The One Penalty in the Table With No Ceiling
Cabinet Decision No. 106 of 2025 defines a System Failure as any technical malfunction, disruption, or unavailability of the Electronic Invoicing System that prevents the Issuer or Recipient from complying with their obligations under the legislation in force. Violations 4 and 5 in the annexed table both address what happens when that failure goes unreported: AED 1,000 for each day of delay or part thereof, applied separately to the Issuer's obligation and the Recipient's obligation to notify the Authority. Unlike the document-transmission penalties in Violations 2 and 3, there is no monthly cap here. Every day the notification is outstanding adds another AED 1,000, without limit.
Two Independent Obligations in the Same Transaction
The decision treats the Issuer's notification duty and the Recipient's notification duty as entirely separate violations, each carrying its own AED 1,000-per-day penalty. In a standard bilateral B2B transaction, both the supplier and the buyer are independently obligated to notify the Authority if a System Failure prevents them from meeting their respective obligations. A system-wide outage affecting an ASP that serves both parties to a transaction can, in principle, generate two parallel penalty streams — one against the Issuer, one against the Recipient — if both fail to notify within the prescribed window. Businesses relying on the assumption that a counterparty's notification covers their own obligation are working from a reading the decision does not support; each Person's duty to notify stands on its own.
Why the Definition of System Failure Matters
The definition in Article 1 of CD 106 is broad by design: it covers disruption or unavailability that prevents compliance, without narrowing the cause to a particular layer of the system. A malfunction at the ASP level, an outage in the Central Register the Ministry maintains, or a failure in the business's own connection into the Electronic Invoicing System can each qualify, provided the effect is that the business cannot meet its obligations as a result. This means the notification duty is triggered by effect, regardless of fault. If system disruption causes non-compliance, the notification clock starts, no matter where in the chain the disruption originated.
The Arithmetic of Delay
Because the penalty accrues daily without a cap, the cost of a slow internal escalation process compounds quickly. A System Failure that a business identifies immediately but takes ten days to formally notify to the Authority — because the internal process for recognising and escalating a system failure notification is not clearly assigned to anyone — generates AED 10,000 in penalty exposure from that delay alone, on each side of the transaction where the duty applies and is missed. Extend that to thirty days and the exposure reaches AED 30,000 per stream. There is no cap that limits how high this climbs; the only variable a business controls is how quickly it notifies once a failure occurs.
The Operational Fix Is Ownership, Not Technology
Violations 4 and 5 are closed by a named internal owner — someone whose job includes recognising that a system disruption has occurred, confirming it meets the definition of a System Failure, and submitting notification to the Authority within the prescribed window, on both the issuing and receiving sides of the business's invoice flow. Businesses that treat system failure notification as an IT ticket rather than a compliance deadline are the ones most likely to discover, weeks later, that an uncapped daily penalty has been accruing the entire time.
