Ask most finance teams how an e-invoice actually gets from one company's ERP into another's, and the answer usually stops at "it goes through Peppol." That's true, but it skips the part that makes the whole thing work. Somewhere between a supplier hitting send and a buyer's system receiving a clean, validated invoice, a lookup happens that nobody in either company will ever see.
That lookup runs through something called the Service Metadata Publisher, or SMP. It rarely comes up in vendor decks or compliance briefings, and yet it is arguably the single component holding the network's scalability together, which is exactly why it deserves a closer look before anyone shortlists an e-invoicing solution for UAE operations.
Table of Contents
A directory, not a delivery service
It helps to separate two things that get conflated: moving a document, and knowing where to move it.
Peppol's Access Points handle the moving. They encrypt, transmit, and receive using the AS4 protocol, and that part gets most of the attention because it's the visible machinery. But an Access Point can't send anything until it knows three things about the recipient: what formats they can process, which technical address to reach them at, and whether their security credentials check out.
That's the job of the SMP. Every organisation on the network publishes a record describing its own capabilities: which document standards it accepts, which business processes it participates in, its endpoint address, and its current certificate. Think of it less as an address book someone else maintains for you, and more as a public profile you're responsible for keeping current. Other participants query it before they ever try to reach you.
Following one invoice through the system
Say a construction supplier in Sharjah needs to bill a contractor in Ras Al Khaimah. Four things happen before the invoice ever lands in the contractor's inbox, and only the last one resembles "sending."
First, the supplier's Access Point has to figure out which SMP even holds the contractor's record. It does this through a separate registry layer, the SML, which functions purely as a pointer. It doesn't know anything about capabilities; it just knows which SMP to ask.
Second, once it has the right address, the Access Point queries that SMP directly. This is the actual discovery moment: it returns the contractor's accepted document types, process identifiers, and certificate details.
Third, the supplier's system checks its own invoice against what came back. Does the format match? Does the tax structure conform to what the contractor has declared it can handle? This validation step exists specifically to catch mismatches before transmission, not after.
Only once all of that resolves cleanly does the fourth step happen: the message actually travels, secured and authenticated, into the contractor's Access Point and onward into their ERP.
Three of those four steps are invisible groundwork. And the middle two depend entirely on the SMP returning accurate, current information.
Why bilateral connections were never going to scale
There's a reason this discovery layer exists rather than everyone simply maintaining a spreadsheet of trading partner endpoints.
Picture the alternative: every company individually agreeing on formats, endpoints, and security details with every other company it invoices. That's roughly how older EDI networks operated, and it's why they stayed expensive and slow to expand. Adding a new partner meant a new negotiation. Multiply that across thousands of participants and the number of required connections explodes far faster than the number of companies involved.
The SMP model breaks that math. A company publishes its capabilities exactly once. Every other participant on the network can then discover those capabilities on demand, with zero prior coordination. Nobody has to call anybody. Nobody has to configure anything bilaterally. The network scales because the responsibility shifted from "negotiate with everyone" to "describe yourself accurately, once," which is also the design principle behind any genuinely best Peppol-ready e-invoicing solution in UAE rather than a system that just claims Peppol compatibility on paper.
The stakes get higher under a five-corner model
The UAE's approach to e-invoicing, set out under Ministerial Decision No. 64 of 2025 and rolling out in phases from 2027, layers something extra onto the standard Peppol architecture. Rather than the conventional four-corner exchange between supplier, two Access Points, and buyer, the UAE model adds a fifth corner: the Federal Tax Authority itself.
Both the supplier's accredited service provider and the buyer's report transaction data to the FTA independently, as part of the reporting obligation baked into the model. That changes what a discovery failure actually costs. In a purely commercial network, a bad SMP lookup means a late invoice and an irritated counterparty. Once a tax authority sits structurally inside the exchange, the same failure touches a regulatory reporting chain. Discovery stops being a technical footnote and becomes part of the compliance surface, which is precisely why working only with an FTA-approved accredited service provider in UAE matters more here than in most other Peppol markets.
The failures nobody budgets for
Because SMP records are typically set up once, during onboarding, and then left alone, they tend to drift out of sync with reality without anyone noticing until something breaks.
A few patterns show up repeatedly. A company updates its invoicing software but forgets its published document type identifiers and still point to an older version, so incoming messages get rejected for a mismatch nobody can immediately explain. A security certificate quietly expires, and transmissions that worked yesterday start failing today with no code change on either side. An endpoint URL becomes stale after an infrastructure migration, and the SMP keeps pointing senders at an address that no longer exists.
None of these show up as bugs in anyone's own system. They show up as a working process that suddenly stops working, with the root cause sitting in a directory record that neither party thinks to check first. It's exactly this kind of silent failure that separates genuinely reliable e-invoicing software in UAE from platforms that only look complete on a feature list.
Treat it as infrastructure, not paperwork
The uncomfortable truth is that almost nobody responsible for finance operations ever looks at their own SMP record after go-live. It isn't part of any dashboard. It isn't reviewed in a monthly close. It sits quietly doing its job until the day it doesn't, at which point it becomes a support escalation instead of a maintenance task.
As phased mandates spread across the GCC, that gap gets more expensive to ignore. Organisations preparing for the UAE's 2027 timeline would do well to assign clear ownership of SMP registration now: someone who knows when the certificate renews, someone who updates the record when systems change, someone who would actually notice if discovery started silently failing. This is usually the point where businesses start actively comparing the best e-invoicing system in UAE rather than treating compliance as a checkbox handled once at go-live.
The invoice that arrives on time isn't just a successful transmission. It's a successful lookup that nobody had to think about. That's the whole point of good infrastructure: it disappears when it works, and it becomes urgent the moment it doesn't.
Where SMARTeIS fits into this picture
Getting SMP registration and discovery right isn't something most finance teams should have to manage manually, and that's precisely the gap SMARTeIS is built to close. Developed by Skill Quotient Technologies, it's built specifically around the UAE's five-corner model, with the FTA reporting layer treated as a first-class part of the architecture rather than an afterthought bolted onto a generic international product. It handles Peppol discovery, certificate lifecycle management, and regulatory reporting as one unified system, integrating with SAP, Oracle, Microsoft Dynamics 365, and 150+ other ERP and POS systems ahead of the 2027 phased rollout under Ministerial Decision No. 64 of 2025.
Ready to get your e-invoicing infrastructure audit-ready?
If your SMP setup, certificate management, or Peppol readiness hasn't been reviewed since onboarding, now is the time, well before the 2027 deadline creates pressure to fix it under time constraints. Book a free consultation with SMARTeIS and see how a properly managed discovery layer keeps your invoices moving without the silent failures.
Talk to our UAE e-invoicing expert!
Get clarity on timelines, PEPPOL requirements, and implementation approach tailored to your business.
Enquire Now!