Every other guide here is written for the person issuing an invoice. This one is for the same person an hour later, working through the supplier invoices that arrived this month and deciding which support a claim for input VAT. You cannot validate someone else's document, but a few minutes at filing catches the two problems that cost a buyer money: the wrong kind of document, and one that does not carry your details.
Why this is the buyer's problem at all
Saudi e-invoicing has two documents. A standard tax invoice (B2B and B2G) is cleared by the Authority before the seller may hand it over, and carries the buyer's name, VAT number and address. A simplified tax invoice (B2C) goes to the buyer immediately, is reported within 24 hours, and carries no buyer block.
The consequence lands on you, not the seller: a VAT-registered buyer cannot deduct input VAT from a simplified invoice. When the company card pays and the supplier prints a simplified receipt, that document is not defective — it is the wrong one for your purpose. Ask, before paying if you can, for a standard tax invoice made out to the company, with your VAT number and address on it. Standard vs simplified settles which is owed.
The fastest check: scan the QR code
The QR code at the foot of a Saudi e-invoice is not a link. It is a Base64 string of TLV fields — tag, length, value — and the count tells you which phase produced it. Phase 1, mandatory since 4 December 2021, carries five: seller name, seller VAT number, timestamp, total with VAT, VAT total. Phase 2 adds the hash of the XML, the ECDSA signature and the public key of the stamp. Eight fields, not five.
Our QR code reader is free and needs no sign-in: drop in the supplier's PDF, an image or a screenshot, or point a phone camera at the code. Decoding runs inside your browser, so nothing is uploaded. Back come the phase and the five readable fields as the seller's system stored them, worth holding against the printed page, plus flags for a malformed seller VAT number, an invalid timestamp, or a VAT amount that is not 15% of the total — information rather than a fault, since exempt and zero-rated lines make it normal.
What to read off the page by eye
| Check | What good looks like | Why it matters |
|---|---|---|
| Your company name | The registered name, not an employee's | An invoice made out to a person is not made out to your business |
| Your VAT number and address | Correct, on a standard invoice | A wrong one means a reissue, not a pen correction |
| Seller VAT number | 15 digits, first and last digit 3 | Malformed rejects at issuance (BR-KSA-40, error) |
| Seller name and address | Registered name, six national address elements | Incomplete is a defect, not a rejection (BR-KSA-09, warning) |
| Invoice number, date, time | All three, time included | The time is its own field, and required (BR-KSA-70, error) |
| VAT shown | Taxable amount, rate and VAT stated | You deduct a stated figure, not a derived one |
| The totals | Lines, total before VAT, VAT, total with VAT | Arithmetic that does not close means a hand-built document |
| A QR code | Present, and scannable | A square that decodes to nothing is not a compliant QR |
One line there is yours rather than theirs: no supplier can guess your VAT number. And a supplier still on Phase 1 is their compliance problem, not yours — Phase 2 arrives in waves. What matters to you is a standard tax invoice with your details on it.
What the check establishes, and what it does not
| The scan tells you | The scan does not tell you |
|---|---|
| Which phase produced the document | That the Authority cleared or received it |
| What the issuing system wrote into the code | That those values match the underlying XML |
| That a signature and a public key are present | That the signature is cryptographically valid |
The right-hand column is where an honest check turns into an overclaim. Our reader labels a ninth field where one is present, the Authority's signature over the public key added when a standard invoice is cleared — but that too is read out of the document, not from the Authority. The scan is a filter for wrong-phase and wrong-shape documents, nothing more. Where an invoice must be certain, ask the supplier and treat zatca.gov.sa as the authority; the free VAT number lookup shows the establishment behind the number.
Common problems, and what to ask for
- A simplified receipt where a standard invoice was needed. Ask for a standard tax invoice carrying your VAT number and address.
- Your VAT number missing, or somebody else's. Send yours in writing, and ask for a corrected document.
- The seller's number malformed. Often a commercial registration number printed in the VAT box.
- No issue time, only a date. Minor alone, and a reliable sign of a document assembled by hand.
- A PDF with no signed XML behind it. The six-year retention obligation, in the format issued, sits with the issuer — so ask.
- Totals that do not add up. Do not reconcile it in a spreadsheet and file it anyway.
What not to ask for
Do not ask a supplier to edit or delete an invoice they have already issued: a cleared or reported document cannot be withdrawn, and the request puts them in a worse position than the mistake did. The correction is a second document referencing it — a credit note (381) if the amount falls, a debit note (383) if it rises, with a reason and a reference. The reason is required (BR-KSA-17, error); a missing reference comes back as a warning alongside acceptance (BR-KSA-56), a gap nobody notices for a year. Credit and debit notes walks the path. VAT itself falls due at the earlier of supply, invoice or payment, so a correction adjusts that event rather than moving it.
If you have just recognised your own invoices
Most people who get this far recognise their own documents somewhere in the table: no issue time, a district missing from the address, a buyer block copied off an email signature. The requirements checklist is the same list from the issuing side, with the rule behind each field.
If you would rather not maintain that yourself: ZATCA Tools connects to Fatoora in minutes with one OTP, signs every invoice with a compliant QR code, clears standard invoices and reports simplified ones, and keeps the signed XML downloadable for six years. Rejections arrive with the official code and a link to its guide — 135 documented, two dozen in full. It also issues quotations, credit and debit notes, receipt vouchers, statements and per-branch devices. Integrations: WooCommerce, Shopify, n8n, WHMCS, a REST API and a Partner API. It is not an accounting system. Free during the launch period, starting at 50 invoices and expanding — start here.