Grounded in April Smith’s real-world personal experiences · Policy memorandum
ASDigital Banking Integrity

Financial consumer protection

Consumer Protection in Digital Banking & Recurring Billing

Drawn from real consumer experiences with hidden recurring charges, inadequate fraud alerts, insecure phone authentication, and the loss of accessible non-app banking support.

Core consumer-protection principle

Card replacement alone must not be presented as a complete fraud resolution.

Key findings

The customer sees a card. The system sees continuing permissions.

The memorandum identifies gaps between what consumers reasonably believe has been cancelled or secured and what payment and support systems may continue to permit.

01

Card replacement may not stop recurring charges

Payment-network infrastructure can allow merchants with existing billing authorizations to continue charging after a debit or credit card is replaced. Without clear disclosure, a consumer may reasonably believe the problem has been resolved when charges can continue.

02

Hidden authorizations create “ghost contracts”

Recurring merchant authorizations may remain active within payment networks after a consumer believes a subscription has been cancelled, leaving an invisible billing relationship without clear visibility or control.

03

Detectable fraud may not be communicated

Repeated identical charges, unusually high transaction frequency, and small-value testing transactions can form visible patterns, yet consumers are not always warned early enough to prevent extended harm.

04

Phone authentication can weaken security boundaries

Requiring an ATM cash-withdrawal PIN during phone verification blurs the line between identity verification and cash-access credentials and may normalize unsafe disclosure.

05

Digital migration can create access barriers

App-only service pathways disadvantage older adults, people without smartphones, and customers who need or prefer secure non-digital banking support.

Regulatory recommendations

Six standards for transparent, accessible digital banking.

These recommendations place responsibility on institutions to disclose system behavior, preserve safe access, and verify that corrective action is complete.

  1. 01

    Transparent disclosure

    Financial institutions should clearly explain that replacing a card may not terminate existing recurring billing authorizations. Disclosure should occur during onboarding, when fraud is reported, and when a replacement card is issued.

  2. 02

    Network-level cancellation

    When an unauthorized recurring charge is reported, the merchant authorization should be cancelled at the payment-network level, future charges should be blocked, and the customer should receive written confirmation.

  3. 03

    High-velocity fraud alerts

    Repeated identical charges, unusually high transaction frequency, and recurring low-value testing transactions should trigger prompt alerts and give the customer a direct way to pause or block the merchant.

  4. 04

    Separated authentication credentials

    Banks should not require ATM cash-withdrawal PINs over the phone. Dedicated phone-banking passcodes, one-time codes, secure callbacks, or other appropriately governed methods should keep cash access separate from identity verification.

  5. 05

    Secure non-app access

    Customers who do not use mobile banking applications should retain secure phone support, written confirmation of fraud actions, and a customer-service route that does not depend on app access.

  6. 06

    Visibility and revocation

    Customers should be able to see recurring merchant authorizations, revoke billing permissions, and confirm that cancellation is effective.

Policy objective

Do not shift the burden of hidden infrastructure onto the customer.

Digital banking should make recurring authorizations transparent, identify high-velocity fraud earlier, preserve secure authentication boundaries, and maintain accessible service for customers who do not use mobile applications.

Illustrative consumer harm examples

Five patterns the proposed standards are designed to prevent.

Example 01

Repeated identical charges

Failure pattern
Dozens of identical charges occur rapidly, but no alert reaches the customer while the pattern is unfolding.
Policy relevance
High-velocity patterns should trigger an automatic alert and temporary merchant blocking pending customer confirmation.
Example 02

Charges continue after card replacement

Failure pattern
A replacement card is issued, yet an existing recurring authorization allows the same merchant’s charges to continue.
Policy relevance
The institution should disclose the persistence risk and provide network-level authorization cancellation.
Example 03

Shared merchant exposure

Failure pattern
Separate household accounts receive the same unauthorized merchant charges after both cards were previously stored in a subscription system.
Policy relevance
Fraud monitoring should recognize cross-customer merchant patterns and support effective authorization cancellation.
Example 04

ATM PIN requested by phone

Failure pattern
A customer contacting a fraud department is asked to disclose the same PIN used to withdraw cash.
Policy relevance
Phone authentication should use separate credentials or a safer verification method.
Example 05

Support available only through an app

Failure pattern
A customer who does not use mobile banking is left with an insecure or inaccessible route to assistance.
Policy relevance
Banks should preserve secure non-app authentication and support for every customer.
AS

Creator & Author of Record

April Smith, J.D.

Systems Governance & Safety · Governance Architect

April Smith developed this policy memorandum to address consumer harm created when recurring-payment infrastructure, fraud controls, authentication practices, and support access do not match what customers have been told or can reasonably see.

This memorandum is authored solely by April Smith. Structural assistance does not transfer authorship. Modification, reproduction, adaptation, or distribution requires explicit written permission from the Author of Record. Permanent attribution must remain attached.