In the last six weeks, Malaysia's LHDN (Inland Revenue Board) has begun auditing invoices sent via WhatsApp. They're finding the same five gaps in nearly every case: missing NPWP (Tax ID), incomplete GST/SST registration fields, no sequential invoice numbering, absent payment proof links, and zero audit trails. The result is a 14-day lockdown on payments and a compliance file that takes weeks to close. If you've sent invoices over WhatsApp in the last 90 days—and most Malaysian businesses have—you need to audit them now. What LHDN is actually looking for (and why your invoices are failing) LHDN's audit trigger is simple: an invoice sent via WhatsApp lacks the statutory fields required under Malaysian tax law. Specifically: NPWP (Nomor Pokok Wajib Pajak) — Your 15-digit tax identification number must appear on every invoice. Missing it is an automatic red flag. GST/SST registration number and date — If you're GST/SST registered, the certificate number and effective date must be legible and match your current status. LHDN cross-checks this against their live register. Sequential invoice numbering with no gaps — WhatsApp invoices often reuse numbers or skip sequences. LHDN flags these as a fraud indicator. Payment proof and settlement timestamp — WhatsApp invoices sent without a corresponding payment link, proof of payment date, or settlement confirmation are treated as incomplete transactions. Audit trail and sender identification — LHDN wants to know who sent the invoice, when, and to whom. WhatsApp's default metadata does not include this. No trail = no proof of intent. The lockdown happens because LHDN cannot verify the invoice's authenticity without these fields. You cannot collect payment, and the invoice cannot be matched to your GST/SST return. Until the gaps are closed, the invoice is suspended. The 14-day audit: What to check right now Day 1–2: Pull all WhatsApp invoices from the last 90 days. Export every invoice you've sent via WhatsApp since 90 days ago. If you're using a CRM or accounting tool, pull the export directly. If you're using WhatsApp Business or a manual process, you'll need to log each one manually. Do not skip this—LHDN's audit scope is typically three months. Day 3–4: Validate NPWP presence and format. Check that your NPWP appears on each invoice. The format is: XX.XXX.XXX.X-XXX.XXX (15 digits, grouped as shown). A missing digit, transposed number, or abbreviated format will fail. Create a simple spreadsheet: Invoice Number | NPWP Present (Y/N) | Format Correct (Y/N) | Status. Day 5–6: Cross-check GST/SST registration status. Log into LHDN's online portal and pull your current GST/SST certificate. Verify that the certificate number and effective date on each WhatsApp invoice match. If you renewed your certificate or let it lapse, any invoices sent after the change date with the old number are non-compliant. Record the discrepancies in your spreadsheet. Day 7–8: Audit sequential numbering for gaps and duplicates. Sort your 90-day WhatsApp invoices by invoice number and check for: Gaps in sequence (e.g., WA-001, WA-002, WA-004 with no WA-003) Duplicate numbers (two invoices with the same number sent to different customers) Out-of-sequence sends (e.g., WA-010 sent before WA-009) LHDN flags these as potential fraud. Record any gaps or duplicates and the reason (e.g., 'voided invoice' or 'manual renumbering'). You'll need to explain each one in your compliance file. Day 9–10: Verify payment proof and settlement data. For each invoice, check: Does the WhatsApp message include a payment link (Stripe, Razorpay, local gateway)? Is there proof of payment (receipt, transaction ID, settlement confirmation)? Does the payment date match the invoice date? (LHDN flags invoices paid weeks later as cash-flow manipulation.) If an invoice was sent but never paid, flag it as 'unpaid' and note the customer and date. Unpaid invoices sent via WhatsApp are treated with extra scrutiny because there's no payment trail. Day 11–12: Check for audit trail and sender metadata. Pull the metadata for each WhatsApp message (sender number, timestamp, delivery confirmation). WhatsApp Business and most CRM integrations log this automatically. If you're using plain WhatsApp, you may not have this data. Missing metadata is a compliance gap—you'll need to document it and implement logging going forward. Day 13–14: Compile and remediate. Create a summary report: Total invoices audited | Compliant invoices | Non-compliant invoices | Breakdown by gap type. For each non-compliant invoice, you have three options: Reissue — Send a corrected invoice with all required fields. Mark the original as 'superseded.' Amend — If the customer has already paid, send an amendment document (not a new invoice) listing the corrections. Document — If neither is possible, create a compliance memo explaining the gap and the customer's status (e.g., 'paid but invoice lost,' 'customer dispute'). The goal is to show LHDN that you are aware of the gap