Search across all content
An AI-supported risk-analysis system that scores purchase and sale transactions for fake-invoice risk in near real time using electronic tax and banking data, with final assessments made by human auditors.
Türkiye's Tax Inspection Board (VDK) describes fake invoices as a decades-old, self-perpetuating problem that costs billions of lira each year, distorts fair competition between businesses, feeds the informal economy, and conceals other crimes. A fake invoice records a sale of goods or services that is fabricated and is used to claim tax deductions or refunds that are not owed.
The tax administration's traditional tools were not well-suited to catching it early. Audits were largely retrospective and could begin years after the transactions in question; they leaned on document-by-document examination, limited data analysis and manual selection of which taxpayers to review. Tracking networks of fraudulent documents and complicated commercial relationships was difficult with those methods alone and took human capital away from higher-value tasks. These limitations, together with the spread of the digital economy, rising transaction volumes and the growth of electronic invoicing and ledger systems, have called for a more data-driven approach to auditing.
To detect risky transactions in real time rather than years later, the VDK built KURGAN, an AI-supported risk-analysis system. It was deployed on 1 October 2025 as part of a package of measures against fraudulent invoices. The VDK set out the system in an official guide, which presents KURGAN as the central means by which the administration gauges tax risk and sends taxpayers requests for information.
The system works across purchase and sale transactions in the economy, moving quickly to surface those that look suspicious. It draws on the country's electronic tax data, including e-invoices and e-ledgers (which businesses are required to keep), alongside banking records, and scores transactions for risk in near real time. It does not look at every transaction, but concentrates on those judged high-risk, based on factors ranging from fraudulent documentation to variance from sectoral profit/loss/cost norms. As a dynamic model, real-time changes, such as a new declaration, also influence risk scoring. The system also weighs the relationships around a transaction. A companion intelligence system, VİS (the Tax Intelligence System), uses network analysis to map the people and businesses linked to suspected fraud and feeds its findings into KURGAN's scoring, so the parties to a transaction and their wider connections also shape its risk.
A central design choice is that the system advises rather than decides. Its outputs are alerts that signal a need for examination; they do not place a taxpayer in the category of having issued or used a fake invoice, and all final assessments are made by human auditors. When the system flags a transaction, the process begins with a request for information from the taxpayer. Under Article 148 of the Tax Procedure Law, the authorities may require taxpayers and those who deal with them to provide requested information. This request for information gives a business the chance to demonstrate that a transaction was genuine, voluntarily correct an error, or set out its position before any formal audit begins, while preserving the right to appeal.
KURGAN went live in October 2025, so the firmest figures so far come from running it over historical transactions.
1. Run over past transactions, it flagged hundreds of billions of lira as potentially risky
Applied to 2023 data, the system marked about 190 billion lira in transactions for attention, spread across 8,753 sellers and 35,901 buyers; for 2024, the figure was about 389 billion lira, across 11,530 sellers and 52,557 buyers. Once duplicates were removed, the two years together totalled roughly 578 billion lira, about 14 billion US dollars, tied to 17,373 sellers and 77,834 buyers. Each figure represents the value of transactions singled out for closer examination, the point at which risk is identified. It does not represent confirmed fraud or tax collected; whether a flagged transaction involves a fake invoice, and whether any tax is owed, are established only later, once the business has responded and any examination has run its course.
2. Buyers received early-warning notices before any audit
More than 70,000 notices have gone to buyers caught up in the flagged transactions, warning them of the risk and giving them a chance to review their records and put things right before a formal audit opens.
3. Examinations have started, and advisers are being brought in
The VDK has begun examining the 17,373 sellers behind those transactions. Accountants and tax advisers whose clients appear among them are being notified as well, so they can help those taxpayers correct their books and filings.
As KURGAN is recent, the clearest lessons concern the conditions on which it depends and the questions still open around it.
A mature digital tax base is the first condition for attempting this. KURGAN runs on data Türkiye already collects across the whole economy: electronic invoices, electronic ledgers, which are the digital accounting records businesses are required to keep, and banking records, with an academic assessment noting it also draws on customs and tax-return data.
Keeping a human judgment between the score and the verdict is the design feature most likely to transfer. The system raises alerts rather than reaching decisions. The first formal step is an information-request letter under Article 148 of the Tax Procedure Law, which lets a business explain a transaction before any audit, and inspectors, not the model, make the final judgment on whether a fake invoice was used knowingly. This arrangement is what prevents an automated risk score from serving as an automated verdict, and it is the part of the design that a government could adopt without first building the same data systems.
Transparency is the central concern that critics raise. The academic assessment of the system argues that, although it discloses the types of data and risk factors it relies on, it does not reveal how those factors are weighted or the thresholds at which a transaction is flagged. On that basis, the assessment warns of three risks: that businesses may be wrongly flagged or genuinely risky ones may be missed, that the practical burden can shift onto businesses to prove a transaction was genuine, and that tax morale and trust can suffer when businesses cannot see why they were flagged. It recommends safeguards built into the design: explainable AI, strong human oversight, sound data governance, independent technical and legal auditing of the system, and clear, multi-step routes for challenging a flag and seeking correction.
Whether an unwitting buyer should carry the risk remains an open question. Critics read the limited transparency as pressuring buyers to disprove wrongdoing. The official guidance sets out a different view: a business that can show a transaction was genuine has the opportunity to do so before any penalty; the question of whether a fake invoice was used knowingly is decided by inspectors against a defined test rather than by the system, and the early-warning letter is meant to serve as the safeguard in practice.
This case study was written with assistance from artificial intelligence.





Connect with 500,000+ public servants solving your hardest challenges.





Connect with 500,000+ public servants solving your hardest challenges.
Help public servants worldwide learn from your work, what worked, what flopped and what you'd do differently
Share your project
Log in or sign up to continue the conversation