Your bank checks the payee name now. What that covers.
Since 9 October 2025, banks in the euro area have been required to check the payee’s name against the IBAN before you confirm a credit transfer. You type the account number, and your bank tells you whether the name on that account matches the name you entered.
This is a genuinely good control, and it answers a question this site cannot: does the account actually belong to them? No public register in Europe maps a bank account to its owner — Poland is the single exception, and only for VAT-registered businesses. Everywhere else, your own bank at the moment of payment is the only place that answer exists.
So use it. If Verification of Payee says the name does not match, stop, whatever any other check said.
What follows is the other half: the questions it was never designed to answer.
What a name match does not tell you
Verification of Payee compares two strings at the receiving bank. It is a check on the account, not on the business behind it. A perfect match is entirely consistent with all of the following.
The company is in liquidation. A company being wound up keeps its bank account and its VAT number, often for months. The name matches. The VAT number resolves. The invoice looks ordinary, and the money goes to an insolvency estate rather than to a going concern.
The company was struck off the register. Same picture, worse ending. In Greece, Bulgaria and Latvia a struck-off company’s VAT number frequently still validates in the EU’s own VIES service, because deregistration and strike-off are different processes run by different authorities on different timetables.
The company is on the EU sanctions list. The name match confirms the account belongs to the entity you named. It says nothing at all about whether you are permitted to pay them.
The email asking for payment was forged. The commonest invoice fraud is not a wrong account number. It is a real supplier, a real account, a real invoice — sent from a compromised or lookalike mailbox, with the bank details swapped for the attacker’s. If the attacker has opened an account in a name close enough to the supplier’s, the name check can pass. Whether the sending domain can be forged at all is a separate question, and it is answerable in advance.
They are a company you have never dealt with. Verification of Payee tells you the account belongs to whoever you typed. It cannot tell you that whoever you typed is real, trading, or the party that actually did the work.
Where the rule does not reach yet
Two gaps matter more than they first appear.
Outside the euro area, providers have until 9 July 2027. Payment service providers in member states whose currency is not the euro get a longer deadline. That covers Denmark, Sweden, Poland, Czechia, Hungary and Romania. If you are paying a supplier there, or paying from an account there, the check your euro-area counterparts already rely on may simply not exist yet.
Domestic transfers in a national currency are outside the regulation entirely. The requirement attaches to credit transfers in euro. A Polish business paying a Polish supplier in złoty — the overwhelming majority of Polish invoices — is not covered by it at all, and will not be in July 2027 either.
Poland is worth singling out, because the gap and the remedy sit in the same country. It is the only EU member state that publishes the bank accounts of VAT-registered businesses, on the Ministry of Finance white list. Paying an unlisted account above PLN 15,000 costs the payer the corporate-tax deduction and can create joint liability for the supplier’s unpaid VAT. So a Polish account number can be checked against its owner today, by anyone, without a bank — which is exactly the check Verification of Payee will eventually provide and currently does not.
How the two fit together
They answer different questions, in a sensible order.
| Question | Answered by |
|---|---|
| Does this account belong to the payee I named? | Your bank, at payment — or the white list, in Poland |
| Is this business registered for VAT? | VIES, live |
| Is it trading, or in liquidation, insolvent, struck off? | The national company register |
| Is the name on any EU sanctions list? | The consolidated list |
| Could the email that sent this invoice be forged? | The sending domain’s SPF and DMARC records |
Only the first row is Verification of Payee’s. The rest have to happen before you get to the payment screen, because by then you have already decided to pay — the bank is checking your typing, not your judgement.
The practical shape of it: check the supplier when the invoice arrives, and let the bank check the account when you pay. Neither replaces the other, and the second one arrives too late to change your mind about the first.
The one control that outranks both
If a supplier’s bank details have changed, telephone them on a number you already had — from an earlier invoice, your own records, or their website typed in by hand. Never a number from the email that announced the change.
This is the control that catches the attack neither system sees, and it is the reason this site never gives a single “safe to pay” verdict. When a real supplier’s mailbox has been compromised, every automated check passes: the company is real, the VAT number is valid, the domain is properly authenticated, and — if the attacker was careful — the payee name matches too. A voice on a known number is what breaks that chain.
Run a vendor check →Registry, IBAN, EU sanctions and sending domain, in one pass. Free, no signup.