diff --git a/REGISTER.md b/REGISTER.md index 4fca084..9492db7 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -2,14 +2,15 @@ Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22. -2 live of 11 findings; 3 notes below the floor. +3 live of 12 findings; 3 notes below the floor. ## Findings | ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | +| [RISK-F-0012](findings/RISK-F-0012-e-invoice-receipt-and-retention.md) | The estate cannot show it receives and retains EN 16931 e-invoices | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** | | [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** | -| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z | +| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | **due** | | [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** | | [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z | | [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** | @@ -35,6 +36,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | Finding | Who | What would change | Default if silent | On | | --- | --- | --- | --- | --- | +| RISK-F-0012 | qonto-assistant | fix_tracking is set and the finding is tracked on the owner's own workplan state | the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed | 2026-10-06 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | ## Notes (below the floor) diff --git a/STATE.md b/STATE.md index ed4f021..ae8b543 100644 --- a/STATE.md +++ b/STATE.md @@ -54,6 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub. | ID | Sev | Status | Disclosure | Cadence | System | | --- | --- | --- | --- | --- | --- | | `RISK-F-0011` | medium | open | public | instant | qonto-assistant | +| `RISK-F-0012` | medium | open | public (handover after workplan) | instant | qonto-assistant | | `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform | | `RISK-F-0009` | high | fixed | public | instant | railiance-platform | | `RISK-F-0008` | medium | accepted | public | 1h | audit-core | diff --git a/docs/regulatory/policies/RISK-POL-0012-e-invoicing.md b/docs/regulatory/policies/RISK-POL-0012-e-invoicing.md index 039d92d..6f94178 100644 --- a/docs/regulatory/policies/RISK-POL-0012-e-invoicing.md +++ b/docs/regulatory/policies/RISK-POL-0012-e-invoicing.md @@ -69,3 +69,9 @@ not been re-read against the current text. Confirm it before planning to it. ## Reviews - **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z. + +**2026-09-22 — filed as a finding.** The unowned receiving duty is now +`RISK-F-0012` (medium). The founder assigned `qonto-assistant` as owner: +Qonto provides the e-invoice capability, and qonto-assistant is the estate's +bridge to it. The measures and the re-grade follow that finding. This record +keeps the duty itself. diff --git a/findings/RISK-F-0012-e-invoice-receipt-and-retention.md b/findings/RISK-F-0012-e-invoice-receipt-and-retention.md new file mode 100644 index 0000000..3a1f8d7 --- /dev/null +++ b/findings/RISK-F-0012-e-invoice-receipt-and-retention.md @@ -0,0 +1,133 @@ +--- +id: RISK-F-0012 +type: finding +title: "The estate cannot show it receives and retains EN 16931 e-invoices" +status: open +owner: risk-nexus +reported_by: risk-nexus +reported_via: risk-nexus +routed_by: risk-nexus +date_reported: "2026-09-22" +date_filed: "2026-09-22" +source_policy: RISK-POL-0012 +system: qonto-assistant +environment: production +fix_owner: qonto-assistant +fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it" +fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22" +closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive" +severity: medium +severity_at_production: medium +impact: I2 +likelihood: L3 +fidelity_modifier: false +production_rescore: false +disclosure: public +escalation: none +last_checked: "2026-09-22T08:00:00Z" +next_check: "2026-09-22T08:00:00Z" +cadence: instant +clean_streak: 0 +waiting_on: + - who: qonto-assistant + what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read" + since: "2026-09-22" + would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state" + default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed" + default_at: "2026-10-06" +graded_by: risk-nexus +ruling: RISK-RULING-2026-09-22-B +checked_by: "claude-code/risk-nexus" +--- + +# RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices + +## What is true + +Since 2025-01-01 a German business must be able to receive a structured +electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received +invoice is an accounting voucher: it must be kept for eight years in the form in +which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an +XRechnung is not the invoice. + +The policy record has said since 2026-08-20 that this duty is live and has no +named owner in the estate. The 2026-09-22 review found that still true. A duty +reviewed on a cadence with no owner and no grade can stay open indefinitely, so +this finding moves it onto the findings track. + +Not established, in either direction: + +- whether the Qonto account already accepts structured invoices, and in which + formats; +- whether any structured invoice has already been received, and what happened + to its XML; +- whether qonto-assistant can retrieve the structured original through the Qonto + API rather than only a rendering; +- where the original is kept, by whom, and for how long. Qonto's own document + retention is a provider's commitment, not estate custody, until someone + decides to rely on it and records that decision. + +## How it was found + +A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No +system was probed and no Qonto data was read. + +## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B) + +`medium` (`I2` × `L3`), public, no escalation. + +**`I2`: one system's records, recoverable.** If a structured invoice is lost or +kept only as a rendering, one class of voucher fails its retention duty. That +exposes the business to a tax-audit objection and to a challenge to the input-VAT +deduction on that invoice. It is confined to the bookkeeping records and can +usually be recovered by asking the supplier to re-issue. No data crosses a +boundary and no recovery is removed for a system, so this is not `I3`. + +**`L3`: expected in the normal course.** Suppliers are now entitled to send +structured invoices and increasingly do. Nothing in the estate has to go wrong +for this to happen: an ordinary supplier invoice arriving is enough. It is not +graded `L4` because receipt of a structured invoice is not on record. + +**Public.** Describing a compliance gap in invoice handling does not shorten any +attack path. Publication handover is not requested until the finding has an +owner workplan, so that the published page can say what is being done. + +**No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4 +(unowned) is answered before it fires. Everything else is below the triggers. + +**Issuing is not graded here.** The duty to *issue* e-invoices phases in on +2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates +are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a +separate one, once qonto-assistant says whether Qonto also covers issuing. + +## Suggested measures + +These are suggestions. `qonto-assistant` owns the measures and their order. + +1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving + is active for the account, which formats it accepts (XRechnung UBL/CII, + ZUGFeRD/Factur-X), and whether the API returns the structured original. +2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its + embedded XML) unaltered, record its hash, and archive it under estate control. + Alternatively, record an explicit decision to rely on Qonto's retention, with + its term and what happens if the account closes. +3. **Retention and expiry.** Keep it eight years from the end of the calendar + year of receipt, retrievable and not rewritable, with deliberate deletion at + expiry (`RISK-POL-0009`, `RISK-POL-0002`). +4. **Demonstrate.** Receive one real structured invoice end to end and retrieve + it from the archive. This is the closure condition. +5. **Say what already happened.** If structured invoices have already arrived, + say where their originals are now. + +## Re-evaluation + +The register re-grades this finding when: + +- the workplan exists (tracking only, grade unchanged); +- measure 1 answers whether invoices have already been received. Receipt with + the original lost would make the likelihood `L4` and the grade `high`; +- the closure condition is met, and the finding becomes fixed. + +## Reviews + +- **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.