Ten questions. One result. No flattery.
Most businesses have VAT processes. Very few know whether those processes would hold in a German Section 25f dispute — when a tax office alleges the company “should have known” about fraud somewhere in its supply chain. The VAT CMS Quick Scan answers exactly that question — not with a legal opinion, but with an honest baseline: ten questions built along what courts actually examined in 2025 — from the timing of the VAT ID check to the documented approval. A traffic-light finding per field of action, a PDF report with the three most valuable next steps. Free of charge, confidential, in about fifteen minutes.
Why a baseline — and why now
The legal position has been strict since the European Court of Justice’s Kittel line: a trader who knew or should have known that its transaction was connected with VAT fraud loses input VAT deduction and zero-rating — codified in Germany in Section 25f of the VAT Act, the provision behind most German supply-chain assessments against foreign-connected traders. These cases are decided on evidence. Formally, the authority must prove constructive knowledge; in practice it assembles indications, and the business must demonstrate its historic diligence. German tax literature is blunt: that counter-proof normally succeeds only where control systems were established and documented in advance.
“In advance” is the operative phrase. Once a VAT inspection or special audit has been ordered, much can still be organised — but nothing can be retrofitted. The Quick Scan is therefore built as an early indicator: it shows the gaps while they can still be closed, before an auditor finds them. And it follows an internationally familiar logic: maturity models — the kind the OECD developed for tax administrations, and the kind underlying the German assurance standard IDW PS 980 for compliance management systems — all begin with the same question: where do we actually stand, as opposed to where we intended to stand?
Since late 2025, the yardstick has been more concrete than ever. Germany’s Federal Fiscal Court has, for the first time, judicially approved a concrete, transaction-time checklist — qualified VAT ID confirmation, identity and authority verification, commercial register extract, copy of an identity document, contractual commitment: precisely the points the scan asks about. And the commentary literature names the tipping point without embellishment: “Where sufficient indications of knowledge exist, a de facto reversal of the burden of proof occurs.” The scan shows whether your documentation would withstand that tipping point.
The ten questions
The scan walks you through ten fields of action. Each question carries two to four clarifying sub-points; the core questions in overview:
- Risk map: Which product groups, countries and sales channels create heightened VAT or carousel (Missing Trader Intra-Community fraud: EU-wide VAT fraud in which one trader in the chain reports the tax, never remits it, and vanishes.">MTIC) exposure in your business?
- Anomalous counterparties: Which trading partners are new, margin-anomalous or logistically unusual — and who in your organisation notices systematically?
- Checking responsibility: Who verifies VAT IDs, registry data, bank details, addresses, beneficial owners and delivery routes — and is the result recorded with date and owner?
- First transactions: Which first deals with new partners trigger enhanced review — and which pass through unchecked?
- Escalation rules: Which warning signals mandatorily require tax or legal sign-off — up to managing-director level?
- Data linkage: How are invoice, payment, delivery and accounting entries connected so that they tell one consistent story?
- Reporting consistency: How do you reconcile EC Sales Lists, VAT ID confirmations, ERP data and documentary evidence?
- Error and correction process: Is there a defined process for corrections under Section 153 of the German Fiscal Code when an error is discovered?
- Crisis readiness: Does an emergency card exist for VAT inspections, dawn raids and asset freezes — who does what in the first hours?
- Insurance cover: Have D&O, criminal-defence legal expenses and trade credit policies been reviewed against VAT risk, including notification deadlines?
Reading the questions has diagnostic value of its own: hesitate on three of them, and you know why the scan is worth fifteen minutes.
How the result works
A traffic light per field, not just an overall grade. Each answer maps to one of three findings: green (the field is addressed and documented), amber (partially addressed — typically practised but not provable) or red (open — this is where the evidential gap would appear in a dispute). The gauge shows the overall picture; the pattern across the ten fields shows where to start.
A PDF report by e-mail. On completion you receive a compact report: your traffic-light profile, a short assessment per field and the three steps with the best ratio of effort to evidential value. Delivery follows a double opt-in — you confirm your e-mail address before the report is sent. No disclosure to third parties, deletion on request, no newsletter without separate consent.
A realistic expectation: hardly any business scores green across the board — and that is not an alarm signal but the normal finding for a mid-sized company that has so far relied on practised, undocumented diligence. Amber means: substance exists, provability is missing. That is precisely where the leverage is greatest.
What the Quick Scan is — and what it is not
Here we are deliberately precise, because trust begins with expectation management. The Quick Scan is a baseline — not a legal opinion, not an assurance engagement, not case-specific legal advice. It tests structures, not transactions; it assesses your self-reported answers, not your files. A green result is no safe harbour, no certificate and no release from liability — and a red result is no accusation, but a work list.
Equally part of honesty: taking the scan creates no attorney–client relationship. If your finding suggests deeper review, we will say so — and we will say so just as plainly if, in our view, no action is needed. A baseline that diagnoses the same advisory need in every participant would not be one.
Why this restraint? Because the case law demands it. The European Court of Justice decides “should have known” cases on the facts of each case; blanket clearances therefore cannot exist. What can exist — and what the German administration itself recognises — is the indicative effect of functioning controls: under the official guidance to Section 153 of the Fiscal Code, an internal control system can weigh against intent and recklessness. The Quick Scan measures how far your organisation is from such a system.
From finding to system
The report does not end in generalities; it points to concrete modules, depending on where your ambers and reds sit:
- If escalation rules and approval levels are missing (questions 2, 4, 5), the next step is the traffic-light system for daily trading.
- If the methodical check trail is missing (questions 3, 6, 7), Proof of Check with its seven building blocks is the lever.
- If the structured evidence file is missing (questions 6–10), work begins on the VAT Evidence Pack.
- And if the matter is already acute — an ongoing audit, an assessment, a dawn raid — do not take the scan; go straight to the confidential first assessment.
If you then want to turn the finding into an audit-proof system, the path is described separately: From scan to system: building a VAT tax CMS under IDW PS 980.
The full defence architecture is described in the VAT compliance overview. Workshops and in-depth modules are offered at a fixed fee per module on request — the Quick Scan itself remains free and without obligation. For international groups: the scan, the report and all follow-up work are available entirely in English.
Confidentiality and data minimisation
The scan asks for no business secrets: no customer names, no supplier lists, no amounts. It works with structural questions (“Does … exist? Who does …? Is … documented?”). The report requires an e-mail address; name and company details are optional. If you prefer to stay anonymous and still talk, use the anonymous case outline on the confidential first assessment page. Document uploads are deliberately not part of the scan — records belong in a mandate relationship, after conflict checks and via a secured channel.
FAQ
Is the Quick Scan really free — and what is the catch?
It is free, and the “catch” is transparent: the scan is our way of getting acquainted. If your finding shows a need for action, we propose suitable next steps — whether you take them with us is your decision. No obligation and no attorney–client relationship arise.
How long does it take, and who should complete it?
About fifteen minutes. Answers are most meaningful when the managing director or CFO completes it together with whoever owns tax or compliance — the gap between those two perspectives is often a finding in itself.
Is the result a legal opinion or an assurance report?
No. The Quick Scan is a structured baseline built on your self-assessment — not a legal opinion, not an IDW PS 980 assurance engagement, not case-specific advice. It identifies fields of action; reviewing actual transactions and legal questions is reserved for a mandate.
What happens to our answers and data?
Report delivery only after double opt-in; no disclosure to third parties; deletion on request. The scan deliberately asks for no business secrets, customer names or amounts. Confidentiality is not a marketing word for us — it is a professional duty.
We already run a group tax CMS — is the scan still useful?
Especially then. Many group systems are built around corporate income tax and filing risks and leave the specific VAT fields open: supply-chain checks, escalation, evidence filing, crisis card, insurance interface. The scan shows in fifteen minutes whether your CMS covers those fields — and it translates the German specifics for head office.
What if an audit or assessment is already under way?
Then the scan is the wrong instrument — not because it would do harm, but because you need something faster. Use the confidential first assessment or the direct line; in acute matters we first address deadlines, enforcement and immediate measures.
Start the Quick Scan. Ten questions, about fifteen minutes, traffic-light result immediately — PDF report by e-mail after double opt-in. Free and without obligation. Start the Quick Scan →
Prefer to talk first?
Request a confidential first assessment — on request as an anonymous case outline; response within 24 hours on business days. Request a first assessment →
Acute matter?
Audit, assessment, dawn raid or asset freeze: direct line in the page header — call-back today.