By Joshua Clouston, Head of Product, ezyshield

News 8 min read

Confirmation of Payee Is Live: What It Covers, What It Misses

Australia's banks reached industry-wide Confirmation of Payee coverage in 2026. What it covers, what it misses, and what B2B businesses need to do next.

A hand holding a blank bank card with a visible chip beside an open laptop keyboard on a wooden desk

Last financial year, a Northern Territory government agency wired $3,583,363 to what it believed was a trusted construction contractor. The email looked right. The invoice looked right. The bank details had been updated by the contractor - except the contractor hadn’t updated them. A criminal had compromised the contractor’s email, quietly swapped the BSB and account number, and collected the payment before anyone noticed. (AFP)

This week, Australia’s banks reached industry-wide coverage on the tool designed to prevent exactly that: Confirmation of Payee (CoP). It’s the first national rollout of its kind outside Europe. It marks a genuine step forward for Australian payment safety. And it leaves a verification gap that every business sending money to other businesses still needs to close.

What Is Confirmation of Payee and What Just Changed

Confirmation of Payee is a service run by Australian Payments Plus (AP+) that checks the account holder’s name against the BSB and account number you enter before a payment is made. The result comes back as one of three signals: match, close match, or no match.

The scheme first went live in July 2025 with NAB, ANZ, Commonwealth Bank, Westpac, HSBC, and Macquarie as the initial cohort. It has been progressively rolling out to mutual banks, credit unions, and regional lenders since, with AP+ targeting near-universal coverage - more than 95% of personal accounts. Australians have now completed over 100 million CoP lookups since launch. (Customer Owned Banking Association)

The $100 million the banking sector invested in CoP is part of the Scam-Safe Accord - a set of commitments by Australian banks to harden the payment system against fraud. CoP is the centrepiece initiative. (Australian Banking Association)

The traffic-light design is deliberate. Green means the name you entered matches the account. Amber means there’s a partial match - common where names are abbreviated, or a sole trader’s account is in a personal rather than business name. Red means the name doesn’t match at all. Each result is designed to be understood without any financial expertise, and it appears automatically when you enter a new payee or update account details in your banking platform.

Why This Matters: The Scale of the Problem CoP Was Built For

Payment redirection fraud - where criminals intercept business communications and redirect legitimate payments to fraudulent accounts - has become the defining B2B fraud type in Australia.

The AFP’s figures for FY2024 make that clear: BEC losses hit $152.6 million, up 66% from $91.6 million the year before. The construction sector is the AFP’s current focus given its volume of subcontracting relationships, high invoice values, and complex multi-party payment chains. Organised groups, both domestic and offshore, are running sustained campaigns against it. (AFP)

The mule account problem is visible too. In May 2026, AFP cybercrime detectives arrested a woman and two men at a Sydney CBD gold dealership who were converting BEC proceeds to bullion. NAB flagged the funds as suspicious. About $300,000 was recovered - a fraction of what had been stolen. (AFP)

Beyond BEC, the broader authorised push payment (APP) fraud picture is serious. ACI Worldwide’s Scamscope report estimated Australia recorded AUD 1.24 billion in APP fraud losses in 2023, with 83% of that flowing through real-time NPP payments. The 2028 projection sits at AUD 1.76 billion, with real-time payment fraud accounting for AUD 1.547 billion. (Australian Cyber Security Magazine)

Real-time payments are fast and nearly irreversible. Once money moves through Osko, the recipient can layer it through additional accounts within minutes. The window for intervention - from the moment funds leave to the moment they’re beyond recovery - is often under an hour.

What CoP Does Well

It adds friction at the right moment: before the payment leaves.

For consumer payments, where a scammer provides convincing but incorrect account details, or where a victim misremembers a BSB, the name-match check creates a pause. That pause catches mistakes. Of the 100 million lookups completed, a significant portion flagged genuine mismatches that the sender corrected before proceeding.

For mistaken payments - transposed digits, a digit off in the account number, a BSB copied incorrectly from an old record - CoP is a practical backstop. These errors are common and costly, and genuinely hard to reverse once processed.

The interface design deserves credit too. A traffic light at the payment screen, appearing automatically, readable without financial expertise, requiring no opt-in from the user. Getting that live across the Australian banking system at near-universal coverage is a serious piece of infrastructure work. The $100M investment reflects the scale of what it took to build and integrate.

What CoP Doesn’t Catch - and Where the Harder Fraud Lives

Here’s where businesses that pay other businesses need to stay sharp.

CoP verifies that the name you entered matches what the receiving bank has on file for that account. It does not:

  • Verify that the business you’re paying is a real, registered entity
  • Confirm that an ABN on an invoice belongs to a trading business with a legitimate history
  • Indicate whether the person authorising or requesting the payment works for the business they claim to represent
  • Detect fraud where a criminal has opened a real bank account in a plausible business name
  • Cover international payments, which remain entirely outside the CoP framework

Return to the NT government contractor case. The attacker’s method was account takeover - they compromised the contractor’s email and swapped the bank details on the invoice. If they opened a receiving account in a name that matched the real contractor closely enough, a CoP check returns green. The account is real. The name matches. The criminal collects.

More sophisticated operators register shell entities with plausible names, obtain ABNs, and open bank accounts before approaching any victim. By the time they send an invoice, the account is real, the name matches, and CoP has nothing to flag.

AUSTRAC’s expanded AML/CTF reporting obligations, which came into force from 1 July 2026, raise the cost of opening mule accounts by requiring more rigorous KYC from financial institutions. That’s a useful supply-side control. (AUSTRAC) But it doesn’t remove the need for the business making the payment to verify the payee independently.

The AFP’s standing advice remains correct regardless of what CoP shows: call a known contact on a number from your existing records to confirm any bank detail change. Never use contact details provided in the same communication as the change request.

The Three Layers of Payee Verification

Payment fraud prevention for B2B transactions has three distinct problems, each requiring its own check:

Layer 1 - Bank account verification: Does this BSB and account number exist? Does the account name match what I’m expecting? CoP now covers this for the vast majority of Australian accounts. It’s a real capability, and it matters.

Layer 2 - Business identity verification: Is this a real, registered business? Is the ABN active and consistent with the trading name on the invoice? Does the registered address match? How long has this entity been registered? Were there recent changes to its details before the invoice arrived?

Layer 3 - Person verification: Is the individual I’ve been dealing with - who sent the invoice, updated the bank details, or confirmed the order - actually an employee of the actual business they represent?

Most BEC and payment redirection fraud that passes a CoP check operates at Layers 2 and 3. Attackers who target high-value B2B payments are not going to hand over account details with a name mismatch. They either compromise a legitimate supplier’s communications (so the account details were correct until they weren’t), or they set up entities and accounts specifically designed to pass a name check.

Verifying across all three layers before each significant payment - and especially before adding or updating a payee record - is what closes the gap that CoP leaves open.

What Accounts Payable Teams Should Do Right Now

CoP is active in your banking platform. Here’s how to use it as one part of a broader process, not a replacement for it.

Treat a green match as one data point, not a green light. CoP confirms the account name is consistent with the bank’s records. It says nothing about whether the business is legitimate or the payment request is genuine.

Build verbal confirmation into your bank detail change process. Every time a supplier asks you to update their payment details - by email, invoice, or any other channel - call a contact at that business on a number from your existing records. Do not use any contact detail provided alongside the change request. This single step prevents most payment redirection fraud.

Verify new payees at the business and person level before the first payment. Check the ABN on the ATO’s ABN Lookup. Confirm ASIC registration. Check when the entity was incorporated. Make sure the trading name, address, and account details are internally consistent with what you know about the supplier.

Set a verification threshold for high-value payments. Any payment above a limit your business defines should trigger a secondary approval or verbal confirmation from the payee, regardless of how routine the email chain looks. The NT government case involved a single transfer of $3.58 million.

Extend the same scrutiny to international payments. CoP doesn’t cover payments sent overseas. For any international transfer - especially to a new or recently changed account - treat the verification bar as higher, not lower.

Confirmation of Payee is genuine, welcome infrastructure. The banking sector’s investment and the speed of rollout reflect the seriousness of the problem. But fraud evolves faster than any single control, and the attacks that cost Australian businesses the most are precisely the ones designed to pass basic name-match checks.


ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more

Stop payment fraud before money moves

Verify the person, business, and bank account before any payment leaves your account.