Skip to content
KeneaKenea

Systems
for a working tomorrow

Explore my process
Guide /

VeriFactu declaration of responsibility: what it is, who signs and what it contains

Certification through a producer’s declaration of responsibility is different from prior external approval. This guide helps identify the document and its scope. Part of the VeriFactu for integrators guide.

Editorial review: .

No prior approval: a producer’s declaration

Article 13 of Royal Decree 1007/2023 establishes the producer’s declaration (declaración responsable). It requires neither prior external certification nor prior product registration; this does not prevent subsequent checks by the authorities.

The AEAT website explains this in its certification and declaration FAQs.

Who signs it

The producer is responsible. For in-house development, commissioned systems and systems with several components, identify that role and its scope. Knowing who uses or pays for the application is not enough.

SituationWho signs
You sell your own ERP or invoicing application to othersYou do
You implement and customise a vendor’s ERPReview the vendor’s declaration, the changes made and the responsibility of each component’s producer
Custom development for one clientThe producer; if the client commissioned and maintains it, document who takes that role
You integrate a third-party tax APIIdentify the producer of the whole system and the provider’s declared scope; do not assume the entire integration is covered

Kenea currently offers a technical assessment. An integration report would be a deliverable within an agreed engagement, not a declaration Kenea signs on another producer’s behalf. See the fictional sample report and KeneaFactu’s current status.

Two articles, not one

The obligation arises in Article 13 of Royal Decree 1007/2023: each invoicing software system must be certified through the producer’s declaration, visible in every version of the application. Article 15 of Order HAC/1177/2024 specifies what the document must say and where it must be accessible. Citing only the Order leaves out the source of the obligation.

What it must contain

Article 15 sets the minimum content. In broad terms:

  1. System identification: name, identifying code and version. The AEAT states that each version needs its own declaration, even after a small change.
  2. Producer identification: individual or company name, tax identification number and address.
  3. Date and place of the declaration, and the signature of the producer’s representative.
  4. The declaration itself: that the system complies with the regulation approved by Royal Decree 1007/2023 and the Order, including the system’s constituent components.

One easily missed format requirement: the declaration must be accessible from the system itself, as well as available on request. A PDF hidden in a file-server folder is not enough. An About link, help screen or document shown by the application on request can provide access.

An indicative structure

This structure is illustrative and does not, by itself, ensure every requirement is covered. Check it against Article 15 and the AEAT FAQs. It is neither an official form nor a prediction of what an inspection will request.

SectionContent
1. SystemTrading name, identifier used in invoicing records, declared version and its release date
2. ProducerName, tax identification number, address and the signatory with authority to represent the producer
3. ScopeModes covered: VeriFactu, non-VeriFactu or both; invoice types issued; exclusions
4. ComponentsParts involved in generating, signing, storing or submitting records: own modules, libraries and third-party APIs. Reference each third party’s declaration
5. DeclarationA statement of compliance expressly citing Royal Decree 1007/2023 and Order HAC/1177/2024
6. Date, place and signatureAlso identify the application screen that provides access to the document

Retain supporting evidence with the declaration: AEAT test-environment results, the integration report and version history. The declaration is a statement; the supporting record substantiates it.

When you integrate a tax API

Request the provider’s declaration and check exactly which component and version it covers. That documentation alone does not establish how your integration works. The conceptual states guide illustrates technical decisions that still need testing.

Document components, versions and scope, and review how provider changes affect the whole system. Assigning responsibility requires examining how the system is produced and maintained.

Penalties

Applying the penalty regime requires examining the particular circumstances and statutory conditions with specialist advice. This guide does not automatically assign a fine to someone whose software has yet to be adapted.

Common mistakes

For the relevant dates, see the VeriFactu 2027 deadlines. For questions about the vendor declaration for Sage, Odoo or a3, read VeriFactu for ERP integrators. Our scope and reference prices are described under services.

Sources

Discuss an assessment of my software

This guide is general technical information, not tax or legal advice. The structure is illustrative. Discuss your case with your adviser.

Kenea / Your privacy

Only what is needed.

Kenea does not use its own analytics or advertising. You can use the assessment without identifying yourself. External videos require a separate choice.

Technical preference
Only if you save it. Remembers your technical-storage preference for six months.
Colour theme
The system theme is used by default. If you choose light or dark, only that choice is saved in this browser until you change or clear it.
Kenea analytics and advertising
No tools of our own. Saving this preference does not authorise external videos.
Assessment
Answers stay on this page, without persistent storage. They are sent only if you choose to contact us.
External videos
Only after “Allow and play”. YouTube/Google receives connection data. Permission is for that video and is not saved.

This preference does not remove data or cookies from external providers.

Cookie policy · Privacy policy