Banking has changed dramatically. We have moved from cheques and physical withdrawal slips to debit cards, mobile banking, banking applications, electronic transfers and increasingly automated financial systems. But one fundamental principle has survived technological change:

A bank requires proper authority before debiting a customer’s account.

The Supreme Court of Zambia’s decision in Barclays Bank Zambia PLC v Chipepa [2017] ZMSC 38 remains an important reminder of that principle.

The Transaction

Ms Chipepa used her debit card to purchase an airline ticket. She entered her PIN and authorised the transaction. Her account was debited. There was nothing unusual about that. The problem arose approximately one month later when the same amount was debited again, even though she had not made another purchase or authorised another transaction. The dispute eventually reached the Supreme Court. The important question was not simply whether the bank’s electronic system had processed the transaction.

It was:

Where was the customer’s authority for the second debit?

The Mandate Matters

A banking mandate defines the authority under which the bank may act in relation to the customer’s money. In a traditional banking relationship, authority might have been evidenced through a signature or cheque.

Today it may involve:

  • PINs;
  • passwords;
  • banking applications;
  • electronic approvals;
  • biometric authentication;
  • authorised corporate signatories.

Technology changes the method of authentication. It does not eliminate the underlying requirement for authority. The Supreme Court recognised that the original transaction had been authorised. The duplicate transaction had not. Authorising one payment did not create continuing authority to make another.

The Bank’s Duty of Care

The case also reminds financial institutions that executing customer instructions involves an obligation to exercise reasonable care and skill. This is increasingly important in an era of automated payments. Banks process enormous numbers of transactions every day. Automation is commercially necessary. But automation cannot become an answer to the question:

“Why did this money leave the customer’s account?”

When a disputed transaction occurs, the audit trail should allow the institution to establish the authority relied upon.

The Modern Corporate Application

The principle extends beyond debit cards. Consider a company whose banking mandate requires two directors jointly to authorise payments. One director gives an instruction. The fact that the bank knows that director personally cannot ordinarily substitute for the agreed mandate. Corporate mandates exist precisely to define and limit authority.

Businesses should therefore regularly review banking mandates when:

  • directors change;
  • employees leave;
  • signing powers change;
  • transaction limits change;
  • corporate structures change.

There Was Also a Damages Lesson

Ms Chipepa established an infringement of her rights. But she did not establish sufficient evidence to justify substantial damages. The Supreme Court therefore awarded nominal damages. That gives litigators another important lesson:

Liability and quantum are separate questions.

Proving that a defendant acted unlawfully does not automatically prove the financial value of the resulting loss.

The DAC View

At Dzekedzeke and Company, we believe Chipepa has become more relevant—not less—as banking becomes increasingly digital. AI, automation and instant payments will make financial systems faster. But the legal architecture must continue asking an old-fashioned question:

Who authorised the transaction?

The future of banking may be digital.

The principle of authority remains fundamental.

For legal advice on banking disputes, unauthorised transactions and commercial law, contact Dzekedzeke and Company.

www.dzekedzekeandco.com

Based on Barclays Bank Zambia PLC v Chipepa (Appeal No. 131 of 2014) [2017] ZMSC 38.