Skip to content
Case study · Public institutions

Independent assurance testing of the national e-invoicing system

Engaged as independent consultant for assurance testing of the Merchant Buyer Solution (MBS) e-invoicing system: penetration testing and vulnerability assessment, a privacy impact assessment, performance and stress testing, functional and integration testing, and audit-trail and disaster-recovery assurance.

Client
NRS (formerly FIRS)
Engagement
Awarded October 2025
Outcome
Assurance testing completed.
SECURITYPRIVACYPERFORMANCEFUNCTIONALINTEGRATIONRECOVERYMBS E-INVOICINGINDEPENDENT ASSURANCE · SIX TEST STREAMS
Fig. · Illustrative diagram, not the client’s system
The challenge

What had to be solved

Before a national e-invoicing system carries the country's business-to-business invoices, the revenue authority needs independent evidence that it is secure, protects taxpayer data, performs under load and can be recovered.

  • Every VAT-registered business will depend on the system.
  • It holds commercial and personal data.
  • Its records must stand up to audit.
Scope

Scope of the engagement

  1. Penetration testing and vulnerability assessment

  2. Privacy impact assessment

  3. Performance and stress testing

  4. Functional and integration testing

  5. Audit-trail and disaster-recovery assurance

Approach

How we approached it

We acted as an independent consultant: our job was to find what was wrong, evidence it and report it so it could be fixed before go-live.

Planning
Agree the systems in scope, exclusions, rules of engagement and testing windows.
Testing
Reconnaissance, vulnerability scanning and exploitation attempts, the way an attacker would work.
Validation
Confirm each finding and remove false positives before it is reported.
Reporting
An executive summary, technical findings and a remediation checklist, reviewed by a senior consultant.
Security

Security and compliance

Rules of engagement
Testing ran only against agreed systems, within agreed windows.
Confidential findings
Vulnerabilities were reported to NRS only and are not published.
Privacy impact
Personal-data processing in the system was assessed as part of the scope.
Delivery

How it was delivered

  1. Scope and acceptance

    Scope agreed in writing and commercial terms accepted before work began.

  2. Assurance testing

    Delivered against the agreed scope, with weekly status reports.

  3. Internal QA

    Every deliverable reviewed internally before it reached the client.

  4. Client review and acceptance

    Deliverables reviewed with the client and accepted in writing before close-out.

Results

Results and status

  • Assurance testing completed.

    Evidence · Completion confirmed by Byteflow, 9 October 2026

Related work

Engagements in the same field.

  1. PTDF

    NIN verification and API services supporting scholarship applications, delivered through Verifio, our verification platform, with checks made through a licensed partner.

    OutcomeDeployment completed.

    Government & public institutionsEducation & scholarship administrationIdentity & E-invoicing

  2. NRS (formerly FIRS)

    Awarded October 2025 · three-year engagement

    Secure API submission of EMTL, withholding tax and VAT transaction data by financial institutions, validated against compliance rules, with reporting, audit and secure storage, bringing banks and fintechs onto the RevAssured platform.

    StatusOngoing.

    Government & public institutionsFinancial servicesDigital Engineering

  3. FERMA

    PRMS Phase II software development

    Software development for Phase II of the PRMS programme.

    OutcomeDeployment completed.

    Government & public institutionsRoad infrastructureDigital Engineering

Facing a similar problem?

Tell us what has to work and what it has to connect to. We will tell you plainly what it involves.