ZATCA Phase 2 E-Invoicing Audit Readiness Checklist

A client receives a ZATCA audit notice. Their ERP was upgraded six months ago. The integration certificate was never renewed. Every invoice issued since the upgrade fails the clearance verification trail. The accounting office managing that client had assumed the IT department handled it — and the IT department had assumed the same of the accounting office.
This is the failure mode that Phase 2 of Saudi Arabia's e-invoicing mandate was built to expose. The Integration Phase does not merely change how invoices look; it changes who is accountable for a continuous, verifiable link between a business's invoicing system and the Zakat, Tax and Customs Authority's (ZATCA) platform. That accountability belongs with the accounting office, not the server room.
What Phase 2 Actually Demands — and Why It Exceeds Phase 1
Phase 1 required businesses to generate structured electronic invoices — a document compliance task. Phase 2, the Integration Phase, requires those invoicing systems to connect directly to ZATCA's platform and submit transactions in real time [3].
The technical bar is specific. Every business-to-business invoice must be cleared by ZATCA before it is shared with the buyer. Simplified business-to-consumer invoices must be reported to ZATCA within 24 hours of issuance [3]. Each invoice must be generated in UBL 2.1 XML format with prescribed data fields, carry a cryptographic digital signature using the company's ZATCA-issued certificate, and include a QR code that embeds invoice details, seller information, and a hash value. For simplified invoices, hash chaining is mandatory — each invoice hash must reference the previous invoice to maintain a verifiable sequence [3].
None of these requirements are set-and-forget. The certificate expires. The XML schema can be misconfigured after a software patch. The hash chain can break if invoices are issued through a non-integrated channel. An accounting office that reviewed integration compliance at onboarding and never returned to it is operating with a false assurance.
The Wave Rollout: Where Your Clients Stand Right Now
ZATCA is phasing in Phase 2 requirements based on annual revenue [3]:
- Wave 1 — SAR 3 billion+ annual revenue: January 2023 (complete)
- Wave 2 — SAR 500 million+: July 2023 (complete)
- Wave 3 — SAR 250 million+: October 2023 (complete)
- Wave 4 — SAR 100 million+: 2024 (in progress)
- Wave 5 — SAR 50 million+: 2025 (upcoming)
- Wave 6 and beyond — all remaining businesses: 2025–2026 (future)
For accounting offices managing mid-market and smaller clients, Wave 5 and beyond represent the bulk of the portfolio. The 2025 timeline is close enough that onboarding reviews must begin now, not at the deadline. Importantly, a client who crossed the SAR 50 million threshold recently may not know which wave applies to them — that determination is the accountant's responsibility to make and document.
The Audit-Readiness Checklist: Seven Verification Points
Audit readiness in a Phase 2 context means being able to demonstrate, at any point, that a client's integration has remained intact and compliant since it was first certified. The following checkpoints define what that demonstration requires.
1. ZATCA onboarding and certification status Confirm that the client completed ZATCA's onboarding process for Phase 2 and holds a current, valid cryptographic certificate. This is not a one-time check — certificates have expiry dates, and an expired certificate invalidates every invoice signed after expiry.
2. Accredited software confirmation Verify that the client's invoicing or ERP software appears on ZATCA's list of approved solutions. Accreditation is tied to specific software versions; a version upgrade without re-verification is a compliance gap. For a detailed breakdown of what accreditation actually covers, see What Software Accreditation Really Means for ZATCA Compliance.
3. B2B clearance workflow integrity Test, or obtain documented evidence, that the client's system is submitting B2B invoices to ZATCA's platform and receiving clearance confirmation before those invoices are delivered to buyers [3]. This workflow should be tested against a sample of recent invoices, not assumed operational because it was once configured.
4. B2C reporting timeliness Confirm that simplified invoices are being reported within the 24-hour window [3]. A batch-reporting failure — where invoices accumulate and are submitted late — constitutes non-compliance even if the invoices are technically well-formed.
5. XML format and digital signature validation Review a sample of invoice files to confirm UBL 2.1 XML structure, complete required data fields, and valid digital signatures. This is especially critical after any software update or configuration change.
6. Hash chain continuity For simplified invoices, verify that hash chaining is intact — no gaps in the sequence, no invoices issued outside the integrated system that would break the chain [3]. A missing invoice number in the sequence is the first indicator of a chain break.
7. ERP change and re-certification log Maintain a dated record of every ERP change, software upgrade, or certificate renewal event for each client, alongside evidence that ZATCA re-onboarding or re-certification was completed before invoicing resumed through the changed system. This log is the core of an audit trail. For the broader obligations around audit trails for regulatory notices, see Audit Trails for Regulatory Notices: What Saudi Law Actually Requires.
ERP Changes Are a Compliance Reset — Not an IT Ticket
The most underestimated risk in Phase 2 compliance is the ERP change event. ZATCA's integration approval is issued to a specific system configuration with a specific certificate. When that configuration changes — whether through a major upgrade, a migration to a new vendor, or a change in the invoice generation module — the approved integration no longer exists in the form ZATCA certified.
The practical consequence: the client must re-register their new system with ZATCA, obtain a new certificate, complete the onboarding process, and receive fresh approval before issuing invoices through the new configuration. Any invoices issued in the gap are potentially non-compliant.
Accounting offices that manage multi-client portfolios face this risk at scale. One client's IT refresh, if not flagged to the compliance function, can generate hundreds of defective invoices before anyone notices. The structural answer is a client change-event protocol — a documented process by which any client system change triggers an automatic compliance review before go-live. For a broader treatment of how to manage compliance events across a multi-client book, see Managing Multi-Client Compliance in Saudi Arabia Without Delegation Failure.
How to Track ZATCA Notifications Without Missing a Wave Deadline
ZATCA communicates wave assignments, onboarding invitations, and compliance alerts through its official channels. For accounting offices managing multiple clients, the risk is not that the notifications don't arrive — it is that they arrive to the client's own registered contacts and never reach the accounting office before a deadline passes.
A robust tracking approach requires three things: first, that the accounting office is listed or copied on ZATCA communications for each client; second, that ZATCA notifications are logged in a central register with action deadlines rather than filed in email inboxes; third, that the register is reviewed on a fixed cadence, not only when a client escalates an issue. For a detailed treatment of how to build this infrastructure, see How Accounting Firms Should Track ZATCA Notifications Systematically.
The same logic applies to the broader compliance stack. A unified register that surfaces ZATCA wave deadlines alongside GOSI contribution dates and Qiwa Saudization thresholds prevents the fragmentation that causes offices to stay on top of one obligation while missing another. See The Case for a Unified Compliance Register Across Client Portfolios for the structural argument.
MAKYN's View: Integration Compliance Is a Service Line, Not a One-Time Setup
The accounting profession in Saudi Arabia is being asked to do something structurally new. Phase 2 e-invoicing compliance is not a filing — it is a live technical state that can degrade between visits. An invoice that was compliant in January may not be compliant in September if a certificate expired, a system was patched, or a hash chain was broken by an edge case in the client's POS workflow.
Accounting offices that treat Phase 2 as a one-time onboarding task will find themselves exposed when a client is audited and the compliance trail has a six-month gap. The offices that treat it as a recurring service — one with structured checkpoints at onboarding, at every ERP change event, and on a fixed annual review cycle — will be able to demonstrate integration integrity on demand.
The checklist above is a starting point. The harder work is building the operational infrastructure to execute it consistently across every client in the portfolio, at the frequency Phase 2 requires. That is precisely the problem MAKYN is built to address — structuring compliance oversight so that what needs to be verified gets verified, and what needs to be escalated reaches the right desk before a deadline expires.
If your office manages clients entering the Phase 2 waves in 2025, now is the time to build the verification workflow rather than improvise it under audit pressure. اطلب عرضاً توضيحياً to see how MAKYN structures ZATCA compliance oversight across multi-client accounting practices.
Frequently asked
- What is the difference between ZATCA Phase 1 and Phase 2 e-invoicing?
- Phase 1 required businesses to generate structured electronic invoices instead of paper ones. Phase 2 — the Integration Phase — goes further by mandating that invoicing systems connect directly to ZATCA's platform, submit B2B invoices for real-time clearance before delivery to the buyer, and report B2C simplified invoices within 24 hours. The compliance burden shifts from document format to continuous system integration.
- When does ZATCA Phase 2 apply to SMBs in Saudi Arabia?
- ZATCA is phasing in the requirement by annual revenue. Wave 5 covers businesses with SAR 50 million or more in revenue and is expected during 2025. Waves 6 and beyond will capture all remaining businesses through 2025–2026. Accounting offices should determine each client's wave assignment at onboarding and calendar the relevant deadline as a hard compliance date.
- What technical requirements must every Phase 2 invoice meet?
- Each invoice must be generated in UBL 2.1 XML format with prescribed data fields, carry a cryptographic digital signature using the company's ZATCA-issued certificate, and include a QR code embedding invoice details, seller information, and a hash. For simplified invoices, hash chaining is also required — each invoice hash must reference the previous one to maintain a verifiable sequence.
- Why is an ERP change a compliance re-certification trigger?
- ZATCA's integration approval is tied to a specific software configuration and cryptographic certificate. When a client changes ERP systems, upgrades to a new version, or allows a certificate to expire, the technical link to ZATCA's platform is broken or invalidated. The client must re-onboard and re-certify, which requires accountants to verify renewed ZATCA accreditation before any invoices are processed through the new system.
Sources
- 1. Complete Guide to ZATCA Phase 2 E-Invoicing | Qeemah — qeemahcloud.com