ARLing

E-invoice / Rules / BR-51

E-invoice rule EN 16931 schematron

BR-51: The payment card number (BT-87) is longer than

The payment card number (BT-87) is longer than 10 characters. An invoice should carry only the first six and last four digits, for example 411111******1111.

Original wording of the rule

[BR-51]-In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.

Source of the quotation: EN 16931 schematron (ConnectingEurope/eInvoicing-EN16931, licence EUPL 1.2)

How to fix it

  1. Open the XML file and find the element cac:CardAccount/cbc:PrimaryAccountNumberID.
  2. Add or correct the element the way the wording of the rule above asks for.
  3. Save the file and check it again with our checker. It runs in your browser, the file is never uploaded.

A correct UBL 2.1 snippet

<cac:CardAccount
    xmlns:cac="urn:oasis:names:specification:ubl:schema:xsd:CommonAggregateComponents-2"
    xmlns:cbc="urn:oasis:names:specification:ubl:schema:xsd:CommonBasicComponents-2">
  <cbc:PrimaryAccountNumberID>text</cbc:PrimaryAccountNumberID>
</cac:CardAccount>

The snippet is only the part of the document the rule is about. Put it in the right place inside your invoice; the namespaces are written here only so that the snippet reads on its own.

When it is reported

Profile: EN 16931, Peppol BIS Billing 3.0, XRechnung 3.x

How we rate it: warning

Where we point in the file: /Invoice/cac:PaymentMeans/cac:CardAccount/cbc:PrimaryAccountNumberID

Related rules

Our check is not complete: we do not check the XSD schema and we do not implement every rule, and a file that passes says nothing about whether the buyer or the Peppol network will accept it. Licences for the quoted wordings are listed in our sources.