GLOBAL PAYMENTS KNOWLEDGEISO 20022 / SWIFT / SEPA / MT / MX

Fraud & Controls / Learning brief

Confirmation of Payee and APP fraud

Your notes

What this means in plain language

In authorised push payment fraud the victim sends the money themselves, deceived into paying a criminal's account. Confirmation of Payee checks the name on an account before the payment is authorised, so a mismatch shows before the money moves. Here is what the check does, and what it does not.

Authorised push payment fraud (APP fraud) is fraud in which the victim is deceived into authorising a payment from their own account to an account controlled by a criminal. Because the victim initiates and approves the payment, it passes the usual authentication checks: the bank sees a genuine, authorised instruction. The deception sits before the payment, an impersonated supplier, employer, or authority persuading the payer that the destination is legitimate, which is why controls aimed at unauthorised access do not stop it. Confirmation of Payee (CoP) attacks the deception instead. It is a name-verification service that compares the payee name the payer enters against the name actually held on the destination account, and shows the payer the result before they authorise. The outcome is a match, a close match, no match, or that the check could not be done. CoP informs the payer, but it warns rather than blocks: a payer can override a no-match and send anyway. It catches mismatches and honest typos, but it does not judge whether a payee is honest, so it is one control among several rather than a complete answer.

Three things to remember

  1. 01

    In APP fraud the victim authorises the payment themselves, so it passes authentication; the deception comes before the payment.

  2. 02

    Confirmation of Payee checks the payee name against the destination account before authorisation and shows the payer the result.

  3. 03

    CoP warns rather than blocks, catching mismatches and typos but not judging whether a payee is honest.

Where you would use this

USE CASE 01

A bank runs a name check before authorising a push payment and shows the payer a match, close match, no match, or unavailable result.

USE CASE 02

A fraud team analyses no-match overrides to spot payers who may have been deceived into paying a criminal's account.

USE CASE 03

A payer pauses on a no-match and verifies new bank details through a trusted channel before sending a large invoice payment.

Put the idea into a real situation

Illustrative example: (SYNTHETIC / TRAINING ONLY) Maya Chen is buying from Example Supplies Ltd and receives an email, appearing to be from them, saying their bank details have changed. The email is from a criminal. Maya goes to pay GBP 4,500.00 to the new account, entering the payee name Example Supplies Ltd. Her bank asks the receiving bank whether the name matches the account and returns no match, because the account is not held in that name. Maya sees the warning before authorising and can stop and verify through a trusted channel, or override and send anyway.

Evidence & review

REVIEWED 2026-07-18

Account-name verification before a push payment, illustrated by the UK Confirmation of Payee model. Match logic and coverage differ by scheme and country.

What this brief simplifies: Match categories are simplified to match, close match, no match, and unavailable. CLS, cheque, and Confirmation of Payee scheme-specific operational detail was not re-verified against primary operator docs this pass (environment egress limits).

Sources for this brief4
  1. Scheme-specific rule

    Faster Payment System (FPS)Pay.UK · Confirmation of Payee name-checking context

    Describes the UK Faster Payment System, operated by Pay.UK: near-real-time retail credit transfers in sterling, available 24/7, cleared in real time and settled on a deferred net basis across settlement accounts at the Bank of England. · Checked 2026-07-14

    Interbank settlement in FPS is deferred net at the Bank of England — the customer experience is instant, but the banks settle net at defined cycles, not payment-by-payment. Not an RTGS system.

  2. Market practice

    Launching the FATF's Roadmap 26-28 on Combatting FraudFinancial Action Task Force · Authorised push payment fraud context

    FATF's 2026-2028 strategic roadmap for tackling fraud, set as a priority of the incoming UK Presidency; relevant background for why payment and screening controls increasingly treat fraud typologies alongside money-laundering and sanctions risk. · Checked 2026-07-14

    Launched 1 July 2026, the first day of the UK's two-year FATF Presidency. The roadmap itself is a plan of work (data-gathering through October 2026, recommendations by February 2027), not yet a new binding requirement.

  3. Official requirement

    PSD2 and the RTS on strong customer authentication and secure communicationEuropean Banking Authority · Strong customer authentication and payer protection context

    Governs open banking access in the European Union, including payment initiation and account information services offered by third-party providers, and the requirement for strong customer authentication. · Checked 2026-07-13

    Referenced from the European Banking Authority's public summaries, guidelines, and technical standards on payment services.

  4. Simplified educational illustration

    Payments Signal editorial teaching modelsPayments Signal · Fictional impersonation scenario

    This site's own simplified teaching models. · Checked 2026-07-12

    Used wherever diagrams, scenarios, figures, or example values are didactic constructions rather than sourced facts; every such use carries a simplifications disclosure. All people, companies, banks, and list entries in examples are fictional.

Learn this properly

Related briefs

Confirmation of Payee (UK)

Confirmation of Payee is the United Kingdom's pre-payment name-checking service. Before a sterling transfer is sent, it tells the payer whether the name they typed matches the account holder, returning a match, close match, or no match, and it compares closely with the euro area's Verification of Payee.

READ BRIEF

Verification of Payee

Explains how Verification of Payee compares the beneficiary name a payer enters against the name held on the account before a euro credit transfer is authorised, and what a match, close match, or no match means for the payer.

READ BRIEF

Security and fraud controls in payment operations

Explains where access control, segregation of duties, dual authorization, and screening and fraud checkpoints sit inside payment operations, and how these layered controls protect payments by detecting, reviewing, and escalating what looks wrong.

READ BRIEF
COMMUNITY SIGNAL

Discuss this learning page

Share an operational observation or ask a concrete payments question. Your name and message are public; your email remains private.

NEXT QUESTION REVIEWMonday, 27 Jul, 8:00 amMonday answer runs use source-supported educational material. Some questions may need owner review.
WHAT ARE YOU SHARING?

Public discussion

LOADING

Loading the discussion…