risk-nexus/docs/regulatory/policies/RISK-POL-0012-e-invoicing.md
tegwick 228116926b File and grade RISK-F-0012: e-invoice receipt and retention
Moves the unowned RISK-POL-0012 receiving duty onto the findings track:
medium (I2 x L3), public, no escalation. The founder assigned qonto-assistant
as fix owner; workplan requested with suggested measures, default 2026-10-06.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 10:06:58 +02:00

3.3 KiB

id type title regime status activates_when owner written cadence clean_streak last_checked next_check checked_by
RISK-POL-0012 legal-policy E-invoicing UStG §14 (as amended by the Wachstumschancengesetz), EN 16931, ViDA active the estate is a German business receiving B2B invoices — already true risk-nexus 2026-08-20 1h 1 2026-09-22T06:26:29Z 2026-09-22T07:26:29Z worsch

RISK-POL-0012 — e-invoicing

Active now, on the receiving side. Since 1 January 2025 a German business must be able to receive a structured electronic invoice conforming to EN 16931 for domestic B2B transactions. That obligation had no transition period: the issuing obligations are phased, the receiving one was not.

Issuing obligations phase in afterwards, with thresholds by turnover. The estate should assume it will be required to issue conformant invoices before it notices the deadline, because the receiving obligation arrived that way.

What it requires of systems

  • An inbox that accepts a structured invoice (XRechnung, or ZUGFeRD's hybrid PDF/A-3 carrying the XML) and does not treat it as an attachment to be eyeballed.
  • Storage of the structured original. A rendered PDF is not the invoice; a human-readable copy alongside it is not sufficient by itself.
  • Retention per RISK-POL-0009 — eight years for the voucher, in the original format it was received in.

Where it bears on this estate

markitect and binect-js handle document flows, and rapp-qonto/fin-hub touch payment and banking records. None of them is currently claimed to be the receiving point for statutory invoices, and this policy does not assign that role — naming the system that must satisfy this is the owning repo's decision, not the register's.

What the register records is that the duty exists, is live, and currently has no named owner in the estate.

Evidence that would show this is met

A demonstrated receipt and archival of an EN 16931 invoice, retained in its structured form, retrievable at eight years.

Not established. If a supplier sends one tomorrow, nobody here can say what happens to it — which is a small, ordinary, entirely fixable gap, and exactly the kind that only becomes visible when it is written down.

2026-09-22 review. The position is unchanged. The receiving duty is live and still has no named owner in the estate, five weeks after this record was written. The issuing dates under §27(38) UStG are:

  • 2027-01-01 for businesses with prior-year turnover above EUR 800,000;
  • 2028-01-01 for everyone else.

A turnover below the threshold therefore leaves about fifteen months, not three. This is from general knowledge of the Wachstumschancengesetz and has not been re-read against the current text. Confirm it before planning to it.

Reviews

  • 2026-09-22 — clean check: Receiving duty live, still no named owner; issuing phase-in dates noted (2027/2028), to be confirmed. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:26Z.

2026-09-22 — filed as a finding. The unowned receiving duty is now RISK-F-0012 (medium). The founder assigned qonto-assistant as owner: Qonto provides the e-invoice capability, and qonto-assistant is the estate's bridge to it. The measures and the re-grade follow that finding. This record keeps the duty itself.