What it does
Confirmation of Payee runs through a central hub operated by Australian Payments Plus. When you enter a payee name, BSB and account number, it checks whether the name matches the account before the payment goes through, and returns one of three answers: match, close match, or no match. A no match doesn't reveal the real account name, which is deliberate.
The rollout started in July 2025 with CommBank, NAB, ANZ, Westpac, HSBC and Macquarie, and other banks followed over the months after. It applies to domestic payments where you key in the details, including new payees and edits to existing ones, and it appears automatically in banking apps and online banking rather than being something you switch on.
Where it stops
Four limits matter for a business.
- It's advisory, not a block. A no match is a warning you can read and pay anyway. The banks' own material is clear that if you authorised the payment, you generally carry the loss.
- It doesn't cover international transfers, which is where a good deal of invoice fraud ends up.
- PayID sits on a different rail and works differently.
- Business banking, BPAY, direct debits and batch payment files aren't spelled out in the public material. If your bookkeeper pays a run of supplier invoices out of accounting software as a single upload, don't assume a name check is happening in there. Ask your bank, in writing, what gets checked and what doesn't.
That last one is the gap we'd worry about in a fitout business or an accounting practice, because batch payment runs are exactly where a single altered line item disappears into forty legitimate ones.
The attack it doesn't touch
Confirmation of Payee verifies that the name you typed belongs to the account you typed. It can't tell you whether the invoice is genuine.
The version of this fraud we deal with most doesn't involve a crude edit to a PDF. Someone gets into a mailbox, sits quietly, and reads the thread until a real invoice is genuinely in flight. Then they reply from the real address, in the real thread, with a plausible reason for new banking details: a change of entity, a new finance provider, an account under audit. By the time the payment is being entered, the person doing it has been primed by a credible conversation to expect different details. A close match prompt against a company name chosen to sit near the supplier's, read by someone who's already been told the details changed, is not much of a speed bump.
We wrote up how this played out against a law firm's trust account, and the mechanics are the same whether the money is settlement funds or a joinery deposit. The phishing email that gets them into the mailbox in the first place is usually unremarkable.
What still does the work
Verbal verification, on a number you already hold. Not the number on the invoice, not the number in the email signature, the one in your own records from before this conversation started. Any change to bank details gets a call, every time, and urgency is a reason to be more careful rather than less. Scammers rely on a deadline.
Multi-factor authentication on every mailbox, because the thread that made the request believable came out of somebody's inbox. A mailbox without a second factor is the whole attack, and in a practice where one person handles invoices, it's the only account that needs to fall.
Separation in the accounting system between approving a payment and changing a supplier's bank details. If the same login can do both, there's nothing to catch a bad change except the person who made it.
And a written rule that a no match stops the payment. Not "check with someone", not "proceed if it looks right". Stops it. Tools that give advice only work when somebody has decided in advance what the advice means.
None of this is expensive. It's a phone call, a setting, and a sentence in your payments procedure, and it addresses the part of the problem your bank can't.
