Skip to main content

Multiple-Banks Mandate

Global Standing Mandate (GSM)​

Developer & Merchant Integration Guide​


⚠️ Important Disclaimer The Global Standing Mandate (GSM) described in this document is a private, merchant-initiated, consent-based direct debit arrangement built on CreditChek's infrastructure. It is not the Central Bank of Nigeria (CBN) / NIBSS-regulated Global Standing Instruction (GSI) system. Give your business the tools to build and run its own secure, compliant, consent-driven direct debit infrastructure across your borrowers' multiple bank accounts β€” protecting your credit terms at every stage, without compromising consumer rights.

GSI is a regulated interbank framework exclusively available to CBN-licensed commercial banks. GSM is a complementary, fully-consented alternative designed for OFIs, fintechs, cooperative societies, and post-paid service providers operating outside the CBN-licensed banking perimeter. Usage of this system implies acceptance of CreditChek's Terms of Service and applicable regulatory obligations.

Purpose of this document: To provide developers, merchants, compliance officers, and regulators with a fact-based, line-by-line comparison between the CBN's GSI framework and CreditChek's GSM service β€” using the CBN's own published language as the authoritative reference.


Executive Summary​

The CBN's GSI is a regulatory enforcement tool β€” a last resort for licensed commercial banks connected to the NIBSS NIP systems to recover loans already in default, executed involuntarily (upon the condition of the executed GSI condition or prior consent by the payer) against a borrower without requiring their real-time cooperation. It is administered by NIBSS under the authority of the CBN Act 2007.

CreditChek’s Global Standing Mandate (GSM) is our proprietary multi-bank collection infrastructure. Unlike traditional direct debits that attach only a single bank account (which fail if that account has insufficient funds on the repayment date), CreditChek GSM allows you to attach up to 7 bank accounts (1 primary and up to 6 backup accounts) to a single mandate agreement.

When an automated collection falls due, Recova’s collection engine debits the primary account first. If the balance is insufficient or the transaction declines due to lack of funds, the engine gracefully and automatically cascades across the payer’s secondary backup accounts until the due amount is recuperated.

CreditChek's GSM is a private, consent-driven direct debit infrastructure β€” a pre-default repayment automation tool that requires explicit, active payer participation at every step. It is governed by contract law, the FCCPC Act 2018, and CreditChek's terms of service.

They address different problems, serve different audiences, and operate under entirely different legal regimes. They are not interchangeable or comparable systems.


Table of Contents​

  1. Overview
  2. GSM vs GSI β€” Key Distinctions
  3. Who Can Use GSM
  4. Architecture & Flow
  5. Step 1 β€” Bank Account Discovery (RADAR Lookup)
  6. Step 2 β€” Set Mandate (Place e-Mandate on Accounts)
  7. Step 3 β€” Micro-Deposit Verification Loop
  8. Step 4 β€” Automated Collection
  9. Consent & FCCPC Compliance
  10. Caveats, Limits & Legal Boundaries
  11. Glossary

1. Overview​

CreditChek’s Global Standing Mandate (GSM) is our proprietary multi-bank collection infrastructure. Unlike traditional direct debits that attach only a single bank account (which fail if that account has insufficient funds on the repayment date), CreditChek GSM allows you to attach up to 7 bank accounts (1 primary and up to 6 backup accounts) to a single mandate agreement.

When an automated collection falls due, Recova’s collection engine debits the primary account first. If the balance is insufficient or the transaction declines due to lack of funds, the engine gracefully and automatically cascades across the payer’s secondary backup accounts until the due amount is recuperated.

Global Standing Mandate (GSM) is CreditChek's consent-driven, BVN-anchored multi-bank direct debit framework. It enables merchants and lenders outside the traditional commercial banking space to:

  • Discover all active bank accounts tied to a borrower's BVN via RADAR
  • Place verified e-mandates on one or more of those accounts via RecovaPRO
  • Automate repayment collection from a primary account, with fallback to backup accounts
  • Report every loan lifecycle event to the credit bureau via Spectrum, making collection legally defensible and always FCCPC-compliant

The system is fully consent-based. The payer (borrower) actively participates in designating their accounts β€” there is no silent or involuntary sweep.


2. GSM vs GSI β€” Key Distinctions​

DimensionCBN/NIBSS GSICreditChek GSM
Governing BodyCBN / NIBSSCreditChek (Private Infrastructure) via NIBSS (NDD)
EligibilityCBN-licensed commercial banks onlyOFIs, fintechs, cooperatives, post-paid providers
Consent ModelRegulatory mandate; borrower consent implicit at loan originationExplicit, active, per-account payer consent required at every step
Account DiscoveryBank-wide sweep by CBN authorityRADAR BVN lookup; payer-confirmed accounts
Initiation AuthorityCBN-empowered sweepMerchant-initiated via CreditChek API
Reporting TriggerNon-performing loan reported to CBNLoan lifecycle reported to Credit Bureau via Spectrum
Legal BasisCBN Act, BOFIA Act 2020FCCPC Act 2018, Contract Law, CreditChek Terms of Service
Collection BehaviorInvoluntary interbank sweepAutomated but fully consented debit per mandate
Bureau ReportingHandled by bankMandatory via CreditChek Spectrum
Micro-deposit VerificationNot applicableRequired for every account enrolled

⚠️ You must never represent this service to borrowers or regulators as equivalent to, or backed by, the CBN's GSI system.


CBN's own language on authority:

"In pursuant of the powers conferred on the Central Bank of Nigeria (CBN) by Section 2(d) of the CBN Act, 2007... the CBN hereby issues this guideline on Global Standing Instruction (GSI) to enhance loan recovery across the banking sector."

Implication for GSM merchants: CreditChek's GSM derives no authority from the CBN Act or any CBN guideline. It operates entirely within the contractual relationship between the merchant and the borrower, governed by FCCPC consumer protection law.


3. Who Can Use GSM β€” Eligibility​

GSM is designed for entities that extend credit or post-paid services but are not CBN-licensed commercial banks:

  • Microfinance Institutions & OFIs β€” registered under CBN MFB/State Government Lending/OFI licences
  • Digital Lenders & Fintechs β€” FCCPC-registered, operating under the Digital Lending Guidelines
  • Cooperative Societies β€” registered under the Cooperative Societies Act
  • Post-paid Service Providers β€” telcos, e-commerce, utilities, SaaS platforms collecting on deferred billing
DimensionCBN GSICreditChek GSM
Eligible initiatorsCBN-licensed Participating Financial Institutions (PFIs) onlyOFIs, digital lenders (FCCPC-registered), cooperatives, post-paid providers, fintechs
Participation requirementMust execute a GSI Master Agreement with NIBSS; must be connected to Nigeria Central SwitchMust hold an active CreditChek merchant account with approved appId and businessId
Infrastructure dependencyNIBSS NIP platform; Industry Customer Accounts Database (ICAD)CreditChek RADAR API; CreditChek RecovaPRO API
Commercial banksβœ… Eligibleβœ… Eligible (as merchants) but GSI is the preferred regulatory channel
Fintechs / digital lenders❌ Not eligibleβœ… Primary target audience
Cooperatives❌ Not eligibleβœ… Eligible
Post-paid service providers❌ Not eligibleβœ… Eligible

Prerequisites before integrating GSM:

  • Active CreditChek merchant account with approved appId (go-live) and businessId
  • FCCPC registration or applicable operating licence
  • A compliant loan origination process with explicit borrower consent captured (written/digital)
  • Integration with CreditChek Spectrum for credit bureau reporting (mandatory β€” see Step 4)

3.1 When It Is Triggered β€” Pre-Default vs Post-Default​

This is arguably the most fundamental distinction between the two systems.

DimensionCBN GSICreditChek GSM
Trigger pointAfter default β€” borrower has already failed to repay per loan terms and classified per CBN Prudential GuidelinesBefore default β€” scheduled, pre-agreed repayment automation from day one of the loan
Nature of useExplicitly a "last resort" recovery mechanismA primary repayment collection infrastructure
Borrower notificationCollection happens "without recourse to the Borrower"Payer is actively informed and consented at every collection event
Loan status at triggerNon-performing; classified under CBN Prudential GuidelinesPerforming; active loan in good standing
Relationship to NPLTriggered because NPL existsDesigned to prevent NPL by automating timely repayments

CBN's own language on trigger intent:

"The GSI shall serve as a last resort by a Creditor bank, without recourse to the Borrower, to recover past due obligations... from a defaulting Borrower through a direct set-off."

Implication: GSI is a debt recovery instrument. GSM is a repayment facilitation instrument. A merchant should be running GSM throughout the healthy life of a loan, not as a response to default.

CBN's own language on consent:

"(a) Execute a GSI mandate in hard copy or digital form. (b) Ensure that the terms and conditions of the mandate are clearly understood before execution."

Important nuance: Both systems require a mandate to be executed. However, in GSI, once that mandate is signed, the CBN-empowered sweep can happen entirely without the borrower's knowledge or participation when default occurs. In CreditChek's GSM, the payer's active, consented participation is required at account discovery, mandate placement, and micro-deposit confirmation β€” and the payer decides which accounts are enrolled.


DimensionCBN GSICreditChek GSM
Consent natureMandate executed once at loan origination; subsequent GSI triggers require no further borrower involvementExplicit, active, per-account consent required from the payer at each mandate placement
Account selectionNIBSS sweeps all qualifying accounts automatically via ICAD β€” borrower has no say in which accounts are hitPayer chooses their Primary Account and opts in to each Backup Account individually
Real-time involvementBorrower is not involved at point of GSI triggerPayer confirms each enrolled account via micro-deposit verification
Consent revocabilityGoverned by the executed GSI mandate instrumentPayer may request mandate cancellation (subject to outstanding obligations); merchant must honour
Consent documentationHard copy or digital GSI mandate; stored by Creditor Bank and retrievable on demandDigital consent with timestamp, IP, payer ID; merchant's responsibility to retain

CBN's own language on consent:

"(a) Execute a GSI mandate in hard copy or digital form. (b) Ensure that the terms and conditions of the mandate are clearly understood before execution."

Important nuance: Both systems require a mandate to be executed. However, in GSI, once that mandate is signed, the CBN-empowered sweep can happen entirely without the borrower's knowledge or participation when default occurs. In GSM, the payer's active participation is required at account discovery, mandate placement, and micro-deposit confirmation β€” and the payer decides which accounts are enrolled.


Supported Banks for Micro-Deposit Mandate​

The following banks support the micro-deposit mandate authorization method:

Access Bank Plc Β· EcoBank Plc Β· Fidelity Bank Plc Β· First Bank of Nigeria Plc
First City Monument Bank Plc Β· Globus Bank Ltd Β· Guaranty Trust Bank Plc
Jaiz Bank Β· Keystone Bank Plc Β· Polaris Bank Limited Β· Providus Bank
Stanbic IBTC Β· Standard Chartered Bank Plc Β· Sterling Bank Plc
Suntrust Bank Β· TAJBank Ltd Β· Titan Trust Bank Β· Union Bank of Nigeria Plc
United Bank for Africa Plc Β· Unity Bank Plc Β· Wema Bank Β· Zenith International Bank Plc
Kuda MFB . JAIZ Bank

To programmatically retrieve the current list:

GET https://api.creditchek.africa/v1/recova/micro-deposit/bank-list
Authorization: token <YOUR_SECRET_API_KEY>

4. Architecture & Flow​

The GSM integration follows a strict sequential flow. Do not skip or reorder steps.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ PAYER ONBOARDING β”‚
β”‚ β”‚
β”‚ 1. Merchant captures BVN + consent from payer at loan origination β”‚
β”‚ 2. RADAR Lookup β†’ discover all BVN-linked bank accounts β”‚
β”‚ 3. Payer selects Primary Account + Backup Accounts (Select up to 7 accounts. Designate 1 Primary account and up to 6 β”‚
β”‚ secondary backup accounts. ) β”‚
β”‚ 4. RecovaPRO β†’ loop micro-deposit (₦50) on each account β”‚
β”‚ 5. Accounts confirmed β†’ e-mandates activated β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DISBURSEMENT GATE β”‚
β”‚ β”‚
β”‚ 6. Spectrum β†’ report loan approval + disbursement to credit bureau β”‚
β”‚ ⚠️ Automated collection is BLOCKED until disbursement is β”‚
β”‚ confirmed reported to bureau via Spectrum β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ REPAYMENT LIFECYCLE β”‚
β”‚ β”‚
β”‚ 7. On each instalment due date β†’ debit Primary Account β”‚
β”‚ 8. If Primary fails β†’ cascade through Backup Account array β”‚
β”‚ 9. Spectrum β†’ report each payment event (success / missed /partially paidβ”‚
β”‚ 10. Loan reaches term β†’ Spectrum closes loan record with Credit Reference Bureauβ”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

GSM Architecture & Workflow (summarized view)​

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. RADAR BVN Discovery β”‚
β”‚ Call CreditChek Radar with the payer's BVN to discover all active β”‚
β”‚ bank accounts linked to the borrower across Nigerian banks. β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. Account Selection & Allocation β”‚
β”‚ Select up to 7 accounts. Designate 1 Primary account and up to 6 β”‚
β”‚ secondary backup accounts. β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. GSM Enrollment API β”‚
β”‚ Submit the accounts array to: β”‚
β”‚ POST /v1/recova/micro-deposit/create/mandate/gsm β”‚
β”‚ (Creates independent consents concurrently with high resilience) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. Payer Micro-Deposit Authorization β”‚
β”‚ Payer transfers ₦50 from EACH individual enrolled account to its β”‚
β”‚ specific dedicated virtual account (e.g., 7 accounts = 7 transfers).β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 5. Automated Cascading Collection β”‚
β”‚ On due date, scheduler debits the Primary account. If balance is β”‚
β”‚ insufficient, it seamlessly cascades through Backup accounts. β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜


Stage 1 β€” Bank Account Discovery (RADAR BVN Lookup)​

Service: CreditChek RADAR Purpose: Discover all active bank accounts linked to the payer's BVN across Nigerian financial institutions.

Before enrolling bank accounts into a GSM mandate, query the CreditChek Radar service with the borrower's 11-digit BVN. Radar scans the banking ecosystem and returns a list of verified active bank accounts associated with that customer.

POST /v1/radar/bvn-lookup
token: <YOUR_API_KEY>
Content-Type: application/json

Endpoint​

POST: https://api.creditchek.africa/v1/radar/

Request​

{
"bvn": "22222222222"
}

Request Parameters​

ParameterPositionRequiredDescription
bvnbodyβœ… YesPayer's Bank Verification Number
tokenAuthorizationβœ… Yesapp secret key
typebodyβœ… Yesto contain the bvn in JSON format

Headers:

Authorization: Bearer <token>
Content-Type: application/json

Full documentation: https://docs.creditchek.africa/nigeria/radar/getRadar

Implementation Notes​

  • Present discovered accounts to the payer. The payer must actively consent and select their Primary Account and opt-in to any Backup Accounts. Do not pre-select on their behalf (to comply to the Privacy and Data protection act).
  • Store the payer's selection before proceeding to Step 2.
  • RecommendationUndiscovered or inactive accounts should be excluded from the mandate setup(can be added as Tooltip to the users).

Response (200 OK)​

{
"status": true,
"message": "BVN accounts retrieved successfully",
"data": {
"bvn": "22222222222",
"firstName": "Oluwaseun",
"lastName": "Adekunle",
"accounts": [
{
"bankName": "ACCESS BANK PLC",
"bankCode": "044",
"accountNumber": "0088741090"
},
{
"bankName": "ZENITH BANK PLC",
"bankCode": "057",
"accountNumber": "2178920069"
},
{
"bankName": "GUARANTY TRUST BANK PLC",
"bankCode": "058",
"accountNumber": "0123456789"
},
{
"bankName": "UNITED BANK FOR AFRICA PLC",
"bankCode": "033",
"accountNumber": "1022889091"
},
{
"bankName": "FIRST BANK OF NIGERIA PLC",
"bankCode": "011",
"accountNumber": "3011223344"
}
]
}
}

Stage 2: Account Selection & Allocation Rules​

From the accounts discovered via Radar, select the accounts to enroll into the mandate based on the following rules:

  • Maximum 7 Accounts: A single GSM mandate request accepts between 1 and 7 bank accounts (MAX_ACCOUNTS_PER_REQUEST = 7). Requests with more than 7 accounts are rejected with an HTTP 400 error.
  • Single Primary Account: Exactly one account must have "primary": true. This will be the priority account attempted on scheduled repayment dates.
  • Backup Accounts: Up to 6 accounts marked "primary": false. These serve as fallback accounts during cascading collections.
  • Unique Accounts: All account numbers in the request must be unique. Submitting duplicate account numbers in the same request is rejected.
  • Shared Contact Details: Top-level address, email, and mobileNumber apply across all enrolled accounts.
{
"primaryAccount": {
"accountNumber": "0088741090",
"bankCode": "044"
},
"backupAccounts": [
{ "accountNumber": "2034556781", "bankCode": "058" },
{ "accountNumber": "0112334456", "bankCode": "033" }
]
}

Stage 3 β€” Set Mandate (Place e-Mandate on Accounts - Multi-Bank Mandate Attachment API)​

Service: CreditChek RecovaPRO β€” Initialize e-mandate with the payer Purpose: Register an e-mandate against each of the payer's selected bank accounts. Each account requires a separate API call using the same mandateId, email, and BVN combination.

Submit the selected list of accounts to the Recova GSM enrollment endpoint.

POST /v1/recova/micro-deposit/create/mandate/gsm
Content-Type: application/json

Full documentation: https://docs.creditchek.africa/nigeria/recovaPro/api.md/initiateConsent

Looping Across All Discovered Accounts​

Call this endpoint once per account β€” for the primary account and each backup account β€” using the identical mandateId + email + BVN combination. CreditChek uses this triplet to link all mandates to the same loan arrangement.

// Pseudocode β€” Loop through all payer-selected accounts
const allAccounts = [primaryAccount, ...backupAccounts];

for (const account of allAccounts) {
await placeMandateAPI({
appId: "630c8be89131cd442344e794",
businessId: "630c8be89131cd442344e790",
email: payerEmail,
mandateId: mandateId,
accountNumber: account.accountNumber,
bankCode: account.bankCode,
address: payerAddress,
mobileNumber: payerPhone
});
}

Sample request account_number: 12345678901 and 09876543212

Contact [email protected] if you encounter any error responses at this stage.

Key Rule: The combination of email + BVN + mandateId must be identical across all mandate placement calls for the same loan. This uniquely ties all accounts to one loan event and prevents duplicate mandate conflicts.

Request Parameters​

FieldTypeRequired?Description
appIdstringYesYour application ID.
businessIdstringYesYour business ID.
mandateIdstringYesThe mandate _id returned from POST /consent/create.
emailstringYesPayer's email address.
mobileNumberstringYesPayer's mobile phone number.
addressstringYesPayer's residential address.
accountsarrayYesArray of 1 to 7 bank accounts (see structure below).
accounts[].accountNumberstringYes10-digit NUBAN account number.
accounts[].bankCodestringYes3-digit CBN bank code.
accounts[].primarybooleanOptionalSet true for exactly one account to designate as the primary account. Defaults to false.

Sample Request​

{
"appId": "730c8be89131cd1111111111",
"businessId": "730c8be89121212121212121",
"mandateId": "77192739b3cf770000000000",
"email": "[email protected]",
"mobileNumber": "08012345678",
"address": "12 Marina Road, Lagos Island, Lagos",
"accounts": [
{
"accountNumber": "1234567890",
"bankCode": "044",
"primary": true
},
{
"accountNumber": "0987654321",
"bankCode": "057",
"primary": false
}
]
}

Sample Response (200 OK)​

{
"status": true,
"message": "Mandate accounts processed (test mode)",
"error": false,
"data": {
"mandate": {
"_id": "77192739b3cf770000000000",
"consents": [],
"provider": "mono"
},
"results": [
{
"accountNumber": "1234567890",
"bankCode": "044",
"success": true,
"demo": true,
"primary": true,
"message": "Mandate created successfully",
"transfer_destinations": [
{
"bank_name": "Parallex Bank",
"account_number": "6007049662",
"icon": "https://res.cloudinary.com/creditchek-africa/image/upload/v1772053274/banks/parallex-logo_k4e30p.png"
}
]
},
{
"accountNumber": "0987654321",
"bankCode": "057",
"success": true,
"demo": true,
"primary": false,
"message": "Mandate created successfully",
"transfer_destinations": [
{
"bank_name": "Parallex Bank",
"account_number": "6007049662",
"icon": "https://res.cloudinary.com/creditchek-africa/image/upload/v1772053274/banks/parallex-logo_k4e30p.png"
}
]
}
]
}
}

[!TIP] Concurrent Processing & Fault Tolerance All accounts submitted in the array are processed concurrently. If one bank experiences temporary downtime or an individual account fails name-enquiry verification, the remaining valid accounts proceed without interruption. Check each account's success flag in the results array.

For each successfully attached account, CreditChek dispatches a recova.consent.created webhook event to your registered webhook URL.



7. Step 3 β€” Micro-Deposit Verification Loop​

Purpose: Verify that each enrolled bank account is valid, active, and capable of processing credit and debits by sending a strict ₦50 micro-deposit from each selected account to the displayed account details from the platform. The NIBSS NDD(Direct Debit) platform confirms (or rejects) each deposit to forward the activate request of the mandate to the payer's bank.

How It Works​

  1. PAYER initiates a ₦50 micro-deposit from each selected bank account submitted in Step 2
  2. The payer's bank either honours or rejects the deposit confirmation auto-relayed message from NIBSS NDD.
  3. Honoured accounts have their mandate status set to active
  4. Rejected accounts are marked failed β€” the merchant should notify the payer and optionally prompt re-selection

[!IMPORTANT] Crucial Rule: Transfers Must Originate from Each Enrolled Account Each ₦50 transfer MUST originate directly from the specific bank account being authorized to its corresponding dedicated virtual destination returned in transfer_destinations.

If a mandate enrolls multiple bank accounts, the payer must complete a separate ₦50 transfer for each:

  1. Account 1 (e.g., Access Bank - 1234567890): Payer transfers ₦50 from their Access Bank account to Account 1's dedicated destination.
  2. Account 2 (e.g., Zenith Bank - 0987654321): Payer transfers ₦50 from their Zenith Bank account to Account 2's dedicated destination.
  3. Account 3 (e.g., GTBank): Payer transfers ₦50 from their GTBank account to Account 3's dedicated destination.
  4. Account 4 (e.g., UBA): Payer transfers ₦50 from their UBA account to Account 4's dedicated destination.
  5. Account 5 (e.g., First Bank): Payer transfers ₦50 from their First Bank account to Account 5's dedicated destination.
  6. Account 6 (e.g., Providus Bank): Payer transfers ₦50 from their Providus Bank account to Account 6's dedicated destination.
  7. Account 7 (e.g., Kuda Bank): Payer transfers ₦50 from their Kuda Bank account to Account 7's dedicated destination.

Why this is required: The receiving interbank settlement network and NIBSS verify the originating account number and sender identity against the enrolled account record. If a payer uses one bank account (e.g., Access Bank) to send money to another bank account's destination (e.g., Zenith Bank's destination), the receiving bank cannot verify ownership of that second account, and the authorization will fail.

Micro-Deposit Status Outcomes​

OutcomeMandate StatusAction Required
Deposit accepted by bankactiveAccount ready for collection
Deposit rejected / account inactivefailedNotify payer; prompt re-selection
Payer disputes depositdisputedEscalate through RecovaPRO dispute flow
No response within TTLpending_timeoutNotify payer; prompt re-selection

Mandate Priority Logic​

The collection engine follows this priority during automated repayment:

1. Attempt PRIMARY account debit
2. If PRIMARY fails β†’ attempt BACKUP account [0]
3. If BACKUP [0] fails β†’ attempt BACKUP account [1]
4. Continue through backup array in sequence
5. If ALL accounts fail β†’ trigger missed repayment event β†’ report to Spectrum

Note: A minimum of one active mandate (primary) is required before disbursement is permitted. Backup accounts are strongly recommended to maximise collection success rates.


8. Step 4 β€” Automated Collection​

Once mandates are active and Spectrum confirms disbursement, RecovaPRO's collection engine handles scheduled debits automatically.

Collection Behaviour​

  • Debits are initiated on the scheduled repayment dates defined at mandate creation
  • The primary account is attempted first; backup accounts are cascaded through in order
  • All collection events (success, failure, partial) are automatically fed back to Spectrum for bureau reporting
  • The merchant receives webhook notifications for every collection event and daily collection summary (digest) email

Authorization & Webhook Flow​

  • As the payer completes each transfer from its respective account, that bank verifies ownership and activates that consent.
  • Recova receives confirmation from the banking rail and marks each consent as active.
  • For each verified account, CreditChek fires recova.consent.approved.
  • Once the designated primary account is verified, the overarching mandate status switches to active, and recova.mandate.approved is dispatched to your registered webhook URL. Collections can now proceed automatically.

Webhook Events​

Register a webhook URL in your CreditChek dashboard to receive real-time notifications:

EventDescription
mandate.activatede-mandate successfully verified and active
mandate.failedMicro-deposit rejected; mandate not established or Mandate not approved
collection.successRepayment collected successfully
collection.failedAll accounts exhausted; repayment missed
collection.partialPartial amount collected (insufficient funds)
mandate.expiredMandate has reached end of loan tenure

Sample Webhook Payload β€” Collection Success​

{
"businessId": "65c23585353059",
"consentId": "68e505b6c0570b",
"mandateId": "68e4156dc6f60",
"accountName": "LEADSAUTO CENTER NIG LTD",
"accountNumber": "2063293726",
"bankName": "Access Bank",
"totalAmount": 2033626.28,
"providerMessage": "Account debited successfully.",
"amountCollected": 610087.88,
"status": "success",
"collectedOn": "2025-11-06T02:07:46.195Z",
"collectionType": "auto",
"instalmentReference": "4a3b4a76-f897-483c-aca1-d8db30d86efa",
"instalmentStatus": "success",
"reference": "1762394845143",
}

Sample Webhook Payload β€” Collection On Overdue​

{
"businessId": "65c23585353059",
"consentId": "68e505b6c0570b",
"mandateId": "68e4156dc6f60",
"accountName": "LEADSAUTO CENTER NIG LTD",
"accountNumber": "2063293726",
"bankName": "Access Bank",
"totalAmount": 2033626.28,
"providerMessage": "Account debited successfully.",
"amountCollected": 610087.88,
"status": "success",
"collectedOn": "2025-11-06T02:07:46.195Z",
"collectionType": "auto",
"instalmentReference": "4a3b4a76-f897-483c-aca1-d8db30d86efa",
"instalmentStatus": "overdue",
"reference": "1762394845143",
}

Sample Webhook Payload β€” Collection Failed​

{
"businessId": "65c23585353059",
"consentId": "68e505b6c0570b",
"mandateId": "68e4156dc6f60",
"accountName": "LEADSAUTO CENTER NIG LTD",
"accountNumber": "2063293726",
"bankName": "Access Bank",
"totalAmount": 2033626.28,
"providerMessage": "Account debited successfully.",
"amountCollected": 610087.88,
"status": "success",
"collectedOn": "2025-11-06T02:07:46.195Z",
"collectionType": "auto",
"instalmentReference": "4a3b4a76-f897-483c-aca1-d8db30d86efa",
"instalmentStatus": "failed",
"reference": "1762394845143",
}

Sample Webhook Payload β€” Collection Partial Paid​

{
"businessId": "65c23585353059",
"consentId": "68e505b6c0570b",
"mandateId": "68e4156dc6f60",
"accountName": "LEADSAUTO CENTER NIG LTD",
"accountNumber": "2063293726",
"bankName": "Access Bank",
"totalAmount": 2033626.28,
"providerMessage": "Account debited successfully.",
"amountCollected": 610087.88,
"status": "success",
"collectedOn": "2025-11-06T02:07:46.195Z",
"collectionType": "auto",
"instalmentReference": "4a3b4a76-f897-483c-aca1-d8db30d86efa",
"instalmentStatus": "partially paid",
"reference": "1762394845143",
}

Sample Webhook Payload β€” Collection Processing​

{
"businessId": "65c23585353059",
"consentId": "68e505b6c0570b",
"mandateId": "68e4156dc6f60",
"accountName": "LEADSAUTO CENTER NIG LTD",
"accountNumber": "2063293726",
"bankName": "Access Bank",
"totalAmount": 2033626.28,
"providerMessage": "Account debited successfully.",
"amountCollected": 610087.88,
"status": "success",
"collectedOn": "2025-11-06T02:07:46.195Z",
"collectionType": "auto",
"instalmentReference": "4a3b4a76-f897-483c-aca1-d8db30d86efa",
"instalmentStatus": "processing",
"reference": "1762394845143",
}

Stage 5: Intelligent Cascading Collection Logic​

When an automated collection is scheduled, Recova's scheduler follows an intelligent multi-account cascade:

  1. Attempt Primary Account: The scheduler first attempts to debit the installment amount from the designated primary account.
  2. Evaluate Insufficient Funds: If the primary account has sufficient funds, the collection completes immediately, and the transaction is marked as paid.
  3. Graceful Cascade to Backup Accounts: If the primary account returns an insufficient balance or declines, the scheduler immediately and sequentially attempts the enrolled backup accounts (primary: false) in order.
  4. Transparent Audit Trail: Every collection attempt, cascade event, and settlement status is recorded and reported via webhooks (recova.mandate.approved, installment payment events) and accessible via the mandate status API.

6. Webhooks & Lifecycle Events​

Because interbank mandate approvals and electronic debit collections are asynchronous, your system should rely on webhooks rather than continuous polling.

RecovaPRO delivers webhook events directly to your registered webhook URL.

Webhook Security​

Every webhook payload dispatched to your endpoint includes standard webhook verification headers:

  • Verify the webhook signature against your webhook secret using HMAC-SHA256 / Webhook Service verification.
  • Always return an immediate 2xx HTTP status code upon receiving the event to acknowledge receipt.
[ POST /consent/create ]
β”‚
β–Ό
status: "pending" ────────────────► recova.mandate.initialize
β”‚
β–Ό (Payer links bank account / accounts)
recova.consent.created (Fires for each linked account)
β”‚
β–Ό (Payer transfers ₦50 per individual account)
β”œβ”€β”€ Individual Account Verified ──► recova.consent.approved
β”œβ”€β”€ Individual Account Rejected ──► recova.consent.rejected
β”œβ”€β”€ Individual Account Expired ──► recova.consent.expired
└── Individual Account Revoked ──► recova.consent.cancelled
β”‚
β–Ό (Primary account verified)
status: "active" ◄─────────────── recova.mandate.approved (Collection begins)
β”‚ β–²
β”‚ β”‚
β–Ό β”‚
status: "paused" ◄─────────────── recova.mandate.paused / recova.mandate.resumed
β”‚
β–Ό
status: "deactivated" ────────────► recova.mandate.cancelled (Terminated by merchant)
status: "closed" ────────────► Mandate expired (endDate passed)

The Federal Competition and Consumer Protection Commission (FCCPC) Act 2018 governs all consumer-facing financial and credit services in Nigeria. CreditChek's GSM is designed to be fully compliant. The following obligations fall on the merchant:

At loan origination, before any RADAR lookup or mandate placement, you must capture and store verifiable consent from the payer for:

  • Use of their BVN to discover linked bank accounts
  • Placement of e-mandates on each selected bank account
  • Automated debit on repayment due dates
  • Reporting of their loan data to a licensed Credit Reference Bureau
  • Cascading debit to backup accounts if primary account fails

Consent must be:

  • Explicit β€” affirmative action (tick-box, OTP confirmation, digital signature and verifiable personalInfo)
  • Informed β€” payer must understand what they are consenting to in plain language
  • Auditable β€” stored with timestamp, IP address, and payer identifier
  • Revocable β€” payer must be able to request mandate cancellation (subject to outstanding obligations)

FCCPC Prohibited Practices (Merchant Obligations)​

PracticeStatus
Initiating collection without proof of disbursement❌ Prohibited
Collecting amounts exceeding approved loan terms❌ Prohibited
Placing mandates without explicit payer consent❌ Prohibited
Failing to report loan lifecycle to credit bureau❌ Prohibited
Presenting GSM as CBN/NIBSS GSI to borrowers❌ Prohibited
Collecting after borrower has filed valid dispute❌ Prohibited β€” pause pending resolution
Retaining mandate after full loan repayment❌ Prohibited

What CreditChek GSM Is​

  • βœ… A consent-based, merchant-operated, BVN-anchored multi-account direct debit system
  • βœ… A private infrastructure service built by CreditChek for eligible non-bank lenders
  • βœ… Designed as an empowerment tool for businesses to complement the regulated GSI system outside the commercial banking sector
  • βœ… Fully auditable with end-to-end bureau reporting via Spectrum

What GSM Is Not​

  • ❌ Not the CBN/NIBSS Global Standing Instruction (GSI) system
  • ❌ Not a regulatory mandate β€” it is a contract-based arrangement between merchant and payer
  • ❌ Not available to entities without a valid CreditChek merchant account and applicable operating licence
  • ❌ Not a substitute for FCCPC compliance or applicable state/federal lending regulations
  • ❌ Not a payment gateway β€” CreditChek does not hold, move, or settle funds directly

Technical Limits​

ParameterLimit
Maximum backup accounts per mandatePlatform limit β€” NONE
Micro-deposit amount₦50 per account (fixed)
Mandate validityTied to loan tenure defined at mandate creation
Retry attempts per due dateConfigurable per merchant agreement
API rate limitsRefer to CreditChek developer portal

Liability & Indemnification​

  • CreditChek bears no liability for collections on mandates where loan.disbursed has not been reported via Spectrum
  • Merchants bear full responsibility for consent validity, FCCPC compliance, and accuracy of loan data reported to bureaus
  • CreditChek's indemnification of the merchant is contingent on correct use of Spectrum for end-to-end bureau reporting
  • Misuse of the GSM system β€” including misrepresenting it as CBN-regulated β€” may result in immediate account suspension and regulatory referral

9. Glossary​

TermDefinition
BVNBank Verification Number β€” a unique CBN-issued identifier tied to an individual across all Nigerian bank accounts
GSIGlobal Standing Instruction β€” CBN/NIBSS-regulated system for commercial banks to sweep accounts for NPL recovery
GSMGlobal Standing Mandate β€” CreditChek's consent-based multi-bank direct debit framework for non-bank lenders
RADARCreditChek's BVN account discovery service that returns all active accounts linked to a BVN
RecovaPROCreditChek's e-mandate placement and automated collection service
SpectrumCreditChek's credit bureau reporting service; mandatory for GSM collection to be activated
Micro-depositA ₦50 test credit sent to verify an account is active and capable of transacting
Primary AccountThe payer's preferred account for first-attempt repayment collection
Backup AccountsAdditional payer-consented accounts debited in sequence if the primary account fails
MandateA formal, consent-backed authorisation for a merchant to debit a borrower's bank account
NPLNon-Performing Loan β€” a loan where scheduled repayments have been missed beyond a defined threshold
FCCPCFederal Competition and Consumer Protection Commission β€” Nigeria's consumer rights and fair market practices regulator
OFIOther Financial Institution β€” financial entities regulated by the CBN but not licensed as commercial banks