Not a binder. Not a certificate. A system that testifies for you.
A VAT tax compliance management system is not a folder for the next audit but a defence architecture: it organises how your business checks, decides and documents — before anyone asks. This page shows what the system consists of, why the 2024/2025 case law makes building one urgent, and the path: structured, sized for mid-sized businesses, no corporate manuals.
Why now: The courts have delivered the formula
Fighting VAT fraud is legitimate. But it creates a second danger: honest businesses end up in suspicion grids. Under the ECJ’s Kittel line, whoever knew or should have known that a transaction was connected with VAT fraud loses input VAT deduction and exemption — codified in Section 25f of the German VAT Act. The commentary literature is sober about the consequence: once sufficient indications exist, the burden of proof shifts de facto onto the business. Whoever starts collecting evidence then is collecting memories — not proof.
Three developments argue for building the system now:
First, the ECJ’s exculpation formula. In late 2024, in Dranken Van Eetvelde, the Court spelled out what matters: the taxable person must be able to prove it “took all measures that can reasonably be required” to ensure its transactions were not part of a fraud scheme. Not a footnote — the blueprint. A VAT tax CMS is exactly this proof: organised, repeatable, exportable.
Second, the Federal Fiscal Court’s template. In December 2025, Germany’s highest tax court approved for the first time a concrete, time-stamped catalogue of due care — qualified VAT ID confirmation, identity and authority checks, register extract, documented undertakings — and prohibited overstretching the standard. Supreme-court authority now shows what a check path that holds looks like.
Third, recognition by the administration. German administrative guidance has stated since 2016: an internal control system can indicate against intent and recklessness. The commentary on the current ECJ line is plain: the Court holds the door for tax compliance wide open. The question is no longer whether a system works — but whether you have one when it counts.
The roof: IDW PS 980 — seven core elements, one benchmark
IDW PS 980 is the established German audit standard for compliance management systems. It describes seven core elements: culture, objectives, organisation, risks, programme, communication, monitoring and improvement. These elements are the roof — they decide whether a system deserves to be taken seriously: lived culture or mission statement? Measurable objectives or declarations? Clear responsibility or fog?
What the standard does not deliver is the VAT substance: a generic CMS spots neither an inconsistent payment route nor circulating goods nor a missing supplier registration. Hence the ten building blocks — the VAT-specific execution under the roof.
Paper CMS or lived system: the difference that decides
The key distinction first. Compliance literature separates the written ideal organisation from the lived business reality — in a dispute, only the second counts. A manual nobody knows, a policy purchasing has never seen, an escalation route never used: that is a paper CMS — activity, not reasoning. A binder reconstructed after the event looks defensively weak; a lived system can address intent, recklessness, constructive knowledge and organisational fault in a structured way.
Lived means: the check is filed with date, source and responsible person. The approval has a name. The warning signal has a documented outcome. Promising to prevent every fraud in the chain sets an impossible standard of care; a good VAT tax CMS does not promise the absence of errors — it makes decisions traceable. That is enough.
The ten building blocks of the VAT tax CMS
The ten blocks are the VAT-specific execution of the seven core elements — built from a defence perspective: each answers a question that auditors, investigators or courts will ask later.
Block 1 — Governance and tone from the top. VAT compliance is a management task: who owns it, how is it delegated, who may escalate — up to the managing director. Without this allocation, later exculpation remains abstract.
Block 2 — Risk inventory. Which goods, countries, price structures, delivery and payment routes create elevated risk? The inventory classifies — and records the boundary: sector risk triggers checks, not a presumption of guilt.
Block 3 — Supplier and customer onboarding. VAT ID, commercial register, the people acting, bank account, address consistency — versioned, with date and responsible person: the block the 2025 Federal Fiscal Court catalogue addresses directly.
Block 4 — Transaction review and first deal. The first deal with a new counterparty deserves special attention: price, margin, volume, routes, commercial logic — checked before performance. After-the-fact plausibility is an assertion, not a check.
Block 5 — Ongoing revalidation. Checked once is not checked forever: new bank account, new address, new contact, different product range — changes trigger re-checks at a risk-driven frequency.
Block 6 — Red-flag escalation with a traffic light system. Green proceeds, amber is clarified and recorded, red stops until tax or management approves. The uncomfortable truth: a warning signal without documented escalation becomes incriminating later — see the traffic light system for VAT risk control.
Block 7 — Evidence Pack. All checks, sources, timestamps, approvals and documented doubts per business relationship — one readable proof package, exportable for the tax office, the bank or a court: the structured Evidence Pack.
Block 8 — Correction Pack. Errors happen in the best system. The block governs the orderly response: corrected returns, the boundary to voluntary disclosure, root cause, system fix — part of the system, not downstream panic.
Block 9 — Crisis module. Unannounced inspection, dawn raid, asset freeze: who leads, who speaks, who accompanies data access, which insurer is notified when — designed before the emergency, not improvised in it.
Block 10 — Monitoring and improvement. KPIs, samples, training, adaptation to e-invoicing, ViDA, CESOP: a static system loses its exculpatory value; a learning system proves with every update that it is alive.
How these checks become provable diligence is described by the Proof of Check and its seven building blocks — the working formula for daily trading.
The path: Quick Scan, workshop, sprint
Nobody builds ten blocks in a day — nobody has to. Three stages, each with a clear deliverable in a clear timeframe:
Stage 1: the guided Quick Scan. In 90 to 120 minutes we walk the core questions along your real processes — result: a short written traffic-light assessment with the three top priorities. Prefer to self-test first? The VAT CMS Quick Scan is online, free and confidential; the Missing Trader Quick Check shows in three minutes whether purchasing sees signals.
Stage 2: the CMS workshop day. One day with management, purchasing and accounting: roles, thresholds, approvals and escalation routes fixed against your actual workflows — you leave with a prioritised roadmap, not a slide deck.
Stage 3: the Evidence Pack sprint. Within 30 days your standard transaction file takes shape: which records arise at onboarding, first transaction and triggering events, where they live, who owns them.
All formats at a fixed fee per module on request — no subscription, no mega-project. One honest commitment: if you do not need a CMS project, we say so in the Quick Scan — not after the workshop.
Source box
Legal status: 7 July 2026. Full citations for the legal statements made in the text.
- ECJ, judgment of 6 July 2006 — C-439/04 and C-440/04, Kittel and Recolta Recycling, ECLI:EU:C:2006:446, para. 56 et seq. (knowledge or constructive knowledge).
- ECJ, judgment of 12 December 2024 — C-331/23, Dranken Van Eetvelde, ECLI:EU:C:2024:1027, para. 32 (exculpation: all measures that can reasonably be required).
- ECJ, judgment of 11 January 2024 — C-537/22, Global Ink Trade, ECLI:EU:C:2024:6, para. 41 et seq. (legal certainty; administration bound by its guidance).
- Federal Fiscal Court (BFH), judgment of 18 December 2025 — V R 3/25, ECLI:DE:BFH:2025:U.181225.VR3.25.0, paras 31 f. (catalogue of due care; no overstretching of the standard).
- Section 25f German VAT Act (UStG); Federal Ministry of Finance circular of 15 June 2022 — III C 5 - S 7429-b/21/10003 :001, BStBl I 2022, 1001.
- Federal Ministry of Finance circular of 23 May 2016 — IV A 3 - S 0324/15/10001, BStBl I 2016, 490 (internal control system as indication against intent and recklessness).
- IDW Assurance Standard 980 (revised 09.2022): compliance management systems audit (seven core elements).
- Heidner, in: Bunjes, UStG, 24th ed. 2025, Section 25f para. 9 (de facto reversal of the burden of proof).
- Treiber, in: Sölch/Ringleb, UStG, 106th suppl. March 2026, Section 25f para. 75 (the ECJ holds “the door for … ‘tax compliance’” wide open).
- Müller/Fischer, Tax Compliance, 2nd ed. 2022, pp. 23 f., 94 et seq. (tax CMS as evidence organisation, not a safe harbour).
- Bay/Hastenrath (eds.), Compliance-Management-Systeme, 4th ed. 2026, §§ 3, 9 (risk matrix; warning against zero-tolerance promises).
FAQ
Do we really need a tax CMS as a mid-sized business?
A question of scale, not corporate status. Mid-sized businesses need lean, resilient processes, not corporate manuals: the ten blocks scale from five to five hundred employees. What matters is not document volume but that critical decisions are provable.
Does a VAT tax CMS reliably protect against Section 25f?
No — and anyone promising that promises too much. No safe harbour, no certificate, no release from liability. A lived system delivers the counter-indication against constructive knowledge, intent and recklessness — exactly the proof the ECJ requires for exculpation. Not a free pass, but the difference between assertion and evidence.
We already run a tax CMS for corporate income tax. Is that enough?
Usually not. Income-tax systems address filing and accounting risks; the specific VAT fields — supplier checks, payment routes, red-flag escalation, evidence filing, crisis module — typically remain open. The Quick Scan shows quickly whether your system covers them.
How long does the build take — and where do we start?
With a stocktake, not a manual: Quick Scan (90–120 minutes, three priorities), workshop (one day, roles and rules), sprint (30 days, evidence filing). A workable core system stands in weeks — not years.
Know where you stand. The VAT CMS Quick Scan shows in ten questions which building blocks hold and where the evidence gaps sit. Free and confidential. Fast. Specific. No strings. Start the Quick Scan →
Prefer to talk first?
Bring one case, one file or one question — in a confidential first assessment we tell you how critical it is and what to do next. Response within 24 hours on working days. Request a first assessment →
Acute situation?
Audit, assessment notice, dawn raid: direct phone line in the page header — call-back today.