Emergency? DE

Supplier Due Diligence: Spotting Red Flags — Without Blanket Suspicion

No blind trust. No limitless duty to investigate. Documented plausibility instead.

Any business buying or selling in EU cross-border trade now carries a second product on every invoice: its own evidence position. Under the EU Court of Justice’s Kittel line (2006) — implemented in Germany through Section 25f of the German VAT Act (UStG) — input VAT deduction and the zero-rating of intra-Community supplies can be denied where a trader knew or should have known that a transaction was connected with VAT fraud somewhere in the chain. The encouraging part is often overlooked: the same court has drawn a firm boundary around what authorities may demand. Nobody has to treat suppliers as suspects. What the case law requires is something narrower and more achievable — a risk-based, trigger-driven and documented review of the specific business relationship. This page maps the boundary, the warning signs that matter, and the way a check becomes evidence.

Mere proximity to a contaminated chain does not create liability. Since Optigen (2006), the Court of Justice has held that an honest trader’s right to deduct does not depend on what other links in the chain do. The exposure begins only where objective factors show that the trader knew or should have known of the fraud connection — the consistent line from Kittel/Recolta (2006) through Mahagében/Dávid (2012) to Aquila Part Prod Com (2022) and Global Ink Trade (2024).

One feature of this standard deserves emphasis, because tax authorities sometimes argue as if it did not exist: the assessment is made ex ante, at the time of the transaction — not with the hindsight of an investigator three years later. Information that surfaces afterwards does not retroactively poison a decision that was reasonable when it was made. That is precisely why supplier due diligence is an evidence discipline rather than a paperwork exercise: it preserves what you knew, checked and decided at the time.

The Mahagében limit: what authorities may require — and what they may not

Fighting VAT fraud is legitimate. No serious adviser disputes that. But enforcement has a boundary, and the boundary has a name: Mahagében. In 2012 the Court of Justice ruled that tax authorities may not generally require a trader to verify that the issuer of an invoice had the goods at its disposal, was able to supply them, or had met its own VAT declaration and payment obligations. Those controls are the job of the authorities — not of trading businesses. There is no general duty to investigate the upstream chain.

Germany’s Federal Fiscal Court (BFH) has confirmed the same standard for German practice: there is no general obligation to research a supplier’s affairs; a duty to make further inquiries arises only where there are concrete indications of irregularities (BFH, 2021, the “scrap gold” case). The burden of proof follows the same logic: it is for the tax authority to establish, to the requisite legal standard, the objective factors showing knowledge or constructive knowledge — presumptions and reversed burdens are not permitted (Aquila, 2022). The German Federal Ministry of Finance circular of 15 June 2022 on Section 25f UStG acknowledges this allocation expressly.

The result is a middle standard:

What the baseline check should contain has been mapped out at the highest judicial level since late 2025: Germany’s Federal Fiscal Court has judicially approved a concrete, transaction-time checklist — qualified VAT ID confirmation, verification of identity and authority to represent, commercial register extract, copy of an identity document, contractual commitment. That is the reference point for every baseline check.

How far reasonableness stretches can now be read even in administration-leaning German commentary: “remote” constructive knowledge without direct contact with the fraudster is accepted there “only in exceptional cases”; duties of inquiry arise only upon concrete indications — and the mere facts that invoicing runs through a chain and that the parties know one another are not, taken alone, enough. The compliance literature draws the organisational conclusion: Section 25f UStG is business-partner due diligence in action — not an exotic specialty, but part of general counterparty review.

That is the law. Practice is less comfortable: a trader asked to show it “could not have known” will, in reality, only win that argument with controls that existed beforehand and checks that were documented at the time. The Mahagében limit protects against excessive duties — it does not replace your own audit trail. You need both.

The red-flag catalogue: five groups, one principle

A red flag is not proof of fraud. It is an instruction to look closer. Knowing the warning signs is what makes a trigger-based system work — and a trigger-based system is exactly what the case law rewards. The catalogue below groups the recurring indicators from case law, administrative practice and typology work into five clusters. None of them carries an accusation on its own. Each of them deserves a documented answer.

1. Identity and reachability

2. Price and margin

3. Payment route

4. Logistics and movement of goods

5. History and trading pattern

The reverse case matters just as much: the absence of red flags should be documented too. “We checked and found nothing” is worth exactly as much as the record that proves it.

Whether you would spot these signals in your own data can be tested in advance: Self-check: would you spot the red flags in your own supplier data?

From warning sign to decision: escalation, not reflex

The most common operational failure has two faces. One business ignores warning signs because the deal is attractive. The other aborts every transaction at the first anomaly and loses the market to better-organised competitors. Both are avoidable.

The answer is a tiered process, as described in our traffic-light system for VAT risk control: green runs in the standard process. Amber triggers a defined additional review — with a deadline, an owner and four-eyes approval. Red means stop or hold until management has decided. What counts is not the colour but the trail: who saw the signal, who assessed it, who approved — and why?

A warning sign that was seen but never visibly assessed becomes the most dangerous exhibit against your own company. A warning sign that was documented, reviewed and plausibly resolved is the opposite: proof of due care in action.

Documentation: turning checks into evidence

What decides cases is not the volume of paper but the quality of proof. Screenshots without timestamps, PDFs scattered across systems and e-mail threads detached from any internal policy show activity — not reasoning. A defensible audit trail answers four questions: Which checks did your own policy require? When were they performed, with what result and from which source? Who approved the decision? What changed later — and who reacted?

This is the logic of our Proof of Check approach: do the checks, record the decision, keep the proof — as one readable package, not 80 folders. Getting started usually takes less than feared: a red-flag checklist, clear thresholds for enhanced review, an approval field, one evidence folder per supplier. Mid-sized businesses do not need group-style manuals. They need systems that fit their size — and that can explain, years later, why a transaction was accepted, escalated or declined.

To see where your organisation stands, start with the VAT CMS quick scan — ten questions, one traffic-light result. If you already suspect a contaminated chain, the defence perspective is on Unknowingly in the chain: missing trader, buffer, broker. For intra-Community supplies, good-faith protection completes the picture.

The future will not reward the trader who says “we were careful”. It will reward the trader who can prove it.

Red flag margin scheme: “margin cars” — and “margin phones”

Goods offered under the margin scheme (Section 25a UStG) without a documented history belong on every checklist — in two constellations:

Vehicles. Used cars offered as “margin cars” without a plausible, documented history: the “Huracán” investigation wave expressly targets buyers of such vehicles emerging from carousel chains, and Operation “Vortex” (2 July 2025, EPPO Frankfurt/Milan) expressly names the “unlawful application” of margin taxation as part of the scheme, in relation to several thousand second-hand luxury vehicles — estimated damage €100 million.

Electronics. Here the ruse is younger — and bolder: brand-new devices are “repackaged”, briefly “taken into use” or simply re-declared, and then sold as second-hand goods under Section 25a UStG with tax charged on the margin alone. No variant of this is legal. The margin scheme presupposes that the reseller acquired the goods within the EU from someone on whose supply no VAT was owed, or to whose supply the margin scheme itself applied — typically private individuals, small businesses or other margin-scheme resellers (Section 25a(1) no. 2 UStG). Regular new goods from the trade never satisfy that condition; third-country imports do not, in principle, open the margin either. The EPPO now pursues precisely these constellations as a fraud vehicle in its own right: in Operation “Mela” (23 October 2025, EPPO Munich), factory-new mobile phones had been turned into second-hand goods “on paper only” since 2018 — damage €48 million; in “Concertina” (17 January 2024, EPPO Munich), second-hand smartphones from Hong Kong, the UAE and the USA were channelled into the margin chain although the conditions were “clearly” not met — damage €19 million; and in an Ostrava case (March 2025), US goods were falsely declared as being of EU origin in order to obtain the margin — damage €14 million.

For procurement this means: a buyer of margin-taxed smartphones, small electronics or vehicles documents the VAT history before the price decides — the acquisition route, the upstream supplier’s status, and for devices the IMEI/serial numbers and provenance papers. A “used device” in its original shrink wrap is not an opportunity. It is a warning sign.

FAQ

Do we have to investigate every supplier with the same depth?

No. The standard is risk-based: a proportionate baseline check for all counterparties, enhanced review only on triggers. Under Mahagében and the German BFH case law there is no general duty to research a supplier’s affairs — let alone the entire upstream chain.

Is a VIES VAT ID check enough to show due care?

It is necessary, but not sufficient. The VAT ID check is one building block; it does not replace plausibility checks on counterparty, price, payment route, logistics and business model. And it only counts if date, source and result are recorded — including re-checks at the right moments.

Is an unusually low price by itself “constructive knowledge”?

No. A low price is a trigger, not a conclusion. It calls for a documented plausibility assessment (clearance stock, market phase, currency effects, insolvency sales). The problem is not the price — it is a price anomaly that nobody visibly examined.

A red flag appears in the middle of an ongoing relationship — what now?

Neither abort by reflex nor carry on regardless: escalate on the record. Log the signal, assess it, and respond with additional checks, an approval hold or a stop decision depending on severity. A new bank account, a sudden country change or a changed delivery address are classic triggers for a fresh review.

Do we owe the authorities a reconstruction of the whole upstream chain?

No. Complex and far-reaching controls are the task of the tax authorities, not of traders. What is required is a review of your own, specific business relationship — deepened when triggers appear, never limitless.

The German tax office denied our input VAT despite our checks — what next?

The burden of proving knowledge or constructive knowledge lies with the authority; your documented audit trail is the central defence instrument in the objection and fiscal-court procedure. German proceedings can be handled with English-language correspondence — use the confidential first assessment to get an initial view.

Your next step

Request a supply-chain check — We test your supplier and customer due diligence for gaps before an auditor does: confidential, fixed conditions per module. → Confidential first assessment

Download the red-flag checklist — The five-group catalogue from this page as a compact working aid for procurement, sales and finance (PDF, e-mail registration with double opt-in).

Or start with the VAT CMS quick scan: ten questions, one traffic-light result.

Book your free 15-minute assessment →Or pick a slot now (Mon·Wed·Fri 10–12)
◈ Explore this structure live — infinitely deep