Reference🧭 Global overviewsIntermediate⏱ 30 min read

🔁 Direct debits and mandates around the world

Where the mandate lives, who refunds, and for how long: SEPA Direct Debit, US ACH debits, Bacs and its Service User Number, BECS and PayTo, e-NACH and UPI AutoPay, Pix Automático, and dispute windows compared

Anatomy of a mandate: three things, one word

Direct debit is the only mass-market payment instrument in which the creditor, not the payer, issues the debit order. The payer does nothing on the due date. They consented once, sometimes years earlier, and the money leaves their account without any action on their part. On the agreed date, the creditor sends a collection instruction to its bank, which forwards it to the payer’s bank for execution. This reversal of who initiates the payment drives every rule that applies to the instrument. It sets the dispute windows, the advance-notice obligations, the financial guarantees required of the creditor, and how long a collected payment can still be reversed.

The term “direct debit” covers three distinct things, and each system’s rules name them separately. The authorization is the act by which the payer consents. It is called a mandate in Europe, a Direct Debit Instruction in the UK, a Direct Debit Request in Australia, an authorization in the US, and a recorrência in Brazil. The collection instruction is the message a creditor sends its bank for a specific due date. The rail is the system that clears and settles the transactions. A single rail often carries two authorization regimes that give opposite rights. The creditor’s exposure therefore depends on the authorization regime that applies, not on the rail the payment travels over.

Direct debit systems are classified first by where the authorization is stored. There are four options: with the creditor itself, with the payer’s bank, with a central third party, or in the payer’s banking app. That location determines who bears the burden of proof in a dispute. It also sets how long the transaction can be reversed, and the channel through which the creditor learns that a customer has canceled.

ModelWho holds the mandateSystems in operationOperational impact
Creditor-held mandateThe creditor, which must be able to produce it on requestSEPA Direct Debit Core (European Payments Council), Bacs Direct Debit (Pay.UK), BECS Direct Entry (AusPayNet)Archiving is not a paperwork formality: a creditor that cannot find the mandate loses the dispute automatically
Mandate controlled by the payer’s bankThe payer registers the mandate with its own bank, which checks every collectionSEPA Direct Debit B2B (European Payments Council)Every mandate requires action by the customer; in return, refunds without a reason are ruled out
Mandate registered with a central third partyThe system operator, or the central bank itselfUAEDDS (Central Bank of the UAE, 2012), Betalingsservice (Mastercard Payment Services, 1974)The third party owns the mandate registry; the creditor must follow its calendar and formats
Mandate native to the payer’s appThe payer’s bank, with self-service revocationPayTo (NPP Australia, 2022), Pix Automático (Banco Central do Brasil, 2025)Cancellations no longer go through the creditor’s customer service: the creditor finds out at the next reject, or not at all
The four mandate custody models, and what each means for a creditor
1968
Bacs goes live
The UK launches one of the oldest automated clearing systems still in operation. Direct Debit and Direct Credit have run side by side from the start.
1969
Autogiro in Sweden
Domestic direct debit in Swedish kronor, operated by Bankgirot and never migrated to SEPA (Sveriges Riksbank, December 2025).
1972
The US ACH opens
Regional clearing houses come first; Nacha is formed in 1974 to unify the rules nationwide.
1974
Betalingsservice in Denmark
Centrally held mandates and a fixed monthly cycle, a constraint that still shapes every Danish subscription model.
1984
GIRO in Singapore
Batch direct debit and credit transfer, operated by Banking Computer Services for the Association of Banks in Singapore. It still dominates recurring bills and tax payments.
1994
BECS in Australia
Australia’s Direct Entry, run by AusPayNet, still carries most of the country’s recurring payments.
2009
SEPA Direct Debit
The European Payments Council replaces the region’s patchwork of national direct debit schemes with two pan-European rulebooks, Core and B2B.
2012
UAEDDS in the United Arab Emirates
The central bank launches a direct debit system to replace the post-dated checks that had served as a repayment guarantee.
2016
e-NACH and Incassomachtigen
NPCI launches NACH in India; in the Netherlands, Currence scales up the signing of SEPA mandates through online banking authentication.
2022
PayTo in Australia
Mandates become digital objects that are created, suspended, and revoked in real time in the payer’s app, on the NPP instant payment rail.
June 16, 2025
Pix Automático in Brazil
The Banco Central do Brasil builds recurring authorization onto its instant payment rail, mandatory for all payer-side participants.
🔑
Where the mandate lives decides the burden of proof
When the creditor holds the mandate, it must be able to retrieve it, establish its date, and prove that advance notice was sent. When the mandate is registered with the payer’s bank, that bank checks every collection before accepting it. The creditor gives up commercial flexibility in exchange for legal certainty. When the mandate lives in a banking app, the creditor has no control over its lifecycle. A multi-country collection program that applies the same data model to all four situations loses the fields that decide the outcome in each: the document to produce, the party that checks the collection, and the channel through which a revocation comes back. Its returns then have no identifiable cause in its own data.
11.7 billion
direct debits in the euro area in the second half of 2025, or 14% of non-cash payments, worth €5.6 trillion
ECB, payment statistics, second half of 2025
35.2B
payments on the US ACH Network in 2025, worth $93 trillion, credits and debits combined
Nacha, 2026
5.0B
Bacs direct debits in the UK in 2025, out of 6.86 billion Bacs payments worth £6.05 trillion
Pay.UK, 2025 annual statistics
≈ 117 000
creditors holding a Bacs Service User Number at the end of 2025
Pay.UK

SEPA Direct Debit: two rulebooks, two risk regimes

SEPA Direct Debit is the direct debit scheme shared across the Single Euro Payments Area, live since 2009. Its rules are written by the European Payments Council, an industry association that publishes the rulebooks but runs no infrastructure. Clearing goes through EBA Clearing, national clearing houses, or bilateral links between banks. SEPA covers 41 participating countries (EPC), well beyond the euro area and the European Union. Two schemes share the same brand. Core and B2B give the payer rights so different that the creditor’s risk changes by an order of magnitude.

  • The SEPA creditor identifier (SCI) and the unique mandate reference (UMR) together identify a mandate anywhere in SEPA. A single identifier covers all 41 countries; a creditor does not need one per market.
  • Pre-notification at least 14 calendar days before the due date, unless both parties agree on a shorter period. A dated schedule showing the amounts counts as pre-notification for every line on it.
  • Submission no later than D-1 (business day) and no earlier than D-14, whatever the sequence type. The due date D is the date the payer’s account is debited.
  • Expiry after 36 months: a mandate with no collection submitted for 36 months lapses. Resuming collections requires a new mandate and a new reference.
  • The rulebooks in force are the 2025 v1.1 versions (EPC016-06 for Core, EPC222-07 for B2B), effective since October 5, 2025.
CriterionSDD CoreSDD B2B
Who can be debitedConsumers or businessesNon-consumers only; consumer accounts are rejected
Role of the payer’s bankNo mandate check: it pays, then refunds on requestChecks every collection against the mandate data it holds
Refund of an authorized transaction8 weeks, no reason requiredNone, which is the whole point of the scheme
Presumed unauthorized transaction13 months, with a request for proof of consentAlso 13 months, but the payer’s bank bears the loss
Return of an unpaid debit≤ 5 interbank business days after the due date≤ 3 interbank business days
Mandate setupSigned with the creditor; the payer does nothing at their bankThe payer must register the mandate with its bank, a real hurdle at sign-up
SDD Core vs. SDD B2B: the comparison that determines return risk (EPC rulebooks 2025 v1.1)
⚠️
Eight weeks, no reason needed: broader reversibility than cards
Within the eight-week window, the payer’s bank refunds on request without examining the merits of the claim. It then recovers the amount from the creditor’s bank, which debits the creditor. There is no adversarial process, and the payer has nothing to produce. A card chargeback at least requires citing a reason; an SDD Core refund requires none. The refund always covers the full amount, since the scheme has no partial refunds.

After eight weeks, the rules change. The only transactions that can still be disputed are those presumed unauthorized: the mandate does not exist, was revoked with the creditor, or lapsed after 36 months. The payer’s bank then opens a request for proof of consent, and the creditor must produce the mandate. The outer limit is 13 months after the debit. An SDD Core collection therefore stops being refundable without a reason after eight weeks, but the residual exposure tied to the mandate lasts more than a year.

SEPA Direct Debit coexists with domestic direct debit schemes that it did not replace. Switzerland runs LSV+ (SIX) and Debit Direct (PostFinance) outside SEPA for its Swiss franc payments. Denmark, Norway, and Sweden keep Betalingsservice, AvtaleGiro, and Autogiro, denominated in their own currencies. Germany has used the Elektronisches Lastschriftverfahren at the checkout since 1980: a direct debit mandate signed at the point of sale, with no payment guarantee and no scheme fee. It skews every comparison of card market share in the country. Finland went the other way. Its national direct debit disappeared in 2012, and Finnish banks chose not to offer SDD, favoring e-invoicing instead.

US ACH debits: an authorization, not a mandate

In the US, the authorization is the act by which the payer consents to be debited over the ACH network, and its form depends on the channel used to obtain that consent. The US system has no mandate in the European sense: no standardized creditor identifier, no mandate reference in the message, and no sequence check. The form of authorization is declared in a three-letter code, the SEC code, carried in the ACH entry. The rules are written by Nacha, a private association. Clearing is handled by two competing operators, FedACH (the Federal Reserve Banks) and EPN (The Clearing House). No other country has two clearing operators side by side in this way.

CodeNameUse caseWhat the authorization record must contain
PPDPrearranged Payment and DepositRecurring consumer debit, with written authorizationAuthorization signed or authenticated electronically, retained and reproducible
CCDCorporate Credit or DebitBusiness account debit, one addenda recordContract between the two businesses; no consumer protection
CTXCorporate Trade ExchangeBusiness debit with structured remittance dataSame as CCD, with up to 9,999 addenda records for reconciliation
WEBInternet-Initiated / Mobile EntryConsumer debit authorized online or on mobileTime-stamped authorization flow; account validation required on the first debit to a given account
TELTelephone-Initiated EntryConsumer debit authorized by phoneRecording of the oral authorization, or written confirmation; existing relationship required
IATInternational ACH TransactionAny entry with part of the transaction outside the USSeven mandatory addenda records to enable OFAC screening
The SEC codes a creditor actually encounters, and what each requires of the authorization

The ODFI (Originating Depository Financial Institution), the bank that sends the entry into the network, bears the risk. It gives Nacha contractual warranties on the entries it submits. In return, it imposes reserves, submission limits, and requirements on third-party processors on the creditor. A US creditor therefore negotiates its access terms with its bank, not with the scheme, and each ODFI sets its requirements based on its own risk appetite.

CodeReasonReturn windowWhat to do
R01Insufficient funds2 banking daysRetry allowed: Nacha permits up to two re-presentments after an R01 or R09
R02Account closed2 banking daysNever re-present: ask for new account details
R03 / R04Account does not exist or invalid account number2 banking daysData error: a sign that account validation was skipped at enrollment
R07Authorization revoked by the account holder60 calendar days after the settlement dateThe mandate is dead: stop the series and document the revocation
R08Payment stopped by the payer (stop payment)Depends on the entry typeThe payer blocked this debit at its bank without revoking the authorization
R10 / R11The consumer says the entry was unauthorized or did not match the authorization60 calendar days after the settlement dateThe real cost of consumer ACH: the debit can come back up to two months after delivery
R29The receiving business says the entry was unauthorized2 banking daysA very short window: this is what makes CCD/CTX debits far less risky than PPD or WEB
The ACH return codes that drive the economics of debits (Nacha rules)
⚠️
A 30-fold gap between consumer and business debits
The return window for an unauthorized transaction is 60 calendar days for an R10 and two banking days for an R29, on the same rail, in the same file, and at the same bank. The exposure periods differ by a factor of about 30. A consumer account holder has no evidence to produce: a written statement is enough to trigger the return. The burden of proof falls entirely on the creditor. Nacha monitors each originator’s unauthorized return rate, with a 0.5% threshold above which the ODFI must step in. A consumer debit program that exceeds it faces the cost of the returns and the loss of its access to the rail.

Two changes have reshaped ACH debits. The first is Same Day ACH, launched in 2016, which offers three same-day settlement windows. Its per-payment limit was raised to $1 million in March 2022. It handled 1.4 billion payments worth $3.9 trillion in 2025, up from 1.2 billion and $3.2 trillion in 2024 (Nacha, 2026). The second is account validation, required on the first WEB debit to a given account since March 19, 2021. Checking how the provider implements it is the first audit item for any US program. The legal foundation remains Regulation E (12 CFR 1005), which protects consumers against unauthorized transfers. Other disputes fall outside its scope.

Bacs: the Service User Number and the Direct Debit Guarantee

Bacs is the UK’s batch clearing system for sterling payments, in service since 1968. It is owned by Pay.UK and operated by Vocalink, a Mastercard subsidiary. It carries two products: Bacs Direct Credit for salaries, pensions, and benefits, and Direct Debit for recurring bills. The UK processed 5.0 billion direct debits in 2025 over Bacs, out of 6.86 billion Bacs payments worth £6.05 trillion (Pay.UK, 2025 annual statistics). The rail has 33 direct participants and about 330 indirect participants (Pay.UK, end of 2025).

Access to the scheme goes through the Service User Number (SUN), a six-digit identifier that the sponsoring bank assigns to the creditor. The number identifies the entity financially liable for indemnity claims, and the creditor gets one only after showing its bank that it is financially strong enough to repay them. A creditor without a SUN goes through a bureau service and collects under a third party’s number. That third party then carries the liability the scheme attaches to the number.

The three-business-day Bacs cycle
Day 1: creditor
Submits the collection file
Before the cutoff, through Bacs-approved software or a bureau service; the file carries the six-digit Service User Number
Day 2: Bacs
Processes and distributes to payers’ banks
Format rejects and unknown instructions come back in the return files
Day 3: settlement
Payers debited and creditor credited the same day
That day’s unpaid debits come back via ARUDD; the funds were never available
After the cycle
Indemnity claims
A claim under the Direct Debit Guarantee can arrive much later, notified via DDICA
  • AUDDIS (Automated Direct Debit Instruction Service): setting up and canceling instructions, initiated by the creditor.
  • ADDACS (Automated Direct Debit Amendment and Cancellation Service): amendments and cancellations made by the payer or their bank; the file that tells you a customer has just left.
  • ARUDD (Automated Return of Unpaid Direct Debits): the cycle’s unpaid debits, with the reason for each.
  • DDICA (Direct Debit Indemnity Claim Advice): notice of an indemnity claim, meaning a refund already paid to the payer and recovered from the creditor.
  • Advance Notice: the creditor tells the payer the amount and date before each debit. The notice period is set in the sponsorship agreement: 10 business days by default, shorter if both sides agree.
⚠️
The Direct Debit Guarantee: no cap, no time limit
Every UK payer is covered by the Direct Debit Guarantee. If a direct debit is wrong (wrong amount, wrong date, no mandate), the payer’s bank refunds it immediately and in full, without investigating and with no time limit. It then recovers the money from the creditor through an indemnity claim. SDD Core closes its no-reason refund window after eight weeks; the UK Guarantee has no deadline at all. A creditor that cannot produce the instruction and proof of advance notice loses the claim automatically. The financial exposure tied to archiving UK mandates is therefore permanent.

Variable Recurring Payments (VRP), which grew out of UK open banking, are where this market is heading. The mandate lives in the payer’s banking app, and payments run over the Faster Payments rail. Settlement is immediate, with no comparable refund guarantee. Sweeping, meaning transfers between accounts held by the same person, is live; commercial VRP is not yet live at scale. The two models expose billers to different risks. With Bacs direct debit, a collection can be reversed with no time limit. With VRP, the customer can revoke the authorization instantly, alone, at any time, with no notice to the creditor.

Asia-Pacific: BECS, PayTo, GIRO, DuitNow AutoDebit

BECS (Bulk Electronic Clearing System), also known as Direct Entry, is Australia’s batch clearing system for retail payments, the equivalent of the US ACH. It went live in 1994 and is governed by the rules of AusPayNet, the industry’s self-regulatory body. It accepts transactions of up to A$100 million, though its day-to-day traffic is low-value: salaries, benefits, and bill payments. The authorization is called a Direct Debit Request (DDR). It comes with a DDR Service Agreement, in which the creditor sets out its own commitments to the payer on advance notice, dispute handling, and cancellation. AusPayNet publishes the BECS regulations, the BECS procedures, and drafting guidelines for DDRs.

BECS was supposed to be retired. In November 2023, AusPayNet had set a shutdown target of June 2030, in favor of the NPP instant payment rail. AusPayNet dropped that target date in December 2025, for lack of a credible account-to-account roadmap. The Reserve Bank of Australia published an updated risk assessment of BECS in March 2026 without setting a new deadline. The shutdown date is therefore open again. In the meantime, BECS still carries most of Australia’s recurring payments.

PayTo, launched in 2022 by NPP Australia (part of Australian Payments Plus), is BECS’s designated successor. Its mandate is a digital object that is created, amended, suspended, and revoked in real time in the payer’s banking app. Three features set it apart from earlier direct debit models and rule out reusing their integrations as is. Settlement is immediate and final. There is no multi-day reject window for the creditor to adjust its cash position. Revocation is unilateral and instant, and the payer exercises it with their own bank. Finally, the creditor learns that a customer has left the moment it happens, not at the next collection cycle.

SystemCountry and operatorType of authorizationWhat a creditor needs to know
GIRO (1984), eGIROSingapore, Banking Computer Services for the Association of Banks in SingaporeOriginally a paper mandate, now set up online through eGIROStill dominant for recurring bills and tax despite PayNow; eGIRO eliminated the setup delay, not the batch rail
BECS / Direct Entry (1994)Australia, AusPayNetDirect Debit Request held by the creditor, backed by a DDR Service AgreementStill carries most Australian recurring payments; payroll software vendors integrate it by default, not the NPP
BECS (New Zealand)New Zealand, under the Payments NZ rules frameworkAuthorization held by the creditorShares its name with the Australian system but runs under separate rules: never copy a configuration from one to the other
Interbank GIRO (IBG) and DuitNow AutoDebitMalaysia, Payments Network Malaysia (PayNet), supervised by Bank Negara MalaysiaIBG: batches with deferred settlement. AutoDebit: a mandate given once in the banking appDuitNow Transfer and FPX are both payer-initiated: recurring billers use AutoDebit or legacy direct debit
PayTo (2022)Australia, NPP Australia (AP+)Digital mandate hosted by the payer’s bankFinal settlement within seconds, self-service revocation: no reject window, no cancellation notice
Recurring mandates in Asia-Pacific, from oldest to newest
ℹ️
PayTo is not a direct debit, and neither is Pix Automático
Mandates on an instant payment rail change how a collection is accounted for. The payment is final the moment it goes through, and the period during which part of the revenue could still come back disappears. The creditor has no provision for returns to build and no retry cycle to run in the days that follow. It also receives no advance warning that a customer is leaving. Exposure shifts upstream, away from the returns that used to follow collection. It now hinges on the quality of the authorization obtained and on the observed revocation rate.

India: NACH, e-NACH, UPI AutoPay, and the 2026 e-mandate framework

NACH (National Automated Clearing House), operated by NPCI since 2016, is India’s bulk clearing rail, carrying recurring direct debits one way and bulk disbursements the other. Its paperless version, e-NACH, registers a mandate online via Aadhaar, net banking, or a debit card, with no paper form and no wet signature. UPI AutoPay is the equivalent on the instant payment rail: the mandate is linked to the payer’s UPI ID and executed by the switch. Indian creditors therefore have two families of mandates, running on two separate rails. Success rates depend on which family they choose.

NACH also handles a use case that no other country runs at this scale. Through the Aadhaar Payment Bridge System (APBS), the Indian government pays direct benefit transfers to hundreds of millions of recipients identified by their Aadhaar number rather than an account number. Routing relies on a continuously updated mapping table between Aadhaar numbers and bank accounts, not on the paying agency’s own database of bank details. On the debit side, the value processed on NACH Debit is growing about 27% a year (NPST analysis of RBI data, 2026).

e-NACH (NACH rail)UPI AutoPay (UPI rail)
AddressingPayer’s bank account: account number and IFSC codePayer’s UPI ID (VPA)
EnrollmentAadhaar, net banking, or debit card (longer flow)In the UPI app, in seconds
ExecutionBatch clearing with net settlementDebit on the instant rail
Typical useLarge amounts: loan installments (EMI), insurance premiums, systematic investment plans (SIP)Consumer subscriptions and small recurring amounts
Failed debitReject handled within the NACH cycle; a retry must be scheduledImmediate reject; retry possible the same day
Choosing between e-NACH and UPI AutoPay

The legal framework for these mandates was rewritten on April 21, 2026. The Digital Payments – E-mandate Framework, 2026 (circular RBI/CO.DPSS.POLC.No.S56/02.14.003/2026-27) repeals the circulars issued since 2019 and consolidates them into a single text. It applies equally to cards, UPI, and prepaid instruments, for both domestic and cross-border recurring transactions.

  • The first transaction under a mandate always requires an additional factor of authentication (AFA). No exceptions.
  • After that, AFA is not required up to ₹15,000 per transaction. Above that amount, it is required again at the time of debit.
  • Threshold raised to ₹1 lakh per transaction for three categories: insurance premiums, mutual fund subscriptions, and credit card bill payments.
  • Pre-debit notification at least 24 hours before each debit, showing the payee’s name, the amount, the date and time, the mandate reference, and the purpose.
  • The right to decline individual transactions, and mandate revocation validated with AFA.
  • No charges to the customer for using the e-mandate service, and a post-debit notification listing the ways to file a complaint.
🔑
Pre-debit notification moves the point of failure
The 24-hour notice, combined with the right to decline, changes when a direct debit fails. Failure now happens the day before the debit, when the payer reads the notification and declines. The failure rate then depends on how clear that message is. A retry model imported from Europe or the US and built around return codes misses this entirely. In India, a significant share of failures are early cancellations triggered by the notification itself. The 2026 framework also has a structural effect. The same ₹15,000 limit and the same ₹1 lakh (₹100,000) exception now apply to both rails, which ends regulatory arbitrage between cards and UPI.

Pix Automático: a mandate born on an instant payment rail

Pix Automático is the recurring payment authorization feature of Brazil’s Pix system, defined in Article 11-Q of the Pix regulation annexed to Resolução BCB No. 1 of August 12, 2020. It went live on June 16, 2025, a date set by Resolução BCB No. 402 of July 22, 2024. The payer’s provider automatically initiates a Pix from the payer’s account on instruction from the payee’s provider, subject to the payer’s prior, specific authorization. It runs on the Pix rail, which carried 79.8 billion transactions worth R$35.36 trillion in 2025 (BCB, 2026).

  • Mandatory for payer-side providers: every Pix participant that offers transaction accounts must offer Pix Automático to its customers. Offering it as a payee’s provider is optional.
  • Business payees only, with an active CNPJ (Brazilian company registration number). Pix Automático does not handle person-to-person transfers or one-off payments.
  • Free for the payer: payers cannot be charged. The payee’s provider is free to charge its own customer.
  • No brand of its own: the Banco Central do Brasil prohibits any derived logo or symbol. You cannot put a badge on a Pix Automático flow.
  • Declared frequency (weekly, monthly, quarterly, semiannual, or annual), with an open-ended term, a set number of payments, or an end date.
Lifecycle of a Pix Automático payment
Recipient
Obtains authorization through one of four flows
Request pushed to the payer’s app, authorization QR code, QR code combining an immediate payment with the authorization, or a flow tied to an invoice
Payee’s provider
Sends the payment instruction
Between 10 and 2 days before the scheduled settlement date, never earlier, rarely later
Payer's provider
Schedules the payment and notifies the payer
The 2-to-10-day lead time gives the payer notice of the debit and time to prepare
Settlement
Two mandatory windows
00:00 to 08:00, then 18:00 to 21:00, Brasília time; any attempts in between are left to the payer’s provider
Failure
Mandatory same-day retry
Between 18:00 and 21:00 the same day, after a notification asking the payer to top up the account or raise the limit
Continued failure
Retries for up to 7 days
Only if the authorization allows it; the instruction must go out by 23:59 the day before the new date

Two features specific to Pix Automático have no equivalent in the other systems covered here. The first is the Pix Automático limit, a daily cap per transaction account, separate from the standard Pix limit and not overlapping with it. A request to raise it must be processed within 8 hours at most, compared with at least 24 hours for the standard Pix limit (BCB Normative Instruction No. 512 of August 30, 2024). The second is the credit line attached to the account, drawn on by default when funds are insufficient. The payer can turn it off authorization by authorization, from the Pix Automático menu in their app.

Code or messageRoleWhat it triggers for the creditor
pain.009 / pain.011Request to confirm a recurring payment, and its cancellationResending an identical offer within 30 calendar days of a refusal counts as abusive
pain.012Payer confirms or rejects the authorizationIts reason table covers every authorization failure: account not found, payer data not identifiable, and so on
pain.013Payment instruction for a scheduled paymentStrict window: 10 to 2 days before scheduled settlement
UPAYPayment made in error: no valid recurring authorization at settlementThe authorization was canceled on the payee side, but the payer’s provider did not learn of it in time
AC06Payer’s account frozen by court orderNew schedules refused; existing schedules are not canceled
FRUDCancellation on well-founded suspicion of fraudEither provider can cancel an authorization at any time, on its own initiative
Codes a Pix Automático integration encounters (Pix Automático FAQ, Banco Central do Brasil)
⚠️
No refund window: the mandate can be revoked, but the payment does not come back
Canceling a Pix Automático authorization takes effect immediately and ends the recurring series. Payments scheduled from the next day onward are canceled with it, or from the day after that if the message arrives after 22:00. The payer can also cancel a single scheduled payment until 23:59 (Article 8 of BCB Normative Instruction No. 513 of August 30, 2024), without affecting the authorization. The scheme, however, provides no after-the-fact dispute process for a payment that has already settled. An improper charge falls under Brazil’s Consumer Defense Code and is resolved between the payee and its customer, with no R-transaction. A provision for returns calculated on SEPA logic is therefore irrelevant in Brazil, where the creditor’s exposure lies in instant revocation of the authorization.

Dispute windows compared

The dispute window is the period during which a direct debit that has already been collected can still be clawed back from the creditor’s account. Each scheme’s rules set its length, which ranges from two days to unlimited depending on the country. A collection becomes earned revenue only once that window has closed. The table below ranks the regimes from shortest to longest exposure.

SchemeTechnical returnNo-questions-asked refundUnauthorized transactionWho ultimately bears the loss
Business ACH debit (CCD, CTX), US2 banking days (R01 and others)None2 banking days (R29)The creditor, through its ODFI
SDD B2B, SEPA≤ 3 interbank business daysNone13 months, but the payer’s bank bears the lossThe payer’s bank
PayTo, AustraliaNone: settlement is final within secondsNoneNo scheme window; general legal remedies onlyThe payer, unless fraud is proven
Pix Automático, BrazilNone: the payment settles or fails, with no in-between stateNoneNo scheme window; Consumer Defense CodeThe payee, under its contract with the customer
SDD Core, SEPA≤ 5 interbank business days8 weeks, no reason required13 months, with a request for proof of consentThe creditor, through its bank
Consumer ACH debit (PPD, WEB, TEL), US2 banking daysNo general right, but the payer can issue a stop payment (R08)60 calendar days (R10, R11), on a simple written statementThe creditor, through its ODFI
Bacs Direct Debit, UKUnpaid debits reported via ARUDD within the cycleDirect Debit Guarantee: no cap, no time limitSame as the previous column: the Guarantee covers bothThe creditor, through an indemnity claim
Return and dispute windows by scheme (sources: EPC rulebooks 2025 v1.1, Nacha rules, Pay.UK, AusPayNet, Banco Central do Brasil, RBI)

These regimes fall into three groups. B2B and instant regimes expose the creditor little or not at all, since the payment is final within days, sometimes seconds. Traditional consumer regimes expose it for 2 to 13 months, and the burden of proof falls on the creditor. The UK regime is a group of its own, because it has no time limit at all. A company selling the same subscription in Munich, Chicago, and Manchester therefore needs three different provisions for an identical product.

🔑
The revenue recognition rule
A direct debit collection goes through three stages before it is final. The first is interbank settlement. The second is the end of the return window, two to five business days depending on the scheme. The third is the end of the dispute window, which runs from eight weeks to 13 months and never closes in the UK. A cash forecast built only on the first stage ignores the third, yet that is exactly when reversals happen. They come in clusters after a billing incident, and they hit entire cohorts.

These windows apply alongside local law; they do not replace it. A refund denied under the rulebook may still be owed under consumer law, and vice versa. The scheme governs how funds move between banks; it does not decide the underlying dispute between the creditor and its customer.

Running a multi-country direct debit program

A multi-country direct debit program collects recurring receivables over several national rails from a single billing system. Its hard problems are the mandate registry, evidence retention, and cash forecasting, more than API integration or file formats. The most common integration failures come from a data model that assumes a universal mandate, and from a retry policy tuned for a single return regime.

🪪
One creditor identifier per region, not per country
A single SEPA creditor identifier covers all 41 countries in scope. By contrast, the UK Service User Number, enrollment with a payee’s provider in Brazil, and bank sponsorship in Australia are local and cannot be transferred. Design the registry to accept several creditor identifiers for the same legal entity.
📄
A mandate is evidence, not a database record
Timestamp, channel, version of the accepted terms, IP address or authentication ID, proof that the notice was sent. This record must be rebuilt months later, at the request of a bank that will not grant extra time. Without it, the dispute is lost by default.
⏱️
Advance notice is mandatory, and the deadline differs everywhere
14 calendar days for SDD, 10 business days by default for Bacs, 24 hours in India with a right to decline, 2 to 10 days in Brazil. A billing engine that applies a single notice period breaks three rules out of four and triggers refusals that were entirely avoidable.
💧
Provision by regime, not by revenue
A consolidated average return rate is meaningless when one line is exposed for two days and another for 13 months. Break down the provision by scheme and by mandate cohort. Sponsoring banks require reserves calculated this way.
  • Treat return files as product data. ADDACS and ARUDD in the UK, R codes in the US, SEPA R-transactions, pain.011 and pacs.002 in Brazil: on rails where the mandate lives with the payer, these are the creditor’s only cancellation signals.
  • Tell revocations apart from returns. A US R07, an ADDACS cancellation, or a canceled Pix authorization ends the series for good. Retrying after one is a breach of contract, not a collections optimization.
  • Choose the strictest regime the customer will accept. SDD B2B rather than Core when the payer is a business, CCD rather than PPD in the US: you trade friction at sign-up for exposure that is orders of magnitude smaller.
  • Check account validation at enrollment. Required on the first US WEB debit since March 19, 2021, it is still the most cost-effective measure everywhere else: half of structural rejects come from account details that were wrong from the start.
  • Track the unauthorized return rate separately from the overall return rate. It is the metric banks and scheme operators watch (Nacha sets a 0.5% threshold), and its drift, not the return rate, is what gets a creditor cut off from the rail.
✅
The question to ask before entering a market
Three questions are enough to size up an unfamiliar direct debit rail. First, where the mandate is stored, and who must produce it in a dispute. Second, how long a collection can still be reversed, and what evidence is needed to contest a reversal. Third, how a cancellation reaches the creditor, and how quickly. The answers fit on one page per country. They clear away three-quarters of the problems that come up when entering a market, and they are all in the scheme documentation, which is public in almost every market covered here.

Legacy rails such as Bacs, ACH, BECS, and GIRO are not going away, despite announced shutdown timetables. Australia has withdrawn its deadline. A second generation of mandates is growing alongside them, hosted at the payer’s bank and running on instant payment rails: PayTo, Pix Automático, UK Variable Recurring Payments, and UPI AutoPay. This generation removes return risk and replaces it with revocation risk. For a biller, the work shifts from managing returns to retaining customers, and the overall workload is no lighter.