✓ Last verified: 15 September 2026 · UAE Electronic Invoicing Guidelines V1.1 (1 June 2026), chs. 5, 10 · Ministerial Decision No. 243 of 2025, Arts. 6, 8, 10, 11

Your invoice reaches the tax authority before it reaches your customer.

The UAE did not build a portal you upload invoices to. It adopted a decentralised Peppol network with five corners, and the fifth corner is the Federal Tax Authority. The Ministry's own framework puts the report to the FTA at step 4 of 11 — in parallel with transmission to the buyer's provider, and three steps before the buyer sees the document at all. Understanding the order of those steps is the difference between reading a confirmation message correctly and guessing at it.

The five corners

CornerWho
Corner 1Supplier — you, when you are selling
Corner 2The supplier's Accredited Service Provider
Corner 3The recipient's (buyer's) Accredited Service Provider
Corner 4Recipient — the buyer
Corner 5The Federal Tax Authority

Four-corner Peppol models are the international norm: sender, sender's provider, receiver's provider, receiver. The UAE added a fifth. Everything unusual about the local regime follows from it.

The eleven steps, in the Ministry's order

#What happens
1The supplier (C1) submits invoice data to its provider (C2), in whatever format the two of them have agreed.
2C2 validates that data and converts it into the UAE standard electronic invoice in XML — if it did not already arrive in that form.
3C2 transmits the XML invoice to the buyer's provider (C3).
4In parallel, C2 reports the tax data to the FTA (C5).
5On validating the invoice, C3 sends an electronic confirmation back to C2.
6C3 delivers the invoice to the buyer (C4), in a format the two of them have agreed.
7On successful validation, C3 also reports tax data to C5. On unsuccessful validation, C3 confirms the failure electronically to C2 and to C5 — and reports no tax data.
8C5 confirms to C2 once the tax data has been successfully reported.
9C5 confirms to C3 once its tax data has been successfully reported.
10C2 forwards the confirmations it received to the supplier (C1).
11C3 forwards the confirmations it received to the buyer (C4).

Step 4 is the one worth rereading. The supplier's provider reports to the FTA in parallel with sending the invoice onward — not after the buyer accepts it, and not at the end of a period. By the time your customer's accounts payable team has even seen the document, the tax data is already with the Authority. There is no window in which an invoice has been "sent but not yet declared".

Step 7 is the other one. Tax data is reported twice for a healthy invoice — once by each provider — which is how the FTA reconciles the two sides of a transaction. When the buyer's provider cannot validate the document, that second report simply does not happen, and instead a failure confirmation goes to the supplier's provider and to the Authority. So a failed invoice is not silent: the FTA learns about the failure by design.

Note what the steps do not include: an approval gate. Nothing in the framework waits for the FTA to clear an invoice before it moves. The confirmations at steps 8 and 9 are acknowledgements that reporting succeeded, not permissions to issue. This is a reporting model, not a clearance model — which distinguishes it from several regimes in the region that UAE businesses are often told to benchmark against.

There is no QR code

Guidelines V1.1 is unambiguous: electronic invoices are issued, transmitted and received in XML format and will not feature a QR code or barcode. The contents are set by Peppol's PINT-AE billing specification, and they vary by document type and by scenario.

This matters because the most common mental model a UAE business brings to eInvoicing comes from neighbouring implementations where a QR code on a printed or PDF invoice is the visible artefact of compliance. Here there is nothing to print and nothing to scan. The compliant document is the XML that moved between the providers; anything human-readable your system renders from it is a convenience, not the invoice.

What your provider does not do for you

Appointing an accredited provider does not move the obligation. The guidelines set out the split directly, and the footnote to their table is blunt: providers are engaged to carry out these activities in practice, "although the compliance obligation remains with the supplier (or buyer in the case of self-billed invoices)."

ActivitySupplierBuyerProvider
Exchanging and reporting invoices, including receiving confirmation messagesYesSelf-billed onlyNo
Calculating all electronic invoice valuesYesSelf-billed onlyNo
Secure transmission using encryptionNoNoYes
Agreeing business-specific data security requirements with providersYesYesNo
Obtaining the buyer's Peppol participant identifierYesNoNo
Looking up a participant identifier once providedNoNoYes
Generating a UUID for every invoice, so no invoice can be duplicatedNoNoYes

Row five is a master-data project disguised as a technical detail. Contacting each buyer and gathering their Peppol participant identifier is the supplier's job, not the provider's — the provider only looks up an identifier you have already supplied. For a business with a few hundred B2B customers, that is a data-collection exercise with a deadline attached, and it is the single most common reason an otherwise finished implementation cannot send anything. Your participant identifier is your TIN: the first 10 digits of your TRN. If you are in scope but not registered for any tax type, you must register with the FTA purely to obtain one. And if you are part of a tax group, it is the first 10 digits of your own TRN, not the group representative's.

The three endpoints for a buyer who has no identifier

The obvious objection to a network built on participant identifiers is that some counterparties will not have one. The guidelines answer it with three predefined endpoints, each for a specific situation.

SituationEndpoint to use
Deemed supply — no identifiable recipient address0235:9900000097 (does not vary with the supplier)
Buyer has not yet implemented eInvoicing and has no participant identifier0235:9900000098
Export — buyer outside the UAE with no Peppol ID0235:9900000099

Each is described as mandatory in its situation, not as a fallback of last resort. Two consequences follow.

  • You must still send a PDF. Where the buyer has not yet implemented eInvoicing — because their phase has not begun and they have not volunteered — the guidelines state that regular tax invoices, for example in PDF, are required in addition to electronic tax invoices. Through the transition you are running two invoice streams for some customers, not one. A Phase 1 supplier live from January 2027 will be doing this for most of its smaller customers until July 2027.
  • Deemed supplies may never be exchanged at all. Where an invoice for a deemed supply is not issued to a recipient, there is no exchange of electronic invoices — only reporting to the FTA by the supplier's provider. The network carries the tax data and nothing else.

The Authority can access the data, and share it

Article 10 of MD 243 grants the FTA power to access and use any data processed, received and stored under the system. It also permits the Authority, subject to the Tax Procedures Law and its executive regulations, to share that data with other government entities and with foreign government bodies, in implementation of the UAE's obligations under any international agreement, treaty or arrangement to which it is a party.

That is a narrower power than it first reads — it is tied to treaty obligations rather than to general discretion — but it is worth knowing that transaction-level data now exists in a form that can move across borders under an exchange-of-information arrangement, where previously the FTA held only periodic returns.

Where the records live afterwards

Article 11 requires storage of electronic invoices, electronic credit notes and associated data for the periods in the Tax Procedures Law: 5 years following the tax period for a taxable person, 5 years from the end of the calendar year of creation for anyone else, 7 years for real estate records, with 4 extra years during a dispute or audit and 1 extra year after a voluntary disclosure made in the fifth year.

Appendix 4 of the guidelines then makes three clarifications that matter operationally. There is no requirement to store at a particular layer of the network — Corner 1 and Corner 4 storage are not mandated; any compliant arrangement works provided the data is retained, its integrity preserved, and the records producible to the Authority on request. Your provider may store the data for you by contract, but the legal obligation does not move with it — the person remains ultimately responsible. And providers must inform you on an event-driven basis, without undue delay, that documents have been successfully transmitted to the Authority. The transactional logs the provider keeps — transmission statuses, routing information, unique transaction identifiers — are its own compliance artefact under the OpenPeppol agreement and the UAE Peppol Authority Specific Requirements, and are expressly not the business document data you have to retain under Article 11.

Two questions to put to a provider that follow directly from the model. First: how are the step 8 and step 9 confirmations surfaced to me, and what do I see when step 7 fails — a failed validation at the buyer's end is the scenario where you find out whether a provider's interface is designed or improvised. Second: what happens to an invoice addressed to 0235:9900000098 when that customer later gets a real identifier. The rest of the provider questions are here — with the ones accreditation already answers for you.

Frequently asked questions

What is the five-corner model in UAE eInvoicing?

It is the framework under which electronic invoices are issued and distributed in the UAE. Corner 1 is the supplier, Corner 2 the supplier's Accredited Service Provider, Corner 3 the recipient's provider, Corner 4 the recipient, and Corner 5 the Federal Tax Authority. It extends the standard four-corner Peppol model by adding the tax authority as a participant that receives reported tax data.

When does the FTA receive my invoice data?

At step 4 of the Ministry's eleven-step framework — in parallel with the transmission of the invoice from your provider to the buyer's provider, and before the buyer has received the document. The buyer's provider then reports tax data separately at step 7 if its validation succeeds, so a healthy transaction is reported from both sides.

Does the FTA approve an invoice before it is sent?

No. The UAE model is a reporting model, not a clearance model. Nothing in the eleven-step framework waits for the Authority to clear an invoice before it moves to the buyer. The confirmations the Authority sends at steps 8 and 9 acknowledge that tax data was successfully reported; they are not permission to issue.

What happens if the buyer's provider cannot validate my invoice?

Under step 7 of the framework, the recipient's provider confirms the unsuccessful validation electronically to the supplier's provider and to the Federal Tax Authority, and in that case reports no tax data to the Authority. The failure is therefore visible to the Authority by design rather than being a silent gap.

Does a UAE electronic invoice have a QR code?

No. Guidelines V1.1 states that electronic invoices are issued, transmitted and received in XML format and will not feature a QR code or barcode. The invoice is the XML exchanged between the accredited providers; any human-readable rendering of it is a convenience, not the compliant document.

What is my participant identifier for UAE eInvoicing?

Your Tax Identification Number, which is the first 10 digits of your TRN. If you are in scope but not registered for any tax type, you must register with the Federal Tax Authority to obtain a TIN. If you are part of a tax group, your identifier is the first 10 digits of your own TRN, not the first 10 digits of the group representative's.

Who has to collect the buyer's Peppol identifier — me or my provider?

You. The Ministry's responsibility table assigns contacting the buyer and gathering their Peppol participant identifier to the supplier, and assigns only the lookup of an identifier already provided to the Accredited Service Provider. Generating a UUID for each invoice and encrypting transmission are the provider's jobs; calculating invoice values and receiving confirmation messages remain yours.

What do I do if my customer is not on the eInvoicing system yet?

Use the predefined endpoint 0235:9900000098 on the electronic invoice, which the guidelines make mandatory where the buyer has not implemented eInvoicing and has no participant identifier. You must also continue to issue that customer a regular tax invoice — for example a PDF — in addition to the electronic one, until they are live.

Which endpoint is used for exports and deemed supplies?

For exports where the buyer has no Peppol ID, the predefined endpoint 0235:9900000099 must be included. For deemed supplies, the buyer electronic address is always 0235:9900000097, and that value does not change with the identity of the supplier. Where an invoice for a deemed supply is not issued to a recipient, there is no exchange of electronic invoices at all — only reporting to the Authority by the supplier's provider.

Can the FTA share UAE eInvoicing data with other countries?

Article 10 of Ministerial Decision No. 243 of 2025 gives the Authority power to access and use data processed, received and stored under the system, and — subject to the Tax Procedures Law and its executive regulations — to share it with other government entities or foreign government bodies pursuant to the UAE's obligations under an international agreement, treaty or arrangement to which it is a party.

Can my provider store my electronic invoices for me?

Yes, where that is agreed contractually, but the delegation does not transfer the legal obligation — Appendix 4 of Guidelines V1.1 states that the person remains ultimately responsible for compliance with the retention requirements. There is also no requirement to store at any particular layer of the network, provided the data is retained for the required period, its integrity and security preserved, and the records made available to the Authority on request.

Sources

Verified 15 September 2026 against the Ministry of Finance's published PDFs, re-downloaded on the date of verification. The eleven steps and the responsibility table are the Ministry's own, reproduced in its order and wording; the reading of step 4 and step 7 offered here is ours. The endpoint values are quoted from chapter 10 of the guidelines — the deemed supply endpoint appears there with an internal space in the source text and is reproduced here without it, matching the form used for the other two. Detailed field-level requirements are fixed by Peppol's PINT-AE billing specification rather than by the guidelines, and we have not reproduced them.

Related