XAS version reviewed: AuditfileSalaris v2027.1.0 (consultation document, Belastingdienst)
Files examined: XSD schema + Toelichting DOCX + FunHie DOCX (from xas-2027-consultatie.zip)
SRS target: DA-098 (Fictitious-Bank-Account and Salary-Fraud Detection) and related Liquide Middelen requirements
Date: 2026-09-02
XAS (AuditfileSalaris) is the Belastingdienst's payroll/salary auditfile standard — the payroll-domain sibling of XAF (AuditfileVersie, the GL/accounting auditfile). Both are XML-based, both are published under the same odb.belastingdienst.nl namespace authority, and both follow the same annual-submission model. They are, however, produced by different software, cover different data domains, and are filed with the Belastingdienst for different purposes:
| | XAF | XAS |
|---|---|---|
| Domain | General ledger / accounting | Payroll / salary administration |
| Produced by | Accounting packages (Exact, Twinfield, Unit4, AFAS Boekhouden) | HR/payroll packages (AFAS Salaris, Nmbrs, Visma, HR2day) |
| Filed with | Tax authority for GL audit | Tax authority for payroll tax audit |
| Schema namespace | AuditfileVersie3... | AuditfileSalaris-Versie2027_1.0 |
| Core entity | Journal transaction / GL posting | Employee income relationship / salary period |
auditfile
├── BrAlg (Bericht Algemeen — file header)
│ ├── AandatAud (audit date)
│ ├── Bljr (boekjaar / fiscal year)
│ └── TotLnLbPh (total wage tax withheld)
│
├── Inhpl (Inhoudingsplichtige — the employing entity)
│ ├── Nm (employer name)
│ ├── Lnadm (salary administration record with software metadata)
│ │ └── Lncmp[] (salary component definitions — types 03–99, e.g. LnGld / LnBijBel / etc.)
│ │
│ └── Wrknmr[] (one record per employee / recipient)
│ ├── SofiNr (BSN / SoFi tax ID)
│ ├── Persnr (employee number)
│ ├── Gebdat (date of birth)
│ ├── SignNm (significant part of surname)
│ ├── Voorl (initials)
│ ├── Voorv (surname prefix / tussenvoegsel)
│ │
│ └── InkVrhVst[] (income relationship — one per employment)
│ ├── NumIV (income relationship number)
│ ├── Ingdat/Enddat (start/end date of employment)
│ ├── SrtInkCd (income type code — see below)
│ ├── JrlnTbBzBel (annual salary for special remuneration base)
│ ├── CAOCd (collective labour agreement code)
│ │
│ └── Lntdvk[] (salary period — one per payroll run / pay period)
│ ├── Prdnr (period number)
│ ├── Ingdat/Enddat (period start/end)
│ ├── InkVrhVar (variable period fields)
│ │ ├── LnLbPh (wage for wage tax / loon voor loonheffing)
│ │ ├── LnSV (wage for social insurance)
│ │ ├── LnInGld (wage in cash — net/gross cash component)
│ │ ├── IngLbPh (withheld wage tax)
│ │ └── AantVerlU (hours paid)
│ │
│ └── LnPrLncmp[] (salary amount per salary component)
│ ├── IdLncmp (salary component ID — references Lncmp above)
│ ├── IbanRknr (IBAN of bank account receiving this payment)
│ └── Bdr (amount paid)
The SrtInkCd field inside InkVrhVst classifies each employment relationship:
| Code | Dutch label | Relevance to Athena | |------|-------------|---------------------| | 13 | Loon/salaris directeuren van een nv/bv | Director of a BV/NV — directly relevant to DA-098 management-override check | | 17 | Loon/salaris directeur-grootaandeelhouder | DGA (director-major-shareholder) — highest-risk category for DA-098 | | 11 | Loon/salaris ambtenaren | Civil servants | | 15 | Overig loon/salaris | Regular employees | | 22–63 | Social security / pension / termination payments | Out of scope for DA-098 |
Codes 13 and 17 are the authoritative Belastingdienst classification for the director/DGA roles that DA-098 targets.
DA-098 (management-override salary comparison) currently requires a user-uploaded director registry CSV (name, personal IBAN, registered annual gross salary) because the XAF file contains no structured payroll data. The SRS already notes this as a genuine data gap. The current V1 approach (user-supplied CSV + IBAN regex from GL description) is fragile.
A XAS file for the same fiscal year as the XAF file contains, in structured form, exactly the data DA-098 needs:
| DA-098 data need | XAS field | Location in schema |
|---|---|---|
| Director identity (name) | SignNm + Voorl + Voorv | Wrknmr |
| Director tax ID (BSN) | SofiNr | Wrknmr |
| Employment type = director | SrtInkCd = 13 or 17 | InkVrhVst |
| Registered annual salary | JrlnTbBzBel | InkVrhVst |
| Period-level salary amount | LnInGld (per period) or LnLbPh | Lntdvk > InkVrhVar |
| Bank account receiving salary | IbanRknr | Lntdvk > LnPrLncmp |
The IbanRknr field is critical: it is the IBAN to which each salary component is actually paid by the payroll system. This is the authoritative bank account of the employee/director — not a regex-inferred IBAN from a free-text GL description. Cross-referencing this against XAF Liquide Middelen transactions would be exact matching rather than heuristic matching.
The user-supplied director registry CSV that DA-098 currently requires is:
A XAS file submitted to the Belastingdienst is:
The current DA-098 spec should document XAS as the preferred future data source for the director registry, replacing the manual CSV upload. The V1 implementation can retain the manual CSV approach (since XAS files are not universally available in all audit engagements), but the data-model-gap description should be updated to reflect:
XAS and XAF share several structural patterns that validate Athena's existing data model:
ValCd / IsoValutacode) — same pattern as XAF HeaderDto.currency; confirms the single-currency-per-file modelBljr) — same annual filing period as XAF HeaderDto.fiscalYearPrdnr, Ingdat/Enddat per period) — same pattern as XAF accounting periodsInhpl) — same as XAF Header > CompanyThe following XAS structures are payroll-domain-specific and have no counterpart in XAF or in Athena's fraud detection scope:
IndZW, IndWW, IndZvw, IndWAO)PrAofLg, PrAofHg, PrAwfLg, etc.)Urnreg) and contracted hoursAuto, Kenteken, CatprijsAuto, Bijtelperc)VakBsl, OpbAvwb, OpnAvwb)Legbew)Lncmp with WzBlCd types: tijdvakloon / bijzondere beloningen / eindloonheffing)These are all payroll administration concepts outside the scope of financial fraud detection on GL data.
XAS is genuinely a separate format from XAF. Building XAS ingestion in Athena would require:
XasParser (new, separate from XafParser) — the XML structure is entirely differentXasHeaderDto, EmployeeDto (Wrknmr), IncomeRelationshipDto (InkVrhVst), SalaryPeriodDto (Lntdvk)SofiNr) and salary data — XAS contains sensitive personal data at a finer grain than XAFThis is not a near-term task. The scope of building an XAS ingestion pipeline is comparable to building the original XAF ingestion pipeline. It should be tracked as a distinct future work item, not subsumed into DA-098.
The DA-098 data model assessment section should be extended to state:
XAS as authoritative source: The Belastingdienst's XAS (AuditfileSalaris) standard defines, in structured form, exactly the director salary and bank account data that DA-098's salary-comparison check requires. SrtInkCd (codes 13 and 17) distinguishes directors and DGA from regular employees; JrlnTbBzBel carries the annual salary basis; IbanRknr within LnPrLncmp carries the exact bank account IBAN receiving each salary payment.
Near term (V1): Retain the current design — user-uploaded director registry CSV — as the practical approach, since XAS files are not universally available in audit engagements. Document in the UI that an XAS upload (when available) will be a superior substitute for the manual CSV in a future release.
Future work: A "XAS Ingestion" feature (separate from XAF ingestion, distinct work item) would parse the employer's XAS file alongside the XAF, automatically extract director/DGA salary data and IBANs, and populate the DA-098 comparison data without any manual user input. This would make the salary-override check reliable and auditor-independent.
| Topic | In scope for Athena now | Out of scope / future | |-------|------------------------|----------------------| | XAS schema awareness for DA-098 gap documentation | Yes — this document | — | | DA-098 V1 with user-uploaded CSV director registry | Yes — existing design | — | | XAS as the preferred future data source for DA-098 | Documented here as intent | XAS parser = future work item | | XAS ingestion pipeline / XasParser | — | Future — distinct scope, not part of current sprint | | XAS fields for payroll administration (social insurance, hours, car, leave) | — | Out of scope — not relevant to GL fraud detection | | DA-098 surname-concentration and IBAN-regex checks | In scope per existing spec | — |
Reacties