Preparing for PSD3 and the Payment Services Regulation: Why Verification of Payee Is Only the First Step
- Team Svenry

- Jul 2
- 5 min read
Payment fraud continues to evolve across Europe. Invoice fraud, Business Email Compromise, and manipulated supplier bank details are becoming increasingly sophisticated, costing businesses billions of euros each year. As organizations digitize their payment processes, criminals are finding new ways to exploit weaknesses in supplier onboarding, payment approvals, and master data.
To strengthen payment security, the European Union is finalizing a new legislative package consisting of the Third Payment Services Directive (PSD3) and the Payment Services Regulation (PSR). Together, these measures are designed to improve fraud prevention, increase transparency, and create a more secure and harmonized payments market across the EU. One of the most important changes is the broader implementation of Verification of Payee (VoP), a control that helps ensure payments are sent to the intended recipient before money leaves a bank account.
Where Do PSD3 and the Payment Services Regulation Stand Today?
As of mid 2026, PSD3 and the Payment Services Regulation have reached political agreement but are not yet fully in force. Formal publication in the Official Journal of the European Union is expected during 2026. Once adopted, most provisions are expected to apply after a transition period of approximately 21 months, meaning many of the new requirements are likely to become applicable during late 2027 or 2028. For businesses, this transition period provides valuable time to review payment processes, improve supplier data quality, and prepare for the evolving regulatory landscape. More information is available from the European Commission.
Understanding PSD3 and the Payment Services Regulation
Although often discussed together, PSD3 and the PSR have different purposes whereas PSD3 updates the existing Payment Services Directive and establishes the legal framework that each EU Member State must implement into national legislation. The Payment Services Regulation (PSR) complements PSD3 by introducing rules that apply directly across all Member States without national implementation. This creates greater consistency across the European payments market.
Together, the package aims to:
Reduce payment fraud
Improve payment security
Strengthen consumer and business protection
Increase transparency
Support innovation
Harmonize payment rules across Europe
Verification of Payee Is Expanding
Verification of Payee is one of the most widely discussed elements of the new framework.
It is important to understand that Verification of Payee is not entirely new, under the Instant Payments Regulation, many payment service providers already perform Verification of Payee for SEPA Instant Credit Transfers. The Payment Services Regulation expands this concept by extending Verification of Payee more broadly to standard credit transfers, creating a more consistent level of protection across European payments. For businesses, this means the same verification principle will increasingly become part of everyday payment processing.
What Is Verification of Payee?
Verification of Payee helps reduce payments being sent to fraudulent or incorrect accounts.
Before a payment is executed, the payment service provider compares the recipient's account name with the IBAN supplied by the payer.
The payer typically receives one of four responses:
Match
Close match
No match
Verification unavailable
If a mismatch is detected, the payer can review the payment before authorizing the transfer.
This additional validation helps prevent payments from being sent to unintended recipients due to fraud or human error.
Why Verification of Payee Matters
Invoice fraud continues to be one of the fastest growing financial crimes affecting businesses. Fraudsters often impersonate suppliers by compromising email accounts or sending convincing requests to update payment details. The invoice itself may appear completely legitimate. Without additional verification, finance teams may unknowingly transfer funds directly to criminals.
Verification of Payee introduces an important safeguard by confirming that the bank account belongs to the intended recipient before payment is executed. It helps reduce the risk of:
Invoice fraud
Business Email Compromise
Authorized Push Payment fraud
Incorrect payments caused by manual errors
Supplier bank account manipulation
Verification of Payee Is Only One Layer of Protection
Verification of Payee represents an important improvement, but it is not designed to detect every type of payment risk. Verification of Payee confirms only that the account holder's name matches the bank account.
It does not determine whether:
The supplier is legitimate.
The company has entered insolvency.
Ownership has changed.
The supplier appears on sanctions lists.
The invoice has been manipulated.
The supplier is connected to previous fraud.
The payment request originated from a compromised email account.
Organizations therefore still need broader supplier verification and counterparty risk management.
Strong Payment Security Starts Before the Payment
Verification of Payee is an important safeguard, but it is only one step in the payment process. Effective fraud prevention begins much earlier, with accurate supplier data and ongoing counterparty verification.
Fraud risks can emerge at any stage of the supplier lifecycle. A supplier's ownership may change, bank account details may be fraudulently updated, company registration information may become outdated, or a previously stable business may enter financial distress. These changes can introduce significant risk, yet they cannot be detected through Verification of Payee alone.
To reduce these risks, organizations should continuously verify and monitor their suppliers and other counterparties. This includes:
Company registration validation
VAT verification through the European Commission VIES system
Legal Entity Identifier verification
Beneficial ownership verification
Insolvency monitoring
Sanctions screening
Continuous supplier monitoring
By combining these controls with Verification of Payee, organizations create multiple layers of protection that help prevent fraud, improve data quality, and strengthen payment security before a transaction is ever initiated.
How Svenry Supports the Objectives of the Payment Services Regulation
The Payment Services Regulation places Verification of Payee obligations on payment service providers, including banks and payment institutions. Businesses themselves are not responsible for performing Verification of Payee. However, businesses remain responsible for maintaining accurate supplier data, managing payment risk, implementing effective internal controls, and demonstrating appropriate governance. Recommended actions:
Supplier and Counterparty Verification
Before suppliers are onboarded, Svenry verifies company information using trusted external data sources. This includes:
Company registration
VAT registration
Legal Entity Identifiers
Sanctions screening
Company status
Insolvency records
Beneficial ownership
These checks help organizations establish confidence that suppliers are legitimate before payments are approved.
Continuous Monitoring
Counterparty risk can change at any point in the payment lifecycle. A supplier may become insolvent, change ownership, or be added to a sanctions list after onboarding but before a payment is made. Svenry continuously monitors counterparties against trusted external registries, both throughout the supplier relationship and during the payment process, helping organizations identify material changes before payments are approved.
Better Supplier Master Data
Effective payment controls rely on accurate and consistent supplier data. If supplier names, legal entities, or payment details differ across ERP systems, procurement platforms, invoices, and payment files, organizations increase the risk of payment errors, unnecessary Verification of Payee mismatches, and manual intervention.
Svenry helps organizations maintain trusted supplier master data by validating business information against authoritative external registries and identifying inconsistencies before they impact the payment process. By ensuring supplier records remain accurate and up to date, businesses can improve operational efficiency, reduce payment risk, and strengthen the effectiveness of Verification of Payee.
Governance and Audit Readiness
The Payment Services Regulation places greater emphasis on proactive fraud prevention and operational resilience.
Svenry helps organizations strengthen governance by providing:
Continuous verification records
Supplier risk assessments
Audit trails
Counterparty monitoring
Data quality reporting
These capabilities support internal audit, procurement, finance, and compliance teams as they prepare for the evolving regulatory environment.
Preparing for the New Requirements
Although many provisions of PSD3 and the Payment Services Regulation are not expected to apply until late 2027 or 2028, organizations should begin preparing now.
Practical steps include:
Review supplier onboarding procedures.
Improve supplier master data quality.
Verify suppliers before approving payments.
Introduce continuous counterparty monitoring.
Automate fraud detection using AI.
Strengthen payment approval workflows.
Train employees to recognize phishing and Business Email Compromise.
Organizations that prepare early will be better positioned to reduce fraud while supporting future regulatory expectations.
Request a demo at: https://www.svenry.com/demo



