Recurring Card Payments: What Are CIT and MIT?
Recurring card payments let a business charge a customer's saved card on a schedule, for subscriptions, memberships, insurance premiums or instalments, without the customer being present for each charge. To make this safe and traceable, the card schemes divide transactions into two classes: customer-initiated transactions (CIT), where the cardholder actively takes part, and merchant-initiated transactions (MIT), where the merchant charges a stored card under a prior agreement.
Getting the CIT/MIT framework right matters. Correctly flagged transactions are approved more often, comply with Visa and Mastercard rules, and stand up better if a customer disputes a charge.
What Is a Customer-Initiated Transaction (CIT)?
A CIT is any transaction where the cardholder actively participates at the time of payment, for example:
- Paying at an online checkout
- Tapping a card at a terminal
- Paying through a payment link
- The initial sign-up payment for a subscription, even a R0 or small card-verification charge
Because the customer is present, a CIT can be authenticated with 3D Secure. The first payment in any recurring relationship must be a CIT, and it is where the customer's agreement to future charges is established.
What Is a Merchant-Initiated Transaction (MIT)?
An MIT is a transaction the merchant submits later using stored credentials, without the customer being present, based on the agreement made during the initial CIT. Common MIT types include:
- Recurring – fixed, scheduled charges such as a monthly subscription.
- Instalment – a fixed number of scheduled payments for a single purchase.
- Unscheduled card-on-file – charges triggered by an event rather than a schedule, such as an automatic top-up when a prepaid balance runs low.
- Operational MITs – amounts such as a no-show fee or delayed charge permitted under the original agreement.
MITs cannot be 3D Secure authenticated (nobody is there to approve a prompt), so the schemes require them to reference the original authenticated transaction, proving the chain of consent back to the initial CIT.
CIT vs MIT at a Glance
| Aspect | CIT | MIT |
|---|---|---|
| Cardholder present? | Yes | No |
| 3D Secure possible? | Yes, and usually applied | No; relies on the original CIT's authentication |
| Triggered by | The customer | The merchant, per prior agreement |
| Examples | Checkout payment, first subscription charge | Monthly billing, instalments, auto top-ups |
| Consent evidence | Established at the time of payment | Must reference the original agreement and transaction |
What Does a Valid Recurring Setup Look Like?
- Clear consent – during sign-up, the customer agrees to the amount (or how it is calculated), the frequency and the cancellation terms. Keep this evidence.
- Authenticated first payment – the initial CIT is processed with 3D Secure, and the card is tokenised for storage. See What Is 3D Secure? and Card Tokenisation and Network Tokens.
- Correctly flagged MITs – each subsequent charge is submitted as the correct MIT type, referencing the initial transaction.
- Easy cancellation – scheme rules and good practice require that cancelling is straightforward; hard-to-cancel subscriptions drive chargebacks.
Why Do Recurring Card Payments Fail, and What Helps?
Stored-card charges fail for the usual reasons, most commonly insufficient funds on debit cards and expired or reissued cards. Practical mitigations:
- Retry soft declines on a sensible schedule, for example aligned to common South African salary dates. See Dunning and Payment Recovery.
- Keep credentials fresh with network tokens and account updater services, so reissued cards keep working. See Backup Cards and Account Updaters.
- Collect a backup card where the business model justifies it.
- Notify customers before billing, especially after a price change, which reduces disputes and involuntary churn.
For a broader treatment of subscription billing strategy, see Recurring Card Payments in the Billing section.
Related Topics
Digital Wallets
How digital wallets like Apple Pay, Google Pay and Samsung Pay work, the role of device tokenisation, and what merchants need to accept them.
Refunds, Reversals and Voids
The difference between a refund, a reversal and a void on card payments, how long each takes to reflect, and what they cost the merchant.