Open any supplier invoice from 2026 and two things now stare back at you that weren't there five years ago: an ATCUD string at the bottom, and a QR code in the corner. Both are mandatory. Both show up in SAF-T — see our SAF-T Portugal guide for the full filing mechanics. And when they don't match what AT already has, it's your inbox that hears about it.
For accountants processing dozens or hundreds of supplier invoices a month, this isn't a theoretical compliance topic. It's a set of small new failure modes that quietly slip into the monthly close — usually noticed two weeks after filing, when a cross-check at AT comes back flagged.
Here's what actually changes in the processing workflow, and where the common traps sit.
What ATCUD Is, in One Paragraph
ATCUD stands for Código Único de Documento — a unique code that identifies every invoice issued in Portugal. It's built from two parts separated by a hyphen: a validation code for the document series (obtained by the issuer from AT) plus the sequential document number. So a real ATCUD looks like CSDF7T5H-35 — not random, not self-generated, and tied to a specific series registered with the tax authority.
The QR code is the human-readable (well, machine-readable) sibling. It encodes the key invoice fields — NIFs, date, totals, tax breakdown, ATCUD, document hash — into a single 2D code that anyone with a phone can scan and verify against AT.
Together, they make every invoice self-describing and self-verifying. That sounds neat in a press release. In practice, it means your processing checks have new jobs.
What AT Actually Validates
AT does not just trust what the issuer wrote. When your SAF-T is submitted, the following now get cross-checked — automatically, silently, at scale:
- ATCUD structure. Is it in the correct format (
<validation code>-<sequence number>)? Is the validation code one that AT registered for that issuer's series? - Series consistency. Does the ATCUD's series match the series declared in the SAF-T
InvoiceTypeandInvoiceNofields? - QR code payload vs. invoice body. Do the totals, NIFs, and dates inside the QR match the fields declared elsewhere in the invoice and in the SAF-T entry?
- ATCUD in SAF-T. Is the
ATCUDelement actually present for every invoice that legally requires one?
When any of these fail, the invoice may still post in your accounting software — but it becomes a liability the moment AT runs a cross-reference, which is now continuous rather than annual.
Process invoices in minutes, not hours
Faturiza works with the Google Drive & Sheets you already use.
Where Things Quietly Go Wrong
After processing a few thousand supplier invoices with ATCUD and QR codes across client portfolios, the same failure patterns keep surfacing. They're rarely dramatic. They're the kind that eat an hour on day 14 of the month.
1. Missing ATCUD on small-supplier invoices
Every Portuguese-issued invoice requires ATCUD since January 2023. But a long tail of small suppliers — a freelancer issuing a recibo verde, a micro-business using an older billing tool, a restaurant with a non-compliant till — still emits invoices without it. Technically, those invoices are non-conforming, and AT can reject them as deductible expenses.
The accountant's practical problem: you can't force the supplier to reissue. But you do need to catch these before filing. A quick policy like "flag any supplier invoice without ATCUD and notify the client within 48 hours" is far cheaper than a VAT adjustment six months later.
2. ATCUD typos from manual entry
When ATCUD is keyed in by hand — especially the eight-character validation code — transpositions are inevitable. The invoice number ends up correct, the amount is correct, but the ATCUD's first half has a zero where an O should be, or vice versa. It posts fine. AT flags it later.
The fix is structural: ATCUD should be extracted, not typed. If your invoice processing pipeline reads the QR code instead of transcribing ATCUD from the PDF text layer, this whole failure mode disappears. The QR payload is the source of truth; typing is noise.
3. QR payload mismatch with the invoice body
Occasionally — and this is the one that really bites — the QR code on an invoice encodes totals or a NIF that don't match the visible invoice. This usually happens when the issuer's software generated the QR from one version of the document, then someone manually corrected a line afterwards without re-generating the code.
For the accountant, the question becomes: which version is truth? AT will treat the QR as authoritative. So will a well-configured processing pipeline. If the QR says €1,230.00 and the printed total says €1,230.50, you have a non-conforming invoice — not an arithmetic error.
4. Series confusion across reissues
When a supplier reissues an invoice (replacing a cancelled one, for example), the new document should carry a fresh ATCUD from a valid series — not a reused one from the cancelled document. Cheap or outdated billing software occasionally reuses series in ways that break the uniqueness guarantee. The result: a duplicate ATCUD in your SAF-T across months, which AT's system treats as a red flag.
You can't fix the supplier's software. You can flag the duplicate during processing and ask for clarification before filing.
5. Foreign invoices without ATCUD
Invoices from EU or non-EU suppliers obviously don't carry ATCUD — it's a Portuguese construct. But the SAF-T expects the ATCUD element for any Portuguese-issued document. Processing pipelines that naively require ATCUD on every invoice end up either rejecting legitimate foreign invoices or silently inserting placeholder values that break the SAF-T schema.
The right behaviour is conditional: apply ATCUD validation only when the issuer is Portuguese (NIF starts with the Portugal country code or is a bare 9-digit Portuguese NIF). For foreign invoices, skip ATCUD checks and apply the reverse-charge VAT rules instead.
What Changes in the Monthly Close
Compared to the pre-ATCUD workflow, three things shift concretely:
Validation moves earlier. Catching ATCUD issues at the moment of receipt is an order of magnitude cheaper than catching them at SAF-T generation. An invoice missing ATCUD on day 3 can still be reissued by the supplier. The same invoice on day 28, with the filing window closing, can't.
QR becomes the entry point. If your processing tool reads QR codes, you get NIFs, totals, tax breakdown, and ATCUD in one structured object — no OCR ambiguity, no transcription. This is the single biggest quality upgrade available right now. The invoices are literally designed to be machine-read.
SAF-T validation has more surface. Your monthly SAF-T validator now needs to check ATCUD presence, ATCUD format, and series consistency — not just totals and NIFs. Most off-the-shelf accounting software does this automatically. Spreadsheet-based workflows do not.
A Practical Checklist
Use this at the start of each month. It takes about 10 minutes once the habits are in place.
- For every supplier invoice received: confirm ATCUD is present and well-formed (two parts separated by a hyphen; first part is alphanumeric; second part is numeric).
- Scan the QR code on a sample of invoices per supplier per month. Confirm the payload matches the invoice body — NIFs, date, totals. If you're on automation, this runs on every invoice, not a sample.
- Flag ATCUD-less Portuguese invoices to the client within 48 hours of receipt, not at month-end.
- Handle foreign invoices with a different rule set. Skip ATCUD validation, apply reverse-charge VAT rules, and document the supplier's tax ID country.
- Before SAF-T generation, run a final sweep for: duplicate ATCUDs, missing ATCUDs on Portuguese invoices, and QR payload mismatches flagged during processing.
- After SAF-T submission, watch the Portal das Finanças message box for ATCUD-related notifications. They arrive fastest — usually within 72 hours of a flagged cross-reference.
What to Do Differently
The temptation with ATCUD and QR codes is to treat them as another box to tick on the invoice and move on. For most accounting practices, that's an expensive mistake. The codes are not decoration — they're the main channel through which AT now verifies every invoice you file.
Treat them as your primary data source. Extract from the QR, not from the PDF text layer. Validate ATCUD on receipt, not at filing. And build your monthly close around the principle that a compliant invoice is a machine-readable invoice — because that's what 2026 actually is.
If you handle supplier invoices for more than a handful of clients, this is the processing shift that pays back fastest.
Faturiza is built for Portuguese accountants who want ATCUD, QR, and SAF-T validation running automatically across every client. Start free during beta at /para-contabilistas, and see the companion guide on SAF-T compliance in Portugal for how this fits into your monthly filing.
Part of our SAF-T & Compliance guide series.
For accountants
Running this kind of workflow for multiple clients?
Faturiza has a multi-client dashboard built for accountants. Each client gets their own folder, email intake, and SAF-T-ready export.
Manuel Monteiro
Founder, Faturiza · LinkedIn
Ready to automate your invoices?
Try Faturiza for free and save hours every week.
Join 500+ businesses saving hours every week