The French text is the legally binding one. This page is a working guide for a reader who does not read French; it is not a substitute for the instruments themselves, and wherever a decision turns on wording, the French wording governs.
What does the new architecture change?
Before the reform, issuing an invoice was a single-point event: the document left, usually by email, and its fate depended on the recipient. Now the chain has several actors and each of them can produce a state.
| Link | What it produces | Under your control |
|---|---|---|
| Source system (ERP, billing) | The document and its data | Yes |
| Integration layer | The call, the retries, the errors | Yes |
| Issuing plateforme agréée | Deposit, technical rejection | No |
| Annuaire (PPF, CGI art. 289 bis) | Routing to the recipient's PA | No |
| Concentrateur (CGI art. 242 nonies G) | Collection of data and statuses | No |
| Recipient's plateforme agréée | Making available, commercial refusal | No |
You own the first two rows. So the audit trail has to do one thing nobody will do for you: durably bind what you control to what the others hand back. A quick vocabulary note while we are here, because English-language coverage is still overwhelmingly wrong about it — since 27 July 2026 the term PDP is obsolete; the current term is plateforme agréée (PA). An opérateur de dématérialisation (OD) is not registered and cannot transmit on its own; it sits behind a PA, and if that is your arrangement, your evidence chain has seven links rather than six.
Which parts does a group outside France actually control?
Formally, the same two. In practice a multinational usually discovers that neither of them is where it thought.
The source system is often not French. The document is produced by a group ERP instance in Frankfurt, London or a shared service centre elsewhere, and the French entity only appears as a company code. The obligation, however, attaches to the unité légale identified by its SIREN. Evidence held at group level and not attributable to a single SIREN answers a question nobody asked.
The integration layer is often owned by a third party. Where a middleware supplier or an opérateur de dématérialisation sits between the ERP and the plateforme agréée, the retry history — the part that matters most — belongs to someone whose retention policy you did not write. Put the retention period in the contract, or accept that the most useful half of the trail is outside your control.
The platform contract may be a group contract. One plateforme agréée serving three French SIRENs is efficient, but it makes per-entity attribution a configuration question rather than a natural consequence. Ask, before signing, how transmission identifiers and statuses are attributed per SIREN and how they are exported.
A domestic filer with one entity, one ERP and one platform never meets any of this. That is why the local-language treatment of the subject stops at what to log; for a group, where the log lives and who can produce it is the harder half.
What has to be recorded?
Identity of the operation
- An operation identifier allocated before the first call, stable and deterministic, identical across every retry. This is what binds several attempts to a single event.
- The source document identifier in the system it came from, and the SIREN of the issuing legal entity.
Origin
- What triggered the operation — user, batch run, partner integration, AI agent. A technical account name is not enough if several processes share it.
- The execution context: job, run, session.
Content
- The significant parameters: recipient, amount, format chosen, document type.
- A fingerprint of the document transmitted, so you can establish that what was sent matches what the register says, without keeping a copy inside the trail itself.
Authorisation
- Where an approval threshold applied: who validated, when, and what was presented to them. That last point is what separates a defensible validation from a click.
- The policy applied and its version. Rules change; the evidence must name the one in force at the time of the facts.
Outcome
- Start and end timestamps.
- The result: deposit accepted, rejection with code, no response at all.
- The transmission identifier returned by the plateforme agréée.
- The lifecycle status returned, with its own timestamp.
What are the three technical requirements?
Write before the operation, not after
The operation initiated event has to be persisted before the call leaves the system. A trail written only when a response comes back keeps no record of the attempts that never returned — which is precisely what the questions are about.
Resistance to retroactive modification
Any mechanism that makes alteration detectable will do: a hash chain, where each entry carries the fingerprint of the previous one, needs no special infrastructure. The substance is elsewhere — the process that writes must not have the right to modify or delete. In a group, that means the service account used by the integration layer, not just the human operators.
Retention aligned to the document, not to the infrastructure
The audit trail for an operation must stay consultable for as long as the invoice itself. The practical consequence: it cannot share storage with diagnostic logs, or it inherits their rotation policy. For a group, add the cross-border version of the same rule — retention has to satisfy the longest applicable obligation across the jurisdictions the evidence serves, not the shortest.
Why are lifecycle statuses legal qualifications rather than receipts?
Consistently underestimated in automation projects. The four mandatory statuses — déposée, rejetée, refusée and encaissée — do not carry the same weight.
Rejetée is a technical rejection by a platform, for format or business-rule non-conformity: the document does not enter the circuit. Refusée is a commercial refusal by the recipient, and the administration states that this status must not be used for a simple commercial dispute. Three grounds for refusal are admitted, and three only: a regulatory non-conformity not caught by the receiving platform — typically the absence of the purchase order required under article L441-9 of the code de commerce — an unrecognised transaction, and a breach of contractual conditions preventing processing. The distinction is set out in our glossary entry, and the terminology corrections this library maintains are at corrections.
A system that automatically maps its internal error codes onto these normalised statuses is therefore not issuing acknowledgements: it is issuing qualifications. That mapping deserves to be audited in its own right, and the trail must keep both the originating internal code and the status emitted. Without that pair, a mapping error becomes undetectable after the fact — and the error is not cosmetic, because a wrongly issued refusée asserts something about the counterparty relationship that the company never decided.
What does the reconstruction test involve?
The fastest way to find out whether your audit trail exists in operation or only in the project documentation. It needs no preparation.
- Take an invoice at random issued at least three months ago — not one you know went through cleanly.
- Reconstruct: what triggered it, with which parameters, whether there were earlier unsuccessful attempts, whether human validation was required and what was presented to the validator, which transmission identifier and which final status.
- Do it without application logs and without asking a developer.
| Result | Reading |
|---|---|
| Under five minutes, from a single place | The audit trail works. |
| Around fifteen minutes, across several systems | The data exists but does not constitute a trail; at the scale of an audit covering hundreds of documents it does not hold. |
| Requires a developer or a restore | There is no audit trail. |
| Earlier failed attempts cannot be established | The most common result, and the most damaging — that is exactly what duplicate questions turn on. |
Run it once per French SIREN rather than once per group. The entity whose evidence fails is rarely the one whose systems were reviewed.
What changes when an AI agent initiates the operation?
Two further items become necessary that a deterministic process does not need:
- The input data the decision rested on — not the whole history, but what led to the call;
- The model version and the configuration in force at the moment of the operation.
The reason is mechanical. A deterministic process is reconstructed by re-running the same code over the same data. An agent is not: the same prompt against the same model can produce a different result, and the model may have been replaced in the meantime. Re-running does not reconstruct the original decision — it produces a new one. The wider treatment is in our note on what to record before an AI agent acts, and the France-specific version in keeping control when agents issue invoices.
What is this evidence actually for?
Three things, and it is worth being concrete because the trail is usually funded as a technical nicety.
Penalties. The fines raised by the loi de finances pour 2026 have applied since 1 September 2026: €50 per invoice for failure to issue electronically, capped at €15,000 a year (CGI, art. 1737), and €500 per transmission for failure to transmit e-reporting data, capped at €15,000 (CGI, art. 1788 D). Failure to use a plateforme agréée draws €500 after a three-month formal notice, then €1,000 every three months until regularised.
The tolérance de démarrage, which is not a postponement. The DGFiP has been explicit that it is neither a postponement nor a suspension of the obligation. Penalties apply; what the tolerance describes is that they are not applied immediately, automatically and blindly to businesses able to demonstrate good faith and corrective measures already under way. What protects you is not the calendar; it is the file. The audit trail is the file.
E-reporting evidence is a separate obligation with its own cadence. The transmission of transaction data — covering B2C operations, international operations with a taxable person not established in France, exports, intra-Community supplies and transfers, and payment data for supplies of services — is not routed to a counterparty and produces no lifecycle status coming back. Its evidence is therefore entirely yours to keep, and its rhythm follows the entity's VAT regime rather than the invoice: under the régime réel normal with monthly VAT, transmission is per decade, within ten days, which is three filings a month. A trail designed around returned statuses will silently have no coverage of this half.
The first-offence relief. No penalty applies to a first offence committed during the current calendar year and the three preceding ones, provided it is put right spontaneously or within thirty days of a first request. One protection, on a rolling four-year window, spent the first time it is used — and you cannot argue you have not used it if you cannot show what happened.
And the population needing this evidence is about to grow — on a date that is not settled. Smaller French entities join the issuing and e-reporting obligation on 1 September 2027, which multiplies the number of SIRENs whose trail has to stand up. That date should not be planned as fixed: every previous slippage in this reform arrived through a loi de finances, and the projet de loi de finances for 2027 had not been tabled as at 3 September 2026. Evidence design is among the work worth doing regardless, because it is not wasted if the date moves and it cannot be retrofitted to invoices already issued.
In practice
Where issuance is automated across systems, the evidence has to be written by whatever performs the action rather than reconstructed afterwards. BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, recording the policy version applied and what was presented to the approver. It exposes nine tools, and the receipt is written before the call rather than after the response.
Frequently asked questions
Are application logs enough?
Rarely. They rotate, they remain modifiable, and their completeness depends on a logging level adjusted in production. An audit trail must outlive them and resist modification.
What must be recorded for an automated issuance?
Operation identifier, source document and SIREN, trigger, parameters, timestamps, result, transmission identifier, returned status, and the validation data where a threshold applied.
Why keep the returned status?
Because rejetée and refusée carry different legal consequences and only three grounds for refusal are admitted. Keep the internal code and the emitted status together.
Which links does a foreign group control?
Two of six: the source system and the integration layer. The plateforme agréée, the annuaire, the concentrateur and the recipient's platform are not yours.
How do you check the trail works?
The reconstruction test above: a random invoice more than three months old, without logs and without a developer. Run it per SIREN.
Does the tolérance de démarrage remove the need for it?
No. It is neither a postponement nor a suspension. It protects businesses that can document good faith, which is what the trail produces.
In practice
The control has to run before the invoice becomes irreversible.
An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.
338 days leftPME, TPE and micro-entreprises: issuing and e-reporting from 1 September 2027
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- France's e-invoicing reform: what changed on 1 September 2026
- Factur-X, UBL and CII: choosing a format and what each costs downstream
- Keeping control when AI agents issue invoices into an irreversible national system
- The 2027 wave: what a smaller French entity of a foreign group needs ready
- AI agent audit trail: what to record before it acts
- Approving AI agent actions before execution
Sources
- CGI, art. 289 bis (annuaire) and art. 242 nonies G (concentrateur); art. 1737 and art. 1788 D (penalties).
- impots.gouv.fr, Spécifications externes B2B, version 3.2 of 30 April 2026 (lifecycle statuses and grounds for refusal).
- Décret n° 2026-677 and arrêté du 27 juillet 2026 (plateformes agréées), Journal officiel of 28 July 2026.
- Code de commerce, art. L441-9 (purchase order among the mandatory particulars).
- impots.gouv.fr, Facturation électronique et plateformes agréées.
- entreprendre.service-public.gouv.fr, news item of 20 February 2026 (penalty amounts).
- AFNOR standards XP Z12-012, XP Z12-013 and XP Z12-014 — paywalled, with no free official full text; not linked.
This article is for information and does not constitute tax or legal advice. The French text is the binding one.