VeriFactu declaration of responsibility: what it is, who signs and what it contains
Certification through a producer’s declaration of responsibility is different from prior external approval. This guide helps identify the document and its scope. Part of the VeriFactu for integrators guide.
Editorial review: .
No prior approval: a producer’s declaration
Article 13 of Royal Decree 1007/2023 establishes the producer’s declaration (declaración responsable). It requires neither prior external certification nor prior product registration; this does not prevent subsequent checks by the authorities.
The AEAT website explains this in its certification and declaration FAQs.
Who signs it
The producer is responsible. For in-house development, commissioned systems and systems with several components, identify that role and its scope. Knowing who uses or pays for the application is not enough.
| Situation | Who signs |
|---|---|
| You sell your own ERP or invoicing application to others | You do |
| You implement and customise a vendor’s ERP | Review the vendor’s declaration, the changes made and the responsibility of each component’s producer |
| Custom development for one client | The producer; if the client commissioned and maintains it, document who takes that role |
| You integrate a third-party tax API | Identify the producer of the whole system and the provider’s declared scope; do not assume the entire integration is covered |
Kenea currently offers a technical assessment. An integration report would be a deliverable within an agreed engagement, not a declaration Kenea signs on another producer’s behalf. See the fictional sample report and KeneaFactu’s current status.
Two articles, not one
The obligation arises in Article 13 of Royal Decree 1007/2023: each invoicing software system must be certified through the producer’s declaration, visible in every version of the application. Article 15 of Order HAC/1177/2024 specifies what the document must say and where it must be accessible. Citing only the Order leaves out the source of the obligation.
What it must contain
Article 15 sets the minimum content. In broad terms:
- System identification: name, identifying code and version. The AEAT states that each version needs its own declaration, even after a small change.
- Producer identification: individual or company name, tax identification number and address.
- Date and place of the declaration, and the signature of the producer’s representative.
- The declaration itself: that the system complies with the regulation approved by Royal Decree 1007/2023 and the Order, including the system’s constituent components.
One easily missed format requirement: the declaration must be accessible from the system itself, as well as available on request. A PDF hidden in a file-server folder is not enough. An About link, help screen or document shown by the application on request can provide access.
An indicative structure
This structure is illustrative and does not, by itself, ensure every requirement is covered. Check it against Article 15 and the AEAT FAQs. It is neither an official form nor a prediction of what an inspection will request.
| Section | Content |
|---|---|
| 1. System | Trading name, identifier used in invoicing records, declared version and its release date |
| 2. Producer | Name, tax identification number, address and the signatory with authority to represent the producer |
| 3. Scope | Modes covered: VeriFactu, non-VeriFactu or both; invoice types issued; exclusions |
| 4. Components | Parts involved in generating, signing, storing or submitting records: own modules, libraries and third-party APIs. Reference each third party’s declaration |
| 5. Declaration | A statement of compliance expressly citing Royal Decree 1007/2023 and Order HAC/1177/2024 |
| 6. Date, place and signature | Also identify the application screen that provides access to the document |
Retain supporting evidence with the declaration: AEAT test-environment results, the integration report and version history. The declaration is a statement; the supporting record substantiates it.
When you integrate a tax API
Request the provider’s declaration and check exactly which component and version it covers. That documentation alone does not establish how your integration works. The conceptual states guide illustrates technical decisions that still need testing.
Document components, versions and scope, and review how provider changes affect the whole system. Assigning responsibility requires examining how the system is produced and maintained.
Penalties
Applying the penalty regime requires examining the particular circumstances and statutory conditions with specialist advice. This guide does not automatically assign a fine to someone whose software has yet to be adapted.
Common mistakes
- Confusing certification with external approval. Ask for the product’s declaration and the version it covers.
- Declaring one version and distributing another. The declaration is tied to a version. Changing the invoicing engine without updating it can make the declaration inaccurate.
- Burying the document. If it cannot be accessed from the application, the format requirement is not met even if the content is correct.
- Assuming the API provider signs for you. Its declaration covers its own scope.
- Forgetting customisations. Check whether they fall within the declared scope and who is responsible for their changes.
- No supporting evidence. Keep AEAT test-environment evidence and the integration report.
For the relevant dates, see the VeriFactu 2027 deadlines. For questions about the vendor declaration for Sage, Odoo or a3, read VeriFactu for ERP integrators. Our scope and reference prices are described under services.
Sources
- Royal Decree 1007/2023, invoicing software systems regulation.
- Order HAC/1177/2024, Article 15, declaration of responsibility.
- AEAT: system certification and declarations of responsibility.
- AEAT: invoicing software systems.
Discuss an assessment of my software
This guide is general technical information, not tax or legal advice. The structure is illustrative. Discuss your case with your adviser.