Your invoice reaches the tax authority before it reaches your customer.
The UAE did not build a portal you upload invoices to. It adopted a decentralised Peppol network with five corners, and the fifth corner is the Federal Tax Authority. The Ministry's own framework puts the report to the FTA at step 4 of 11 — in parallel with transmission to the buyer's provider, and three steps before the buyer sees the document at all. Understanding the order of those steps is the difference between reading a confirmation message correctly and guessing at it.
The five corners
| Corner | Who |
|---|---|
| Corner 1 | Supplier — you, when you are selling |
| Corner 2 | The supplier's Accredited Service Provider |
| Corner 3 | The recipient's (buyer's) Accredited Service Provider |
| Corner 4 | Recipient — the buyer |
| Corner 5 | The Federal Tax Authority |
Four-corner Peppol models are the international norm: sender, sender's provider, receiver's provider, receiver. The UAE added a fifth. Everything unusual about the local regime follows from it.
The eleven steps, in the Ministry's order
| # | What happens |
|---|---|
| 1 | The supplier (C1) submits invoice data to its provider (C2), in whatever format the two of them have agreed. |
| 2 | C2 validates that data and converts it into the UAE standard electronic invoice in XML — if it did not already arrive in that form. |
| 3 | C2 transmits the XML invoice to the buyer's provider (C3). |
| 4 | In parallel, C2 reports the tax data to the FTA (C5). |
| 5 | On validating the invoice, C3 sends an electronic confirmation back to C2. |
| 6 | C3 delivers the invoice to the buyer (C4), in a format the two of them have agreed. |
| 7 | On successful validation, C3 also reports tax data to C5. On unsuccessful validation, C3 confirms the failure electronically to C2 and to C5 — and reports no tax data. |
| 8 | C5 confirms to C2 once the tax data has been successfully reported. |
| 9 | C5 confirms to C3 once its tax data has been successfully reported. |
| 10 | C2 forwards the confirmations it received to the supplier (C1). |
| 11 | C3 forwards the confirmations it received to the buyer (C4). |
Step 4 is the one worth rereading. The supplier's provider reports to the FTA in parallel with sending the invoice onward — not after the buyer accepts it, and not at the end of a period. By the time your customer's accounts payable team has even seen the document, the tax data is already with the Authority. There is no window in which an invoice has been "sent but not yet declared".
Step 7 is the other one. Tax data is reported twice for a healthy invoice — once by each provider — which is how the FTA reconciles the two sides of a transaction. When the buyer's provider cannot validate the document, that second report simply does not happen, and instead a failure confirmation goes to the supplier's provider and to the Authority. So a failed invoice is not silent: the FTA learns about the failure by design.
Note what the steps do not include: an approval gate. Nothing in the framework waits for the FTA to clear an invoice before it moves. The confirmations at steps 8 and 9 are acknowledgements that reporting succeeded, not permissions to issue. This is a reporting model, not a clearance model — which distinguishes it from several regimes in the region that UAE businesses are often told to benchmark against.
There is no QR code
Guidelines V1.1 is unambiguous: electronic invoices are issued, transmitted and received in XML format and will not feature a QR code or barcode. The contents are set by Peppol's PINT-AE billing specification, and they vary by document type and by scenario.
This matters because the most common mental model a UAE business brings to eInvoicing comes from neighbouring implementations where a QR code on a printed or PDF invoice is the visible artefact of compliance. Here there is nothing to print and nothing to scan. The compliant document is the XML that moved between the providers; anything human-readable your system renders from it is a convenience, not the invoice.
What your provider does not do for you
Appointing an accredited provider does not move the obligation. The guidelines set out the split directly, and the footnote to their table is blunt: providers are engaged to carry out these activities in practice, "although the compliance obligation remains with the supplier (or buyer in the case of self-billed invoices)."
| Activity | Supplier | Buyer | Provider |
|---|---|---|---|
| Exchanging and reporting invoices, including receiving confirmation messages | Yes | Self-billed only | No |
| Calculating all electronic invoice values | Yes | Self-billed only | No |
| Secure transmission using encryption | No | No | Yes |
| Agreeing business-specific data security requirements with providers | Yes | Yes | No |
| Obtaining the buyer's Peppol participant identifier | Yes | No | No |
| Looking up a participant identifier once provided | No | No | Yes |
| Generating a UUID for every invoice, so no invoice can be duplicated | No | No | Yes |
Row five is a master-data project disguised as a technical detail. Contacting each buyer and gathering their Peppol participant identifier is the supplier's job, not the provider's — the provider only looks up an identifier you have already supplied. For a business with a few hundred B2B customers, that is a data-collection exercise with a deadline attached, and it is the single most common reason an otherwise finished implementation cannot send anything. Your participant identifier is your TIN: the first 10 digits of your TRN. If you are in scope but not registered for any tax type, you must register with the FTA purely to obtain one. And if you are part of a tax group, it is the first 10 digits of your own TRN, not the group representative's.
The three endpoints for a buyer who has no identifier
The obvious objection to a network built on participant identifiers is that some counterparties will not have one. The guidelines answer it with three predefined endpoints, each for a specific situation.
| Situation | Endpoint to use |
|---|---|
| Deemed supply — no identifiable recipient address | 0235:9900000097 (does not vary with the supplier) |
| Buyer has not yet implemented eInvoicing and has no participant identifier | 0235:9900000098 |
| Export — buyer outside the UAE with no Peppol ID | 0235:9900000099 |
Each is described as mandatory in its situation, not as a fallback of last resort. Two consequences follow.
- You must still send a PDF. Where the buyer has not yet implemented eInvoicing — because their phase has not begun and they have not volunteered — the guidelines state that regular tax invoices, for example in PDF, are required in addition to electronic tax invoices. Through the transition you are running two invoice streams for some customers, not one. A Phase 1 supplier live from January 2027 will be doing this for most of its smaller customers until July 2027.
- Deemed supplies may never be exchanged at all. Where an invoice for a deemed supply is not issued to a recipient, there is no exchange of electronic invoices — only reporting to the FTA by the supplier's provider. The network carries the tax data and nothing else.
The Authority can access the data, and share it
Article 10 of MD 243 grants the FTA power to access and use any data processed, received and stored under the system. It also permits the Authority, subject to the Tax Procedures Law and its executive regulations, to share that data with other government entities and with foreign government bodies, in implementation of the UAE's obligations under any international agreement, treaty or arrangement to which it is a party.
That is a narrower power than it first reads — it is tied to treaty obligations rather than to general discretion — but it is worth knowing that transaction-level data now exists in a form that can move across borders under an exchange-of-information arrangement, where previously the FTA held only periodic returns.
Where the records live afterwards
Article 11 requires storage of electronic invoices, electronic credit notes and associated data for the periods in the Tax Procedures Law: 5 years following the tax period for a taxable person, 5 years from the end of the calendar year of creation for anyone else, 7 years for real estate records, with 4 extra years during a dispute or audit and 1 extra year after a voluntary disclosure made in the fifth year.
Appendix 4 of the guidelines then makes three clarifications that matter operationally. There is no requirement to store at a particular layer of the network — Corner 1 and Corner 4 storage are not mandated; any compliant arrangement works provided the data is retained, its integrity preserved, and the records producible to the Authority on request. Your provider may store the data for you by contract, but the legal obligation does not move with it — the person remains ultimately responsible. And providers must inform you on an event-driven basis, without undue delay, that documents have been successfully transmitted to the Authority. The transactional logs the provider keeps — transmission statuses, routing information, unique transaction identifiers — are its own compliance artefact under the OpenPeppol agreement and the UAE Peppol Authority Specific Requirements, and are expressly not the business document data you have to retain under Article 11.
Two questions to put to a provider that follow directly from the model. First: how are the step 8 and step 9 confirmations surfaced to me, and what do I see when step 7 fails — a failed validation at the buyer's end is the scenario where you find out whether a provider's interface is designed or improvised. Second: what happens to an invoice addressed to 0235:9900000098 when that customer later gets a real identifier. The rest of the provider questions are here — with the ones accreditation already answers for you.
Frequently asked questions
What is the five-corner model in UAE eInvoicing?
It is the framework under which electronic invoices are issued and distributed in the UAE. Corner 1 is the supplier, Corner 2 the supplier's Accredited Service Provider, Corner 3 the recipient's provider, Corner 4 the recipient, and Corner 5 the Federal Tax Authority. It extends the standard four-corner Peppol model by adding the tax authority as a participant that receives reported tax data.
When does the FTA receive my invoice data?
At step 4 of the Ministry's eleven-step framework — in parallel with the transmission of the invoice from your provider to the buyer's provider, and before the buyer has received the document. The buyer's provider then reports tax data separately at step 7 if its validation succeeds, so a healthy transaction is reported from both sides.
Does the FTA approve an invoice before it is sent?
No. The UAE model is a reporting model, not a clearance model. Nothing in the eleven-step framework waits for the Authority to clear an invoice before it moves to the buyer. The confirmations the Authority sends at steps 8 and 9 acknowledge that tax data was successfully reported; they are not permission to issue.
What happens if the buyer's provider cannot validate my invoice?
Under step 7 of the framework, the recipient's provider confirms the unsuccessful validation electronically to the supplier's provider and to the Federal Tax Authority, and in that case reports no tax data to the Authority. The failure is therefore visible to the Authority by design rather than being a silent gap.
Does a UAE electronic invoice have a QR code?
No. Guidelines V1.1 states that electronic invoices are issued, transmitted and received in XML format and will not feature a QR code or barcode. The invoice is the XML exchanged between the accredited providers; any human-readable rendering of it is a convenience, not the compliant document.
What is my participant identifier for UAE eInvoicing?
Your Tax Identification Number, which is the first 10 digits of your TRN. If you are in scope but not registered for any tax type, you must register with the Federal Tax Authority to obtain a TIN. If you are part of a tax group, your identifier is the first 10 digits of your own TRN, not the first 10 digits of the group representative's.
Who has to collect the buyer's Peppol identifier — me or my provider?
You. The Ministry's responsibility table assigns contacting the buyer and gathering their Peppol participant identifier to the supplier, and assigns only the lookup of an identifier already provided to the Accredited Service Provider. Generating a UUID for each invoice and encrypting transmission are the provider's jobs; calculating invoice values and receiving confirmation messages remain yours.
What do I do if my customer is not on the eInvoicing system yet?
Use the predefined endpoint 0235:9900000098 on the electronic invoice, which the guidelines make mandatory where the buyer has not implemented eInvoicing and has no participant identifier. You must also continue to issue that customer a regular tax invoice — for example a PDF — in addition to the electronic one, until they are live.
Which endpoint is used for exports and deemed supplies?
For exports where the buyer has no Peppol ID, the predefined endpoint 0235:9900000099 must be included. For deemed supplies, the buyer electronic address is always 0235:9900000097, and that value does not change with the identity of the supplier. Where an invoice for a deemed supply is not issued to a recipient, there is no exchange of electronic invoices at all — only reporting to the Authority by the supplier's provider.
Can the FTA share UAE eInvoicing data with other countries?
Article 10 of Ministerial Decision No. 243 of 2025 gives the Authority power to access and use data processed, received and stored under the system, and — subject to the Tax Procedures Law and its executive regulations — to share it with other government entities or foreign government bodies pursuant to the UAE's obligations under an international agreement, treaty or arrangement to which it is a party.
Can my provider store my electronic invoices for me?
Yes, where that is agreed contractually, but the delegation does not transfer the legal obligation — Appendix 4 of Guidelines V1.1 states that the person remains ultimately responsible for compliance with the retention requirements. There is also no requirement to store at any particular layer of the network, provided the data is retained for the required period, its integrity and security preserved, and the records made available to the Authority on request.
Sources
- The five corners, the eleven steps, the responsibility table, the XML-only and no-QR-code rule, storage periods and Appendix 4 — UAE Electronic Invoicing Guidelines V1.1, chs. 2, 3, 5 and Appendix 4 (PDF)
- The three predefined endpoints, deemed supplies, exports and the transitional PDF requirement — the same guidelines, ch. 10.2 and 10.4 (PDF)
- Exchange and reporting obligations, agents, FTA access and data sharing, storage — Ministerial Decision No. 243 of 2025, Arts. 6, 8, 10, 11 (PDF)
- Implementation phases and dates — Ministerial Decision No. 244 of 2025 (PDF) · Ministerial Decision No. 66 of 2026 (PDF)
- Programme overview and document library — Ministry of Finance, eInvoicing
Verified 15 September 2026 against the Ministry of Finance's published PDFs, re-downloaded on the date of verification. The eleven steps and the responsibility table are the Ministry's own, reproduced in its order and wording; the reading of step 4 and step 7 offered here is ours. The endpoint values are quoted from chapter 10 of the guidelines — the deemed supply endpoint appears there with an internal space in the source text and is reproduced here without it, matching the form used for the other two. Detailed field-level requirements are fixed by Peppol's PINT-AE billing specification rather than by the guidelines, and we have not reproduced them.
Related
- Nine VAT rules change on 1 October 2026 — cash payments, employee accommodation, bundled supplies. The rate stays at 5%.
- eInvoicing below AED 50 million — the scope rule that has nothing to do with VAT registration, and your date.
- Choosing an accredited provider — half the Ministry's own checklist is already answered by the badge.
- Electronic credit notes — the four cases where one is compulsory, including a clerical error.
- The mandatory fields — what the XML has to carry.
- Self-billing and VAT groups — the 24-month intra-group grace period, the TIN each member needs, and why the buyer has to be live before it can self-bill you.
- Charges, currency and rounding — the one place rounding is allowed, which day's Central Bank rate converts a foreign-currency invoice, and where a municipality surcharge belongs.
- The penalties — including the AED 1,000 a day for not reporting an outage, which falls on both sides of the transaction.
- VAT calculator — the 5%, the thresholds, and the timetable in short.