Verification of Payee and Instant Payments: A 2026 Compliance Guide for Fintechs and PSPs
For most of banking history, a credit transfer was routed on one thing only: the account number, or IBAN. The name you typed for the payee was, in practice, ignored. That gap made life easy for fraudsters and hard for victims of misdirected payments. In the European Union, that era is now closing – and for payment service providers (PSPs), Verification of Payee (VoP) has moved from a nice-to-have to a legal obligation.
This article is general information for fintech and compliance professionals and is not legal advice. Regulatory obligations depend on your jurisdiction, licence, and specific circumstances; confirm your position with qualified counsel and your competent authority.
What Verification of Payee actually is
Verification of Payee is an automated check that compares the payee name provided by the payer with the name associated with the destination IBAN, before the payment is authorized. The payer typically receives one of a few outcomes – a full match, a close (partial) match, no match, or “verification not possible” – and can then decide whether to proceed. The aim is simple: give the payer a last, informed chance to catch a mistake or a scam before the money moves.
The regulatory backdrop: the EU Instant Payments Regulation
VoP in the EU is anchored in the Instant Payments Regulation (Regulation (EU) 2024/886), which amends the existing SEPA framework. The regulation does two big things: it makes euro instant credit transfers a baseline expectation rather than a premium product, and it ties a payee-verification service to those payments. Importantly, the VoP requirement applies to credit transfers generally – not only instant ones – and the service must be offered to the payer free of charge.
The obligation covers PSPs broadly, including banks, electronic money institutions, and payment institutions operating in the European Economic Area. If you move euro payments in the EU, VoP is now part of your baseline product, not an optional add-on.
Key timelines at a glance
| Milestone | Who | Date |
|---|---|---|
| EPC VoP Scheme Rulebook enters into force | Scheme participants | 5 October 2025 |
| VoP obligation applies | Euro-area PSPs | 9 October 2025 |
| VoP obligation applies | Non-euro EU Member State PSPs | 9 July 2027 |
In other words, across the euro area VoP has been a live, mandatory service since October 2025. PSPs in non-euro EU Member States – Bulgaria, Czech Republic, Denmark, Hungary, Poland, Romania, and Sweden – have until 9 July 2027 to comply. The European Payments Council’s VoP scheme rulebook, which entered into force on 5 October 2025, provides the common scheme that lets providers interoperate rather than each building a proprietary check.
How a VoP check works in practice
Operationally, the payer’s PSP asks the payee’s PSP to confirm whether the supplied name matches the account holder for that IBAN. The response is normalized into a result the payer can act on:
- Match: the name and IBAN correspond. The payer proceeds with confidence.
- Close match: the details are nearly right (for example, a legal name versus a trading name). The payer usually sees the suggested correct name and decides.
- No match: the name does not correspond to the account. A strong signal to stop and check.
- Verification not possible: the check could not be completed. The payer proceeds without the assurance and should weigh the risk.
Crucially, VoP is advisory: it informs the payer but generally does not block the payment. The payer keeps control – and, with that, a share of the responsibility for proceeding past a warning.
Why VoP matters for fraud
The two problems VoP targets are misdirected payments and authorized push payment (APP) fraud, where a victim is tricked into sending money to an account they believe is legitimate. Because these transfers are authorized by the customer, they have historically been hard to reverse and hard to attribute. A name-check at the moment of payment inserts friction exactly where scams rely on its absence. VoP is not a silver bullet – determined fraudsters adapt – but it removes one of the easiest attack surfaces in the payment flow. It complements, rather than replaces, other controls; see our guides to fraud and chargeback management and strong customer authentication.
Operational and compliance implications for PSPs
Meeting the obligation is not simply switching on a feature. PSPs have to connect to a VoP scheme and directory so they can both request and answer verifications, handle real-time responses within the tight timing expectations of instant payments, and design clear customer messaging for each result type. They also need matching logic that is neither too strict (flooding customers with false “no match” warnings) nor too loose (waving through names that should raise a flag). Getting that balance wrong has direct customer-experience and fraud consequences.
There is also a governance dimension: audit trails of verification requests and responses, handling of opt-outs where permitted, and coverage of corporate as well as retail payments. For teams maturing their control frameworks, VoP fits naturally alongside the payment-infrastructure decisions covered in our guide to choosing payment software and gateways.
Data, privacy, and customer-experience trade-offs
A name-matching service inevitably processes personal data, so PSPs must handle it under applicable data-protection rules – sharing only what the check requires and no more. The customer-experience trade-off is equally real: verification adds a step, and poorly tuned matching that produces frequent false warnings will train users to click through them, defeating the purpose. The best implementations make the result clear and actionable, and reserve friction for the cases that genuinely warrant it.
A readiness checklist
- Are you connected to a VoP scheme and directory for both requesting and responding?
- Does your matching logic clearly distinguish match, close match, no match, and not-possible?
- Is the service free to the payer and available across the relevant payment types?
- Is customer messaging clear enough to change behavior at the “no match” moment?
- Do you retain auditable records of requests and responses?
- If you operate in a non-euro EU Member State, is your 9 July 2027 plan underway?
How VoP fits the wider fraud and compliance stack
It helps to see Verification of Payee not as a standalone feature but as one layer in a broader defense. On its own, a name-check catches misdirected payments and blunts some social-engineering scams; combined with other controls, it becomes far more powerful. Transaction monitoring can flag anomalous behavior that a single name-match would miss, strong customer authentication confirms the payer is who they claim to be, and sanctions and watchlist screening address a different risk entirely – who you are ultimately paying.
Treated in isolation, each control has blind spots; layered together, they cover for one another. For PSPs, the practical takeaway is to slot VoP into an existing control map rather than bolt it on. Our guide to sanctions screening shows how a neighboring control handles the false-positive trade-offs that VoP tuning also raises.
Frequently asked questions
Does VoP block payments automatically?
Generally no. It informs the payer, who decides whether to proceed. It is a warning mechanism, not a hard stop.
Does VoP apply only to instant payments?
The obligation sits within the Instant Payments Regulation, but the payee-verification requirement applies to credit transfers more broadly, not solely instant ones.
Can we charge customers for VoP?
No. The regulation requires the verification service to be offered to the payer free of charge.
Conclusion
Verification of Payee marks a quiet but significant shift: the payee’s name finally matters. For euro-area PSPs it has been mandatory since October 2025, and for the rest of the EU the 2027 deadline is closer than it looks. Treated as a checkbox, VoP is an integration cost. Treated well – with sensible matching, clear messaging, and solid governance – it is a genuine fraud-reduction control and a trust signal to customers.
To discuss how VoP and instant-payment compliance fit your platform and screening stack, get in touch with the DanuSoft team.