e-invoicing

Compliance Network Implementation Guide

Send invoices

Build and submit an invoice, poll for clearance, retrieve the UUID and QR code, and resolve validation errors or rejections.

Note:

A Postman collection with request and response samples for Malaysia is available at the Malaysia Postman Collection. The collection includes examples for sending invoices in the Sovos Canonical Invoice (SCI) and local UBL format, uploading credentials, configuring an inbound service, retrieving and acknowledging notifications, and rejecting invoices.

Before you start

Before submitting invoices, make sure that:

  • Your organization has the Malaysia outbound product enabled.

  • Your Inland Revenue Board of Malaysia (IRBM) credentials and digital certificate are configured and valid.

  • You have an ERP System ID configured for this organization.

  • Your Tax Identification Number (TIN) and Business Registration Number (BRN) are active and verified with IRBM and Companies Commission of Malaysia (SSM).

  • You have tested invoice submission in the UAT environment.

Build your invoice's Standard Business Document

Before submitting, wrap your invoice in a Standard Business Document (SBD). The SBD consists of a Standard Business Document Header (SBDH) routing container and the invoice XML body.

Submit an invoice through the API

  1. Send a POST request to the /v1/documents endpoint with your Base64-encoded SBD.
    JSON
    POST 'https://api-test.sovos.com/v1/documents' \
    --header 'Content-Type: application/json' \
    --header 'Authorization: Bearer TOKEN' \
    --header 'x-correlationId: SET-TO-UNIQUE-VALUE' \
    --data-raw '{
    	"data": "PD9...d4=",
    	"dataEncoding" : "base64"
    }'
  2. Verify you received an HTTP 202 Accepted response.
    JSON
    {
      "timestamp": 1605282724079,
      "status": 202,
      "success": true,
      "message": "Document Received",
      "data": {
        "documentId": "DOCUMENT-ID"
      }
    }

    A 202 confirms Sovos received the document. It doesn't mean the invoice was validated or cleared. You can track the outcome through notifications.

  3. Poll for the application response to verify clearance.

If the Indirect Tax API is unavailable, check the Sovos status page for operational status. Do not resubmit a document until you have confirmed it was not accepted. For Malaysia, submitting the same invoice number twice risks a duplicate rejection because the number is consumed even if the original submission was rejected.

Important:

Don't resubmit a document unless you have confirmed it was rejected.

Submitting the same invoice number twice risks a duplicate rejection because IRBM consumes the number even if it rejects the submission.

Retrieve application responses

Application responses provide status updates throughout the transaction lifecycle. Poll for responses until you receive a notification with SCICloudStatusCode of 209, which means that the transaction is complete.

Note:

A value in the 5xx range means that the transaction didn't complete.

Option A: retrieve one final notification

Sovos can return a single notification that contains all attachments and data when the transaction is complete (SCICloudStatusCode: 209). When you receive the final notification, the SCIResponseCode can be:

AP

IRBM accepted the invoice. The notification contains the UUID, LongId, validation link, and reception date.

RE

IRBM rejected the invoice. Read SCIGovtStatusCode or SCIInternalValidationCode to find the error in StatusReason.

Option B: retrieve multiple incremental notifications

Sovos can also return a notification at each stage of the workflow. In that case, you must poll the notifications endpoint until you receive SCICloudStatusCode: 209.

SCICloudStatusCode SCIResponseCode Meaning
100 IP Document received.
101 IP Document mapped.
200 IP, then AP Authorized by IRBM. The status changes from IP to AP after the 72-hour buyer rejection window closes.
207 AP PDF generated.
209 AP Transaction complete.
400 RE IRBM or the buyer rejected the invoice..
Note:

Contact the Sovos Professional Services team to configure which notification option your company uses.

IRBM response data in accepted notifications

When SCIResponseCode is AP, the UBLExtensions element in the application response contains the following fields:

Uuid
Unique identifier that IRBM assigns to each accepted document.
LongId
Identifier that allows anonymous querying of document data.
validationLink
URL to embed in the QR code on the human-readable invoice.
receptionDate
Date and time that IRBM received the document.

Distribute the invoice to the buyer

After clearance, share the invoice with the buyer using one of the following distribution options:

Sovos distribution

Sovos can send the invoice to the buyer through a configured email distribution channel. Contact the Sovos Professional Services team to set up a channel.

Note:

After you configure a distribution channel, don't send the invoice separately.

Self-distribution

If you don't configure a distribution channel, your organization sends the invoice to the buyer. Include the QR code in any human-readable version you share. The QR code lets the buyer verify the invoice on IRBM's system.

Troubleshoot submission issues

Validation errors (SCICloudStatusCode 401)

A 401 status code means that the document failed Sovos validation before reaching IRBM. Common causes:

  • Missing required fields: TIN, BRN, and the Malaysian Standard Industrial Classification (MSIC) code.

  • Invalid TIN format or inactive TIN.

  • Tax amounts do not balance.

  • Invoice number is not unique within your TIN.

  • Certificate not uploaded or expired.

  • Document exceeds the five- megabyte size limit.

Tax authority rejections

An IRBM rejection means that you have submitted the invoice and it exists in IRBM's records as rejected. You can't resubmit the same invoice number but you can do the following:

  1. Review the rejection code in the notification.

  2. Correct the identified errors in your system.

  3. Issue a new invoice with a new invoice number.

    Note:

    IRBM consumes the rejected invoice number even for rejected invoices, so don't reuse it.

  4. Void the rejected invoice number in your accounting system before issuing the corrected one.

Common IRBM rejection codes:

Invalid or inactive supplier TIN
Verify the TIN is active at https://www.hasil.gov.my.
Duplicate document number for this TIN
Issue a new invoice with a unique document number.
Tax calculation error
Recalculate tax amounts. Ensure line-level calculation.
Certificate expired or invalid
Upload a new valid certificate.
Invalid or inactive buyer TIN
Verify the buyer's TIN. For consolidated B2C, use EI00000000010.
Missing MSIC code
Include the five-digit MSIC code in the supplier party identification.
Note:

For the complete rejection code reference, see https://sdk.myinvois.hasil.gov.my/document-validation-rules/.

Clearance timeout

If polling exceeds 60 minutes without a clearance response, the invoice may be stuck in IRBM's processing queue.

Warning:

Don't resubmit a pending invoice without first confirming its status. If IRBM processed the original submission successfully but a network error prevented Sovos from receiving the response, the number is already consumed. Resubmitting the same invoice number results in a duplicate rejection and the correct invoice is not cleared.

Steps for a pending invoice:

  1. Check the IRBM MyInvois portal for any announced maintenance or outages.

  2. Query the portal using the invoice number and your TIN to check whether clearance was issued.

  3. If the portal granted clearance but Sovos didn't receive it, contact the Sovos Professional Services team. Sovos can retrieve the UUID from IRBM's records.

  4. If IRBM shows the invoice as pending or not found, contact the Sovos Professional Services team before resubmitting.

Certificate expiration

An expired certificate causes all invoice submissions to fail with a signing error until you upload a new certificate. In that case, you must:

  1. Get a new certificate from a Malaysian CA or through the MyInvois portal.

  2. Upload the new certificate using the Indirect Tax API.

  3. Resubmit any invoices that failed due to the expired certificate.

Note:

To avoid unplanned downtime, set a renewal reminder at least 30 days before the certificate expiration date.

Certificate configuration errors

Symptom
Signing fails. Sovos returns a validation error related to the certificate.
Cause
The certificate doesn't match the IRBM-required X.509 profile or the Base64 encoding contains errors.
Solution
Verify the certificate matches the IRBM certificate profile. Re-encode the certificate using the SSL certificate conversion to Base64 steps. Verify that the Base64 string contains no line breaks. Make sure that the password value matches the export password you used when creating the .p12 file.

Wrong listVersionID on InvoiceTypeCode

Symptom
IRBM rejects the document with a validation error on InvoiceTypeCode.
Cause
The listVersionID attribute doesn't match your certificate configuration.
Solution
Set listVersionID="1.1" if you have a certificate configured. Set listVersionID="1.0" if you don't.

Polling start date too far in the past

Symptom
Inbound service configuration fails with an IRBM error about the polling date.
Cause
PollingDateFrom is set to a date more than 10 days in the past.
Solution
Set PollingDateFrom to a date within the past 10 days.

Document too large

Symptom
Sovos rejects the document before it reaches IRBM.
Cause
The document exceeds the 300 KB limit.
Solution
Reduce the document size. If the invoice has many line items, remove unnecessary white space from the XML. If you can't reduce the invoice size, split it into multiple invoices.

The following limits apply to all Malaysia document submissions:

Maximum document size
300 KB
Maximum batch size
Five MB
Maximum batch document count
100 documents