UPI AutoPay and Mandates: Convenience or Silent Leakage?
Reviewed by CA Nikhil Gupta · Last reviewed 24 June 2026
A mandate is permission for future debits within its terms. Cancelling a subscription and cancelling the payment mandate may be separate actions.
For broader context, see the NRI, RBI and International Transactions Hub.
The safest recurring payment is one you can identify in seconds: merchant, amount ceiling, frequency, validity and cancellation path.
What the rule means in practice
UPI AutoPay enables recurring payments through electronic mandates. The user approves parameters such as merchant, amount or ceiling, frequency and validity. The exact authentication requirement can depend on transaction type and applicable limits. The mandate remains a payment instruction until revoked, expired or otherwise ended under the product flow.
For the connected rule, example or next step, see UPI AutoPay Mandate: How to Stop Silent Recurring Debits.
Stopping a merchant subscription may not always remove the bank-side or UPI mandate immediately, and revoking a mandate may not resolve a contractual amount already due. Users should complete both merchant cancellation and mandate revocation where appropriate, then keep screenshots or acknowledgements.
A debit can be disputed where it exceeds the mandate, occurs after valid revocation or is otherwise unauthorised. First identify whether the issue is the merchant contract, the UPI instruction, a bank processing error or fraud. Do not approve a “collect” request or new mandate merely because a caller says it is needed for a refund.
Decision table
| Mandate field | What to check | Risk if ignored |
|---|---|---|
| Merchant or biller | Legal and display name | Wrong or confusing merchant |
| Amount | Fixed amount or maximum ceiling | Unexpected higher debit |
| Frequency | Daily, monthly or other cycle | Duplicate or too-frequent payment |
| Validity | Start, end and revocation status | Debit after intended service ends |
| Authentication | Approval and pre-debit alerts | Unnoticed or fraudulent consent |
For the connected rule, example or next step, see Credit on UPI: Convenience, APR and Borrower Protection.
A user cancels a fitness app but leaves its UPI mandate active. A later debit appears. The user needs the app cancellation record, mandate details and debit reference to determine whether the merchant contract or payment instruction failed.
Action checklist
- Open every UPI app and list active mandates.
- Check merchant, ceiling, frequency and expiry.
- Cancel unused subscriptions with the merchant and revoke the mandate.
- Save mandate ID and cancellation confirmation.
- Review pre-debit alerts and bank statements monthly.
- Report unauthorised debits immediately through app and bank channels.
Evidence checklist
- Mandate-creation screen or message
- Mandate ID and parameters
- Merchant subscription terms
- Cancellation and revocation acknowledgement
- Debit alert and UTR
- App, bank and merchant complaint IDs
Common mistakes
- Assuming deleting an app revokes mandates
- Approving a mandate for a refund
- Ignoring low-value repeated debits
- Using multiple UPI apps without a central list
- Cancelling the mandate while ignoring a valid contract debt
Red flags
- Mandate request from unknown merchant
- Ceiling much higher than expected bill
- Daily frequency for a monthly service
- Caller asks for UPI PIN to receive money
- Debit continues after confirmed revocation
Escalation route
Raise the issue in the UPI app and with the account-holding bank using the mandate ID and UTR. Separately complain to the merchant for contract or subscription issues. Follow NPCI’s dispute-redressal route and RBI CMS for eligible unresolved bank complaints. Report fraud to 1930 promptly.
Frequently Asked Questions
Source and review trail
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
- Primary category
- Banking, RBI & Payments
- Official starting point
- www.rbi.org.in