A recent Malaysian court ruling has raised an important question for banks, payment providers, and businesses: if a payment system asks for both a payee name and an account number, should it also check whether those details match?
The case involved a motor and spare parts dealer that intended to transfer funds to Perodua Sales Sdn Bhd. An account number was entered incorrectly, causing more than RM1.2 million to be sent to a different company. Most of the funds were never recovered, and the High Court ultimately ordered the bank and its subsidiary to compensate the claimant for RM1.16 million in losses.
According to reports on the judgment, the court noted that a mechanism to identify inconsistencies between the payee name and account details could likely have detected the issue before the transaction became irreversible.
While the case centres on a single payment error, it highlights a broader issue in modern payments: organisations may have extensive controls around the person sending a payment, but limited visibility into whether the destination account belongs to the intended payee.
This is where Payee Verification can help.
Why verifying the payee matters
Many payment controls focus on authenticating the payer. Financial institutions use identity checks, multifactor authentication, device monitoring, and transaction screening to determine whether the person initiating a payment is authorised to do so.
These controls remain essential, but they do not necessarily establish whether the destination account belongs to the person or business the payer intends to pay.
The Malaysian case illustrates the distinction. The account was valid and capable of receiving the payment, but it belonged to a different company from the intended payee. The issue was not whether the account existed, but whether the payee and account corresponded.
This reflects a broader Know Your Payee (KYP) challenge: organisations need greater confidence not only in who is sending money, but also in who is receiving it. Payee Verification is one practical control that can help address that gap before funds are sent.
Why account numbers alone are not enough
A valid account number does not mean a payment is going to the right payee. An account may be open, active, and capable of receiving funds while belonging to an entirely different individual or organisation.
Misdirected payments can result from manual entry errors, incorrect beneficiary details, outdated supplier information, changes to vendor bank accounts, or fraudulent attempts to redirect legitimate payments.
In each case, relying only on the destination account leaves an important question unanswered: does this account actually belong to the intended payee?
Once funds reach the wrong account, organisations may face recovery efforts, operational repair work, delayed payments, disputes, and direct financial losses.
Faster payments leave less room for correction
As domestic and cross-border payments become faster, the window to identify and correct an error after initiation continues to shrink.
Once funds reach the destination account, recovery can depend on the recipient, the receiving institution, local rules, and how quickly the problem is identified. In the Malaysian case, despite efforts to stop the transaction, only a small portion of the funds was ultimately recovered.
This makes prevention increasingly important. For payment teams, the most valuable point to identify a discrepancy is before the payment is released.
Why Payee Verification is becoming a reasonable expectation
One of the most significant aspects of the Malaysian judgment was the court's focus on the payment platform itself.
According to reporting on the case, the system required both a payee name and an account number. The court observed that a mechanism capable of identifying inconsistencies between those fields could likely have prevented the loss.
The same principle is reflected in payment initiatives elsewhere. Confirmation of Payee (CoP) in the UK and Verification of Payee (VoP) in Europe are designed to give payers greater visibility into whether the payee details entered correspond to the destination account before a payment is sent.
These controls are not designed to eliminate every payment error or instance of fraud. Their value lies in introducing another decision point before funds leave the payer's control.
How Payee Verification supports payment integrity
Before a payment is sent, Payee Verification can check the intended payee's information against available banking or account data to determine whether the name and destination account correspond.
Depending on the market, scheme, and available data, the result may indicate a match, close or partial match, or mismatch. A match can provide additional confidence to proceed, while a mismatch or uncertain result can prompt further review before the payment is released.
Payee Verification does not replace customer due diligence, sanctions screening, fraud monitoring, authentication, or transaction controls. Its role is more specific: helping organisations answer a critical question before payment.
Are we paying the person or business we actually intend to pay?
The lesson for payment teams
The Malaysian ruling may have resulted from one incorrectly entered account number, but the underlying issue extends far beyond a single transaction or market.
Payment organisations have spent years strengthening controls around who can initiate a transaction. As payments become faster and harder to recover once settled, greater attention is also needed on who will actually receive the funds.
Payee Verification gives financial institutions, fintechs, and enterprises an opportunity to detect incorrect or suspicious payee information while there is still time to act, rather than relying on recovery after funds reach the wrong account.
iPiD's Payee Verification helps organisations verify payee details before payment and reduce the risk of misdirected payments, payment failures, and operational repair work.
References
- Free Malaysia Today — Bank, subsidiary to pay RM1.16mil credited to wrong company (2026)
