The four SEPA rails: SCT, SCT Inst, SDD Core, and SDD B2B
SEPA credit transfers and SEPA direct debits are two euro-denominated, bank-money payment instruments governed by common rules across the area. A credit transfer is initiated by the payer, who instructs the movement of funds. A direct debit is initiated by the creditor, based on a mandate signed by the debtor. The European Payments Council (EPC) publishes four versions, called schemes, whose rules on timelines and revocability differ from one scheme to another. In France, in the first half of 2025 (according to the OSMP, France’s payment security observatory, in a statistical note published January 27, 2026), credit transfers accounted for 17.9% of cashless transactions by number and 90% of the value exchanged. Direct debits accounted for 14.3% of transactions, with an average amount of €453, typical of a recurring bill rather than an occasional payment. The distinction between SDD Core and SDD B2B determines the refund window: eight weeks, no questions asked, in the first case, and none at all in the second for an authorized transaction.
| Scheme | Who initiates | Settlement time | Reversibility | ISO 20022 messages | Typical use |
|---|---|---|---|---|---|
| SCT (SEPA credit transfer) | The payer | Payee credited by D+1 business day at the latest, a deadline set by the EPC SCT rulebook for the entire SEPA area (codified in France in Article L. 133-13 of the Monetary and Financial Code) | Return within 3 banking days; Recall within 10 business days, with no guarantee of recovery | pain.001.001.09 (customer → bank), pacs.008.001.08 (interbank) | Salaries, invoices, refunds |
| SCT Inst (instant credit transfer) | The payer | 10 seconds max, 24/7, 365 days a year | No unilateral cancellation: funds are credited and available before any dispute can be raised | pacs.008.001.08, cancellation via camt.056.001.08 | P2P, pay-by-bank, urgent payments, large purchases |
| SDD Core (standard direct debit) | The creditor, under a mandate signed by the debtor | Presented no later than D-1 business day and no earlier than D-14 calendar days; debited on due date D | 8 weeks for a no-questions-asked refund; 13 months if unauthorized | pain.008.001.08 (customer → bank), pacs.003.001.08 (interbank) | Subscriptions, consumer bills, installment plans |
| SDD B2B (business-to-business direct debit) | The creditor, under a mandate from a non-consumer debtor | Presented no later than D-1 business day; the debtor’s bank checks the mandate before paying | No refund of an authorized transaction; return possible within 3 business days only | Same messages, LclInstrm = B2B | Commercial rents, suppliers, franchises |
Reading an IBAN correctly
FR 14 20041 01005 0500013M026 06 French IBAN: 27 characters (34 max, ISO 13616)
| | | | | |
| | | | | +-- RIB key: 2 digits, legacy French national check
| | | | +-------------- account number: 11 characters, digits AND letters
| | | +-------------------- branch code: 5 digits
| | +-------------------------- bank code: 5 digits
| +----------------------------- IBAN check digits: 2 digits, ISO 7064 MOD 97-10
+-------------------------------- ISO 3166-1 country code (FR)
# Checking the IBAN check digits by hand:
# 1. move the first 4 characters to the end -> 20041010050500013M02606FR14
# 2. convert letters to digits, A=10 ... Z=35 -> 200410100505000132202606152714
# 3. the result modulo 97 must equal exactly 1 -> IBAN is arithmetically valid
# National lengths: 27 in France, 22 in Germany, 16 in Belgium, 15 in Norway.
# A shorter IBAN is therefore perfectly normal, and SEPA no longer requires the BIC.The IBAN, or International Bank Account Number, is the standardized bank account identifier defined by ISO 13616. It combines a country code, check digits, and a national account identifier, and its total length varies by country. Two features of this structure govern how it is used. First, the BIC is no longer required for a SEPA credit transfer or direct debit: Regulation (EU) No 260/2012 removed that requirement in February 2014 for domestic transactions and in February 2016 for cross-border ones. A form that still asks for it adds a data-entry step, and therefore a source of errors, without improving processing. Second, the IBAN check digits prove only that the number is arithmetically consistent. An IBAN that passes the calculation may belong to a closed account or to a fraudster. The account holder is not verified. Verification of payee, mandatory since October 9, 2025, addresses exactly that point.
signal.conso.gouv.fr. The technical excuse sometimes offered, that a system only handles 27 characters, is no defense. Bringing the form into compliance is the responsibility of whoever operates it.VOP: what verification of payee has checked since October 9, 2025
Verification of payee (VOP) is the check that compares the name entered by the payer with the actual holder of the account identified by the IBAN, before the transfer is authorized. It has been mandatory for every payment service provider (PSP) in the euro area since October 9, 2025, under Article 5c of the SEPA Regulation. That article was inserted by Regulation (EU) 2024/886 on instant payments, which made instant credit transfers mandatory in the euro area. The payer’s bank queries the payee’s bank, which holds the name registered on the account. The check takes place before any authorization, whether or not the transfer is instant. The service is free (Article 5b(2)) and must be offered on every initiation channel. Paper instructions are subject to the same check, carried out on receipt if the payer is present. The EPC standardizes the exchanges between PSPs through the VOP rulebook, which took effect on October 5, 2025, four days before the regulatory deadline.
| Response | What the payer sees | What the PSP must do | Who bears the risk |
|---|---|---|---|
| Match | Nothing special; the flow continues | Let the payer authorize | Normal situation |
| Close match (near match) | The name actually registered by the payee’s bank is displayed | Display that name so the payer can decide, applying data minimization | The payer, who approves with full knowledge |
| No match | Explicit warning: authorizing may send the funds to an account that does not belong to the named payee | Warn without blocking: the PSP cannot prevent authorization (Art. 5c(5)) | The payer, who has been warned and owns the decision |
| Verification not possible | Notice that the check could not be performed | Proceed and inform: no response within 5 seconds, PSP unreachable or outside the scheme | Gray area: the payer received no useful information |
- Normalization before comparison: case ignored, accents and diacritics neutralized (
é = e,ö = o = oe), titles and punctuation removed, leading and trailing spaces trimmed (EPC288-23 recommendations, October 2024). - Individuals: exact first and last name = Match; the exact name of just one of the joint account holders is enough.
- Legal entities: the trade name can count as a Match if the payee’s bank has a reliable source for it, in addition to the registered company name.
- Close match: two transposed letters, a first name reduced to an initial, a phonetic substitution, or a misspelling below the Levenshtein distance threshold set by the payee’s bank.
- Identification codes (VAT number, legal entity identifier): Match or No match only; no Close match is possible on a code.
- The payee’s bank is responsible for the verdict it returns: that bank, not the payer’s, decides what counts as a Match.
The regulation allocates liability among providers based on whether each has met its own obligations. A PSP that has met them is not liable for a transfer executed to the wrong payee on the basis of an incorrect unique identifier. A failure on its part, such as not offering VOP or not giving the payer the result, can however make the transaction defectively executed. In that case, it refunds the amount transferred without delay and restores the debited account. When the failure lies with the payee’s bank or the payment initiation service provider, liability shifts to them (Article 5c(8)).
SCT Inst and the IPR: what actually changed in 2025–2026
- Tighter intermediate deadlines in the 2025 SCT Inst rulebook v1.1 (EPC004-16, in force since October 5, 2025) to meet the statutory 10 seconds. The old 10-20-25 s sequence becomes 5-7-9 s: a 5 s target for confirmation by the payee’s bank (down from 10 s), time-out at 7 s (down from 20 s), and receipt of the confirmation by the payer’s bank by the 9th second at the latest (down from the 25th).
- Millisecond time stamps are mandatory (the Time Stamp attribute): they are the reference for measuring the 10 seconds.
- After 10 s without confirmation, the payer’s bank must immediately restore the payer’s account and notify the payer.
- Sanctions screening redesigned (Art. 5d): screening covers the customer base, immediately after any list update and at least once every calendar day. Rescreening the payer and payee transaction by transaction is prohibited, which removes the main source of delays.
- SCT Inst Recall: only one per transaction, for limited reasons (duplicate, technical problem, fraudulent transfer); 10 banking days, extended to 13 months for fraud; the payee’s bank has 15 business days to respond, after which a Request for Status Update is the only recourse.
The direct debit mandate: SCI, UMR, and pre-notification
FR 72 ZZZ 123456 French SCI (ICS): 13 characters (35 max in SEPA)
| | | |
| | | +-- national identifier, 6 alphanumeric characters (formerly NNE), assigned
| | | by the Banque de France via the creditor's bank
| | +------ business code (Creditor Business Code): 3 free characters, chosen
| | by the creditor, NOT included in the check digits, NOT checked by
| | the debtor's bank -> they do NOT create a new creditor
| +--------- check digits, ISO 7064 MOD 97-10, calculated on country + national
| identifier only
+------------ country code: FR, MC (Monaco), NC, PF, WF
# Mandate uniqueness across SEPA = pair (SCI minus business code; UMR).
# One SCI covers the whole SEPA area: no need for one SCI per country.<PmtInf>
<PmtMtd>DD</PmtMtd>
<PmtTpInf>
<SvcLvl><Cd>SEPA</Cd></SvcLvl>
<LclInstrm><Cd>CORE</Cd></LclInstrm> <!-- CORE or B2B: never mixed -->
<SeqTp>RCUR</SeqTp> <!-- OOFF | FRST (optional) | RCUR | FNAL -->
</PmtTpInf>
<ReqdColltnDt>2026-08-05</ReqdColltnDt> <!-- D: due date = debit date -->
<Cdtr><Nm>ACME ENERGIE SAS</Nm></Cdtr> <!-- name shown on the debtor's statement -->
<CdtrSchmeId><Id><PrvtId><Othr>
<Id>FR72ZZZ123456</Id> <!-- SCI (ICS) -->
<SchmeNm><Prtry>SEPA</Prtry></SchmeNm>
</Othr></PrvtId></Id></CdtrSchmeId>
<DrctDbtTxInf>
<PmtId><EndToEndId>FACT-2026-08-004512</EndToEndId></PmtId>
<InstdAmt Ccy="EUR">64.90</InstdAmt>
<DrctDbtTx><MndtRltdInf>
<MndtId>RUM-CLI-004512</MndtId> <!-- UMR: identical for the life of the mandate -->
<DtOfSgntr>2024-03-11</DtOfSgntr> <!-- signature date: can be relied on in a dispute -->
</MndtRltdInf></DrctDbtTx>
<Dbtr><Nm>MARTIN DUPONT</Nm></Dbtr>
<DbtrAcct><Id><IBAN>FR1420041010050500013M02606</IBAN></Id></DbtrAcct>
</DrctDbtTxInf>
</PmtInf>- Mandatory pre-notification: the creditor tells the debtor the amount and date no later than 14 calendar days before the due date, unless both parties agree on a shorter period. A schedule with dates and amounts counts as pre-notification for every line on it.
- UMR: up to 35 Latin characters chosen freely by the creditor, but strictly identical in the first direct debit, all subsequent ones, and all R-transactions. Spaces are discouraged (they cause rejects when files are read manually), and the CFONB, France’s banking standards body, recommends including no sensitive data (IBAN, ID document number, card number).
- Lapse after 36 months: a mandate with no direct debit presented for 36 months after the last due date lapses, as does a mandate after a collection with sequence type FNAL. Resuming collections requires a new mandate and a new UMR.
- Sequence type: since version 9.0 of the SDD Core rulebook, applicable from November 2016, using
FRSTfor the first collection in a series is optional, andRCURis accepted from the very first collection. An inconsistent sequence, however (anRCURafter anOOFF), triggers anAG02reject. - Retention: the creditor must be able to produce the mandate for at least the full dispute window for unauthorized transactions, or 13 months after the last direct debit. This is the copy the debtor’s bank will request.
The life cycle of a direct debit, from D-14 to D+13 months
| R-transaction | Who initiates it | Operating hours | Effect and notes |
|---|---|---|---|
| Revocation | The creditor, with its bank | Before the collection is released into the clearing system | Outside the scope of the EPC rulebooks: an optional service; check your bank contract |
| Request for cancellation | The creditor’s bank | Before settlement | Also outside the rulebook; typically used after a duplicate batch |
| Reject | The debtor’s bank or the CSM | Before settlement on D | Technical or banking reason: invalid IBAN, closed account, invalid file format |
| Refusal | The debtor | Before D | Handled before D, it becomes a Reject; handled after D, a Refund |
| Return | The debtor’s bank | Within 5 banking days after D in Core, 3 in B2B | Standard return: insufficient funds, blocked account, debtor stop instruction |
| Reversal | The creditor or its bank | From settlement up to 5 interbank business days | Refunds the debtor voluntarily; the debtor’s bank must process it without checks |
| No-questions-asked refund (Refund, MD06) | The debtor | Within 8 weeks of the debit (+ 2 business days of processing) | Core only, no justification required, refunded on first request |
| Refund for an unauthorized transaction (MD01) | The debtor | From 8 weeks to 13 calendar months (+ 30 days for the procedure + 4 business days) | Triggers the proof-of-consent investigation |
After 8 weeks, the basis for a debtor’s claim changes. Only a transaction presumed unauthorized, because the mandate never existed, was revoked with the creditor, or lapsed after 36 months, can still be disputed, for up to 13 months. The debtor’s bank then applies the proof-of-consent investigation procedure, which requires the creditor to produce a copy of the signed mandate. In France, each step of this procedure has a time limit. The debtor’s bank forwards the claim within 4 banking days, and the creditor’s bank passes it on to the creditor within 3 days. The creditor responds within 7 days, and the debtor’s bank concludes within 4 days of the response, no later than 30 calendar days after its customer’s claim. The refund may include compensatory interest calculated on €STR. Under French law, the foundation is the Monetary and Financial Code. Its Article L. 133-18 requires immediate refund of an unauthorized transaction, and Article L. 133-24 sets the reporting deadline at 13 months after the debit. Article L. 133-25 grants the right to a refund of an authorized direct debit within 8 weeks.
Core or B2B: the choice that determines return risk
| Criterion | SDD Core | SDD B2B |
|---|---|---|
| Who can be the debtor | Consumer or business | Non-consumers only (Art. 2(24) of Regulation 260/2012); a consumer account is rejected with AC13 |
| Role of the debtor’s bank | No mandate check: it pays, and refunds on request | Must check every collection against the mandate data registered with it |
| Refund of an authorized transaction | 8 weeks, no questions asked | None; that is the whole point of the scheme |
| Unauthorized transaction | 13 months; the debtor’s bank recovers the funds from the creditor’s bank | 13 months as well, but the debtor’s bank cannot recover from the creditor’s bank: it bears the loss |
| Return after settlement | ≤ 5 banking days | ≤ 3 banking days |
| PSP participation | Mandatory for every PSP that joins the SEPA schemes | Optional scheme: not every institution offers it, on either the creditor or the debtor side |
| Mandate administration burden | Mandate kept by the creditor only | The debtor must submit and register the mandate with its bank, and notify the bank of any revocation |
MD01 rejects, even though the creditor holds a signed mandate.The choice between the two schemes comes down to the risk of returns versus the cost of obtaining the mandate. B2B is used when individual amounts are high, the contractual relationship is stable, and the debtor is equipped to handle mandate registration with its bank. Commercial rents, franchise fees, and recurring supply orders meet those conditions. For a €49-a-month software subscription sold online to microbusinesses, the balance flips. The friction of mandate registration, in both delay and signature rate, far outweighs the risk of returns. Core, combined with automated follow-up on reject codes, then costs less than a B2B mandate.
When it fails: ISO codes, deadlines, who pays
| Code | ISO description | What actually happened | What to do |
|---|---|---|---|
AM04 | Insufficient funds | Insufficient funds on the due date, the number one reason for returns | Re-present on a chosen date (after payday), not immediately |
AC01 | Incorrect account number | IBAN doesn’t exist or was mistyped | Collect the IBAN from the customer again; never “correct” an IBAN yourself |
AC04 | Closed account | Account closed | Dead mandate: new bank details and a new mandate needed |
AC06 | Blocked account | Account blocked, or the debtor has blocked this creditor | Contact the debtor: a block amounts to a revocation |
AC13 | Invalid debtor account type | B2B direct debit presented on a consumer account | Switch the relationship to Core |
AG01 | Transaction forbidden | Direct debits not allowed on this account type (savings account, term deposit) | Ask for a checking account |
AG02 | Invalid bank operation code | Inconsistent sequence: RCUR after an OOFF, or mandate already finalized | Fix SeqTp in the mandate database |
AM05 | Duplication | Duplicate detected by the CSM or the debtor’s bank | Audit batch idempotency: a replayed file is expensive |
BE05 | Unrecognised initiating party | Unknown or inconsistent SCI | Check the SCI with your bank before re-presenting |
MD01 | No mandate | No valid mandate: never signed, revoked, lapsed, or not registered (B2B) | Produce a copy of the mandate within 7 business days, or the loss is final |
MD06 | Refund requested by end customer | Refund claimed without a reason within 8 weeks | Commercial follow-up: the interbank route is closed |
MD07 | End customer deceased | Debtor deceased | Close the contract and pursue the claim with the estate |
MS02 | Refusal by the debtor | Debtor refused before the due date, after pre-notification | Warning sign: the pre-notification did its job |
SL01 | Specific service offered by the debtor PSP | Filter set by the debtor: creditor whitelist, cap, frequency | Get the SCI added to the customer’s allowlist |
MS03 | Reason not specified | Masked reason: some banks use it when national rules prohibit disclosing AC04, AM04, MD07, RR01… | Don’t assume a “technical error”: an MS03 often hides insufficient funds |
Credit transfers have a narrower set of R-transactions than direct debits, and each procedure depends on when the problem is detected. Before settlement, the originator’s bank or the CSM rejects the transaction (invalid IBAN or BIC, duplicate, file past the cut-off). After settlement, the payee’s bank can return the transaction within 3 banking days (closed account, deceased payee, transfers not allowed on that account type, payee refusal). Finally, the originator’s bank can initiate a Recall within 10 banking days, for three reasons only: duplicate, technical problem, or fraudulent transfer. The deadline extends to 13 months for fraud. Only one recall is allowed per transaction, and the payee’s bank has 15 business days to respond. For any other reason, such as the customer sending money to the wrong payee, the only option left is a Request for Recall by the Originator, which requires the payee’s consent. Technically, the request is sent with camt.056.001.08 and the response with camt.029.001.09.
Deadlines to put on the calendar
Elsewhere in the world. The same mechanism, elsewhere.
Maximum execution time for an instant credit transfer
In Brazil, the Pix timing manual sets a 40-second limit between the payer’s bank receiving the order and settlement. Beyond that, SPI, the central bank’s instant payment system, rejects the transaction. On top of that come a service-level agreement on the payer experience (6.0 seconds at the 50th percentile, 10.0 seconds at the 99th) and a secondary channel capped at 45 minutes for scheduled Pix payments.
Banco Central do Brasil, Manual de Tempos do Pix, version 7.0, § 1.1, https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IX_ManualdeTemposdoPix.pdf
In the US, the Federal Reserve’s FedNow Service applies a 20-second payment timeout clock: if the payee’s bank has not responded before the clock runs out, the payment is rejected and both banks receive a failure message. Each receiving bank reserves 1 to 5 seconds of that clock for itself, depending on its capacity to process the message.
Federal Reserve, FedNow Service, “Understanding the payment timeout clock,” https://explore.fednow.org/resources/readiness-guide-understanding-the-payment-timeout-clock.pdf
In India, the Reserve Bank of India sets no deadline in seconds but puts a price on delays. When a UPI transfer is debited without the payee being credited, the automatic reversal must happen by D+1 at the latest. Otherwise, the bank owes the customer ₹100 in compensation per day of delay, paid without the customer having to claim it. The deadline extends to D+5 for a merchant payment left unconfirmed.
RBI, circular DPSS.CO.PD No.629/02.01.014/2019-20 of September 20, 2019, “Harmonisation of Turn Around Time (TAT) and customer compensation for failed transactions,” https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11693
Verifying the payee’s name before a credit transfer is authorized
In the UK, the Payment Systems Regulator mandated Confirmation of Payee in two waves: the six largest banking groups under Specific Direction 10, by March 31, 2020, then about 400 more institutions under Specific Direction 17, by October 31, 2024. The payer receives a match, close match, or no match before confirming, and can correct the instruction before the funds are sent.
Payment Systems Regulator, Confirmation of Payee, https://www.psr.org.uk/our-work/app-scams/confirmation-of-payee/
In Brazil, the check has been built into the Pix flow from the start. Looking up a Pix key in the DICT directory must return to the payer, before confirmation, the payee’s full name, a masked CPF (individual taxpayer number) or the CNPJ (company registration number), and the unmasked key, but never the branch or account number. For a legal entity, the trade name must be displayed where one exists, and the registered company name otherwise.
Banco Central do Brasil, Requisitos mínimos para a experiência do usuário, version 7.3, December 2025, https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IV_RequisitosMinimosparaExperienciadoUsuario.pdf
In Australia, payee verification comes not from legislation but from an industry-wide commitment, the Scam-Safe Accord. Banks put A$100 million into a national Confirmation of Payee platform, rolled out from July 2025, with a target of more than 95% of personal accounts covered by the end of 2025.
Australian Banking Association, Confirmation of Payee, https://www.ausbanking.org.au/scam-safe-accord/confirmation-of-payee/
What protects the debtor in a direct debit: mandate, pre-notification, and refund
In the US, there is no equivalent of the no-questions-asked refund. Regulation E limits the consumer’s liability to $50 if the unauthorized transaction is reported within two business days, and to $500 after that. Consumers must also report a transaction that appears on a statement within 60 days of the statement being sent, or bear the cost of subsequent debits.
12 CFR § 1005.6 (Regulation E), https://www.consumerfinance.gov/rules-policy/regulations/1005/6/
In South Africa, protection sits before the debit rather than after it. Since May 1, 2021, every new or renegotiated early debit order mandate must be created in the DebiCheck system, where debtors approve the mandate electronically with their own bank before any collection takes place.
South African Reserve Bank, “The SARB modernises NPS with DebiCheck Project,” https://www.resbank.co.za/en/home/publications/publication-detail-pages/media-releases/2021/The-SARB-modernises-NPS-with-Debicheck-Project
In India, the notice owed to the debtor is counted in hours, not days. The Reserve Bank of India requires the issuer to send the cardholder a pre-transaction notification at least 24 hours before a recurring mandate is debited, stating the merchant name, amount, date and time of the debit, transaction reference, and reason for the debit.
RBI, circular DPSS.CO.PD.No.447/02.14.003/2019-20 of August 21, 2019, “Processing of e-mandate on cards for recurring transactions,” https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11668