Malaysian compliance
Four statutes, checked nightly
Tourism Tax, SST, LHDN e-invoice and PDPA each carry rules a hotel is expected to get right every single night. KAI enforces them from the reports your PMS already prints, and every flag cites the rule it comes from.
This is the depth global tools don't localise: Malaysian statutory rules, maintained as the rules move.
- Tourism Tax Act 2017
- Tourism Tax (Exemption) Order 2017
- Service Tax Act 2018
- LHDN e-Invoice Guideline
- Personal Data Protection Act
How each statute is enforced
Tourism Tax, guest by guest
The Tourism Tax listing is reconciled against the night audit with seven rule families. Guests are classified from nationality and ID format, because a 12-digit MyKad is not a passport, so exemptions and charges land on the right rooms.
- Rules A to G: over-collection, leakage, missing passports, waiver reconciliation, incomplete classification, exemption cross-checks, under-charge
- Comp and house-use exemptions checked against the Tourism Tax (Exemption) Order 2017
- RM 10 per room per night for non-exempt tourists, reconciled to the listing totals

SST that is checked, not assumed
KAI computes service tax at 8% on net room revenue and holds that basis consistently across every check, so a month's SST reconciles against it. A zero-SST night is respected as authoritative. The system never fabricates a derived tax.
- 8% on net room revenue: the invariant is test-pinned in the engine
- Period sanity check: the month's SST against net × 8%
- Zero-SST nights kept as reported, not overwritten
LHDN e-invoice, ahead of the deadline
The RM10,000 rule and the T+7 consolidation deadline are tracked per night. KAI builds the MyInvois-shaped envelope, consolidated or individual, and keeps an append-only status ledger.
- Nights reaching RM 10,000 surfaced the night they appear, so a qualifying transaction gets caught
- The consolidation deadline, the 7th of the following month, tracked with escalating warnings
- Agent-commission self-billed invoices surfaced with commission, SST and payable totals
PDPA by construction, not by policy
Guest identifiers never reach the statutory record: the parsers read only the fields the checks need, raw report files purge after 30 days, and guest analytics carry a K=5 anonymity floor. If the Commissioner ever asks, the access-trail report is generated, not compiled.
- Names, passports and ICs never reach the statutory record: the parsers drop those columns before a row is read
- 30-day purge of raw report uploads; 7-year retention of anonymised tax metadata only
- 72-hour breach access-trail report, submission-ready, with a DPO contact block
Where audit revenue actually leaks
Most audit losses are not dramatic. They are small, nightly, and invisible inside a monthly total: a waived tax here, an amended rate there, a commission point nobody re-checks. Some are deliberate, most are not, and the ledger cannot tell the difference on its own. Every loss pattern below has a named check, and every flag cites its rule.
Deliberate manipulation
- Quiet rate amendments
- A room rate amended mid-stay. Any rate amendment that moves a charge more than twenty percent is flagged with the before, the after and the folio, and a night whose amendments total more than five percent of its revenue is flagged as a pattern in its own right.
- Unpaired rate drops
- A charge amended downwards with no reversing correction inside the window. Paired round trips read as fat-finger fixes and pass; unpaired drops are flagged with the room and the amount.
- Amendments without reasons
- Every amendment is expected to carry a reason code, and a single amendment without one is enough to trip the flag, with the count and a sample folio. That reason trail is the audit-trail expectation behind LHDN's e-invoice regime.
- Edits after the seal
- Once a night is verified it seals into the tamper-evident vault. Changing a sealed figure takes a maker-checker correction that is itself hash-chained, so there is no quiet path back into a sealed night.
Honest mistakes that reach the books
- Revenue mispicks
- A report layout that hands the parser a room count where revenue belongs. A floor check blocks the impossible figure from the statutory record and raises a high-severity flag instead of archiving it.
- Guest misclassification
- Tourism Tax charges and waivers land on the wrong rooms when nationality and ID format disagree. Classification is cross-checked both ways, and incomplete is its own flag rather than a silent pass.
- Waived totals that attribute to nothing
- The listing's waived Tourism Tax must reconcile to per-row exemptions. A remainder that attributes to nothing is flagged with the ringgit difference.
- Sticky defaults
- The same intermediate amount recurring across folios is usually a PMS configuration rewriting rates on its own. It is surfaced as a pattern, not left as coincidence.
Third-party leakage
- Commission overcharge
- Each OTA statement's effective commission is computed against your contracted rate, per channel, with the difference in ringgit.
- Channel-mix cost
- Direct share falling while OTA share rises is a commission cost on the same occupancy. Every sealed night carries its booking-source mix, and the commission cost of that mix is computed against your contracted per-channel rates.
- Cancellations and double-bookings
- The cancellation report becomes a monthly inventory: revenue at risk in ringgit, channel and reason mix, and the double-bookings counted.
- Comp and house-use rooms
- Comp and house-use nights are cross-checked against the Tourism Tax listing under the Exemption Order, and a listing that covers fewer rooms than the night sold is flagged before MOTAC submission.
What catching it is worth
You do not need dramatic fraud for the arithmetic to work. Losses of this kind are small per night and relentless per year, which is exactly why a monthly review misses them and a nightly check does not.
The ledger alongside is deliberately conservative and openly illustrative. Its point is not the total; it is that each line already has a check running against your own reports, so the honest version of this ledger is the one KAI assembles from your nights.
What a year of quiet leakage costs
Conservative monthly assumptions at a mid-size city property, carried over twelve months. Every line is a check KAI runs against your own reports.
- Tourism Tax misclassification
- RM 900
- OTA commission overcharge
- RM 800
- Unpaired rate drops
- RM 900
- Balances written off
- RM 600
- Illustrative monthly exposure
- RM 3,200
- Over twelve months
- RM 38,400
- The KAI subscription, one property
- RM 14,400 a year
Three foreign-guest room nights a night waived in error, at the statutory RM 10
A two-point gap between the statement's effective rate and the contracted rate, on RM 40,000 of channel gross
Six amendments that lower a charge with no reversing correction, around RM 150 each
Four collect-at-checkout misses and mis-posted folios a month, around RM 150 each
The monthly figure above, times 12.
RM 1,200 a month, at the published rate.
Illustrative figures, not measured results: the statutory RM 10 rate and the published subscription are the only fixed numbers. The annual total is the monthly assumptions above times twelve, which amplifies the illustration as well as the leak — the per-month workings are shown so you can redo the arithmetic with your own numbers. Because every line is a live check, your own figures replace these from your first uploads.
What gets checked nightly
- Guest classification
- Nationality cross-checked against MyKad vs passport format; incomplete classification is its own flag, never silently passed.
- Waived TTx reconciliation
- The listing's waived total must attribute to per-row exemptions; an unattributable remainder is flagged.
- RM10k night watch
- Every night whose total reaches RM 10,000 is surfaced for review. KAI records night totals, not per-folio amounts, so it tells you which nights to check rather than asserting which transaction crossed the line.
- T+7 consolidation clock
- The deadline banner escalates inside the window; overdue is never shown as ready.
- e-Invoice status ledger
- Pending, submitted, accepted, rejected, tracked per night and per invoice.
- Amendment audit trail
- Amendments without reason codes are flagged. That is the audit-trail expectation behind LHDN's e-invoice regime.
- PII firewall
- Column allow-lists and anchored parsing: the parsers read only the dates, amounts and codes the checks need, and guest identifier columns are dropped before a row is read.
- Retention split
- Raw report files: purged at 30 days. Housekeeping photos: purged at 90 days. Anonymised tax metadata: kept 7 years in the statutory vault.
- Breach response
- A 72-hour access-trail window report for PDPA breach notification, generated on demand with the DPO contact block.
- Compliance-readiness score
- Audit coverage, submission status and open flags in one number, with honesty caps: an overdue e-invoice can never read as ready.
Be ready before the relaxation ends
Half an hour on the statutory checks, run against real Malaysian report formats.