No blind trust. No limitless duty to investigate. Documented plausibility instead.
Any business buying or selling in EU cross-border trade now carries a second product on every invoice: its own evidence position. Under the EU Court of Justice’s Kittel line (2006) — implemented in Germany through Section 25f of the German VAT Act (UStG) — input VAT deduction and the zero-rating of intra-Community supplies can be denied where a trader knew or should have known that a transaction was connected with VAT fraud somewhere in the chain. The encouraging part is often overlooked: the same court has drawn a firm boundary around what authorities may demand. Nobody has to treat suppliers as suspects. What the case law requires is something narrower and more achievable — a risk-based, trigger-driven and documented review of the specific business relationship. This page maps the boundary, the warning signs that matter, and the way a check becomes evidence.
The legal core: “knew or should have known” — not proximity to a chain
Mere proximity to a contaminated chain does not create liability. Since Optigen (2006), the Court of Justice has held that an honest trader’s right to deduct does not depend on what other links in the chain do. The exposure begins only where objective factors show that the trader knew or should have known of the fraud connection — the consistent line from Kittel/Recolta (2006) through Mahagében/Dávid (2012) to Aquila Part Prod Com (2022) and Global Ink Trade (2024).
One feature of this standard deserves emphasis, because tax authorities sometimes argue as if it did not exist: the assessment is made ex ante, at the time of the transaction — not with the hindsight of an investigator three years later. Information that surfaces afterwards does not retroactively poison a decision that was reasonable when it was made. That is precisely why supplier due diligence is an evidence discipline rather than a paperwork exercise: it preserves what you knew, checked and decided at the time.
The Mahagében limit: what authorities may require — and what they may not
Fighting VAT fraud is legitimate. No serious adviser disputes that. But enforcement has a boundary, and the boundary has a name: Mahagében. In 2012 the Court of Justice ruled that tax authorities may not generally require a trader to verify that the issuer of an invoice had the goods at its disposal, was able to supply them, or had met its own VAT declaration and payment obligations. Those controls are the job of the authorities — not of trading businesses. There is no general duty to investigate the upstream chain.
Germany’s Federal Fiscal Court (BFH) has confirmed the same standard for German practice: there is no general obligation to research a supplier’s affairs; a duty to make further inquiries arises only where there are concrete indications of irregularities (BFH, 2021, the “scrap gold” case). The burden of proof follows the same logic: it is for the tax authority to establish, to the requisite legal standard, the objective factors showing knowledge or constructive knowledge — presumptions and reversed burdens are not permitted (Aquila, 2022). The German Federal Ministry of Finance circular of 15 June 2022 on Section 25f UStG acknowledges this allocation expressly.
The result is a middle standard:
- A baseline check for everyone: identity, VAT ID validation, register data, plausibility of the business model — proportionate, standardised, documented.
- A deeper review only on triggers: an anomaly opens the next level of scrutiny. Trigger-based, not suspicion-by-default.
- No forensics: a trading company is not a tax office. It cannot, and need not, illuminate every upstream link in Europe.
What the baseline check should contain has been mapped out at the highest judicial level since late 2025: Germany’s Federal Fiscal Court has judicially approved a concrete, transaction-time checklist — qualified VAT ID confirmation, verification of identity and authority to represent, commercial register extract, copy of an identity document, contractual commitment. That is the reference point for every baseline check.
How far reasonableness stretches can now be read even in administration-leaning German commentary: “remote” constructive knowledge without direct contact with the fraudster is accepted there “only in exceptional cases”; duties of inquiry arise only upon concrete indications — and the mere facts that invoicing runs through a chain and that the parties know one another are not, taken alone, enough. The compliance literature draws the organisational conclusion: Section 25f UStG is business-partner due diligence in action — not an exotic specialty, but part of general counterparty review.
That is the law. Practice is less comfortable: a trader asked to show it “could not have known” will, in reality, only win that argument with controls that existed beforehand and checks that were documented at the time. The Mahagében limit protects against excessive duties — it does not replace your own audit trail. You need both.
The red-flag catalogue: five groups, one principle
A red flag is not proof of fraud. It is an instruction to look closer. Knowing the warning signs is what makes a trigger-based system work — and a trigger-based system is exactly what the case law rewards. The catalogue below groups the recurring indicators from case law, administrative practice and typology work into five clusters. None of them carries an accusation on its own. Each of them deserves a documented answer.
1. Identity and reachability
- Newly formed company with no trading history offering large volumes immediately
- Registered address without operational substance: letterbox, virtual office, no warehouse, no staff
- Unclear or changing contact persons; contact only via mobile or messenger
- Beneficial owners not identifiable; directors with no recognisable link to the industry
- VAT ID not verifiable, only recently issued, or withdrawn in the meantime
- Supplier not registered for VAT, invoices issued without VAT shown — the Court of Justice accepts a hard formal limit on input VAT deduction here (SEM Remont, November 2024); registration status and the face of the invoice belong in the baseline check
- Removal of a counterparty from the VAT register — a trigger for review, not a verdict: removal without a case-by-case assessment is contrary to EU law (Cityland, April 2025), and the equation “deregistered = acting in bad faith” does not hold
2. Price and margin
- Purchase price noticeably below market with no explicable reason (clearance, insolvency stock, currency)
- A suspiciously “safe” margin despite volatile market prices
- Unusual availability of scarce goods in large quantities
- Buy-back offers or signs that goods are circulating in a loop
3. Payment route
- Payment to a third-party account, or to an account in a country unconnected with the supplier
- Bank details changed at short notice; unusual payment service providers
- Cash elements, unusual prepayment pressure, split payments
- Seller, buyer, payer and bank account that do not tell one story
4. Logistics and movement of goods
- Delivery address differing from the place of business; neutral logistics hubs with no clear function
- Ex-works collection in constellations where it makes no commercial sense
- Extremely short trading legs under conspicuous time pressure; goods that move only on paper
- Inconsistencies between invoice, transport documents and the physical flow; duplicate serial numbers
5. History and trading pattern
- Sudden revenue growth of a counterparty with no economic explanation
- Sector switch without recognisable expertise; takeover by unknown acquirers
- Loss of reachability after signing; counterparties in the chain who know each other conspicuously well
- Earlier irregularities that were noticed internally but never assessed
The reverse case matters just as much: the absence of red flags should be documented too. “We checked and found nothing” is worth exactly as much as the record that proves it.
Whether you would spot these signals in your own data can be tested in advance: Self-check: would you spot the red flags in your own supplier data?
From warning sign to decision: escalation, not reflex
The most common operational failure has two faces. One business ignores warning signs because the deal is attractive. The other aborts every transaction at the first anomaly and loses the market to better-organised competitors. Both are avoidable.
The answer is a tiered process, as described in our traffic-light system for VAT risk control: green runs in the standard process. Amber triggers a defined additional review — with a deadline, an owner and four-eyes approval. Red means stop or hold until management has decided. What counts is not the colour but the trail: who saw the signal, who assessed it, who approved — and why?
A warning sign that was seen but never visibly assessed becomes the most dangerous exhibit against your own company. A warning sign that was documented, reviewed and plausibly resolved is the opposite: proof of due care in action.
Documentation: turning checks into evidence
What decides cases is not the volume of paper but the quality of proof. Screenshots without timestamps, PDFs scattered across systems and e-mail threads detached from any internal policy show activity — not reasoning. A defensible audit trail answers four questions: Which checks did your own policy require? When were they performed, with what result and from which source? Who approved the decision? What changed later — and who reacted?
This is the logic of our Proof of Check approach: do the checks, record the decision, keep the proof — as one readable package, not 80 folders. Getting started usually takes less than feared: a red-flag checklist, clear thresholds for enhanced review, an approval field, one evidence folder per supplier. Mid-sized businesses do not need group-style manuals. They need systems that fit their size — and that can explain, years later, why a transaction was accepted, escalated or declined.
To see where your organisation stands, start with the VAT CMS quick scan — ten questions, one traffic-light result. If you already suspect a contaminated chain, the defence perspective is on Unknowingly in the chain: missing trader, buffer, broker. For intra-Community supplies, good-faith protection completes the picture.
The future will not reward the trader who says “we were careful”. It will reward the trader who can prove it.
Red flag margin scheme: “margin cars” — and “margin phones”
Goods offered under the margin scheme (Section 25a UStG) without a documented history belong on every checklist — in two constellations:
Vehicles. Used cars offered as “margin cars” without a plausible, documented history: the “Huracán” investigation wave expressly targets buyers of such vehicles emerging from carousel chains, and Operation “Vortex” (2 July 2025, EPPO Frankfurt/Milan) expressly names the “unlawful application” of margin taxation as part of the scheme, in relation to several thousand second-hand luxury vehicles — estimated damage €100 million.
Electronics. Here the ruse is younger — and bolder: brand-new devices are “repackaged”, briefly “taken into use” or simply re-declared, and then sold as second-hand goods under Section 25a UStG with tax charged on the margin alone. No variant of this is legal. The margin scheme presupposes that the reseller acquired the goods within the EU from someone on whose supply no VAT was owed, or to whose supply the margin scheme itself applied — typically private individuals, small businesses or other margin-scheme resellers (Section 25a(1) no. 2 UStG). Regular new goods from the trade never satisfy that condition; third-country imports do not, in principle, open the margin either. The EPPO now pursues precisely these constellations as a fraud vehicle in its own right: in Operation “Mela” (23 October 2025, EPPO Munich), factory-new mobile phones had been turned into second-hand goods “on paper only” since 2018 — damage €48 million; in “Concertina” (17 January 2024, EPPO Munich), second-hand smartphones from Hong Kong, the UAE and the USA were channelled into the margin chain although the conditions were “clearly” not met — damage €19 million; and in an Ostrava case (March 2025), US goods were falsely declared as being of EU origin in order to obtain the margin — damage €14 million.
For procurement this means: a buyer of margin-taxed smartphones, small electronics or vehicles documents the VAT history before the price decides — the acquisition route, the upstream supplier’s status, and for devices the IMEI/serial numbers and provenance papers. A “used device” in its original shrink wrap is not an opportunity. It is a warning sign.
FAQ
Do we have to investigate every supplier with the same depth?
No. The standard is risk-based: a proportionate baseline check for all counterparties, enhanced review only on triggers. Under Mahagében and the German BFH case law there is no general duty to research a supplier’s affairs — let alone the entire upstream chain.
Is a VIES VAT ID check enough to show due care?
It is necessary, but not sufficient. The VAT ID check is one building block; it does not replace plausibility checks on counterparty, price, payment route, logistics and business model. And it only counts if date, source and result are recorded — including re-checks at the right moments.
Is an unusually low price by itself “constructive knowledge”?
No. A low price is a trigger, not a conclusion. It calls for a documented plausibility assessment (clearance stock, market phase, currency effects, insolvency sales). The problem is not the price — it is a price anomaly that nobody visibly examined.
A red flag appears in the middle of an ongoing relationship — what now?
Neither abort by reflex nor carry on regardless: escalate on the record. Log the signal, assess it, and respond with additional checks, an approval hold or a stop decision depending on severity. A new bank account, a sudden country change or a changed delivery address are classic triggers for a fresh review.
Do we owe the authorities a reconstruction of the whole upstream chain?
No. Complex and far-reaching controls are the task of the tax authorities, not of traders. What is required is a review of your own, specific business relationship — deepened when triggers appear, never limitless.
The German tax office denied our input VAT despite our checks — what next?
The burden of proving knowledge or constructive knowledge lies with the authority; your documented audit trail is the central defence instrument in the objection and fiscal-court procedure. German proceedings can be handled with English-language correspondence — use the confidential first assessment to get an initial view.
Request a supply-chain check — We test your supplier and customer due diligence for gaps before an auditor does: confidential, fixed conditions per module. → Confidential first assessment
Download the red-flag checklist — The five-group catalogue from this page as a compact working aid for procurement, sales and finance (PDF, e-mail registration with double opt-in).
Or start with the VAT CMS quick scan: ten questions, one traffic-light result.
Book your free 15-minute assessment →Or pick a slot now (Mon·Wed·Fri 10–12)