BR-51
In accordance with card payments security standards an invoice should never include a full card primary account number (BT-97). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
What does this rule mean?
In accordance with card payments security standards an invoice should never include a full card primary account number (BT-97). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
A core EN 16931 business rule.
- BT-97
- Document level allowance reason
Official rule message (standard)
In accordance with card payments security standards an invoice should never include a full card primary account number (BT-97). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.
Where the rule applies
Syntax: CII · UBL
The same rule, expressed twice: UBL and CII name the same fields with different paths. Running a CII file against the UBL rules is why you get errors that mean nothing.
UBL
cac:PaymentMeans/cac:CardAccount/cbc:PrimaryAccountNumberID
CII
//ram:ApplicableTradeSettlementFinancialCard
Technical test
The rule passes when this Schematron expression holds true:
string-length(ram:ID)<=10How to fix it
A missing or incorrect business entry only you can supply. Add or correct it, then re-check.
Add or correct the named entry, then re-check.
Correct the affected entry in your XML, then re-check the invoice. Validation runs locally in your browser — your file never leaves your machine.
Check an e-invoice here
Drop an XML or ZUGFeRD PDF file here. Validation runs locally in your browser against EN 16931 — your file never leaves your machine.