• Sep 03, 2026
  • 11 min read

How Does Verification of Payee Work?

See how Verification of Payee works, who must comply, and what it means for banks, payment service providers, and everyday payments.

A finance team approves an invoice from a supplier it has paid every month for three years. Nothing on the invoice looks wrong. But a fraudster has swapped the supplier's bank details for an account they control, and the moment the payment is authorized, the money lands with the fraudster instead. On an instant rail, it's gone in seconds.

This is authorized push payment (APP) fraud, and it's now one of the costliest forms of financial crime. In the UK, for example, APP scams caused £576.4 million ($781 million) in losses in 2025, accounting for approximately 45% of all payment fraud losses.

One factor increasing opportunities for APP fraud is the growing popularity of instant payments. More than 70% of jurisdictions worldwide now have some form of instant payment system, while Visa predicts 58% of ecommerce transactions will use alternative payment methods, including real-time payments by 2028. In Brazil, for example, the central bank's Pix instant payment platform is now used for 54.7% of payment transactions, processing 79.8 billion transactions worth R$35.36 trillion in 2025 – a 33.6% year-on-year increase.

The instantaneous nature of these payment methods offers convenience for buyers and retailers, but it also means fraud attempts must be spotted instantly, too.

Verification of Payee (VoP) helps prevent misdirected payments and certain forms of APP fraud, as it verifies that the recipient’s name matches the account details provided before a transfer is authorized. If the details do not match, the payer can be alerted before the money is sent. 

What is Verification of Payee?

Verification of Payee is a check performed before a transfer is authorized. The payee information provided by the payer is checked against information associated with the destination payment account. In the most common case, this involves comparing the payee name entered by the payer against the name associated with the specified account. The result indicates whether the details match, closely match, do not match, or cannot be verified, allowing the payer to review any discrepancies before deciding whether to proceed.

VoP should not be understood as verifying that a payee is trustworthy or establishing the payee’s identity in the same way as a KYC or KYB check. It verifies specified payee data against information associated with a payment account and provides the resulting match information to the payer before payment authorization. 

VoP generally uses an account’s International Bank Account Number (IBAN) to check the name against the account, so the term ‘IBAN-name check’ is also commonly used for the technology.

However, name-to-IBAN matching is only the most familiar VoP use case. The EU legal requirement under Article 5c is broader. For legal persons, verification may also use other data elements that unambiguously identify the payee, such as a fiscal number, a European Unique Identifier (EUID), or a Legal Entity Identifier (LEI).

The concept isn't new. The UK's Confirmation of Payee (CoP) scheme has been in place since 2020, and the Netherlands first introduced IBAN-name checking even earlier, in 2017. Brazil offers another example of the growing role of payee-name verification in instant payments. Its Pix system uses the Central Bank's DICT directory to link payment keys to account holder information, and since July 2025, Pix participants have been required to validate the name associated with a Pix key against the holder's CPF or CNPJ records.

What’s changing is the move from individual national initiatives to broader regulatory requirements. 

Verification of Payee vs. Confirmation of Payee: What’s the difference?

The two terms get used interchangeably, and functionally that is close to fair. Both return the same match, close-match, and no-match outcomes, and both sit in the same place in the payment flow.

The differences are institutional and technical. CoP is the UK's industry-led payee name-checking service, built under the Payment System Regulator's direction and Pay.UK scheme rules. VoP is the EU-wide, legally mandated equivalent introduced under the IPR, covering every payment service provider(PSP) offering SEPA credit transfers, anchored in binding legislation, and standardized through the European Payment Coucil's Rulebook. The technical split matters for anyone integrating both: CoP checks payee details against a UK sort code and account number, while VoP works from the IBAN.

How does Verification of Payee work step by step?

VoP occupies the gap between a payer confirming details and the transfer being sent. It is a real-time exchange between the payer's PSP and the payee's PSP.

  1. Data entry. The payer enters the payee's account identifier, usually an IBAN, along with the payee's name.
  2. Verification request. The payer's PSP, known as the requesting PSP, sends a real-time verification request to the payee's PSP, the responding PSP. Under the EPC Verification of Payee Scheme, that exchange runs over API-based infrastructure using standardized data elements, including ISO 20022 resource elements.
  3. Record check. The responding payment service provider compares the submitted name against the name it holds.
  4. Response returned. Within seconds, the responding PSP confirms a match or close match, or returns a no match or a "verification not possible".
  5. Payer decision. The requesting PSP surfaces the result, and the payer proceeds, corrects the details, or cancels.

The timing is tight. The EPC's VoP scheme caps the verification exchange at five seconds, with a response in one second or less preferred where possible. That budget is separate from the EU's ten-second execution requirement for instant euro transfers, which starts once the payment order is received. The service also has to be available around the clock. Manual review is not an option at that cadence, which is why VoP only works as automated, API-driven infrastructure.

The concept behind routing and verification mechanisms

VoP relies on infrastructure that can quickly route a verification request to the correct responding PSP among thousands of participating institutions. 

In the EU, the European Payments Council's VoP Scheme Rulebook standardizes message formats, timing, and response codes. This means a bank in Germany and a payment provider in Portugal can exchange requests directly. The Eurosystem has also built a shared VoP infrastructure based on solutions originally developed by Banco de Portugal and Latvijas Banka, providing smaller PSPs with a route to compliance without building proprietary systems.

Underpinning the technical messaging is ISO 20022, the international standard for financial messaging. The EPC's VoP inter-PSP API specifications use ISO 20022 resource elements to structure relevant payment and verification data consistently across participating PSPs.

How VoP changes the experience for payers and consumers

For the person or business sending money, VoP adds one screen. After the account details go in, a message confirms whether the name matches, closely matches, or does not match what the receiving bank holds, or that the check could not be completed. It is friction. It is also reassurance that the money is going where it is supposed to.

When a mismatch appears, three routes open up: cancel, correct the details (the common case of a mistyped name), or proceed anyway on the basis that the payment is legitimate.

That third option stays open by design. Article 5c(7) requires the payer's PSP to warn that authorizing the transfer may send funds to an account not held by the intended payee, and to explain what disregarding the warning means for PSP liability and for refund rights. Where the PSP has met its VoP obligations, Article 5c(8) protects it from liability for execution to an unintended payee caused by an incorrect unique identifier, in line with Article 88 of PSD2. Where a PSP or payment initiation service provider fails to comply with its VoP obligations and that failure produces a defectively executed transaction, the payer's PSP has to refund the amount without delay.

Proceeding past a warning, in other words, does not automatically hand liability to the payer. Compliance on the PSP side is what determines where liability sits.

The role of the requesting and responding PSP in Verification of Payee

A VoP check normally involves two parties, though a payment initiation service provider or a Routing and/or Verification Mechanism may sit in the chain as well.

The requesting PSP is the payer's own bank or provider. It captures the payee details, sends the verification request, and relays the result and any mismatch warning back before authorization.

The responding PSP holds the payee's account. It compares the submitted payee information against what it has on file and returns the applicable result inside the required window.

This puts a lot of weight on account-holder records. A name change after a marriage, a corporate restructuring, a legal entity that trades under a different name: any of these can produce a mismatch on a perfectly legitimate payment, and each false mismatch costs a customer conversation the PSP did not need to have.

What data requesting and responding PSPs must provide for VoP

The core of a VoP check is usually the payee's account identifier, such as an IBAN, plus the payee's name. Article 5c contemplates more than that. For legal persons, where the payer's payment-initiation channel supports it, and the information is available in the payee PSP's systems, verification may instead run on an identifier that unambiguously identifies the payee: a fiscal number, an EUID, or an LEI.

The Regulation also covers accounts maintained on behalf of multiple payees. Additional information may be supplied to identify the intended payee, and the relevant PSP has to confirm whether that person or entity is among the payees the account is maintained for.

Responding PSPs carry the maintenance burden: accurate, current account-holder names, with defensible handling of legal-entity names against commonly used trading names, joint account holders, and post-marriage or post-restructuring changes. Get this wrong and VoP stops being a reliable fraud signal at all.

Both sides also need audit trails of requests and responses, which is what makes dispute resolution possible when a payer challenges a no-match result.

How do requesting and responding PSPs benefit from VoP?

VoP helps requesting PSPs reduce payment fraud losses and exposure to misdirected-payment and APP-fraud scenarios, as it cuts the number of payments sent to mismatched account details. This also lowers dispute-handling costs and can improve customer retention.

Responding PSPs may benefit from fewer erroneous-payment investigations, recall requests, and related operational work where VoP helps identify incorrect beneficiary details before a credit transfer is authorized.

Both sides also gain from shared fraud intelligence. As more PSPs participate, patterns in mismatch responses become a useful early-warning signal for emerging fraud campaigns, supporting better fraud prevention.

What rules must PSPs follow under VoP guidelines?

Guidelines for VoP and equivalents (such as CoP in the UK) vary by jurisdiction.

Key rules for Payment Service Providers under the EU Instant Payments Regulation, for example, include:

  • PSPs must provide the Article 5c verification service to payment service users free of charge. The payer’s PSP must perform the verification immediately after the payer provides the relevant payee information and before the payer is offered the opportunity to authorize the credit transfer. The service must be available regardless of the payment-initiation channel used.
  • Where the relevant payee information does not match, the payer’s PSP must notify the payer and warn that authorizing the credit transfer could result in the funds being transferred to an account not held by the intended payee. The verification process must not, however, prevent the payer from authorizing the credit transfer.
  • Proceeding after a mismatch does not automatically shift liability to the payer. PSPs must explain the implications for their liability and the payer’s refund rights. Where VoP obligations have been met, the Regulation provides specific protection for PSPs against liability for payments sent to an unintended payee due to an incorrect unique identifier.
  • If the payer’s PSP does not receive confirmation of receipt of funds in the payee’s accounts within 10 seconds, they must reimburse the payer’s account.
  • PSPs must screen their users against sanctions lists detailing the subjects of targeted financial restrictions. Whenever new targeted financial restrictive measures come into force, PSPs must immediately verify if any of their users are included in these measures.

PSPs must also follow the EPC's VoP Scheme Rulebook, which governs response formats, timing, and data-handling.

If an obliged PSP is found to have breached the provisions of the EU’s IPR, penalties (including fines) can be imposed by the competent authorities or judicial authorities in the relevant member state. These penalties can be applied both to PSPs and members of their senior management or management body. For PSPs, the maximum fine is at least 10% of their total annual net turnover in the previous year, while for individuals it is €5 million (or the equivalent for member states with other currencies).

How is adoption of VoP progressing across Europe?

PSPs in EU member states that use the euro as their currency were required to offer VoP from October 9, 2025. For member states outside the Eurozone, PSPs have until July 9, 2027 to meet this requirement.

Challenges Verification of Payee is facing in the EU

Rolling out a real-time payee-verification framework across multiple countries, languages, payment channels and PSP systems was never going to be straightforward. Key challenges associated with implementing VoP across the EU include:

  • Data formatting. Names with diacritics or non-Latin transliterations can trigger false "close match" or "no match" results on entirely legitimate payments. Businesses trading under a name different from their legal entity can also experience this problem. Systems must be configured to account for these issues, and users should be educated on the steps they need to take to minimize potential problems.
  • Resource gaps. Smaller PSPs and EMIs can struggle with integration costs. This can cause issues with key technical requirements of VoP compliance, such as connecting to shared directories and adopting ISO 20022 messaging.
  • Timeline fragmentation. PSPs located in euro-area EU member states have been subject to the VoP requirement since October 9, 2025, while PSPs located in non-euro EU member states have until July 9, 2027. During this transitional period, a VoP check may not always be available where the relevant counterparty PSP is not yet required to participate in, or is not yet reachable through, the VoP framework. 
  • Lack of coverage for non-euro payments. Payments in other currencies are outside the scope of the EU’s euro-transfer requirement.

Data privacy and GDPR requirements impact

To verify a payee's name, the requesting and responding PSPs will need to share the payee’s personal data with one another. This process complements existing account verification checks and can raise concerns about data privacy and regulatory compliance, such as the EU’s General Data Protection Regulation (GDPR). 

Under data protection rules, organizations must have a lawful basis for sharing and processing someone’s personal data. In the case of VoP, this lawful basis generally rests on a combination of legal obligation (e.g., because VoP is mandated by the IPR in the EU) and a legitimate interest argument (that sharing the data is necessary to prevent fraud).

The principle of data minimization should be integral to VoP checks. This means PSPs should exchange only the minimum personal data needed to verify a payee (i.e., an account identifier and a name), rather than full account or transaction details. Responding PSPs are expected to protect this data from misuse and retain verification logs only for as long as necessary for compliance or dispute resolution.

For PSPs with branches outside the European Economic Area, cross-border considerations must also be taken into account. In such cases, verification data transfers may need to meet GDPR's international transfer rules. 

How payee verification is being adopted in other regions 

Payee-verification mechanisms are being adopted in a growing number of jurisdictions. The following are some key examples. 

Australia

Confirmation of Payee (CoP) was introduced in Australia in July 2025. As of July 2026, CoP is offered by more than 100 financial institutions across the country and has been used over 150 million times.

United Kingdom

Confirmation of Payee is the UK’s payee name-checking service. It was launched in 2020 and initially adopted by the six largest UK banking groups before the Payment Systems Regulator (PSR) directed an expansion covering roughly 400 PSPs by October 2024.

United States

Payee Name Verification is an optional service offered by the Federal Reserve Financial Services for institutions using its FedLine solutions. However, there is no legal requirement to use the technology in the US. Financial institutions are legally entitled to rely solely on the account number provided by a payer even if the name provided does not match that on the payee’s account, as set out in Section 4A-207 of the Uniform Commercial Code.

What are the benefits of VoP for businesses?

For banks and PSPs, VoP does a few jobs at once. It satisfies a regulatory requirement, and it cuts certain fraud risks. It also stops expensive payment errors before they happen. For businesses making or receiving account-to-account payments, it buys confidence that funds are reaching the intended recipient.

The reimbursement exposure is what makes the fraud reduction concrete. Institutions are frequently on the hook for reimbursing APP fraud victims, and in the UK the PSR's mandatory reimbursement requirement, in force since October 2024, has moved real money: £316 million (approximately $428 million) repaid to victims in the first 18 months, representing 88% of the money lost to APP scams. Recovering that from the scammers is usually impossible, so the cost stays with the institution.

Misdirected payments also create hidden costs. Each one can require extra work to investigate and resolve, adding administrative overhead for payment providers.

There’s also the trust argument. Effective fraud prevention keeps existing customers and attracts new ones, and it makes customers more willing to use instant payments in the first place.

Is VoP the ultimate fraud prevention measure?

No. VoP is not a fraud silver bullet, and treating it as one is the fastest way to be disappointed by it.

The check confirms that a name and an account belong together. It cannot tell whether the recipient is trustworthy, or whether the customer sending the money is being manipulated. A payment can pass a VoP check cleanly and still be fraudulent: money mules, fraudulent businesses, and scammers using their own correctly named accounts all clear it without a flag. So does any case where a fraudster talks the victim into ignoring a mismatch warning.

Social engineering is where this bites hardest. A romance scam or an imposter scam produces a perfect match, because there is no name discrepancy to catch. US consumers lost over $3.5 billion to imposter scams alone in 2025, according to the Federal Trade Commission, and VoP does nothing for any of it.

That’s why VoP belongs in a stack rather than on its own, alongside real-time transaction monitoring, behavioral analytics, device intelligence and fraud network detection, all of which can flag a fraudulent payment even when the payee name checks out perfectly.

Verification of Payee: What comes next? 

During 2026, the VoP operational framework in the EU is continuing to evolve. In particular, version 1.1 of the EPC VoP Scheme Rulebook and related API specifications will become effective on September 20, 2026, incorporating changes and clarifications arising from the initial deployment of the scheme.

The next major regulatory milestone is July 9, 2027, when PSPs located in EU member states whose currency is not the euro must comply with the Article 5c VoP requirements. This will extend the regulatory requirement across the remaining EU member states within scope.

Today, the EU is setting the most prescriptive regulatory model, but the broader trend is international. More payment markets are introducing account-name verification to reduce fraud and misdirected payments, either through regulation or industry-led schemes. Australia is the latest major example. Similar initiatives are being developed or piloted in markets including India, Canada, Singapore, Hong Kong, and South Africa. Payee verification is likely to become a more common payment-security control globally, even if adoption timelines and regulatory requirements differ by market.

Verification of Payee FAQ

  • What is the purpose of VoP?

    Verification of Payee aims to reduce fraud and human error in credit transfers by confirming, in real time, that the account a payer is about to send money to genuinely belongs to the person or business they intend to pay. VoP can catch accidental misdirected payments and fraudulent attempts to misdirect funds before any money leaves the payer's account.

  • Is Verification of Payee applicable to all payment types?

    No. Which payments require VoP (or equivalent protocols) will depend on the jurisdiction. For example, under the EU’s IPR, VoP is required for standard and instant SEPA credit transfers in euros, but not for card payments, direct debits, or cash. Non-SEPA and non-euro payments generally rely on separate mechanisms, such as the UK's Confirmation of Payee.

  • Are dedicated regulatory compliance processes needed for VoP?

    Yes. Although adopting a third-party VoP technology solution can make meeting compliance obligations easier, each PSP remains legally responsible for its own compliance obligations. Financial institutions must have effective internal policies and controls, including staff training and ongoing monitoring and reporting, to meet obligations such as the IPR's mandatory compliance reporting introduced in 2026.

  • What is authorized push payment fraud?

    Authorized push payment (APP) fraud is the problem VoP was built to address. It happens when a victim is deceived into authorizing a payment to a fraudster’s account that masquerades as the account of someone the victim intended to pay.