Mandates in digital commerce

In digital commerce, a mandate is an instruction, agreement, or industry requirement that determines how a payment may be initiated, authenticated, or processed. The term is used in two related ways: a customer mandate authorizes future or recurring payments, while a scheme or regulatory mandate sets requirements for payment security, data, or authentication.

Mandates in digital commerce matter because payment journeys now extend beyond a single checkout. A customer may approve a subscription, save a payment credential, return through a wallet, or complete a purchase under a card-network authentication program. Each journey needs clear consent, reliable records, and risk decisions that match the payment context.

What is a mandate in digital commerce?

A mandate in digital commerce is an instruction or rule that establishes the authority for a payment action. It can come from the payer, who authorizes a merchant to initiate future charges, or from a payment scheme, regulator, or standards body that sets conditions for processing and authentication.

A customer mandate normally records the payer’s consent, the merchant or creditor identity, the payment arrangement, and any terms that govern later transactions. A scheme mandate, by contrast, tells participating institutions what data, controls, or authentication outcomes they must support.

What are the main types of digital commerce mandates?

Type What it does Typical example
Recurring payment mandate Authorizes a merchant to initiate scheduled payments after an initial agreement. A streaming subscription billed each month.
Merchant-initiated transaction mandate Records consent for a later payment initiated by the merchant rather than the payer at the moment of collection. A hotel charging a card after a reservation condition is met.
SEPA Direct Debit mandate Authorizes a biller to collect funds directly from a payer’s bank account. A utility bill collected by direct debit.
Scheme mandate Sets payment-network requirements for participating issuers, acquirers, merchants, or processors. A card-network requirement for richer 3-D Secure data.
Regulatory mandate Creates legal or supervisory requirements for payment security and customer protection. Strong Customer Authentication rules under PSD2.

How do recurring payment mandates work?

A recurring payment mandate begins when the payer agrees to a billing arrangement. The initial transaction usually establishes the relationship and records the payment details, terms, and consent. Later transactions follow the agreed schedule or billing conditions.

The merchant must retain evidence that the arrangement exists and must apply the correct transaction indicators when sending later payment requests. A change to the amount, schedule, merchant, or terms may require renewed consent or a new authentication decision.

Recurring payments cover subscriptions, installments, memberships, insurance premiums, utilities, and other services. The payment may be recurring at a fixed interval or triggered by an event, such as usage, delivery, or a reservation condition.

What is a merchant-initiated transaction?

A merchant-initiated transaction, or MIT, is a payment that the merchant initiates after the payer has established an agreement or mandate. The payer is not actively initiating each later payment, so the transaction carries different authentication and processing considerations from a customer-initiated purchase.

The European Banking Authority describes later payments in a recurring card arrangement as payee-initiated transactions. Its guidance also distinguishes these payments from the initial transaction, where the payer is present and authentication may be required under the applicable rules.

MIT categories can include recurring payments, unscheduled credential-on-file payments, and deferred payments. Correct classification matters because the payment message, authentication record, liability treatment, and issuer decision may depend on how the transaction was initiated.

How do SEPA Direct Debit mandates work?

A SEPA Direct Debit mandate authorizes a biller to collect funds from the payer’s bank account. The European Payments Council states that the mandate sits at the center of a SEPA Direct Debit payment and may be issued in paper or electronic form.

The mandate identifies the authorization relationship between the payer and the biller. It supports recurring collections and gives the payer a defined process for challenging or requesting a refund for an eligible debit.

SEPA Direct Debit includes a Core scheme for consumers and a Business-to-Business scheme for businesses. The operational rules, payer rights, and implementation requirements differ, so the relevant scheme must be identified before a digital mandate journey is designed.

How do scheme mandates affect digital commerce?

Scheme mandates turn industry expectations into operational requirements for payment participants. They may require better transaction data, specific authentication methods, stronger risk analysis, or reporting that enables issuers to make more informed authorization decisions.

For example, Mastercard and Visa have introduced requirements associated with their 3-D Secure authentication programs. These initiatives focus on data quality and authentication performance across the payment ecosystem. Entersekt’s analysis of these changes explains how issuers can prepare for evolving 3DS requirements.

3DS authentication mandates can affect merchants, payment service providers, acquirers, issuers, and cardholders at the same time. A change in one participant’s data or authentication process can influence authorization outcomes elsewhere in the chain.

What is the relationship between mandates and authentication?

Authentication confirms that the person or device involved in a payment is authorized to act. A mandate establishes why a merchant may initiate a payment or what requirements a participant must meet. They are related, but they are not interchangeable.

The initial setup of a recurring arrangement may require customer authentication, consent, or both. Later payments may rely on the original agreement and the transaction indicators that show the payment is merchant initiated. Risk signals can still influence whether the issuer requests additional assurance.

Strong Customer Authentication rules under PSD2 focus on situations where the payer initiates an electronic payment or performs an action that may create a payment-fraud risk. The exact treatment depends on the transaction type, applicable exemptions, and current legal interpretation.

For a regulatory reference, consult the EU technical standards for strong customer authentication and the relevant supervisory guidance for the market in which the payment is processed.

Why do mandates matter for fraud prevention?

Mandates create an evidence trail for payment consent, but they do not guarantee that every later payment is legitimate. A criminal may compromise an account, alter payment details, manipulate a customer into approving a transaction, or exploit a poorly controlled recurring arrangement.

Risk decisioning should therefore consider more than the existence of a mandate. Useful signals can include device context, customer behavior, transaction details, merchant history, location, and the relationship between the payer and the payee.

Entersekt connects authentication and payment risk signals across digital banking and payment journeys. This helps financial institutions decide when a payment can proceed, when additional assurance is needed, and when a transaction requires investigation.

How should organizations implement digital commerce mandates?

Payment Process Flow Diagram

  1. Define the payment relationship. Identify the payer, payee, payment instrument, billing conditions, and party initiating each transaction.
  2. Capture clear consent. Record the terms, scope, timing, and evidence associated with the customer’s authorization.
  3. Classify each later transaction correctly. Distinguish recurring, unscheduled, deferred, installment, and customer-initiated payments.
  4. Map applicable requirements. Review scheme rules, regulatory obligations, card-network programs, and local consumer-protection requirements.
  5. Send complete transaction data. Give issuers and risk systems the context required to make informed decisions.
  6. Monitor changes. Reassess the mandate when the merchant, amount, schedule, payment credential, or customer agreement changes.
  7. Retain evidence. Store consent and authentication records in a way that supports disputes, audits, refunds, and customer support.

Organizations should also test the full journey across browsers, mobile applications, wallets, payment service providers, acquirers, and issuer systems. A mandate may be valid in the merchant system but still fail if the payment message does not describe the transaction accurately.

What are common mandate implementation risks?

  • Unclear consent: The payer cannot understand what will be charged, when it may be charged, or who will initiate the payment.
  • Incorrect transaction classification: A later merchant-initiated payment is sent as if the payer were actively initiating it.
  • Incomplete payment data: Issuers lack the context needed for risk assessment and authorization.
  • Stale payment credentials: A stored credential changes, expires, or is replaced without a controlled update process.
  • Weak change management: Material changes to the agreement are not linked to renewed customer consent.
  • Disconnected fraud controls: Mandate records, authentication events, and transaction monitoring operate in separate systems.

How can authentication support mandate-based payments?

Authentication supports mandate-based payments by confirming the initial agreement, protecting high-risk changes, and adding assurance when later activity differs from the expected pattern.

Entersekt’s 3-D Secure Access Control Server supports issuer authentication journeys that use payment data and risk signals to determine the appropriate experience. This can help issuers address scheme requirements while protecting authorization performance.

For broader payment and banking coverage, modern payment authentication can connect card-not-present payments with digital account access, transaction approval, and other high-risk interactions. The goal is a consistent risk decision across the customer journey rather than an isolated check at checkout.

Mandates in digital commerce: frequently asked questions

➡️ Is a mandate the same as payment authentication?

No. A mandate records authority or sets a requirement, while authentication verifies identity, possession, or intent. Entersekt links authentication decisions to payment context so financial institutions can apply additional assurance when a mandate-based payment presents elevated risk.

➡️ Does every recurring payment require authentication?

No. The initial transaction and later merchant-initiated transactions may receive different treatment under applicable rules. Entersekt supports risk-aware payment authentication so the institution can assess the transaction type, available evidence, and relevant regulatory or scheme requirements.

➡️ What is the difference between a recurring payment and an MIT?

A recurring payment follows an agreed schedule or billing pattern. A merchant-initiated transaction is a broader category for payments started by the merchant after an arrangement exists. Recurring payments can therefore be one type of merchant-initiated transaction.

➡️ Why do scheme mandates matter to issuers?

Scheme mandates can change the data, authentication, monitoring, or reporting capabilities expected from issuers. Entersekt helps issuers connect richer payment context with adaptive authentication decisions across 3-D Secure and digital banking journeys.

➡️ What should a digital commerce mandate record?

It should record the parties, consent, payment scope, timing or triggering conditions, relevant terms, and evidence of acceptance. Entersekt can add authentication evidence and risk context to help institutions investigate disputes and protect later high-risk payment activity.

 Sources and related articles

Payment rules and scheme requirements vary by market and may change. Organizations should confirm the current requirements with their regulator, payment scheme, acquirer, and legal advisers before implementation.


Keep exploring

M
All insights

Find the right path forward

Explore the solutions most relevant to your organization

Solutions by outcome

Explore the outcomes that matter most, from fraud reduction to lower friction.

Solutions by use case

Find the right path for the challenges you need to solve across channels and journeys.

Solutions by industry

See how Entersekt supports banks, credit unions, and other financial institutions.

We don't just protect - we revolutionize

See how Entersekt helps financial institutions move forward