Unfortunately submitting a VAT/GST return and making the required tax payment to the tax authority is not always the end of the story, or the indirect tax lifecycle. Businesses will need to retain certain mandated data and documentation for prescribed periods (which differ by country). It is likely that tax authorities will periodically look to audit a business or at least make enquiries. This may include requests for supporting data to substantiate the VAT/GST return that has been submitted, including details of VAT/GST registration numbers provided by business customers.
In the EU, digital service providers registered for the simplified One-Stop Shop (OSS) registration must be able to respond to requests from the member state of identification (i.e. the country where the OSS number was issued) on a timely basis and provide required records within a month of receiving a reminder. Any failure to do so is likely to be regarded as a persistent failure to comply with the rules of the streamlined and simplified scheme and will result in exclusion from OSS. This triggers a requirement to register in each EU member state individually and meet the full local VAT compliance obligations of each.
It is therefore recommended that digital service providers are on the front foot and take a proactive approach to being prepared for data requests and audits. One way businesses registered for OSS could prepare for this is by using the Standard Audit File for OSS (SAF-OSS) XML schema that has been designed by the European Commission to make the collation and provision of information to an EU tax authority easier.
It is not just national tax authorities that digital service providers need to be prepared for in relation to requests for information and audit defence. In fact, it could be said that the greater threat to a digital service provider is not from a tax authority but from a firm of tax accountants or lawyers undertaking a due diligence exercise on the business.
A due diligence is a systematic examination of a business ahead of a major business event such as a merger or acquisition, a capital raise, an initial public offering (IPO) or audit. It is common as part of a tax due diligence for digital services revenue to be requested split by the customer’s country and a request to prove that customers are business customers (with the relevant evidence held). Where the digital service provider is not registered in a country or is unable to substantiate that the customers are business customers, the accountant or lawyer may then simply multiply the revenue by the relevant VAT/GST rate, extrapolate the data by a set number of years, and even double the amount to account for possible penalties, interest, and remediation costs.
The result is usually a very worst-case assessment of a liability, but this is quantified and presented back in the due diligence report to the party that commissioned it (for example, a bank or the prospective buyer). This can then be used by the prospective purchaser to obtain a significant discount (equal to the liability) or require complex indemnities. In some cases it could also delay or prevent the transaction or fund raising event. Digital service businesses that are scaling fast and are likely to have an upcoming business funding or exit event in the future could opt to undertake their own due diligence, being proactive and assessing the quality of data held to substantiate its current tax policy and indirect tax footprint (nexus). The results should ensure that there are fewer surprises later down the line, as well as providing a clear roadmap of countries where the business should register for VAT/GST.