The bank that must prove the mandate is never the bank that holds it
Die Bank, die das Mandat beweisen muss, hat es nie in der Hand
In the second half of 2025, banks in the euro area debited 11.7 billion direct debits worth €5.6 trillion. That is the European Central Bank’s count, published on 22 July 2026. In the same release the ECB reports that 13% of those collections rested on an electronic mandate and 87% on “consent given in other forms”. None of those mandates, electronic or otherwise, is held by the bank that performs the debit. And under Article 72 of the second Payment Services Directive, that bank — the payer’s — is the party that must prove the payment was authenticated if the customer says it was not. To do so it has to ask the party that collected the money to send it the evidence.
What the payer’s bank is holding
A direct debit is a payment in which the person losing the money does nothing at the moment the money leaves. The payee assembles a collection file, its bank passes the file to a clearing and settlement mechanism, and the payer’s bank debits the account on the due date. The payer’s participation happened earlier, once, when the mandate was signed.
Where that mandate then lives is not a matter of practice. It is written into the law. Article 5(3)(a)(ii) of Regulation (EU) No 260/2012 — the SEPA Regulation — requires the payee’s bank to ensure that “the mandates, together with later modifications or cancellation, are stored by the payee or by a third party on behalf of the payee”. The document that records the payer’s consent is kept by the party that benefits from it. The payer’s own bank receives, with each collection, a set of mandate-related data elements: a mandate reference, a signature date, a creditor identifier. It does not receive the mandate.
The scheme rulebook then says out loud what follows from that. The European Payments Council’s SEPA Direct Debit Core Scheme Rulebook, 2025 version 1.1, issued 5 October 2025, states in process step PT-04.10: “The Scheme does not impose any obligations on the Debtor PSPs to verify or otherwise check Collections received in respect of a Debtor’s account, such as checking for the existence of Mandates for the Creditor who presents the instructions.” The rulebook adds that banks may agree such obligations with their customers outside the scheme — which is another way of saying that inside the scheme, nobody does.
So the position at the moment of debit is this. There is no authentication of the payer, because the payer is not present. There is no verification against the mandate, because the scheme does not require one and the mandate is not there to verify against. The payer’s bank debits the account on the strength of a reference number supplied by the collecting party.
The one rule that would force a check, and why it never applies
European law did anticipate this. The SEPA Regulation contains a provision that would put a mandate check into the payer’s bank — and it is switched off by the very protection that makes the instrument tolerable.
Article 5(6) of Regulation 260/2012 reads: “Where the framework agreement between the payer and the payer’s PSP does not provide for the right to a refund, the payer’s PSP shall … verify each direct debit transaction to check whether the amount of the submitted direct debit transaction is equal to the amount and periodicity agreed in the mandate before debiting the payer’s payment account, based on the mandate-related information.” Article 5(3)(d)(ii) grants the payer a matching right to demand that check, again “where a mandate under a payment scheme does not provide for the right to a refund”.
Both are conditioned on the absence of a refund right. The SEPA Core scheme always provides one: the rulebook states that debtors may request a refund for any SEPA direct debit within eight weeks of the debit “on a no-questions-asked basis”, and Article 76 of PSD2 gives the payer, for direct debits within the scope of Regulation 260/2012, “an unconditional right to a refund”. The condition in Article 5(6) is therefore never met for a Core collection. The only provision in European law that would have required the payer’s bank to compare a collection against the mandate cannot apply to the scheme that carries almost all of Europe’s direct debits. This is a deduction from the texts rather than a finding anyone has published, and I set it out that way so it can be checked.
The controls the payer does have, and no count of who is offered them
Article 5(3)(d) does give the payer two rights that are not conditioned on anything: to instruct its bank to limit a collection to a certain amount or periodicity or both, and “to block any direct debits to the payer’s payment account or to block any direct debits initiated by one or more specified payees or to authorise direct debits only initiated by one or more specified payees”. Ceilings, blacklists and whitelists. Where neither payer nor payee is a consumer, banks need not offer them at all.
These address the actual failure mode — a collection from a party the customer has never heard of — and they have existed since the Regulation applied. What is missing is any published measurement of how many banks offer them in a form a customer can find, or how many customers use them. I could find no supervisory count for the euro area, which means the most direct preventive control in the instrument is one whose deployment nobody reports.
Two clocks, doing two different jobs
The direct debit carries two reversal periods, and they are not two versions of the same thing.
The first is the eight-week refund. Article 77 of PSD2 gives the payer eight weeks from the debit date to ask, and gives the bank ten business days either to refund in full or to justify a refusal and name the bodies the payer can complain to. Under the Core rulebook, refusal is not on the table: process step PT-04.15 says the payer “must instruct the Debtor PSP to refund the Collection, without being required to disclose the reason”, and the bank “must credit the Debtor’s account”. The rulebook is equally clear about what the refund does not do — it “does not relieve the Debtor of its responsibility to seek a resolution with the Creditor”. The money comes back; the argument stays where it was. That is the same confusion of a payment remedy with a contractual one that runs through the European rules on a cancellation button that ends the contract but not the charge.
The second clock is thirteen months. The rulebook: “If the request for a Refund concerns an Unauthorised Transaction … a Debtor must present its claim to the Debtor PSP within 13 months of the debit date in accordance with Article 71 of the Payment Services Directive.” This is the period that covers the case where no valid mandate ever existed. It is also the only period in which the question “was this authorised?” is actually asked, because inside eight weeks nobody is allowed to ask it.
The settlement mechanics follow. Returns settle at the latest five inter-bank business days after the collection did; a refund for an unauthorised transaction settles up to thirty calendar days plus four business days after the deadlines run out. The gap between five days and a month is the space in which evidence has to be gathered.
Where the evidence comes from
Article 72 of PSD2 is unambiguous about who carries the burden. Where a user “denies having authorised an executed payment transaction”, it is for the payment service provider to prove that the transaction was “authenticated, accurately recorded, entered in the accounts and not affected by a technical breakdown or some other deficiency of the service”. It adds that a record of the use of a payment instrument “is not in itself sufficient to prove that the transaction was authorised”, and that the provider “must provide supporting evidence”. Germany’s transposition, § 675w of the Civil Code, ends on the same requirement.
Now put that beside the process the scheme provides. Rulebook process PR-06, “Obtain a copy of a Mandate”, has four steps. The payer’s bank asks the payee’s bank. The payee’s bank forwards the request to the payee. The payee sends the copy to its bank. The bank sends it on. In the unauthorised-refund flow, PT-04.21 to PT-04.23, the sequence is the same: the payer’s bank requests the mandate copy, the request reaches the payee, and “the Creditor investigates the request for Refund and provides a response”.
The party accused of collecting without a mandate is the party asked to produce the mandate, through two intermediaries, on a document set it has held alone since the day it was signed. The rulebook requires the payee to keep the mandate at least as long as the unauthorised-refund window, which is the right retention rule; it does not and cannot change who holds it.
The joint report of the European Banking Authority and the ECB on payment fraud, published in December 2025, notices the asymmetry from another angle: direct debits differ from every other instrument in its liability tables because “the ‘PSP’ is the service provider of the payee instead of the service provider of the payer”. A footnote in the same report is franker still — the two authorities record that since the reporting guidelines were drafted in 2018, “legal discussions have evolved such that a transaction that is authenticated cannot automatically be assumed to also have been authorised”. In a direct debit there is not even an authentication to over-read. The gap between performing a check and bearing the consequences of it is the one that runs through a name-matching warning that is displayed and then changes nothing about who pays.
The refund erases the measurement
If the eight-week refund is the compensation for an unverified debit, the obvious question is how often it is used and how much of it is fraud. Neither number exists in a form anyone publishes.
The reason is written into the reporting rules. The EBA’s Guidelines on fraud reporting under PSD2, quoted verbatim in the December 2025 EBA-ECB report, state at paragraph 20 that for direct debits “refunds under eight weeks should not be automatically reported, as they do not always indicate fraud cases; such transactions should be reported only if they were subject to fraud and the reporting PSP was aware that this was the case, without implying any legal obligation to ask the payment service user whether this was the case.”
Read that last clause slowly. The bank need not ask. The rule is defensible — most eight-week refunds are billing disputes, not crime, and requiring an interrogation before every no-questions-asked refund would destroy the thing that makes it work. But its consequence is exact: fraud that is refunded inside eight weeks and not volunteered as fraud leaves no trace in the statistics. The two authorities say so themselves, listing the unconditional refund right and the absence of any duty to investigate among the reasons why “a large number of EEA countries reported no data at all on fraud losses for direct debits”.
What is reported behaves oddly, and the report offers no explanation for it. Fraudulent direct debits in the EEA rose from €36 million in 2023 to €112 million in 2024 — a tripling — while the number of fraudulent direct debits fell by around 38%, to 73,935. The average fraudulent direct debit in 2024 was €1,516, against an average direct debit of €504. Working those figures backwards gives an implied 2023 average near €300 — a fivefold jump in a single year; that arithmetic is mine, not the authorities’, and rests on their rounded percentages. Direct debits nonetheless remain the instrument with the lowest reported fraud rate of the five the report covers: 0.001% by value, 0.0004% by volume.
A rate that low, computed on a base from which the most likely fraud cases have been silently removed, is not a measurement of safety. It is a measurement of what the refund rule allows to be counted. The country breakdown makes the point again: Belgium reported all direct debit fraud losses as borne by banks; the Czech Republic, Ireland and Luxembourg reported all of them as borne by users; Portugal and Slovakia attributed all of them to “other” entities. Those are not three views of one reality. They are three national reporting habits sitting in one table.
The case for the design, at its strongest
The argument for leaving the mandate with the payee is strong and is worth putting properly before disagreeing with any of it.
Start with the volume. According to the European Payments Council’s compilation of ECB data, updated 31 July 2026, 23,150.20 million SEPA direct debits were sent in 2025. Germany alone accounted for 9,990.41 million of them — 43% of the SEPA total by my calculation — ahead of France with 5,051.66 million and the Netherlands with 2,319.44 million. Requiring every payer’s bank to hold and check a mandate would mean building, at thousands of institutions, a document store covering every creditor in Europe that might ever debit one of its customers, and matching against it 23 billion times a year, on collections whose average value is €504.
Against that, reversal is astonishingly cheap. The customer says “give it back”, the money is back, and no evidence is produced by anybody. There is no reason code, no representment, no evidence deadline, no arbitration fee — none of the machinery that turns every rung of a card dispute into a calculation about whether the claim is worth its cost, which is what we found in what each step of an escalation ladder charges the person taking it. Measured as protection per euro of infrastructure, the European direct debit is probably the most efficient remedy in retail payments, and far stronger than what account-to-account payments offer, where there is no chargeback at all.
The banking industry makes a related argument about scope. The German Banking Industry Committee, which represents around 1,700 institutions and is registered in the EU transparency register as an interest representative, told trilogue negotiators on 28 August 2025 that the unconditional refund right “should not apply to merchant-initiated transactions (MIT), as these already ensure a very high level of consumer protection”, because “consumers and merchants both profit from the existing, strict mechanisms of scheme rules”. That is a self-interested submission and should be read as one — but its underlying claim, that scheme dispute rules can substitute for a legal refund right, is the same claim the direct debit relies on in the opposite direction.
The European Commission, meanwhile, has been extending the model rather than repairing it. Its 2023 proposal for a Payment Services Regulation states that “the rules for merchant initiated transactions (MITs) and direct debits are aligned, applying the same consumer protection measures, such as refunds, to direct debits and MITs as both are transactions initiated by the payee”. Recital 85 of the same proposal concedes that legacy non-euro direct debit schemes “ensure the same high level of protection to the payer by other safeguards, not always based on an unconditional right to a refund” — the Commission’s own acknowledgement that reversal is one design choice among several.
The file is nearly done: according to the European Parliament’s legislative train schedule, as of 22 May 2026, Parliament and Council reached provisional political agreement on 27 November 2025, ECON approved the agreed text on 5 May 2026, and the status is “close to adoption”. I have not read the final consolidated text and make no claim about what it says on mandates.
What this does not tell you
Three limits, and they matter.
First, I cannot tell you how often the mandate question actually arises. No central bank or supervisor publishes a series for direct debit returns and refunds; the ECB publishes volumes and values, not R-transaction rates. Without that denominator, “the payer’s bank cannot produce the evidence” is a statement about architecture, not about how many customers are harmed by it.
Second, the fraud figures above are a floor whose distance from the true number is unknown and, given paragraph 20 of the reporting guidelines, unknowable from published data. Anyone quoting a direct debit fraud rate of 0.001% — this article included — is quoting a rate computed on a base with a hole of undetermined size in it.
Third, the liability split by country comes from few reporting states, and for direct debits the report’s “PSP” and “PSU” labels mean the payee’s bank and the payee. Those columns cannot be compared with the card columns beside them, and I have not tried to.
Degrees of confidence
Firmly held: the mandate is stored by the payee under Article 5(3)(a)(ii) of Regulation 260/2012; the scheme imposes no mandate check on the payer’s bank under PT-04.10 of the 2025 Core rulebook; and the evidential burden in a dispute falls on the payer’s bank under Article 72 of PSD2. Those three sentences are quotations, and together they are the finding.
With reasonable confidence: Article 5(6) never bites for SEPA Core collections, because its trigger is the absence of a refund right and the scheme always grants one. I have found no authority saying so, and would welcome being shown one.
Cautiously: the tripling of reported direct debit fraud value alongside a 38% fall in volume is more likely to reflect a change in what a small number of institutions chose to flag than a change in criminal behaviour. The report itself notes that the low case count — around 74,000 across the EEA — makes the series sensitive to outliers.
What the case teaches about payments generally
Every payment system protects its users in one of two ways. It can verify before the money moves, which requires that the party performing the check hold the evidence. Or it can reverse after the money has moved, which requires only that somebody be able to fund the reversal. Verification is expensive and produces a record. Reversal is cheap and produces none.
Europe chose reversal for direct debits, and the choice was rational: 23 billion collections a year cannot each be matched against a document, and an eight-week no-questions-asked refund is a better deal for a consumer than almost any verification regime would have delivered. But the second-order effect is the one worth carrying to other instruments. A reversal-based system is structurally incapable of measuring the problem it is solving, because the reversal happens instead of the investigation, not after it. The refund is not merely silent about fraud; it is the reason the fraud is silent.
That trade-off is being written into more of the payments landscape rather than less: into merchant-initiated card transactions, into instant credit transfers where reversal is a matter of goodwill, into account-to-account rails sold on the promise of no chargebacks. Each time, the question to ask is not “is the consumer protected?” but “after the protection has operated, does anyone still know what happened?” For the European direct debit the answer, on the two authorities’ own account, is that a large number of member states do not — and that the rule which made them not know was written deliberately, for good reasons, by people who did not intend a blind spot.
Im zweiten Halbjahr 2025 haben Banken im Euroraum 11,7 Milliarden Lastschriften über 5,6 Billionen Euro eingezogen. So zählt es die Europäische Zentralbank in ihrer Veröffentlichung vom 22. Juli 2026. In derselben Mitteilung steht, dass 13 Prozent dieser Einzüge auf einem elektronischen Mandat beruhten und 87 Prozent auf einer „in anderer Form erteilten Zustimmung”. Keines dieser Mandate, ob elektronisch oder nicht, liegt bei der Bank, die die Belastung ausführt. Und nach Artikel 72 der zweiten Zahlungsdiensterichtlinie ist genau diese Bank — die des Zahlers — diejenige, die im Streitfall den Nachweis führen muss. Um ihn zu führen, muss sie denjenigen um die Unterlagen bitten, der das Geld eingezogen hat.
Was die Bank des Zahlers in der Hand hat
Eine Lastschrift ist ein Zahlungsvorgang, bei dem derjenige, der das Geld verliert, in dem Moment nichts tut, in dem es abfließt. Der Zahlungsempfänger stellt eine Einzugsdatei zusammen, seine Bank reicht sie an ein Clearing- und Abwicklungssystem weiter, die Bank des Zahlers belastet das Konto am Fälligkeitstag. Der Zahler hat einmal mitgewirkt, früher, bei der Unterschrift unter das Mandat.
Wo dieses Mandat anschließend liegt, ist keine Frage der Übung, sondern des Gesetzes. Artikel 5 Absatz 3 Buchstabe a Ziffer ii der Verordnung (EU) Nr. 260/2012 — der SEPA-Verordnung — verlangt von der Bank des Zahlungsempfängers sicherzustellen, dass „die Mandate zusammen mit späteren Änderungen oder deren Widerruf vom Zahlungsempfänger oder von einem Dritten für den Zahlungsempfänger aufbewahrt werden”. Das Schriftstück, das die Zustimmung des Zahlers festhält, verwahrt derjenige, dem sie zugutekommt. Die Bank des Zahlers erhält mit jedem Einzug nur mandatsbezogene Datenfelder: eine Mandatsreferenz, ein Unterschriftsdatum, eine Gläubiger-Identifikationsnummer. Das Mandat erhält sie nicht.
Das Regelwerk des Verfahrens spricht die Folge offen aus. Das SEPA Direct Debit Core Scheme Rulebook des European Payments Council, Fassung 2025 Version 1.1, ausgegeben am 5. Oktober 2025, hält im Verfahrensschritt PT-04.10 fest: „The Scheme does not impose any obligations on the Debtor PSPs to verify or otherwise check Collections received in respect of a Debtor’s account, such as checking for the existence of Mandates for the Creditor who presents the instructions.” Das Verfahren verpflichtet die Bank des Zahlers also zu keinerlei Prüfung, ob für den einziehenden Gläubiger überhaupt ein Mandat besteht. Solche Pflichten dürften Banken mit ihren Kunden außerhalb des Verfahrens vereinbaren — was auf Deutsch heißt: innerhalb des Verfahrens tut es niemand.
Die Lage im Augenblick der Belastung ist damit diese. Es gibt keine Authentifizierung des Zahlers, weil der Zahler nicht anwesend ist. Es gibt keinen Abgleich mit dem Mandat, weil das Verfahren keinen verlangt und das Mandat gar nicht da ist. Die Bank belastet das Konto auf die Kraft einer Referenznummer hin, die der Einziehende mitgeliefert hat.
Die eine Regel, die einen Abgleich erzwingen würde — und warum sie nie greift
Der europäische Gesetzgeber hat das durchaus bedacht. Die SEPA-Verordnung enthält eine Vorschrift, die den Mandatsabgleich in die Bank des Zahlers verlegt. Ausgeschaltet wird sie ausgerechnet von jenem Schutz, der das Verfahren erträglich macht.
Artikel 5 Absatz 6 der Verordnung 260/2012 lautet: Sieht der Rahmenvertrag zwischen dem Zahler und seinem Zahlungsdienstleister kein Erstattungsrecht vor, so hat dieser Zahlungsdienstleister jede Lastschrift daraufhin zu prüfen, ob Betrag und Periodizität des vorgelegten Einzugs mit dem im Mandat Vereinbarten übereinstimmen, und zwar vor der Belastung des Kontos, auf Grundlage der mandatsbezogenen Angaben. Artikel 5 Absatz 3 Buchstabe d Ziffer ii gibt dem Zahler das dazu passende Recht, diese Prüfung zu verlangen — wiederum nur dort, „wo ein Mandat im Rahmen eines Zahlverfahrens kein Erstattungsrecht vorsieht”.
Beide Vorschriften hängen am Fehlen eines Erstattungsrechts. Das SEPA-Basislastschriftverfahren gewährt eines immer: Das Regelwerk hält fest, dass der Zahler binnen acht Wochen nach der Belastung die Erstattung jeder SEPA-Lastschrift verlangen kann, „on a no-questions-asked basis” — ohne Angabe von Gründen. Und Artikel 76 der Zahlungsdiensterichtlinie gibt dem Zahler für Lastschriften im Anwendungsbereich der Verordnung 260/2012 „ein bedingungsloses Recht auf Erstattung”. Die Bedingung des Artikels 5 Absatz 6 ist für einen Basislastschrifteinzug also nie erfüllt. Die einzige Vorschrift des europäischen Rechts, die die Bank des Zahlers zum Abgleich mit dem Mandat verpflichtet hätte, kann auf das Verfahren, das nahezu alle Lastschriften Europas trägt, nicht angewandt werden. Das ist ein Schluss aus den Texten, keine Feststellung, die jemand veröffentlicht hätte; ich schreibe es so hin, damit es nachprüfbar bleibt.
Die Werkzeuge, die der Zahler hat — und keine Zahl darüber, wer sie bekommt
Artikel 5 Absatz 3 Buchstabe d gibt dem Zahler zwei Rechte, die an keine Bedingung geknüpft sind: seiner Bank aufzutragen, einen Einzug auf einen bestimmten Betrag oder eine bestimmte Periodizität oder beides zu begrenzen, und „jegliche Lastschriften auf seinem Zahlungskonto zu sperren oder Lastschriften eines oder mehrerer bestimmter Zahlungsempfänger zu sperren oder nur Lastschriften eines oder mehrerer bestimmter Zahlungsempfänger zuzulassen”. Obergrenzen, Sperrlisten, Positivlisten. Sind weder Zahler noch Zahlungsempfänger Verbraucher, müssen Banken das alles gar nicht anbieten.
Diese Rechte treffen den tatsächlichen Schadensfall — einen Einzug von jemandem, von dem der Kunde nie gehört hat — und es gibt sie, seit die Verordnung anwendbar ist. Was fehlt, ist jede veröffentlichte Messung, wie viele Banken sie in einer Form anbieten, die ein Kunde findet, und wie viele Kunden sie nutzen. Eine aufsichtliche Erhebung dazu habe ich für den Euroraum nicht gefunden. Die unmittelbarste vorbeugende Kontrolle des Verfahrens ist damit eine, über deren Verbreitung niemand berichtet.
Zwei Fristen, zwei verschiedene Aufgaben
Die Lastschrift trägt zwei Rückgabefristen, und sie sind nicht zwei Spielarten derselben Sache.
Die erste sind acht Wochen. Artikel 77 der Zahlungsdiensterichtlinie gibt dem Zahler acht Wochen ab dem Belastungstag, um die Erstattung zu verlangen, und der Bank zehn Geschäftstage, um entweder den vollen Betrag zu erstatten oder die Ablehnung zu begründen und die Stellen zu benennen, an die sich der Zahler wenden kann. Im Basislastschriftverfahren steht die Ablehnung nicht zur Wahl: Verfahrensschritt PT-04.15 hält fest, der Zahler weise seine Bank an, den Einzug zu erstatten, „without being required to disclose the reason”, und die Bank „must credit the Debtor’s account”. Ebenso deutlich sagt das Regelwerk, was die Erstattung nicht bewirkt — sie „does not relieve the Debtor of its responsibility to seek a resolution with the Creditor”. Das Geld kommt zurück; der Streit bleibt, wo er war. Es ist dieselbe Verwechslung eines zahlungsrechtlichen mit einem vertraglichen Rechtsbehelf, die durch die europäischen Regeln über einen Kündigungsknopf zieht, der den Vertrag beendet, aber nicht die Abbuchung.
Die zweite Frist sind dreizehn Monate. Im Regelwerk: „If the request for a Refund concerns an Unauthorised Transaction … a Debtor must present its claim to the Debtor PSP within 13 months of the debit date in accordance with Article 71 of the Payment Services Directive.” Das ist die Frist für den Fall, dass nie ein gültiges Mandat bestand. Es ist zugleich die einzige Frist, in der die Frage „war das autorisiert?” überhaupt gestellt wird — denn innerhalb der acht Wochen darf sie niemand stellen.
Die Abwicklung folgt dem. Rückgaben werden spätestens fünf Interbanken-Geschäftstage nach dem Einzug verrechnet; die Erstattung einer nicht autorisierten Zahlung erst bis zu dreißig Kalendertage plus vier Geschäftstage nach Ablauf der Fristen. Zwischen fünf Tagen und einem Monat liegt der Raum, in dem Beweise beschafft werden müssen.
Woher der Beweis kommt
Artikel 72 der Zahlungsdiensterichtlinie ist eindeutig darin, wer die Last trägt. Bestreitet ein Nutzer, „einen ausgeführten Zahlungsvorgang autorisiert zu haben”, so hat der Zahlungsdienstleister nachzuweisen, dass der Vorgang „authentifiziert, ordnungsgemäß aufgezeichnet, verbucht und nicht durch eine Störung beeinträchtigt” wurde. Die Aufzeichnung der Nutzung eines Zahlungsinstruments genügt dafür ausdrücklich „nicht für sich allein”; der Dienstleister muss unterstützende Beweismittel vorlegen. Die deutsche Umsetzung in § 675w BGB endet auf derselben Anforderung: Der Zahlungsdienstleister muss unterstützende Beweismittel vorlegen, um Betrug, Vorsatz oder grobe Fahrlässigkeit des Nutzers nachzuweisen.
Und nun daneben der Weg, den das Verfahren dafür vorsieht. Der Prozess PR-06 des Regelwerks, „Obtain a copy of a Mandate”, hat vier Schritte. Die Bank des Zahlers fragt bei der Bank des Zahlungsempfängers an. Diese leitet die Anfrage an den Zahlungsempfänger weiter. Der Zahlungsempfänger schickt die Kopie an seine Bank. Die Bank schickt sie weiter. Im Ablauf der Erstattung einer nicht autorisierten Zahlung, PT-04.21 bis PT-04.23, ist es dieselbe Kette: Die Bank des Zahlers fordert die Mandatskopie an, die Anfrage erreicht den Gläubiger, und „the Creditor investigates the request for Refund and provides a response”.
Wer beschuldigt wird, ohne Mandat eingezogen zu haben, ist derjenige, der um die Vorlage des Mandats gebeten wird — über zwei Zwischenstationen, aus einem Bestand, den er seit dem Tag der Unterschrift allein verwahrt. Das Regelwerk verpflichtet den Gläubiger, das Mandat mindestens so lange aufzubewahren, wie die Erstattungsfrist für nicht autorisierte Zahlungen läuft. Das ist die richtige Aufbewahrungsregel. Wer das Papier hält, ändert sie nicht und kann sie nicht ändern.
Der gemeinsame Bericht der Europäischen Bankenaufsichtsbehörde und der EZB zum Zahlungsbetrug vom Dezember 2025 bemerkt die Schieflage von einer anderen Seite: Lastschriften unterscheiden sich in seinen Haftungstabellen von jedem anderen Instrument, weil dort „the ‘PSP’ is the service provider of the payee instead of the service provider of the payer” — der Dienstleister des Empfängers steht, wo sonst der des Zahlers steht. Eine Fußnote desselben Berichts ist noch offener: Beide Behörden halten fest, dass sich seit der Erarbeitung der Meldeleitlinien im Jahr 2018 die rechtliche Diskussion so entwickelt habe, dass eine authentifizierte Zahlung nicht automatisch als autorisiert gelten könne. Bei einer Lastschrift gibt es nicht einmal eine Authentifizierung, die man überinterpretieren könnte. Der Abstand zwischen dem Durchführen einer Prüfung und dem Tragen ihrer Folgen ist derselbe, der durch eine Namensabgleich-Warnung läuft, die angezeigt wird und an der Haftung nichts ändert.
Die Erstattung löscht die Messung
Wenn die Acht-Wochen-Erstattung der Ausgleich für eine ungeprüfte Belastung ist, dann lautet die nächste Frage: Wie oft wird sie in Anspruch genommen, und wie viel davon ist Betrug? Keine der beiden Zahlen wird irgendwo veröffentlicht.
Der Grund steht in den Melderegeln. Die Leitlinien der Bankenaufsichtsbehörde zur Betrugsmeldung nach der Zahlungsdiensterichtlinie, im Bericht vom Dezember 2025 wörtlich zitiert, sagen in Randnummer 20 zu Lastschriften: „refunds under eight weeks should not be automatically reported, as they do not always indicate fraud cases; such transactions should be reported only if they were subject to fraud and the reporting PSP was aware that this was the case, without implying any legal obligation to ask the payment service user whether this was the case.”
Der letzte Halbsatz ist der entscheidende: Die Bank muss nicht nachfragen. Die Regel ist vertretbar — die meisten Erstattungen innerhalb von acht Wochen sind Abrechnungsstreitigkeiten und keine Straftaten, und ein Verhör vor jeder Erstattung ohne Angabe von Gründen würde genau das zerstören, was den Rechtsbehelf brauchbar macht. Ihre Folge ist trotzdem präzise: Betrug, der innerhalb von acht Wochen erstattet und nicht von sich aus als Betrug gemeldet wird, hinterlässt in der Statistik keine Spur. Die beiden Behörden sagen das selbst und führen das bedingungslose Erstattungsrecht und die fehlende Nachforschungspflicht unter den Gründen dafür auf, dass „a large number of EEA countries reported no data at all on fraud losses for direct debits”.
Was gemeldet wird, verhält sich seltsam, und der Bericht erklärt es nicht. Der Wert betrügerischer Lastschriften im Europäischen Wirtschaftsraum stieg von 36 Millionen Euro im Jahr 2023 auf 112 Millionen Euro im Jahr 2024 — eine Verdreifachung —, während ihre Zahl um rund 38 Prozent auf 73.935 fiel. Die durchschnittliche betrügerische Lastschrift lag 2024 bei 1.516 Euro, die durchschnittliche Lastschrift überhaupt bei 504 Euro. Rechnet man die beiden veröffentlichten Angaben zurück, ergibt sich für 2023 ein Durchschnitt von etwa 300 Euro, also eine Verfünffachung binnen eines Jahres; diese Rechnung ist meine, nicht die der Behörden, und sie beruht auf deren gerundeten Prozentwerten. Dennoch bleibt die Lastschrift das Instrument mit der niedrigsten gemeldeten Betrugsquote der fünf untersuchten: 0,001 Prozent nach Wert, 0,0004 Prozent nach Stückzahl.
Eine so niedrige Quote, berechnet auf einer Grundgesamtheit, aus der die wahrscheinlichsten Betrugsfälle still entfernt wurden, misst nicht die Sicherheit. Sie misst, was die Erstattungsregel zu zählen erlaubt. Die Länderaufteilung führt es vor: Belgien meldete sämtliche Lastschrift-Betrugsschäden als von den Zahlungsdienstleistern getragen; Tschechien, Irland und Luxemburg sämtliche als von den Nutzern getragen; Portugal und die Slowakei ordneten alles „sonstigen” Beteiligten zu. Das sind nicht drei Blicke auf eine Wirklichkeit. Das sind drei nationale Meldegewohnheiten in einer Tabelle.
Der Fall für diese Bauweise, in seiner stärksten Form
Das Argument dafür, das Mandat beim Zahlungsempfänger zu lassen, ist stark, und es gehört sauber vorgetragen, bevor man ihm irgendwo widerspricht.
Zuerst die Menge. Nach der Zusammenstellung von EZB-Daten durch den European Payments Council, Stand 31. Juli 2026, wurden 2025 insgesamt 23.150,20 Millionen SEPA-Lastschriften eingereicht. Auf Deutschland allein entfielen 9.990,41 Millionen — nach meiner Rechnung 43 Prozent der SEPA-Summe —, vor Frankreich mit 5.051,66 Millionen und den Niederlanden mit 2.319,44 Millionen. Jede Zahlerbank zur Aufbewahrung und Prüfung eines Mandats zu verpflichten hieße, bei tausenden Instituten einen Bestand aufzubauen, der jeden Gläubiger Europas umfasst, der je einen ihrer Kunden belasten könnte, und 23 Milliarden Mal im Jahr dagegen abzugleichen — bei Einzügen mit einem Durchschnittswert von 504 Euro.
Die Umkehr ist demgegenüber verblüffend billig. Der Kunde sagt „zurück”, das Geld ist zurück, und niemand legt irgendetwas vor. Kein Grundcode, keine Wiedervorlage, keine Beweisfrist, keine Schiedsgebühr — nichts von der Maschinerie, die jede Stufe eines Kartenstreits in eine Rechnung darüber verwandelt, ob der Anspruch seinen Preis wert ist. Genau das haben wir gefunden, als wir uns ansahen, was jede Sprosse einer Eskalationsleiter demjenigen kostet, der sie nimmt. Gemessen als Schutz je Euro Infrastruktur ist die europäische Lastschrift vermutlich der wirtschaftlichste Rechtsbehelf im Massenzahlungsverkehr — und weit stärker als das, was Zahlungen von Konto zu Konto bieten, wo es gar keine Rückbelastung gibt.
Die Kreditwirtschaft führt ein verwandtes Argument über die Reichweite. Die Deutsche Kreditwirtschaft, die rund 1.700 Institute vertritt und im EU-Transparenzregister als Interessenvertretung geführt wird, schrieb den Trilog-Verhandlern am 28. August 2025, das bedingungslose Erstattungsrecht solle nicht für händlerinitiierte Zahlungen gelten, „as these already ensure a very high level of consumer protection”, weil „consumers and merchants both profit from the existing, strict mechanisms of scheme rules”. Das ist eine Eingabe im eigenen Interesse und so zu lesen — nur ist der Kern, dass Verfahrensregeln ein gesetzliches Erstattungsrecht ersetzen können, genau die Annahme, auf die sich die Lastschrift in umgekehrter Richtung stützt.
Die Europäische Kommission wiederum dehnt das Modell aus, statt es zu reparieren. Ihr Vorschlag von 2023 für eine Zahlungsdiensteverordnung hält fest, die Regeln für händlerinitiierte Zahlungen und für Lastschriften würden angeglichen, sodass „the same consumer protection measures, such as refunds” für beide gälten, da beide vom Zahlungsempfänger ausgelöst würden. Erwägungsgrund 85 desselben Vorschlags räumt ein, dass fortbestehende Lastschriftverfahren in Nicht-Euro-Ländern denselben hohen Schutz „by other safeguards, not always based on an unconditional right to a refund” gewährleisten — das Eingeständnis der Kommission, dass die Umkehr eine Bauweise unter mehreren ist.
Das Verfahren ist fast am Ende: Nach dem Legislative Train Schedule des Europäischen Parlaments, Stand 22. Mai 2026, haben Parlament und Rat am 27. November 2025 eine vorläufige politische Einigung erzielt, der Wirtschafts- und Währungsausschuss hat den Text am 5. Mai 2026 gebilligt, der Status lautet „close to adoption”. Den konsolidierten Endtext habe ich nicht gelesen und behaupte deshalb nichts darüber, was er zu Mandaten sagt.
Was daraus nicht folgt
Drei Grenzen, und sie wiegen.
Erstens kann ich nicht sagen, wie oft die Mandatsfrage tatsächlich auftritt. Keine Zentralbank und keine Aufsicht veröffentlicht eine Reihe zu Lastschrift-Rückgaben und -Erstattungen; die EZB veröffentlicht Stückzahlen und Werte, keine R-Transaktionsquoten. Ohne diesen Nenner ist „die Bank des Zahlers kann den Beweis nicht führen” eine Aussage über die Bauweise, nicht darüber, wie vielen Kunden das schadet.
Zweitens sind die Betrugszahlen oben eine Untergrenze, deren Abstand zur Wirklichkeit unbekannt und angesichts der Randnummer 20 der Meldeleitlinien aus den veröffentlichten Daten auch nicht bestimmbar ist. Wer eine Lastschrift-Betrugsquote von 0,001 Prozent zitiert — dieser Beitrag eingeschlossen —, zitiert eine Quote auf einer Grundgesamtheit mit einem Loch unbekannter Größe.
Drittens stammt die Haftungsaufteilung nach Ländern von wenigen meldenden Staaten, und für Lastschriften bezeichnen die Spalten „PSP” und „PSU” des Berichts die Bank des Empfängers und den Empfänger. Mit den danebenstehenden Kartenspalten sind sie nicht vergleichbar, und ich habe es nicht versucht.
Sicherheitsgrade
Fest vertreten: Das Mandat wird nach Artikel 5 Absatz 3 Buchstabe a Ziffer ii der Verordnung 260/2012 vom Zahlungsempfänger aufbewahrt; das Verfahren erlegt der Bank des Zahlers nach PT-04.10 des Regelwerks 2025 keinerlei Mandatsprüfung auf; und die Beweislast im Streitfall liegt nach Artikel 72 der Zahlungsdiensterichtlinie bei der Bank des Zahlers. Diese drei Sätze sind Zitate, und zusammen sind sie der Befund.
Mit vernünftiger Sicherheit: Artikel 5 Absatz 6 greift für Basislastschriften nie, weil sein Auslöser das Fehlen eines Erstattungsrechts ist und das Verfahren immer eines gewährt. Eine Quelle, die das ausspricht, habe ich nicht gefunden, und ich lasse mich gern eine zeigen.
Vorsichtig: Die Verdreifachung des gemeldeten Schadenswerts bei gleichzeitig um 38 Prozent gefallener Fallzahl dürfte eher widerspiegeln, was einige wenige Institute zu melden begonnen haben, als eine Veränderung im Verhalten der Täter. Der Bericht selbst weist darauf hin, dass die niedrige Fallzahl — rund 74.000 im gesamten Wirtschaftsraum — die Reihe anfällig für Ausreißer macht.
Was der Fall über den Zahlungsverkehr insgesamt lehrt
Jedes Zahlungssystem schützt seine Nutzer auf eine von zwei Arten. Es kann prüfen, bevor das Geld fließt — dann muss derjenige, der prüft, den Beweis in der Hand haben. Oder es kann rückabwickeln, nachdem das Geld geflossen ist — dann muss nur jemand die Rückabwicklung tragen können. Prüfen ist teuer und erzeugt eine Aufzeichnung. Rückabwickeln ist billig und erzeugt keine.
Europa hat sich bei der Lastschrift für die Rückabwicklung entschieden, und die Entscheidung war vernünftig: 23 Milliarden Einzüge im Jahr lassen sich nicht einzeln gegen ein Schriftstück halten, und eine Erstattung binnen acht Wochen ohne Angabe von Gründen ist für den Verbraucher ein besseres Geschäft als fast jedes Prüfregime es geworden wäre. Die Nebenwirkung ist das, was man mitnehmen sollte. Ein auf Rückabwicklung gebautes System kann das Problem, das es löst, prinzipiell nicht messen — weil die Rückabwicklung an die Stelle der Aufklärung tritt und nicht hinter sie. Die Erstattung schweigt nicht bloß über den Betrug; sie ist der Grund, warum der Betrug schweigt.
Genau dieser Tausch wird derzeit in mehr Teile des Zahlungsverkehrs geschrieben statt in weniger: in händlerinitiierte Kartenzahlungen, in Echtzeitüberweisungen, bei denen eine Rückholung Kulanz ist, in Konto-zu-Konto-Wege, die mit dem Fehlen von Rückbelastungen beworben werden. Jedes Mal lautet die richtige Frage nicht „ist der Verbraucher geschützt?”, sondern „weiß nach dem Schutz noch jemand, was passiert ist?”. Für die europäische Lastschrift lautet die Antwort nach dem Eingeständnis der beiden Behörden: in einer großen Zahl von Mitgliedstaaten nicht — und die Regel, die dieses Nichtwissen erzeugt, wurde absichtlich geschrieben, aus guten Gründen, von Leuten, die keinen blinden Fleck beabsichtigt haben.