Unscheduled Credential-on-File Transaction
Pronunciation: un-SKEH-joold krih-DEHN-chul ahn FEYEL tran-ZAK-shun
Definition
An unscheduled credential-on-file transaction uses a previously stored payment credential for a charge that occurs without a fixed or regular processing date. This transaction type commonly covers merchant-initiated charges under prior customer consent, such as an automatic account top-up triggered by a low balance. The amount may be fixed or variable, but the triggering event rather than a regular calendar schedule determines timing. It is distinct from an ordinary recurring payment and from a checkout where the customer actively initiates the charge.
Overview
This transaction type commonly covers merchant-initiated charges under prior customer consent, such as an automatic account top-up triggered by a low balance. The amount may be fixed or variable, but the triggering event rather than a regular calendar schedule determines timing.
It is distinct from an ordinary recurring payment and from a checkout where the customer actively initiates the charge. Incorrect classification, missing consent, unclear triggers, expired agreements, or wrong network indicators can cause declines, disputes, compliance failures, and confusing customer experiences.
Merchants should disclose how the credential will be stored and used, define the triggering event and amount method, retain consent, identify subsequent transactions correctly, and honor cancellation. Credentials require secure storage or tokenization, lifecycle updates, transaction linking, monitoring, and customer support.
For Unscheduled Credential-on-File Transaction, collecting more sensitive data does not automatically improve security or compliance when provenance, accuracy, proportionality, and deletion obligations are ignored.
For Unscheduled Credential-on-File Transaction, end-to-end validation must therefore include both mechanism and business meaning.
An unscheduled credential-on-file transaction uses a previously stored payment credential for a charge that occurs without a fixed or regular processing date. Unscheduled credential-on-file charges require prior consent, a defined event trigger, correct transaction identification, secure credential handling, and cancellation controls.
For Unscheduled Credential-on-File Transaction, the trust decision should establish the use of a previously stored payment credential for a charge that occurs without a fixed or regular processing date and bind the result to the requested action and protected resource. Teams should test issuance, storage, validation, expiry, revocation, recovery, and privileged override for regular processing date, rather than checking only a successful request. Logs concerning the Unscheduled Credential-on-File Transaction context and regular processing date should support investigation without exposing reusable secrets or unnecessary personal data.
Key Takeaway
Unscheduled credential-on-file charges require prior consent, a defined event trigger, correct transaction identification, secure credential handling, and cancellation controls.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)