Before a bank or fintech pays an agent, it should be able to answer a simple question: is this agent authorised to do this, for this principal, right now? A mandate verification API exists to answer that question in real time — before money moves, rather than after a dispute.

What is being verified

An agent in the SUPA model acts for an identified principal and owns nothing itself. It is never anonymous, and its identity is revocable. A verification call therefore checks several things at once: that the agent is registered, that it is linked to a principal, and that the operation fits the policy attached to the unit.

Policy here is not a document to be trusted but a rule set applied below the model. Limits, approved counterparties and approval thresholds live where the agent cannot argue with them, so verification can rely on them rather than on the agent's own account of its authority.

What a clean response should contain

A useful response is explicit and minimal — enough to make a decision, no more.

  • the status of the agent's identity — valid or revoked
  • the identified principal behind it
  • whether the requested counterparty is approved
  • whether the operation falls within limits
  • the policy version against which the check was made

Minimalism is deliberate. Data minimisation is a compliance property, not an aesthetic one; sharing more than the check requires is a liability, and cross-border sharing rules differ by jurisdiction.

Why it matters across institutions

The same mechanism supports reliance between institutions. Under FATF Recommendation 17, a regulated institution may rely on client due diligence performed by another regulated institution — though reliance does not transfer legal responsibility, and is not permitted everywhere. Mandate verification is the practical, per-operation expression of that idea: a check that can be made in seconds, attributed and logged.

In short

  • Verification should happen before payment, not after a dispute.
  • Check registration, principal, counterparty approval and limits.
  • Return the minimum needed, plus the policy version used.
  • Reliance supports this model but does not remove each party's own legal duties.

This is general information, not legal, tax or financial advice. See how institutions plug in: institutions.