File and grade RISK-F-0012: e-invoice receipt and retention

Moves the unowned RISK-POL-0012 receiving duty onto the findings track:
medium (I2 x L3), public, no escalation. The founder assigned qonto-assistant
as fix owner; workplan requested with suggested measures, default 2026-10-06.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 10:06:58 +02:00
parent 5a7e4ac2d4
commit 228116926b
4 changed files with 144 additions and 2 deletions

View file

@ -2,14 +2,15 @@
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22. Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22.
2 live of 11 findings; 3 notes below the floor. 3 live of 12 findings; 3 notes below the floor.
## Findings ## Findings
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check | | ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| [RISK-F-0012](findings/RISK-F-0012-e-invoice-receipt-and-retention.md) | The estate cannot show it receives and retains EN 16931 e-invoices | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** |
| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** | | [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | **pending** (t5, sent) | qonto-assistant | open | instant (0) | **due** |
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z | | [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | **due** |
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** | | [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** |
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z | | [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 8h (2) | 2026-09-22 14:13Z |
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** | | [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** |
@ -35,6 +36,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
| Finding | Who | What would change | Default if silent | On | | Finding | Who | What would change | Default if silent | On |
| --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- |
| RISK-F-0012 | qonto-assistant | fix_tracking is set and the finding is tracked on the owner's own workplan state | the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed | 2026-10-06 |
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
## Notes (below the floor) ## Notes (below the floor)

View file

@ -54,6 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub.
| ID | Sev | Status | Disclosure | Cadence | System | | ID | Sev | Status | Disclosure | Cadence | System |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant | | `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
| `RISK-F-0012` | medium | open | public (handover after workplan) | instant | qonto-assistant |
| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform | | `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform |
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform | | `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core | | `RISK-F-0008` | medium | accepted | public | 1h | audit-core |

View file

@ -69,3 +69,9 @@ not been re-read against the current text. Confirm it before planning to it.
## Reviews ## Reviews
- **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z. - **2026-09-22** — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.
**2026-09-22 — filed as a finding.** The unowned receiving duty is now
`RISK-F-0012` (medium). The founder assigned `qonto-assistant` as owner:
Qonto provides the e-invoice capability, and qonto-assistant is the estate's
bridge to it. The measures and the re-grade follow that finding. This record
keeps the duty itself.

View file

@ -0,0 +1,133 @@
---
id: RISK-F-0012
type: finding
title: "The estate cannot show it receives and retains EN 16931 e-invoices"
status: open
owner: risk-nexus
reported_by: risk-nexus
reported_via: risk-nexus
routed_by: risk-nexus
date_reported: "2026-09-22"
date_filed: "2026-09-22"
source_policy: RISK-POL-0012
system: qonto-assistant
environment: production
fix_owner: qonto-assistant
fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it"
fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22"
closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive"
severity: medium
severity_at_production: medium
impact: I2
likelihood: L3
fidelity_modifier: false
production_rescore: false
disclosure: public
escalation: none
last_checked: "2026-09-22T08:00:00Z"
next_check: "2026-09-22T08:00:00Z"
cadence: instant
clean_streak: 0
waiting_on:
- who: qonto-assistant
what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read"
since: "2026-09-22"
would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state"
default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed"
default_at: "2026-10-06"
graded_by: risk-nexus
ruling: RISK-RULING-2026-09-22-B
checked_by: "claude-code/risk-nexus"
---
# RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices
## What is true
Since 2025-01-01 a German business must be able to receive a structured
electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received
invoice is an accounting voucher: it must be kept for eight years in the form in
which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an
XRechnung is not the invoice.
The policy record has said since 2026-08-20 that this duty is live and has no
named owner in the estate. The 2026-09-22 review found that still true. A duty
reviewed on a cadence with no owner and no grade can stay open indefinitely, so
this finding moves it onto the findings track.
Not established, in either direction:
- whether the Qonto account already accepts structured invoices, and in which
formats;
- whether any structured invoice has already been received, and what happened
to its XML;
- whether qonto-assistant can retrieve the structured original through the Qonto
API rather than only a rendering;
- where the original is kept, by whom, and for how long. Qonto's own document
retention is a provider's commitment, not estate custody, until someone
decides to rely on it and records that decision.
## How it was found
A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No
system was probed and no Qonto data was read.
## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B)
`medium` (`I2` × `L3`), public, no escalation.
**`I2`: one system's records, recoverable.** If a structured invoice is lost or
kept only as a rendering, one class of voucher fails its retention duty. That
exposes the business to a tax-audit objection and to a challenge to the input-VAT
deduction on that invoice. It is confined to the bookkeeping records and can
usually be recovered by asking the supplier to re-issue. No data crosses a
boundary and no recovery is removed for a system, so this is not `I3`.
**`L3`: expected in the normal course.** Suppliers are now entitled to send
structured invoices and increasingly do. Nothing in the estate has to go wrong
for this to happen: an ordinary supplier invoice arriving is enough. It is not
graded `L4` because receipt of a structured invoice is not on record.
**Public.** Describing a compliance gap in invoice handling does not shorten any
attack path. Publication handover is not requested until the finding has an
owner workplan, so that the published page can say what is being done.
**No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4
(unowned) is answered before it fires. Everything else is below the triggers.
**Issuing is not graded here.** The duty to *issue* e-invoices phases in on
2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates
are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a
separate one, once qonto-assistant says whether Qonto also covers issuing.
## Suggested measures
These are suggestions. `qonto-assistant` owns the measures and their order.
1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving
is active for the account, which formats it accepts (XRechnung UBL/CII,
ZUGFeRD/Factur-X), and whether the API returns the structured original.
2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its
embedded XML) unaltered, record its hash, and archive it under estate control.
Alternatively, record an explicit decision to rely on Qonto's retention, with
its term and what happens if the account closes.
3. **Retention and expiry.** Keep it eight years from the end of the calendar
year of receipt, retrievable and not rewritable, with deliberate deletion at
expiry (`RISK-POL-0009`, `RISK-POL-0002`).
4. **Demonstrate.** Receive one real structured invoice end to end and retrieve
it from the archive. This is the closure condition.
5. **Say what already happened.** If structured invoices have already arrived,
say where their originals are now.
## Re-evaluation
The register re-grades this finding when:
- the workplan exists (tracking only, grade unchanged);
- measure 1 answers whether invoices have already been received. Receipt with
the original lost would make the likelihood `L4` and the grade `high`;
- the closure condition is met, and the finding becomes fixed.
## Reviews
- **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.