BREAKING Afri Invoice secures NRS accreditation as a System Integrator for Nigeria's mandatory e-Invoicing platform. Read the mandate timeline

NRS Compliance & Data Security

Afri Invoice — NRS-Accredited Systems Integrator (SI) & Access Point Provider (APP)

Last Updated
1 January 2025
Effective
1 January 2025
Read Time
~8 minutes

Afri Invoice Nigeria Limited (RC 7570323) is accredited by the Nigeria Revenue Service (NRS) as both a Systems Integrator (SI) and an Access Point Provider (APP) under the NRS Merchant Buyer Solution (MBS) e-invoicing framework. This dual accreditation authorises Afri Invoice to provide end-to-end e-invoicing services from the integration of your existing business systems to the secure validation, digital signing, and real-time transmission of your electronic invoices to the NRS under a single point of accountability. This page explains what the mandate means for your business, how Afri Invoice keeps you compliant, and how we protect your data.

01

Our Accreditations & Certifications

  • NRS Access Point Provider (APP): authorised to validate, digitally sign, and transmit electronic invoices between taxpayers and the NRS MBS platform, and to retrieve validation identifiers and clearance status in real time;
  • NRS Systems Integrator (SI): authorised to connect taxpayers' ERP, accounting, POS, and billing systems to the MBS platform through secure, tested integrations;
  • ISO/IEC 27001:2022: our Information Security Management System (ISMS) is certified to the current international standard for information security, covering the people, processes, and technology behind the Platform;
  • NITDA-recognised solution provider: our solutions align with the standards of the National Information Technology Development Agency;
  • NDPA 2023 / NDPR compliance: our data protection programme operates under the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation 2019, supervised by the Nigeria Data Protection Commission (NDPC).
02

Understanding the NRS E-Invoicing Mandate

Nigeria operates a mandatory national e-invoicing regime administered by the NRS (which assumed the tax administration functions formerly exercised by the Federal Inland Revenue Service, FIRS). At its centre is the MBS platform: a centralised, real-time system through which business-to-business (B2B) and business-to-government (B2G) invoices are validated, digitally signed, and reported to the tax authority. An invoice is only cleared once the MBS platform has issued its validation identifiers, including the Invoice Reference Number (IRN) and QR code.

The mandate is being rolled out in phases according to taxpayer size:

Phase Who is covered Status / timeline
Phase 1 Businesses with annual turnover above ₦5 billion Live and under active enforcement
Phase 2 Businesses with annual turnover between ₦1 billion and ₦5 billion Live from 1 July 2026; enforcement from January 2027
Phase 3 All VAT-registered businesses with turnover below ₦1 billion From 1 July 2027; enforcement from 2028

Taxpayers cannot connect to the MBS platform directly on their own: invoice data must flow through an accredited Access Point Provider that meets the technical and security standards prescribed by the NRS. Businesses that fail to comply within their applicable phase face penalties under the Nigeria Tax Administration Act 2025, which came into legal force on 1 January 2026, and invoices that have not been validated through the MBS platform cannot be used to claim input VAT.

03

How Afri Invoice Keeps You Compliant

  • API-driven ERP integration (SI): stable, well-documented APIs and connectors enable your ERP, accounting, or billing systems to connect to the Platform, mapping your data into the NRS-prescribed structured formats (including JSON);
  • Schema validation before submission: every invoice is checked against NRS schema and business rules, including all NRS-mandated tax categories, quantity codes, and payment status fields, so that errors are caught before transmission;
  • Digital signing and real-time transmission (APP): validated invoices are cryptographically signed and transmitted to the MBS platform in real time, with the IRN and QR code returned to you automatically;
  • Certificate lifecycle management: we manage the digital certificates and cryptographic keys used in signing and transmission on your behalf;
  • Queue-and-retry resilience: if the MBS platform is temporarily unavailable, validly submitted invoices are queued and transmitted once connectivity is restored, in accordance with NRS-permitted procedures;
  • Credit and debit note workflows: post-clearance corrections follow the procedures prescribed by the NRS, preserving a complete and auditable fiscal record;
  • Audit trails and dashboards: every e-invoice is fully traceable from the moment it is generated, with clear compliance dashboards, clearance statuses, and exportable audit trails for finance teams, CFOs, and auditors;
  • Interoperability by design: our architecture aligns with international standards, including the PEPPOL framework and OAuth 2.0, future-proofing your business for cross-border e-invoice interoperability;
  • Integrate your way, two clear paths: Developer-led (free): connect your ERP, accounting, or POS system including SAP, Oracle, QuickBooks, Sage, and Microsoft Dynamics, directly through our stable, well-documented REST APIs and full sandbox environment, with support for genuine platform and API issues. Partner-led: if you do not have in-house technical resources, we match you with our preferred integration partners who handle the build, data mapping, and end-to-end testing, so your invoices flow through an NRS-accredited pipeline without you maintaining the infrastructure.
04

Our Security Architecture

4.1 Encryption & Transmission Security

  • TLS encryption for all data in transit between your systems, the Platform, and the NRS;
  • AES-256 encryption for data at rest;
  • OAuth 2.0 secured APIs with scoped, revocable credentials;
  • Cryptographic signing of every e-invoice, making it possible to verify authenticity, ensuring data integrity, preventing tampering and enabling validation.

4.2 Access Control

  • Two-factor authentication (2FA) for user accounts;
  • Role-based access control (RBAC) and the principle of least privilege for both customers and staff;
  • Segregation of production and sandbox environments.

4.3 Monitoring, Testing & Assurance

  • Regular vulnerability assessments and penetration testing;
  • Independent internal audits of the ISMS and periodic certification audits under ISO/IEC 27001:2022;
  • Vendor and partner due diligence before any third party touches our service chain.
05

Data Protection & Privacy

Invoice data is fiscal data, and we treat it accordingly. Personal data is processed in line with the Nigeria Data Protection Act 2023 and our Privacy Policy. Data transmitted to the NRS is limited to what the e-invoicing framework requires; we do not sell customer data, and we do not permit third-party advertising technologies inside signed-in e-invoicing workspaces. Where data is transferred internationally for example, to our offices in the United Kingdom and France, NDPA-compliant safeguards apply.

06

Business Continuity & Availability

  • A 99.7% monthly Platform availability target for all Customers, excluding scheduled maintenance and events attributable to the NRS MBS platform, telecommunications providers, or other third parties;
  • Redundant infrastructure, automated backups, and tested disaster recovery procedures;
  • Scheduled maintenance performed outside peak business hours wherever practicable, with advance notice;
  • Queuing of validly submitted invoices during any MBS platform downtime, so that your compliance position is preserved.
07

Incident Response & Breach Notification

We operate a documented incident response procedure under our ISMS. In the event of a personal data breach likely to result in a risk to affected individuals, we will notify the Nigeria Data Protection Commission and affected users within 72 hours of becoming aware, in line with the NDPA, and we will act promptly to contain, investigate, and remediate any incident affecting the confidentiality, integrity, or availability of invoice data.

08

Responsible Disclosure

We welcome reports from security researchers. If you believe you have identified a vulnerability in the Platform, please contact support@afrinvoice.com with sufficient detail for us to reproduce the issue. We ask that you do not access, modify, or disclose customer or fiscal data in the course of your research, and we commit to acknowledging and investigating good-faith reports promptly.

09

Questions & Contact

Afri Invoice Nigeria Limited
Registered in Nigeria · RC 7570323
Address
10 Gbolagade Street, Ikotun, Lagos, Nigeria