Skip to main content

Jomeinvoice

Outsource e-Invoice Submission in Malaysia: LHDN Rules

The guideline lets a technology provider transmit for you. It never lets the provider carry your liability. Here is the line between the two, with the section numbers.
Reading Time: 18 minutes
Outsource e-invoice submission in Malaysia: a technology provider transmits to MyInvois while liability stays with the taxpayer
🔑Key Takeaways
  • Outsourcing is permitted. The General Guideline v4.8 recognises transmission “through Peppol service providers” and “through non-Peppol technology providers” as API methods alongside direct ERP integration. (e-Invoice General Guideline v4.8, Section 2.4)
  • Liability does not transfer. The guideline states that the supplier “is to ensure the accuracy of the information included in the e-Invoice that is submitted to IRBM for validation”, even when a technology provider creates and submits it. (General Guideline v4.8, Section 2.4.2)
  • LHDN imposes no registration or certification requirement on technology providers “at this juncture”, so vetting the provider is the taxpayer’s job, not LHDN’s. (LHDN e-Invoice FAQ, Q117 and Q118)
  • Failure to issue a compliant e-invoice carries a fine of RM200 to RM20,000 per invoice, imprisonment of up to six months, or both, under Section 82C(1) read with Paragraph 120(1)(d) of the Income Tax Act 1967. The penalty attaches to the taxpayer.
  • The businesses deciding this in 2026 are not micro-firms. Phase 4 covers annual revenue of RM3 million to RM5 million from 1 January 2026, with a relaxation period to 31 December 2027. Businesses below RM3 million are exempt unless a related-company rule pulls them in. (General Guideline v4.8, Section 1.6.1(e) and Section 1.6.10)

Yes. A business in Malaysia can outsource e-invoice submission to a third-party provider. The e-Invoice General Guideline v4.8 issued by Lembaga Hasil Dalam Negeri Malaysia (LHDN, also referred to as the Inland Revenue Board of Malaysia or IRBM) lists three ways to transmit e-invoices through the MyInvois Application Programming Interface (API): direct integration of the taxpayer’s Enterprise Resource Planning (ERP) system, transmission through a Peppol service provider, or transmission through a non-Peppol technology provider (Section 2.4). The second and third are outsourcing. What the guideline never does is move the legal duty: the supplier named on the e-invoice remains responsible for what is submitted under its Tax Identification Number (TIN).

This article is for the finance or IT lead who has to choose, or re-choose, a submission route: a company already live on a direct API build that is costing more than expected, a group with several entities under one ERP, or a business entering the mandate in 2026 with no integration in place. It sets out what the guideline allows, where liability sits, who is actually deciding this in 2026, and what to check before appointing a provider.

Verified against the e-Invoice General Guideline v4.8 (30 August 2026), the e-Invoice Specific Guideline v4.8 (7 July 2026), and the LHDN e-Invoice FAQ (5 January 2026, amended April 2026) on 18 September 2026.

Can a Business Outsource e-Invoice Submission in Malaysia?

Yes, and the permission is explicit rather than implied. Section 2.4 of the e-Invoice General Guideline v4.8 states that “API allows taxpayers to submit e-Invoices directly to IRBM” and lists the methods to transmit via API as: (i) direct integration of the taxpayer’s ERP system with the MyInvois System, (ii) through Peppol service providers, and (iii) through non-Peppol technology providers. Table 2.1 of the same guideline summarises the API mechanism as one where the “API connection may be made directly to IRBM or through intermediary technology providers”.

That gives a business three submission routes, only one of which requires no technical build. How they compare, and where each route is positioned in our guide to e-invoice integration models in Malaysia , is summarised below.

Route Who transmits to MyInvois Guideline basis Set-up effort Typical fit
MyInvois Portal The taxpayer, manually or by batch upload General Guideline v4.8, Section 2.3 None beyond portal login Low transaction volume, no invoicing system
Direct API integration The taxpayer’s own ERP or billing system General Guideline v4.8, Section 2.4(i) High: in-house development against the MyInvois Software Development Kit (SDK), plus ongoing maintenance for every validation change Large taxpayers with a development team that owns the invoicing stack
Intermediary technology provider (middleware, Peppol or non-Peppol) The appointed provider, under the taxpayer’s TIN General Guideline v4.8, Section 2.4(ii) and (iii); Table 2.1 Low to moderate: the provider builds and maintains the connection Businesses that want API-grade automation without owning the integration

Each route produces the same outcome. Once validated, MyInvois returns the IRBM Unique Identifier Number, the date and time of validation, and the information needed to form the validation link (General Guideline v4.8, Section 2.4.3). The route changes who does the work, not what LHDN receives. A fuller side-by-side is in our comparison of MyInvois Portal, direct API integration and e-invoicing middleware .

What the Guideline Says About Third-Party Providers

The General Guideline v4.8 uses the terms “technology provider”, “service provider” and “intermediary technology provider” for the same role: a party that generates and transmits e-invoices on the taxpayer’s behalf. Four passages define the arrangement.

  1. Engagement is expected, not merely tolerated. Section 2.4.1 states that taxpayers “need to configure their systems or engage a technology provider to assist them in generating e-Invoices in the required XML or JSON format” (Extensible Markup Language or JavaScript Object Notation).
  2. The provider may create and submit the document. Section 2.4.2 describes the submission step as one where “the Supplier or technology provider creates an e-Invoice in accordance with the defined UBL2.1 structure in XML / JSON format, and submits it to IRBM via API for validation”. UBL is Universal Business Language; XML and JSON are Extensible Markup Language and JavaScript Object Notation, the two file formats MyInvois accepts.
  3. The provider may receive the validation response. Section 2.4.3 states that “the Supplier or technology provider (if Supplier utilises a technology provider) will receive an API response” containing the Unique Identifier Number.
  4. The provider may sign the document. The description of the Issuer’s Digital Signature field states that “in the event where taxpayers utilise the services of service provider, the e-Invoice shall be signed using service provider’s digital certificate”.

On whether the provider needs LHDN’s approval, the LHDN e-Invoice FAQ is direct. Q117: “There is no registration requirement at this juncture. However, technology providers are responsible to ensure the functionality and reliability of their API integration with IRBM.” Q118: technology providers do not need to apply for a certification in Malaysia “at this juncture”, though “this may change in the future”. Q116 adds that “any service providers in the market that can comply to IRBM’s API requirements are welcomed”.

Important: The absence of an LHDN registration or certification step means there is no official list to check a provider against. Treat the provider’s handling of your digital certificate and API credentials as a contractual and security matter, because LHDN does not vet it for you.

The technical onboarding itself (API credentials tied to your TIN, and the digital certificate used to sign under your name) is set out in the MyInvois SDK.

Why the Taxpayer Stays Liable Even When Submission Is Outsourced

The liability position follows from four separate rules rather than one sentence.

  • The accuracy duty sits with the supplier. Section 2.4.2 of the General Guideline v4.8 places the duty to “ensure the accuracy of the information included in the e-Invoice” on the supplier, in the same paragraph that allows the technology provider to create and submit it.
  • The penalty provisions name the taxpayer. Section 82C(1) of the Income Tax Act 1967 makes failure to issue an e-invoice with the prescribed particulars an offence punishable under Paragraph 120(1)(d) by a fine of RM200 to RM20,000 per invoice, imprisonment of up to six months, or both. Section 82C(7) applies the same range to late or non-compliant consolidated e-invoices. Neither section is addressed to the provider.
  • The document carries your TIN. Every validated e-invoice is issued under the supplier’s Tax Identification Number. When LHDN’s compliance review programme examines a taxpayer’s records, it examines the documents under that TIN, whoever pressed submit. The published Compliance Review Framework allows a review to cover up to two years of assessment, and prosecution up to twelve years under Section 121(1). Our explainer on TIN codes used in Malaysian e-invoices covers what the number encodes.
  • Corrections need the taxpayer’s decision. A validated e-invoice can be cancelled within 72 hours of validation; after that, the adjustment is a credit, debit or refund note e-invoice. A provider can detect the error and prepare the correction, but the underlying commercial decision, and the exposure if it is wrong, is the taxpayer’s.

Two operational rules make the point concrete. Any single transaction of RM10,000 or more must be issued as an individual e-invoice from 1 January 2026, regardless of implementation phase or relaxation status; a provider that consolidates it has created your offence, not theirs. See the RM10,000 individual e-invoice rule for the boundary cases. And consolidated e-invoices for the remaining transactions are due within seven calendar days after month-end; a provider that misses the window leaves the taxpayer exposed under Section 82C(7). The month-end mechanics are in our consolidated e-invoice guide .

Who Is Actually Deciding This in 2026

The question “can we outsource submission” is being asked by three different groups this year, and the right answer differs for each.

Group Revenue basis Mandatory start Relaxation ends Enforcement What outsourcing means for them
Phases 1 to 3 (established, financial year 2022 revenue above RM5 million) Above RM100 million; RM25 million to RM100 million; RM5 million to RM25 million 1 August 2024; 1 January 2025; 1 July 2025 Ended Active Already live. The decision is whether to migrate from a direct API build or a first-generation vendor to a managed intermediary.
Phase 4 (established) RM3 million to RM5 million 1 January 2026 31 December 2027 1 January 2028 First implementation. Relaxation permits consolidated issuance, but the RM10,000 rule still applies.
New businesses commenced 2023 to 2025 Current revenue of at least RM3 million 1 July 2026 31 December 2027 1 January 2028 Same as Phase 4, six months later.
Below RM3 million Any category of taxpayer Exempt Not applicable Not applicable No mandate, unless a shareholder, holding company, related company or joint venture with revenue of at least RM3 million removes the exemption.

Source: e-Invoice General Guideline v4.8, Table 1.1, Section 1.5, Section 1.6.1(e) and Section 1.6.10; e-Invoice Specific Guideline v4.8, Table 16.1 and Sections 16.2 to 16.3.

The threshold moved twice; the dates never did

Two points from this table are routinely missed in vendor content. First, the RM3 million exemption threshold is recent: it replaced RM1 million on 30 August 2026, and RM1 million had itself replaced an originally planned RM500,000. A page that tells a business with RM500,000 in revenue it has a 2026 deadline is wrong under the current guideline; the change is explained in our note on the General Guideline v4.8 RM3 million exemption . Second, the relaxation period is optional and conditional. Section 16.2 of the Specific Guideline v4.8 allows Phase 4 and new-business taxpayers to issue consolidated e-invoices for all transactions until 31 December 2027, and Section 16.3 provides that no prosecution under Section 120 of the Income Tax Act 1967 will be taken during that period where the consolidation conditions are met. The relaxation does not extend to the RM10,000 rule, and the industry restrictions in Table 3.6 resume in full on 1 January 2028. Details are in our Phase 4 extension to 2028 explainer, and the exemption caveats in the SME exemption guide .

Note: For a Phase 4 business, the relaxation window is a set-up period, not a reason to defer the decision. A provider appointed in 2026 can run consolidated issuance during the window and switch on individual issuance before 1 January 2028 without a second implementation.

Direct API or Intermediary: The Decision Rule

For a business that already has a system generating invoices, the choice narrows to direct API integration or an intermediary. The guideline treats both as API submission; the difference is who owns the connection when MyInvois changes.

Direct integration makes sense where the business already runs a development team that maintains the invoicing stack and expects to keep doing so. The maintenance is not one-off. LHDN’s MyInvois SDK 1.0 release notes record a validation change that takes effect in the Production environment on 23 October 2026 (a 26-digit cap on amount fields and a 12-character cap on passport identifiers). Every such change lands as work for whoever owns the integration.

An intermediary makes sense where the business wants the outcome of API submission (validation in near real-time, the Unique Identifier Number written back to the source document, no manual keying) without owning the code. In the enterprise integrations JomeInvoice builds, the connection to the client’s ERP is custom-built per client through API or Secure File Transfer Protocol (SFTP) feeds; there is no one-click connector, because no two ERP configurations expose the same fields. The practical consequence for a multi-entity group is that one integration pattern can be reused across entities, each submitting under its own TIN, rather than each entity maintaining its own build. Businesses replacing a foreign-hosted middleware for data-residency or support reasons should read our note on choosing a local middleware over ClearTax alongside this one.

A pure business-process-outsourcing arrangement, where a provider re-keys your invoices into the MyInvois Portal, is legal under Section 2.3 of the General Guideline but delivers none of the API-side controls. It moves the typing, not the risk.

What to Check Before Appointing a Provider

Because LHDN does not register or certify providers, the due diligence is yours. The checks below map to the rules above.

  1. TIN validation before submission. The provider should validate the buyer’s TIN against LHDN’s records before the document is transmitted, not after MyInvois rejects it. This matters most for self-billed e-invoices, which may only be issued in the scenarios listed in Section 8.3 of the Specific Guideline v4.8; see our self-billed e-invoice scenarios guide .
  2. RM10,000 split logic. Confirm the provider issues an individual e-invoice for any single transaction of RM10,000 or more and never folds it into a consolidated document, regardless of your phase.
  3. Month-end consolidation timing. Consolidated e-invoices must reach MyInvois within seven calendar days after month-end. Ask how the provider handles a MyInvois outage inside that window.
  4. Validation response pass-back. The Unique Identifier Number, validation timestamp and validation link should be written back to your ERP or accounting record, so the visual representation you share with buyers carries the QR code and the audit trail is in your system, not only the provider’s.
  5. 72-hour cancellation handling. Ask how a cancellation request is authorised and executed inside the 72-hour window, and how the provider prevents an unauthorised cancellation under your certificate.
  6. Digital certificate and credential custody. The e-invoice will be signed with the provider’s certificate on your behalf. Establish contractually who holds the credentials, how access is revoked at termination, and what security assurance the provider carries. JomeInvoice, for example, holds ISO 27001, ISO 9001 and ISO 20000-1 certification and is MySTI-registered.
  7. Retention beyond the portal window. MyInvois gives recent-document access of roughly 30 days, while a compliance review can look back two years of assessment. Confirm the provider’s retention period and export format, and keep your own archive.
  8. Exit terms. Because there is no LHDN accreditation, switching providers is a commercial event, not a regulatory one. Confirm that historical validated documents and their Unique Identifier Numbers remain accessible after you leave.

Where JomeInvoice Fits

JomeInvoice is a Malaysian e-invoicing middleware that acts as the intermediary technology provider in the terms of Section 2.4 of the General Guideline v4.8. It connects an existing ERP, accounting or point-of-sale system to MyInvois through a custom-built API or SFTP integration, validates TINs before submission, applies the RM10,000 individual-issuance rule and the month-end consolidation window automatically, and writes the Unique Identifier Number and validation link back to the source record so the audit trail stays inside your system. Every document is submitted under the client’s TIN. The company is ISO 9001, ISO 20000-1 and ISO 27001 certified and MySTI-registered, which is relevant to check 6 above. For a business weighing a direct API build against a managed route, or a Phase 1 or Phase 2 company reconsidering the integration it went live with, the useful next step is a comparison of your current set-up against a managed one rather than a sales call.

Outsource the transmission, keep the accountability

LHDN’s General Guideline v4.8 lets a business hand the technical work of e-invoice submission to a technology provider, and its FAQ confirms that no registration or certification of that provider is currently required. The same guideline keeps the accuracy duty, and the Income Tax Act 1967 keeps the penalty, with the taxpayer whose TIN is on the document. The businesses deciding this in 2026 are Phase 4 companies with RM3 million to RM5 million in revenue inside a relaxation window to 31 December 2027, and earlier-phase companies reconsidering a first-generation integration. For both, the eight checks above are the difference between outsourcing a task and outsourcing your exposure.

E-Invoice Middleware for Enterprise

Compare your current submission set-up against a managed middleware route

Integrate with SAP, Oracle, Dynamics 365 and more.
Local support from Malaysia.

Book a Demo Sign Up Free
PDPA Compliant  ·  ISO 9001  ·  ISO 20000-1  ·  ISO 27001  ·  MySTI Certified  ·  STI202501062
Disclaimer: This article is for general informational purposes only and does not constitute legal or tax advice. LHDN guidelines are subject to updates. Always refer to the latest official LHDN e-Invoice Guidelines at myinvois.hasil.gov.my and consult a qualified tax professional for advice specific to your business.

Frequently Asked Questions

Can a business outsource e-invoice submission in Malaysia?

Yes. The e-Invoice General Guideline v4.8 lists transmission through Peppol service providers and non-Peppol technology providers as recognised API methods (Section 2.4). The supplier named on the e-invoice remains responsible for its accuracy (Section 2.4.2).

Does LHDN need to approve or register a third-party e-invoice provider?

No. LHDN’s e-Invoice FAQ (5 January 2026) states there is “no registration requirement at this juncture” for technology providers (Q117) and no certification requirement (Q118), while noting this may change. The taxpayer must vet the provider itself.

Who is liable if an outsourced e-invoice is wrong or late?

The taxpayer. Section 82C(1) and Section 82C(7) of the Income Tax Act 1967, read with Paragraph 120(1)(d), impose a fine of RM200 to RM20,000 per invoice, up to six months’ imprisonment, or both, on the person required to issue the e-invoice.

Is using e-invoicing middleware the same as outsourcing submission?

Yes. Middleware is the “intermediary technology provider” route in Table 2.1 of the General Guideline v4.8: it connects your system to MyInvois by API and transmits under your TIN. Manual re-keying by an accountant into the MyInvois Portal is also outsourcing, but without the API controls.

Which businesses must issue e-invoices in 2026?

Established businesses with FY2022 revenue of RM3 million to RM5 million from 1 January 2026 (Phase 4), and businesses commenced 2023 to 2025 with revenue of at least RM3 million from 1 July 2026, both with relaxation to 31 December 2027. Below RM3 million is exempt, subject to related-company rules.

Do consolidated e-invoice rules still apply when a provider submits for us?

Yes. Any single transaction of RM10,000 or more needs an individual e-invoice from 1 January 2026, and consolidated e-invoices are due within seven calendar days after month-end, whoever transmits them.

Can a provider sign e-invoices on our behalf?

Yes. The General Guideline v4.8 states that where a taxpayer uses a service provider, the e-invoice is signed using the service provider’s digital certificate. Contract for custody of that certificate and for revocation of access when the engagement ends.

Can an accounting firm submit e-invoices for several clients?

Yes, provided each document is submitted under the correct client’s TIN and each client has authorised the arrangement. The guideline places no cap on the number of taxpayers a technology or service provider may serve.

Last updated: 18 September 2026 | Written by Yinn Sheng Ng, Head of Marketing

References

To learn more about how JomeInvoice can transform your e-invoicing processes, check out JomeInvoice’s website or book a demo.

Share