A customer chooses a phone, accepts the monthly amount, and completes the order. The confirmation arrives. The warehouse releases the device. Sales rise by one.
That ordinary checkout can also contain a regulated credit decision. On 20 August 2026, the Dutch Authority for the Financial Markets, the AFM, published its action against Vodafone Financial Services. A software change had caused a required income-and-expense assessment to be skipped for several weeks in August 2022.
The AFM reported that 158 customers received credit that should not have been granted, or should not have been granted at that amount. It imposed a €375,000 fine in July 2024. The AFM also reported that the Rotterdam District Court reduced the amount to €185,000 in June 2026.
The number attracts attention. The software failure deserves more.
The sale and the credit decision
For telecom credit above €250, AFM guidance requires information about income and housing costs. The provider uses that information to assess whether the monthly repayment is affordable. The credit must also be agreed and presented separately from the subscription.
Customers experience one commercial journey. They see a phone, a subscription, and a monthly bill. The provider must recognise the separate financial decision inside that journey.
An affordability assessment is a working safeguard, not a form added after the sale. It should prevent an unsuitable agreement before a customer takes on another monthly payment. When checkout continues without it, the safeguard has disappeared at the moment it should work.
That is the practical tension for smaller companies too. Digital sales connect identity checks, pricing, eligibility, instalments, customer messages, and payment collection within seconds. Different people may own each element. The customer still passes through one door.
A founder may hear that the ordering system remained available and call the release successful. Sales continued. Customers received their products. No red warning covered the screen.
Availability, however, is not control. A process can remain commercially productive while quietly making decisions it should not make.
A release can pass and still fail
The Vodafone Financial Services matter carries extra weight because it followed earlier AFM warnings. The company received warning letters about comparable shortcomings in July 2018 and March 2022. Several months after the latter warning, the software error occurred.
Earlier warnings change the management question. Closing an incident is not enough when the same weakness can return through another route. The real test is whether the lesson reached product design, release approval, daily reporting, and the authority to pause a sales journey.
Picture a small retailer offering deferred payment through its online checkout. A developer updates the ordering logic on Friday evening. Payments still work. Confirmation emails still leave. The dashboard shows no outage.
On Monday, someone finds that an eligibility rule stopped running after the update. The questions become painfully concrete. Which orders were affected? Can the retailer identify them without joining three spreadsheets? Who can stop new agreements? What remains collectible? Which customers need contact?
Those are not compliance questions alone. Technology knows what changed. Operations sees unusual cases. Finance sees receivables. Customer service hears the confusion. Management decides whether sales continue.
A safeguard spread across five teams needs one clearly named owner.
The second cost arrives later
Vodafone Financial Services identified and reported the error, ended the breach, cooperated with the AFM, and introduced measures intended to prevent recurrence. It cancelled the affected credits while allowing customers to keep their phones. Those actions formed part of the AFM’s sanction assessment.
They also show the financial shape of a control failure. The fine is visible, but it is only one cost. Expected collections can disappear while the product cost remains. Staff must reconstruct transactions, contact customers, and explain the event. Management attention shifts from trading to remediation.
For a small company, that combination can hurt more than a formal penalty. Margin, cash, and attention leave the business together.
Return to the customer at checkout. The company may have booked a normal sale and created a normal receivable. Once the failed safeguard is found, both entries acquire a different meaning. Revenue quality partly depends on whether the agreement came through a responsible and lawful process.
That is why management information should show missing assessments, unusual approval volumes, and manual overrides quickly. A quarterly compliance presentation arrives too late. A short operational view should reach someone with authority while the affected flow is still running.
November is closer than it looks
The case concerns established telecom credit, but its timing reaches further. The AFM states that the revised Consumer Credit Directive, CCDII, is due to take effect on 20 November 2026. The Dutch framework is set to bring more deferred-payment models, including buy now, pay later services, into conduct supervision.
Businesses approaching that perimeter may start with terms, customer notices, and licence questions. Those matters count. The harder work sits inside daily operations: reliable age checks, responsible lending decisions, visible exceptions, and a clear response when a mandatory step fails.
A useful management conversation starts with one completed transaction. Can the business show which required checks ran, what data supported the decision, and what happened when a check failed? Then look at the latest release affecting checkout, pricing, or customer data. Who considered the customer-protection effect before approval?
The Vodafone Financial Services case is not a reason to distrust digital selling. It is a reason to understand it properly. A smooth journey can hide a broken safeguard, while a modest monthly payment can still become a credit obligation for a household.
Good compliance does not stand beside the sale and comment afterwards. It shapes the route the sale is allowed to take. When that route changes, management should know that the safeguard travelled with it.
Need a review of checkout controls, release ownership, and exception reports? We can identify gaps in the customer and contract flow
The data, sourcing, and analysis behind this article were conducted by Paolo Maria Pavan. AI was not used to identify sources, build the factual basis, or produce the analytical judgment contained here. AI was used only as a drafting aid. The final English text was personally reviewed, edited, and approved by Paolo Maria Pavan before publication.
