The date finance teams were watching was 1 July 2026. That was when ZATCA's penalty waivers expired and e-invoicing under FATOORAH moved from a phased rollout to full enforcement. Most companies read it as a compliance milestone and moved on. It was also something quieter: the day nearly every transaction your business runs began leaving a cleared, structured, time-stamped record. That record is the most powerful fraud-detection asset a Saudi company has ever held. Almost no one is using it that way.
What full enforcement actually changed
The waiver period is over. Enforcement now applies across the board for businesses above the VAT registration threshold. B2B and B2G invoices are cleared by ZATCA in real time before they can be issued, and B2C simplified invoices are reported within 24 hours. In May 2026 ZATCA published version 3 of its e-invoicing controls and technical specifications, tightening the fields each document must carry.
The practical effect is simple. The informal invoice, the one typed up after the fact to fit a number someone already decided on, no longer clears. Every document now carries a validated seller, buyer, timestamp, and line detail that a third party has already checked before your accounts ever see it.
The compliance system is a forensic dataset
Fraud hides in gaps and edits. Paper and loose PDFs allowed both. A cleared e-invoice stream closes them, and the schemes that used to live in those gaps now leave a signature in data you already hold:
- Duplicate invoice numbers or repeated identical amounts to the same vendor, the classic marker of a double payment.
- Round-number invoices clustered just below an approval threshold, which is how a large spend gets split to avoid a second signature.
- A vendor whose first cleared invoice is dated after the payment went out, or whose registration details do not reconcile with the commercial register.
- Invoices timestamped well outside a supplier's normal pattern.
None of these signals is new. What is new is that the data to catch them is now standardized, complete, and machine-readable across the whole ledger rather than scattered across formats and drawers.
The same record cuts both ways
This is not only a monitoring tool. The trail that lets you watch also exposes you. Manipulation that once sat in a desk drawer now sits on a national platform with a timestamp on it. In a dispute, an internal investigation, or a regulator's review, your cleared invoices become the record everyone reads first. If your controls are weak, that record documents the weakness in your own hand.
So reconciliation between what you filed and what actually happened is no longer an internal courtesy. It is the version of events a tribunal or an auditor can pull. The question is whether you find the break before they do.
Turning the obligation into a control
The shift in mindset is to treat cleared e-invoice data as a continuous monitoring layer, not a once-a-year filing. That means running analytics against the full stream on a schedule instead of testing a sample at audit time. It means reconciling the FATOORAH record against the purchase ledger and the payment run, then investigating the breaks rather than explaining them away. And it means setting the vendor tests and the thresholds now, because the value of this data is highest when someone is reading it in near real time.
The infrastructure is already built and already mandatory. Firms that treat it as a cost will file and forget. The ones that treat it as evidence will see the anomaly in week one instead of year three. We help boards and finance leaders turn the FATOORAH record into a working fraud-detection control, and stand behind the findings when they matter. Speak with a Specialist.

