How Do Customers Authenticate a DebiCheck Mandate?
Authentication is the step that makes DebiCheck different from every other debit order: the consumer approves the mandate with their own bank before the first collection. The bank then stores an electronic copy of the mandate and verifies every future collection against it.
The authentication request always comes from the consumer's bank, not from the service provider. It presents the debit order information — amount, frequency, collection day and the collecting party — and asks the consumer to approve or reject it.
Which channels can be used to authenticate?
The exact channels vary per bank, but across the major South African banks consumers can typically authenticate through:
- Banking app — approve a push notification or an item in the app's inbox
- USSD — respond to a USSD prompt on any cellphone, no smartphone needed
- Internet banking — approve the pending mandate online
- Cellphone banking — approve via the bank's mobile banking menu
- ATM — approve at the bank's ATM
- Card and PIN on a device — approve at a point-of-sale device (the TT3 route)
- In branch — approve with a consultant
Which channel applies depends partly on the transaction type (TT1, TT2 or TT3) used to initiate the mandate.
How long does the customer have to respond?
| Request type | Typical window |
|---|---|
| Immediate (real-time, TT1) | About 120 seconds |
| Delayed (TT2) | Until end of day or end of the next business day, depending on the bank |
| Card and PIN (TT3) | Approved on the spot at the device |
If the window passes without a response, the authentication request expires. An expired request is not a rejection — the service provider can usually initiate a new request, often falling back from TT1 to TT2.
Why does the cellphone number at the bank matter so much?
Authentication requests are typically sent to the cellphone number the bank has on record for the consumer — not the number the service provider captured at sign-up. If the bank has an old number, the request never reaches the consumer and the authentication expires.
Consumers should keep their contact details up to date with their bank. Businesses seeing high expiry rates should prompt payers to confirm that their bank has their current number — this is one of the most common issues covered in troubleshooting.
What happens after the customer responds?
- Approved: the bank stores the mandate in its mandate register and the mandate becomes authenticated. Collections that match it will be processed.
- Rejected: the consumer declined the request. No collections can be submitted. The service provider should contact the customer to resolve the reason before re-initiating.
- Expired: no response was received in time. The service provider can re-initiate, typically via TT2 or after contacting the customer.
These outcomes flow back to the service provider as statuses — see statuses and reason codes.
How can customers tell a genuine request from phishing?
A genuine DebiCheck authentication request:
- Comes through the bank's own channels — the banking app, the bank's USSD service, internet banking or an ATM.
- Displays the debit order details for the consumer to review.
- Never contains a link to click, and never asks for a PIN, password or one-time PIN over the phone, by SMS link or by email.
Banks never send links or ask for PINs or passwords to approve a DebiCheck mandate. Any such request is phishing and should be reported to the bank. See is DebiCheck safe? for more on security.
Related topics
TT1, TT2 and TT3
Compare DebiCheck TT1 real-time, TT2 delayed and TT3 card-and-PIN authentication, including timeouts, use cases and when each transaction type applies.
Mandate Lifecycle
Follow a DebiCheck mandate from initiation and authentication through amendments, suspensions and cancellation, with the statuses used at each stage.