The compliance gap nobody budgets for
Saudi taxpayers in later ZATCA waves discover the same problem: the compliance surface is wider than the accounting system. Zoho Books can produce a compliant standard tax invoice for the documents that originate inside Books. But real Saudi operations issue tax documents from places Books never sees — a Zoho Creator field-service app that closes a job card on site, a CRM quote that a sales manager converts and hands to a customer at the counter, a POS terminal or a delivery-note workflow that produces a simplified invoice, a recurring subscription billed out of a custom Deluge function, an inter-company debit note raised by finance in a spreadsheet and posted later.
Every one of those is a tax document under the E-Invoicing Resolution. Every one needs a UUID, a previous-invoice hash, an ICV counter, a cryptographic stamp, a QR code carrying the TLV payload, and — for standard invoices — clearance through the Fatoora portal before it is handed to the buyer. Miss it and the penalty schedule runs to SAR 50,000 per violation category, with repeat violations escalating. Worse, the failure is silent: your team keeps issuing documents, the counter keeps incrementing wrong, and the gap only surfaces when ZATCA asks for the archive.
ECOSIRE builds a bridge that sits between every document source in your Zoho estate and ZATCA, so compliance stops depending on which screen the document was raised from.
What ECOSIRE builds
This is not a downloadable app. We build the bridge against your actual Zoho org — your Books organization, your CRM layout, your Creator schema, your ERP number series — and install it into your environment.
Document capture across every source
We wire capture points into each system that raises a taxable document:
- Zoho Books — custom functions bound to Invoice, Credit Note and Debit Note create/edit/void events, plus a scheduled sweep that catches records created by imports or the Books API.
- Zoho CRM — a Deluge workflow on Quotes, Sales Orders and Invoices modules so a document converted in CRM is registered before it reaches the customer, with the resulting clearance status written back to a custom field set on the record.
- Zoho Creator — a Deluge integration in your Creator app's form success and record-update workflows, so job cards, delivery notes and site-issued documents route through the same queue.
- Zoho Inventory — capture on shipment and package-linked invoices where invoicing runs out of Inventory rather than Books.
- Zoho Flow — optional external triggers via webhook for any non-Zoho source (a terminal, a portal, a legacy till) so it joins the same numbering chain.
The clearance and reporting engine
At the centre is a Creator-hosted or Books-embedded engine that does the regulated work: builds the UBL 2.1 XML in the ZATCA invoice schema, applies the required extensions, computes the invoice counter value and the SHA-256 hash of the previous document to maintain the chain, applies the cryptographic stamp with your onboarded CSID, generates the base64 TLV QR payload, and calls the correct ZATCA API — clearance for standard (B2B) invoices, which must return a cleared XML before issue, and reporting for simplified (B2C) invoices, which are submitted within the reporting window after issue.
Standard and simplified are handled as genuinely different flows, because they are. A cleared standard invoice is only valid in its ZATCA-returned form — the engine writes that returned XML back as the authoritative document and blocks the pre-clearance PDF from being sent.
Onboarding, CSR and certificate lifecycle
We build the onboarding path: CSR generation with the correct ZATCA subject fields for your VAT registration and device, compliance CSID request, the compliance checks ZATCA requires before production, production CSID issue, and a renewal reminder workflow so the certificate does not expire silently. Certificates and private key material are stored in your own Zoho environment — ECOSIRE does not hold them.
Failure handling, because the API will fail
A network timeout during clearance is not an edge case, it is a Tuesday. The engine keeps a queue with explicit states (pending, cleared, cleared-with-warnings, rejected, retry-exhausted), exponential-backoff retry via a scheduled Deluge function, and a rejection reason parsed out of the ZATCA response into readable text rather than a raw code. Rejected documents raise a task or notification to a named finance owner. Nothing is retried in a way that could double-submit or break the ICV sequence.
Arabic, archive and audit
Invoice PDFs are produced with the mandatory bilingual fields, the QR code, seller and buyer VAT numbers, and the correct invoice type code. Every submitted XML, every ZATCA response and every hash is archived against the source record so a ZATCA audit can be answered from your own system without reconstructing anything.
Who this is for
Businesses registered for VAT in Saudi Arabia that run Zoho as the operational system and issue tax documents from more than one place — distributors and wholesalers, field-service and maintenance companies, retail groups with counter sales, contractors running Creator apps, and multi-branch operations where each branch is a separate ZATCA device.
How delivery works
1. Scoping call. We map every document source in your org, your ZATCA wave and onboarding status, your Books organization structure, branch/device count, and whether you need standard, simplified, or both. We look at your real records, not a questionnaire. 2. Fixed quote. You receive a written scope and a fixed price before any build starts. If the scope changes later, the quote changes in writing first. 3. Build. ECOSIRE develops the Deluge functions, Creator components, widgets and Flow connections against a sandbox or a duplicate Books organization. 4. Install in test. Deployed into your test environment and connected to the ZATCA simulation environment. You issue real document shapes and see real clearance responses before anything touches production. 5. Production go-live. Production CSID onboarding, cutover of the ICV counter and hash chain, and a supervised first day of live clearance. 6. Support. A defined post-go-live support window for defects, ZATCA response changes and operator questions.
Typical lead time is 2-4 weeks from signed quote to production, driven mostly by how many document sources exist and how quickly certificate onboarding can be completed on your side.