In such cases, the platform has to check the integration. If they are calling the right mandate, then they need to make sure the author of the pay-in is the owner of the mandate.
In the example below, find the API response when using the Create a Direct Debit PayIn endpoint to make a pay-in with an AuthorId different from the Mandate UserId.