You've found your first contractor in Indonesia. The paperwork looks good, the rate is locked in, and you're ready to issue that first invoice. But you're missing one critical gate: NPWP validation. Skip this step and you'll face withholding penalties, invoice rejections, GL mismatches, and audit exposure. The good news: 14 days of structured work gets you past it. NPWP—Nomor Pokok Wajib Pajak (the individual tax registration number)—is the lynchpin. It gates whether you withhold tax (PPh21 for wages, PPh22 for services), how much you withhold, whether your invoice passes e-Faktur, and how your accountant reconciles it to the GL. This playbook walks you through collection, format validation, withholding rate assignment, and audit-proof line-item tagging. Why NPWP validation matters (and what happens when you skip it) An NPWP isn't just a receipt number. It's your proof that the contractor is tax-registered with the Directorate General of Taxes (LHDN). When you invoice them, the tax authority expects that NPWP to match: Contractor name and legal entity type (individual vs. PT/company) Withholding eligibility (some professions require withholding, others don't) Withholding rate rules (15% PPh21 for wages, 2–15% PPh22 for services, depending on profession) Invoice submission to e-Faktur and reconciliation to the GL If the NPWP is missing, invalid, or mismatched, you'll see: Invoice rejection at submission (e-Faktur won't accept an unregistered tax ID) Withholding errors (you'll either over-withhold or under-withhold, creating a tax adjustment and penalty) GL divergence (invoice gross ≠ contractor payment + withholding, breaking reconciliation) Audit exposure (LHDN flags invoices with invalid NPWPs and can impose penalties on both you and the contractor) The fix is systematic: validate the NPWP format, check it against the LHDN database (if real-time lookup is available), assign the correct withholding rate, and tag every invoice line with the tax logic. Then audit it before submission. Days 1–3: Collect and format-check the NPWP Start by asking your contractor for their NPWP. Make this a required field in your contractor onboarding form—don't make it optional, and don't defer it to invoice time. NPWP format rules: An NPWP is a 15-digit number. The structure is: Digits 1–2: Registration area code (01–99) Digits 3–5: Serial number (001–999) Digits 6–8: Batch code (001–999) Digit 9: Control digit (a checksum) Digits 10–15: Registration sequence (000001–999999) Example valid NPWP: 07.123.456.0.123.456 (often written with dots, sometimes without). In your contracts or contractor profile, create a field for NPWP and add a simple client-side check: 15 digits, numeric only, no letters. If your platform has regex validation, use it: Format check: ^[0-9]{15}$ This catches typos and format errors immediately. Ask the contractor to provide their NPWP and a copy of their tax card (Kartu NPWP) or a recent letter from LHDN. Keep both in your contractor file—you'll need them if audited. Days 4–7: Validate against the LHDN database Once you have the NPWP in the correct format, check it against the Indonesian tax authority's database. LHDN offers a real-time lookup API (the taxpayer data service), but access requires registration and authorization. If your accounting software or invoicing platform integrates with it, use it. If not, you have two options: Option A: Manual verification (simpler, no API setup). Ask your contractor to provide a recent tax filing receipt or letter from LHDN that shows their NPWP. Match the number on that document to what they've given you. This is not bulletproof, but it's a strong secondary control and shows due diligence during audit. Option B: API integration (more reliable, requires setup). Work with your accountant or IT team to integrate the LHDN taxpayer data API. This will check the NPWP in real-time and return the contractor's registered name, entity type, and tax status. If the NPWP is invalid or the contractor is not registered, the API will reject it immediately. This is the gold standard but requires compliance with LHDN's technical and legal requirements. If you're using invoicing software that handles Indonesian tax compliance, confirm whether it has built-in LHDN lookup. Some platforms (like certain implementations of SAP Concur or specialist Indonesian accounting software) do; others (like generic invoicing tools) don't. Store the verification result in your contractor record. Document the date and method: "NPWP validated via LHDN API on [date]" or "NPWP validated via tax card copy on [date]." This becomes your audit trail. Days 8–10: Assign withholding rates and profession codes Indonesia's withholding tax (PPh) rules vary by contractor profession. The two main categories are: PPh21 (income tax on wages and salaries): 5–30% depending on income bracket. Most contractors fall into the 15% bracket for routine services. PPh22 (income tax on certain services and supplies): 2–15% dependi