--- id: RISK-F-0012 type: finding title: "The estate cannot show it receives and retains EN 16931 e-invoices" status: open owner: risk-nexus reported_by: risk-nexus reported_via: risk-nexus routed_by: risk-nexus date_reported: "2026-09-22" date_filed: "2026-09-22" source_policy: RISK-POL-0012 system: qonto-assistant environment: production fix_owner: qonto-assistant fix_owner_assigned_by: "founder, 2026-09-22 — e-invoice capability is provided by Qonto and qonto-assistant is the estate's bridge to it" fix_tracking: "unset — workplan requested from qonto-assistant 2026-09-22" closure_condition: "one real EN 16931 invoice received through the Qonto lane, its structured original (XML or ZUGFeRD PDF/A-3) archived unaltered in estate custody under the RISK-POL-0009 voucher schedule, and retrieved from that archive" severity: medium severity_at_production: medium impact: I2 likelihood: L3 fidelity_modifier: false production_rescore: false disclosure: public escalation: none last_checked: "2026-09-22T08:00:00Z" next_check: "2026-09-22T08:00:00Z" cadence: instant clean_streak: 0 waiting_on: - who: qonto-assistant what: "a workplan that establishes the e-invoice receiving and retention path through Qonto and names the measures below, with fix_tracking this register can read" since: "2026-09-22" would_change: "fix_tracking is set and the finding is tracked on the owner's own workplan state" default: "the medium grade stands; the absence of a workplan is recorded as a stalled remediation and escalation trigger 5 is assessed" default_at: "2026-10-06" graded_by: risk-nexus ruling: RISK-RULING-2026-09-22-B checked_by: "claude-code/risk-nexus" --- # RISK-F-0012 — the estate cannot show it receives and retains EN 16931 e-invoices ## What is true Since 2025-01-01 a German business must be able to receive a structured electronic invoice for domestic B2B transactions (`RISK-POL-0012`). The received invoice is an accounting voucher: it must be kept for eight years in the form in which it was received (`RISK-POL-0009`, §147 AO, §14 UStG). A rendered PDF of an XRechnung is not the invoice. The policy record has said since 2026-08-20 that this duty is live and has no named owner in the estate. The 2026-09-22 review found that still true. A duty reviewed on a cadence with no owner and no grade can stay open indefinitely, so this finding moves it onto the findings track. Not established, in either direction: - whether the Qonto account already accepts structured invoices, and in which formats; - whether any structured invoice has already been received, and what happened to its XML; - whether qonto-assistant can retrieve the structured original through the Qonto API rather than only a rendering; - where the original is kept, by whom, and for how long. Qonto's own document retention is a provider's commitment, not estate custody, until someone decides to rely on it and records that decision. ## How it was found A regulatory review by the register: `RISK-POL-0012`, reviewed 2026-09-22. No system was probed and no Qonto data was read. ## Register ruling — 2026-09-22 (RISK-RULING-2026-09-22-B) `medium` (`I2` × `L3`), public, no escalation. **`I2`: one system's records, recoverable.** If a structured invoice is lost or kept only as a rendering, one class of voucher fails its retention duty. That exposes the business to a tax-audit objection and to a challenge to the input-VAT deduction on that invoice. It is confined to the bookkeeping records and can usually be recovered by asking the supplier to re-issue. No data crosses a boundary and no recovery is removed for a system, so this is not `I3`. **`L3`: expected in the normal course.** Suppliers are now entitled to send structured invoices and increasingly do. Nothing in the estate has to go wrong for this to happen: an ordinary supplier invoice arriving is enough. It is not graded `L4` because receipt of a structured invoice is not on record. **Public.** Describing a compliance gap in invoice handling does not shorten any attack path. Publication handover is not requested until the finding has an owner workplan, so that the published page can say what is being done. **No escalation.** The founder assigned the owner on 2026-09-22, so trigger 4 (unowned) is answered before it fires. Everything else is below the triggers. **Issuing is not graded here.** The duty to *issue* e-invoices phases in on 2027-01-01 (prior-year turnover above EUR 800,000) or 2028-01-01. Those dates are still unconfirmed in `RISK-POL-0012`. It becomes part of this finding, or a separate one, once qonto-assistant says whether Qonto also covers issuing. ## Suggested measures These are suggestions. `qonto-assistant` owns the measures and their order. 1. **Establish the provider lane.** Find out whether Qonto's e-invoice receiving is active for the account, which formats it accepts (XRechnung UBL/CII, ZUGFeRD/Factur-X), and whether the API returns the structured original. 2. **Take the original into custody.** Fetch the XML (or the PDF/A-3 with its embedded XML) unaltered, record its hash, and archive it under estate control. Alternatively, record an explicit decision to rely on Qonto's retention, with its term and what happens if the account closes. 3. **Retention and expiry.** Keep it eight years from the end of the calendar year of receipt, retrievable and not rewritable, with deliberate deletion at expiry (`RISK-POL-0009`, `RISK-POL-0002`). 4. **Demonstrate.** Receive one real structured invoice end to end and retrieve it from the archive. This is the closure condition. 5. **Say what already happened.** If structured invoices have already arrived, say where their originals are now. ## Re-evaluation The register re-grades this finding when: - the workplan exists (tracking only, grade unchanged); - measure 1 answers whether invoices have already been received. Receipt with the original lost would make the likelihood `L4` and the grade `high`; - the closure condition is met, and the finding becomes fixed. ## Reviews - **2026-09-22** — filed and graded from the `RISK-POL-0012` review. Owner assigned by the founder; workplan requested from qonto-assistant. Cadence starts at instant.