# AI in French E-Invoicing: Compliance & Audit Trail Challenges

> Navigate the complexities of AI in French e-invoicing. Understand ISO 27001 scope, reliable audit trails, and data retention for compliance.

Published: 2026-10-03

Canonical: https://sygnet.ai/blog/ai-french-e-invoicing-compliance-audit-challenges

---

## Key takeaways

- ISO/IEC 27001 certification covers a **declared scope**, and for an approved platform (plateforme agréée) that scope is the part of the information system handling e-invoicing and e-reporting, not your upstream extraction stack. A certification never covers an entire company by default; the requirement targets the portion of the IS covering electronic invoicing and e-reporting.
- France's reliable audit trail obligation requires reconstructing the chain from the originating document to the invoice and back, uninterrupted, which means your AI extraction step is part of the evidence, not a black box.
- Changing the file format of an electronic invoice does not preserve integrity of content under Article 289-V CGI, so a pipeline that normalises, re-renders or re-encodes documents before archiving can invalidate probative value.
- Under the EU AI Act, deployers of high-risk AI systems must keep automatically generated logs for at least six months, far shorter than the six-year minimum retention for invoices and audit-trail control elements. Two retention clocks, one chain of evidence.

## Why does ISO 27001 on the platform not cover your extraction pipeline?

Because ISO 27001 certifies a management system over a defined boundary, and your extraction pipeline sits outside it. The certificate is a required piece of the DGFiP registration file under decree n° 2022-1299 of 7 October 2022, not a marketing label, and registration is granted for three renewable years, with a third-party conformity audit required. That audit examines the platform's ISMS. It does not examine the OCR service, the VLM, the prompt templates, the confidence thresholds, or the retry logic you run before handing a structured invoice to the platform.

The practical consequence is a seam. Your PA can produce a perfect, signed, timestamped record of what it received and transmitted. It cannot tell a tax inspector where the SIREN, the VAT rate or the line-item totals came from if your own system inferred them from a scanned PDF. The DGFiP does not issue the certificate itself: it is issued by an accredited body (COFRAC in France) after an independent audit, and the tax administration simply requires it as part of the file and then supervises the platform throughout its registration. Supervision of the platform is not supervision of your pipeline.

> The platform certifies the pipe. You still have to certify the water.

## What exactly does the reliable audit trail require from an AI step?

It requires an unbroken, documented link between the source transaction and the invoice line. The audit trail must allow the invoicing process to be reconstructed in a tax audit, from its origin (contract, quote, purchase order, delivery note) through to the invoice and the bank statement. Every operation must be justifiable by an originating document from which it is possible to follow an uninterrupted path to the invoice, and back the other way.

An AI extraction step breaks that path in three common ways. First, non-determinism: the same document processed twice can yield different field values if temperature, model version or prompt changes between runs, and nothing in the record says which run produced the archived figure. Second, silent correction: pipelines that auto-fix a VAT total to make it balance produce an invoice that no longer matches its source. Third, missing lineage: the output JSON is stored, the input page image is discarded or re-compressed.

The legal nature of this obligation is an obligation of means, which is good news for engineers: you are not required to be perfect, you are required to show documented, permanent controls. Documented means written down, versioned, and testable. See our notes on [measuring real invoice extraction accuracy](https://sygnet.ai/blog/invoice-ai-accuracy-testing-real-performance) for how to build that evidence instead of asserting it.

## Which pipeline design choices actually destroy probative value?

Format conversion before archiving, undocumented model upgrades, and logging that cannot be replayed. Article 96 I of annex III to the CGI requires invoices secured by reliable-audit-trail controls, and the constituent elements of those controls, to be kept in their original form and content by both issuer and recipient. Content must not be modified for the entire retention period of six years. Companies may change the format for management purposes, but only if they keep the original in parallel. Many IDP pipelines do the opposite by default: they ingest a PDF, rasterise it, straighten it, convert to PNG tiles for the model, and keep the derived artefacts.

Readability is the second trap. For structured formats such as XML or Factur-X, a visual PDF rendering must remain accessible. If your pipeline generates the human-readable layer at render time from extracted fields, that rendering changes when the extraction model changes. The "same" invoice looks different in 2029 than it did in 2026, and you cannot prove which version the counterparty received.

| Layer | Who certifies it | Evidence it must produce | Typical retention | Common failure |
|---|---|---|---|---|
| Approved platform (PA) | ISO/IEC 27001 required, plus third-party conformity audit, 2FA and no data transfer outside the EU | Transmission, directory lookup, e-reporting | 3-year renewable registration | Scope assumed to cover upstream systems |
| Archiving | Contractual / probative archiving | Original form and content | 6 years minimum | Derived formats stored instead of originals |
| AI extraction | Nobody, unless you do it | Model version, prompt, confidence, human override | 6 months under AI Act Art. 26(6) | Logs rotated before the tax clock runs out |

## How do the AI Act logging rules interact with French tax retention?

They impose a shorter floor on a longer obligation, and the shorter one wins by accident. Article 12 of Regulation (EU) 2024/1689 requires high-risk AI systems to technically allow automatic recording of events over the system's lifetime, with traceability appropriate to the intended purpose. Article 19 requires providers to keep those logs for at least six months, and Article 26(6) places the same minimum on deployers. Both duties were due to apply on 2 August 2026.

Six months of inference logs plus six years of invoice retention equals a five-and-a-half-year hole in your reconstruction capability. A 2029 VAT audit on a 2026 invoice will ask which value your system proposed and who approved it. Generic application logging does not answer that. Article 12 requires logging that supports traceability, incident investigation and post-market monitoring, not just generic application logging, and most code already has a log call, which is exactly the trap. The fix is to treat extraction decisions as business records with the tax retention period, and operational telemetry separately. Our guide to [GDPR and SOC 2 constraints on LLM logging](https://sygnet.ai/blog/gdpr-soc2-compliance-llm-logging) covers the personal-data side of keeping those records that long.

> Six months of model logs cannot defend a six-year invoice.

## What should a defensible extraction record contain?

At minimum: the immutable input hash, the model and prompt version, per-field confidence, the human decision, and a timestamp. Build each extraction event so a third party can replay it. Store the SHA-256 of the exact bytes received, the model identifier including the deployed snapshot (not "gpt-4-class"), the prompt or schema version, the raw model output before post-processing, the post-processed value, the confidence per field, the threshold policy applied, and the identity of any reviewer who overrode a value.

Then version your thresholds. A pipeline that straight-through-processes anything above 0.92 in March and above 0.85 in June has two different control environments, and the audit trail documentation must say so. This is where published [confidence threshold policies for automated processing](https://sygnet.ai/blog/ai-confidence-thresholds-claims-processing) become compliance artefacts rather than tuning notes.

Finally, check the data residency boundary of the extraction step specifically. Platform candidates must hold ISO 27001 or SecNumCloud certification and two-factor authentication including a dynamic factor, and commit not to transfer data outside the European Union. If your PA honours that commitment but your extraction model call leaves the EU, the commitment is broken upstream of the certified perimeter. Sygnet publishes its [processing and residency architecture](https://sygnet.ai/security) for that reason.

## Why does the timing make this urgent now?

Because reception is already live and emission widens in under a year. Since 1 September 2026 all VAT-liable businesses in France must be able to receive an electronic invoice, and large companies and ETIs must issue them. Emission becomes mandatory for SMEs, very small businesses and micro-enterprises on 1 September 2027, under article 91 of the 2024 finance law. The DGFiP confirmed in mid-July 2026 that this calendar would not move again.

The asymmetry matters for pipeline design. During the 2026-2027 window, an SME already receives structured invoices from its large suppliers while still sending its own as PDF or by post. That means inbound AI extraction is doing double duty: parsing legacy PDFs and validating incoming Factur-X/UBL/CII payloads. Two code paths, two sets of controls, one audit trail that must look coherent to an inspector. Teams that document only the structured path will find the PDF path is the one under scrutiny, because that is where inference happened. Our [France e-invoicing workflow notes](https://sygnet.ai/solutions/e-invoicing-france) map the two paths.

## FAQ

### Does using a registered plateforme agréée mean I no longer need a reliable audit trail?

No. The platform secures transmission and format compliance; the audit trail is an obligation on the issuing and receiving business. Both the issuer and the recipient must keep the invoices and the constituent elements of the audit-trail controls in their original form and content. If an AI step produced or modified a field, the documentation of that control sits with you, not with your platform provider.

### Can I rely on my vendor's ISO 27001 certificate for my extraction layer?

Only if the certificate's scope statement names the extraction service. An ISO 27001 certification covers a declared perimeter, never an entire company by default. Ask for the scope annex, not the logo. Then check whether the certification body is accredited: in France the certificate is issued by a COFRAC-accredited body following an independent audit.

### How long should I keep AI extraction logs for e-invoicing?

Align them with the tax retention period, not the AI Act floor. The AI Act sets at least six months for deployers, while invoice content and audit-trail control elements must remain unmodified for six years; commercial law pushes some document retention to ten years under article L.123-22 of the Code de commerce. Keep the decision record on the long clock and strip or pseudonymise personal data inside it.

### What happens if my approved platform loses its registration?

You migrate, and the audit trail has to survive the migration. The DGFiP's own platform factsheet provides for sanctions up to withdrawal of registration. Registration lasts three renewable years with an annual independent audit, a platform can lose it, so require a portability plan activable within 30 days. Test the export: original formats, hashes, and extraction decision records, not just a CSV of invoice headers.