Electronic Invoicing: Why Compliance Alone Won’t Secure B2B Payments
Electronic invoicing is changing status in France. Since September 1, 2026, every company must be able to receive dematerialized invoices, and the obligation to issue them is rolling out progressively: it already applies to large companies and mid-sized enterprises (ETI), before extending to SMEs and micro-businesses on September 1, 2027. For many finance departments, this project has mainly been treated as a matter of technical compliance: choosing the right platform, adopting the right format, securing the transition by the deadline. That reading isn’t wrong, but it’s incomplete.
The reform organizes how invoices circulate between companies. It does nothing to guarantee the reliability of the data attached to them. A misidentified supplier, an outdated or falsified IBAN, an impersonated company: these risks don’t disappear just because the invoice now passes through an accredited platform. They shift, and can even worsen, under the effect of digitalization itself. This article looks at the framework of the electronic invoicing reform, at what it actually covers, and at a question few companies are asking yet: what happens when the invoice is perfectly compliant, but the data about the third party receiving it is false?
Understanding France’s Electronic Invoicing Reform
A Phased Timeline Through 2027
The electronic invoicing reform rests on a timeline built in several stages. Since September 1, 2026, all VAT-registered companies in France must be able to receive electronic invoices, regardless of their size. The obligation to issue invoices in this format, however, applies on a staggered basis: large companies and mid-sized enterprises (ETI) have already had to issue their invoices in electronic format since that same date, while small and medium-sized businesses and micro-businesses have an extra grace period, until September 1, 2027.
This sequencing isn’t neutral for companies sitting between these two dates. An SME may well already be receiving electronic invoices from its major accounts as customers, while continuing to issue its own in a traditional format until the deadline that applies to it. Companies therefore have to operate, for several months, with two regimes coexisting at once, which complicates the reading of invoice flows and makes vigilance over the true origin of incoming invoices all the more necessary.
Standardized Formats and Accredited Platforms
Technically, the reform relies on formats recognized by the tax authorities: Factur-X, a hybrid format combining a readable PDF with structured data, along with the UBL and CII formats, which are better suited to automated exchanges between information systems. Invoices no longer pass directly from one company to another: they go through accredited dematerialization platforms known as PDPs (Plateformes de Dématérialisation Partenaires), themselves connected to a central public portal that gathers certain data for monitoring and control purposes.
This new technical circuit brings genuine standardization to these exchanges. But it also changes how a company perceives the reliability of an invoice. An invoice arriving via an accredited platform, in a recognized format, naturally inspires trust. That trust, however, applies to the channel and the format, not to the accuracy of the information the invoice contains, nor to the real identity of the issuer.
The Stated Objectives of the Reform
Fighting VAT Fraud and Simplifying Exchanges
The government justifies this reform through several complementary objectives. The first is budgetary: by generalizing the transmission of invoicing data to the tax authorities, the state aims to better detect VAT fraud, a phenomenon that represents a significant shortfall for public finances every year. The second objective is more operational: simplifying and automating invoice processing for companies, reducing manual data entry and processing delays. The third objective, finally, is to secure commercial exchanges by making invoice format and traceability more reliable.
These objectives are legitimate and address real issues. However, they concern the structure of the data and its administrative journey, rather than its accuracy at the point it reaches a company’s accounting or finance department. An invoice can perfectly comply with the Factur-X format, pass through an accredited platform, and still carry bank details that no longer match the usual supplier.
A Supported Transition, Not a Hard Cutoff
Aware of the scale of the change, lawmakers built in a right to error for the first year of application. Companies that make good-faith mistakes in implementing their obligations aren’t sanctioned immediately. This leniency is useful for absorbing the technical difficulties that are inevitable when rolling out a new system at national scale. It should not, however, be confused with a guarantee of security: the right to error covers the administrative compliance of the process, not the financial consequences of a payment made to a fraudulent third party.
Why Technical Compliance Isn’t Enough
A Valid Format Says Nothing About the Supplier’s Identity
This is the central, often underestimated, point of this reform: an invoice’s format and its issuer’s identity are two separate things. A perfectly structured Factur-X invoice can be issued in the name of a genuine supplier, but with bank details altered without that supplier’s knowledge. The accredited platform checks that the file meets the expected technical standards; it does not check that the IBAN listed actually belongs to the company supposedly issuing it. That verification still falls, today, to the company receiving the invoice and about to make the payment.
Bank Details That Can Be Outdated, Incorrect, or Fraudulent
A supplier’s bank details are not fixed over time. A change of bank, a merger, a business sale, a routine administrative update: all perfectly legitimate situations that can change an IBAN over the course of a business relationship. It is exactly this variability that bank-detail-change fraud exploits, posing as the usual supplier to redirect payments to an account controlled by a malicious third party. Digitalizing invoice flows does not reduce this risk: it can even make it harder to detect, since an invoice received through an official channel, in a standardized format, appears, by its very nature, more legitimate to finance teams.
A Supplier Base That Is Constantly Changing
This risk is compounded by a structural phenomenon many companies underestimate: a supplier base is never static. At Sis ID, market observation shows that a supplier base changes by an average of 20% every year, between new entrants, suppliers that cease trading, and changes to bank details. A supplier database that is checked once and never updated again quickly becomes obsolete, regardless of how technically compliant a company is with the invoice format itself.
Une digitalisation qui peut aussi nourrir la fraude
The DGFiP Data Breach, an Additional Risk Factor
Recent events concretely illustrate this risk. On August 14, 2026, the government confirmed that the DGFiP (France’s tax administration) had suffered a data breach, potentially exposing the tax and land-registry data of 678,000 businesses and individuals. By nature, this kind of incident feeds the databases that malicious actors can use to make their fraud attempts more credible: knowing a company’s tax number, address, or certain administrative details makes it possible to build far more convincing fraud scenarios than a generic email.
Toward an “Electronic Invoice Fraud”? The Accounting Profession’s Warning
This concern has been raised publicly by the accounting profession. Gilles Bösiger, chairman of the Paris Île-de-France order of chartered accountants, has warned of the risk of a new form of “electronic invoice fraud” emerging, built on the model of CEO fraud, and potentially fueled by data exposed in incidents such as the DGFiP breach. At this stage, this is a risk flagged by a recognized industry figure, not a phenomenon already measured at scale. It nonetheless deserves to be taken seriously, given how consistent the scenario is with already-known fraud mechanisms: identity theft, exploitation of real data, and excessive trust placed in a channel perceived as official.
What Case Law Says About Paying a Fraudulent Third Party
The Court of Cassation Ruling of June 17, 2026
On the legal side, a recent ruling serves as a reminder of the concrete consequences these situations carry for companies. In a ruling dated June 17, 2026, France’s Court of Cassation confirmed that payment made to a fraudulent IBAN does not discharge the debt. In other words, a company that pays an invoice in good faith, but into a bank account that does not belong to its real supplier, remains legally liable for that amount to its genuine supplier.
A Liability That Stays With the Paying Company
This case law places clear responsibility on the company making the payment: it is up to that company to ensure, before any transfer, that the bank details being used truly belong to its supplier. Compliance with the electronic invoicing format has no bearing on this point: a company can have scrupulously met every obligation of the reform and still end up having to pay the same invoice twice — once to the fraudster, and a second time to its legitimate supplier.
The Scale of Payment Fraud Risk in France
Fraud on the Rise, According to the Banque de France
Figures published by the Observatoire de la sécurité des moyens de paiement (OSMP), backed by the Banque de France, give a concrete measure of this risk. For 2025, total fraud across all payment methods reached €618 million, up 7% from 2024. This figure covers all payment methods, but wire transfers hold a particular place in companies’ concerns, since they account for the bulk of the amounts stolen in supplier fraud and bank-detail-change fraud.
More Targeted Transfers, Smaller Amounts
In the first half of 2025, the volume of fraudulent transfers rose by 107%, while the average amount per fraud case fell, dropping from €3,023 to €2,104. This shift reflects a change in method: rather than targeting a single, very large transfer, fraudsters are multiplying attempts involving smaller amounts, which are harder to spot among a company’s usual volume of supplier payments. This is exactly the type of fraud that digitalizing invoices, without stronger controls on third parties, risks facilitating rather than limiting.
Making Data Reliability the Natural Extension — and Solution — of Compliance
Verifying the Identity and Bank Details of Third Parties
Given this reality, the answer isn’t to question the electronic invoicing reform itself, whose benefits in terms of simplification and traceability are real. It is to treat technical compliance as a necessary step, but not a sufficient one. Verifying suppliers’ identity and bank details, before every payment and at regular intervals, becomes the essential complement to invoice digitalization. This is precisely the ground on which Sis ID operates, helping companies make their payment data more reliable and verify their third parties, beyond simply complying with the format and channel imposed by the reform.
Automating Controls to Support Digitalization Without Inheriting Its Risks
The challenge for companies now is to match the digitalization of their financial processes with an equivalent level of automation in their controls. Manually checking every supplier, on a base that changes by 20% a year, is no longer realistic at the scale of an organization processing hundreds or thousands of invoices. Automating consistency checks between declared data, registered bank details, and official third-party information makes it possible to keep the benefits of digitalization without inheriting its main weakness: excessive trust placed in a flow that now appears, on the surface, fully secure.
Electronic invoicing marks an important step in modernizing exchanges between French companies. It standardizes formats, centralizes part of tax oversight, and ultimately simplifies invoice processing for accounting teams. But it does not, on its own, resolve the question of the reliability of the data circulating within those invoices. The DGFiP breach, the accounting profession’s warning about a possible electronic invoice fraud, the recent Court of Cassation ruling, and the continued rise in transfer fraud all point to the same conclusion: technical compliance is a starting line, not a finish line. Companies that truly secure their B2B payments are the ones that pair this compliance with rigorous, ongoing verification of their third parties and their bank data.

