General Notes on the Incassomachtigen R&R
Version: 1.92
Publication date: 1 feb. 2022
1 Introduction
Incassomachtigen B.V. is the eMandate and brand owner of the Scheme eMandates (Incassomachtigen; electronic issuing of valid direct debit mandates).
1.1 eMandates Scheme
In the R&R you wil find terms ware defined are all written with an initial capital. The meanings of these terms which are used have been laid down in definitions. The definitions are listed in alphabetical order in the section General Regulations – part 2 – Definitions.
A Scheme is a system of agreements, consisting of governance agreements, role descriptions, rules and legal conditions, referred to as Rules & Regulations (hereafter: R&R), including a set of technical requirements, grouped in the Technical Standards. This document provides a general explanation of the Scheme and the on these eMandates based R&R. The R&R clarify the rules and agreements governing all relevant activities relating to the eMandates Scheme.
The explanation covers the following topics:
the background to the development of the eMandates R&R; see section 2;
a more detailed description of the various Roles relating to the eMandates Scheme; see section 3;
a description of the R&R, including an explanation of the Acceptance Regulations, the Certification Procedure, the Licence and Certification Structure and an explanation of the R&R documents, including the Technical Standards; see section 4.
2 Background to the eMandates Rules & Regulations
Incassomachtigen B.V. is the eMandate owner and trademark holder eMandates . In that capacity, it defines and manages the requirements regarding the various Roles that feature in the eMandates Scheme, with Incassomachtigen B.V. taking into account the wishes from the market.
The Scheme have been developed to facilitate issuing eMandates from/by a User to a Merchant via the online or mobile banking environment (hereafter: Online Channel) of the Issuer.
The R&R, including the Technical Standards, is owned by Incassomachtigen B.V.. In that capacity, it defines and manages the requirements regarding the various Roles that feature in the Scheme and the underlying eMandates. These requirements are necessary for the eMandates to operate effectively for all parties concerned. The requirements are objective, non-discriminatory, and not more stringent than strictly necessary. A set of rules, the R&R, has been drawn up in order to set out the requirements in practical terms. Incassomachtigen B.V. consults its Licencees and Certificate Holders when drawing up or amending the rules.
The R&R contain the established rules and also a description of the Roles and activities that parties involved in the eMandates can carry out. In that context, Incassomachtigen B.V. issues Licence and Certificate Agreements.
Incassomachtigen B.V. helps safeguard the efficiency, quality (including reliability and image) and the integrity of its eMandates. Incassomachtigen B.V. carries out the following tasks:
determining the strategy and policy of the Scheme;
developing and, if necessary, revising the Scheme and the underlying eMandates;
drawing up, laying down, and managing the R&R;
certifying Licencees and Certificate Holders;
accreditation of Accredited Parties;
monitoring Licencees and Certificate Holders (with the power to impose sanctions) and Accredited Parties;
coordinating anti-fraud measures;
facilitating collective consultation structures;
public relations, public affairs, communications, brand promotion.
3 Description of eMandates Scheme
eMandates is an online alternative to the paper mandate for the SEPA Direct Debit (SDD). This facilitates the online confirmation of agreements on the payment methods for services and eMandates for which the User must make single or recurrent payments or payment in arrears. This includes insurance policies, gas and electricity, memberships, charities, instalments and subscriptions.
eMandates enables Merchants to use the Online Channel of the Issuers to receive legally valid electronic payment mandates (eMandates) for standard (Core) or business (B2B) SEPA Direct Debit payments from Users in an efficient manner, in accordance with the SDD Core Rulebook and the SDD B2B Rulebook, without a signature on paper being required. The User is routed from the Merchants environment to its Online Channel of its Issuer, where he or she authenticates himself or herself, using the standard Authentication Tools, and subsequently authorises the mandate in the Online Channel. Afther the authorisation, the User is routed back to the Merchants online environment.
There are two types of eMandate:
An eMandate for the standard SEPA Direct Debit. This can be issued by Users and businesses (SEPA Direct Debit (SDD) Core).
The eMandate for the business SEPA Direct Debit. This is for direct debits between businesses (SDD B2B).
By eMandates is meant the issuing, amending and cancelling of a digital Mandate.
Because, on the basis of the SEPA Regulation, Users must also have access to a White List or Black List for direct debits, these are also automatically updated during the issuing process. For business-to-business direct debits, the registration of the mandate details is automatically updated for business Users. If applicable, and to the extent offered by the Issuer, multiple authorization is also offered specifically for business Users.
Finally, the eMandates system of agreements supports the issuing, amendment and cancellation process, although cancellation of the eMandate for standard SEPA Direct Debits (Core) is not processed via the Issuer of the User.
Besides this option of issuing (and amending or cancelling) a mandate online, it remains possible to issue, amend or cancel a mandate on paper. This is also possible for previously issued eMandates or vice versa. The various processes concerning paper mandates and eMandates are described in the Implementation Guidelines of the eMandates Standard and in the SDD Rulebooks.
Through eMandates, the Acquirers, which facilitate eMandates for Merchants, provide Merchants with the option of collecting mandates online using an application that is fast, safe and simple. eMandates enables Users who use a suitable Online Channel to issue a digital mandate so that the Merchant can execute a direct debit on the Users bank account. By means of eMandates, the Issuer, which provide a suitable Online Channel, can offer their Users a fast, safe and simple alternative to paper mandates.
3.3.1 eMandates brand
eMandates are identified by means of the eMandates logo, which is protected by trademark law:
eMandates is a registered logo, which is owned by Incassomachtigen B.V. The eMandates brand is used, among other things, as a feature for the marketing and use of the electronic payment mandate it stands for. The eMandates brand may only be used in connection with the activities related to it, in accordance with a Licence or Certificate Agreement with Incassomachtigen B.V. to that end.
4 Organisation of eMandates Scheme
4.1 Message model
The message model developed by Incassomachtigen B.V. is based on a so-called four-party model. Acquirers and Issuers with a Licence offer eMandates to the market on a commercial basis. This produces benefits for all parties. The model forms the basis for the contents of the iDX Standard, part of the R&R. This is represented in Figure 1. The figure is used to demonstrate the process flow for the eMandate message in section 4.1.1.
Message model
4.1.1 Process flow for the eMandates message
The User wishes issue a mandate to a Merchant. Therefor the User selects the button for the eMandate on the Merchant's website and subsequently selects the Issuer with whom the User has access to the Online Channel provided with the correct authorisations and AuthenticationTools;
The Merchant sends the request with the data it has requested to the Routing Service Provider (RSP) concerned, in accordance with the message protocol described in the MIG for the eMandate concerned;
The RSP sends the data for the eMandate concerned to the Validation Service Provider (VSP).
The User is then automatically redirected to the Online Channel of his Issuer where the User must authenticate himself;
The User then checks the message data in his Online Channel. If he agrees to the payment, mandate and/or provision of the data displayed on the screen4 , the User must authorise the message. The User is then automatically redirected back to the Merchant’s web portal. Parameters sent along with the message enable the Merchant to recognise the context (see 2) and therefore the User;
The VSP sends the status of the eMandate message and the data to the Acquirer/RSP. The RSP sends the data of a successful eMandate message to the Merchant;
The Merchant requests the status of the transaction from the Acquirer/RSP;
The Merchant confirms the receipt and displays the content of the message to the User on its own website.
4.2 Contract model
Contract model
The contract model developed by Incassomachtigen B.V. forms the basis of the contents of the R&R. This is represented in Figure 2.
The various Roles in the Scheme are explained on the basis of this contract model in sections 4.2.1 to 4.2.8.
4.2.1 Incassomachtigen B.V. (Betaalvereniging Nederland)
Incassomachtigen B.V. is the Product and brand owner of eMandates, as described in the R&R, including the Technical Standards, in which capacity it lays down requirements in relation to the Product and the parties involved in the contract model.
4.2.2 Issuer
The Issuer is the party that has signed a Licence Agreement with Incassomachtigen B.V.. A Licence Agreement is concluded for the Scheme. An Issuer must also have a licence as a Payment Service Provider, or an exemption for this. The Issuer is responsible for the entire Issuing Domain with regard to the activities for the Product, to the extent that they relate to the Product it has issued/will issue for an appropriate Online Channel. The Issuer is the Institution with which the User has access to the Online Channel by making use of the correct authorisations. The Issuer has an existing or new agreement (e.g. as part of the agreement and/or general terms and conditions for online and mobile banking or payment services; to be filled in by the Issuer) with the User on the basis of which the messages can be authorised. The Issuer facilitates the issuing of the data from its Users by means of messages to the Acquirer. The Acquirer facilitates the issue to the Merchant via the RSP or VSP.
An Issuer may only offer Users the Product if it has obtained a Licence from Incassomachtigen B.V..
4.2.3 VSP; Certificate Holder
The VSP is the party that has signed a Certificate Agreement with Incassomachtigen B.V.. A Licence Agreement is concluded for the Scheme. The VSP has an agreement with, and operates on behalf and under the responsibility of, one or more Issuers. The VSP is responsible for processing message traffic concerning the issuing of messages by the Issuers. The VSP must be able to connect to all RSPs in the Scheme.
A VSP may only participate in the Product if the VSP has been certified by Incassomachtigen B.V. and has concluded a VSP contract with at least one Issuer that is in possession of a Licence Agreement with Incassomachtigen B.V..
When Issuers carry out the Role of VSP themselves, this Role is certified together with the Role of the Issuer. The Institution receives a Licence for the Role of Issuer and a Certificate for the Role of VSP.
4.2.4 User
The User is the individual with access to the Online Channel of his Issuer provided with the correct authorisations and Authentication Tools. The User can authorise the eMandate message through the Online Channel of the Issuer concerned. The User has an agreement (e.g. as part of the agreement and/or general terms and conditions for the Online Channel; to be filled in by the Issuer) with the Issuer concerning the use of the eMandates. A User of eMandates can be either a natural person6 or a business entity.
A User is not subject to any requirements on the part of Incassomachtigen B.V.. Any obligations will be imposed on the User by the Issuer.
4.2.5 Acquirer
The Acquirer is the party that has concluded a Licensing Agreement with Incassomachtigen B.V.. A Licence Agreement is concluded for the Scheme. An Acquirer must also have a licence as a Payment Service Provider, or an exemption for this. Furthermore the Acquirer concludes eMandate contracts with Merchants for the eMandate concerned. The Acquirer is responsible for the entire Acquiring Domain with regard to the activities for the eMandates, to the extent that they concern its Merchants and Certificate Holders. The Acquirer is responsible for the correct processing of the issuing of the messages for its Merchants, which have been sent by a User who purchases a a service or product from a Merchant. The Acquirer concludes a contract with an RSP to that end.
An Acquirer may only offer Merchants and Certificate Holders the Product if it has obtained a Licence from Incassomachtigen B.V..
4.2.6RSP; Certificate Holder
The RSP is the party that has signed a Certificate Agreement with Incassomachtigen B.V. (a Licence Agreement is concluded for each Scheme) and that has an agreement with or is part of the Acquirer. The RSP offers its service for the routing of a eMandate message, initiated by a User by means of the Online Channel of his Issuer via the website of the Merchant. The RSP is responsible for ensuring that the eMandate messages are received, verified, processed and forwarded correctly. The RSP makes agreements with an Acquirer concerning the processing of eMandate messages for the Merchants and Users. The RSP has an agreement with, and operates on behalf and under the responsibility of, one or more Acquirers. The RSP must be able to connect to all VSPs in the Scheme.
An RSP may only participate in the Scheme if the RSP has been certified by Incassomachtigen B.V. and has concluded an RSP contract with at least one Acquirer that is in possession of a Licence Agreement with Incassomachtigen B.V..
When Acquires carry out the Role of RSP themselves, this Role is certified together with the Role of the Acquirer. The Institution receives a Licence for the Role of Acquirer and a Certificate for the Role of RSP.
4.2.9 eMandates Service Provider (MSP; Accredited Party)
The MSP can provide the technical aspects of the connection to the eMandates service on behalf of the Creditor and ensures the correct flow of the eMandates messages. The MSP may also facilitate in the conclusion of the eMandate contract between the Creditor and the Creditor Institution. The MSP can only facilitate eMandates contracts for Creditors who have a valid SDD contract with a Creditor Institution.
An MSP may only participate in the eMandates service if the MSP has been accredited by Incassomachtigen B.V..
4.2.10 Merchant
The Merchant is the party that has concluded a contract with an Acquirer in order to use eMandates. The Merchant offers goods or services to Users in accordance with the eMandate conditions prescribed by the Acquirer, which, as a minimum, also include the provisions as described in the R&R annex 'Minimum Acceptance Criteria for Merchants'. If the Merchant purchases this service, the Merchant must provide its Users with the opportunity to authorise a eMandate transaction via the Online Channel of their Issuer.
Incassomachtigen B.V. has no direct relationship with a Merchant. The Acquirer is responsible for onboarding a Merchant, in accordance with the requirements as stated in the R&R annex 'Minimum Acceptance Criteria for Merchants' and 'Guidelines and Use of eMandate Logos'.
4.3 Earnings model
The earnings model is based on the mutual contractual relationships between the parties involved in the Scheme, see Figure 3. Acquirers and Issuers (with a Licence Agreement),VSPs and RSPs (Certificate Holders) and MSPs (Accredited Parties) offer the eMandates to the market commercially. They can charge their User or Merchant a fee for this, the interpretation of which is at the Institutions' discretion. The Institutions must draw up a mutual agreement on a Fee, if applicable. Incassomachtigen B.V. charges its Licencees and Certificate Holders a fee.
Earnings model
5 eMandates Rules & Regulations, including Technical Standards
5.1 eMandates R&R
Incassomachtigen B.V. has adopted a uniform set of rules, the Rules & Regulations (R&R), which are to be adhered to by every Licencee, Certificate Holder and Accredited Party for the eMandate Scheme. Among other things, the R&R include rules covering all relevant activities relating to the Scheme. Incassomachtigen B.V. has compiled the R&R with great care, taking the relevant laws and regulations as the starting point.
The requirements in respect of the various Roles, as described in section 4.2, can be divided into those of a general organisational nature and those that relate to the process associated with the Role fulfilled by the party within the Scheme. The process comprises the various relevant activities that together make up the complete Role. The process-related requirements can be divided into quality requirements and, where necessary, additional detailed requirements of a more operational nature. All requirements are recognisable as such in the documents and, where applicable, are accompanied by explanatory notes.
With regard to the activities for which rules have been made in the R&R, a distinction is made between the Issuing Domain and the Acquiring Domain. The Issuing Domain comprises all activities relating to the authentication of the User by the Issuer and the authorisation of the message by the User. Based on the User’s authorisation, the Issuer provides the requested data as indicated in the message to the Acquirer. The Acquirer facilitates the issue to the Merchant via the RSP. The Acquiring Domain comprises all activities relating to the receipt and processing of the message by the Acquirer (through the RSP) on behalf of a Merchant.
For both the Issuing and Acquiring Domain, the Licencees must comply with the relevant laws and regulations that apply to them, and with the rules and guidelines prescribed by the regulators in the country where the organisation is based.
5.1.1 Licence and Certificate structure
Institutions wishing to join the Scheme must conclude a Licence, Certificate or Accreditation Agreement with Incassomachtigen B.V.:
Institutions wishing to fulfil the Role of Issuer or Acquirer are eligible for a Licence Agreement. Licencees are responsible for all activities in their domain.
Institutions wishing to fulfil the Role of VSP and RSP, are eligible for a Certificate Agreement. Certificate Holders are responsible for the activities associated with their Role. Institutions wishing to fulfil the Role of Certificate Holder are eligible for a Certificate Agreement.
Institutions wishing to fulfil the Role MSP are eligible for an Accreditation Agreement. Accredited Parties are responsible for the activities associated with their Role. Institutions wishing to fulfil the Role as an Accredited Party qualify for an Accreditation Agreement.
5.1.2 Acceptance and Acceptance Regulations
An Institution shall be eligible for a Licence or Certificate Agreement if it has demonstrated that it meets the Acceptance Requirements associated with the Role that the Institution wishes to fulfil in the Scheme. The Acceptance Regulations form the basis for this. The acceptance procedure listed here describes the steps the Applicant must take in order to be certified for the Role in question. To start the acceptance procedure, the Institution must send a signed Application Form to Incassomachtigen B.V. for approval. Incassomachtigen B.V. will then send a set of documents to the Institution, including the R&R. The certification procedure will then start.
An Accredited Party does not have to go through a certification procedure.
5.1.3 Certification and certification procedure
The certification procedure mainly involves carrying out a Control Self Assessment (CSA). A CSA is used by the Applicant to demonstrate that it meets the requirements associated with the Role that the Applicant wishes to fulfil in the Scheme.
The certification procedure covers the activities that the Applicant must perform in order to be able to fulfil a Role as described in the R&R. The certification procedure comprises the following stages:
Carrying out a Control Self Assessment (CSA) by the Applicant/Institution;
Evaluation of the CSA by Incassomachtigen B.V.;
Selective verification by Incassomachtigen B.V. to establish the accuracy of the CSA (and therefore of the implementation of the R&R by the Applicant);
Successful conclusion of the test set by means of the Test Tool (TT);
The Applicant must carry out eMandate verification tests with all Licencees and Certificate Holders already certified;
A new Issuer must have its issuer screens assessed by Incassomachtigen B.V.;
Final evaluation and decision by Incassomachtigen B.V. concerning the granting of a Licence and/or Certificate Agreement;
Monitoring of compliance with agreements to rectify any outstanding issues (of minor importance) revealed by the certification process.
NB If an Institution does not fulfil all functions of its Role, the Institution must declare the provisions regarding the functions concerned ‘Not Applicable’ during certification for the Role in question.
5.1.4 Technical Standard
Incassomachtigen B.V. provides a Technical Standard in the R&R eMandates, these are the iDx Protocol and the Implementation Standard. The Technical Standard describes the message traffic of a eMandate message. The Merchant Implementation Guide (MIG) is available for the technical implementation of the Merchant or MSP.
5.2 R&R documentation
Incassomachtigen B.V. is in no way liable for errors or omissions or the consequences of later amendments to the documentation. The R&R consist of the following documents:
General Notes (this document)
This gives an outline description of the Scheme, with the Roles and eMandates associated with them.Agreements
Licence Agreement: The agreement concluded by a Licencee with Incassomachtigen B.V. after successfully completing the Certification Procedure for the Scheme in which it wishes to take part. The Fees annex also applies here;
Certificate Agreement: The agreement concluded by a Certificate Holder with Incassomachtigen B.V. after successfully completing the Certification Procedure for the Scheme in which it wishes to take part. The Fees annex also applies here;
Accreditation Agreement: The agreement concluded by an Accredited Party with Incassomachtigen B.V. after successfully completing the accreditation procedure for eMandates.
General Regulations
GR - part 1 - General Provisions: description and applicability of the General Regulations;
GR - part 2 - Definitions: definition of terms in the R&R that start with a capital letter;
GR - part 3 - Council of Licencees: duties and powers of the members of the Council of Licencees;
GR - part 4 - Scheme Communication: description of how parties may communicate in relation to the Scheme;
GR - part 5 - Change Procedure: description of how Incassomachtigen B.V. implements changes to the R&R;
GR - part 6 - Penalty Regulations: description of when Incassomachtigen B.V. may impose a penalty on a Licencee or Certificate Holder. The Tables annex also applies here;
GR - part 7 - Bilateral fees: description of how and when a Bilateral Fee is applicable.Acceptance Regulations and Certification Procedure
Acceptance Regulations: description of the procedure established by Incassomachtigen B.V. that is used to assess whether an Applicant may be accepted to the Scheme concerned in order to be able to fulfil the Role it has applied for;
Certification Procedure: description of the procedure established by Incassomachtigen B.V. that is used to assess whether an Applicant meets the conditions set out in the R&R on the basis of a /wiki/spaces/SPEEL/pages/59277442 (CSA) it has itself carried out.R&R Provisions
/wiki/spaces/SPEEL/pages/65929472: set of provisions that a Licencee who is certified for this Role is obliged to comply with.
/wiki/spaces/SPEEL/pages/67633182: set of provisions that a Certificate Holder who is certified for this Role is obliged to comply with;
/wiki/spaces/SPEEL/pages/67567687: set of provisions that a Licencee who is certified for this Role is obliged to comply with;
/wiki/spaces/SPEEL/pages/67600565: set of provisions that a Certificate Holder who is certified for this Role is obliged to comply with;
Mandate Service Provider (MSP):set of provisions that an Accredited Party for this Role is obliged to comply with;
R&R Annexes
Management of IT infrastructure
Operational Agreements
Escalation Procedure
Minimum acceptance criteria for Merchants
Reporting Obligations for Roles and eMandate
Monitoring and follow-up (suspected) Misuse of a eMandate
Part 1 - Branding Manual
Part 2 - Guidelines use eMandates-logo
Technical Standards
The Technical Standards consist of the following components:
iDx Documentation Suite
iDx 001 Cover document: an overview of the various documents that form the Technical Standard;
iDx_010 Protocol: setting down the technical aspects of the Technical Standards with regard to messages for the relevant eMandate front-end implementation, to which the parties involved in the Scheme must adhere based on their Roles of Issuer and Acquirer;
iDx_025 Messages between Acquirer and Issuer: an overview of the iDx messages exchanged between the Validation Service Provider and the Routing Service Provider;
iDx_035 Messages between Merchant and Acquirer: an overview of the iDx messages exchanged between Merchants and Routing Service Providers;
Implementation Guidelines
A document that describes guidelines concerning the implementation and content of the messages for Issuers and Acquirers.
Software libraries
A piece of programming language/software to simplify the technical implementations of Merchants
Merchant Implementation Guide (MIG):
A derivative of the Technical Standard. The MIG gives an overview of the guidelines and recommendations that are relevant for the implementation of the Product concerned by Merchants. A Licencee can incorporate relevant Technical Standard matters as information in its own publication of the MIG. The MIG is issued by the Acquirer to the Merchant or MSP.
5.2.1 Availability of the Technical Standards
The following is applicable:
For access to the Technical Standards, interested parties first need to complete and sign the ‘Technical Standard application form’ and pay a fee.
The Technical Standard will only be made available via an intranet website specifically set up for this purpose. This is accessed using a username and password. The applicant is responsible for ensuring that unauthorised persons do not gain access to the intranet website.