FAQ Section
DebiCheck

How Do Customers Authenticate a DebiCheck Mandate?

 

How payers approve DebiCheck mandates via banking apps, USSD, ATMs and card-and-PIN devices, and what happens when authentication is rejected or expires.

Authentication is the step that makes DebiCheck different from every other debit order: the consumer approves the mandate with their own bank before the first collection. The bank then stores an electronic copy of the mandate and verifies every future collection against it.

The authentication request always comes from the consumer's bank, not from the service provider. It presents the debit order information — amount, frequency, collection day and the collecting party — and asks the consumer to approve or reject it.

Which channels can be used to authenticate?

The exact channels vary per bank, but across the major South African banks consumers can typically authenticate through:

  • Banking app — approve a push notification or an item in the app's inbox
  • USSD — respond to a USSD prompt on any cellphone, no smartphone needed
  • Internet banking — approve the pending mandate online
  • Cellphone banking — approve via the bank's mobile banking menu
  • ATM — approve at the bank's ATM
  • Card and PIN on a device — approve at a point-of-sale device (the TT3 route)
  • In branch — approve with a consultant

Which channel applies depends partly on the transaction type (TT1, TT2 or TT3) used to initiate the mandate.

How long does the customer have to respond?

Request typeTypical window
Immediate (real-time, TT1)About 120 seconds
Delayed (TT2)Until end of day or end of the next business day, depending on the bank
Card and PIN (TT3)Approved on the spot at the device

If the window passes without a response, the authentication request expires. An expired request is not a rejection — the service provider can usually initiate a new request, often falling back from TT1 to TT2.

Why does the cellphone number at the bank matter so much?

Authentication requests are typically sent to the cellphone number the bank has on record for the consumer — not the number the service provider captured at sign-up. If the bank has an old number, the request never reaches the consumer and the authentication expires.

Consumers should keep their contact details up to date with their bank. Businesses seeing high expiry rates should prompt payers to confirm that their bank has their current number — this is one of the most common issues covered in troubleshooting.

What happens after the customer responds?

  • Approved: the bank stores the mandate in its mandate register and the mandate becomes authenticated. Collections that match it will be processed.
  • Rejected: the consumer declined the request. No collections can be submitted. The service provider should contact the customer to resolve the reason before re-initiating.
  • Expired: no response was received in time. The service provider can re-initiate, typically via TT2 or after contacting the customer.

These outcomes flow back to the service provider as statuses — see statuses and reason codes.

How can customers tell a genuine request from phishing?

A genuine DebiCheck authentication request:

  • Comes through the bank's own channels — the banking app, the bank's USSD service, internet banking or an ATM.
  • Displays the debit order details for the consumer to review.
  • Never contains a link to click, and never asks for a PIN, password or one-time PIN over the phone, by SMS link or by email.

Banks never send links or ask for PINs or passwords to approve a DebiCheck mandate. Any such request is phishing and should be reported to the bank. See is DebiCheck safe? for more on security.

Copyright © 2026 Kwik Payments