A pull payment is one the payee starts by drawing funds out of the payer's account, like a card charge or direct debit, under a mandate or stored card. Handing the payee the power to pull money creates risk of unauthorized debits, but it also gives the payer strong recourse when something goes wrong.
What is a pull payment, in plain English?
A pull payment is money movement that the payee initiates. Instead of the customer sending funds, the merchant or biller reaches into the customer's account and takes what they are owed, based on permission the customer granted earlier. A card charge, a direct debit, and a recurring subscription billing are all pull payments: the payer authorized the relationship once, and the payee pulls from it.
That permission is captured in a mandate or a stored card on file. It is convenient, which is why subscriptions and utilities rely on it, but it also hands the payee a standing ability to debit. If that trust is abused, or the credentials are stolen, the account can be drained through charges the customer did not specifically approve.
The upside is protection. Pull rails come with built-in recourse: cardholders can raise chargebacks, and direct-debit schemes give payers return rights, so a wrong or unauthorized debit can be reversed. That contrasts sharply with push payments, where the payer sends the money and usually has little way to get it back.
Pull versus push payments
What changes | Pull payment | Push payment |
Who starts it | The payee draws from the payer's account | The payer sends money to the payee |
Examples | Card charges, direct debits, subscriptions | Bank transfers, instant and real-time payments |
Payer recourse | Chargebacks and return rights available | Little recourse once sent |
Main risk | Unauthorized debits and mandate abuse | Scams that trick the payer into sending |
What it looks like in practice
In practice
A customer notices a small monthly charge from a service they never knowingly signed up for. Their card details had been stored during a free trial that quietly rolled into a paid plan, and the merchant has been pulling the fee ever since. The customer disputes the charge with their bank.
Because this is a pull payment, the customer has recourse: the bank opens a chargeback, reverses the debit, and the stored mandate is cancelled. The same protection that makes pull rails safer for consumers is also what the merchant must manage carefully, since a pattern of these disputes drives up its chargeback rate and invites network scrutiny.
Why it matters to operators
The pull-versus-push distinction shapes where your fraud and dispute risk lives. On pull rails, the payer is relatively protected, so the pressure lands on the merchant: unauthorized debits, mandate abuse, and stored-card fraud all flow back as chargebacks and returns that the business has to manage and, where possible, contest. The recourse that reassures customers is a cost center the merchant owns.
Pull rails also carry their own attack surface. Because a stored card or mandate can be charged repeatedly, they are a target for card testing and unauthorized recurring debits. Knowing a flow is pull rather than push tells you to invest in mandate hygiene, stored-credential security, and dispute management rather than the pre-send scam controls that dominate push fraud.
What to watch in the data
- Unrecognized recurring debits. Repeated small charges customers do not recognize point to mandate abuse or a stored-card problem.
- Trial-to-paid rollovers. Silent conversions from free trials into charged subscriptions drive disputes and chargebacks.
- Card testing on stored credentials. Bursts of small charges against saved cards can mean the credentials are being probed.
- Rising chargeback rate. A climbing dispute rate on pull transactions signals either fraud or a customer-experience failure.
- Mandate mismatches. Debits that do not line up with the agreed mandate amount or schedule deserve review.
Quick questions
What is the difference between a pull and a push payment?
In a pull payment the payee draws funds from the payer's account under a mandate or stored card. In a push payment the payer sends the money themselves. Pull offers more recourse; push offers little.
Are card payments pull or push?
Card payments are pull. The merchant initiates the charge against the cardholder's account using stored or entered card details, which is why cardholders have chargeback rights.
Why do pull payments give the payer more protection?
Because the schemes behind them build in recourse. Cardholders can file chargebacks and direct-debit payers have return rights, so an unauthorized or incorrect debit can be reversed.
What is the main fraud risk on pull rails?
Unauthorized debits and mandate abuse, plus card testing against stored credentials. Because the payee can charge repeatedly, stolen or misused mandates can drain an account over time.
Who bears the cost of disputes on pull payments?
Largely the merchant. The payer's recourse comes through chargebacks and returns, which land back on the business, so managing and contesting disputes is a merchant-side cost.
Does more recourse mean pull payments are always safer?
Safer for the payer, yes, but the risk shifts to the merchant. And the standing ability to charge a stored card or mandate creates an attack surface that push payments do not have.
Go deeper
- EMVCo ↗ — Maintains the EMV chip and 3-D Secure specifications for card payments.
- PCI Security Standards Council ↗ — Security standards for handling cardholder data, including PCI DSS.

