IBAN name check: what applies from October 2025
From October 2025, the IBAN name check becomes mandatory for banks in the euro area. Find out what the EU rules mean for your mid-sized company and how you protect your master data.

What is the IBAN name check under EU Regulation 2024/886?
With the adoption of EU Regulation 2024/886 promoting instant payments, the European Union has taken a significant step towards modernising cashless payments. A central pillar of this initiative is the mandatory introduction of the payee check, known as Verification of Payee (VoP) or simply the IBAN name check. The legal basis is Article 5c of Regulation (EU) 260/2012, which Regulation (EU) 2024/886 inserted there. By the deadline on 9 October 2025, all payment service providers in the euro area must implement this security measure across the board, while providers in member states outside the euro area follow by 9 July 2027[1]. Important for you: the obligation applies to the bank, not to your company as the payer. For you as a managing director or IT manager in a mid-sized company, this means a far-reaching change in risk assessment in day-to-day business operations: before every SEPA credit transfer, an automated check will in future determine whether the payee name entered matches the IBAN provided. The check obligation applies to all SEPA credit transfers and not only to instant payments.
Objectives and how the new security standard works
The primary aim of this regulation of the European Parliament and of the Council is to drastically curb the misdirection of funds as well as targeted fraud attempts such as the notorious CEO fraud or forged invoices. The check takes place within seconds directly before the final authorisation of a payment. The underlying technical rulebook of the European Payments Council (EPC) already enters into force on 5 October 2025[1].
- Real-time check: the payment service provider compares the payee name entered with the actual account holder of the target IBAN.
- Immediate feedback: in the event of discrepancies, you receive a warning before the money leaves your account.
- Shift of liability: if you knowingly ignore a warning and release the payment anyway, you bear the financial risk of misdirection yourself[1].
For mid-sized companies, this changeover requires not only an adjustment of internal financial processes, but above all clean master data in the ERP system. As a modern partner for cybersecurity and compliance, CAVRIX helps the German Mittelstand to master such regulatory hurdles proactively and to secure your digital workflows without gaps.
The deadline in October 2025: when the new rules take effect
The implementation of the new EU requirements for instant payments takes place in clearly defined steps. For you as a managing director or IT manager in a mid-sized company, this means that the statutory timeframe is tight. As early as 9 October 2025, all payment service providers in the eurozone must offer the IBAN name check as standard, as prescribed by Regulation (EU) 2024/886[2]. From that deadline onwards, every outgoing SEPA credit transfer will be checked to see whether the payee's name matches the IBAN provided.
For payment service providers in member states outside the euro area, the regulation provides for a longer transition period[2]. These institutions only have to have the verification processes fully implemented by 9 July 2027[2]. Since modern compliance and the protection of digital processes are, however, inseparably linked to your general cyber security strategy, adapting your own master data early is strongly advisable. This ensures that your outgoing payments are processed without errors from day one.
| Currency area & service provider | Deadline for the IBAN name check |
|---|---|
| Eurozone (based in the euro area) | 9 October 2025 |
| Outside the eurozone (payments in euro) | 9 July 2027 |
This regulatory obligation affects not only banks, but has a direct impact on your internal workflows. From October 2025, inaccurate master data will lead to warning messages and therefore to additional checking effort. A payment is not automatically blocked as a result; the decision on release remains with you. For this reason, preparing your IT infrastructure should not be a purely administrative duty, but should be understood as an integral part of your proactive risk reduction. For mid-sized businesses, seamless verification of digital documents and payment data is a central building block for effectively fending off fraudulent activities such as so-called invoice fraud. This turns the topic into a strategic task in which IT security must be treated as a matter for top management, in order to avert financial damage and liability risks.
The four response scenarios: how verification works in daily practice
When your accounting team makes credit transfers in future, a check running within seconds takes place in the background. Before the money leaves your account, the bank checks the payee's name against the IBAN. According to PwC (2024), this Verification of Payee (VoP) system is based on a clear comparison that gives your team precise feedback directly before release[3]. This query noticeably changes the daily workflow of your finance department, because it has to intervene actively in the event of discrepancies.
| Response scenario | What it means for your accounting |
|---|---|
| Exact match (Match) | Name and IBAN match. The transfer is released immediately and without additional warnings. |
| Near match (Close Match) | Minor deviations (for example typing errors). The bank proposes a corrected name that your team has to check and confirm manually. |
| No match (No Match) | Name and IBAN differ significantly. A clear warning appears. The risk of fraud is high; release should only follow after consultation. |
| Not available (Not Checked) | Verification is not possible because, for example, the payee's bank does not yet support the check. The team has to weigh up the risk itself. |
These scenarios make release more structured, but also demand clear processes. While an exact match speeds up processing, deviations require immediate manual checks. Since many threats deliberately target smaller companies, as reports on cyber attacks on SMEs show, this step does protect against misallocation, but it lengthens processing time where master data maintenance is poor. For managing directors in mid-sized companies this means: only clean master data ensures smooth handling without time-consuming delays. CAVRIX supports you here with modern services for fraud prevention and digital verification in order to secure your internal processes.
Why the Mittelstand must clean up its supplier master data now
With the introduction of the mandatory IBAN name check, considerable challenges are coming towards IT and accounting systems in the German Mittelstand. When your ERP and financial accounting software triggers automated payment runs, the payee bank's system will in future compare the payee's name with the IBAN. From October 2025, outdated or incomplete supplier master data in your systems will lead to frequent discrepancy messages and to manual checking effort. Even small differences such as a deviating legal form, abbreviations or transposed digits drastically delay your regular payment processes.
The experts at the tax consultancy GHP (2025) point out in a recent analysis that companies must now act proactively and systematically review their account holder data in order to prevent operational disruptions[4]. A data set that has not been cleaned up endangers your suppliers' liquidity chain and burdens your accounting with time-consuming manual re-checks. The check forgives no errors: if the company name entered on your invoice deviates from the data held by the bank, the system raises the alarm.
| Check result | System response | Impact on your accounting |
|---|---|---|
| Exact match | Payment goes through as normal | No manual intervention or delays required. |
| Partial match | The bank's name proposal is displayed | Payment stalls; data has to be corrected in the ERP system. |
| No match | Clear warning before release | Payment should only be released after consultation with the payee. |
In order to handle these administrative hurdles efficiently and at the same time rule out fraudulent invoices or incorrect transfers, a clean data basis is indispensable. An error-free system landscape protects you from outages and strengthens your resilience. Since digital processes and NIS2 compliance are closely interlinked, securing your payment transactions is part of modern cybersecurity for mid-sized companies. As an SME you should make this topic a priority in order to maintain smooth business operations and to successfully establish IT security as a matter for top management in your company.
Protection against CEO fraud and invoice manipulation through real-time checks
The introduction of the mandatory IBAN name check (Verification of Payee, VoP for short) marks a decisive turning point in the fight against digital financial fraud. Cyber criminals are increasingly using sophisticated methods such as CEO fraud to divert payment flows in mid-sized companies. The scale of this risk is shown by the payment fraud report from the EBA and the ECB: in the 2024 data year, payment fraud in the European Economic Area amounted to 4.2 billion euros, 17 percent higher than in the previous year. Fraudulent credit transfers accounted for 2.5 billion euros, an increase of 24 percent. 74 percent of this value was due to manipulation of the payer, that is to say precisely to schemes such as CEO fraud and forged invoices. For Germany, the report shows 474,164,942 euros in credit transfer fraud. The real-time check puts a stop to this fraudulent practice by checking, directly before a SEPA credit transfer is executed, whether the payee's name actually matches the IBAN provided.
For you as a managing director or IT manager in a mid-sized company, this legal innovation means an important safety net which, however, covers only one part of the picture. The bank check alone only takes effect at the very last moment of the payment process. In order to protect your liquidity and your reputation preventively, you have to stop attacks beforehand. This is where the interplay with the CAVRIX solutions comes in: while the IBAN name check validates the formal bank details, our comprehensive cybersecurity protects your entire IT network against phishing campaigns and the theft of sensitive access credentials. Supplemented by digital verification processes from CAVRIX, you make sure that incoming invoices, documents and emails are checked automatically for authenticity in advance, even before a transfer is prepared at all.
- Advance control: digital verification from CAVRIX checks emails and documents for manipulation before invoice data flows into your systems.
- Real-time check: the automated IBAN name check validates the payee directly at the bank and stops incorrect or manipulated payments before execution.
- Holistic protection: CAVRIX cybersecurity secures your endpoints and communication channels in order to block CEO fraud attempts at the outset.
The combination of regulatory protection and proactive IT security closes the dangerous gaps that criminals deliberately exploit at SMEs with fewer than 500 employees. If you would like to set up your existing processes in line with NIS2 and secure them against invoice manipulation, the CAVRIX team is happy to support you personally. Simply send us an email to info@cavrix.de for individual advice.
Automating payment processes and minimising compliance risks
For IT managers in the German Mittelstand, the introduction of the payee check, also known as Verification of Payee (VoP), is more than a purely regulatory duty. From 9 October 2025, credit institutions in the euro area must offer this check as standard for credit transfers under Article 5c of Regulation (EU) 260/2012. The statutory obligation applies to your bank and not to your company. What counts for you is that your processes can handle the responses cleanly. For your internal financial workflows this means: a manual check in online banking with hundreds of transactions is not viable in day-to-day business. Instead, automated checks must be integrated directly via application programming interfaces (APIs) into your existing ERP and accounting systems in order to block incorrect payments and fraud attempts proactively. Without such automation, there is a risk of expensive delays in payment transactions and an increased risk of errors in daily transfers.
- Automated API interfaces: connecting the financial software to banking interfaces for real-time checks in every payment run.
- Master data cleansing: continuous digital verification of supplier data and invoices before payment release.
- Security monitoring: real-time alerting on warning messages from payment service providers to protect against invoice forgery.
An unsecured payment process represents a considerable security risk for the entire supply chain under directives such as NIS2. Cyber criminals are increasingly using forged invoices and manipulated payment data to harm companies. CAVRIX supports you in closing these weak points structurally. With our service Managed IT, we make sure that your ERP systems and interfaces are always hardened, monitored and secured. Our Compliance service also delivers the necessary audit trails and risk management processes so that you as a managing director minimise your personal liability and can demonstrate all statutory requirements without gaps. Thanks to the seamless documentation in the CAVRIX Command Center, you keep an eye on the status of your IT infrastructure at all times. For questions about secure interfaces and your compliance strategy, you can reach us at info@cavrix.de.
Your roadmap to implementation: how to prepare your company
The mandatory IBAN name check (Verification of Payee) requires structured preparation of your internal processes. When the new EU requirements for payment transactions become mandatory from 9 October 2025, your technical systems and your workforce must be attuned to the changed procedures. For managing directors and IT managers, this means acting in good time and decisively. A clear roadmap helps you to minimise financial risks and operational hurdles systematically.
- Cleaning up master data: check and correct your existing supplier and customer accounts thoroughly. Even minor deviations in special characters, umlauts or abbreviations in the company name can lead to error messages from October 2025. A cleaned-up data basis prevents unnecessary delays in daily payment transactions.
- Reviewing your financial software: clarify early on with your software provider whether the ERP and accounting systems you use natively support the automated query of the Verification of Payee procedure. According to Regulation (EU) 2024/886, banks in the euro area must provide this check for all SEPA credit transfers from 9 October 2025[5].
- Training your employees: train your finance and accounting team specifically in how to handle the banks' new warning notices correctly. Your employees must learn to reliably distinguish between harmless typing errors and genuine fraud attempts (such as CEO fraud) in daily payment transactions.
Seamless protection of your business processes can, however, only be achieved through a holistically protected digital infrastructure. Fraudsters often do not step in only at the point of payment, but manipulate invoices and documents beforehand via compromised emails or internal systems. CAVRIX supports the German Mittelstand with proactive cybersecurity and tailored Managed IT. For questions about securing your systems and implementing robust protective measures, you can reach us at any time directly via our contact page or simply by email at info@cavrix.de.
Frequently asked questions
What is the IBAN name check for credit transfers?
The IBAN name check, also called Verification of Payee (VoP), is an automated procedure. Before a transfer is executed, your bank checks whether the payee name you entered actually matches the account holder of the IBAN provided.
When does the IBAN name check become mandatory in Germany?
For all payment service providers in the eurozone, the deadline is 9 October 2025. From that date, banks must offer the service for instant payments and standard credit transfers. Payment service providers in member states outside the euro area have until 9 July 2027.
Does the IBAN name check also apply to normal SEPA credit transfers?
Yes. Regulation (EU) 2024/886 prescribes the check via Article 5c of Regulation (EU) 260/2012 for all SEPA credit transfers, not only for instant payments.
What happens in the event of a warning from the IBAN name check?
If the name and IBAN do not match, you receive a warning before release. You can cancel the transfer to prevent fraud, or release it anyway at your own risk.
How can companies prepare their master data for Verification of Payee?
You should clean up the supplier master data in your ERP system. Make sure that the exact legal company names of your partners are stored in order to avoid constant false alarms during payments.
Who is liable if a transfer is executed despite a warning?
If you execute a transfer despite a clear warning about a missing match, you bear the financial risk yourself. In this case the bank is released from liability.