Darko Pavic’s four-level model helps retailers and POS vendors assess how they manage fiscalization today, choose the maturity level that fits their strategy, and build the governance, architecture and evidence needed to improve.
A compliance maturity model is a structured framework for assessing how consistently, proactively and strategically an organization manages compliance. It describes observable stages of capability – from ad hoc reaction to integrated governance, standardized processes, scalable technology, reliable evidence and continuous improvement – so that an organization can identify its current position, select an appropriate target state and prioritize the next practical improvements. (CMMI Institute – maturity levels). (OECD tax maturity models).
| Darko Pavic’s practical definition A compliance maturity model shows whether an organization merely reacts to legal obligations or has built compliance into a repeatable capability that protects operations, supports innovation and makes international growth easier. In fiscalization, maturity is not measured by the number of countries supported or certifications collected, but by how predictably the organization can understand, implement, monitor and change its compliance environment. |
Darko Pavic developed the Fiscalization Compliance Maturity Model to help retailers and software providers do two things: assess their current compliance strategy objectively, and use a staged roadmap to improve it when the business case justifies change. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 16-19 and 50-68).
Key takeaways
- The model is an assessment and improvement framework, not a legal standard, certification or ranking system.
- It contains four stages: Reactive, Fragmented, Connected and Strategic.
- Maturity should be assessed across six dimensions: governance, process, technology, data and evidence, organization and skills, and ecosystem integration.
- A company can be mature in one dimension and weak in another; the useful output is a maturity profile, not only one overall score.
- Level 4 is not automatically correct for every organization. The appropriate target depends on geographic footprint, growth plans, risk exposure, architecture, resources and product strategy.
The full methodology was introduced in Darko Pavic’s book, The Fiscalization Compliance Maturity Model.
Table of contents
- What a compliance maturity model includes – and what it does not
- Why compliance maturity matters in global retail
- How the Compliance Maturity Model works
- The four compliance maturity levels
- The six assessment dimensions
- Choosing the right target maturity
- Impact on retail and POS systems
- Compliance maturity compared with related concepts
- International and jurisdictional variations
- Common misconceptions
- Darko Pavic’s perspective
- Implementation considerations and assessment checklist
- A practical roadmap from assessment to improvement
- Metrics that demonstrate maturity
- Related work by Darko Pavic
- Frequently asked questions
- Sources and further reading
What a compliance maturity model includes – and what it does not
A compliance maturity model includes staged descriptions of organizational capability, assessment criteria, observable evidence and improvement priorities. It helps leadership and delivery teams create a shared language for discussing why compliance work is slow, expensive, fragile or difficult to scale. (Becker, Knackstedt and Poppelbuss, 2009).
What it includes
- Defined maturity stages with clear differences in behavior, ownership and outcomes.
- Assessment dimensions covering people, processes, technology, data, governance and external dependencies.
- Evidence requirements: policies, architecture, monitoring data, release records, audit packs, training, roles and performance metrics.
- A target-state discussion based on business needs, not on the assumption that every organization must reach the highest level.
- A prioritized roadmap that connects weaknesses to realistic improvements.
- Periodic reassessment so the model remains useful as laws, systems, teams and business models change.
What it does not include
- It is not legal advice and does not determine whether a particular transaction or system is compliant in a jurisdiction.
- It is not a replacement for a legal inventory, country analysis, certification, audit or control test.
- It is not a vendor score based on feature count. A sophisticated product can still be embedded in an immature operating model.
- It is not proof that risk has been eliminated. Mature programs still experience incidents; the difference is that they detect, contain, learn and improve more effectively.
International standards and regulator guidance reinforce this distinction. ISO 37301 addresses the establishment, implementation, evaluation, maintenance and improvement of a compliance management system. The U.S. Department of Justice evaluates whether a corporate compliance program is well designed, applied in good faith and effective in practice. A maturity model can help an organization structure those questions, but it does not replace the underlying management system or evidence of effectiveness. (ISO 37301:2021). (U.S. DOJ Evaluation of Corporate Compliance Programs, September 2024).
Why compliance maturity matters in global retail
Retail compliance is becoming a continuous operating requirement rather than a final project checkpoint. Fiscalization, e-invoicing and transaction reporting increasingly connect tax authorities to the software and devices in which transactions are created. The OECD describes digital continuous transactional reporting as the near-real-time reporting of invoices or transaction data, while the European Union’s VAT in the Digital Age package introduces cross-border digital reporting requirements from 1 July 2030 and a staged implementation through January 2035. (OECD Digital Continuous Transactional Reporting for VAT, 2026). (European Commission – VAT in the Digital Age).
This shift changes the cost of immaturity. A missed requirement no longer creates only a later tax correction; it can block receipt issuance, delay a store opening, break an integration, invalidate evidence, interrupt checkout or force emergency releases across many countries. The maturity question is therefore operational and architectural: can the organization absorb legal change without repeatedly destabilizing the business? (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 12-23, 71-110 and 299-342).
Why retailers need the model
- To understand whether compliance is managed centrally or delegated without sufficient oversight.
- To expose duplicated country solutions, hidden manual work and inconsistent evidence retention.
- To align Tax, Legal, Finance, IT, Store Operations, E-commerce and vendors around one roadmap.
- To determine whether expansion plans are supported by repeatable country-entry capability.
- To measure compliance as risk reduction, operational resilience and time-to-market – not only as cost.
Why POS and software vendors need the model
- To assess whether country coverage is maintained through reusable architecture or one-off custom code.
- To make regulatory monitoring and update delivery part of the product lifecycle.
- To clarify the boundary between vendor responsibility and retailer accountability.
- To reduce implementation time, support incidents and regression risk across countries.
- To show customers evidence of readiness, maintainability and operating discipline rather than relying on feature claims.
How the Compliance Maturity Model works
The model works as a structured self-assessment and improvement cycle. The assessment should be evidence-based, cross-functional and repeated over time; it should not be completed by one person as a perception survey or used only to produce a flattering score. (OECD maturity-model approach). (Mettler, 2011).
1. Define the assessment boundary. Specify the organization, business units, countries, channels, products and compliance domains being assessed. A retailer and its POS vendor may need separate assessments because their responsibilities and capabilities differ.
2. Collect evidence before scoring. Gather policies, ownership maps, architecture diagrams, country inventories, monitoring reports, incident records, release histories, certification evidence, training records, SLAs and audit findings.
3. Assess the six dimensions. Evaluate governance, process, technology, data and evidence, organization and skills, and ecosystem integration. Use the descriptions of the four levels as anchors.
4. Create a maturity profile. Assign a level by dimension and document the evidence and uncertainty behind each rating. Avoid averaging away critical weaknesses.
5. Identify the dominant constraint. Find the factor that most limits reliable operation: unclear ownership, manual change management, fragmented architecture, weak evidence, insufficient skills or uncontrolled vendor dependencies.
6. Choose the target maturity. Select the level that fits the business strategy, risk and footprint. The target can differ by dimension and country group.
7. Build a staged roadmap. Prioritize foundational controls before advanced automation. The roadmap should specify owners, dependencies, measurable outcomes and decision gates.
8. Measure and reassess. Track incidents, regulatory update lead time, deployment time, evidence quality, downtime, manual effort and business outcomes. Reassess after material changes or at a defined cycle.
The book describes the same journey as an iterative path: perform a candid assessment, secure leadership support and resources, strengthen foundations, integrate fragmented practices, automate repeatable work, embed compliance into strategy and maintain continuous improvement. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 299-342).
The four compliance maturity levels
| Level | Dominant operating pattern | Typical evidence | Primary improvement priority |
| Level 1 – Reactive | Compliance is triggered by problems, deadlines or external demands. | Unclear ownership; last-minute fixes; informal knowledge; manual evidence. | Establish scope, ownership, basic procedures and a reliable legal-information source. |
| Level 2 – Fragmented | Compliance exists, but each country, team or product solves it differently. | Duplicated solutions; local silos; inconsistent controls; patchwork architecture. | Create shared governance, common requirements, reusable components and central visibility. |
| Level 3 – Connected | Countries and functions share architecture, processes, knowledge and oversight. | Central coordination; middleware or common services; partial automation; some legacy fragmentation. | Harmonize lifecycle management, automate updates and evidence, and connect metrics to business outcomes. |
| Level 4 – Strategic | Compliance is an adaptive business capability embedded in product and expansion strategy. | Proactive monitoring; modular architecture; continuous assurance; measured value; leadership ownership. | Sustain learning, scenario planning and alignment; avoid complacency and preserve local expertise. |
Level 1 – Reactive compliance
At Level 1, compliance is managed in fire-fighting mode. The organization acts when a regulator, customer, local consultant or failed implementation forces action. There is little formal governance, limited documentation and low awareness outside the people dealing with the immediate problem. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 52-54 and 71-79).
- Architecture: direct country-specific changes are made in the POS or local solution with limited reuse.
- Change management: regulatory updates are discovered late and converted into emergency projects.
- Evidence: logs, approvals and documentation may exist only after an incident or audit request.
- Organization: responsibility is unclear or delegated to an individual without authority or resources.
- Business effect: high unpredictability, delayed go-lives, rework, operational incidents and dependence on external specialists.
| Practical warning Reactive does not mean that nothing works. A Level 1 organization may remain legally operational for years. The risk is that success depends on individual effort, stable conditions and luck rather than on a system that can withstand change. |
Level 2 – Fragmented compliance
At Level 2, the organization has learned to solve compliance, but it solves the same class of problem repeatedly in different ways. Country teams, vendors, products or legal entities maintain their own processes, tools and interpretations. The result is a functioning patchwork that becomes increasingly expensive as the footprint grows. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 54-57 and 81-90).
- Architecture: multiple country versions, local fiscal modules, device integrations or vendor-specific interfaces.
- Change management: updates are handled within local silos and do not consistently reach other stakeholders.
- Evidence: country evidence exists but is stored in different formats and repositories.
- Organization: responsibility is distributed, but coordination and common accountability remain weak.
- Business effect: duplication, slow international rollout, high maintenance cost and uneven risk exposure.
| The Level 2 trap Fragmented compliance often looks mature because every country has a solution and every team is busy. The missing capability is not effort; it is the ability to reuse knowledge, architecture, controls and evidence across the organization. |
Level 3 – Connected compliance
At Level 3, compliance becomes a coordinated program. The organization establishes shared architecture, central governance, common processes and specialist knowledge that can serve multiple countries and channels. Technology such as middleware, common services and centralized monitoring makes the program more proactive and efficient. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 57-60 and 91-100).
- Architecture: a shared core, middleware or reusable service separates common retail logic from country-specific controls.
- Change management: regulatory updates are monitored centrally and assigned through a controlled lifecycle.
- Evidence: data, logs, certificates and release records are consolidated and more accessible.
- Organization: Tax, Legal, IT, Operations and vendors work through defined governance and escalation paths.
- Business effect: faster expansion, fewer duplicated changes and more predictable operations.
| Connected is not yet fully strategic Level 3 organizations can still depend on manual interpretation, spreadsheet inventories, legacy country components and key individuals. The transition to Level 4 is less about adding another platform and more about making the entire change-and-assurance lifecycle measurable, adaptive and embedded in business planning. |
Level 4 – Strategic compliance
At Level 4, compliance is treated as a durable business capability. Legal monitoring, implementation, testing, evidence, operations and continuous improvement are connected to product governance and international growth. Leadership understands the architecture and the risk, while teams use metrics to improve both compliance outcomes and business performance. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 60-62 and 101-110).
- Architecture: modular and multi-country by design, with controlled adapters and clear separation of legal logic from channel and payment logic.
- Change management: new obligations are detected early, validated, translated into requirements, implemented, tested, deployed and monitored through one traceable process.
- Evidence: compliance status is continuously observable; audit packs can be produced from trusted records rather than assembled manually.
- Organization: leadership, compliance specialists, product teams and operations share explicit objectives and accountability.
- Business effect: compliance supports faster market entry, architecture simplification, resilience, customer trust and product differentiation.
| Important qualification Strategic compliance is not a permanent achievement. Regulations, technologies, channels and vendors change. A Level 4 organization remains mature only by continuing to learn, test, measure and adapt. |

The six assessment dimensions
A useful assessment should not force the entire organization into one label. The Fiscalization Compliance Maturity Model can be applied across six dimensions, producing a profile that shows where capability is strong, weak or inconsistent. (Fiscal Solutions – 4-Level Fiscalization Compliance Maturity Model white paper).
| Dimension | What it covers | Evidence-based assessment question |
| Governance and accountability | Decision rights, ownership, escalation, leadership oversight, funding and alignment with business strategy. | Is there one accountable owner? Are country and vendor responsibilities explicit? Are material risks visible to leadership? |
| Process and lifecycle | Regulatory monitoring, interpretation, requirements, design, implementation, testing, release, incident response and review. | Can every change be traced from official source to production control and post-deployment evidence? |
| Technology and architecture | POS, e-commerce, ERP, middleware, devices, APIs, security, offline design, deployment and observability. | Are country differences isolated in reusable components, or embedded across multiple applications? |
| Data and evidence | Transaction records, signatures, sequence controls, reports, logs, retention, reconciliation and audit access. | Can the organization prove what happened, which version was active and how exceptions were handled? |
| Organization, skills and culture | Legal, tax, technical and operational competence; training; role clarity; knowledge continuity; incentives. | Does capability survive staff turnover? Do teams understand both the rule and its retail-system impact? |
| Ecosystem integration | Authorities, legal advisers, fiscal providers, POS vendors, payment providers, auditors, integrators and customers. | Are interfaces, SLAs, dependencies, certifications and evidence responsibilities governed end to end? |
A mature assessment may produce a profile such as Governance 3, Process 2, Technology 4, Data 2, Organization 3 and Ecosystem 2. Reporting only the average would hide the evidence weakness and ecosystem dependency that could still block a rollout or audit. The profile should therefore guide priorities rather than serve as a vanity score. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 63-68).

Choosing the right target maturity
The correct target is the lowest maturity profile that reliably supports the organization’s strategy, obligations and risk tolerance. Darko Pavic’s model explicitly rejects the idea that every Level 1 company is failing or every Level 4 company is superior. A domestic retailer with a stable model may operate effectively with disciplined Level 2 or Level 3 capabilities; a POS vendor serving global tier-one retailers may need Level 4 capabilities in architecture, change management and evidence. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 18-19).
Factors that should influence the target
- Number and diversity of jurisdictions, legal entities, brands, channels and transaction types.
- Rate of expansion and frequency of product or business-model change.
- Regulatory volatility, certification dependencies and potential operational impact of failure.
- Existing architecture, legacy constraints, offline requirements and availability targets.
- Internal competence, vendor strategy, budget and ability to sustain the operating model.
- Commercial differentiation: whether compliance capability influences sales, retention, customer trust or market access.

Impact on retail and POS systems
Compliance maturity affects not only the compliance team but the way the entire transaction environment is designed and operated. Higher maturity does not mean more controls everywhere; it means the right controls are implemented once, reused where possible, monitored continuously and supported by clear evidence.
| System area | Lower-maturity pattern | Connected or strategic pattern |
| Checkout process | Country exceptions are discovered late and handled by cashier workarounds. | Legally relevant scenarios are designed into flows, exception paths and training before rollout. |
| POS architecture | Fiscal logic is embedded in multiple POS versions. | Common transaction semantics connect to modular country controls or middleware. |
| Receipts and invoices | Templates and mandatory data are maintained locally. | Document rules are versioned, tested and linked to legal sources and transaction types. |
| Transaction data | Fields and event meanings vary by channel and country. | A governed data model defines items, tax, discounts, returns, cancellations, payments and identifiers. |
| Integrations | Interfaces are created project by project. | Authority, device, payment, ERP and archive interfaces use managed contracts and monitoring. |
| Security | Keys, certificates and access are addressed during certification or incidents. | Security material has ownership, rotation, expiry monitoring, access control and recovery procedures. |
| Master data | Tax and product attributes are corrected after failures. | Data ownership, validation and release controls prevent invalid combinations from reaching checkout. |
| Reporting | Teams reconcile reports manually after transactions. | Reporting obligations are mapped to source events with automated validation and exception queues. |
| Availability and offline | Network or authority outages create improvised procedures. | Offline rules, local persistence, retry, sequence continuity and recovery are designed and tested. |
| Auditability | Evidence is assembled from emails, screenshots and local folders. | Source, requirement, version, test, deployment and transaction evidence are traceable. |
| International rollouts | Each country is a new compliance project. | Country entry uses a repeatable readiness process, reusable architecture and controlled local variation. |
| Vendor responsibility | Contracts say the vendor is responsible, but boundaries remain unclear. | RACI, interface ownership, SLAs, evidence and incident obligations are explicit and tested. |
Compliance maturity compared with related concepts
| Concept | Primary purpose | Typical scope | Main output |
| Compliance maturity model | Assess capability and define a staged improvement path. | Organization-wide profile across governance, process, technology, data, people and ecosystem. | A maturity profile, target state and roadmap. |
| Compliance management system | Establish and operate the policies, controls and governance required to meet obligations. | The management system itself. | Operational policies, roles, controls, monitoring and improvement. |
| Legal or regulatory gap analysis | Compare current practice with a specific obligation. | A jurisdiction, regulation, product or transaction scope. | List of gaps and remediation actions. |
| Certification or approval | Demonstrate that a defined system, version, device or process meets specified criteria. | The object and scope defined by the scheme. | Certificate, approval or formal assessment result. |
| Audit or control test | Verify whether controls were designed and operated effectively during a period. | Selected controls, evidence and time period. | Findings, assurance and corrective actions. |
| Readiness assessment | Determine whether a project, market or release is prepared for a specific milestone. | A defined go-live, certification or audit event. | Go/no-go decision and open-item plan. |
These concepts should reinforce one another. A mature organization uses legal gap analyses to feed a managed lifecycle, certifications as scoped evidence, audits to test effectiveness and the maturity model to decide which capabilities should improve next. ISO 37301 provides a management-system reference, while the maturity model supplies a staged lens for evaluating capability. (ISO 37301:2021).
International and jurisdictional variations
The maturity model is jurisdiction-neutral, but the evidence of maturity changes with the regulatory model. Fiscalization may be device-centric, software-security-based, online reporting-based, clearance-based, e-invoicing-based or hybrid. The same retailer may therefore need different country adapters, certificates, offline controls and reporting interfaces while maintaining one global operating model. (Pavic, The Fiscalization Compliance Maturity Model, 2025, Chapters 1, 7, 8 and the 25-country appendix).
Illustrative regulatory models
- Device-centric models: certified printers, cash registers or security devices create and preserve evidence locally. Maturity is shown through device lifecycle management, configuration control, monitoring, replacement and reconciliation.
- Software-security or certification models: a POS application or defined component must satisfy integrity and documentation requirements. Maturity is shown through version control, certification planning, release discipline and evidence of unchanged approved behavior.
- Online transaction reporting: sales data is transmitted at or near the time of transaction. Maturity is shown through connectivity, retries, idempotency, status monitoring, reconciliation, offline rules and incident response.
- Clearance and e-invoicing models: an authority or authorized platform may validate data before or shortly after issuance. Maturity is shown through structured data quality, schema governance, response handling and document lifecycle control.
- Hybrid models: hardware, software, signatures, e-invoicing and periodic reporting coexist. Maturity is shown by controlling the whole lifecycle rather than treating each mandate as an isolated integration.
The global direction is toward deeper integration between tax rules and business systems. OECD Tax Administration 3.0 describes taxation becoming embedded in the natural systems used by taxpayers, and the OECD’s 2026 DCTR report addresses near-real-time invoice and transaction reporting. The EU’s ViDA package creates a staged cross-border digital-reporting framework. These developments increase the value of reusable architecture, governed data and continuous change management. (OECD Tax Administration 3.0). (OECD DCTR for VAT, 2026). (European Commission – ViDA).
| Maturity is not determined by the country model A company can be strategically mature in a hardware-based country when it manages devices, evidence and change through a repeatable global capability. The same company can be fragmented in a modern API-based country if ownership, data and operational controls remain local and inconsistent. |
Common misconceptions
“The highest level is always the correct target.” Maturity must fit the business. The model is for alignment, not competition. The target depends on footprint, growth, risk and resources.
“Buying middleware moves us to Level 4.” Technology can enable maturity, but it cannot replace ownership, controlled processes, reliable data, training, evidence and continuous improvement.
“Centralization means every local decision must be made globally.” Strategic maturity combines global governance and reusable architecture with local legal expertise and controlled jurisdiction-specific variation.
“Certification proves the organization is mature.” A certificate normally covers a defined object, version and scope. It does not prove that monitoring, deployment, support, data quality and future changes are controlled.
“The vendor owns fiscalization responsibility.” Vendors may carry contractual or jurisdiction-specific obligations, but the retailer or taxpayer normally retains accountability for its complete operating environment. Responsibility boundaries must be explicit rather than assumed.
“One score tells us everything.” A single score can hide a critical weakness. A six-dimension maturity profile is more useful because technology may be advanced while evidence, governance or ecosystem integration remains weak.
“Once Level 4 is reached, the program is finished.” Strategic maturity depends on continuous learning and adaptation. New laws, channels, payment models, acquisitions and AI-enabled processes can reduce maturity if governance does not evolve.
Darko Pavic’s perspective
| Compliance maturity is alignment, not status In my view, a maturity model should never become another corporate ranking. Its value is to expose the distance between the compliance capability a company has and the capability its strategy actually requires. A business is mature when that distance is understood, governed and deliberately reduced – not when it can claim the highest number. |
Based on my experience in international retail technology, the biggest practical mistake is to treat compliance as a collection of country projects. Every local project may be successful, yet the organization becomes slower and more fragile because knowledge, code, devices, contracts and evidence multiply without a common design. That is the pattern I describe as Fragmented compliance. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 81-90).
I distinguish between solving a requirement and building a capability. Solving a requirement means one country can go live. Building a capability means the organization can repeat the process, understand the dependencies, apply a controlled architecture, produce evidence, absorb change and learn from operations. The transition from Level 2 to Level 3 begins when the organization stops asking only “How do we make this country work?” and starts asking “Which parts of this solution should become reusable for every country?” (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 91-110 and 150-188).
The practical problem for retailers is that fiscalization reaches beyond the POS. It affects ERP, e-commerce, payments, returns, reporting, archives, support and the way different legal entities operate. A vendor can provide important components, but only the retailer has the end-to-end view needed to ensure that the complete ecosystem behaves compliantly. The maturity model makes that broader responsibility visible. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 48-50).
My strategic prediction is that the most valuable compliance capability will increasingly be the trusted knowledge and control layer between law and transaction systems. Models, devices and interfaces will change. Organizations that can structure legal requirements, trace interpretations, apply machine-readable rules and verify outcomes will be able to adopt AI and automation without surrendering control. (Darko Pavic author profile – rule-based systems and compliance intelligence).
Implementation considerations and assessment checklist
The following questions can be used to prepare a workshop or self-assessment. They are not legal advice and should be adapted to the organization, jurisdictions and product scope.
Legal scope and obligations
- Do we maintain a complete inventory of countries, legal entities, channels, transaction types and applicable fiscal obligations?
- Can every active requirement be linked to an official source, interpretation owner and effective date?
- Do we distinguish law, authority guidance, technical specification, industry practice and internal interpretation?
Governance and accountability
- Who is accountable for fiscalization at executive, program, country, product and operational levels?
- Are decision rights and escalation paths defined across Tax, Legal, IT, Product, Finance and Operations?
- Are vendor responsibilities, SLAs, evidence and incident obligations explicit?
Architecture and technology
- Where does country-specific compliance logic live, and how many copies of it exist?
- Can new channels use the same compliance services without rebuilding the POS?
- Are online, offline, retry, duplicate, sequence and recovery behaviors designed and tested?
- Can components be replaced without losing legal knowledge and evidence continuity?
Data and transaction semantics
- Are sale, return, cancellation, deposit, gift card, discount, payment and invoice events defined consistently?
- Who owns tax, product and customer master data used by compliance controls?
- Are schemas, mandatory fields, identifiers and code lists versioned and validated?
Security and evidence
- How are certificates, keys, signatures, device identities and privileged access managed?
- Can we reconstruct which requirement, software version, configuration and control applied to a transaction?
- Are records retained, searchable and protected for the required period?
- Can an audit evidence pack be produced without a manual search across emails and local folders?
Change and release management
- How are regulatory developments detected, validated and prioritized?
- Is there traceability from source to requirement, design, test, approval, deployment and monitoring?
- How early before an effective date do we normally release?
- Are emergency changes measured and followed by root-cause improvement?
Organization and knowledge
- Do we have the legal, technical and retail-process competencies required for each market?
- Are key processes dependent on individuals who cannot be replaced?
- Is training role-specific and tested in operational scenarios?
- Do teams understand why controls exist, not only which steps to follow?
Monitoring and operations
- Can we see transaction failures, reporting rejections, certificate expiry, offline queues and reconciliation gaps centrally?
- Are thresholds, owners and response times defined?
- Do incidents produce structured lessons and preventive changes?
- Are compliance controls tested after infrastructure, POS, payment or ERP changes?
Performance and value
- Do we track regulatory update lead time, country deployment time, incidents, downtime, audit preparation and manual effort?
- Can we quantify cost avoided, revenue protected, stores opened faster or support effort reduced?
- Do compliance metrics influence architecture, product and expansion decisions?
A practical roadmap from assessment to improvement
| Stage | Core work | Expected outcome |
| 1. Baseline | Define scope, gather evidence and assess all six dimensions. | Agreed maturity profile with documented evidence and uncertainty. |
| 2. Target | Choose the maturity needed for the business strategy and risk. | Target profile by dimension, not only a single Level 4 ambition. |
| 3. Foundations | Clarify ownership, legal inventory, standard procedures and evidence. | Reduced dependence on individuals and emergency response. |
| 4. Connect | Create shared governance, architecture, knowledge and monitoring. | Common control model and reusable country implementation pattern. |
| 5. Automate | Automate repeatable validation, deployment, reporting, evidence and alerts. | Lower manual effort and more consistent outcomes. |
| 6. Embed | Integrate compliance into product, expansion, procurement and architecture decisions. | Compliance considered before commitments and designs are finalized. |
| 7. Measure | Track risk, speed, cost, resilience and commercial value. | Evidence that investment improves business and compliance performance. |
| 8. Reassess | Repeat the assessment after material changes and at a regular cadence. | A living capability rather than a one-time transformation project. |
The book’s Level 4 roadmap emphasizes a candid baseline, leadership support, foundational procedures, cross-country integration, technology enablement, metrics, ROI and future-proofing. The sequence matters: automation applied to unclear ownership and inconsistent transaction semantics can scale errors instead of maturity. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 299-342).
Metrics that demonstrate maturity
Retailer metrics
- Percentage of regulatory changes implemented before the effective date.
- Average lead time from validated legal change to production release.
- Compliance incidents, failed transactions and authority rejections by country and cause.
- Store or channel downtime attributable to fiscal controls.
- Average time and effort to open a new country, entity, store type or sales channel.
- Manual reconciliation hours and audit-evidence preparation time.
- Percentage of countries and channels using the common architecture and monitoring model.
- Fines, delayed openings and emergency releases avoided or reduced.
POS and software vendor metrics
- Number and strategic relevance of jurisdictions supported by a maintained product capability.
- Time from regulatory announcement to supported and tested product release.
- Compliance-related defects, support incidents and client escalations.
- Average implementation time for an existing or new country adapter.
- Reuse rate of shared services, data models, tests and evidence templates.
- Client retention, deal win rate and revenue influenced by compliance coverage.
- Developer, QA and support effort per country and per regulatory change.
Metrics should show whether maturity creates observable value, not merely whether activities occurred. The book recommends connecting indicators such as incident reduction, audit preparation, rollout speed, regulatory coverage, support effort, customer satisfaction and revenue influence to an explicit compliance investment case. (Pavic, The Fiscalization Compliance Maturity Model, 2025, pp. 329-336).
Related work by Darko Pavic
The Fiscalization Compliance Maturity Model – book – The primary source for the four levels, assessment approach, technology and governance guidance, roadmaps, checklists, KPIs and 25-country appendix.
The 4-Level Fiscalization Compliance Maturity Model – white paper – A concise practitioner version organized around four levels, six assessment dimensions and a staged roadmap.
The Four Stages of Compliance Maturity in Global Retail – Forbes – A short executive explanation of the framework and why near-real-time tax controls make compliance architecture a strategic issue.
Forbes Executive Library: The Fiscalization Compliance Maturity Model – Independent editorial context explaining the book’s relevance to senior retail, technology and compliance leaders.
What Is Fiscalization? – Defines the regulatory domain to which the maturity model is first applied and explains the principal fiscalization mechanisms.
What Is POS Compliance? – Explains the end-to-end legal, technical and operational system property that a mature compliance capability must maintain.
Compliance in Global Retail: The 2026 Overview – Places fiscalization, e-invoicing, reporting and technology obligations within the wider global retail compliance landscape.
Frequently asked questions
What is a compliance maturity model?
A compliance maturity model is a staged framework for assessing how consistently and strategically an organization manages obligations, controls, evidence and change. It identifies the current capability, a suitable target and the improvements required to close the gap.
What are the four levels of Darko Pavic’s Fiscalization Compliance Maturity Model?
The four levels are Reactive, Fragmented, Connected and Strategic. They describe a progression from crisis-driven work, through country and team silos, to shared capability and finally to compliance embedded in business and technology strategy.
Is Level 4 always the best level?
No. The appropriate maturity depends on the organization’s footprint, growth plans, regulatory exposure, architecture, resources and commercial strategy. The model is intended to create alignment, not to rank companies.
Can a company be at several maturity levels at once?
Yes. Governance may be connected while data evidence remains fragmented, or technology may be strategic while training is reactive. A six-dimension profile is more useful than one average score.
Does a fiscal middleware platform automatically create strategic compliance?
No. Middleware can provide reusable architecture, connectivity and monitoring, but strategic maturity also requires governance, legal interpretation, process discipline, data quality, skills, evidence and continuous improvement.
How often should a maturity assessment be repeated?
Repeat it at a defined cadence, commonly annually, and after material events such as a major acquisition, architecture change, new sales channel, large geographic expansion, regulatory shift or serious incident.
Who should participate in the assessment?
The assessment should include Tax or Finance, Legal, Compliance, IT architecture, Product, Development, QA, Store and E-commerce Operations, Support, Security and key vendors. A single-function assessment will usually miss important dependencies.
Can the model be used beyond fiscalization?
Yes. The four-level logic can be applied to e-invoicing, POS compliance, transaction reporting and other compliance-critical domains, provided the assessment dimensions and evidence are adapted to the specific obligations.
Sources and further reading
1. Official policy and government sources
- European Commission, “VAT in the Digital Age (ViDA),” package adopted 11 March 2025; progressive implementation to January 2035. Official source for the EU digital-reporting and e-invoicing implementation timeline.
- U.S. Department of Justice, Criminal Division, “Evaluation of Corporate Compliance Programs,” updated September 2024. Government evaluation framework emphasizing design, resourcing, effectiveness in practice, monitoring and improvement.
2. Tax administration and regulator guidance
- OECD, “Digital Continuous Transactional Reporting for Value Added Tax,” 2026. Defines and analyzes near-real-time invoice and transaction reporting regimes and their operational design.
- OECD, “Tax Administration 3.0: The Digital Transformation of Tax Administration,” 2020. Sets out a vision in which tax processes become embedded in taxpayers’ natural systems.
- OECD, “Tax Administration Digitalisation and Digital Transformation Initiatives,” 17 June 2025, DOI 10.1787/c076d776-en. Current comparative source on digital tax capabilities, governance and integration.
- OECD Forum on Tax Administration, “Tax Administration and Tax Crime Maturity Models.” Explains the OECD’s use of maturity models for organizational self-assessment and improvement.
3. Technical and management standards
- ISO 37301:2021, “Compliance management systems – Requirements with guidance for use.” International standard for establishing, developing, implementing, evaluating, maintaining and improving a compliance management system.
- CMMI Institute, “Maturity Levels” and “What is CMMI?” Primary reference for the staged use of maturity levels as a path for capability and performance improvement.
4. Academic and research sources
- Becker, J.; Knackstedt, R.; Poppelbuss, J. “Developing Maturity Models for IT Management.” Business & Information Systems Engineering 1, 213-222 (2009). DOI: 10.1007/s12599-009-0044-5. A widely cited procedure model for developing maturity models and linking assessment to improvement measures.
- Mettler, T. “Maturity Assessment Models: A Design Science Research Approach.” International Journal of Society Systems Science 3(1/2), 81-98 (2011). DOI: 10.1504/IJSSS.2011.038934. Discusses rigor, relevance, design and application choices in maturity assessment models.
- Pereira, R.; Serrano, J. “A review of methods used on IT maturity models development: A systematic literature review and a critical analysis.” Journal of Information Technology 35(2) (2020). DOI: 10.1177/0268396219886874. Systematic research on how maturity models are developed and where methodological weaknesses arise.
5. Industry implementation sources
- Fiscal Solutions, “The 4-Level Fiscalization Compliance Maturity Model,” white paper. Practitioner summary of the four levels, six dimensions and staged roadmap.
- Darko Pavic, “The Four Stages of Compliance Maturity in Global Retail,” Forbes Technology Council, 19 February 2026. Executive article connecting the model to real-time reporting, architecture and global retail operating models.
6. Darko Pavic’s related analysis
- Darko Pavic, The Fiscalization Compliance Maturity Model: A Playbook for Retailers & POS Vendors, first edition, 2025, ISBN 9798264853975. Primary source for the original framework, detailed stages, architecture, certification, information management, team design, roadmap, checklists and KPIs.
- Forbes Councils Executive Library, “The Fiscalization Compliance Maturity Model By Darko Pavic,” 10 September 2025. Independent overview and author context.
- Darko Pavic, “What Is Fiscalization?” Authority-page definition and global system overview.
- Darko Pavic, “What Is POS Compliance?” Authority-page explanation of the control and evidence lifecycle around POS transactions.
How this page was prepared
This page was prepared from Darko Pavic’s book The Fiscalization Compliance Maturity Model and his published framework, then checked against current official policy, regulator guidance, international standards and maturity-model research. The article distinguishes external facts, general maturity-model principles and Darko Pavic’s professional interpretation. Jurisdiction-specific examples are illustrative and do not replace current legal or tax advice.
| Artificial intelligence supported source discovery, structural drafting and editing. Darko Pavic created and reviewed the article, verified the professional interpretation and accepts responsibility for the final published content. |
Publication and review information
| Field | Value |
| First published | 19 July 2026 |
| Last substantively reviewed | 19 July 2026 |
| Author | Darko Pavic |
| Permanent author profile | https://darkopavic.xyz/about/ |
| Primary topic | Compliance Maturity Model / Fiscalization Compliance Maturity Model |
Suggested citation: Pavic, Darko. “Compliance Maturity Model: Four Levels for Retail Fiscalization.” DarkoPavic.xyz, first published 19 July 2026.
About the author
Darko Pavic is the founder and CEO of Fiscal Solutions and has more than 28 years of experience in international retail technology and fiscalization. He has led POS, fiscal middleware and multi-country retail programs across more than 27 markets, including earlier large-scale software work at Diebold Nixdorf. He is a member of the Forbes Technology Council and the author of The Fiscalization Compliance Maturity Model, a practical framework for retailers and POS vendors managing global regulatory complexity. (Darko Pavic – About).
Follow the development of compliance maturity
| Future of the High Street Subscribe for practical analysis of fiscalization, e-invoicing, POS compliance, compliance intelligence and the technology architecture behind global retail. The newsletter is written for retailers, POS vendors and technology leaders who need to decide faster and implement safely. Subscribe to Future of the High Street |