Saudi clearance and reporting XML · active

ZATCA FATOORA

Saudi Arabia’s e-invoicing system using UBL-based XML, security features, cryptographic stamping, hash chains and QR data during Phase Two integration.

UBL Invoice XMLPDF/A-3 with embedded XMLClearance/reporting response

Current version and implementation status

Version noteXML Implementation Standard 1.2 and associated security artefacts; verify current waves
Statusactive
Reviewed2026-08-02
FamilySaudi clearance and reporting XML
Open official technical source

How to recognize the profile

Do not rely on the file extension alone. Inspect the root namespace, customization/profile identifiers, version values and authority-specific envelope.

  • ZATCA UBL extensions
  • Invoice hash
  • Cryptographic stamp
  • TLV QR payload
  • ICV and PIH

Production validation stack

  1. 1
    UBL and ZATCA rules

    Confirm that the document is well formed and structurally compatible with the intended FATOORA syntax.

  2. 2
    Security features

    Apply semantic and business-rule checks rather than accepting a file merely because it parses.

  3. 3
    QR tags

    Validate currencies, countries, tax categories, units, payment means and other controlled values against the correct release.

  4. 4
    Clearance/reporting API response

    Apply the national, network or authority restrictions that narrow the base syntax.

EInvoiceLab’s browser tools provide detection, inspection and technical preflight. A profile is only production-valid after applying the correct official artefacts and obtaining the required network or authority outcome.

Common errors and corrective action

!
Invalid invoice hash

Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.

!
QR tag mismatch

Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.

!
Certificate/CSID issue

Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.

!
Business rule failure

Locate the relevant field and rule, correct the source mapping, rerun every validation layer, then preserve the final response.

Countries using or referencing this profile

Questions people ask

What is FATOORA?

Saudi Arabia’s e-invoicing system using UBL-based XML, security features, cryptographic stamping, hash chains and QR data during Phase Two integration.

How is FATOORA validated?

A production check normally applies UBL and ZATCA rules, Security features, QR tags, Clearance/reporting API response. Local browser preflight cannot replace the official validation artefacts or authority outcome.

Which version should I use?

The current research note is: XML Implementation Standard 1.2 and associated security artefacts; verify current waves. Confirm release notes at the official source before production deployment.

Practical tools

Inspect and prepare FATOORA files