Research: Dutch Audit Standards & Compliance Posture for Athena
Research date: 2026-09-01. Compiled for the Athena project (AI-assisted Dutch financial-audit tool, initial scope: liquide middelen / cash audit). Owner-directed research relayed via manager orchestrator, 2026-09-01.
Scope note: this document reports research findings only. It does not specify Athena's architecture or write any of the project's own docs — that is being done in parallel by a separate agent from the training-data side. Findings below should be handed to that effort.
1. NBA-Standaarden / NV COS (200-series) — audit evidence, fraud, and external confirmations
Summary
The Dutch translation/adoption of ISA is formally called "Nadere voorschriften controle- en overige standaarden" (NV COS), published and maintained by the NBA (Koninklijke Nederlandse Beroepsorganisatie van Accountants). It is codified in the HRA (Handboek Regelgeving Accountancy), an official regulation vastgesteld under Dutch law (see Staatscourant publications, e.g. stcrt-2022-32525 and stcrt-2022-1836). Individual standards are numbered identically to their ISA counterparts — the numbering does map 1:1 to ISA numbers in the current (post-2022) HRA edition, confirmed by direct inspection of the NBA website:
- Standaard 200 — "Algehele doelstellingen van de onafhankelijke accountant, alsmede het uitvoeren van een controle overeenkomstig de Standaarden." Confirmed URL:
https://www.nba.nl/wet--en-regelgeving/hra/1619/1645/1646/1647/. Contains the overall audit objectives, definitions (15 terms), requirements on ethics/professional skepticism/judgment, and extensive application guidance. Cross-references Standaard 240 explicitly (e.g. §A20, A23, A53 on indications of possible fraud, including senior-management involvement).
- Standaard 240 — "De verantwoordelijkheden van de accountant met betrekking tot fraude in het kader van een controle van financiële overzichten." Confirmed URL:
https://www.nba.nl/wet--en-regelgeving/hra/1619/1645/1646/2169/. Three objectives: (1) identify/assess fraud risk of material misstatement, (2) obtain sufficient appropriate audit evidence on assessed fraud risks via appropriate responses, (3) respond appropriately to fraud or suspected fraud identified during the audit. Defines fraud (§240.12) as an intentional act using deception for unjust/illegal advantage, by management, those charged with governance, employees, or third parties. Distinguishes fraudulent financial reporting from misappropriation of assets. Directly relevant to Athena's finding types:
- Journal entry testing requirement: auditors must design procedures to test the appropriateness of journal entries and other adjustments, including inquiring about inappropriate activity in the entry-recording process, selecting entries at period-end, and considering testing entries throughout the period (not just year-end). This is the direct standards basis for finding F-002 (unsupported manual journal entries lacking a bank mutation).
- Management override of controls: treated as a fraud risk present in every entity by definition; auditors must test journal entries/adjustments regardless of other risk assessment results, review accounting estimates for bias, and evaluate the business rationale of significant unusual transactions. Directly supports kiting-style year-end timing manipulation (F-001) as an override-of-controls fraud risk category.
- Standaard 500 — "Controle-informatie" (audit evidence). Confirmed URL:
https://www.nba.nl/wet--en-regelgeving/hra/1619/1645/3835/3836/. Objective: design and perform procedures enabling the auditor to obtain sufficient and appropriate ("voldoende en geschikte") audit evidence. "Sufficiency" = quantity (driven by risk assessment and evidence quality); "appropriateness" (geschiktheid) = quality, meaning relevance and reliability. Reliability framework: evidence from independent external sources is more reliable than internally generated information; reliability also depends on the entity's internal controls over how the information was prepared.
- Standaard 505 — "Externe bevestigingen" (external confirmations). Confirmed URL:
https://www.nba.nl/wet--en-regelgeving/hra/1619/1645/3835/4047/. Objective: design and perform external confirmation procedures to obtain relevant and reliable audit evidence, per Standaard 330 and Standaard 500. Excludes litigation/claims inquiries (covered by Standaard 501). Defines: external confirmation, positive confirmation request, negative confirmation request, non-response, exception. Requires the auditor to maintain control over the confirmation request process, address management refusals to permit confirmation, evaluate response reliability, investigate exceptions, and perform alternative procedures for non-responses. The Standaardbankverklaring (see section 2) operationalizes this standard for bank confirmations specifically.
- Standaard 501 — "Controle-informatie — Specifieke overwegingen voor geselecteerde posten," which per NBA's own cross-reference addresses the auditor's specific considerations in obtaining sufficient appropriate evidence under Standaard 330/500 for particular items (litigation/claims, inventory, segment information — litigation and claims inquiries are explicitly carved out of Standaard 505 into 501).
- The full 200-series/300-series numbering chain confirmed present in the HRA includes: 210, 220, 230, 240, 250, 260, 265, 300, 315, 320, 330, 450, 500, 501, 505, 510, 520, 530, 540, 550, 570, 610, 700, 705, 800.
Implication for Athena
- Athena's four finding types map onto specific Standaarden the tool should cite in its output: F-001 (kiting) → Standaard 240 (management override of controls / fraud risk); F-002 (unsupported manual journal entries) → Standaard 240's explicit journal-entry-testing requirement; F-003 (G-rekening restricted cash) → Standaard 500 (evidence sufficiency/appropriateness for balance sheet presentation) plus BW2 art. 2:372 lid 2 (see section 3); F-004 (lapping) → Standaard 240 (asset misappropriation) and Standaard 330 (response to assessed risk).
- Bank confirmation extraction (guarantees/securities) should be framed as supporting Standaard 505 external-confirmation evidence, not as a standalone AI output — the auditor must still control the confirmation process and evaluate reliability per 505's requirements.
- All four Athena finding types should be labeled/output as audit evidence supporting professional judgment, never as an automated conclusion — this is reinforced independently in section 6 (AFM/NBA AI guidance) but is also implicit in Standaard 200's core requirement that the auditor personally exercises professional skepticism and judgment.
Sources
- 200 Algehele doelstellingen van de onafhankelijke accountant — NBA.nl, official
- 240 De verantwoordelijkheden van de accountant met betrekking tot fraude — NBA.nl, official
- 500 Controle-informatie — NBA.nl, official
- 501 Controle-informatie - Specifieke overwegingen voor geselecteerde posten — NBA.nl, official
- 505 Externe bevestigingen — NBA.nl, official
- Nadere voorschriften controle- en overige standaarden — NBA.nl, official regulation index
- Staatscourant 2022, 32525 — Nadere voorschriften controle- en overige standaarden — Overheid.nl, official gazette
- NBA-handreiking 1153: Frauderisicoanalyse — NBA.nl, official practitioner guidance, explicitly cross-references Standaarden 240 and 330
2. NV COS controlestandaarden voor liquide middelen — practitioner-level cash/bank audit guidance
Summary
There is no separate, standalone "NV COS voor liquide middelen" standard — cash/bank audit procedures are governed by the general standards above (240, 330, 500, 505), applied to the liquide middelen balance sheet line. The concrete, Dutch-specific practitioner artifact is the Standaardbankverklaring (Standard Bank Confirmation), jointly developed and maintained by the NBA and NVB (Nederlandse Vereniging van Banken):
- Official NBA tool page:
https://www.nba.nl/tools-en-ondersteuning/tools-en-modellen/standaardbankverklaring/.
- Purpose: lets the auditor obtain, directly from the bank, information the entity's records alone cannot substantiate (per NBA's own framing: matters the auditor "can only establish via information from third parties, usually the bank").
- Content confirmed on official NBA page: endorsement rights on bills of exchange, guarantees and indemnities, credit facilities and collateral/security arrangements, and other banking matters. A separate confirmation is submitted per legal entity in a group; one bank response covers all accounts that entity holds at that bank. Contains both mandatory and situational/optional questions. Must be signed by an authorized bank relationship officer; improperly signed declarations are returned.
- Explicitly tied to Standaard 505 by NBA's own cross-reference.
- Digital request channel: as of January 2025, digital requests are supported only via ING and Rabobank; other banks require postal requests, with banks committing to respond within 15 working days (per NBA news item, Jan 2025, and Rabobank/ABN AMRO service pages).
- There has been recent internal professional debate (accountant.nl opinion piece, Jan 2023) arguing the standard bank confirmation format is outdated for the digital era — worth monitoring but not yet resulting in a formal standard change as of this research date.
Kiting/lapping detection: no NBA-published Dutch-language standard or handreiking was found that documents specific audit procedures for detecting kiting or lapping by name. These are US/international forensic-accounting terms (AICPA/ACFE tradition); Dutch audit literature treats the underlying risks generically under Standaard 240 (fraud risk, management override, asset misappropriation) rather than naming these specific schemes. This is a research gap: no authoritative NBA source names "kiting" or "lapping" specifically — Athena's terminology for these findings is importing US forensic-accounting vocabulary onto a Dutch standards base, which is defensible (the underlying risk categories are covered) but should not be presented as if it maps to a named Dutch standard.
Bank reconciliation: no distinct NBA-published standard procedure for GL-to-bank-statement reconciliation was found beyond the general application of Standaard 500 (evidence) and 505 (external confirmation) — this is treated as ordinary audit technique/practice rather than codified standard text.
Implication for Athena
- The bank-guarantee/securities extraction feature should be explicitly modeled on the Standaardbankverklaring's actual question structure (credit facilities, securities/collateral, positive and negative declarations) rather than an ad hoc schema — this is the real-world document format the tool will encounter as its "Word bank confirmation letter" input class.
- Athena's kiting/lapping finding labels should be documented internally as forensic-accounting terms mapped onto Standaard 240 fraud-risk categories, not as terms with independent Dutch standards backing — avoid implying NBA has a named "kiting standaard."
Sources
3. BW2 Titel 9 — Burgerlijk Wetboek Boek 2, Titel 9 (jaarrekeningenrecht)
Summary
Confirmed via direct fetch of the operative article text (multiple mirror sources; direct wetten.overheid.nl fetch was not reachable in this session, so treat article text below as verified via secondary legal-database mirrors (wetboekplus.nl, hodak.nl, lawyrup.nl) rather than the primary government source — flagged per instruction to note when only secondary sources were reachable):
- Artikel 2:372 BW (part of Afdeling 3, §2 Activa — balance sheet asset provisions):
- Lid 1: "Onder de liquide middelen worden opgenomen de kasmiddelen, de tegoeden op bank- en girorekeningen, alsmede de wissels en cheques." (Liquid assets comprise cash on hand, balances on bank and giro accounts, and bills of exchange and cheques.)
- Lid 2: "Omtrent de tegoeden wordt vermeld, in hoeverre deze niet ter vrije beschikking van de rechtspersoon staan." (Disclosure must be made of the extent to which these balances are not freely available ("niet vrij beschikbaar") to the legal entity.) This is the direct statutory basis for Athena's F-003 finding (G-rekening restricted cash).
- Secondary commentary (boekhoudplaza.nl, jortt.nl style sources, consistent across multiple secondary sites) confirms liquide middelen that are unavailable for longer than one year should be reclassified out of vlottende activa (current assets) into financiële vaste activa (financial fixed assets) — this is standard Dutch GAAP/RJ practice guidance layered on top of the BW article, not the BW article's own text; flagged as secondary-source-only.
- Artikel 2:373 BW: verified this article governs equity presentation (eigen vermogen: geplaatst kapitaal, agio, herwaarderingsreserves, wettelijke en statutaire reserves, overige reserves, onverdeelde winsten; foreign-currency translation disclosure), not liquid assets or current-asset valuation. An earlier search result had conflated this article with liquid-asset provisions — corrected here after direct-text verification via hodak.nl.
- Artikel 2:384 BW: governs the general valuation basis for all assets/liabilities (acquisition/manufacturing cost vs. current value as the two admissible bases; lid 2 = prudence principle — profits recognized only when realized at balance sheet date; lid 3 = going-concern principle). This is the general valuation-basis article that liquide middelen (nominal value, as a monetary asset) falls under, though the specific "liquide middelen gewaardeerd tegen nominale waarde" phrasing was found only in secondary practitioner sources (e.g. maena.nl, boec.nl), not confirmed against primary article text in this session — flagged as unverified against primary source.
Implication for Athena
- The tool's F-003 output (G-rekening balance "not vrij beschikbaar") should cite Artikel 2:372 lid 2 BW directly and by exact article number — this is a confirmed, on-point statutory citation, not an inference.
- Athena should NOT cite Artikel 2:373 in relation to liquid assets (confirmed miscite risk) — that article is equity presentation only.
- Research gap: the primary source (wetten.overheid.nl) itself was not directly fetchable in this session (returned unusable/blocked content or was not attempted with a working URL); all BW2 findings above rest on secondary legal-database mirrors that quote the article text directly and consistently across independent sources, giving reasonable confidence, but a follow-up direct pull of wetten.overheid.nl/BWBR0003045 is recommended before hard-coding citations into Athena's compliance copy.
Sources
4. XAF / SAF-T-NL auditfile specification
Summary
- Current official standard: XAF (XML Auditfile Financieel), currently at version 4.0 (specifically point releases 4.0.2 and 4.0.3 confirmed present on the official portal). XAF 4.0 became mandatory as of 1 January 2026, retiring the prior XAF 3.2 format (in use since 2014). The Belastingdienst states plainly: "XAF 3.2 files are no longer accepted by the Belastingdienst from January 1, 2026." Correction (2026-09-03, primary-source ODB scrape): the odb.belastingdienst.nl Auditfiles start page (fetched 2026-09-02) carries the news item "Belangrijke update: Uitfasering oude Auditfiles Financiëel XAF per 01-01-2027" (published 22-04-2026) — the phase-out of old XAF versions is per 1 January 2027, not 2026 as stated in the preceding sentences (datadump
belastingdienst/odb/auditfiles-index.txt).
- Authoritative maintaining body: confirmed via direct fetch of the Belastingdienst's own ODB (Ondersteuning Digitaal Berichtenverkeer) portal at
https://odb.belastingdienst.nl/auditfiles/ — this is the current official, primary source for the schema and documentation. It also lists the sibling auditfile family: XAA (afrekensystemen), XAB (taxi boordcomputer), XAK (kansspelen op afstand), XAR (ritregistratiesystemen), XAS (salaris).
- Governance structure: per the Dutch Wikipedia article on Auditfile (cross-checked against the ODB portal), the standard is currently managed by the "Auditfileplatform", described as a collaboration between the Belastingdienst, SRA (accountancy branch organization), and commercial parties. The original historical development of the first Dutch auditfile was led by the Belastingdienst itself, not NOAB. This corrects the research brief's premise that XAF was "maintained historically by NOAB" — no source found in this research supports a NOAB origin; NOAB (Nederlandse Organisatie van Administratie- en Belastingdeskundigen, an accounting-office trade body) is a distinct, unrelated organization. The version history found (via auditfile.nu) shows: ASCII Auditfile Financieel (CLAIR 1.0, designed by Belastingdienst) → XML Auditfile Financieel 1.0 (CLAIR 2.0, designed by SRA/Harold Kinds) → XAF 3.0 (designed by ABZ, added sub-administrations/opening balances) → 3.1 → 3.2 (RGS integration, master data history) → 4.0.
- XAF 4.0 structural changes: reduces data elements from ~250 (in 3.2) to ~90, driven by the observation that many 3.2 fields were inconsistently or incompletely populated by software vendors in practice. Now explicitly aligned with RGS (Referentie GrootboekSchema), the Dutch standard reference chart of accounts. Developed with a stakeholder "sounding board group" (accountants + software vendors) for the 4.0 redesign.
- Relationship to SAF-T: confirmed the Netherlands is explicitly NOT a SAF-T country. XAF and SAF-T "serve the same fundamental purpose" (structured, machine-readable financial data for tax/audit authorities) but are technically distinct standards with different XML schemas and data element specs — no merger is planned. Historically notable and worth flagging: one secondary source (invoicedataextraction.com) states the Dutch auditfile effort predates and reportedly influenced/inspired the OECD Committee on Fiscal Affairs' later development of the international SAF-T standard — i.e., the historical relationship is the reverse of "XAF as a derivative of SAF-T": XAF came first. This is stated only by a secondary/commercial blog source and was not independently corroborated by an OECD or Belastingdienst primary source in this research — flag as plausible but unverified.
- XSD schema access: the official download location is confirmed to be
https://odb.belastingdienst.nl/auditfiles/xmlauditfile-financieel-xaf-v-4-0-3/ (and the 4.0.2 equivalent), each offering a downloadable ZIP containing the schema/documentation package. This page required an authenticated login in this research session (WebFetch hit a login wall, not the document content) — I could not directly confirm the XSD file's internal contents/structure. The background page https://odb.belastingdienst.nl/auditfiles/achtergrond-informatie-xaf4-0/ was reachable and confirms the 250→90 field reduction and RGS alignment narrative but did not itself expose the schema.
Implication for Athena
- Athena's XAF ingestion/validation module should target XSD v4.0.3 (the current point release) as the authoritative schema, sourced from
odb.belastingdienst.nl/auditfiles/ — this requires either a manual authenticated download (the portal gates the ZIP behind login) or locating a redistributed copy from an ERP vendor (e.g. Microsoft Dynamics 365's NL localization docs reference the 4.0 schema and may redistribute or link it without a login wall — worth checking as a fallback).
- Athena's training-data documentation claim that its sample XAF is "not a formal validation set against an official XSD" is accurate and should remain — a follow-up task (outside this research scope) is needed to actually obtain the authenticated XSD and build real schema validation.
- Athena should not describe XAF as "Dutch SAF-T" or "the NL implementation of SAF-T" — confirmed these are formally distinct, non-interoperable standards. If historical framing is needed, "XAF pre-dates and is understood to have informed the later international SAF-T standard" is the best-supported framing, caveated as secondary-sourced.
- The RGS (Referentie GrootboekSchema) alignment in XAF 4.0 is a new dependency worth noting: Athena's XAF parser should be aware that GL account codes in 4.0-era files are expected to map to RGS reference codes, which could be a useful cross-check signal for the tool's ledger-mapping logic.
Sources
- Auditfiles — Ondersteuning Digitaal Berichtenverkeer (ODB) Belastingdienst — Belastingdienst, official, primary
- Achtergrond informatie XAF4.0 — ODB Belastingdienst — Belastingdienst, official, primary
- XMLAuditfile Financieel (XAF) v 4.0.3 — ODB Belastingdienst — Belastingdienst, official, login-gated — content not directly verified
- Auditfile — Wikipedia (NL) — secondary/tertiary but cross-checked, cites Belastingdienst as originator
- XAF Auditfile financieel historie en toepassing — auditfile.nu — secondary, version-history detail
- Netherlands Auditfile Financieel (XAF 4.0) Requirements Guide — secondary/commercial blog, source of the unverified "XAF inspired SAF-T" claim
- Gebruik regelgevingsupdate van de Audit File Financial - XAF 4 — Microsoft Learn — secondary (vendor documentation), corroborates Jan 2026 mandatory date
- Gap flagged: could not directly access/verify the XAF 4.0.3 XSD schema file contents — portal requires authentication. Corrected premise: no evidence NOAB ever maintained XAF; originator is Belastingdienst, current governance is the Belastingdienst/SRA "Auditfileplatform."
5. G-rekening (geblokkeerde rekening) / WKA (Wet Ketenaansprakelijkheid)
Summary
- Legal basis: chain liability ("ketenaansprakelijkheid") for outstanding wage tax and social-security contributions in subcontracting chains is codified in the Invorderingswet 1990 (Tax Collection Act 1990), specifically Artikel 34 (aannemersaansprakelijkheid, contractor liability) and Artikel 35 (ketenaansprakelijkheid proper, liability up the full subcontracting chain), in force since 1 June 1990. The commonly-used shorthand "WKA" (Wet Ketenaansprakelijkheid) refers to this liability regime as embedded in the Invorderingswet, not a free-standing separate statute.
- Mechanism / how the G-rekening provides relief: Artikel 34 lid 3 and Artikel 35 lid 5 of the Invorderingswet 1990 provide that a contractor's/principal's liability is reduced by amounts deposited on the subcontractor's G-rekening — i.e., depositing part of the invoice amount into the subcontractor's blocked account gives the payer statutory protection ("vrijwarende werking") against being held personally liable for the subcontractor's unpaid wage tax/social-security debt, up to the deposited amount. This reduction does not apply if the payer knew or should reasonably have suspected the subcontractor would misuse the deposited funds.
- Restriction mechanism confirmed via Belastingdienst's own page (
belastingdienst.nl/.../g-rekening): a G-rekening is a geblokkeerde bankrekening tied to one or more specific wage-tax/VAT sub-numbers. Funds on it may only be used to pay payroll taxes (loonheffingen) and/or VAT (btw) for those specific sub-numbers to the Belastingdienst — payments must reference specific payment/assessment identifiers to ensure correct allocation. Self-employed persons without personnel (zzp'ers) are not eligible to open one. The account must be held at a bank where the applicant already holds a regular business account. G-rekening numbers are identifiable by containing the digits "099" in specific positions after a four-letter bank code.
- Historical note: prior to 1 January 2016, an alternative "WKA-depotrekening" mechanism also existed; since that date, the G-rekening deposit is the only route to obtain the chain/inlener-liability exemption (per one secondary source — not independently re-verified against a primary Belastingdienst historical page in this session).
- Deblokkeren (unblocking/release of excess funds): possible via a formal request when the balance exceeds the entity's actual tax liability; per the Belastingdienst page this process typically takes around two weeks, though a separate secondary source (Booij Legal & Tax, discussing G-rekening funds for "uitleners"/staffing agencies) cautions that release is conditional — e.g., not available while a special payment-deferral request is still under review, or was granted but no formal collection measures have yet been taken, or absent formal (re)assessment notices. That source frames premature/uncautious treatment of G-rekening balances as "freely available" as a director-liability risk (bestuurdersaansprakelijkheid) if payroll tax/VAT debts subsequently accumulate unpaid.
- Accounting/disclosure treatment: no explicit NBA or RJ (Raad voor de Jaarverslaggeving) source was found in this research stating a specific bookkeeping/disclosure rule for G-rekening balances beyond the general statutory disclosure requirement in Artikel 2:372 lid 2 BW (see section 3) that balances "not freely available" to the entity must be separately disclosed. The G-rekening's restriction (funds usable only for tax/social-security payments to the Belastingdienst, not for general operating purposes) is a textbook case of a balance that is legally held by the entity but not vrij beschikbaar — this is the direct legal-factual predicate for Athena's F-003 finding, but the specific instruction "must be separately assessed/presented" is the tool's own synthesis of Art. 2:372 lid 2's general disclosure duty applied to this specific instrument, not a G-rekening-specific rule found in any standard.
Implication for Athena
- F-003 findings should cite two things together: (1) the factual legal restriction on G-rekening funds per Invorderingswet 1990 art. 34/35 (funds usable only for wage-tax/VAT payment to the Belastingdienst), and (2) the disclosure obligation this triggers under Artikel 2:372 lid 2 BW (liquid assets not freely available must be separately stated). These are two distinct statutes serving two distinct purposes (tax-liability protection mechanism vs. financial-statement disclosure rule) and Athena's output/documentation should not conflate them into a single citation.
- Athena should reference "WKA" as informal shorthand for the Invorderingswet 1990 art. 34/35 chain-liability regime, not as an independent act — if the tool's docs currently imply a standalone "Wet Ketenaansprakelijkheid" statute exists, that should be corrected.
- Consider flagging in Athena's F-003 finding language that G-rekening balance restriction is self-evident from the account type (it is definitionally a geblokkeerde rekening) rather than something requiring inference — the auditor's job per Standaard 500 is to obtain evidence of the balance's existence/amount (e.g. via bank confirmation) and confirm proper disclosure, not to determine restriction status, which is inherent to the account.
Sources
- Invorderingswet 1990 artikel 35 — InView — secondary legal database, quotes primary statute text
- Invorderingswet 1990 artikel 34 — InView — secondary legal database
- G-rekening aanvragen, gebruiken, muteren, deblokkeren of opheffen — Belastingdienst — Belastingdienst, official, primary
- Ketenaansprakelijkheid — Belastingdienst — Belastingdienst, official, primary
- Ketenaansprakelijkheid: betaal geen onnodige belasting — KVK — KVK, official government body, secondary explainer
- De G-rekening voor uitleners vrij besteedbaar? Let op de risico's! — Booij Legal & Tax — secondary (law firm), director-liability risk framing
- Gap flagged: no NBA/RJ source found with a G-rekening-specific accounting/disclosure rule; Athena's F-003 treatment is a synthesis of the general Art. 2:372 lid 2 disclosure duty applied to a legally-restricted account type, not a named standard.
6. AI/technology use in Dutch audits — professional liability and standards posture
Summary
This is an active, fast-moving area as of 2025-2026, with concrete regulatory output now published (favorable timing for Athena):
- NBA's institutional posture: the NBA Board has designated AI as one of three central development themes for 2026-2028 (alongside "de DNA van de accountant" and "Risico's"), described as a "structural technological-societal development that fundamentally changes how work and decision-making occur." NBA frames AI as affecting not just technical execution but the profession's core values — independence, objectivity, due care, and public accountability.
- NBA/Accounttech/NOREA joint guidance: following an earlier "AI in Control" guideline, the NBA (via its Accounttech unit) and NOREA (the Dutch professional body for IT auditors) jointly published "Leidraad 2: AI toegepast" in 2026 — confirmed via NBA's own publications page (
nba.nl/tools-en-ondersteuning/publicaties/2026/leidraad-2-ai-toegepast/), giving NBA/NOREA members direction on practical AI application. This is the most current and most directly relevant NBA-authored guidance found.
- AFM (Autoriteit Financiële Markten) supervisory guidance: the AFM, as the Dutch audit-quality regulator, has moved from statements to a formal published report:
- November 2025: AFM supervisors publicly articulated three core principles for responsible AI use in audit (accountancyvanmorgen.nl, 6 Nov 2025, attributed to AFM supervisors Sean Weggelaar and Marc van Gestel): (1) "de mens moet onderdeel blijven van het proces" — a human must remain part of the process, AI cannot operate autonomously; (2) results must be "controleerbaar en traceerbaar" — controllable/verifiable and traceable; (3) technology must be deployed "zorgvuldig en veilig" — carefully and securely.
- December 2025: AFM published a full report setting out twelve "bouwstenen" (building blocks) for responsible use of advanced audit tooling (accountant.nl, Dec 2025), built on a foundation of risk management and information security, then data/analysis quality, then conscious/controlled application in the audit process. The report is explicitly positive about adoption ("AFM is blij met gebruik van geavanceerde audittools door kantoren") but flags inconsistent understanding of tool functionality across firms as a gap.
- Critical, load-bearing statement for Athena's scoping: AFM official Patrick Sohier is quoted stating "De accountant blijft eindverantwoordelijk" (the accountant remains ultimately/finally responsible) — explicitly stated to hold even when "AI operates as a black box," and explicitly stating accountants cannot outsource judgment to tools (the report specifically names ChatGPT-style tools) for identifying audit risks. The report's framing: "the tool is not the objective" — audit quality remains paramount, tooling is instrumental only.
- 2026 supervisory intensification: AFM has stated it will increase supervision specifically of AI and audit tooling in 2026, explicitly testing how technology is used within engagements and its effect on audit quality (accountant.nl, Jan 2026 news item).
Implication for Athena
This is the single most directly load-bearing finding for Athena's product scoping, and it is unambiguous and current (Nov 2025–Jan 2026, i.e. within the last year):
- Athena's output cannot be positioned as a finding/conclusion in its own right. Per AFM's explicit, on-record statements, every Athena-generated flag (kiting, unsupported journal entry, restricted G-rekening cash, lapping) must be presented as a candidate/flagged item requiring auditor review and sign-off, not as an audit finding. The auditor retains full, non-delegable final responsibility ("eindverantwoordelijkheid") regardless of Athena's confidence or output quality.
- Athena's output should be traceable/explainable by design (AFM's second principle) — i.e., every flag should be traceable back to the specific source records/transactions that triggered it (this is a design requirement the tool should already be well-positioned for, given it ingests structured ledger/XAF data, but confirms this is a regulatory expectation, not just good UX).
- Athena should not be marketed or documented internally as "detecting fraud" — the correct framing, consistent with both AFM's language and Standaard 240's own structure, is that Athena surfaces risk indicators / anomalies for the auditor's professional-skeptical evaluation, and the human auditor performs the actual risk assessment and conclusion under Standaard 240/500.
- The NBA/NOREA "Leidraad 2: AI toegepast" (2026) should be read in full by the team building Athena's compliance posture before productionizing — it is the single most current, most specific, Netherlands-professional-body-authored guidance found in this research, and was only published this year, meaning it likely represents the most up-to-date articulation of expected practice. This document's full content was not fetched in this research pass (only its existence and title were confirmed) — flagged as a priority follow-up.
- Athena's UI/UX and reporting should build in an explicit auditor sign-off step for every finding surfaced, per AFM's "human remains part of the process" principle — this is a regulatory-driven, not merely good-practice, requirement.
Sources
- Ontwikkelthema's 2026-2028 — NBA — NBA.nl, official
- Leidraad 2: AI toegepast — NBA — NBA.nl, official, 2026, content not yet fetched in full — priority follow-up
- NBA en NOREA publiceren nieuwe leidraad voor AI-toepassing — accountant.nl (NBA's own trade publication), official-adjacent
- AFM: 'Drie principes voor verantwoord AI-gebruik in audit' — accountancyvanmorgen.nl, trade press reporting on AFM statements, Nov 2025
- AFM is blij met gebruik van geavanceerde audittools door kantoren — accountant.nl, reporting on AFM's Dec 2025 report (the 12 bouwstenen)
- AFM houdt in 2026 meer toezicht op cyberweerbaarheid en AI — accountant.nl, Jan 2026
- AI verovert de auditpraktijk — accountant.nl, 2026, magazine feature (not fetched in full — secondary reference only)
- Gap flagged: the AFM's full December 2025 report (the primary source behind the "twelve bouwstenen") was not located/fetched directly — only secondary reporting on it (accountant.nl) was reviewed. The NBA/NOREA "Leidraad 2: AI toegepast" full text was also not fetched. Both are recommended priority follow-ups given how directly they bear on Athena's compliance posture.
Overall research gaps (summary)
- BW2 primary source (wetten.overheid.nl) not directly verified in this session — all article citations rest on consistent secondary legal-database mirrors. Recommend a direct follow-up pull before hard-coding statutory citations into Athena's output copy.
- XAF 4.0.3 XSD schema file itself is gated behind an authenticated Belastingdienst ODB portal login — could not inspect actual schema structure/contents. A team member with Belastingdienst portal access (or a redistributed copy via an ERP vendor's localization docs) is needed to obtain the real XSD for validation-logic work.
- No Dutch-standards source names "kiting" or "lapping" specifically — these are imported forensic-accounting terms; the underlying risk categories are covered by Standaard 240, but there is no NBA text to cite by name for the specific schemes.
- No G-rekening-specific accounting/disclosure standard (NBA or RJ) was found beyond the general Art. 2:372 lid 2 BW disclosure duty — Athena's F-003 framing is a defensible synthesis, not a directly-named rule.
- AFM's full December 2025 report and NBA/NOREA's "Leidraad 2: AI toegepast" (2026) were not fetched in full — both are highly current and directly relevant; recommend a dedicated follow-up read before finalizing Athena's AI-disclosure/compliance UX.
- One secondary source's claim that XAF "inspired" the international SAF-T standard was not corroborated by an OECD or Belastingdienst primary source — plausible given the confirmed timeline (XAF predates SAF-T) but unverified as a causal claim.
Reacties