is now
|
||||
`RISK-F-0012` (medium). The founder assigned `qonto-assistant` as owner:
|
||||
Qonto provides the e-invoice capability, and qonto-assistant is the estate's
|
||||
bridge to it. The measures and the re-grade follow that finding. This record
|
||||
keeps the duty itself.
|
||||
|
|
|
|||
133
findings/RISK-F-0012-e-invoice-receipt-and-retention.md
Normal file
133
findings/RISK-F-0012-e-invoice-receipt-and-retention.md
Normal file
|
|
@ -0,0 +1,133 @@
|
|||
---
|
||||
id: RISK-F-0012
|
||||
type: finding
|
||||
title: "The estate cannot show it receives and retains EN 16931 e-invoices"
|
||||
status: open
|
||||
owner: risk-nexus
|
||||
reported_by: risk-nexus
|
||||
reported_via: risk-nexus
|
||||
routed_by: risk-nexus
|
||||
date_reported: "2026-09-22"
|
||||
date_filed: "2026-09-22"
|
||||
source_policy: RISK-POL-0012
|
||||
system: qonto-assistant
|
||||
environment: production
|
||||
fix_owner: qonto-assistant
|
||||
fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it"
|
||||
fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22"
|
||||
closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive"
|
||||
severity: medium
|
||||
severity_at_production: medium
|
||||
impact: I2
|
||||
likelihood: L3
|
||||
fidelity_modifier: false
|
||||
production_rescore: false
|
||||
disclosure: public
|
||||
escalation: none
|
||||
last_checked: "2026-09-22T08:00:00Z"
|
||||
next_check: "2026-09-22T08:00:00Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
- who: qonto-assistant
|
||||
what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read"
|
||||
since: "2026-09-22"
|
||||
would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state"
|
||||
default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed"
|
||||
default_at: "2026-10-06"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-09-22-B
|
||||
checked_by: "claude-code/risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices
|
||||
|
||||
## What is true
|
||||
|
||||
Since 2025-01-01 a German business must be able to receive a structured
|
||||
electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received
|
||||
invoice is an accounting voucher: it must be kept for eight years in the form in
|
||||
which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an
|
||||
XRechnung is not the invoice.
|
||||
|
||||
The policy record has said since 2026-08-20 that this duty is live and has no
|
||||
named owner in the estate. The 2026-09-22 review found that still true. A duty
|
||||
reviewed on a cadence with no owner and no grade can stay open indefinitely, so
|
||||
this finding moves it onto the findings track.
|
||||
|
||||
Not established, in either direction:
|
||||
|
||||
- whether the Qonto account already accepts structured invoices, and in which
|
||||
formats;
|
||||
- whether any structured invoice has already been received, and what happened
|
||||
to its XML;
|
||||
- whether qonto-assistant can retrieve the structured original through the Qonto
|
||||
API rather than only a rendering;
|
||||
- where the original is kept, by whom, and for how long. Qonto's own document
|
||||
retention is a provider's commitment, not estate custody, until someone
|
||||
decides to rely on it and records that decision.
|
||||
|
||||
## How it was found
|
||||
|
||||
A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No
|
||||
system was probed and no Qonto data was read.
|
||||
|
||||
## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B)
|
||||
|
||||
`medium` (`I2` × `L3`), public, no escalation.
|
||||
|
||||
**`I2`: one system's records, recoverable.** If a structured invoice is lost or
|
||||
kept only as a rendering, one class of voucher fails its retention duty. That
|
||||
exposes the business to a tax-audit objection and to a challenge to the input-VAT
|
||||
deduction on that invoice. It is confined to the bookkeeping records and can
|
||||
usually be recovered by asking the supplier to re-issue. No data crosses a
|
||||
boundary and no recovery is removed for a system, so this is not `I3`.
|
||||
|
||||
**`L3`: expected in the normal course.** Suppliers are now entitled to send
|
||||
structured invoices and increasingly do. Nothing in the estate has to go wrong
|
||||
for this to happen: an ordinary supplier invoice arriving is enough. It is not
|
||||
graded `L4` because receipt of a structured invoice is not on record.
|
||||
|
||||
**Public.** Describing a compliance gap in invoice handling does not shorten any
|
||||
attack path. Publication handover is not requested until the finding has an
|
||||
owner workplan, so that the published page can say what is being done.
|
||||
|
||||
**No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4
|
||||
(unowned) is answered before it fires. Everything else is below the triggers.
|
||||
|
||||
**Issuing is not graded here.** The duty to *issue* e-invoices phases in on
|
||||
2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates
|
||||
are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a
|
||||
separate one, once qonto-assistant says whether Qonto also covers issuing.
|
||||
|
||||
## Suggested measures
|
||||
|
||||
These are suggestions. `qonto-assistant` owns the measures and their order.
|
||||
|
||||
1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving
|
||||
is active for the account, which formats it accepts (XRechnung UBL/CII,
|
||||
ZUGFeRD/Factur-X), and whether the API returns the structured original.
|
||||
2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its
|
||||
embedded XML) unaltered, record its hash, and archive it under estate control.
|
||||
Alternatively, record an explicit decision to rely on Qonto's retention, with
|
||||
its term and what happens if the account closes.
|
||||
3. **Retention and expiry.** Keep it eight years from the end of the calendar
|
||||
year of receipt, retrievable and not rewritable, with deliberate deletion at
|
||||
expiry (`RISK-POL-0009`, `RISK-POL-0002`).
|
||||
4. **Demonstrate.** Receive one real structured invoice end to end and retrieve
|
||||
it from the archive. This is the closure condition.
|
||||
5. **Say what already happened.** If structured invoices have already arrived,
|
||||
say where their originals are now.
|
||||
|
||||
## Re-evaluation
|
||||
|
||||
The register re-grades this finding when:
|
||||
|
||||
- the workplan exists (tracking only, grade unchanged);
|
||||
- measure 1 answers whether invoices have already been received. Receipt with
|
||||
the original lost would make the likelihood `L4` and the grade `high`;
|
||||
- the closure condition is met, and the finding becomes fixed.
|
||||
|
||||
## Reviews
|
||||
|
||||
- **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.
|
||||
Loading…
Add table
Add a link
Reference in a new issue