France · launch incident operations

How to run a French e-invoicing first-week command centre

Run France e-invoicing launch week with one incident queue, PA and ERP playbooks, duplicate controls, e-reporting recovery and evidence.

Quick verdict:
  • Control unit: a cross-functional launch cell with one accountable case owner.
  • Greatest launch risk: an uncertain delivery state triggering an uncontrolled second transaction.
  • First action: freeze automated resubmission until the source event trail is secured.
Last checked: 20 August 2026Based on official sourcesClear summaryBusiness guidance, not legal advice
Official sources prioritized
Last-checked dates visible
Free checker, no signup required

What you need to know

Guide

1. Set the 1–7 September scope, ownership and decision rights

Define the command centre as a temporary operating model for 1–7 September 2026, not as a substitute for normal AP, AR, tax or IT governance. Start with a legal-entity and flow matrix: SIREN and relevant SIRET, issuing and receiving populations, domestic B2B e-invoicing, transactions subject to e-reporting, payment-data flows where applicable, PA connection, ERP or accounting system, invoice format such as Factur-X, UBL or CII, and the business owner of each flow. Include volumes and criticality, but do not mix entities merely because they share an ERP. A routing defect affecting one establishment should remain traceable to that establishment and its invoices. Assign an incident commander, PA liaison, ERP/integration lead, AP lead, AR lead, tax or compliance reviewer, treasury/payment-control owner and communications owner. The commander prioritises and records decisions; specialists diagnose and execute. Give explicit decision rights for pausing an interface, releasing a corrected batch, sending an incident continuity copy, contacting a customer, and accepting recovery totals. Require two-person approval for actions that could create a second payable, posting or report. Publish one rota and one escalation tree, including out-of-hours contacts and contractual PA support channels. These are recommended internal controls, not DGFiP-prescribed roles or official response times. The legal start dates remain applicable: launch pragmatism is neither a grace period nor a safe harbour. Verify current official guidance, contracts and entity-specific tax and accounting treatment before go-live.

Guide

2. Build one live control board around decisions, not noise

Use a single incident queue even when cases originate in PA monitoring, ERP alerts, AP mailboxes or customer calls. Give every case one command-centre case ID and retain external identifiers alongside it: ERP document number, PA message or correlation ID, invoice identifier, SIREN/SIRET, directory address, lifecycle status and provider ticket. Never replace the original identifiers with a spreadsheet row number. Record the first-observed timestamp, source-system timestamp, last confirmed successful event, environment, flow direction, affected legal entity, estimated document count and value, business impact, current owner, next decision time and authoritative status source. Separate facts from hypotheses. The board should also show containment, duplicate risk, payment or posting hold, e-reporting impact, evidence location, customer or supplier communication state, contractual escalation, recovery batch ID and closure approvers. Use source timestamps rather than the time someone copied an alert into the board; preserve time zones. Avoid fields that no one will use during a decision. A useful line might read: case FR-060, 09:14 CEST PA acknowledgement absent, 47 AR invoices from entity X, ERP export complete, no electronic receipt confirmed, retries paused, PA ticket open, customer communication pending. Access should follow least privilege. Link to protected evidence rather than pasting personal data, full invoices or credentials into a widely visible board. Keep an append-only decision log or auditable history showing who changed the status and why. The objective is a coherent chain from symptom to regularisation, not a decorative dashboard.

Guide

3. Apply an internal impact model and route cases correctly

Label severity as an internal business-impact model, never as an official DGFiP classification. One workable model is: Critical for an uncontrolled risk of duplicate payment or posting, broad inability to issue or receive, corrupted tax data, or a security concern; High for a blocked time-sensitive flow or material backlog with no proven workaround; Moderate for a contained entity, partner or batch with a known recovery path; Low for an isolated case corrected quickly without wider impact. Set escalation and update intervals from business needs and contracts. Do not present them as statutory tolerance or guaranteed sanction protection. Route by the broken control point. PA cases include unavailable services, rejected submissions, missing acknowledgements and uncertain delivery. ERP or integration cases include malformed payloads, mapping errors, stale master data and failed imports. Annuaire or routing cases concern an address, SIREN/SIRET association, receiving platform or endpoint. Lifecycle cases concern inconsistent or misunderstood statuses, including Rejetée and Refusée. Supplier/customer cases include wrong references, disputed commercial facts or a partner claiming non-receipt. E-reporting cases concern transaction or payment data that was not produced correctly or was produced but not transmitted. A symptom can have two routes, but it must retain one accountable owner. Reassess impact when evidence changes. Five isolated invoices with one bad purchase-order reference differ from five invoices missing because a connector stopped. A PA incident does not remove the business's duty to control compliance: process available flows, isolate blocked flows, preserve evidence and regularise. A punctual annuaire incident need not stop all invoicing; work through the PA, confirm details with the customer where needed and use only proportionate temporary arrangements.

Guide

4. Run the first 30 minutes without making the incident worse

In minutes 0–5, open the case, name the commander, mark the affected entity and flow, and contain obvious propagation. Pause blind automated retries when delivery state is uncertain; they can multiply submissions and obscure the original failure. Do not delete queues, rewrite source records or manually change a lifecycle status to make monitoring look healthy. Place a targeted payment, posting or release hold where duplicate or wrong-entity risk exists, while allowing unaffected flows to continue. In minutes 5–15, preserve the original payload or its secure reference, validation response, PA notification, ERP log, correlation ID, directory lookup, screenshots where useful, tickets, exchanges and source timestamps. Establish the authoritative status from the PA and source systems rather than relying on an email assertion or a customer's inbox alone. Compare the last successful transaction with the first failure and test only with controlled, non-personal data in an approved environment; never inject unsafe test documents into production. In minutes 15–30, quantify the blast radius by entity, route, time window, count and value. Decide whether the flow is failed, delayed or merely unobserved. Assign the next diagnostic step, update time and approval path. Notify only affected operators and partners with factual wording. DGFiP's start guidance says a temporary platform outage should not interrupt economic activity and calls for retention of errors, notifications, tickets, timestamps and exchanges. That does not justify routine parallel PDF/email copies. If continuity genuinely requires an alternative channel, control it as the same operation and plan prompt electronic transmission or regularisation after recovery.

Guide

5. Use decision playbooks for the failures most likely to collide

For an invoice not received, first distinguish no PA acknowledgement, no routing confirmation, no customer-system import and no human visibility. Check the invoice and correlation IDs, timestamp, recipient SIREN/SIRET and annuaire route; ask the PA for the authoritative event trail. Do not reissue merely because a customer cannot see the document. Re-submit only when the prior transmission outcome is known and the invoice identity and accounting treatment are controlled. For Rejetée, preserve the rejection reason, correct the technical or data defect through the governed source and link the new event to the case. For Refusée, confirm the commercial or business reason and follow the applicable invoice correction process; do not treat refusal as a connector retry. Exact lifecycle handling depends on the facts, PA capability and current rules. For a wrong entity or route, stop affected dispatches, verify master data with the customer and PA, determine whether the original reached any recipient, and obtain tax/accounting review before cancellation or correction. For a duplicate or continuity copy, freeze payment and posting on all visible representations, compare issuer, invoice number, amount, date and case ID, and nominate one accounting record. If temporary electronic issue is impossible and continuity requires making the invoice known to the customer, the official start guidance permits an alternative channel in that incident context. Label the continuity copy clearly, link it to the original operation, and record the planned electronic regularisation; it is not a normal compliant route. For a PA or ERP outage, continue unaffected flows, isolate the blocked queue, preserve order and identifiers, obtain provider status, and recover in controlled batches with reconciled counts rather than releasing the entire backlog at once.

Guide

6. Separate e-reporting transmission failure from data-production failure

For large enterprises and ETIs in scope at launch, put e-reporting on the same board but not in the invoice-delivery queue. First classify the incident. In an available-but-not-transmitted case, the transaction or payment data exists in the approved source, passes internal checks and is waiting because an interface, PA service or acknowledgement failed. Preserve the dataset and extraction parameters, freeze uncontrolled regeneration, identify the last accepted sequence, and prepare a bounded recovery batch. In a not-correctly-produced case, required data is missing, duplicated, misclassified or incorrectly transformed. Stop transmission of the affected population, correct the source or governed mapping, rerun validation and retain the before-and-after evidence. Continue economic operations where possible. Process unaffected flows and isolate only the blocked population by entity, period, transaction type and failure mode. After recovery, transmit or correct promptly under current requirements, then reconcile source totals, extraction totals, submissions, acknowledgements, rejects and accepted outcomes. Include counts and values; a zero difference in value alone can hide offsetting omissions and duplicates. Payment data should be reconciled separately where applicable. The official guidance says to preserve affected data, distinguish transmission failure from production failure, and transmit, correct and reconcile after recovery. It does not create an invented reporting deadline, retention period or fallback entitlement. Record provider tickets and internal decisions because a third-party incident does not remove the business's control responsibility. Escalate uncertainty about scope, timing or correction method to qualified tax and accounting advisers and confirm current DGFiP instructions.

Guide

7. Communicate with suppliers, customers and accountants without creating a second invoice

Use messages that identify the operation and desired action without claiming compliance has been achieved before evidence exists. Customer non-receipt template: “We are investigating electronic invoice [invoice ID] for [entity], submitted at [source timestamp]. Please do not create or pay a duplicate. We will confirm the authoritative PA status or a controlled next step by [update time]. Case [case ID].” Supplier template: “We cannot yet confirm receipt of electronic invoice [ID]. Please retain the original identifier and do not resend through another channel unless we agree a controlled continuity step. Our case is [case ID].” If an incident continuity copy is justified: “Continuity copy — not a second commercial operation. Electronic transmission is temporarily unavailable. This copy relates to invoice [ID] and case [case ID]; it must not be posted or paid twice. We will confirm electronic regularisation after service recovery.” Tailor that message to the facts and obtain the required internal approval. Do not imply that an emailed PDF has become the normal legal channel. When the electronic flow works, do not send parallel copies routinely. Accountant or adviser template: “Please review the proposed correction for case [case ID]: affected entity [SIREN/SIRET], original event [timestamp/status], proposed treatment [action], duplicate controls [hold/reconciliation], and evidence [location]. Please confirm any fact-specific tax or accounting implications.” Keep recipient lists narrow, avoid unnecessary personal data and do not attach production payloads to broad emails. For isolated incidents corrected quickly, businesses are not expected to notify the administration case by case; handle them with the PA, provider or partner and retain evidence. Escalate systemic or uncertain cases through current official and professional channels.

Guide

8. Close each day with totals, ageing, evidence and explicit acceptance

At fixed checkpoints, reconcile operational totals by legal entity and flow: invoices created, submitted to the PA, acknowledged, routed, received or imported, rejected, refused, pending, corrected and regularised. Keep counts and gross or relevant control values, plus e-reporting source, transmitted, accepted and rejected totals. Reconcile opening backlog + new items − resolved items = closing backlog. Age unresolved cases from the first source timestamp, not from the latest reassignment. Split known failures from unknown outcomes because uncertain delivery carries a different duplicate risk. The shift handover should name the commander, unresolved Critical and High cases, every payment or posting hold, scheduled recovery batch, next provider update, partner commitment, evidence gap and decision due before the next shift. Capture PA or ERP support timestamps, ticket priority, contractual entitlement, response, restoration statement and actual recovery. Compare that evidence with the contract or SLA; do not invent a response time or assume a service credit proves regulatory compliance. Close a case only when the authoritative outcome is known, the technical fault is contained or corrected, any electronic regularisation has completed or has a formally accepted tracked action, duplicate-payment and posting controls are cleared, invoice and e-reporting totals reconcile, communications are complete, and AP/AR plus the relevant technical and compliance owners approve closure. Record residual risk and a problem-management action for recurring defects. Concrete, dated and coherent evidence supports a serious compliance trajectory, but no incident file guarantees protection from penalties. Preserve records under the organisation's verified legal, contractual and records-management rules rather than an invented universal period.

Guide

9. Day-one scenario: recover three connected failures without losing control

Fictional example: at 09:05 CEST on 1 September, AR sees 120 invoices exported from the ERP but only 73 PA acknowledgements. At 09:12, two customers report non-receipt; at 09:18, AP receives an emailed “replacement” for an invoice already visible in its PA portal. The commander opens case LC-001 for the acknowledgement gap and LC-002 for the potential duplicate, pauses retries for the affected export window, holds the duplicate from posting and records the last successful correlation ID. At 09:27, PA evidence shows 47 messages queued, not rejected. The decision log therefore forbids reissue and gives customers a factual update. At 10:10, a separate e-reporting monitor shows no acknowledgement for a batch. Source totals are complete, so LC-003 is classified as available-but-not-transmitted rather than a production defect. Unaffected invoices continue. At 11:20, the PA restores processing; the team releases a five-item canary batch, checks identifiers and outcomes, then drains the queue in bounded batches. By 14:00, all 47 invoices have authoritative acknowledgements. AP confirms that the emailed document is the same operation, retains one payable record and tells the supplier not to resend. The e-reporting batch is transmitted once, with accepted count and value reconciled to source. The closure review records timestamps, tickets, customer exchanges, holds, batch IDs, counts and approvals. Vendor review criteria include status observability, correlation-ID continuity, queue controls, exportable evidence, support responsiveness, routing diagnostics and recovery reconciliation—not a generic brand ranking. Common mistakes would have been blind retries, treating customer inbox visibility as authoritative, posting the continuity copy, combining entities, or calling launch pragmatism a grace period. The next action is to convert observed gaps into a France launch-readiness report: prioritised remediation, tested controls, contractual questions and a capability-based PA or accounting-software shortlist.

Checklist

Map every in-scope legal entity, flow, PA route, ERP interface and accountable owner.

Publish the 1–7 September rota, decision rights and contractual escalation contacts.

Use one case ID while retaining invoice, ERP, PA and correlation identifiers.

Record source timestamps, authoritative status, affected count, value and legal entity.

Pause blind retries and apply targeted payment or posting holds when outcomes are uncertain.

Preserve payload references, errors, notifications, tickets, exchanges and directory evidence securely.

Separate e-reporting transmission failures from incorrect data production before recovery.

Label and link any justified continuity copy, with electronic regularisation and duplicate controls.

Reconcile daily opening backlog, new volume, outcomes, recovery batches and closing backlog.

Require technical, operational and compliance acceptance before closing each incident case.

FAQ

Who should own a French e-invoicing launch incident?

One internal incident commander should own prioritisation, the decision log and closure, while the PA, ERP, AP, AR, tax and treasury specialists own their diagnostic or control actions. A provider ticket does not transfer the business's compliance-control responsibility. Define this governance internally; DGFiP does not prescribe the command-centre roles or severities in this guide.

What should we do when an electronic invoice does not arrive?

Do not immediately resend it. Trace the invoice and correlation IDs through ERP submission, PA acknowledgement, annuaire routing and recipient import; confirm the authoritative outcome with the PA. Pause retries if delivery is uncertain, protect against duplicate posting or payment, inform the partner factually and re-submit only through a controlled process once the original state is known.

Can we send a PDF when the PA or electronic flow is unavailable?

Only treat an alternative channel as an incident continuity measure when electronic issue is temporarily impossible and economic continuity requires the customer to know the invoice. Link and label the copy as the same operation, prevent double payment, posting and reporting, and complete electronic transmission or regularisation promptly after recovery. It must not become a routine parallel route when electronic flow works.

How can AP prevent double payment after a continuity copy or retry?

Place a targeted hold, compare issuer, invoice number, date, amount, entity and case ID across every representation, and designate one accounting record. Keep the hold until PA delivery status and any electronic regularisation are known, then reconcile the ledger, PA events and payment queue before release. Matching on amount alone is insufficient.

Which evidence should the command centre retain?

Retain errors, notifications, provider tickets, source timestamps, exchanges, correlation IDs, secure payload references, routing checks, lifecycle events, decisions, approvals, recovery-batch records and reconciliations. Apply verified legal, contractual and records-management retention rules; there is no universal retention period invented by this guide. Avoid copying unnecessary personal data into the control board.

Must every isolated incident be reported to the French administration?

DGFiP's start guidance indicates that businesses are not expected to report every isolated incident that is corrected quickly. First work with the PA, provider, customer or supplier and retain coherent evidence. For systemic, prolonged or fact-specific uncertainty, verify current official instructions and seek qualified tax or legal advice rather than assuming silence is always appropriate.

How should an e-reporting backlog be recovered?

First decide whether correct data exists but was not transmitted, or whether the data itself was not produced correctly. Preserve and isolate the affected population, identify the last accepted point, correct source or mapping defects where necessary, and recover in bounded batches. Reconcile source, extracted, submitted, accepted and rejected counts and values, including payment data where applicable.

When is a first-week incident genuinely closed?

Close it only when the authoritative outcome is known, the failure is corrected or contained, required electronic regularisation is completed or formally tracked, duplicate controls are resolved, operational and e-reporting totals reconcile, partner communications are complete, and technical, business and compliance owners accept closure. Recurring root causes should remain open in problem management.

Key regulations, formats and terms

FranceFrench tax administrationDGFiPimpots.gouv.frapproved platformplateforme agrééePDPFactur-XUBLCIISIRENVATe-reportingSMEmicro-enterpriseaccounting softwareEuropean CommissioneInvoicingEN 16931Directive 2014/55/EUstructured electronic invoiceVAT automationcross-border tradeFrance e-invoicing first-week incident command centre

France — Country hub

Continue reading

Official sources

We prioritize official government and EU sources where available and keep last-checked dates visible for mandate-sensitive pages.