Every company that has ever paid an invoice has had the same half-thought at the confirmation screen: the beneficiary name is right there, so surely the bank checks it against the account number.
It does not. Not today, and not for payments in lei for some time yet. The name you type travels with the payment as a label; the money travels on the IBAN. That single fact is the mechanism behind most invoice fraud in Romania, and it is what a new EU rule is being phased in to fix — on a timetable that reaches Romania in 2027.
Here is what is changing, what it will and will not cover, and what actually protects a payment run in the meantime.
A transfer is executed on the account number
In a credit transfer, the account number is the instruction and the name is documentation. The paying bank routes on the IBAN, the receiving bank credits the account that IBAN identifies, and neither of them is in a position to know whether the person you meant is the person who holds it.
A payment executed in line with the account number you supplied counts as correctly executed. What follows is not a correction but a recovery attempt: your bank asks the beneficiary's bank to cooperate, the beneficiary's bank needs the account holder's agreement or a legal basis, and all of it depends on the money still being there. In practice, funds that land in a mule account are gone within hours.
This is not a Romanian peculiarity. It is how credit transfers work everywhere, and it is precisely why the EU legislated a check that sits before the payment rather than a remedy that sits after it.
What verification of payee does
Verification of payee — VoP in the industry's shorthand — obliges your bank to compare the payee name you entered against the name registered for the IBAN, before you authorise the payment, and to tell you the result: a match, a close match with the registered name shown, or no match.
Three properties of the rule matter more than the mechanics:
- It is free. The service is provided to the payer at no charge.
- It informs, it does not block. You keep the ability to proceed. The point is that if you proceed past a "no match" on a payment to a supplier you have paid for years, you did so knowingly — and everyone involved can see that you did.
- It applies to ordinary transfers, not only instant ones. The check is attached to credit transfers as such.
The consequence for fraud is structural. An attacker can still send you a perfect invoice with the wrong IBAN, but the account behind that IBAN has to be registered in a name close enough to your supplier's to survive the check — which means a company account opened with real identity documents, not a rented personal account.
The dates, and why Romania's are later
Regulation (EU) 2024/886 phases the obligations in by whether a payment service provider sits in a Member State whose currency is the euro. Romania's are on the later track.
| Obligation | Euro-area providers | Providers in non-euro Member States |
|---|---|---|
| Receive instant euro credit transfers | 9 January 2025 | 9 January 2027 |
| Send instant euro credit transfers | 9 October 2025 | 9 July 2027 |
| Verification of payee | 9 October 2025 | 9 July 2027 |
The European Central Bank publishes the timetable in full, including a further step on 9 June 2028 for accounts held in the national currency of a non-euro Member State, covering the hours outside a provider's business hours.
So: if your Romanian bank already shows you a name check on a euro payment, it is ahead of its obligation, not late with it.
What it will not cover: your payments in lei
This is the part that gets lost in the coverage. The regulation governs credit transfers denominated in euro within the Union. A RON payment from your Romanian account to your Romanian supplier's Romanian account is outside its scope.
Nothing in the regulation obliges a Romanian bank to check the name on a payment in lei — before 2027 or after it. Some banks will offer it anyway, because the infrastructure will be built for euro payments and extending it is cheaper than explaining why it stops at the currency. But it will be a product decision rather than an obligation, which means you cannot plan a control around it.
For a company whose payment run is denominated in lei — which is most Romanian companies — the practical conclusion is blunt: the checking has to happen on your side of the payment.
What invoice redirection actually looks like
It is worth being precise, because the mental image most people carry is wrong. The fraud is not a badly-written email from a stranger. It is:
- A real invoice, from a real supplier you have paid before, for an amount consistent with the last one.
- Arriving by email, often as a reply inside an existing thread, sometimes from a genuinely compromised mailbox at the supplier.
- With exactly one field changed: the bank account.
- Frequently with a plausible sentence attached — a new bank, a factoring arrangement, an account "under audit this month".
Every part of that is designed to survive a human looking at it. The only part that does not survive a machine comparison is the IBAN, because the real one is already recorded somewhere you control.
The controls that work before 2027
Four, in the order they pay for themselves:
- Take the IBAN from the structured invoice, not from the email. For B2B invoices in Romania the authoritative copy is the one delivered through e-Factura, where the account number is a labelled field rather than a line of text somebody can retype. The emailed PDF is a notification; see paying the invoices ANAF delivers.
- Do not re-key account numbers at all. A number that travels from the structured invoice into the payment instruction without a human in between cannot be mistyped, and cannot be swapped in your inbox — the attacker has to compromise the invoice at source instead, which is a much harder job.
- Treat an IBAN change as an event, not a detail. A supplier's account number changing is rare and worth one phone call to a number you already had, never the number in the email that announced the change.
- Keep the second pair of eyes above a threshold you choose. Whoever prepares a payment should not be the only person who releases it — see who approves payments in a small company.
None of these depends on your bank, which is the point: they work in lei, they work today, and they will still be the reason nothing went wrong in July 2027.
Where OpenPay fits
OpenPay reads your incoming invoices from ANAF, so the account number in a payment is the one the supplier put in the invoice they issued through e-Factura — it is never re-typed from an email, and never typed at all. Approval sits above it, and the payment itself is initiated with your own bank over open banking, authorised there with multi-factor authentication. The name check the regulation will bring in 2027 is a second line of defence; not typing the account number is the first one, and it is available now.