Electronic invoicing is the most powerful instrument that European tax administrations have deployed against invoice fraud in a generation. The combination of structured data, real-time or near-real-time transmission, cryptographic signatures, chained hashes and verifiable references has fundamentally altered the economics of invoice manipulation. Practices that were difficult to detect in the paper era —invented invoices for fictitious operations, double-billing of the same service, manipulation of received invoices to inflate deductible amounts, carousel schemes that exploit cross-border VAT mechanisms— are now exposed by structural design rather than by occasional inspection.

For businesses, the same architecture that supports fraud prevention by the tax administration also protects them from being defrauded by counterparts, by employees or by external attackers. Understanding how the protective mechanisms work, what responsibilities they create and how to operate them in daily practice is part of the new electronic invoicing literacy that every operator should acquire.

The typologies of invoice fraud

Several typologies of invoice fraud have historically affected European tax administrations and businesses. The first is the fictitious invoice: a document issued for an operation that never occurred, used by the recipient to inflate deductible expenses and reduce taxable income or to claim a VAT credit that was never paid by the issuer. This pattern is particularly damaging when the issuer is a so-called missing trader who disappears before the tax administration can recover the VAT.

The second is the double invoice: the same operation is invoiced twice to extract a double payment from a counterpart or a double deduction from the tax administration. The variants include the duplication of legitimate invoices and the issuance of variants that differ only in marginal details.

The third is the carousel VAT fraud: a chain of operations between EU businesses exploits the difference between the zero-rating of intra-EU supplies and the deductibility of domestic VAT to extract repeated VAT refunds without any real economic activity. The chain typically involves a missing trader who disappears with the VAT, a buffer that legitimises the transaction and a broker that completes the carousel.

The fourth is the alteration of received invoices: the recipient modifies invoices received from suppliers to inflate the deductible amounts, the chronology or the nature of the expense. The modification can be subtle —changing one digit, altering the date— or substantial —fabricating entire line items—.

The fifth is the parallel cash register or shadow accounting: the business maintains an official record for tax purposes and a parallel record for internal use, with the gap between them representing under-declared revenue. This pattern is particularly relevant for cash-intensive businesses like retail and hospitality.

How structured electronic invoicing addresses each typology

The structured electronic invoice, transmitted through controlled channels and equipped with the cryptographic safeguards that the European mandates require, addresses each of these typologies through specific mechanisms.

Against the fictitious invoice, the real-time or near-real-time transmission of every invoice to the tax administration —through systems like the Italian SDI, the Spanish VeriFactu, the French Portail Public de Facturation, the upcoming European harmonised platforms— creates a cross-check capability that was unimaginable in the paper era. Every invoice that the recipient deducts is also an invoice that the administration has on record from the issuer's side; missing trader patterns become visible within days or weeks rather than years.

Against the double invoice, the chained hash architecture —each invoice carries a cryptographic reference to the previous one, forming an unbreakable sequence— prevents the silent insertion of additional invoices into the issuer's stream. Any duplication is immediately visible in the sequence integrity.

Against carousel VAT fraud, the combination of real-time reporting and the gradual convergence toward the European VIES update mechanism reduces the time window during which a carousel can operate undetected. The European VAT in the Digital Age proposal further compresses this window by mandating near-real-time reporting of intra-EU transactions.

Against the alteration of received invoices, the structured XML format with the issuer's cryptographic signature provides tamper evidence: any modification by the recipient breaks the signature and leaves a visible trace. The recipient who wishes to dispute an invoice must use legitimate channels —credit notes from the issuer, dispute communications, formal corrections— rather than silent modification.

Against the parallel cash register, the certification of point-of-sale devices and the real-time transmission of sales data —the Italian scontrino telematico, the Spanish SIF, the German TSE-equipped Kassen— prevents the technical possibility of maintaining a parallel record that is undetectable by inspection.

The Spanish SIF: integrity by design

The Spanish Sistema Informático de Facturación, introduced by Royal Decree 1007/2023, embodies the integrity-by-design philosophy. The SIF must guarantee five qualities of every record: integrity, conservation, accessibility, legibility and traceability. The technical implementation of these qualities involves the electronic signature of each invoice, the hash chain that links every invoice to its predecessor, the QR code that allows public verification, the secure verification code that the tax administration can use to confirm authenticity, and the conservation infrastructure that maintains the records for the legal retention period.

The choice between VeriFactu and No-VeriFactu modulates the transmission dimension. Under VeriFactu, every invoice is transmitted to the AEAT in real time, providing immediate visibility to the tax administration. Under No-VeriFactu, the records remain in the issuer's custody but with the same technical guarantees and an export capability for inspection. The fraud prevention value is similar in both cases; the difference is in the timing of the administration's visibility.

The QR code on the invoice is a powerful public verification tool. Any recipient can scan the QR code with a smartphone, open the AEAT verification page and confirm that the invoice corresponds to a real record in the system. This capability transforms the recipient into an active participant in fraud prevention; an invoice that does not verify is an invoice that the recipient should not trust.

The German TSE and the Kassensicherungsverordnung

The German approach to fraud prevention in cash-intensive sectors operates through the Kassensicherungsverordnung —the regulation on the security of cash registers—. Every electronic cash register, including modern POS systems for retail and hospitality, must incorporate a technische Sicherheitseinrichtung —a TSE— that signs every transaction with a cryptographic certificate and creates a chained sequence that is tamper-evident.

The TSE was introduced in 2020 and has progressively reshaped the technical landscape of German retail and hospitality. The Finanzamt now expects every cash register to produce TSE-signed receipts; the absence of a TSE or any evidence of tampering produces immediate consequences during inspection, including the rejection of the cash register's records and the potential application of an estimated taxation.

The Wachstumschancengesetz e-invoicing reform extends the fraud prevention architecture to the B2B segment, with structured invoices, mandatory reception capability and progressive adoption of structured issuance. The combination of TSE for B2C and structured e-invoicing for B2B will create a coherent fraud prevention framework that covers the entire German tax landscape.

The Italian Sistema di Interscambio: real-time visibility

Italy has the longest operational experience with mandatory B2B electronic invoicing at scale. The Sistema di Interscambio has processed billions of invoices since its launch, providing the Agenzia delle Entrate with continuous visibility into the country's commercial flows. The fraud prevention impact has been substantial; VAT collection has improved measurably, and several large-scale fraud schemes have been detected and dismantled within months of their operation rather than years.

The architecture relies on the central platform processing every invoice between the issuer and the recipient. The intermediation is invisible to the parties —the invoice arrives at the recipient through the SDI— but it provides the administration with the data needed for real-time analytics. Suspicious patterns —rapid increases in invoice volume, geographic concentrations, sequences that suggest carousel structures— can be flagged for investigation.

The complement to the SDI is the scontrino telematico for B2C transactions, transmitted daily from certified cash registers to the administration. The combination of B2B and B2C real-time visibility makes the Italian system one of the most comprehensive fraud prevention frameworks in Europe.

The French e-reporting and the dual architecture

The French approach combines electronic invoicing for B2B with e-reporting for B2C and cross-border transactions. The B2B invoice flows through the Portail Public de Facturation or through certified private platforms; the B2C and cross-border data is reported separately. The dual architecture allows the administration to maintain visibility over the entire transaction universe without imposing structured invoicing on the B2C segment, where the volumes would be unmanageable for individual receipt-level processing.

The fraud prevention focus is similar to other European systems: real-time or near-real-time visibility, cryptographic safeguards, public verification capabilities, automated cross-checks between issuer and recipient declarations. The phased calendar that France is implementing reflects the operational complexity of bringing millions of businesses into the new infrastructure.

The protection of the business: fraud against the business

The same architecture that supports fraud prevention by the tax administration also protects the business from fraud directed against itself. Three patterns are particularly relevant: invoice phishing, internal fraud and supplier impersonation.

Invoice phishing is the practice of sending fraudulent invoices to a business with the intention of obtaining payment for non-existent services. The fraudster typically impersonates a known supplier or invents a plausible service description, sends the invoice to the accounts payable department and waits for the payment to be processed automatically. The losses can be substantial, especially in businesses that process high volumes of supplier invoices.

Structured electronic invoicing addresses this risk through the verifiability of the issuer's identity. The cryptographic signature attached to the invoice can be validated against the issuer's certificate; the invoice carries a traceable identifier that can be cross-checked against the supplier database; the chained sequence reveals whether the invoice fits into a legitimate stream or appears as an isolated document. The accounts payable process should incorporate these verifications as automated checks before any payment is released.

Internal fraud —the manipulation of invoices by employees with access to the accounts payable or accounts receivable function— is similarly constrained by the structured architecture. The signature, the hash chain and the audit trail leave evidence of any modification; the segregation of duties between invoice approval and payment authorisation, supported by the platform, prevents the same employee from creating and paying fraudulent invoices.

Supplier impersonation —the practice of sending fraudulent invoices that mimic those of a legitimate supplier, with a payment account that has been changed to that of the fraudster— is addressed by the verification of the issuer's certificate and by the standardisation of payment instructions. A change in the payment account should trigger an out-of-band verification with the supplier before the change is accepted into the system.

The recipient's responsibilities

The new architecture imposes specific responsibilities on the recipient of an electronic invoice. The recipient is expected to verify the technical integrity of the invoice —signature, chained hash, QR code— before processing it; to confirm that the issuer is a legitimate supplier through cross-checks against internal databases; to apply the segregation of duties that prevents internal fraud; to investigate any anomaly before completing the payment.

The failure to perform these checks can have fiscal consequences if the invoice turns out to be fraudulent. The recipient who deducted VAT on a fictitious invoice without performing due diligence may face the rejection of the deduction, the application of interest and the imposition of penalties. The standard of due diligence varies by jurisdiction, but the general expectation is that the recipient takes reasonable steps to verify the legitimacy of the invoice and the underlying operation.

The structured electronic invoice makes due diligence easier than ever. The verification mechanisms are automated; the supplier identity is cryptographically established; the chained sequence is verifiable. The recipient who does not use these tools is operating below the standard of care that the new framework expects.

The issuer's responsibilities

The issuer also carries specific responsibilities under the new architecture. The integrity of the invoice depends on the integrity of the issuance process; an issuer who allows the manipulation of invoices —by employees, by counterparts, by external attackers— is responsible for the consequences.

The technical safeguards built into the SIF, the TSE, the SDI and the equivalent national systems reduce the manipulation risk substantially, but they do not eliminate the need for organisational controls. The issuer should maintain access controls on the invoicing system, audit trails of all modifications, segregation of duties between invoice generation and approval, and regular reviews of the chained sequence integrity.

The relationship with the software provider is a particular dimension. The issuer relies on the provider's certification of the SIF or equivalent system; the issuer must verify that the certification is current, that updates are applied promptly and that any anomaly reported by the provider is investigated. The chain of responsibility between provider and issuer is defined by the regulatory framework but operates in practice through the contractual relationship.

The fraud detection analytics

The structured data generated by the e-invoicing systems is the raw material for advanced fraud detection analytics. The tax administrations across Europe are investing heavily in the analytical capabilities that exploit this data: pattern recognition, anomaly detection, network analysis, predictive modelling. The investigations that previously relied on individual tips or random inspections are increasingly driven by data-driven prioritisation.

Businesses can also benefit from analytical capabilities applied to their own invoice flows. The same techniques that the administration uses to detect carousel patterns can be applied to detect supplier risk, customer payment risk, internal process anomalies and emerging operational issues. The compliance investment in structured electronic invoicing produces a data asset that has analytical value beyond the regulatory purpose.

The international dimension: cooperation between administrations

VAT fraud frequently crosses borders, and the response requires cooperation between tax administrations. The European VIES system has provided the foundation for cross-border verification for years; the new e-invoicing reforms are extending the cooperation through real-time data sharing under the VAT in the Digital Age framework.

For businesses operating cross-border, the increased cooperation means that fraud schemes that previously could exploit the gaps between national systems are increasingly visible to the combined administrations. The transparency is a constraint for fraudsters and an asset for legitimate businesses, who benefit from a level playing field where compliance is enforced more uniformly.

Common pitfalls in fraud prevention

Several errors recur in the operational application of the fraud prevention framework. The first is treating the technical safeguards as automatic protection. The signature, the hash chain and the QR code provide tamper evidence, but the verification must actually be performed —the recipient who does not verify is exposed regardless of the technical sophistication of the system.

The second is neglecting the organisational controls in favour of pure technology. The strongest cryptographic infrastructure can be subverted by an employee with excessive access or by a process that does not segregate duties. The organisational design is at least as important as the technical design.

The third is underestimating the social engineering dimension. The most successful invoice frauds rely on manipulating the people in the accounts payable function, not on breaking the technical systems. Training, awareness and clear escalation paths are essential.

The fourth is failing to keep the verification infrastructure current. The certificates, the verification endpoints, the supplier databases and the internal procedures all evolve; an outdated verification configuration produces false positives or, worse, false negatives that allow fraudulent invoices to pass through.

The fifth is not exploiting the analytical value of the structured data. The compliance investment generates a data asset that, if analysed, reveals operational insights and emerging risks. The business that uses this asset is in a stronger position than the business that simply stores it.

The strategic perspective

For businesses, the fraud prevention dimension of the new electronic invoicing framework is simultaneously an obligation and a benefit. The obligation to operate within the structured architecture comes with the benefit of protection against external fraud and internal manipulation. The investment in the compliance infrastructure pays back not only through avoided penalties but through avoided fraud losses.

The strategic stance is to integrate the fraud prevention design with the broader risk management framework of the business. The accounts payable controls, the supplier verification, the segregation of duties and the analytical reviews should be designed as a coherent whole, with the electronic invoicing infrastructure as the technical foundation.

Professional guidance for the transition

Fraud prevention in the new electronic invoicing era is a topic that combines technical, organisational and analytical dimensions. A structured assessment of the business's exposure to invoice fraud, the verification infrastructure currently in place and the integration with broader risk management is the foundation for a robust design.

If your business is preparing for the e-invoicing mandates and you want to see how Invoseal handles the fraud prevention dimensions of the European frameworks —signature verification, hash chain integrity, supplier authentication, analytical reviews—, you can review the functionalities and the deployment options at invoseal.es.

Want to sort it out today?

InvoSeal complies with RD 1007/2023 in VeriFactu and Non-VeriFactu mode from day one. Statement of Responsibility published.

Try InvoSeal →
← Back to blog