Phase two of the ZATCA e-invoicing programme moved Saudi companies from generating compliant invoices to integrating with the Authority: standard tax invoices are cleared in real time, simplified invoices are reported within a day, and every document carries a cryptographic stamp and a QR code. Odoo supports this. Whether your implementation does depends on decisions made weeks before go-live.
The six checks we do not skip
- Entity and branch setup: the commercial registration, VAT number and address on every invoice match the ZATCA portal exactly, per branch.
- Device onboarding: the EGS unit is enrolled with a production CSID, and the renewal date is in someone’s calendar.
- Clearance versus reporting: B2B standard invoices are configured to clear before they reach the customer; B2C simplified invoices report within the 24-hour window.
- Invoice content: line-level VAT categories, exemption reasons, and the buyer identification fields that phase two made mandatory.
- Credit and debit notes: they reference the original invoice and carry the reason; this is where most rejections come from.
- Sandbox first: every invoice type is tested against the ZATCA sandbox, and the rejection log is reviewed, before the production switch.
Where the data lives
Saudi clients ask this before anything else, and they are right to. Under the Personal Data Protection Law, client data should stay on the client’s own systems. Our Odoo implementations keep the ledger on the client’s instance; MFT and the MFT Intelligence agents read it through the API at query time and do not copy it out of the Kingdom.
After go-live
Compliance is not a state, it is a monthly check. The Tax and compliance agent in internal validation at MFT reconciles the sales ledger against what was cleared and reported, so a gap shows up before the Authority finds it. Until it is promoted, our accountants run the same reconciliation by hand as part of the monthly review.