
For a telecom or broadband operator billing across Europe, SEPA Direct Debit is the natural way to collect a monthly subscription. It is cheap, it is automated, and in markets like the Netherlands, where automatische incasso is how most recurring bills are paid, it is simply what customers expect. But compared with a straightforward bank transfer, it carries a specific exposure: the payer can recall the money after it has been collected. That single feature sits behind most of what gets called direct debit fraud.
SEPA Direct Debit is the rail most recurring revenue runs on in Europe. It is also exposed to fraud in ways that are easy to underestimate. Here is how to keep bad actors out without adding friction for everyone else.
Three common fraud patterns in SEPA Direct Debit
Michael Neuwirth, a senior product manager at Billogram, separates three categories worth distinguishing.
The first is IBAN misuse. When a mandate is set up, how do you know the account holder is the person signing up? A user entering an IBAN by hand can enter one belonging to someone else. When that person sees a charge they do not recognise, they dispute it, and their bank recalls the money on the grounds that they never authorised the mandate.
The second is no intent to pay. Here the IBAN is correct, but the account is chosen precisely because it has insufficient funds. The service is used; the payment never clears.
The third is strategic recalls. The service is used and paid for, then the money is pulled back later under the reversal rights the SEPA scheme gives every payer.
Why some sectors are more exposed than others
In all three cases, it is hard to separate deliberate fraud from ordinary failed payments, because they surface under the same reason codes: recalls, insufficient funds, missing mandates. That makes the problem hard to size precisely, but it is real, and some sectors carry far more of it than others.
Two things drive the exposure: how easily an account can be opened, and how many accounts run on direct debit. Parking and mobility sit at the easy-signup end, where an account can be created with little more than an email address and a phone number. Telecom sits further along that axis: postpaid subscriptions in the Netherlands typically require a BSN and a verified bank account, though some SIM-only sub-brands onboard with lighter checks, so signup is not the weak point people assume. The exposure comes from volume instead. Operators run enormous numbers of recurring mandates, much of it onboarded through fast online self-service, and tighter signup checks do nothing about the payments that fail or get recalled cycle after cycle. One operator described this to us as a growing share of its monthly revenue loss, estimating that roughly a fifth of those losses came from bad actors, with the rest down to friendly fraud and collection gaps.
The Dutch picture is not the same as everywhere else
This plays out differently from one market to the next, and the Netherlands is a useful example. Mandate setup there is already comparatively well protected: digital authorisation through iDIN, or a small iDEAL verification payment, confirms that whoever is creating the mandate actually owns the account. That closes off a good part of the IBAN-misuse vector at signup, more than in markets where mandates are still keyed in by hand.
What it does not close off is everything that happens after signup. A verified account holder can still let a payment fail for lack of funds. And the scheme still lets any payer reverse a collection within 8 weeks without giving a reason, or report an unauthorised one for up to 13 months. Verification at the front door does nothing for the cycles that follow. That is why loading all the effort into signup checks solves only half the problem, even in a market as far along on mandate verification as the Netherlands.
What SEPA DD fraud actually costs
The losses hit two metrics finance teams watch closely: bad debt and payment rates. But the real cost is larger. Every case sets off its own expensive, slow process: fees to banks and payment partners, plus a substantial back-office workload. Where teams handle reason codes, reconcile disputes and block accounts by hand, that work quietly eats time that could go elsewhere.
Why tightening the gate for everyone backfires
The tempting response is to tighten the gate for everyone: verification and credit checks across the board. That is rarely the right call. As a blanket policy it is expensive, it does not scale across markets, it adds friction for legitimate customers, and it risks turning away students and others who score poorly today but would be valuable customers tomorrow.
The better approach is to apply the right measure to the right user at the right time, on two layers.
At mandate creation, for low-friction gatekeeping: assess new users by verifying account ownership and enriching it with data to gauge individual risk. Low-risk users get a frictionless signup, medium-risk users are asked for more, and users with clear fraud signals or prior misconduct are blocked.
Across the lifecycle, for continuous hygiene: monitor payments over time to catch early indicators and offboard suspicious users quickly. This is the layer that handles the recall and no-intent vectors that front-door verification, however good, will never see.
The goal is to lift pay rates and reduce bad debt while keeping friction off the vast majority of low-risk users. That is how you protect revenue without breaking your customer experience.