Not a certificate. Not a badge. An evidence architecture.
The decisive question in EU VAT supply-chain cases is not “were we careful?”. It is: “can we show it two years later — quickly, completely and without rebuilding the file?” Proof of Check is our working formula for exactly that capability. In simple words: do the checks, record the decision, keep the proof. Seven building blocks turn the formula into a system.
Why there is no safe harbour — and what takes its place
Start with the uncomfortable truth that serious advice has to state: there is no practical safe harbour in European VAT. No adviser, platform or software provider can make a company immune from VAT questions. A VAT ID check alone certainly cannot — a VAT ID check is not a compliance system.
What replaces the unreachable shield is reachable and more valuable: the ability to show, clearly and quickly, what checks were required; when the checks were performed; which sources were used; what the result was; who reviewed and approved the decision; what changed later; and what evidence can be shared without oversharing sensitive data. That is Proof of Check — not the claim of being “clean”, but the documented path to the decision as it was taken at the time.
Because the principal risk for an honest trader is rarely the fraudster in the chain itself. It is the trader’s own evidential gap: that a good company cannot show, two years later, what it knew, what it checked and why the decision was reasonable.
The seven building blocks
1. KYB and onboarding
Know the business, not just the number: registration, real management, genuine activity, contact details and the counterparty’s role in the chain. A registry extract alone does not answer whether a real market participant stands behind the entity — mailbox addresses, freshly appointed directors and a missing sector history are the classic patterns of missing-trader vehicles. Onboarding records who checked, from which sources, with what result. This file is the foundation everything later builds on: versioned, dated, attributed to a responsible person. Skip it, and every subsequent control inherits the gap.
2. VAT ID re-checks
Do not check only once. A qualified VAT ID confirmation at onboarding is mandatory — but carousel structures often emerge after a trading relationship is established, precisely because the early deals looked clean. Re-checks therefore belong at the right moments: before first transactions, at volume jumps, after master-data changes, at risk-based intervals. And every check is recorded with date, source and result. The difference between “we verify VAT IDs” and “we can produce a time-stamped verification for every single supply” is, in a dispute, the difference between assertion and proof.
3. First transaction review
The first deal with a new counterparty deserves special attention: product, quantity, price, margin, route and commercial logic. Why does an unknown supplier sell below market? Why this volume, why now, why through this route? The first transaction is statistically the most frequent entry point into contaminated chains — and at the same time the moment when a documented plausibility review creates the most protection. A short written record of the commercial logic answers, in advance, the question every auditor will ask later: “should this not have struck you as odd?”
4. Payment and logistics consistency
Seller, buyer, payer, bank account, shipping documents and delivery route should tell one story. If they do not, stop and ask why. Third-party payments from accounts that belong to nobody in the contract chain; bank details in countries with no link to the business; goods that physically travel a different route than the invoice chain — these are the consistency breaks from which authorities later derive “should have known”. Continuously reconciling money flow and goods flow is therefore not a bookkeeping task. It is the authenticity anchor of the entire transaction.
5. Trigger logic
A new bank account, a sudden country change, an abnormal discount, a changed delivery address or an unexpected intermediary should trigger a fresh review. Trigger logic is the hinge between Proof of Check and the traffic-light system: it defines in advance which change forces which reaction, instead of leaving the assessment to chance or to the time pressure of the trading day. The decisive word is “in advance”. A trigger recognised only in hindsight does not protect you — it incriminates you, because it proves the signal was visible.
6. Four-eyes approval
High-risk deals should not be approved only by the person who wants the sale. Someone independent must be able to say “yes”, “no” or “not yet” — with a documented reason. The four-eyes principle neutralises the structural conflict of interest in sales and at the same time answers the attribution question the European Court of Justice addressed in Aquila (2022): the knowledge of agents and delegates is attributed to the company. Clear approval paths control whose knowledge becomes decision-relevant — and let you show, later, who knew what, when, and who was authorised to decide.
7. Evidence Pack
At the end, there should be one clean export: checks, results, timestamps, sources, approvals and reasons. Not 80 documents. One readable proof package. The seventh block condenses the first six into a record that a bank, auditor, tax inspector or court can actually read. It is important enough to have its own page: the VAT Evidence Pack — one readable proof package.
Four layers of legal framework — why the blocks sit exactly there
The seven blocks are not consulting folklore; they respond to four layers of law. First, national law: Section 25f of the German VAT Act codifies the CJEU’s Kittel test; under the German Ministry of Finance circular of 15 June 2022, the trader bears the burden of establishing the substantive conditions, while the authority must prove knowledge or constructive knowledge — a contest that is won with documentation, not protestation. Second, the European data architecture: the VAT Directive and the ViDA reform shift VAT from a document logic to a data logic; from 2030, cross-border B2B supplies will be reported digitally and close to real time. Third, the administrative data space: through Regulation 904/2010, Eurofisc and CESOP, authorities cross-match reporting, payment and risk data at speed. Fourth, the international anti-abuse environment (OECD, ATAD, DAC6), which repeats one principle throughout: anti-abuse enforcement must remain proportionate, case-specific and rebuttable.
All four layers point to the same conclusion: the state will soon see your transactions faster and more sharply than you can explain them — unless you prepare. That gap between the authorities’ data view and your own ability to explain is where the risk now sits. Proof of Check closes it. More on the data side: e-invoicing, ViDA and CESOP — VAT becomes a data tax.
Rebuttability: the doctrinal core
Why does this work legally? Because EU law does not tolerate irrebuttable presumptions. Foundational abuse-of-law scholarship stated it early: presumptions against the taxpayer are sustainable only if they are targeted, proportionate and rebuttable without unreasonable hurdles. The European Court of Justice made it concrete in Aquila (2022): the tax authority must establish the objective circumstances of fraud participation to the requisite legal standard — assumptions are not enough. German practice adds the sober footnote: in reality, the counter-proof succeeds almost only for the trader who built and documented control systems beforehand.
Case law supplied the formula in 2024 and 2025. A trader who demonstrates having “taken every measure that could reasonably be required of him” rebuts the liability presumption — so the European Court of Justice in late 2024 in Dranken Van Eetvelde; it is the strongest new anchor for documented diligence. And Germany’s Federal Fiscal Court showed in late 2025 what that proof looks like in concrete terms: qualified VAT ID confirmation, identity and authority-to-represent checks, a commercial-register extract, a copy of the ID document, a contractual undertaking to deliver the transport evidence — all documented as at the transaction date. Demanding more would, in the Senate’s words, “overstretch the standards of care”.
The commentary literature carries the approach as well — across the camps. Kraeusel accepts counter-proof through “documented verification”. Robisch, in the Bunjes commentary, recommends “describing the checks that are typical for the business and documenting their concrete application” — the commentators’ blueprint of the Proof of Check. And Treiber sums up the Luxembourg line since Global Ink Trade: the Court of Justice holds the door for “tax compliance” “wide open”.
Proof of Check is the organisational translation of that legal position — rebuttal-ready evidence. A business does not have to prove that no fraud chain existed anywhere in Europe. It has to make provable that its own ex-ante decision was reasonable on the information then available. In defence practice this extends to filing expert opinions confirming that the required diligence was observed — but an expert can only assess what was documented. That is what the seven blocks are for. Policy debate in Germany now even calls for audited tax control frameworks to carry a statutory rebuttable presumption against intent and recklessness; that is not yet the law — one more reason to secure the evidential position yourself.
One objection belongs openly on the table. In the commentary literature, Burgmaier warns of a “tax-CMS boomerang”: self-imposed standards could tighten the applicable standard of care — the more a company documents, the more every deviation is measured against its own rulebook. The objection deserves to be taken seriously. But it goes to the yardstick, not the method: the measure remains the prudent merchant, not the self-imposed ideal standard. That is precisely why the Proof-of-Check architecture is calibrated strictly to occasion and risk — it promises traceability, not faultlessness.
Good checks speed trading up
Some traders fear that better checks slow the market down. That is the wrong way to look at it: bad checks slow the market down — through repeated bank queries, stalled audits, frozen liquidity. Good checks, done once and stored properly, make trading faster: banks and credit insurers receive answers instead of paper stacks, audits shorten, repeat onboarding accelerates. The goal is not to create bureaucracy. The goal is to make clean trading easier to defend — not slower to execute.
In daily operations, Proof of Check runs through the traffic-light system; your current maturity is measured in ten questions by the VAT CMS Quick Scan. The full architecture is described in our VAT compliance overview.
What VSK delivers
In the Proof-of-Check workshop we take one real, completed transaction of yours and test where your evidence would hold today — and where it would fail under pressure. The output: the target architecture of the seven blocks for your business model, role and approval definitions, re-check frequencies, a trigger catalogue and the Evidence Pack template. Fixed fee per module on request. No certificates, no badges, no promises of outcomes — an evidence architecture sized to your business. For international groups we work in English throughout and translate German concepts — Section 25f UStG, UStAE, qualified VAT ID confirmation, EC Sales List — into an actionable plan.
FAQ
Is Proof of Check a certificate or certification scheme?
No — emphatically not. Proof of Check is not a government certificate, not a “trusted trader” badge and not a promise that nothing can go wrong. It is an evidence architecture: the documented ability to demonstrate your diligence as at the transaction date.
Does Proof of Check guarantee input VAT recovery?
No. Tax authorities and courts decide each case on its facts. Proof of Check improves the evidence and argumentation position — in our experience, the only lever a business genuinely controls itself.
Do all seven blocks have to be in place at once?
No. The architecture is modular and proportionate to risk. Many businesses start with blocks 1, 2 and 7 (onboarding, re-checks, Evidence Pack) and add trigger logic and four-eyes approval in a second stage. A mid-sized trader is not a tax office — and does not need to become one.
Is our existing VAT ID verification not enough?
As a building block, yes; as a system, no. Qualified VAT ID confirmation is necessary, but it answers neither the commercial logic of a deal nor the consistency of payment and goods flows. A VAT ID check is not a compliance system.
How is this different from a classic tax CMS project?
The evidential focus. Classic CMS projects often produce policies and training records — they show activity, not reasoning. Proof of Check asks consistently backwards: what must be producible in two years for the decision to hold? That determines what must be documented today.
Does this work for non-German groups trading into Germany?
Yes — that is a core use case. The method maps German requirements (Section 25f UStG, the published risk factors, German audit practice) onto your existing group controls, in English, so that head office and German operations work from one playbook.
Request a Proof-of-Check workshop. Bring one deal you rejected and one deal you accepted but would like to prove. We will show where your evidence is strong and where it would fail under pressure. Fixed fee per module on request. Request a workshop →
Take a baseline first: the VAT CMS Quick Scan delivers a traffic-light result on your current evidential capability in ten questions. Start the Quick Scan →
To take away: the Proof-of-Check one-pager with all seven building blocks as a PDF. Request the one-pager →
Confidentiality from first contact. Response within 24 hours on business days.
Book your free 15-minute assessment →Or pick a slot now (Mon·Wed·Fri 10–12)