Skip to main content
VoP Deployment Checklist: What to Add When Name Matching Isn't EnoughFraud Detection Analytics
5 min readFor Fraud Risk Managers

VoP Deployment Checklist: What to Add When Name Matching Isn't Enough

Verification of Payee (VoP) helps reduce misdirected payments but doesn't stop fraud. Erwin Kulk from EBA Clearing highlighted that fraud remains a growing challenge despite VoP's introduction. Your team needs additional controls to detect threats VoP can't identify.

This checklist outlines the network-based detection capabilities and data-sharing infrastructure you need alongside VoP to meet Payment Services Regulations expectations and effectively reduce fraud losses.

Prerequisites

Before proceeding, ensure:

  • VoP is live and integrated into your payment initiation flow.
  • You have access to transaction monitoring logs and can correlate VoP match results with fraud outcomes.
  • Your fraud operations team can act on real-time alerts within your payment processing window.
  • You have legal and compliance approval to participate in industry fraud intelligence networks.

Core Checklist

1. Identify VoP Blind Spots in Your Transaction Flow

Pinpoint payment types and fraud vectors VoP doesn't address. Document where name matching offers no protection.

Done when: You have a written inventory detailing authorized push payment fraud (APP fraud), account takeover scenarios, money mule networks, and social engineering attacks that bypass VoP. For example, "VoP confirms the beneficiary name matches, but doesn't detect that the account holder was coerced into authorizing the payment."

2. Join a Cross-PSP Fraud Data Sharing Network

Connect to a structured fraud intelligence platform where PSPs exchange indicators of suspicious activity in real time.

Done when: You're both receiving and contributing fraud signals to a network that meets your payment processing latency requirements. For instance, you can query whether a beneficiary account has been flagged by other PSPs before releasing funds and submit your own fraud indicators within 60 seconds of detection.

3. Implement Behavioral Analytics on Payment Patterns

Deploy transaction monitoring that detects anomalies VoP can't see, such as velocity changes, unusual beneficiary relationships, geographic mismatches, and deviations from historical patterns.

Done when: Your system flags a payment where VoP returns a match, but the transaction is the account holder's first international transfer in 18 months, sent shortly after a password reset. This involves automated risk scoring that combines VoP results with behavioral signals and generates hold decisions without manual review for clear-cut cases.

4. Establish Real-Time Alert Response Procedures

Define who acts on network-based fraud alerts and how quickly. Most fraud schemes succeed because PSPs can't coordinate fast enough.

Done when: You have documented escalation paths, decision authority limits, and response time commitments for different alert severity levels. High-severity alerts from your fraud network should trigger an automatic payment hold, notify your fraud analyst within 30 seconds, and require a decision before the payment window closes.

5. Configure Mule Account Detection Rules

Build detection logic for accounts receiving multiple payments from different payers in short timeframes, then quickly moving funds to other institutions.

Done when: Your monitoring system automatically identifies beneficiary accounts receiving payments from 5+ unique payers within 48 hours, especially when followed by immediate outbound transfers. Success looks like blocking mule accounts before they can extract funds and sharing those account identifiers with your fraud network the same business day.

6. Integrate Sanctions and PEP Screening at Payment Time

Incorporate sanctions list screening and Politically Exposed Person (PEP) checks into your payment authorization flow, not just at account opening.

Done when: Every payment triggers a real-time check against FATF watchlists, OFAC sanctions, and your PEP database before release. For example, catching a payment to a newly-sanctioned entity 72 hours after the list update, before your quarterly account review would have flagged it.

7. Document VoP + Network Controls for PSR Compliance

Payment Services Regulations require effective fraud prevention. Document how your layered approach addresses known fraud typologies.

Done when: You have a compliance artifact mapping each major fraud vector to specific controls, explaining why VoP alone is insufficient, and demonstrating how network-based tools close the gaps. This allows your internal audit team and external assessors to trace from a fraud typology (like APP fraud) through your control framework to specific system capabilities and response procedures.

8. Establish Feedback Loops Between VoP Results and Fraud Outcomes

Track whether payments that passed VoP checks later turned out to be fraudulent. Use this data to refine your complementary controls.

Done when: You're correlating VoP match results with fraud confirmations (Suspicious Activity Reports, customer disputes, law enforcement notifications) and using those patterns to adjust risk scoring. For example, discovering that VoP full-match payments to newly-opened beneficiary accounts have a 12% fraud rate in your portfolio, prompting you to add account age as a risk factor in your behavioral model.

Common Mistakes

Treating VoP as a fraud prevention control. VoP prevents misdirected payments by confirming name matches. It doesn't detect social engineering, account takeover, or money mule operations. Don't count VoP toward your fraud loss reduction targets.

Joining a fraud network but not contributing data. Network-based detection only works when PSPs share indicators in both directions. Consuming intelligence without submitting your own fraud signals undermines the system and likely violates your participation terms.

Requiring manual review for every network alert. Fraud schemes move faster than your analysts can. Define clear auto-hold criteria for high-confidence alerts, and let your team focus on ambiguous cases.

Failing to measure incremental fraud reduction. You need to know whether your network-based tools are catching fraud VoP misses. If you can't quantify the value, you can't justify the operational cost or make informed tuning decisions.

Next Steps

Start with items 1, 2, and 4. Understand your VoP blind spots, connect to a fraud intelligence network, and establish response procedures before the other controls deliver value. Items 5 and 6 build on that foundation.

Plan for quarterly reviews of your fraud data sharing participation. Are you submitting useful indicators? Are you acting on the intelligence you receive? Adjust your alert thresholds and response procedures based on what you learn.

VoP was a strong start, but it's not enough. Your fraud losses won't decrease until you integrate the collaborative, network-based detection Kulk described. This checklist provides the specific controls to deploy.

You Might Also Like