Emergency? DE

VAT Compliance & Tax CMS in Germany: Proof of Check, not Safe Harbour

The future will not reward the trader who says “we were careful”. It will reward the trader who can prove it.

VAT compliance in Germany is no longer a question of correct invoice fields. Any business trading in EU supply chains — whether a German company or an international group with German exposure — faces one recurring allegation: that it knew, or should have known, of VAT fraud committed somewhere else in the chain. A VAT-focused tax compliance management system (tax CMS) answers that allegation the only way it can be answered: with documented, time-stamped, decision-level evidence of due care. We call this Proof of Check.

Why now: VAT enforcement has become a real-time, data-driven risk

Start with the numbers. The European Commission puts the EU VAT compliance gap at roughly €128 billion, of which an estimated €12.5 to €32 billion per year is attributed to organised missing trader (Missing Trader Intra-Community fraud: EU-wide VAT fraud in which one trader in the chain reports the tax, never remits it, and vanishes.">MTIC) fraud. The European Public Prosecutor’s Office (EPPO) — the EU-level prosecution authority that operates through German investigators on German soil — reported 981 ongoing VAT and customs fraud investigations at the end of 2025, with estimated damage of €45 billion. Coordinated search operations across a dozen or more countries, with hundreds of officers, have become routine.

Fighting fraud on that scale is legitimate. It is necessary. But it creates a second risk: honest businesses are pulled into suspicion grids built for criminals. German tax authorities no longer audit invoices in isolation. They ask whether a prudent businessperson should have recognised fraud somewhere in the supply chain. E-invoicing, the EU’s ViDA reform, the CESOP payment-data system and the Eurofisc network connect transaction data, payment flows and risk signals — increasingly in near real time. VAT is becoming a data tax. Authorities are gaining faster, clearer visibility of transactions. Many businesses cannot yet explain those same transactions with the same clarity. That gap is where the risk now sits.

The case law that governs this field is European, not merely German — which is why it matters to every EU trader. In Optigen (2006), the Court of Justice protected the honest trader: each transaction is assessed on its own; a trader’s right to deduct input VAT is not affected by fraud elsewhere in the chain which that trader did not and could not know about. In Kittel, decided months later, the Court drew the boundary that has defined the field ever since: a trader who knew or should have known that, by its purchase, it was participating in a transaction connected with VAT fraud loses the right to deduct. “Knew or should have known” — readers familiar with HMRC’s Kittel assessments in the United Kingdom will recognise the test. It is the same test, from the same judgment, and it applies in every EU Member State.

In Mahagében and Dávid (2012), the Court drew the equally important opposite boundary: tax authorities may not transfer their own investigative duties onto businesses. There is no general obligation to audit one’s supply chain, to verify a supplier’s tax compliance or to monitor its filings. Enhanced checks are required when there are concrete indications of irregularity — not because a trader happens to operate in a so-called risk sector.

Germany codified the Kittel line with effect from 1 January 2020 in Section 25f of the German VAT Act (Umsatzsteuergesetz — UStG). The provision denies input VAT deduction and the zero-rating of intra-Community supplies where the trader knew or should have known that it was participating in a transaction in which a party at a prior or subsequent stage of the chain evaded VAT. The Federal Ministry of Finance (Bundesministerium der Finanzen — BMF) issued detailed administrative guidance in June 2022, including a catalogue of risk indicators. Formally, the burden of proving knowledge or constructive knowledge lies with the tax authority.

That is the theory. Practice is harsher. German tax offices and tax fraud investigation units (Steuerfahndung — the criminal investigation arm of the tax administration) establish objective indicia; the business must then explain why it could not have known. German tax literature calls this a de facto reversal of the burden of proof. The same literature names the only reliable way out: the counter-evidence generally succeeds only where the business established suitable control systems in advance and properly documented the performance of its duties of care. This is where VAT compliance stops being paperwork and becomes defence architecture.

In 2025, the Court of Justice tightened the screws further. In July 2025, in KONREO, it held that the denial of input VAT deduction and joint and several liability may be applied cumulatively; in December 2025, Vaniz added the next extension: the liability survives even the dissolution of the tax debtor. Even the President of the Court calls the denial a radical measure — “one might even call it a sanction” — which cannot be applied lightly. All the more weight falls on the documented check: in late 2025, the German Federal Fiscal Court spelled out for the first time which concrete, time-of-supply checking trail suffices — and at the same time prohibited overstretching the standards of care.

The decisive question, in other words, is not “are we clean?” It is: “can we prove it?”

No safe harbour — and what works instead

We say this plainly, because honesty about limits is the basis of trust: there is no practical safe harbour in European VAT. A tax CMS is not a government certificate. It is not a “trusted trader” badge. It is not a promise that nothing can go wrong. Anyone selling certainty in this field is selling false comfort.

What a living tax CMS does deliver is, in a dispute, worth more: it forces authorities and courts to measure the “should have known” allegation against a concrete, documented checking trail instead of hindsight. The anchors are robust. As early as 2016, the German Federal Ministry of Finance recognised that an internal control system can serve as an indication against intent and recklessness — the dividing line between an honest error and a criminal allegation. In 2017, the German Federal Court of Justice (Bundesgerichtshof) confirmed that an effective compliance management system matters when corporate fines are assessed. The leading German compliance treatise puts it in one sentence: a tax CMS is not a safe harbour but a system for organising indicia and evidence. And the most recent doctoral research develops the VAT-specific CMS explicitly as a systematic counter-indication against intent, recklessness and constructive knowledge: an invalid VAT ID, a flawed EC sales list or an incomplete transport document does not, by itself, establish that a trader recognised or accepted participation in fraud.

In short: a file reconstructed after the event is defensively weak. A lived tax CMS addresses intent, recklessness, constructive knowledge, organisational fault and crisis response in a structured way — before anyone asks.

Proof of Check: do the checks, record the decision, keep the proof

Proof of Check is the working formula. It means the business does not assert that it was careful — it produces an ordered decision-and-evidence trail. That trail answers the questions actually asked in a German VAT dispute: Which checks did the company’s own policy require? When were they performed? From which sources? With what result? Who reviewed, who approved? What changed later — and who reacted?

In simple words: do the checks, record the decision, keep the proof. Not 80 documents. One readable proof package.

The ten building blocks of a defensible VAT CMS

The VSK architecture organises a VAT-specific tax CMS into ten building blocks, from governance to crisis:

  1. Governance and tone from the top — defined VAT roles across management, tax, purchasing, sales and logistics; delegation and escalation matrix.
  2. Risk inventory — which goods, countries, price patterns, payment routes and channels create MTIC exposure? Sector risk triggers checking; it never presumes guilt.
  3. Counterparty onboarding (KYB) — registry data, VAT ID/VIES validation, beneficial owners, bank account, address and contact consistency; versioned, dated, with a named owner.
  4. First-transaction review (enhanced due diligence) — the first deal with a new counterparty deserves special attention: product, quantity, price, margin, route, commercial logic.
  5. Ongoing revalidation — do not check only once; re-check at the right moments and record date, source and result.
  6. Red-flag escalation with a traffic light system — warning signs are assessed, decided and documented, not collected and ignored. A warning sign without a documented escalation is damaging later.
  7. Evidence Pack — the transaction-level defence file: checks, results, timestamps, sources, approvals and reasons.
  8. Correction Pack — the orderly correction process under Section 153 of the German Fiscal Code (the statutory duty to correct returns): root cause, corrected filing, system fix.
  9. Crisis module — unannounced VAT inspections, special VAT audits, dawn raids, asset freezes: responsibilities, data access, liquidity protection, insurance notifications — designed before the emergency.
  10. Monitoring — continuous updating for case law, BMF practice, ViDA, e-invoicing and CESOP; a static system loses its exculpatory value.

Proportion matters. Mid-sized businesses do not need a multinational’s manuals; they need lean processes that make critical decisions provable. A trading company is not a tax office — it cannot, and need not, investigate every upstream chain in Europe. The case law demands reasonable, risk-triggered checking. Proof of Check is calibrated to exactly that standard: check on a risk basis, decide with documentation, escalate on cause. No more. But no less.

Two warnings from compliance practice belong here. First: what counts is not the written ideal organisation but the lived reality — the leading CMS literature distinguishes precisely between “written reality” and “lived reality”. A manual nobody applies is not protection in a dispute; it is an exhibit against the company, proving the risks were known. Second: beware zero-tolerance promises. A business that promises internally to prevent every fraud in its supply chain sets itself an unmeetable standard of care — and hands the other side the yardstick against which every real-world deviation will be measured. A good tax CMS does not promise infallibility. It promises traceability.

The economic pre-effect: why the tax track leads

One point is routinely underestimated outside specialist practice: in German VAT proceedings, the economic decision falls earlier than the legal one. Banks, trade credit insurers, suppliers and customers react to a suspicion faster than any court rules on it. The leading German defence handbook describes the dynamic soberly: in classic carousel constellations, the mere suspicion of supplies to possible missing traders can drive a company into liquidation within months — while liability assessments simultaneously threaten the directors’ private assets. The asset freeze under Section 324 of the German Fiscal Code (a pre-judgment attachment the tax office can order without a court) is rightly called a “sharp sword” in that literature.

Hence the VSK working thesis of the tax-track lead: in large VAT cases, the tax proceedings must take the lead — because that is where claim, amount, enforcement, liability and liquidity are decided — while the criminal track is managed in parallel to protect the rights of the accused. For prevention, the consequence is plain: a tax CMS without a crisis module is incomplete. Whoever starts deciding only in the emergency — who releases which data, how suspension of enforcement is applied for, which insurer must be notified within which deadline — loses exactly the days that will be missing later. Emergency card, responsibilities and liquidity plan belong in the architecture, not in improvisation.

Knowledge organisation: what Section 25f cases are really about

Behind almost every “should have known” allegation sits an organisational question: who in the company saw what, when — and what happened with that information? Purchasing sees the price. Logistics sees the route. Accounting sees the bank account. The tax function sees the VAT ID and the filings. An allegation that ignores these roles treats the company as a single all-knowing brain. It is not one — and German attribution-of-knowledge doctrine does not support that shortcut.

“We knew nothing” is therefore too weak a sentence. The right sentence is: “We operated a system that captures, assesses, escalates and documents relevant information; under that system, this transaction was defensible at the time.” And the time is what counts: the relevant knowledge is the knowledge available at the moment of supply. Later discoveries must not be reinterpreted as earlier bad faith.

Digital VAT: e-invoicing, ViDA, CESOP — the symmetry principle

VAT enforcement is going digital. German e-invoicing moves invoices from PDF folders into structured data models. ViDA introduces EU-wide digital reporting for cross-border B2B transactions. CESOP channels cross-border payment data into anti-fraud analysis; Eurofisc connects Member States’ risk signals. The state is upgrading its data capabilities — for good reason.

But more government data does not automatically mean more trader knowledge. State risk signals must not be converted into “constructive knowledge” without an individual examination of what this business could reasonably see at the time. For businesses, the consequence is a symmetry task: whoever trades in the digital VAT space must be able to present its own ex-ante decision basis with the same data quality the administration applies to its risk selection. Counterparty, invoice, goods movement, payment, booking, filing and internal approval must tell one story — yours.

Three paths through this section: Understand. Prepare. Defend.

Understand — the risk and its legal foundations: how VAT carousel fraud works, why honest traders end up caught in the chain as buffers, what the Kittel test “knew or should have known” actually requires, how Section 25f of the German VAT Act denies input VAT and zero-rating, why multiple assessments along one chain can arise, when good faith protection applies, what e-invoicing, ViDA and CESOP change, how the EPPO investigates, and where criminal liability ends under Section 25f.

Prepare — the evidence architecture for daily trading: the traffic light system for approvals and stop rules, the seven building blocks of Proof of Check, the Evidence Pack as one readable proof package, supplier due diligence without blanket suspicion — and, as the entry point, the VAT CMS Quick Scan: ten questions, a traffic-light result.

Defend — when it gets serious: the emergency page for dawn raids, inspections and Section 25f assessments and asset freezes under Section 324 of the German Fiscal Code. Speed decides here: banks, credit insurers and suppliers often react to an investigation faster than any court will rule on it.

Industry focus: for mobile phone and electronics wholesale — the lead sector of European VAT fraud enforcement — we have mapped the risk separately. The person behind this practice: Dr Fabian Keller, Senior Counsel and head of VSK’s VAT compliance practice.

There is no safe harbour. No magic badge. Just better evidence, created at the right time.

FAQ

Is a tax CMS a safe harbour against Section 25f of the German VAT Act?

No — and nobody should promise you that. A tax CMS guarantees neither input VAT deduction nor zero-rating. It is a system for organising indicia and evidence: it demonstrates that your business checked on a risk basis, assessed warning signs and documented decisions. German ministry guidance has recognised internal control systems as an indication against intent and recklessness since 2016. In a dispute, that shifts the position — from assertion to evidenced care.

Does the Kittel principle apply in Germany the way it does in the UK?

Yes — the test is identical because the source is identical: the CJEU’s Kittel judgment of 2006. The UK applies it through HMRC’s Kittel assessments; Germany codified it in Section 25f UStG with effect from 2020. The phrase “knew or should have known” carries the same weight in Frankfurt as it does in London. One practical difference: in Germany, the same facts typically trigger parallel tax proceedings, criminal investigation and — early and painfully — asset protection measures.

What supplier due diligence does EU case law actually require?

Less than many fear, and more than a VAT ID screenshot. Under Mahagében, tax authorities may not outsource their investigative duties to traders: there is no general obligation to audit the supply chain. What is required is a tiered logic — baseline checks for every counterparty, enhanced due diligence only where concrete indications arise: unusual prices, new bank accounts, atypical routes. A VAT CMS makes this tiering operational and, crucially, provable.

We are an international group — why does German VAT exposure deserve special attention?

Because Germany is an operational focal point of European VAT enforcement: EPPO offices in Munich, Berlin, Frankfurt, Hamburg and Cologne run their own large-scale investigations, supported by dozens of regional tax fraud investigation units. German law combines the Kittel test (Section 25f UStG) with liability provisions and rapid asset-freeze instruments. International groups with German subsidiaries or German supply legs should be able to explain their German transactions with German-grade evidence.

What does the entry point look like?

The VAT CMS Quick Scan: ten questions, a traffic-light result, a prioritised risk map with immediate actions and evidence-pack gaps. No certificate, no bureaucracy — a decision basis. Fixed fees per module are quoted on request, transparently and before work begins.

What should we do in an acute situation — inspection, dawn raid, assessment?

Keep calm, release nothing uncoordinated, activate professional support immediately. The first 72 hours often decide the evidence position and the company’s liquidity. Use the urgent line of this section — we respond the same business day. Professional confidentiality applies from the first contact.

VAT radar — latest

BGHConfiscation cut from EUR 2.66m to 283k: full target-actual comparison requiredEU-RechtNew EU directive: genuine compliance becomes a mitigating factorBFHInput VAT on advisory fees even where the business never tradedAll entries →
Your next step

Step 1 — test without obligation: Start the VAT CMS Quick Scan: ten questions, an immediate traffic-light result, an optional PDF report. No registration wall, no sales pressure. → Start the Quick Scan

Step 2 — talk confidentially: Outline your industry, supply chain or audit situation — anonymously at first, if you prefer. Confidential first assessment, reply within 24 business hours; professional confidentiality from the first contact. Engagement acceptance and conflict checks remain reserved. → Request a first assessment | Urgent case? Phone +49 6204 9721 0 — same-day call-back.

Book your free 15-minute assessment →Or pick a slot now (Mon·Wed·Fri 10–12)
◈ Explore this structure live — infinitely deep