Confirmation of Payee and the Invoice With New Bank Details
The bank's name check confirms that a name and an account agree. It does not confirm that the invoice in front of you is genuine, and invoice redirection fraud exploits the gap between the two.
A supplier invoice arrives with different bank details, or the bank's name check returns 'close match'. What does Confirmation of Payee actually verify, and what does a lab buyer do before releasing the payment?
Confirmation of Payee compares the name you type with the name the receiving bank holds against an account, and tells you whether they agree. It checks the account. It does not check the invoice, the supplier's identity in any wider sense, or whether the person who sent you the bank details is who they claim to be [1].
That distinction matters most when an invoice arrives with bank details different from the ones you used last time. A fraudster who controls an account in a plausible name can pass the name check. The control that actually catches the fraud is a call to a number you already hold, made before any money moves.

What Confirmation of Payee checks
Pay.UK describes Confirmation of Payee as an account name checking service that lets a payer check the account name, together with a personal or business account indicator, before making a payment. Its stated purpose is to reduce misdirected payments and to give assurance that money is going to the intended account holder [1].
The check works by the paying bank asking the receiving bank whether the name given matches the name on the account. It applies to UK domestic payments to accounts that can be reached by a sort code and account number. TSB's customer help page says it covers CHAPS, Faster Payments and standing orders, and does not cover international payments or Bacs payments, including Direct Debits [2]. Banks implement the service in their own app wording, so the screens differ, but the logic is the same.
What the service cannot tell you is equally important. It does not tell you whether the account holder is a trustworthy business, whether the invoice is real, whether the goods exist, or whether the account was opened last week. It reports agreement between two strings of text. A criminal who opens an account in the name of a lookalike company, or who persuades a genuine account holder to act as a mule, will produce a clean match.
Reading the four responses
TSB's guidance sets out the four outcomes in plain terms, and other banks follow the same pattern with different wording [2]. The table below summarises them and adds the action a careful finance office would take.
| Response | What it means | What to do before paying |
|---|---|---|
| Match | The name, account number, sort code and account type agree | Proceed only if the details were already verified independently; a match is necessary, not sufficient |
| Close match | The name is nearly right but differs slightly | Stop. Establish why the difference exists, using details from a trusted source, before continuing |
| No match | The name does not agree with the account | Do not pay. Contact the supplier using details you already hold, and cancel if anything looks wrong |
| Unable to check | The receiving bank does not support the service or the account type cannot be checked | Treat as unverified. Confirm the details by call-back before paying |
TSB warns that if you proceed after a close match without checking, you accept the risk that the bank may not be able to recover the money if it goes to the wrong account. It gives the same warning for an unable-to-check result [2]. Its advice on a no-match is to check with the recipient using contact details from a trusted source, such as the organisation's public website, and to cancel the payment if it looks suspicious [2].
A close match is the response people click through most often, because it feels like a minor typo. It deserves more attention than that. Some banks show the name they hold when the result is a close match; where yours does, compare it character by character with the supplier's registered name rather than relying on a quick look.
Why a trading name can fail to match
Not every mismatch signals fraud. A supplier may trade under one name while its bank account is held in the legal name of the company, a parent, or a sole trader's own name. A business that sells under a brand name may be limited by a different name on its registration, and its account follows the registration.
Abbreviations, ampersands, the word Limited in full or as Ltd, and punctuation can all produce a close match on an account that is genuinely correct. Accounts for sole traders and partnerships can sit in the proprietor's personal name. Business accounts can also be held by a payment processor or an agent collecting on behalf of the supplier, in which case the account name is the intermediary's.
The way to resolve a legitimate mismatch is the same as for a suspicious one: ask the supplier, by a channel you already trust, what name the account is held in, and why. A genuine supplier can answer that in a sentence. Keep their answer.
How the new bank details email works
Invoice redirection fraud, sometimes called mandate fraud, begins with a message that appears to come from a regular supplier. It says the supplier has changed banks, or that the account is under audit, and asks that future payments go to new details. Sometimes the message carries a genuine looking invoice with the new account already printed on it.
The message may come from a spoofed address that differs by one character, or from the supplier's real mailbox after it has been compromised. In the second case the email is genuinely from the supplier's account and the fraud is still real, which is why the apparent sender is never the check.
Take Five to Stop Fraud, the UK Finance campaign, advises businesses to question changes in payment information and to confirm details directly with suppliers, noting that companies rarely change their bank details [3]. It also advises confirming a change using contact details you already hold rather than those in the new request [3].
The call-back rule
The rule is short. When bank details change, or appear for the first time, telephone the supplier on a number you already hold from a source other than the message that carries the change. Take it from your purchase order records, an earlier invoice, the supplier's own site reached by typing the address, or an official register.
- Do not reply to the email that contains the new details, and do not use the telephone number printed on the new invoice.
- Find a contact number that predates the change: a previous order, a signed contract, or a company's registered contact details.
- Speak to a person you have dealt with before, where possible, and ask them to read the new sort code and account number back to you.
- Ask for the account name and compare it with the bank's name check result.
- Have a second member of staff authorise the first payment to any new account, and make a small test payment only if your process allows it and the supplier agrees.
- Write the date, the person's name, the number called and the outcome on the file.
If the supplier says it sent no such message, stop. Tell your bank, tell the supplier so it can check its own email account, and keep the original message. Do not delete it, since your bank and the police will want to see it.
Paying a supplier outside the UK
Confirmation of Payee does not apply to international payments [2]. A payment to an overseas supplier has no name check at all in the UK system, so the entire burden falls on independent verification. Confirm the account details through a known channel, compare the beneficiary name with the company's registration in its own country, and treat a request to pay into a third country account as a red flag.
The same applies to Bacs payments and Direct Debits, which TSB lists as outside the service [2]. If your supplier arrangement uses either, the call-back rule is still the control.
Recording the check
A small laboratory finance office does not need elaborate software, only a consistent note. A single entry per supplier is enough: the legal name, the account name and number on file, the date the details were last verified, who verified them and by what method. Each change adds a line.
That record serves two purposes. It is the evidence that the check happened if something goes wrong. For Faster Payments, the reimbursement rules ask a claimant to report promptly and to respond to reasonable requests for information from the bank [4], and an organised file makes both easy. It also catches the second attempt: a fraudster who fails once may try again, and an unexpected change request against a file that shows no earlier change is itself informative.
Reimbursement is a safety net with conditions, not a substitute for the check. It covers deception into paying a fraudster and does not cover a dispute with a genuine supplier, as the companion article on the bank transfer rules explains.
What to do next
Before the next payment run, list the suppliers you pay by transfer and note when each one's bank details were last verified independently. Any supplier whose details were taken from an email, with no later call, is the place to start. Agree a rule that no change of bank details is acted on without a call-back and a second authoriser, and brief everyone who opens supplier email.
References
- Confirmation of PayeePay.UK
- Confirmation of PayeeTSB Bank
- Protect your businessTake Five to Stop Fraud (UK Finance)
- APP scamsPayment Systems Regulator
