Skip to content

DebiCheck: The Mandate Your Customer's Bank Holds a Copy Of

South Africa's authenticated debit system is genuinely different from ACH, SEPA and Bacs — and the clean pitch for it is wrong in three ways.

PB
By Shaun Toh
TL;DR

The payer's own bank keeps a copy of the mandate and refuses collections outside its terms — a different trust model from every other direct-debit scheme. But it is opt-in, the custody model is shared with an unauthenticated sibling, and the dispute edge was legislated away.

Operator Summary

DebiCheck is South Africa's authenticated debit-order system, built on ISO 20022 and running alongside the legacy EFT debit system rather than replacing it. Its distinguishing feature is structural: the payer's own bank holds an electronic copy of the mandate and will not allow a collection to be processed outside the agreed terms. ACH, SEPA Direct Debit and Bacs all work the other way — the debtor bank has no independent record of what was agreed, so control is exercised after the fact by reversal. Three qualifications matter. Service providers choose DebiCheck or EFT debit, so it is not universal. Bank-side mandate custody is shared with the non-authenticated Registered Mandate system, standalone since May 2025 — what DebiCheck adds is payer authorisation. And PASA has agreed to unify the dispute window at 60 days across all three systems.

Every direct-debit scheme has the same structural weakness. The creditor asserts that a mandate exists, the debtor's bank has no independent way to check, and control is exercised afterwards — by reversal, within some window, after the money has already moved.

South Africa built a system that works the other way round. It is worth understanding for its own sake, and it is worth understanding because the clean version of the story is wrong in three specific ways.

For the other four schemes — ACH, SEPA Direct Debit, Bacs and eGIRO — see the direct debit reference. This covers the one that is not like them.

The actual difference: the bank holds a copy

PASA's own Debit Order FAQ puts it plainly. The consumer's bank keeps an electronic copy of the mandate — and:

…will not allow a DebiCheck debit order to be processed outside the terms that have been agreed to by the consumer

That is the whole mechanic, and it is genuinely structural rather than presentational. The payer's bank knows the amount, the date, the frequency and the counterparty, because it holds the record. A collection that does not match fails at the payer's bank, before settlement, rather than succeeding and being clawed back.

Compare that with SEPA Direct Debit, where the mandate lives with the creditor and the debtor bank is executing an instruction it cannot independently validate. This next step is this article's inference rather than anything the schemes state: SEPA's eight-week no-questions refund right looks like a remedy for exactly that blindness. Remove the blindness and you need less of the remedy.

The precision most write-ups miss

Bank-side mandate custody is not what separates DebiCheck from the rest of South Africa's electronic debit orders. On PASA's own current comparison, the mandate is stored at the consumer's bank for both DebiCheck and Registered Mandate, and for both of them the consumer's bank validates the specific collection against the mandate parameters it holds on record. Only ordinary EFT debit leaves the mandate with the service provider, with no such check.

So the thing South Africa did differently from ACH, SEPA and Bacs is broader than DebiCheck: it moved mandate custody to the payer's bank across its whole electronic debit-order stack. What DebiCheck adds on top is that the payer actually authorised the mandate. Custody is the structural break with the other schemes; authorisation is the difference between DebiCheck and its own sibling.

That is a real design difference. Now the three qualifications.

Qualification one: it is opt-in, and it did not replace EFT debit

The most common misreading is that DebiCheck is now how South African debit orders work. It is not.

PASA's FAQ states that South Africa has two debit order systems — the legacy EFT debit system and the more modern ISO 20022-based system — and, directly:

Service providers choose whether to use DebiCheck or EFT Debit.

PASA's current debit-orders page counts differently, and the difference is the May 2025 separation rather than a disagreement: it says South Africa has three types of debit order — DebiCheck, Registered Mandate and EFT. Either way the operative point holds. The biller chooses.

What DebiCheck replaced was the early debit-order window: the older AEDO and NAEDO systems, discontinued on 1 November 2021 after a phased migration.

Ordinary EFT debit orders were never in scope and continue to run with no bank-side authentication at all — and they still carry far more value. In SARB's 2025/26 oversight report, EFT debit accounted for 5.3% of retail payment settlement values in the SAMOS system against 1.0% for authenticated collections. Whatever DebiCheck is, it is not where most South African debit-order value sits.

So a substantial share of South African recurring collection carries no authenticated mandate, and whether a given biller uses DebiCheck is a commercial decision about how much recovery certainty is worth, not a compliance obligation. PASA's own framing is that EFT suits known, willing and able customers because it is cheaper and more efficient, while DebiCheck suits relationships where recovery certainty matters more.

Qualification two: the unauthenticated fallback is now a payment system in its own right

DebiCheck was designed, in PASA's glossary wording, "to obtain authorisation of all collection mandates by payers before collections take place." It does not.

Running alongside it is the Registered Mandate service, for electronic mandates the payer never authorised. PASA's glossary is blunt about why it was introduced — to accommodate mandates "where consumers failed to respond to DebiCheck authorisation requests."

That was originally a temporary accommodation inside DebiCheck. It is not one any more. SARB's 2025/26 oversight report records that the separation of the Registered Mandate Service from AC/DebiCheck was implemented in May 2025, and that the two "now operate as independent, standalone payment systems under their own PCH." Registered Mandate has its own clearing house arrangement, and on PASA's current guidance it collects in the evening window, ahead of EFT debits, rather than behind DebiCheck in the morning window as it used to.

Be careful what you conclude from that, because this article originally got it wrong. It is tempting to read the fallback's existence as evidence that authentication frequently fails. The regulator's current position is close to the opposite: the same SARB report describes "consistently high authentication success rates on AC/DebiCheck" and mandate initiations that "remained robust."

There is a real tension in the record, and it is worth seeing rather than resolving. PASA's 2024 Integrated Report describes "persistent debit order mandate authorisation challenges in AC" and sets out minimum thresholds for the successful delivery of authorisation requests to payers, with sanctions under its compliance enforcement policy for failing them. A year and a half later the regulator reports the outcome as healthy. Both can be true — a delivery problem that was being actively enforced against, and a system that now performs well.

No authorisation-success percentage is quoted in this article. SARB presents mandate initiation success graphically rather than as a stated figure in the text, and the chart labelling in the published report does not extract cleanly enough to quote responsibly. If the rate is load-bearing for you, read Figure 9 of the current oversight report yourself — and get your own delivery and response rates from your sponsoring bank, which is the number that actually governs your funnel.

What an operator should take from this: a "DebiCheck" collection stack in practice usually means two separate payment systems, an authenticated path and an unauthenticated one with a different evidentiary position and a different collection window. Falling back to Registered Mandate should be a decision, not what happens by default when authentication does not land.

Qualification three: the dispute advantage narrowed in 2026

DebiCheck's commercial pitch has always leaned on disputes: an authenticated mandate is much harder for a payer to reverse than an ordinary EFT debit order.

That remains directionally true, and PASA's own materials are careful — they describe an exceptional-cases dispute path for authenticated collections, not immunity.

But the gap closed. PASA's 2024 Integrated Report records the decision:

The dispute period will be revised from one year to a 60-day window, to be consistent across all three debit order systems that will be in existence when this change is implemented.

The same report records the choice of a 60-day debit order dispute period instead of a 90-day period, and files the change under a heading giving its own timing: a new dispute regime "to be implemented late in 2025 or early in 2026."

A note on tense, because the source is not consistent with itself. The operational section of the Integrated Report is forward-looking — "will be revised", "when this change is implemented", implementation expected late 2025 or early 2026. A later section of the same document states flatly that "the dispute period has been revised from one year to 60 days." SARB's 2025/26 oversight report does not mention the dispute regime at all.

So the primary record supports the decision firmly and the effective date weakly. South African trade press puts it in April 2026. This article asserts the decision and not the date. Plan on the 60-day regime being the position you will operate under, and confirm the date it took effect with your sponsoring bank if a dispute window is load-bearing for you.

The practical consequence is that where authenticated collections previously enjoyed both a stronger evidentiary position and a different dispute clock, they now have only the first.

Mandate request types — get these from your bank, not from an article

DebiCheck distinguishes mandate request types by how the payer authenticates: a real-time request answered while it is live, a batched request with a longer response window, and a request authenticated by card and PIN at a point-of-sale device.

This article does not publish the type codes or their cut-off times, and the reason is worth stating. The detail lives in bank technical specifications rather than in scheme material, no bank specification could be cited at a resolving URL for this article, and the secondary sources that do circulate disagree with each other on at least one cut-off time — one widely repeated figure differs by two hours from what a bank specification is reported to say.

A two-hour error in a mandate cut-off is the kind of thing that fails a release. Take the request types and their timing from your sponsoring bank's current specification.

What an operator actually does differently

  • You onboard through a sponsoring bank. Participation rules and technical specifications come from it, not from the scheme directly.
  • The Contract Reference Number is persistent. It must be reused across the mandate's lifecycle, including disputes and stop-payments. Treating it as a per-transaction identifier breaks the mandate linkage.
  • Tracking runs for up to 10 days, and that number is under review. A failed collection can be retried as funds become available, on both DebiCheck and Registered Mandate — so "failed" on day one is not final, and your dunning logic should not treat it as such. PASA notes the tracking period is currently under consideration by the clearing house project group, so do not hard-code it.
  • Do not model authentication as free, or as a cliff. PASA was legislating against mandate-authorisation delivery problems in 2024; SARB reported authentication success as consistently high in 2025/26. Get your own sponsoring bank's delivery and response rates rather than assuming either.
  • Decide the Registered Mandate question deliberately. Falling back to an unauthenticated mandate now means using a separate payment system with a different collection window, not toggling a flag on DebiCheck.

What this is not

Two things this article deliberately does not cover, because they are owned elsewhere.

PayShap. It is a push rail — payer-initiated, or payee-requested and payer-approved. DebiCheck is a pull system. They are not two versions of the same thing and an operator is not usually choosing between them; the South Africa market guide covers PayShap's position.

The transfer of payment-system management functions from PASA to PayInc, which is a live 2026 structural change and is covered on the market page. It changes who administers these systems, not how the mandate mechanic works.

The honest summary

DebiCheck is the only major direct-debit scheme where the payer's bank holds its own copy of the mandate and enforces against it. That is a real, structural difference from ACH, SEPA and Bacs, and it is the reason the scheme is worth studying even if you never collect in South Africa.

But it is opt-in, it runs alongside an unauthenticated legacy system that never went away and still carries several times its share of retail settlement value, the mandate-custody property it is famous for is shared with its own non-authenticated sibling, and its dispute-window advantage has been legislated away. The design is genuinely better. The deployment is partial, and the marketing is ahead of both.

Sources & methodology (5)

The consumer's bank keeps an electronic copy of the debit order mandate and will not allow a DebiCheck debit order to be processed outside the terms that have been agreed to. South Africa has two debit order systems, the legacy EFT debit system and the more modern ISO 20022-based system, and service providers choose whether to use DebiCheck or EFT Debit.

Bank holds the mandate; system choice is the biller's

Verified: HTTP 200, application/pdf, 394,495 bytes, parsed with pdftotext. All three quoted phrases were read from the extracted text in this session, not taken from a summary. Note the PDF is largely image-based - only a minority of pages yield extractable text - so a reader checking this should expect to read it visually.

Checked:

PASA recorded a decision to implement a 60-day debit order dispute period instead of a 90-day period, and that the dispute period will be revised from one year to a 60-day window, to be consistent across all three debit order systems that will be in existence when this change is implemented.

60-day window across all three systems

Verified: HTTP 200, application/pdf, 5,243,050 bytes, parsed. IMPORTANT ON TENSE: the report states the dispute period WILL BE revised and refers to when this change is implemented - it is a forward-looking statement in a 2024 report, not confirmation the change is in force. South African trade press puts the effective date in April 2026. The article states it that way rather than asserting a date the primary source does not give.

Checked:

The AC/DebiCheck system went live in August 2018 and the existing authenticated early debit order and non-authenticated early debit order collection systems were discontinued on 1 November 2021.

AEDO/NAEDO discontinued 1 November 2021

Verified: HTTP 200, 107,294 bytes. The page carries the claim directly - it states that the AC/DebiCheck system went live in August 2018 and that the existing authenticated and non-authenticated early debit order collection systems were discontinued on 1 November 2021. Read from the retrieved page in this session.

Checked:

South Africa has three types of debit order - DebiCheck, Registered Mandate and EFT. The mandate is stored at the consumer's bank for both DebiCheck and Registered Mandate and at the service provider for EFT. The consumer's bank validates the specific collection against the mandate parameters it holds for DebiCheck and Registered Mandate but not for EFT. DebiCheck collects in the morning after the credit run; Registered Mandate collects in the evening as first priority and EFT debit in the evening as second priority.

Mandate custody and validation are shared by DebiCheck and Registered Mandate

Verified: HTTP 200, 211,662 bytes, page dateModified 2026-04-23. Read from the retrieved page in this session. This is the current-state source that supersedes the 2024 FAQ on collection windows: the earlier draft of this article stated that the Registered Mandate Service ran at lower priority in the same morning window as DebiCheck, which was the pre-May-2025 arrangement.

Checked:

The separation of the Registered Mandate Service, now known as Registered Mandate, from the AC/DebiCheck payment system was implemented in May 2025, and the two now operate as independent, standalone payment systems under their own PCH. Mandate initiations remained robust, supported by consistently high authentication success rates on AC/DebiCheck. Of retail payment settlement values in the SAMOS system, EFT debit accounted for 5.3% and Authenticated Collections for 1.0%.

Separation implemented May 2025; EFT debit 5.3% vs AC 1.0% of retail settlement values

Verified: HTTP 200, application/pdf, 37,206,834 bytes, parsed with pdftotext. All quoted phrases read from section 4.3 DebiCheck statistics and section 4.1 in this session. DELIBERATE OMISSIONS: (1) No authorisation-success percentage is quoted. The report presents mandate initiation success in Figure 9 as a chart whose axis label, scale and plotted values are mutually inconsistent when extracted, so no figure could be quoted responsibly - an earlier draft of this article carried a 62% figure that does not appear in this report and has been removed as unsupported. (2) The TT1/TT2/TT3 mandate request-type codes and their cut-off times are omitted: no bank specification resolved, and secondary sources disagree by two hours on at least one cut-off.

Checked:

Source types explained in our Methodology.

Shaun Toh By Shaun Toh · Director, Digital Payments · Razer

More Psp And Infrastructure briefings