In digital commerce, a mandate is an instruction, agreement, or industry requirement that determines how a payment may be initiated, authenticated, or processed. The term is used in two related ways: a customer mandate authorizes future or recurring payments, while a scheme or regulatory mandate sets requirements for payment security, data, or authentication.
Mandates in digital commerce matter because payment journeys now extend beyond a single checkout. A customer may approve a subscription, save a payment credential, return through a wallet, or complete a purchase under a card-network authentication program. Each journey needs clear consent, reliable records, and risk decisions that match the payment context.
A mandate in digital commerce is an instruction or rule that establishes the authority for a payment action. It can come from the payer, who authorizes a merchant to initiate future charges, or from a payment scheme, regulator, or standards body that sets conditions for processing and authentication.
A customer mandate normally records the payer’s consent, the merchant or creditor identity, the payment arrangement, and any terms that govern later transactions. A scheme mandate, by contrast, tells participating institutions what data, controls, or authentication outcomes they must support.
| Type | What it does | Typical example |
|---|---|---|
| Recurring payment mandate | Authorizes a merchant to initiate scheduled payments after an initial agreement. | A streaming subscription billed each month. |
| Merchant-initiated transaction mandate | Records consent for a later payment initiated by the merchant rather than the payer at the moment of collection. | A hotel charging a card after a reservation condition is met. |
| SEPA Direct Debit mandate | Authorizes a biller to collect funds directly from a payer’s bank account. | A utility bill collected by direct debit. |
| Scheme mandate | Sets payment-network requirements for participating issuers, acquirers, merchants, or processors. | A card-network requirement for richer 3-D Secure data. |
| Regulatory mandate | Creates legal or supervisory requirements for payment security and customer protection. | Strong Customer Authentication rules under PSD2. |
A recurring payment mandate begins when the payer agrees to a billing arrangement. The initial transaction usually establishes the relationship and records the payment details, terms, and consent. Later transactions follow the agreed schedule or billing conditions.
The merchant must retain evidence that the arrangement exists and must apply the correct transaction indicators when sending later payment requests. A change to the amount, schedule, merchant, or terms may require renewed consent or a new authentication decision.
Recurring payments cover subscriptions, installments, memberships, insurance premiums, utilities, and other services. The payment may be recurring at a fixed interval or triggered by an event, such as usage, delivery, or a reservation condition.
A merchant-initiated transaction, or MIT, is a payment that the merchant initiates after the payer has established an agreement or mandate. The payer is not actively initiating each later payment, so the transaction carries different authentication and processing considerations from a customer-initiated purchase.
The European Banking Authority describes later payments in a recurring card arrangement as payee-initiated transactions. Its guidance also distinguishes these payments from the initial transaction, where the payer is present and authentication may be required under the applicable rules.
MIT categories can include recurring payments, unscheduled credential-on-file payments, and deferred payments. Correct classification matters because the payment message, authentication record, liability treatment, and issuer decision may depend on how the transaction was initiated.
A SEPA Direct Debit mandate authorizes a biller to collect funds from the payer’s bank account. The European Payments Council states that the mandate sits at the center of a SEPA Direct Debit payment and may be issued in paper or electronic form.
The mandate identifies the authorization relationship between the payer and the biller. It supports recurring collections and gives the payer a defined process for challenging or requesting a refund for an eligible debit.
SEPA Direct Debit includes a Core scheme for consumers and a Business-to-Business scheme for businesses. The operational rules, payer rights, and implementation requirements differ, so the relevant scheme must be identified before a digital mandate journey is designed.
Scheme mandates turn industry expectations into operational requirements for payment participants. They may require better transaction data, specific authentication methods, stronger risk analysis, or reporting that enables issuers to make more informed authorization decisions.
For example, Mastercard and Visa have introduced requirements associated with their 3-D Secure authentication programs. These initiatives focus on data quality and authentication performance across the payment ecosystem. Entersekt’s analysis of these changes explains how issuers can prepare for evolving 3DS requirements.
3DS authentication mandates can affect merchants, payment service providers, acquirers, issuers, and cardholders at the same time. A change in one participant’s data or authentication process can influence authorization outcomes elsewhere in the chain.
Authentication confirms that the person or device involved in a payment is authorized to act. A mandate establishes why a merchant may initiate a payment or what requirements a participant must meet. They are related, but they are not interchangeable.
The initial setup of a recurring arrangement may require customer authentication, consent, or both. Later payments may rely on the original agreement and the transaction indicators that show the payment is merchant initiated. Risk signals can still influence whether the issuer requests additional assurance.
Strong Customer Authentication rules under PSD2 focus on situations where the payer initiates an electronic payment or performs an action that may create a payment-fraud risk. The exact treatment depends on the transaction type, applicable exemptions, and current legal interpretation.
For a regulatory reference, consult the EU technical standards for strong customer authentication and the relevant supervisory guidance for the market in which the payment is processed.
Mandates create an evidence trail for payment consent, but they do not guarantee that every later payment is legitimate. A criminal may compromise an account, alter payment details, manipulate a customer into approving a transaction, or exploit a poorly controlled recurring arrangement.
Risk decisioning should therefore consider more than the existence of a mandate. Useful signals can include device context, customer behavior, transaction details, merchant history, location, and the relationship between the payer and the payee.
Entersekt connects authentication and payment risk signals across digital banking and payment journeys. This helps financial institutions decide when a payment can proceed, when additional assurance is needed, and when a transaction requires investigation.
Organizations should also test the full journey across browsers, mobile applications, wallets, payment service providers, acquirers, and issuer systems. A mandate may be valid in the merchant system but still fail if the payment message does not describe the transaction accurately.
Authentication supports mandate-based payments by confirming the initial agreement, protecting high-risk changes, and adding assurance when later activity differs from the expected pattern.
Entersekt’s 3-D Secure Access Control Server supports issuer authentication journeys that use payment data and risk signals to determine the appropriate experience. This can help issuers address scheme requirements while protecting authorization performance.
For broader payment and banking coverage, modern payment authentication can connect card-not-present payments with digital account access, transaction approval, and other high-risk interactions. The goal is a consistent risk decision across the customer journey rather than an isolated check at checkout.
No. A mandate records authority or sets a requirement, while authentication verifies identity, possession, or intent. Entersekt links authentication decisions to payment context so financial institutions can apply additional assurance when a mandate-based payment presents elevated risk.
No. The initial transaction and later merchant-initiated transactions may receive different treatment under applicable rules. Entersekt supports risk-aware payment authentication so the institution can assess the transaction type, available evidence, and relevant regulatory or scheme requirements.
A recurring payment follows an agreed schedule or billing pattern. A merchant-initiated transaction is a broader category for payments started by the merchant after an arrangement exists. Recurring payments can therefore be one type of merchant-initiated transaction.
Scheme mandates can change the data, authentication, monitoring, or reporting capabilities expected from issuers. Entersekt helps issuers connect richer payment context with adaptive authentication decisions across 3-D Secure and digital banking journeys.
It should record the parties, consent, payment scope, timing or triggering conditions, relevant terms, and evidence of acceptance. Entersekt can add authentication evidence and risk context to help institutions investigate disputes and protect later high-risk payment activity.
Payment rules and scheme requirements vary by market and may change. Organizations should confirm the current requirements with their regulator, payment scheme, acquirer, and legal advisers before implementation.