File and grade RISK-F-0012: e-invoice receipt and retention
Moves the unowned RISK-POL-0012 receiving duty onto the findings track: medium (I2 x L3), public, no escalation. The founder assigned qonto-assistant as fix owner; workplan requested with suggested measures, default 2026-10-06. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
parent
5a7e4ac2d4
commit
228116926b
4 changed files with 144 additions and 2 deletions
|
|
@ -2,14 +2,15 @@
|
||||||
|
|
||||||
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22.
|
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22.
|
||||||
|
|
||||||
2 live of 11 findings; 3 notes below the floor.
|
3 live of 12 findings; 3 notes below the floor.
|
||||||
|
|
||||||
## Findings
|
## Findings
|
||||||
|
|
||||||
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|
||||||
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
||||||
|
| [RISK-F-0012](findings/RISK-F-0012-e-invoice-receipt-and-retention.md) | The estate cannot show it receives and retains EN 16931 e-invoices | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** |
|
||||||
| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** |
|
| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** |
|
||||||
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z |
|
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | **due** |
|
||||||
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** |
|
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** |
|
||||||
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z |
|
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z |
|
||||||
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** |
|
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** |
|
||||||
|
|
@ -35,6 +36,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
|
||||||
|
|
||||||
| Finding | Who | What would change | Default if silent | On |
|
| Finding | Who | What would change | Default if silent | On |
|
||||||
| --- | --- | --- | --- | --- |
|
| --- | --- | --- | --- | --- |
|
||||||
|
| RISK-F-0012 | qonto-assistant | fix_tracking is set and the finding is tracked on the owner's own workplan state | the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed | 2026-10-06 |
|
||||||
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
|
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
|
||||||
|
|
||||||
## Notes (below the floor)
|
## Notes (below the floor)
|
||||||
|
|
|
||||||
1
STATE.md
1
STATE.md
|
|
@ -54,6 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub.
|
||||||
| ID | Sev | Status | Disclosure | Cadence | System |
|
| ID | Sev | Status | Disclosure | Cadence | System |
|
||||||
| --- | --- | --- | --- | --- | --- |
|
| --- | --- | --- | --- | --- | --- |
|
||||||
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
|
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
|
||||||
|
| `RISK-F-0012` | medium | open | public (handover after workplan) | instant | qonto-assistant |
|
||||||
| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform |
|
| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform |
|
||||||
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
|
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
|
||||||
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core |
|
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core |
|
||||||
|
|
|
||||||
|
|
@ -69,3 +69,9 @@ not been re-read against the current text. Confirm it before planning to it.
|
||||||
## Reviews
|
## Reviews
|
||||||
|
|
||||||
- **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.
|
- **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.
|
||||||
|
|
||||||
|
**2026-09-22 — filed as a finding.** The unowned receiving duty is now
|
||||||
|
`RISK-F-0012` (medium). The founder assigned `qonto-assistant` as owner:
|
||||||
|
Qonto provides the e-invoice capability, and qonto-assistant is the estate's
|
||||||
|
bridge to it. The measures and the re-grade follow that finding. This record
|
||||||
|
keeps the duty itself.
|
||||||
|
|
|
||||||
133
findings/RISK-F-0012-e-invoice-receipt-and-retention.md
Normal file
133
findings/RISK-F-0012-e-invoice-receipt-and-retention.md
Normal file
|
|
@ -0,0 +1,133 @@
|
||||||
|
---
|
||||||
|
id: RISK-F-0012
|
||||||
|
type: finding
|
||||||
|
title: "The estate cannot show it receives and retains EN 16931 e-invoices"
|
||||||
|
status: open
|
||||||
|
owner: risk-nexus
|
||||||
|
reported_by: risk-nexus
|
||||||
|
reported_via: risk-nexus
|
||||||
|
routed_by: risk-nexus
|
||||||
|
date_reported: "2026-09-22"
|
||||||
|
date_filed: "2026-09-22"
|
||||||
|
source_policy: RISK-POL-0012
|
||||||
|
system: qonto-assistant
|
||||||
|
environment: production
|
||||||
|
fix_owner: qonto-assistant
|
||||||
|
fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it"
|
||||||
|
fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22"
|
||||||
|
closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive"
|
||||||
|
severity: medium
|
||||||
|
severity_at_production: medium
|
||||||
|
impact: I2
|
||||||
|
likelihood: L3
|
||||||
|
fidelity_modifier: false
|
||||||
|
production_rescore: false
|
||||||
|
disclosure: public
|
||||||
|
escalation: none
|
||||||
|
last_checked: "2026-09-22T08:00:00Z"
|
||||||
|
next_check: "2026-09-22T08:00:00Z"
|
||||||
|
cadence: instant
|
||||||
|
clean_streak: 0
|
||||||
|
waiting_on:
|
||||||
|
- who: qonto-assistant
|
||||||
|
what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read"
|
||||||
|
since: "2026-09-22"
|
||||||
|
would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state"
|
||||||
|
default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed"
|
||||||
|
default_at: "2026-10-06"
|
||||||
|
graded_by: risk-nexus
|
||||||
|
ruling: RISK-RULING-2026-09-22-B
|
||||||
|
checked_by: "claude-code/risk-nexus"
|
||||||
|
---
|
||||||
|
|
||||||
|
# RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices
|
||||||
|
|
||||||
|
## What is true
|
||||||
|
|
||||||
|
Since 2025-01-01 a German business must be able to receive a structured
|
||||||
|
electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received
|
||||||
|
invoice is an accounting voucher: it must be kept for eight years in the form in
|
||||||
|
which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an
|
||||||
|
XRechnung is not the invoice.
|
||||||
|
|
||||||
|
The policy record has said since 2026-08-20 that this duty is live and has no
|
||||||
|
named owner in the estate. The 2026-09-22 review found that still true. A duty
|
||||||
|
reviewed on a cadence with no owner and no grade can stay open indefinitely, so
|
||||||
|
this finding moves it onto the findings track.
|
||||||
|
|
||||||
|
Not established, in either direction:
|
||||||
|
|
||||||
|
- whether the Qonto account already accepts structured invoices, and in which
|
||||||
|
formats;
|
||||||
|
- whether any structured invoice has already been received, and what happened
|
||||||
|
to its XML;
|
||||||
|
- whether qonto-assistant can retrieve the structured original through the Qonto
|
||||||
|
API rather than only a rendering;
|
||||||
|
- where the original is kept, by whom, and for how long. Qonto's own document
|
||||||
|
retention is a provider's commitment, not estate custody, until someone
|
||||||
|
decides to rely on it and records that decision.
|
||||||
|
|
||||||
|
## How it was found
|
||||||
|
|
||||||
|
A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No
|
||||||
|
system was probed and no Qonto data was read.
|
||||||
|
|
||||||
|
## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B)
|
||||||
|
|
||||||
|
`medium` (`I2` × `L3`), public, no escalation.
|
||||||
|
|
||||||
|
**`I2`: one system's records, recoverable.** If a structured invoice is lost or
|
||||||
|
kept only as a rendering, one class of voucher fails its retention duty. That
|
||||||
|
exposes the business to a tax-audit objection and to a challenge to the input-VAT
|
||||||
|
deduction on that invoice. It is confined to the bookkeeping records and can
|
||||||
|
usually be recovered by asking the supplier to re-issue. No data crosses a
|
||||||
|
boundary and no recovery is removed for a system, so this is not `I3`.
|
||||||
|
|
||||||
|
**`L3`: expected in the normal course.** Suppliers are now entitled to send
|
||||||
|
structured invoices and increasingly do. Nothing in the estate has to go wrong
|
||||||
|
for this to happen: an ordinary supplier invoice arriving is enough. It is not
|
||||||
|
graded `L4` because receipt of a structured invoice is not on record.
|
||||||
|
|
||||||
|
**Public.** Describing a compliance gap in invoice handling does not shorten any
|
||||||
|
attack path. Publication handover is not requested until the finding has an
|
||||||
|
owner workplan, so that the published page can say what is being done.
|
||||||
|
|
||||||
|
**No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4
|
||||||
|
(unowned) is answered before it fires. Everything else is below the triggers.
|
||||||
|
|
||||||
|
**Issuing is not graded here.** The duty to *issue* e-invoices phases in on
|
||||||
|
2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates
|
||||||
|
are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a
|
||||||
|
separate one, once qonto-assistant says whether Qonto also covers issuing.
|
||||||
|
|
||||||
|
## Suggested measures
|
||||||
|
|
||||||
|
These are suggestions. `qonto-assistant` owns the measures and their order.
|
||||||
|
|
||||||
|
1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving
|
||||||
|
is active for the account, which formats it accepts (XRechnung UBL/CII,
|
||||||
|
ZUGFeRD/Factur-X), and whether the API returns the structured original.
|
||||||
|
2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its
|
||||||
|
embedded XML) unaltered, record its hash, and archive it under estate control.
|
||||||
|
Alternatively, record an explicit decision to rely on Qonto's retention, with
|
||||||
|
its term and what happens if the account closes.
|
||||||
|
3. **Retention and expiry.** Keep it eight years from the end of the calendar
|
||||||
|
year of receipt, retrievable and not rewritable, with deliberate deletion at
|
||||||
|
expiry (`RISK-POL-0009`, `RISK-POL-0002`).
|
||||||
|
4. **Demonstrate.** Receive one real structured invoice end to end and retrieve
|
||||||
|
it from the archive. This is the closure condition.
|
||||||
|
5. **Say what already happened.** If structured invoices have already arrived,
|
||||||
|
say where their originals are now.
|
||||||
|
|
||||||
|
## Re-evaluation
|
||||||
|
|
||||||
|
The register re-grades this finding when:
|
||||||
|
|
||||||
|
- the workplan exists (tracking only, grade unchanged);
|
||||||
|
- measure 1 answers whether invoices have already been received. Receipt with
|
||||||
|
the original lost would make the likelihood `L4` and the grade `high`;
|
||||||
|
- the closure condition is met, and the finding becomes fixed.
|
||||||
|
|
||||||
|
## Reviews
|
||||||
|
|
||||||
|
- **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.
|
||||||
Loading…
Add table
Add a link
Reference in a new issue