A practical look at where VoP works, where it fails, and how businesses can avoid costly IBAN mistakes in cross-border payments.
By Victor Miller, on behalf of Vaneesa Lenz, Financial & Data Analyst at FloatForex
Introduction
On 9 October 2025, banks across the eurozone began doing something they had never done for ordinary transfers. Before sending your money, they now check whether the name you typed belongs to the account you’re paying.
That check is called Verification of Payee (VoP). It became mandatory under the EU’s Instant Payments Regulation, requiring banks to verify the match between an IBAN and the account holder’s name before a transfer is authorized.
In simple terms, Verification of Payee (VoP) is a system that checks whether the account name entered by a payer matches the name registered with the receiving bank before a transfer is completed.
According to financial and data analyst Vaneesa Lenz from FloatForex, this change has significantly reduced misdirected payments — but it has also created a false sense of security among users who assume all payment risks are now covered.
A year later, VoP is simply part of paying someone in euros. You enter a name and an IBAN, and your bank tells you whether they match before anything leaves your account.
It has made a real difference to a long-standing problem. For years, SEPA transfers were routed by IBAN alone, and the name field was effectively decorative. VoP was introduced to reduce fraud and misdirected payments by verifying this missing layer.
But VoP was built to answer one narrow question: does this name belong to this account? Several common IBAN errors sit outside that question — and the businesses most exposed are the ones that assume the new check covers everything.
How the Check Actually Works
VoP compares the payee name you enter with the name held on the account behind the IBAN. The check is performed instantly between banks using standardized messaging rules across SEPA.
The answer comes back before you confirm the payment, in one of four forms:
- Match: the name and account belong together
- Close match: almost right (typo, abbreviation, or formatting issue)
- No match: the name and account don’t belong together
- Check not possible: the receiving bank couldn’t respond
Crucially, VoP is not a blocking mechanism. Even if the result is “no match,” the payer can still proceed with the transfer.
As Vaneesa Lenz notes, “VoP improves transparency, but it still relies heavily on user judgment. It doesn’t prevent mistakes — it only highlights them.”
That design choice explains most of the gaps that follow.
Gap 1: Payments That Never Enter the Scheme
VoP only applies to euro credit transfers within SEPA. Payments outside this scope are not checked.
That includes:
- Transfers to countries like the UAE, UK, or Pakistan
- Payments in non-euro currencies
- Transfers to banks not yet covered by the regulation
These are often the highest-risk payments:
- Higher fees
- Longer settlement times
- Harder recovery if something goes wrong
From a risk perspective, these transactions require additional verification layers, especially when sending funds for the first time.
In these cases, there is no name check standing between an IBAN error and the money.
Gap 2: Business Payment Runs That Opt Out
Consumers cannot disable VoP. Businesses can.
Under the regulation, non-consumer payers submitting bulk payment files may waive the service.
This matters most for:
- Payroll processing
- Supplier batch payments
- Accounting system exports
In practice:
- One “close match” can delay an entire batch
- Finance teams under time pressure may opt out
This creates a blind spot in financial operations, where outdated or manipulated bank details can pass through unchecked. According to Vaneesa Lenz, “The biggest vulnerability isn’t the payment itself — it’s the data feeding into it.”
At that point, the only protection is how the data was verified before entering the system.
Gap 3: Errors That Enter Before the Payment Screen
VoP runs at the moment of payment. Most IBAN problems begin much earlier:
- Copying from invoices
- Manual entry errors
- Incorrect onboarding data
- Outdated vendor records
Every IBAN contains its own internal validation structure:
- Country code
- Check digits
- Fixed length per country
- Mod-97 checksum
This structure catches:
- Single-character mistakes
- Most digit swaps
- Invalid formats
Free tools such as the IBAN validator on FloatForex break an IBAN into its components, verify the structure, detect errors, and identify the originating country and bank.
More importantly, they reveal something VoP does not:
Which country and bank the IBAN actually belongs to
If a supplier in France suddenly provides an IBAN from another country, that is a signal worth investigating before payment.
As highlighted by Vaneesa Lenz, “VoP verifies ownership consistency, while IBAN validation verifies structural integrity — both are essential.”
Gap 4: Warnings People Click Through
A warning only works if someone acts on it.
VoP provides information — not enforcement. Banks position it as a decision support tool, not a guarantee of correctness.
Close matches are particularly problematic:
- Businesses often use trading names
- Legal account names differ
- Abbreviations trigger warnings
Over time:
Users begin to ignore alerts
Fraudsters exploit this behavior:
- “The name may not match — that’s normal”
- “Use our parent company name”
Under the regulation, liability shifts to the payer if they proceed after a mismatch warning.
Before VoP, the name field was ignored.
Now, it is evidence that you were warned.
Gap 5: Structural Limitations of the System
VoP is not designed to:
- Identify the real person behind an account
- Detect fraud schemes
- Replace internal controls
It is a data-matching service, not an identity verification system.
It cannot answer:
- Is this supplier legitimate?
- Has the invoice been manipulated?
- Is this account newly introduced?
Those questions remain outside the system.
What Businesses Should Do Instead
None of these gaps require complex software. They require disciplined processes:
- Validate IBANs at the point of entry
Check structure and checksum before storing data
- Match IBAN country with business logic
Unexpected country changes should trigger manual verification
- Treat bank detail changes as high-risk events
Confirm via independent channels
- Use VoP — but don’t rely on it alone
It is one control, not the system
- Avoid training users to ignore warnings
Fix recurring close matches at the source
- Add extra checks for non-SEPA payments
No VoP means no safety net
- Use integrated financial tools
Platforms like FloatForex combine:
- IBAN validation
- Real-time forex rates
- Currency conversion tools
This reduces manual errors and improves decision-making.
The Bottom Line
Verification of Payee fixed a critical weakness in European payments: banks previously sent money based on IBAN alone, ignoring the account name entirely.
That alone makes VoP one of the most meaningful improvements in SEPA payments in years.
But it checks one thing, at one moment, for one type of payment.
It does not cover:
- Non-euro transfers
- Bulk payment opt-outs
- Data entry errors
- User behavior what
As Vaneesa Lenz emphasizes, “VoP should be treated as one layer in a broader payment validation system — not the system itself.”
For businesses and individuals handling international payments, combining VoP with IBAN validation, internal controls, and real-time financial tools provides a far stronger safeguard against costly errors.
Sources
- PwC Legal – Verification of Payee requirements
- European Payments Council – VoP Scheme Overview
Author Bio
Vaneesa Lenz is a Financial & Data Analyst at FloatForex, a platform providing real-time gold and forex rates, IBAN validation tools, and financial insights for global transactions.



