Its rules, by facet
18 Rules, each in its record's own words with its own status. A rule reached only through the authorisation says so; a rule that also applies to another transaction type names it.
Finality 1
The paying institution cannot cancel or recall a payment once the message is in its own gateway Corroborated (authoritative primary)
The point of no return on this rail is early and it is inside the sending institution. Once the clearing request has been input into the payer participant's own gateway, that participant may neither cancel it nor recall it. Nothing later moves that point, and there is no message in the scheme for taking a payment back.
Rests on rule. Confidence medium. Also applies to Basic Single Credit Transfer (BSCT), Overlay Service Payment (OS Payment). au-npp:rule.finality-no-cancel-or-recall-once-the-message-is-in-the-gateway
Messages 2
A rejected mandate payment initiation request must also carry a valid and applicable reason code Corroborated (authoritative primary)
The same shape on the PayTo leg. A payer participant must respond to each mandate payment initiation request inside the timeframes the procedures prescribe with a status report indicating receipt and either acceptance or rejection, and where it rejects it must provide a valid and applicable reason code. Where it accepts and funds are available it then sends a clearing request for the amount claimed. Again no value is listed.
Rests on rule. Confidence medium. au-npp:rule.messages-a-rejected-mandate-payment-request-carries-a-reason-code
The platform has used ISO 20022 natively since launch Corroborated (authoritative primary)
Every message on this rail is an ISO 20022 message and always has been. A clearing request that starts a payment is a pacs.008, the clearing notification that answers it and the settlement notification the settlement service sends are both pacs.002, the settlement request is a pacs.009, a return is a pacs.004 and a request for one is a camt.056. On the customer to institution leg a payment instruction is a pain.001, a creditor payment initiation request under PayTo is a pain.013, and the status report back to a corporate customer is a pain.002.
Rests on rule. Confidence medium. Also applies to Basic Single Credit Transfer (BSCT). au-npp:rule.messages-iso-20022-from-launch
No facet on the record 15
A PayTo mandate is a record in a database the scheme operator runs, not a document a party keeps Corroborated (authoritative primary)
The Mandate Management Service is a centralised, secure, access controlled database of mandates that the scheme operator established and runs. A mandate is a record in it of a payment authorisation the payer gave in favour of a business or a payment initiator, identified by a unique mandate identifier the database itself generates, which gives the holder the right to send requests instructing the payer's own institution to make payments within the mandate's terms. The database may also hold, at the payer institution's option, records of another kind of arrangement defined only in the procedures.
Rests on rule. Confidence medium. au-npp:rule.mandate-a-mandate-is-a-record-in-the-scheme-operators-database
A mandate may be moved to another institution without the authorisation changing Corroborated (authoritative primary)
A mandate can change custodian. The payer's institution must facilitate porting a mandate where necessary at the payer's request, and a mandate established for a payment initiator may be moved to another participant or connected institution on the initiator's instruction. An institution's right to read a mandate record is expressly subject to the other parties' right to port it away. All the porting provisions took effect on 5 May 2023.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-a-mandate-may-be-ported-to-another-participant
A claim about a migrated mandate is deemed substantiated unless the sponsor produces the evidence Corroborated (authoritative primary)
This is where the missing consent shows up. Where a mandate claim relates to a migrated mandate, the claim is deemed to be substantiated unless the sponsoring participant produces written evidence both of the payer's authorisation of the direct debit request the mandate was based on and that the payment in question was authorised by the mandate's terms. The burden runs against the side that created the record without asking.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-a-migrated-mandate-claim-is-deemed-substantiated
A migrated direct debit mandate is created unilaterally and is active the moment it exists Corroborated (authoritative primary)
The one mandate in the corpus nobody consented to. A participant that is a framework participant in the direct debit system may create mandate records for direct debit arrangements it already processes for the businesses it sponsors. Those records are designated migrated mandates, they are established unilaterally by the business and its sponsor, and they are deemed active in the operator's database immediately on creation. The business is deemed approved as a user of the service by the same act. The obligations to deliver an authorisation request to the payer and to facilitate porting are expressly switched off for them.
Rests on rule. Confidence medium. au-npp:rule.mandate-a-migrated-mandate-is-created-without-a-consent-step
No payment request may be sent unless the mandate is active Corroborated (authoritative primary)
A participant or connected institution acting as the initiating participant must not send a mandate payment initiation request unless the associated mandate is active, and is responsible for each request it sends being properly built and consistent with the mandate's terms. Sending one against a suspended or cancelled mandate is one of the things the rulebook lists as not authorised, which is what turns the resulting payment into a claim. The payer's institution may look the mandate up before processing but is not obliged to.
Rests on rule. Confidence medium. au-npp:rule.mandate-a-request-may-not-be-sent-unless-the-mandate-is-active
A change to the amount or the frequency has to come from the business as a fresh agreement Corroborated (public primary)
A payer can pause, resume and cancel, and can make the amendments the mandate's terms permit, but cannot simply raise or lower what they agreed to. The operator's parent says that for a change of amount or frequency the business has to make the change and send the payer an updated agreement to authorise. That keeps every change to the substance of the authorisation on the same footing as the original one.
Rests on guidance. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-an-amount-or-frequency-change-comes-from-the-business
A claim about an ordinary mandate is tested against the record, or against evidence the initiator must produce Corroborated (authoritative primary)
For an ordinary PayTo mandate the rulebook splits the claim in two. Where the payer's institution says the payment was not permitted by the mandate in amount, frequency or beneficiary, the claim is deemed substantiated by reference to the record in the operator's database itself, which is what makes that record the evidence. Where it says the payer did not authorise that particular payment at the time the request was sent, the claim is deemed substantiated unless the initiating side produces evidence that they did, and if the two of them disagree about the reliability of that evidence they may use the rulebook's own dispute resolution process.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-an-authorised-mandate-claim-is-deemed-substantiated-by-the-record
The payer's institution must deliver the authorisation request to the payer in near real time Corroborated (authoritative primary)
Creating a mandate record is not the same as authorising it. The payer's institution must be able to receive authorisation requests from the operator's database, must associate each one with a payer by the account number in the record, must deliver it to that customer in near real time for authorisation to the standards the procedures set, must take any consents privacy law needs, and must record the confirmation in the database promptly after the customer authorises or rejects it. The mandate is active only once that confirmation is recorded.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-authorisation-is-delivered-in-near-real-time
A mandate record is confidential to its parties and may be looked up only by them Corroborated (authoritative primary)
Lookup rights are restricted to the parties to the mandate, and information in a mandate record must be treated as confidential to them and not disclosed to anybody else except as law requires. A lookup may be performed only for validating and processing requests and payments, resolving investigations and claims, fraud investigation and analytics, or giving effect to the parties' own instructions. Institutions must have systems to prevent unauthorised disclosure, to spot it promptly when it happens, and must tell the operator in writing when it does.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-data-is-confidential-to-the-parties
A migrated mandate may not be used for a payment request until 5 days after it was created Corroborated (authoritative primary)
The second safeguard is delay. A migrated mandate may be used to issue a mandate payment initiation request no earlier than five days after the time and date it was created. To let the payer's institution check the arrangement against its own customer's account status and transaction history, the record must carry the business's direct debit user identifier.
Rests on rule. Confidence medium. au-npp:rule.mandate-five-days-before-a-migrated-mandate-may-be-used
A migrated mandate needs written notice to the payer first, at least 14 days ahead Corroborated (authoritative primary)
The consent step is replaced by a notice step. Before the record is created, the business must have told each of its payers in writing that future debits will generally go through the platform rather than the direct debit system where their account can take them, and must have given whatever notice its direct debit service agreement requires or at least fourteen days. It must hold and be able to produce evidence of the original direct debit authorisation and of the notice. Direct debit processing of the same arrangement must stop from the migration date, except in a genuine outage. The operator's parent tells customers they may opt out during the notice period and stay on direct debit.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-fourteen-days-notice-before-a-migrated-mandate-is-created
Offering PayTo is optional for a creditor's bank and compulsory for the payer's bank Corroborated (authoritative primary)
The service is asymmetric by design. Taking part is optional for a participant acting as a provider of the service to businesses, optional for a connected institution, and optional for an overlay service provider, but it is mandatory for every participant and sponsored institution in its capacity as a payer participant and account servicer. A payer's institution must also provide the service for every account type that is enabled and eligible to make payments on the platform.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-participation-is-mandatory-for-a-payer-participant
The payer's institution must give the payer a way to view, suspend, cancel and amend their mandates Corroborated (authoritative primary)
A payer participant must provide a facility that lets payers see the mandates they are a party to and give instructions to suspend or cancel them or make permitted amendments to them, and must promptly give effect to those instructions. Whoever performs any mandate maintenance function is responsible for making sure the particular mandate's terms allow it. The operator's parent describes the same thing to customers as pausing, resuming or cancelling in online banking, and says that doing so does not change the customer's contract with the business.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-the-payer-customer-can-view-suspend-cancel-and-amend
Until the payer says something, their institution must keep processing a migrated mandate Corroborated (authoritative primary)
The payer's institution could optionally satisfy itself that a migrated mandate really matches its customer's existing direct debit and may ask the customer to confirm it, and must keep a record if the customer does. If the customer says authorisation was never given, or tells it to suspend or cancel, it must act promptly. But pending confirmation or any other instruction from the customer, it must continue to process payment requests against the mandate. Treating one of these as unauthorised by default would misstate the rule as badly as treating it as authorised.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-the-payer-participant-keeps-processing-pending-word
The mandate record is the evidence of the amount, the frequency and the beneficiary Corroborated (authoritative primary)
The rulebook says out loud what most rails leave implicit: the mandate record is evidence of the quantum, the frequency and, where it is recorded, the beneficiary of the payments the payer authorised. That single sentence is why a claim that a payment fell outside the amount, frequency or beneficiary of an ordinary PayTo mandate is deemed substantiated simply by reference to the record.
Rests on rule. Confidence medium. Reached through the authorisation, not linked to the transaction type directly. au-npp:rule.mandate-the-record-is-evidence-of-quantum-frequency-and-beneficiary