Verification of Payee (VoP): what the Instant Payments Regulation requires

Vasco Alexandre
September 22, 2026

Verification of Payee (VoP) is the check a payment service provider must run before a payer authorises any euro credit transfer: the payee's bank compares the name the payer typed with the name attached to the IBAN, and the payer sees whether they match. It has been mandatory in the euro area since 9 October 2025, for instant and standard transfers alike, and it reaches PSPs in the other member states on 9 July 2027.
The rule sits in Article 5c of Regulation (EU) No 260/2012, inserted by Regulation (EU) 2024/886, the Instant Payments Regulation. It reads like a payments rule. It is also an onboarding rule in disguise: VoP can only match a name the payee's bank holds, and for a company that name is often not the one its customers know.
What is Verification of Payee?
VoP is a name-against-account check performed "immediately after the payer provides relevant information about the payee and before the payer is offered the possibility of authorising that credit transfer", whatever the channel (Article 5c(1)). It must be free of charge (Article 5b(2)). The Commission confirms it covers "every credit transfer, including instant and non-instant credit transfers", with no exemption for saved payees (Commission Q&A on the IPR, answers 93 and 94).
For a company, the "name of the payee" means "the commercial or legal name" (Article 2(1d)). Either one counts. That clause is the whole onboarding story.
What are the four VoP outcomes?
The Regulation names three situations: the name and IBAN match, they "almost match" or they do not match. The EPC Verification of Payee scheme rulebook, the interbank standard banks actually run (version 1.1, effective 20 September 2026), adds a fourth:
| Outcome | What the payer sees |
|---|---|
| Match | Confirmation, nothing else |
| Close match | The name actually held for that IBAN, so the payer can correct it |
| No match | A warning that the money may go to an account not held by the intended payee |
| Verification not possible | A warning, for example when the payee's bank does not answer within 5 seconds |
On a no match, the payer can still pay: verification "does not prevent payers from authorising the credit transfer" (Article 5c(5)). But they have been warned, and that shifts the liability.
Who is liable when VoP goes wrong?
If the payer's PSP fails to run the check and the transfer goes to the wrong account, it "shall without delay refund the payer" (Article 5c(8)). If the failure sits with the payee's PSP, that PSP compensates the payer's PSP. If the check ran and the payer ignored a no match, the PSP is not liable for executing on the IBAN given. PSPs must explain those consequences to their users (Article 5c(7)).
Businesses sending payment files can opt out: PSUs "that are not consumers" may decline VoP "when submitting multiple payment orders as a package", and opt back in at any time (Article 5c(6)).
What are the VoP deadlines?
VoP is one of four obligations the Instant Payments Regulation adds: offer instant euro transfers (Article 5a), price them no higher than standard transfers (Article 5b), verify the payee (Article 5c) and screen users against EU sanctions at least daily (Article 5d).
| Date | Who | Obligation | Source |
|---|---|---|---|
| 9 January 2025 | All EU PSPs offering instant transfers | Screen all users against EU sanctions at least daily, instead of per instant payment | Article 5d |
| 9 October 2025 | PSPs in euro area member states | VoP on every credit transfer | Article 5c(9) |
| 9 April 2027 | Payment and e-money institutions in the euro area | Send and receive instant credit transfers | Article 5a(8) |
| 9 July 2027 | PSPs in member states outside the euro area | VoP on every credit transfer | Article 5c(9) |
There is no separate VoP date for payment or e-money institutions. The Commission says VoP "applies also to non-bank PSPs such as PIs and EMIs when the payer is their customer" (Q&A, answer 98), so an EMI in Paris has owed it since October 2025.
How is VoP performing so far?
The first published figures are French. SEPAmail, the routing service most French banks use, processed 180 million checks in its first month, and Natixis reports this breakdown for December and January: 66% match, 13% close match, 19% no match and 2% no answer (Natixis CIB, 9 March 2026). Nearly one request in five ends with a warning the payer has to decide on. Natixis also notes that bulk corporate flows were not fully live yet, so these are mostly single payments.
Some of those no matches are fraud stopped. Many are a legitimate company being paid under the name it trades as.
Why is VoP an onboarding problem?
Because the payee's bank can only match names it collected. The Commission is explicit: the payer "may choose to provide either the commercial or legal name of the payee", so "the PSP shall collect the commercial names of payees", which "will be key to minimise the rate of false 'no match' notifications" (Q&A, answer 100). A match on a trade name counts as a full match (answer 114).
How often does that matter? In the KYB files Dotfile customers built over the past year, 31.9% of companies had a commercial name recorded, and 1 in 5 of those (20.8%) traded under a name that does not appear in their legal name. Those are the companies whose payers type one name while the bank holds another.
Based on companies onboarded on Dotfile over the past year; aggregates only.
What does VoP look like for a company with a trade name?
NWC Hospitality Group SAS runs cafés under the brand Northwind Coffee. A supplier pays its invoice and types "Northwind Coffee".
- The bank onboarded the legal name only. The payee's bank compares "Northwind Coffee" with "NWC Hospitality Group SAS": no match. The supplier sees a warning, calls, delays payment.
- The bank captured the trade name at onboarding. Same request: match. Nothing shown, the money moves.
- The supplier types "NWC Hospitality". Close match: the supplier sees "NWC Hospitality Group SAS" and proceeds.
The difference between the first two lines is a field in the onboarding form and a registry that reports it.
What should change in KYB?
- Collect every name the company uses: legal name, commercial name and any other trade name, from the registry where it reports one and from the customer where it does not.
- Keep them current. A rebrand that never reaches the account record turns into no matches for every payer.
- Hold other identifiers for legal persons. Where a PSP lets payers identify a company by a fiscal number, EUID or LEI, verification runs on that identifier instead of the name (Article 5c(1)(b)), so it needs to be in the file.
- Treat daily sanctions screening as part of onboarding data quality. Article 5d replaced per-payment screening with screening of all users "at least once every calendar day", which only works if the customer data you screen is right.
FAQ
Is VoP mandatory for SEPA credit transfers that are not instant? Yes. In the euro area it applies to every credit transfer since 9 October 2025.
Is VoP the same as UK Confirmation of Payee? Same idea, different law. The UK runs Confirmation of Payee under a Payment Systems Regulator direction that brought in a second group of PSPs on 31 October 2024.
Can a business opt out of VoP? Only a non-consumer, and only for payment orders submitted as a package (Article 5c(6)).
Does VoP check the legal name or the trading name? Either. For a legal person the Regulation accepts "the commercial or legal name", provided the payee's bank holds it.
What Dotfile does
Dotfile is not a VoP provider. It is where the names VoP depends on are collected: company data from official registers includes the commercial name alongside the legal name, with the source of each value recorded, and AI document analysis reads bank details documents, extracts the IBAN and compares the holder with the company in the case (documentation). See also our guides to the KYB process, the 2026 to 2028 AML regulatory calendar and AMLA, the new EU supervisor.

Ready for Anywhere?
Verify any business, enter any market, defend every decision. Every signal orchestrated, every decision traceable, from one platform.



