Invalid VPOS Identifier in the XML File: Why Stripe’s VAT Number Is Incorrect

When XML audit files are checked with the free NAP Ready validator, we repeatedly encounter the same serious issue:

Invalid VPOS identifier

PROC_ID contains Stripe’s VAT number.
Appendix 33 under Regulation N-18 must be corrected immediately.

This error is not a minor technical problem with the XML file format. In most cases, it indicates that incorrect information about the virtual POS terminal was submitted when the online store was registered with the Bulgarian National Revenue Agency (NRA).

Instead of entering an identifier linked to the individual merchant, the store has used Stripe’s VAT number as the VPOS identifier.

This is incorrect.

Stripe’s VAT number identifies the Stripe company for tax purposes. It does not identify the virtual POS terminal or payment account of a specific online store, and it is not unique to an individual merchant.

What is a VPOS identifier?

When an online merchant accepts card-not-present payments by credit or debit card, information about the payment method and the payment service provider must be submitted to the NRA.

For merchants using the alternative reporting regime, Appendix 33 under Regulation N-18 includes information about the payment service provider, the virtual POS terminal, payment accounts and other details relating to the online store.

The VPOS identifier must make it possible to connect a payment configuration to the specific merchant that uses it.

It must not be:

  • Stripe’s VAT number;
  • a general company identifier belonging to Stripe;
  • a public number used by many unrelated stores;
  • an arbitrary value copied from another article, forum or merchant;
  • the same identifier for every merchant that accepts payments through Stripe.

The identifier must be based on the merchant’s own Stripe account and individual payment configuration.

Why Stripe’s VAT number is not a VPOS identifier

Stripe’s VAT number belongs to Stripe itself. It may appear on invoices, contracts, terms and conditions or other company documents.

That does not make it the identifier of your virtual POS terminal.

If more than 100 independent online stores enter the same VAT number in the VPOS field, they are effectively declaring the same identification value for their card payments.

From a data perspective, this creates an obvious problem.

When the information in XML audit files is compared with the details submitted through Appendix 33, the same identifier may appear for many unrelated merchants.

The NAP Ready Validator has already detected more than 100 stores using the same type of value. This alone is a clear sign that the entered number cannot be a unique VPOS identifier for a specific online store.

What may happen during an NRA audit?

The XML audit file contains information about sales, payments and the payment methods used by the online store. The PROC_ID field identifies the payment processor or virtual POS terminal through which the payment was processed.

When a general value shared by many merchants is recorded in this field, inconsistencies arise between:

  • the individual online store;
  • the information declared in Appendix 33;
  • the actual Stripe account used to receive payments;
  • the records in the XML audit file;
  • the information that may be provided by the payment service provider.

If the NRA performs a search or data comparison using the virtual POS identifier, the same number may be found in the XML files of many different stores.

This does not necessarily mean that all sales will automatically be attributed to one merchant. We cannot make that claim without knowing the NRA’s exact internal matching process.

However, the incorrect identifier may create serious uncertainty about which merchant received the relevant payments. This can lead to additional questions, requests for documents and explanations, and the discovery that incorrect information was submitted for the online store.

Appendix 33 is submitted separately for each online store. Using a shared VAT number instead of a merchant-specific identifier therefore contradicts the purpose of the information being declared.

The problem is not limited to the XML file

When the validator displays the following message:

PROC_ID contains Stripe’s VAT number

the first reaction is often to edit the XML file manually. That is not enough.

The XML file reflects the information configured in the merchant’s system. If an incorrect VPOS identifier was submitted in Appendix 33, the problem began when the store was registered with the NRA.

At least three places must be checked and aligned:

  • the information submitted through Appendix 33;
  • the settings of the integration or software that generates the XML file;
  • the value written to PROC_ID for each card payment.

All three must refer to the same real payment configuration.

Changing the value manually in a single XML file does not fix the underlying cause. The incorrect value may be generated again in the next audit file.

What should you do?

If the NAP Ready validator detects an invalid VPOS identifier, do not postpone the correction.

1. Check the submitted Appendix 33

  • Log in to the NRA portal and review the information submitted for the relevant online store.
  • Find the field containing the number or identifier of the virtual POS terminal.
  • If Stripe’s VAT number is entered there, the information must be corrected.

2. Identify the correct merchant-specific value

  • Do not copy a value from another online store, accounting group, forum or random publication.
  • Use information relating to your own Stripe account and the way payments are processed for your business.
  • Our complete guide to Appendix 33 under Regulation N-18 explains what information should be entered for Stripe and other payment methods.

3. Submit a correction to the NRA

  • Once you establish that the information is incorrect, update the registration details of the online store.
  • Changing the settings in your website or XML generator will not automatically update the information already submitted to the NRA.

4. Correct the software settings

  • After updating Appendix 33, check which value the integration uses for PROC_ID.
  • The value must correspond to the correct identifier declared for your online store.

5. Generate and validate a new XML file

  • After making the changes, generate a new test XML audit file and upload it to the free NAP Ready validator.
  • The validator checks not only the XML structure and XSD schema, but also performs additional logical checks on the recorded values.

Why a unique VPOS identifier matters

The main purpose of the identifier is traceability. The data must clearly show:

  • which merchant received the payment;
  • which payment service provider processed it;
  • which individual payment configuration it belongs to;
  • which sale and online store the payment relates to.

When many stores use the same general number, that traceability is lost.

Stripe’s VAT number may correctly identify Stripe as a company, but it cannot distinguish your store from Stripe’s other customers. This is why it must not be used as the merchant’s VPOS identifier in PROC_ID.

Check the XML file before submitting it to the NRA

The worst time to discover this error is after an audit has already started.

The free NAP Ready Validator allows you to check the XML audit file in advance and identify issues that may not be visible when the file is opened normally.

If you receive a warning about an invalid VPOS identifier, take it seriously.

Do not simply edit the XML text or replace the value with another arbitrary number. Check where the information comes from, correct Appendix 33, and synchronize the settings of the software used to generate the file.

The correct VPOS identifier must relate to your specific merchant configuration, not to Stripe as an international payment service provider.

This may be a small field, but it has significant importance. A single incorrect value can cast doubt on the connection between the online store, its reported sales and the card payments it has received.