Why VoP exists
Banks traditionally checked only that an account number was well formed. The recipient name was never compared with the account owner. That is why invoice fraud, where a criminal changes the account number on an invoice, and a simple typing error could send money to the wrong account without any warning.
The EU Instant Payments Regulation (Regulation (EU) 2024/886) changed this. It requires banks in the euro area to offer Verification of Payee for all euro SEPA credit transfers from 9 October 2025, both ordinary transfers and instant payments, which arrive within seconds. Banks in EU countries outside the euro area have until 9 July 2027. The European Payments Council, the body that sets common rules for euro payments, defines how banks answer each other's checks, so a result means the same thing at every bank.
How a check works
Before you approve a payment, your bank asks the recipient's bank whether the name you entered matches the account number. The answer arrives within seconds and is always one of four results:
- Match: the name and account number belong together.
- Close match: the name is nearly right, for example a spelling difference or a missing 'Oy'. The recipient's bank tells you the name actually on the account, so you can compare and decide.
- No match: the name does not belong to that account number.
- Verification not possible: the recipient's bank cannot answer, for example because it does not yet offer the service. Treat this as 'unknown', not as a pass.
What the result means for you
A check never blocks a payment on its own. You decide whether to proceed regardless of the result. If you proceed after a No match and the money ends up in the wrong account, the payer rather than the bank usually carries the loss. In practice that means your company, not the bank, loses the money. Only if the bank failed to run the check properly must it refund you. That is why the result should be shown clearly to the person approving the payment, and the decision recorded.
What VoP does not do
VoP compares only the name and the account number. It does not tell you whether an invoice is genuine or whether the recipient is who they claim to be. A Match is not a promise from the bank that the payment will go through, and it is not proof that a payment was made. The result applies to the moment of the check: account details can change later. Using the check requires that your company has an agreement with its bank that covers the VoP service.
Paying in batches: what changes for companies
Companies usually pay in batches: the finance system creates one payment file that can contain hundreds of payments. The regulation gives companies the right to opt out of the check for payment files sent as a batch. In practice the Finnish banks offer the file check as a separate, optional service, so a company that does not use it has opted out. The risk of a wrong payment then stays with the company.
Nordea, OP and Danske Bank all offer VoP to business customers, but each does it differently. OP takes a separate check request in the same format as the payment file and answers with a result report; the actual payment file is sent afterwards. Nordea checks the file through a separate service, and your software fetches the result afterwards. Danske Bank checks each recipient one at a time, currently as a pilot for customers in Finland and Ireland. The four results are the same, but the request format, limits and agreements differ.
How ISECure runs the check for you
Processing API makes the check part of preparing a payment file. Your software selects the bank and country, enters the payment details and asks for the payees to be verified. ISECure sends the request to the bank under your company's bank agreement and keeps each result attached to the exact set of payments that was checked, so nothing can change after the check without being checked again. A person reviews the Close match and No match results, corrects the payee details where needed, and then approves the file.
- One result model for Nordea, OP and Danske Bank payments, even though the banks' technology differs.
- Each result stays attached to the payments it was checked against. Change a payment and it is checked again.
- A person reviews the exceptions before the file is released to your system.
- Processing API prepares and checks the payments. Sending them to the bank, and the bank's own authorisation of the payment, stays in your own system exactly as today.
Glossary
- Payee: the person or company that receives the payment.
- IBAN: the international account number used in SEPA payments.
- SEPA credit transfer: a euro transfer between accounts in the SEPA area, which covers the EU and EEA countries and several other European countries such as the United Kingdom and Switzerland. The VoP obligation applies to banks in the EU.
- Payment service provider (PSP): a bank or other institution that moves payments.
- Instant Payments Regulation: Regulation (EU) 2024/886, which made VoP mandatory.