CVRP: commercial variable recurring payments explained
In this guide, we cover what commercial variable recurring payments are, how the UK rollout is structured, and what this could mean for marketplaces in 2026.


Get fresh insights, monthly
Stay up to date with our latest news and insights.
Commercial variable recurring payments, or cVRP, let a business collect payments of varying amounts from a customer's bank account. The customer sets the terms once, through open banking. There is no need to authorise every payment individually after that. The UK Payments Initiative launched the first live commercial VRP scheme on 2 June 2026. It is the country's first new payment scheme since Faster Payments launched in 2008.
What is cVRP?
Open banking already supports two payment types many people have used without knowing the term. A single immediate payment moves money instantly for a one-off purchase. It gets authenticated freshly each time it happens. Sweeping variable recurring payments let someone move money between their own accounts instead. That is useful for topping up savings, but it cannot pay a business directly.
cVRP sits between the two. A customer authenticates once, when setting up a mandate with a business. From that point, the business can collect recurring payments within agreed limits, without repeated authorisation for each one. Limits typically cover a maximum amount per payment and a maximum per month. An expiry date sits alongside them, all visible and editable inside the customer's banking app.
This combination gives cVRP a genuinely different profile. It carries strong authentication at setup, similar to a one-off open banking payment. It also offers ongoing convenience, similar to a card saved on file or a direct debit mandate already in place.
How cVRP compares with direct debit and card on file
Settlement speed is the clearest practical difference between the three. A cVRP payment settles within seconds of being initiated, where a direct debit typically takes three working days to clear. For a business managing cash flow, that gap can matter more than it first appears.
Cancellation works differently too. A customer can cancel a cVRP mandate instantly, from inside their own banking app. They are not waiting on a business to process a cancellation request first. This hands customers more direct control over their own money. It also means a business can lose a recurring customer the moment they act on it.
Card on file relies on stored card details, which carry their own fraud and data breach exposure. cVRP mandates never store a card number anywhere. Every payment instead routes through the customer's own bank, using open banking rails rather than card networks.
None of this comes with card-equivalent protections yet, though. Chargebacks and Section 75 cover do not currently have a cVRP counterpart, a gap covered later in this guide.
Why cVRP is being introduced
The UK government's National Payments Vision set out an ambition for open banking. It should become a genuine alternative to cards at checkout. Open banking payments have grown quickly since launch, but adoption at the actual point of sale has lagged behind. Most usage so far has centred on one-off payments and personal finance tools, rather than everyday commerce.
cVRP is the piece meant to close that gap. It combines strong authentication at setup with card-like convenience afterwards. That addresses the two things merchants and customers say matter most: lower fraud risk, and less friction at checkout. Success depends heavily on how quickly banks build the supporting infrastructure. It also depends on the commercial model landing in a way that works for every provider in the chain.
The UK rollout: Wave 1 and Wave 2
The Joint Regulatory Oversight Committee set out a blueprint for a multilateral cVRP framework back in 2024. The goal was a shared rulebook for providers, rather than separate negotiations with every bank. The UK Payments Initiative now operates that scheme, backed by 31 banks and fintechs.
Wave 1 covers regulated and trusted sectors first. This includes utilities, rail, government services, registered charities, and regulated financial services firms. These sectors already carry established consumer protection frameworks. That made them a lower risk starting point for a genuinely new payment scheme.
Wave 2 is where marketplaces and platforms come into scope. Industry discussions point to subscriptions, general ecommerce, marketplace settlements, and usage-based billing as likely applications. UK Finance is leading work on the commercial model for these use cases. That work is expected to progress through the second half of 2026, though final specifications are not yet published.
What cVRP could mean for marketplaces and platforms
Recurring billing on a marketplace today typically runs on stored card details. These get authorised once under PSD2, then charged automatically on a set schedule. cVRP offers a genuinely different rail for the same job. It settles faster, stores no card data, and gives the buyer a mandate they can see and manage directly.
Marketplace settlements sit explicitly inside the Wave 2 discussion, alongside subscriptions and usage-based billing. That makes cVRP worth watching for any platform already running variable recurring charges. A usage-based seller fee or a subscription tier that changes month to month are both natural candidates.
None of this is available for general marketplace use yet. Wave 2 specifications remain under development. Adoption depends on the commercial model UK Finance and the banks eventually settle on. A platform building recurring billing today should treat cVRP as a rail to monitor. It is not yet one to build around before general availability arrives.
Regulatory considerations still being worked through
Consumer protection is the main open question ahead of a wider rollout. Card payments carry established protections, including chargebacks and Section 75 cover on credit transactions. Open banking payments currently rely on the Payment Services Regulations 2017 and the Consumer Rights Act 2015 instead. Neither gives open banking an equivalent bespoke protection model of its own yet.
The Multilateral Agreement
The Multilateral Agreement underpinning the scheme aims to close that gap. It sets shared rules on liability, dispute resolution, and technical standards across every participating provider. Until that framework matures for Wave 2, marketplaces evaluating cVRP should treat consumer protection as a live area of development. It is not yet a fully solved problem.
PSD2
PSD2 remains the baseline regulatory framework behind every open banking payment in the meantime. This includes strong customer authentication at the point a mandate gets set up. Ryft's guide to PSD2 covers this framework in more detail. It sits alongside a separate guide to how PSD3 will change it as it comes into force.
Why this matters beyond the payment itself
A payment mandate a customer can see and edit changes the relationship between buyer and platform. Today, cancelling a recurring card payment usually means contacting support or digging through account settings. A cVRP mandate sits inside the customer's own banking app instead, visible alongside every other regular payment they hold.
For marketplaces, that visibility cuts both ways. Buyers get more confidence committing to a recurring purchase or subscription, since exiting it stays simple. Platforms lose some of the friction that currently slows a customer down before they cancel. That puts more weight on the underlying product earning its renewal each month.
Pre-payment balance checks add a further wrinkle worth watching. A cVRP payment can be verified against available funds before it is sent. That reduces failed payments compared with a card that has expired, or a direct debit that bounces on the day. It could meaningfully cut failed payment rates once Wave 2 reaches marketplace billing.
Where this leaves marketplaces today
Ryft's own recurring billing functionality runs on stored card details under PSD2 today. That remains the rail most marketplace subscription and commission billing relies on right now. cVRP is a genuinely different infrastructure decision, not a feature to bolt onto existing card based billing.
For a marketplace or platform planning ahead, the practical step is tracking Wave 2's commercial model as it gets finalised. Committing engineering time before the specification settles is premature. Contact us to talk through recurring billing and split payment infrastructure for your platform today.
Frequently asked questions
cVRP lets a business collect recurring payments of varying amounts from a customer's bank account. The customer sets limits once through open banking, rather than authorising each payment separately. It combines the strong authentication of a one-off open banking payment with the convenience of a card on file. The UK Payments Initiative launched the first live scheme on 2 June 2026.
cVRP settles within seconds, where direct debit typically takes three working days to clear. Customers can also cancel a cVRP mandate instantly inside their banking app, rather than submitting a request. Both collect recurring payments, but cVRP runs on open banking rails rather than the Bacs scheme.
Marketplace settlements sit inside Wave 2 of the UK rollout, alongside subscriptions and usage-based billing. This is expected to progress through the second half of 2026. UK Finance is still finalising the commercial model, and general marketplace availability depends on that work completing first.
More Blogs

How to implement split payments: complete guide for marketplace platforms

Payment solutions for beauty and wellness booking platforms

Fashion marketplace payments: managing multivendor commission splits
Let's talk about payments
Our payment experts are here to talk through your requirements and set you up for success.
