5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Poland

The KSeF audit trail: documenting every automated operation, and what the system does not keep for you

KSeF holds the invoices it accepted and the numer KSeF it assigned to each one. It holds nothing about the attempts that failed, the reason your system issued outside the system under tryb offline24, or who inside the group authorised an unusual document — and those are precisely what a group auditor asks for. The gap is not a defect in the Polish system; it is a division of responsibility. The register is the record of invoices. The record of operations is yours, and most organisations discover they do not have one at the moment it is worth the most.

Also available in Polski

How Barzel applies here Start free with BarzelVault

Which entities in a group are actually caught?

Before any of this becomes an engineering question, settle the scoping question, because group finance functions routinely get it wrong in both directions.

The test is establishment in Poland, not Polish VAT registration. Taxpayers with neither a seat (siedziba) nor a fixed establishment (stałe miejsce prowadzenia działalności gospodarczej) in Poland sit outside the obligation to issue faktury ustrukturyzowane (structured invoices). Where a foreign-established company does have a Polish fixed establishment, the question becomes whether that establishment participates in the supply. A German or British group company holding a Polish VAT number for distance sales, with no people and no premises in Poland, is in a materially different position from the same group's Polish branch that actually makes the supply.

That boundary is not a Polish invention. Poland introduced mandatory e-invoicing under Council Implementing Decision (EU) 2022/1003 of 17 June 2022, whose Article 1 authorised Poland to accept only electronic invoices issued by taxable persons established in the territory of Poland, and which runs to 31 December 2026. The same limit now sits in the VAT Directive itself: Article 218, as amended by Council Directive (EU) 2025/516 of 11 March 2025, lets a Member State require taxable persons established within their territory to issue electronic invoices for domestic supplies. If your group is mapping e-invoicing obligations across several Member States, that phrase is the one to align your entity register against.

Two practical consequences follow for a group finance function. First, the obligation attaches to the Polish taxpayer, not to the system that operates on its behalf: a shared service centre in Kraków, Lisbon or Bangalore does not become the obliged party, and neither does your software vendor. Second, the obligation to receive structured invoices reached all taxpayers on 1 February 2026, two months before the general issuing obligation on 1 April 2026, so an entity can be inside the receiving population and outside the issuing population at the same time. Get those two lists separately, and check them against the Polish wording rather than an English summary.

Why are application logs not a KSeF audit trail?

Most organisations that believe they have an audit trail for their KSeF integration have application logs with thirty days of retention. Four differences make the two irreconcilable.

PropertyApplication logAudit trail
RetentionDays or weeks, rotated automaticallyMatched to the retention period of the documentation
Resistance to changeA file like any otherImmutable, or modification is detectable
CompletenessDepends on a log level that gets changedGuaranteed for a defined set of events
LinkageA timestamp and a messageA durable link to document, operation and decision-maker

The third row is the insidious one. Log levels are lowered in production when logs consume too much disk and raised again when someone is diagnosing a problem. A record whose completeness depends on a setting changed without a formal procedure is not evidence, whatever it contains.

What exactly should the record contain?

This is the minimum set for a single operation against KSeF. Each item answers a question that can actually be asked.

Identity of the operation

  • Operation identifier — durable, assigned before the first attempt, identical across every retry. It is what binds several attempts into one event; see duplicates and retries.
  • Source document identifier in the system the invoice came from.

Origin

  • Who or what initiated it — a user, a batch process, a partner integration, an AI agent. The name of a technical account is not enough if five different processes share it, which in a group ERP they usually do.
  • Calling context — job, run, session.

Content

  • The material parameters: counterparty, amount, issuing mode.
  • A digest of the transmitted document, which lets you show that what is in the register is what you sent, without keeping a second copy of the invoice inside the trail.

Authorisation

  • Whether approval was required, and if so who gave it, when, and on what basis.
  • The policy applied and its version. Policies change; the evidence has to point at the one in force at the moment of the operation, not the one in force when the auditor asks.

Outcome

  • Start and finish timestamps.
  • Result — accepted, rejected with an error code, or no response at all.
  • Numer KSeF and UPO on acceptance.
  • Issuing mode — online, or the specific offline mode, with the basis for the decision.

What does KSeF not keep for you?

Worth stating plainly, because integration teams often assume the register is the system of record for more than it is. KSeF does not retain:

  • Attempts that did not result in an accepted invoice. A call that timed out and was never resolved leaves no trace you can retrieve later from the register side.
  • Why an invoice was issued offline. The four modes carry different deadlines — tryb offline24 under art. 106nda, transmission by the next working day after the date of issue; the niedostępność (announced unavailability) mode under art. 106nh, next working day after availability is restored; the awaria (announced failure) mode under art. 106nf, seven working days from the failure being removed; and total failure, where invoices are not transmitted at all. Which one applied, and on what evidence, exists only in your records.
  • Whether an announced unavailability was actually in force at the moment you relied on it. Announcements appear in the Ministry's Biuletyn Informacji Publicznej and in the system interface; a system that does not capture their state at the time of issue cannot demonstrate it afterwards.
  • The approval. Nothing in KSeF records that a human authorised an unusual document before it went.
  • The mapping to your ERP. The invoice is in KSeF, the document is in SAP or Dynamics, and the link between them was created in an integration layer that keeps no history. From 1 January 2027 this becomes more visible rather than less: art. 108g requires the numer KSeF in the payment reference for a structured invoice, which pushes the mapping into the settlement process where a mismatch is noticed by counterparties.

What does a group finance function have to do differently?

A domestic Polish filer and a multinational face the same statute and different operational problems. Five differences are worth planning for.

The evidence has to be readable by people who do not read Polish. A group auditor in London or Frankfurt will ask for the population of invoices issued outside KSeF in the period, the reason for each, and proof each was transmitted within its deadline. If that answer lives in a Polish-language ticketing queue, you will spend the inspection translating rather than answering. Store the mode, the basis and the deadline as structured fields, not as free text.

Segregation of duties gets harder, not easier. KSeF certificates carry identity and no permissions — permissions are administered separately — so an access review that inspects certificates alone tells you nothing about who can issue an invoice. Two mutually exclusive certificate types exist: Authentication (keyUsage Digital Signature) and Offline (keyUsage Non-Repudiation, used to sign the second QR code on offline invoices). Your group access-control model needs both facts in it.

Someone has to own the credentials. If the ERP is run centrally and the KSeF token belongs to the Polish entity, decide explicitly who holds it, who rotates it and who is accountable when it is used. This is an intercompany control question before it is a technical one.

Retention runs on the documentation clock, not the infrastructure clock. The operational record for an invoice should remain available as long as the invoice itself must be. The practical consequence: it cannot live where the diagnostic logs live, or it inherits their rotation policy.

The Polish text governs. Group policies drafted in English, however carefully, are a translation of the obligation and not the obligation. Where this page and the Polish statute differ, the statute wins. Where your Polish adviser and this page differ, your adviser wins.

What changes when an AI agent is in the loop?

Where an operation is initiated by an AI agent, the minimum set needs two fields a deterministic process does not require:

  • The inputs the decision was based on — not the whole conversation history, but the data that led to the call.
  • The model and configuration version in force at the moment of the operation.

The reason is practical. A deterministic process can be reproduced by running the same code over the same data. An agent cannot: the same prompt against the same model may produce a different result, and the model may have been swapped out since. Without the version, you cannot even establish whether the behaviour was correct at the time. This is the same control problem covered in general terms under AI agent audit trails and approving AI actions; KSeF simply makes the consequences non-reversible, because an accepted invoice cannot be deleted.

How do you test whether the trail actually exists?

The fastest way to find out whether the audit trail is real or merely documented. It needs no preparation and takes about a quarter of an hour.

  1. Pick a random invoice from at least three months ago. At random — not one you know went through cleanly.
  2. Reconstruct: what triggered it, with which parameters, at what time, in which mode, whether there were earlier failed attempts, who or what approved it, which numer KSeF it received and which UPO.
  3. Do it without the application logs and without asking a developer.

Reading the result:

  • Under five minutes, from one place — the audit trail works.
  • Fifteen minutes, across several systems — the data exists but is not a trail; against an inspection covering hundreds of documents it does not scale.
  • Requires a developer or a restore from backup — there is no trail.
  • Cannot establish whether there were earlier failed attempts — the most common result, and the one that hurts most, because failed attempts are exactly what the duplicate question turns on.

Run it on one entity per quarter rather than on the whole group once. The failure modes differ by country of operation, by ERP instance and by who built the integration.

What is the trail worth in money?

From 1 January 2027, the penalties in art. 106ni of the VAT Act begin to apply — paragraphs 1 to 3 and 5 to 7; before that date only paragraph 4, on criminal proceedings, was in force. The ceilings are 100% of the tax shown on an invoice issued outside KSeF and, where no tax is shown, 18.7% of the total amount due. Throughout 2026 there is no sanction for issuing outside the system or for errors, which makes the remaining months the cheapest time to build evidence.

Those are ceilings, not fixed rates. The Ministry of Finance has consistently declined to lower them on the ground that a mitigating mechanism already exists: art. 189d of the Kodeks postępowania administracyjnego obliges the authority to take account of the gravity and circumstances of the breach, its frequency and the party's previous conduct.

That is the whole value of an audit trail expressed financially. The argument the breach was isolated, it followed an outage, we found it ourselves within a day and we fixed it works only where it can be proved with a record that could not have been assembled after the fact. Without one, what remains is the breach and the upper limit.

A note on searching for this in Polish

If you or your advisers search Polish-language material, the two obvious search terms return two different worlds. E-faktura in general usage means any electronic invoice, including PDFs sent by email; faktura ustrukturyzowana is the statutory term for an invoice issued through KSeF in the mandated logical structure and assigned a numer KSeF. Only the second is about the mandate. The glossary sets out this and the rest of the Polish vocabulary — numer KSeF, UPO, tryb offline24, awaria, niedostępność — with English glosses.

One correction worth carrying into any group briefing: there is no KSeF deferral for micro-entrepreneurs. They came into the obligation on 1 April 2026 like everyone else. The parliamentary bill that would have excluded them until 31 December 2027 — Sejm druk nr 2321, tabled 13 February 2026 — stalled after its first reading on 13 March 2026 and was not passed, yet it is still cited as binding law, including in advisory material. See the running list of corrections.

In practice

BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, for operations run by processes and by AI agents alike. It records the attempt before the call leaves the system, which is the part of this set that cannot be reconstructed afterwards.

How Barzel applies here

Frequently asked questions

Is a foreign company with a Polish branch in scope?

The test is establishment, not VAT registration. Taxpayers with neither a seat nor a fixed establishment in Poland are outside the issuing obligation; where there is a Polish fixed establishment, whether it participates in the supply decides the answer. Check the position of each entity against the Polish wording.

Do application logs count?

No. They rotate, they can be edited, their completeness depends on a setting that is changed in production, and they usually do not link an operation to the source document.

What must the record contain?

Operation identifier, source document, initiator, parameters, timestamps, result, numer KSeF, UPO, issuing mode, and the approval details where approval was required.

How do I know whether it works?

The fifteen-minute test above: a random invoice from three months ago, reconstructed in full, without logs and without a developer.

How is an audit trail different from a backup?

A backup restores a state. An audit trail reproduces the sequence of events and decisions that led to that state, with their cause and their author.

Do we have to keep every XML we sent?

Not inside the trail. A cryptographic digest is enough to show that the document in the register is the one you transmitted. The invoice itself is subject to its own retention rules.

Related reading

In practice

The control has to run before the invoice becomes irreversible.

An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.

95 days leftKSeF penalties apply from 1 January 2027

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. Ustawa o podatku od towarów i usług (Polish VAT Act), art. 106ga, art. 106ni, art. 108g — ISAP.
  2. Kodeks postępowania administracyjnego (Code of Administrative Procedure), art. 189d — ISAP.
  3. Ustawa z dnia 5 sierpnia 2025 r. o zmianie ustawy o podatku od towarów i usług oraz niektórych innych ustaw, Dz.U. 2025 poz. 1203.
  4. Ministerstwo Finansów, Zakres obowiązkowego KSeF — ksef.podatki.gov.pl.
  5. Ministerstwo Finansów, KSeF technical documentation — github.com/CIRFMF/ksef-docs.
  6. Council Implementing Decision (EU) 2022/1003 of 17 June 2022, OJ L 168, 27.6.2022, p. 81 — authorisation limited to taxable persons established in the territory of Poland, applying until 31 December 2026.
  7. Council Directive (EU) 2025/516 of 11 March 2025 amending Directive 2006/112/EC as regards VAT rules for the digital age — amended Article 218.

This article is for information and does not constitute tax or legal advice. The Polish text of the instruments cited is the binding one.