Treating VAT validation as a binary pass/fail check will leave your billing system exposed. When I wired VIES into checkout flows across several SaaS products, the work happened before and after that single API call. Most tutorials stop at "here's the endpoint," but they skip the pipeline that turns a number into audit-ready evidence.
Before hitting VIES, run country-specific regex pre-checks. A German VAT number follows DE followed by 9 digits; a UK one after Brexit uses GB followed by 9 digits or 12 characters. Catching format mismatches client-side cuts VIES load by roughly 15% and spares users a five-second timeout. For format specifics by country, see our guide to validate company registration numbers.
Once VIES returns a valid response, cache that result in Redis with a 24-hour TTL. Companies don't change their VAT status hourly, and VIES itself can be slow or temporarily unavailable. A cached response lets checkout proceed without friction while you handle the stale-refresh in the background. Pair this with a fallback: if VIES is down, accept the number and flag it for manual review rather than blocking the sale entirely.
The evidence pipeline matters most when auditors come calling. ViDA and reverse-charge compliance require you to prove you checked, not just that you got a green light. Store the request timestamp, the VIES consultation number, and the raw SOAP response. Keep an audit log so your finance team can reconstruct each validation when needed. If you need to automate sales tax for carts alongside VAT checks, combine both flows.
On error codes, don't just throw a 500. Design distinct responses: 422 for format mismatch, 504 for VIES timeout, 200 with a validation_skipped flag when the service is down. Your frontend can then show clear messages, "Invalid format, check the country prefix" versus "VAT authority unreachable, we'll verify later." This turns an opaque API call into a transparent pipeline that buyers and auditors can trace.