Reference💳 Payment methodsIntermediate⏱ 15 min read

🏦 SEPA credit transfers and direct debits

SCT, SCT Inst, SDD Core, and SDD B2B: reading an IBAN, understanding VOP, getting the mandate right, and knowing the return windows to the day

The four SEPA rails: SCT, SCT Inst, SDD Core, and SDD B2B

SEPA credit transfers and SEPA direct debits are two euro-denominated, bank-money payment instruments governed by common rules across the area. A credit transfer is initiated by the payer, who instructs the movement of funds. A direct debit is initiated by the creditor, based on a mandate signed by the debtor. The European Payments Council (EPC) publishes four versions, called schemes, whose rules on timelines and revocability differ from one scheme to another. In France, in the first half of 2025 (according to the OSMP, France’s payment security observatory, in a statistical note published January 27, 2026), credit transfers accounted for 17.9% of cashless transactions by number and 90% of the value exchanged. Direct debits accounted for 14.3% of transactions, with an average amount of €453, typical of a recurring bill rather than an occasional payment. The distinction between SDD Core and SDD B2B determines the refund window: eight weeks, no questions asked, in the first case, and none at all in the second for an authorized transaction.

3,093M
credit transfers sent in France in H1 2025, or 90% of cashless payment value
Observatoire de la sécurité des moyens de paiement (OSMP), H1 2025 statistical note, January 2026
467M
instant credit transfers in H1 2025 (up 70% in a year), or 15% of transfers sent, versus 9% a year earlier
OSMP, H1 2025 statistical note
2,481M
SEPA direct debits in H1 2025, average amount €453
OSMP, H1 2025 statistical note
41
countries and territories within the geographic scope of the SEPA schemes (27 EU + 3 EEA + 11 non-EEA)
EPC409-09 v8.0, December 24, 2025
Payerbanking app or ERPPayer’s PSPchecks, debits, forwardsorder + SCAVoP: payee name vs IBANmandatory since Oct. 9, 2025pacs.008 in batchesBatch CSMSTEP2 · CORE(FR): cut-offsPayee’s PSPcredit on D+1 (business day)net settlement, in cyclesfunds on D+1single pacs.008Real-time CSMTIPS · RT1: 24/7/365Payee’s PSPcredit in ≤ 10 sgross settlement in central bank moneyreusable immediatelyaccepted or rejected in ≤ 10 sSCT Inst cap removed Oct. 5, 2025SCT: recall up to 13 months, no guaranteeSCT Inst: irrevocable once creditedStandard SCT: batchesSCT Inst: one by one, 24/7confirmationEach PSP sets its own limits, but under the EU Instant Payments Regulation (IPR) they cannot be lower than for standard SCT.
SchemeWho initiatesSettlement timeReversibilityISO 20022 messagesTypical use
SCT (SEPA credit transfer)The payerPayee credited by D+1 business day at the latest, a deadline set by the EPC SCT rulebook for the entire SEPA area (codified in France in Article L. 133-13 of the Monetary and Financial Code)Return within 3 banking days; Recall within 10 business days, with no guarantee of recoverypain.001.001.09 (customer → bank), pacs.008.001.08 (interbank)Salaries, invoices, refunds
SCT Inst (instant credit transfer)The payer10 seconds max, 24/7, 365 days a yearNo unilateral cancellation: funds are credited and available before any dispute can be raisedpacs.008.001.08, cancellation via camt.056.001.08P2P, pay-by-bank, urgent payments, large purchases
SDD Core (standard direct debit)The creditor, under a mandate signed by the debtorPresented no later than D-1 business day and no earlier than D-14 calendar days; debited on due date D8 weeks for a no-questions-asked refund; 13 months if unauthorizedpain.008.001.08 (customer → bank), pacs.003.001.08 (interbank)Subscriptions, consumer bills, installment plans
SDD B2B (business-to-business direct debit)The creditor, under a mandate from a non-consumer debtorPresented no later than D-1 business day; the debtor’s bank checks the mandate before payingNo refund of an authorized transaction; return possible within 3 business days onlySame messages, LclInstrm = B2BCommercial rents, suppliers, franchises
The four SEPA schemes: who initiates, when, and how reversible, based on the EPC 2025 rulebooks version 1.1 (SCT EPC125-05, SCT Inst EPC004-16, SDD Core EPC016-06, SDD B2B EPC222-07), in force since October 5, 2025
🔑
The rule of thumb, in one sentence
Collecting from consumers calls for SDD Core, where each collection can be reversed without a reason for 8 weeks. Near-final collection from businesses calls for SDD B2B, at the cost of a mandate the debtor must register with its bank. Paying out, as opposed to collecting, runs on SCT. SCT Inst replaces it when the payee needs the funds immediately, with no possibility of unilateral cancellation afterward.

Reading an IBAN correctly

Anatomy of a French IBAN (27 characters) and its check digits
FR 14 20041 01005 0500013M026 06      French IBAN: 27 characters (34 max, ISO 13616)
|  |  |     |     |           |
|  |  |     |     |           +-- RIB key: 2 digits, legacy French national check
|  |  |     |     +-------------- account number: 11 characters, digits AND letters
|  |  |     +-------------------- branch code: 5 digits
|  |  +-------------------------- bank code: 5 digits
|  +----------------------------- IBAN check digits: 2 digits, ISO 7064 MOD 97-10
+-------------------------------- ISO 3166-1 country code (FR)

# Checking the IBAN check digits by hand:
#   1. move the first 4 characters to the end    -> 20041010050500013M02606FR14
#   2. convert letters to digits, A=10 ... Z=35  -> 200410100505000132202606152714
#   3. the result modulo 97 must equal exactly 1 -> IBAN is arithmetically valid
# National lengths: 27 in France, 22 in Germany, 16 in Belgium, 15 in Norway.
# A shorter IBAN is therefore perfectly normal, and SEPA no longer requires the BIC.

The IBAN, or International Bank Account Number, is the standardized bank account identifier defined by ISO 13616. It combines a country code, check digits, and a national account identifier, and its total length varies by country. Two features of this structure govern how it is used. First, the BIC is no longer required for a SEPA credit transfer or direct debit: Regulation (EU) No 260/2012 removed that requirement in February 2014 for domestic transactions and in February 2016 for cross-border ones. A form that still asks for it adds a data-entry step, and therefore a source of errors, without improving processing. Second, the IBAN check digits prove only that the number is arithmetically consistent. An IBAN that passes the calculation may belong to a closed account or to a fraudster. The account holder is not verified. Verification of payee, mandatory since October 9, 2025, addresses exactly that point.

⚠️
Refusing a foreign IBAN is illegal, and fines apply
Article 9 of Regulation (EU) No 260/2012 prohibits IBAN discrimination, the practice of making a payment or collection conditional on the account being held in a particular country. An employer, a government agency, a telecom operator, or an insurer therefore cannot require an IBAN starting with “FR” as long as the account is located in the SEPA area. In France, Act No. 2021-1308 of October 8, 2021, empowers the DGCCRF, France’s consumer protection and anti-fraud authority, to investigate and prosecute this violation. It can fine a refusal up to €75,000 for an individual and €375,000 for a legal entity. Complaints are filed at signal.conso.gouv.fr. The technical excuse sometimes offered, that a system only handles 27 characters, is no defense. Bringing the form into compliance is the responsibility of whoever operates it.

VOP: what verification of payee has checked since October 9, 2025

Verification of payee (VOP) is the check that compares the name entered by the payer with the actual holder of the account identified by the IBAN, before the transfer is authorized. It has been mandatory for every payment service provider (PSP) in the euro area since October 9, 2025, under Article 5c of the SEPA Regulation. That article was inserted by Regulation (EU) 2024/886 on instant payments, which made instant credit transfers mandatory in the euro area. The payer’s bank queries the payee’s bank, which holds the name registered on the account. The check takes place before any authorization, whether or not the transfer is instant. The service is free (Article 5b(2)) and must be offered on every initiation channel. Paper instructions are subject to the same check, carried out on receipt if the payer is present. The EPC standardizes the exchanges between PSPs through the VOP rulebook, which took effect on October 5, 2025, four days before the regulatory deadline.

ResponseWhat the payer seesWhat the PSP must doWho bears the risk
MatchNothing special; the flow continuesLet the payer authorizeNormal situation
Close match (near match)The name actually registered by the payee’s bank is displayedDisplay that name so the payer can decide, applying data minimizationThe payer, who approves with full knowledge
No matchExplicit warning: authorizing may send the funds to an account that does not belong to the named payeeWarn without blocking: the PSP cannot prevent authorization (Art. 5c(5))The payer, who has been warned and owns the decision
Verification not possibleNotice that the check could not be performedProceed and inform: no response within 5 seconds, PSP unreachable or outside the schemeGray area: the payer received no useful information
VOP responses and what they actually mean
  • Normalization before comparison: case ignored, accents and diacritics neutralized (é = e, ö = o = oe), titles and punctuation removed, leading and trailing spaces trimmed (EPC288-23 recommendations, October 2024).
  • Individuals: exact first and last name = Match; the exact name of just one of the joint account holders is enough.
  • Legal entities: the trade name can count as a Match if the payee’s bank has a reliable source for it, in addition to the registered company name.
  • Close match: two transposed letters, a first name reduced to an initial, a phonetic substitution, or a misspelling below the Levenshtein distance threshold set by the payee’s bank.
  • Identification codes (VAT number, legal entity identifier): Match or No match only; no Close match is possible on a code.
  • The payee’s bank is responsible for the verdict it returns: that bank, not the payer’s, decides what counts as a Match.
⚠️
Four VOP pitfalls that are not the bank’s fault
1) VOP covers the match between a name and an IBAN, and nothing else. It confirms that the IBAN belongs to that name, without establishing that the payee is legitimate or that the invoiced service exists. Manipulation fraud, through a fake bank adviser or a fake listing, gets past this check, since the name and IBAN given to the payer are consistent with each other. 2) The IBAN remains the legally binding unique identifier (Article 88 of PSD2), so a Match does not protect anyone from an IBAN typo. The transfer follows the account number; the name entered only serves to alert the payer. 3) Non-consumer users can opt out of VOP for their bulk payments (Article 5c(6)) and opt back in at any time. What that opt-out covers depends on where the batch is assembled. The rulebook allows a bulk request between customers and their own bank, but prohibits it between banks. In the interbank space, the PSP must split the file and send one request per account to be verified (VOP rulebook, section 3.2). 4) A merchant that invoices under a trade name different from the account holder’s name will trigger a string of No match results among its customers. The fix is to show the exact account name, as the bank registered it, on invoices and on the RIB (French bank account details).

The regulation allocates liability among providers based on whether each has met its own obligations. A PSP that has met them is not liable for a transfer executed to the wrong payee on the basis of an incorrect unique identifier. A failure on its part, such as not offering VOP or not giving the payer the result, can however make the transaction defectively executed. In that case, it refunds the amount transferred without delay and restores the debited account. When the failure lies with the payee’s bank or the payment initiation service provider, liability shifts to them (Article 5c(8)).

SCT Inst and the IPR: what actually changed in 2025–2026

April 8, 2024
Regulation (EU) 2024/886 (IPR) takes effect
It amends SEPA Regulation 260/2012 and inserts Articles 5a to 5d: mandatory instant payments, price parity, verification of payee, and sanctions screening.
January 9, 2025
Mandatory receipt and price parity
Every euro area PSP that offers credit transfers must be able to receive SCT Inst, at a price no higher than a standard transfer. As a result, instant transfers are in practice free for consumers in France.
October 5, 2025, 03:30 CET
EPC 2025 v1.1 rulebooks and VOP rulebook
Effective date set in October this time (instead of late November) to match the IPR: SCT, SCT Inst, SDD Core (EPC016-06), and SDD B2B (EPC222-07) version 2025 v1.1, plus the first VOP rulebook.
October 9, 2025
Mandatory sending and mandatory VOP
SCT Inst must be offered for sending on every channel, and verification of payee becomes mandatory and free in the euro area (Art. 5c; free of charge under Art. 5b(2)).
January 9, April 9, and July 9, 2027
Non-euro area wave
Receiving for banks outside the euro area on January 9, 2027, and sending on July 9, 2027; payment institutions and e-money institutions on April 9, 2027 (sending and receiving in the euro area).
⚠️
The €100,000 cap is gone, but every bank keeps its own
The long-standing cap of €100,000 per transaction (raised from €15,000 in July 2020) was removed from the 2025 SCT Inst rulebook, as provided for in Article 5a(6) of the amended SEPA Regulation. The scheme no longer imposes any cap, and the reason code for “amount exceeds the maximum allowed” has disappeared from rejects. Section 2.5 of the rulebook, however, still lets each PSP apply its own value limits based on its risk appetite. Conversely, the IPR requires that payers be able to set, change, or remove their individual limit, per transaction or per day. Limits are therefore set by each institution and each customer rather than by the scheme. The maximum amount that can actually be executed depends on the sending bank’s limit, the receiving bank’s limit, and the payer’s own settings. A €250,000 instant transfer therefore still depends on the limits of that particular pair of banks.
  • Tighter intermediate deadlines in the 2025 SCT Inst rulebook v1.1 (EPC004-16, in force since October 5, 2025) to meet the statutory 10 seconds. The old 10-20-25 s sequence becomes 5-7-9 s: a 5 s target for confirmation by the payee’s bank (down from 10 s), time-out at 7 s (down from 20 s), and receipt of the confirmation by the payer’s bank by the 9th second at the latest (down from the 25th).
  • Millisecond time stamps are mandatory (the Time Stamp attribute): they are the reference for measuring the 10 seconds.
  • After 10 s without confirmation, the payer’s bank must immediately restore the payer’s account and notify the payer.
  • Sanctions screening redesigned (Art. 5d): screening covers the customer base, immediately after any list update and at least once every calendar day. Rescreening the payer and payee transaction by transaction is prohibited, which removes the main source of delays.
  • SCT Inst Recall: only one per transaction, for limited reasons (duplicate, technical problem, fraudulent transfer); 10 banking days, extended to 13 months for fraud; the payee’s bank has 15 business days to respond, after which a Request for Status Update is the only recourse.

The direct debit mandate: SCI, UMR, and pre-notification

SEPA creditor identifier (SCI, or ICS in France): structure and check digits
FR 72 ZZZ 123456      French SCI (ICS): 13 characters (35 max in SEPA)
|  |  |   |
|  |  |   +-- national identifier, 6 alphanumeric characters (formerly NNE), assigned
|  |  |       by the Banque de France via the creditor's bank
|  |  +------ business code (Creditor Business Code): 3 free characters, chosen
|  |          by the creditor, NOT included in the check digits, NOT checked by
|  |          the debtor's bank -> they do NOT create a new creditor
|  +--------- check digits, ISO 7064 MOD 97-10, calculated on country + national
|             identifier only
+------------ country code: FR, MC (Monaco), NC, PF, WF

# Mandate uniqueness across SEPA = pair (SCI minus business code; UMR).
# One SCI covers the whole SEPA area: no need for one SCI per country.
Annotated excerpt from a pain.008.001.08 direct debit instruction
<PmtInf>
  <PmtMtd>DD</PmtMtd>
  <PmtTpInf>
    <SvcLvl><Cd>SEPA</Cd></SvcLvl>
    <LclInstrm><Cd>CORE</Cd></LclInstrm>      <!-- CORE or B2B: never mixed -->
    <SeqTp>RCUR</SeqTp>                       <!-- OOFF | FRST (optional) | RCUR | FNAL -->
  </PmtTpInf>
  <ReqdColltnDt>2026-08-05</ReqdColltnDt>     <!-- D: due date = debit date -->
  <Cdtr><Nm>ACME ENERGIE SAS</Nm></Cdtr>      <!-- name shown on the debtor's statement -->
  <CdtrSchmeId><Id><PrvtId><Othr>
    <Id>FR72ZZZ123456</Id>                    <!-- SCI (ICS) -->
    <SchmeNm><Prtry>SEPA</Prtry></SchmeNm>
  </Othr></PrvtId></Id></CdtrSchmeId>
  <DrctDbtTxInf>
    <PmtId><EndToEndId>FACT-2026-08-004512</EndToEndId></PmtId>
    <InstdAmt Ccy="EUR">64.90</InstdAmt>
    <DrctDbtTx><MndtRltdInf>
      <MndtId>RUM-CLI-004512</MndtId>         <!-- UMR: identical for the life of the mandate -->
      <DtOfSgntr>2024-03-11</DtOfSgntr>       <!-- signature date: can be relied on in a dispute -->
    </MndtRltdInf></DrctDbtTx>
    <Dbtr><Nm>MARTIN DUPONT</Nm></Dbtr>
    <DbtrAcct><Id><IBAN>FR1420041010050500013M02606</IBAN></Id></DbtrAcct>
  </DrctDbtTxInf>
</PmtInf>
  • Mandatory pre-notification: the creditor tells the debtor the amount and date no later than 14 calendar days before the due date, unless both parties agree on a shorter period. A schedule with dates and amounts counts as pre-notification for every line on it.
  • UMR: up to 35 Latin characters chosen freely by the creditor, but strictly identical in the first direct debit, all subsequent ones, and all R-transactions. Spaces are discouraged (they cause rejects when files are read manually), and the CFONB, France’s banking standards body, recommends including no sensitive data (IBAN, ID document number, card number).
  • Lapse after 36 months: a mandate with no direct debit presented for 36 months after the last due date lapses, as does a mandate after a collection with sequence type FNAL. Resuming collections requires a new mandate and a new UMR.
  • Sequence type: since version 9.0 of the SDD Core rulebook, applicable from November 2016, using FRST for the first collection in a series is optional, and RCUR is accepted from the very first collection. An inconsistent sequence, however (an RCUR after an OOFF), triggers an AG02 reject.
  • Retention: the creditor must be able to produce the mandate for at least the full dispute window for unauthorized transactions, or 13 months after the last direct debit. This is the copy the debtor’s bank will request.
⚠️
One UMR for several contracts: a bad idea that looks good
Grouping several contracts under one UMR simplifies the creditor’s mandate database, since only one mandate identifier needs to be managed. But a revocation of the mandate or a stop instruction from the debtor then applies to that single identifier, and all the underlying contracts go down at once. A second rule requires a Core mandate’s UMR to be different from a B2B mandate’s, or the transactions are rejected. As for the SCI’s business code, the debtor’s bank neither checks it nor includes it in the check digits. Using it to identify a subsidiary works within the creditor’s internal database, but it creates no separation that banks will recognize.

The life cycle of a direct debit, from D-14 to D+13 months

Timeline of a SEPA Core direct debit
Creditor
Sends pre-notification to the debtor
Amount and due date, no later than D-14 calendar days
Creditor
Submits the pain.008 file to its bank
Per its bank’s contractual cutoff, often D-2 or D-3
Creditor’s bank
Presents the collection through the CSM
Received by the debtor’s bank no later than D-1 business day, no earlier than D-14
Debtor’s bank
Rejects before settlement, or pays
Technical reject or debtor refusal before D
CSM
Interbank settlement on due date D
D = due date = date the debtor’s account is debited
Debtor’s bank
May return the transaction
Return up to D+5 banking days (3 in B2B)
Debtor
Requests a no-questions-asked refund
Up to 8 weeks after the debit, Core only, code MD06
Debtor
Disputes an unauthorized transaction
From 8 weeks to 13 calendar months, with a search for proof of the mandate, code MD01
Signed mandateSCI + UMRPre-notification≥ 14 calendar dayspain.008 submissionD-1 business dayDebitdue date DmandateD-14D-1 business dayD = due dateBefore settlementReject: technical, bank or CSMRefusal: the debtor refusesRevocation: the creditor cancelsAfter settlement: 4 return windowsReturndebtor bank · 5 days Core, 2 days B2BReversalcreditor, after the debit · 5 business daysRefunddebtor, no reason needed · 8 weeksUnauthorized-debit refundmandate proof required · 13 monthsAn 8-week hidden liabilityevery Core collection can still be disputed€1M/month collected ≈ €2M exposedSDD B2Bmandate verified, no refundreturn within 2 business daysBefore the due dateSubmission and debitBank-initiatedDebtor-initiatedCreditor-initiatedOnly the reason code (AC01, AC04, AM04, MD01) tells you whether a returned debit can legitimately be re-presented.
R-transactionWho initiates itOperating hoursEffect and notes
RevocationThe creditor, with its bankBefore the collection is released into the clearing systemOutside the scope of the EPC rulebooks: an optional service; check your bank contract
Request for cancellationThe creditor’s bankBefore settlementAlso outside the rulebook; typically used after a duplicate batch
RejectThe debtor’s bank or the CSMBefore settlement on DTechnical or banking reason: invalid IBAN, closed account, invalid file format
RefusalThe debtorBefore DHandled before D, it becomes a Reject; handled after D, a Refund
ReturnThe debtor’s bankWithin 5 banking days after D in Core, 3 in B2BStandard return: insufficient funds, blocked account, debtor stop instruction
ReversalThe creditor or its bankFrom settlement up to 5 interbank business daysRefunds the debtor voluntarily; the debtor’s bank must process it without checks
No-questions-asked refund (Refund, MD06)The debtorWithin 8 weeks of the debit (+ 2 business days of processing)Core only, no justification required, refunded on first request
Refund for an unauthorized transaction (MD01)The debtorFrom 8 weeks to 13 calendar months (+ 30 days for the procedure + 4 business days)Triggers the proof-of-consent investigation
Direct debit R-transactions: who, when, and with what effect, based on the timelines in the 2025 SDD Core rulebook v1.1 (EPC016-06, published October 5, 2025)
🔑
The 8 weeks: the real cost of Core direct debit
Within the 8-week window, the debtor’s bank refunds on first request, without assessing the merits of the claim. It then recovers the funds from the creditor’s bank, which in turn debits the creditor. There is no adversarial process and no evidence to produce. SDD Core therefore offers broader reversibility than cards, where a chargeback requires at least a reason and opens an adversarial process. For accounting purposes, a Core collection becomes certain revenue only once those 8 weeks have passed. The refund always covers the full amount; partial refunds are not possible.

After 8 weeks, the basis for a debtor’s claim changes. Only a transaction presumed unauthorized, because the mandate never existed, was revoked with the creditor, or lapsed after 36 months, can still be disputed, for up to 13 months. The debtor’s bank then applies the proof-of-consent investigation procedure, which requires the creditor to produce a copy of the signed mandate. In France, each step of this procedure has a time limit. The debtor’s bank forwards the claim within 4 banking days, and the creditor’s bank passes it on to the creditor within 3 days. The creditor responds within 7 days, and the debtor’s bank concludes within 4 days of the response, no later than 30 calendar days after its customer’s claim. The refund may include compensatory interest calculated on €STR. Under French law, the foundation is the Monetary and Financial Code. Its Article L. 133-18 requires immediate refund of an unauthorized transaction, and Article L. 133-24 sets the reporting deadline at 13 months after the debit. Article L. 133-25 grants the right to a refund of an authorized direct debit within 8 weeks.

Core or B2B: the choice that determines return risk

CriterionSDD CoreSDD B2B
Who can be the debtorConsumer or businessNon-consumers only (Art. 2(24) of Regulation 260/2012); a consumer account is rejected with AC13
Role of the debtor’s bankNo mandate check: it pays, and refunds on requestMust check every collection against the mandate data registered with it
Refund of an authorized transaction8 weeks, no questions askedNone; that is the whole point of the scheme
Unauthorized transaction13 months; the debtor’s bank recovers the funds from the creditor’s bank13 months as well, but the debtor’s bank cannot recover from the creditor’s bank: it bears the loss
Return after settlement≤ 5 banking days≤ 3 banking days
PSP participationMandatory for every PSP that joins the SEPA schemesOptional scheme: not every institution offers it, on either the creditor or the debtor side
Mandate administration burdenMandate kept by the creditor onlyThe debtor must submit and register the mandate with its bank, and notify the bank of any revocation
SDD Core vs. SDD B2B: the differences that drive the decision, based on the scheme comparison in Annex V of the 2025 SDD Core rulebook v1.1 (EPC016-06)
⚠️
“B2B can’t be disputed”: a dangerous claim
The B2B scheme removes refunds for authorized transactions, and only those. Refunds for unauthorized transactions remain available for 13 months, exactly as in Core. The second difference is who bears the loss. The debtor’s bank, which must check the mandate before paying, bears the loss alone instead of passing it back to the creditor’s bank. Two practical consequences follow. Banks process B2B mandate registrations strictly, over several days and on forms specific to each bank. And a poorly registered B2B mandate then triggers a string of MD01 rejects, even though the creditor holds a signed mandate.

The choice between the two schemes comes down to the risk of returns versus the cost of obtaining the mandate. B2B is used when individual amounts are high, the contractual relationship is stable, and the debtor is equipped to handle mandate registration with its bank. Commercial rents, franchise fees, and recurring supply orders meet those conditions. For a €49-a-month software subscription sold online to microbusinesses, the balance flips. The friction of mandate registration, in both delay and signature rate, far outweighs the risk of returns. Core, combined with automated follow-up on reject codes, then costs less than a B2B mandate.

When it fails: ISO codes, deadlines, who pays

CodeISO descriptionWhat actually happenedWhat to do
AM04Insufficient fundsInsufficient funds on the due date, the number one reason for returnsRe-present on a chosen date (after payday), not immediately
AC01Incorrect account numberIBAN doesn’t exist or was mistypedCollect the IBAN from the customer again; never “correct” an IBAN yourself
AC04Closed accountAccount closedDead mandate: new bank details and a new mandate needed
AC06Blocked accountAccount blocked, or the debtor has blocked this creditorContact the debtor: a block amounts to a revocation
AC13Invalid debtor account typeB2B direct debit presented on a consumer accountSwitch the relationship to Core
AG01Transaction forbiddenDirect debits not allowed on this account type (savings account, term deposit)Ask for a checking account
AG02Invalid bank operation codeInconsistent sequence: RCUR after an OOFF, or mandate already finalizedFix SeqTp in the mandate database
AM05DuplicationDuplicate detected by the CSM or the debtor’s bankAudit batch idempotency: a replayed file is expensive
BE05Unrecognised initiating partyUnknown or inconsistent SCICheck the SCI with your bank before re-presenting
MD01No mandateNo valid mandate: never signed, revoked, lapsed, or not registered (B2B)Produce a copy of the mandate within 7 business days, or the loss is final
MD06Refund requested by end customerRefund claimed without a reason within 8 weeksCommercial follow-up: the interbank route is closed
MD07End customer deceasedDebtor deceasedClose the contract and pursue the claim with the estate
MS02Refusal by the debtorDebtor refused before the due date, after pre-notificationWarning sign: the pre-notification did its job
SL01Specific service offered by the debtor PSPFilter set by the debtor: creditor whitelist, cap, frequencyGet the SCI added to the customer’s allowlist
MS03Reason not specifiedMasked reason: some banks use it when national rules prohibit disclosing AC04, AM04, MD07, RR01…Don’t assume a “technical error”: an MS03 often hides insufficient funds
Most common ISO 20022 reason codes for SEPA direct debits

Credit transfers have a narrower set of R-transactions than direct debits, and each procedure depends on when the problem is detected. Before settlement, the originator’s bank or the CSM rejects the transaction (invalid IBAN or BIC, duplicate, file past the cut-off). After settlement, the payee’s bank can return the transaction within 3 banking days (closed account, deceased payee, transfers not allowed on that account type, payee refusal). Finally, the originator’s bank can initiate a Recall within 10 banking days, for three reasons only: duplicate, technical problem, or fraudulent transfer. The deadline extends to 13 months for fraud. Only one recall is allowed per transaction, and the payee’s bank has 15 business days to respond. For any other reason, such as the customer sending money to the wrong payee, the only option left is a Request for Recall by the Originator, which requires the payee’s consent. Technically, the request is sent with camt.056.001.08 and the response with camt.029.001.09.

ℹ️
What French fraud data says about both instruments (H1 2025)
Credit transfers still have the lowest fraud rate of any payment method, at 0.0014% by value in H1 2025 (versus 0.0010% in 2024). Total fraud nonetheless reached €230 million, up 44% year over year. Online banking accounts for 76% of it, with a fraud rate of 0.0059%. Social engineering scams (fake supplier, CEO fraud) now make up 61% of credit transfer fraud, up from 52% in 2024. Instant transfers stand at 0.0434%, below the card rate (0.048%) despite similar use cases. For direct debits, the rate doubled in six months (0.0021% versus 0.0014%), to €23.8 million. That fraud is 95% fake direct debit orders, issued by shell companies without a mandate, sometimes with the complicity of debtors who then invoke SDD Core’s unconditional right to a refund. Source: OSMP, H1 2025 statistical note, January 2026.

Deadlines to put on the calendar

September 20, 2026
VOP rulebook v1.1
Fixes inconsistencies found after the October 5, 2025, rollout; a version 2.0 is slated for publication in November 2026.
November 15, 2026 (postponed)
End of unstructured addresses: postponed
The 2025 v1.1 rulebooks set November 15, 2026, rather than the November 22 date announced in v1.0, as the end of free-format addresses, in line with the November 2026 Swift MX release. After Swift postponed that release on August 27, 2026, the EPC’s Payment Scheme Management Board (PSMB) dropped the deadline for all five schemes on September 9, 2026; a new date will be set in October 2026. Hybrid and structured formats remain the target.
January 9 → July 9, 2027
Rollout beyond the euro area
Banks outside the euro area must receive SCT Inst from January 9, 2027, and send them from July 9, 2027; payment institutions and e-money institutions from April 9, 2027.
End of 2027 (projected)
PSD3 package / Payment Services Regulation
Provisional political agreement between the European Parliament and the Council on November 27, 2025; final compromise texts published on April 23, 2026. Publication in the Official Journal of the EU had not happened as of September 2026, with Parliament's plenary vote provisionally scheduled for December 14, 2026. The regulation (PSR) will apply 21 months after entry into force, extended to 27 months for the payee name verification requirement, and PSD3 must be transposed within the same 21-month period. Check the texts as published in the Official Journal before making any architecture decisions.
🔑
Key takeaways
Credit transfers have become instant by default, free, and verified in the euro area, and both Wero and pay-by-bank run on that rail. Direct debits, by contrast, have not changed. They leave open 8 weeks of no-questions-asked reversibility in Core, 13 months if the mandate is missing, and 5 days (3 in B2B) for a return after settlement. A direct debit collection becomes certain revenue only once these windows have closed. A poorly referenced mandate, whether through an unstable UMR, an incorrect SCI, or a missed pre-notification, exposes the creditor to a claim it cannot document and turns a recoverable receivable into an outright loss. The mandate, the UMR, and the reject code are the three items operations teams need to track.

Elsewhere in the world. The same mechanism, elsewhere.

Maximum execution time for an instant credit transfer

Brazil

In Brazil, the Pix timing manual sets a 40-second limit between the payer’s bank receiving the order and settlement. Beyond that, SPI, the central bank’s instant payment system, rejects the transaction. On top of that come a service-level agreement on the payer experience (6.0 seconds at the 50th percentile, 10.0 seconds at the 99th) and a secondary channel capped at 45 minutes for scheduled Pix payments.

Banco Central do Brasil, Manual de Tempos do Pix, version 7.0, § 1.1, https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IX_ManualdeTemposdoPix.pdf

In the US, the Federal Reserve’s FedNow Service applies a 20-second payment timeout clock: if the payee’s bank has not responded before the clock runs out, the payment is rejected and both banks receive a failure message. Each receiving bank reserves 1 to 5 seconds of that clock for itself, depending on its capacity to process the message.

Federal Reserve, FedNow Service, “Understanding the payment timeout clock,” https://explore.fednow.org/resources/readiness-guide-understanding-the-payment-timeout-clock.pdf

India

In India, the Reserve Bank of India sets no deadline in seconds but puts a price on delays. When a UPI transfer is debited without the payee being credited, the automatic reversal must happen by D+1 at the latest. Otherwise, the bank owes the customer ₹100 in compensation per day of delay, paid without the customer having to claim it. The deadline extends to D+5 for a merchant payment left unconfirmed.

RBI, circular DPSS.CO.PD No.629/02.01.014/2019-20 of September 20, 2019, “Harmonisation of Turn Around Time (TAT) and customer compensation for failed transactions,” https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11693

Verifying the payee’s name before a credit transfer is authorized

In the UK, the Payment Systems Regulator mandated Confirmation of Payee in two waves: the six largest banking groups under Specific Direction 10, by March 31, 2020, then about 400 more institutions under Specific Direction 17, by October 31, 2024. The payer receives a match, close match, or no match before confirming, and can correct the instruction before the funds are sent.

Payment Systems Regulator, Confirmation of Payee, https://www.psr.org.uk/our-work/app-scams/confirmation-of-payee/

Brazil

In Brazil, the check has been built into the Pix flow from the start. Looking up a Pix key in the DICT directory must return to the payer, before confirmation, the payee’s full name, a masked CPF (individual taxpayer number) or the CNPJ (company registration number), and the unmasked key, but never the branch or account number. For a legal entity, the trade name must be displayed where one exists, and the registered company name otherwise.

Banco Central do Brasil, Requisitos mínimos para a experiência do usuário, version 7.3, December 2025, https://www.bcb.gov.br/content/estabilidadefinanceira/pix/Regulamento_Pix/IV_RequisitosMinimosparaExperienciadoUsuario.pdf

Australia

In Australia, payee verification comes not from legislation but from an industry-wide commitment, the Scam-Safe Accord. Banks put A$100 million into a national Confirmation of Payee platform, rolled out from July 2025, with a target of more than 95% of personal accounts covered by the end of 2025.

Australian Banking Association, Confirmation of Payee, https://www.ausbanking.org.au/scam-safe-accord/confirmation-of-payee/

What protects the debtor in a direct debit: mandate, pre-notification, and refund

In the US, there is no equivalent of the no-questions-asked refund. Regulation E limits the consumer’s liability to $50 if the unauthorized transaction is reported within two business days, and to $500 after that. Consumers must also report a transaction that appears on a statement within 60 days of the statement being sent, or bear the cost of subsequent debits.

12 CFR § 1005.6 (Regulation E), https://www.consumerfinance.gov/rules-policy/regulations/1005/6/

South Africa

In South Africa, protection sits before the debit rather than after it. Since May 1, 2021, every new or renegotiated early debit order mandate must be created in the DebiCheck system, where debtors approve the mandate electronically with their own bank before any collection takes place.

South African Reserve Bank, “The SARB modernises NPS with DebiCheck Project,” https://www.resbank.co.za/en/home/publications/publication-detail-pages/media-releases/2021/The-SARB-modernises-NPS-with-Debicheck-Project

India

In India, the notice owed to the debtor is counted in hours, not days. The Reserve Bank of India requires the issuer to send the cardholder a pre-transaction notification at least 24 hours before a recurring mandate is debited, stating the merchant name, amount, date and time of the debit, transaction reference, and reason for the debit.

RBI, circular DPSS.CO.PD.No.447/02.14.003/2019-20 of August 21, 2019, “Processing of e-mandate on cards for recurring transactions,” https://rbi.org.in/Scripts/NotificationUser.aspx?Id=11668