Beneficiary verification for supplier and payroll payments – a PayPoint case study
An obconnect white paper
Executive summary
Almost all payment-security effort is aimed at the transaction: is the amount right, is it properly authorised, has it cleared through the right rail on the right day? This white paper argues that the largest and most persistent exposure sits somewhere quieter and far less examined – the beneficiary. The account you are paying is where value actually leaves the organisation, and it is the one variable that every other control implicitly assumes to be correct.
Drawing on a structured review of PayPoint’s own supplier and staff payments, this paper shows how systematically verifying who is being paid – using Confirmation of Payee (CoP) and related beneficiary checks – reduces fraud exposure, surfaces the silent decay of stored data, and saves operational time, all without disrupting the business. The results were reassuring and instructive in equal measure. Across more than £300,000 of supplier payments examined to a deeper level of assurance and dozens of payroll records reviewed retrospectively, no money had gone to the wrong place. Yet the act of checking still delivered material value: it updated stale records, confirmed that suppliers were being paid into business rather than personal accounts, corrected a widely held misunderstanding about what a routine ‘checker’ actually checks, and demonstrably lowered risk.
The central conclusion is simple and portable to any organisation that pays suppliers or staff: the risk in a payment lives in the beneficiary details and how you manage them over time, not in the payment itself. Verify who you pay before the money moves, keep that verification current, and the single largest category of payment risk shrinks quietly – before it can ever cost you.
1. More than a terminal in the corner shop
Most people know PayPoint as the small terminal on the corner-shop counter – the place to top up a gas key, pay an electricity bill, or collect a parcel. With more than 30,000 stores across the UK, that retail network is genuinely vast: more locations than any bank or post office in the country. But the terminal on the counter is only a fraction of what the business has become, and understanding the rest matters to the argument of this paper.
Behind that familiar front end, PayPoint is a financial-infrastructure company serving over 1,300 major organisations across government, utilities, housing, corporates and financial services. Through its MultiPay platform it processes payments worth billions across every channel imaginable – Direct Debit, Open Banking, card and cash – giving housing associations, local authorities and energy companies a single place to collect from their customers however those customers choose to pay. Sitting alongside MultiPay are several distinct businesses within the same group: Love2shop, the employee-rewards and prepaid-card brand accepted by dozens of major retailers; RSM2000, a Bacs-approved bureau that processes Direct Debit and Direct Credit for organisations that would rather not run that infrastructure themselves; and AperiData, a strategic investment that uses Open Banking to deliver real-time affordability assessments – telling a housing officer or debt adviser what they need to know about a customer’s finances in under three minutes.
And then there is obconnect, a PayPoint subsidiary that handles around 20% of all Confirmation of Payee requests in the UK – the name-checking technology that stops money being sent to fraudsters – processing approximately 35 million API calls every single month, and which delivered the national account-verification scheme for the whole of New Zealand. So yes, PayPoint is in your corner shop. It is also deep inside the plumbing of the UK’s financial system in ways most people never see.
That breadth is not a corporate aside; it is the premise of this exercise. PayPoint is, in effect, a titan in payments and banking operating in a field of narrower fintechs – able to do almost anything in this domain short of holding deposits. It builds and sells the very tools that reduce payment risk to more than a thousand organisations. The obvious question is whether a business like that turns those tools on itself. As with every large plc, joining the dots internally takes time; disparate systems accrue as companies are acquired and integrated. This paper describes what happened when a focused team set out to close that loop.
2. The risk is who you pay, not how much
Payment security is habitually framed around the mechanics of the transaction. Is the value correct? Is it authorised by the right person under the right limit? Has it settled through the intended scheme? These are necessary questions, and organisations invest heavily in answering them. But the dominant risk in a payment is not the sum or the mechanism. It is the beneficiary. If the account receiving the money belongs to the wrong party, every other control has already been satisfied – the payment simply leaves cleanly, correctly authorised, to the wrong place.
2.1 Why the beneficiary is the blind spot
Beneficiary detail is uniquely exposed for three structural reasons. First, it is data that lives for a long time between checks: a supplier’s bank account or an employee’s salary destination is captured once, at onboarding, and then trusted indefinitely. Second, it changes for entirely legitimate reasons – companies restructure and re-bank, people marry, divorce and switch current accounts – so a change in the record is not, in itself, a red flag. Third, that very legitimacy is what fraud exploits: an attacker’s whole objective is to make a malicious change look like one of the many innocent ones that occur every week. The result is a control gap hiding in plain sight, because the organisation is confident the details were right when they were first entered.
2.2 The national picture
The scale of the problem is well documented. Authorised push payment (APP) fraud – where a payer is deceived into sending money to an account they believe is legitimate – cost UK victims £450.7 million in 2024, according to UK Finance’s Annual Fraud Report 2025. The defining characteristic of APP fraud is that the payment itself is genuine and fully authorised; the deception is entirely in the beneficiary. Regulation has responded by making receiving firms share liability for reimbursing victims, which sharpens the commercial case for verifying the payee – but the underlying lesson is older and broader than any single rule: the money is lost at the beneficiary, not at the button.
2.3 How it plays out inside organisations
For businesses, the same logic produces two well-worn attack patterns. The first is invoice redirection, often delivered through business email compromise: a supplier’s genuine invoice arrives, but the bank details have been quietly altered – or a convincing ‘we’ve changed our bank’ notice is sent – and the payment, correct in every other respect, lands in a fraudster’s account. Because supplier payments are large and routine, this is the most valuable prize an attacker can take. The second is payroll diversion, where a salary is routed to the wrong account, whether through error, an un-notified bank change, or coercion. In both cases the organisation’s payment controls perform exactly as designed; they were simply never pointed at the question that mattered.
2.4 Why bank channels do not catch it
It is reasonable to assume the bank will catch this. In practice it usually cannot. Bank channels are, historically, a tool for viewing balances and moving money; they were not built to attest to who a beneficiary really is, and the technology to flag a beneficiary problem is not readily available inside them. Access to those channels is also tightly limited by design, so the people responsible for onboarding a supplier or maintaining payroll rarely have the means to check within the banking interface at all. The capability to verify the payee therefore has to be added deliberately, as a layer around the payment process – which is precisely what the review set out to do.
3. The review — approach and method
A small team with deep transactional-banking backgrounds – spanning clearing, agency, corporate and payment-provider work – was assembled to examine PayPoint’s own payments with a fresh and constructively critical eye. It is worth stating plainly that this was never an exercise in finding fault. The internal teams were, by any measure, slick, and notably open to challenge. The goal was to augment strong existing processes, not to grade them.
One pattern emerged quickly. PayPoint had robust controls for making payments, but drew on disparate information for onboarding the people and businesses it pays – the unavoidable consequence of integrating seven different companies without disrupting day-to-day operations. Differing platforms for differing purposes is simply the reality of any large group. That made discipline about scope essential. Boiling the ocean is never a good plan when delivering change; iteration is what actually lands. The team therefore chose a single, clear, high-value starting point rather than a sweeping programme.
The organising principle was attestation around the beneficiary. If you build strong attestation around who you pay – both suppliers and staff – risk diminishes very quickly, because you are addressing the variable that all the other controls take on trust. The team began where the values, and therefore the exposure, are greatest: suppliers.
4. Suppliers — the highest-value target
Suppliers are the highest-risk beneficiary category for a straightforward reason: the values are larger, which makes supplier takeover the most valuable outcome a fraudulent actor can engineer. The review layered beneficiary verification on top of PayPoint’s standard onboarding rather than replacing anything. Alongside the usual credit checks and company history, PayPoint used its own Confirmation of Payee service to confirm two things that matter enormously and are seldom checked together.
- That the bank account name actually matched the company being paid – the direct defence against invoice redirection and altered bank details.
- That the accounts being paid were business accounts, not personal ones – a simple but powerful signal, because a legitimate supplier is rarely asking to be paid into a personal current account.
The value of that second check is easy to underestimate. A great many payment problems reduce to a personal account sitting where a business account should be, whether through a supplier’s own sloppiness or a deliberate diversion. Confirming account type turns a vague sense of trust into a verifiable fact.
The outcome speaks for itself. PayPoint has had no invoice fraud for three years – a period that coincides with the launch of its Confirmation of Payee service. As part of this review, the team examined more than £300,000 of supplier payments to a deeper level of assurance. Every one matched. The changes that did surface were organic – the ordinary drift of company details over time – rather than anything nefarious. That is a clean bill of health, but it is only meaningful because it was verified rather than assumed; the same result taken on trust would have proven nothing at all.
5. Payroll — the harder, more sensitive problem
Staff payments are considerably harder to review. The underlying data is highly sensitive, and – as expected – the review team could not see it directly. The approach PayPoint took to securing staff data was, in the team’s experience, refreshingly strong. Salaries also carry a distinct and under-appreciated set of beneficiary risks, summarised below.
| # | Risk in staff payments | Why it matters and how it is mitigated |
|---|---|---|
| 1 | An error in the details the employee supplies | A single transposed digit or wrong sort code sends salary to a stranger’s account. Verifying the name against the account at onboarding catches it before the first payment run. |
| 2 | The employee moves bank and forgets to tell payroll | Salary is routed to a closed or reassigned account, causing failed or misdirected payments. Periodic re-verification surfaces the change before it bites. |
| 3 | Short-term temporary staff on- and off-boarded quickly | High churn means details are captured fast and rarely re-checked, so errors slip through. A check at onboarding is the only realistic control point. |
| 4 | Modern-slavery or coerced salary diversion | Pay is directed to an account controlled by someone compromising the worker. This is more common than many employers realise, and beneficiary verification is one of the few controls that can expose it. |
The first practical step was to empower the HR team to validate staff bank records, including a retrospective review of previous salary runs to highlight any anomalies and confirm that they had already been raised by the employee concerned. The findings were revealing without being alarming. Some staff were paid using a hybrid of their name that differed from the exact account name; some were paid into a partner’s or joint account; some used initials where a full name was expected. Each of these is the kind of harmless inconsistency that accumulates in any payroll over time – and each is also exactly the kind of ambiguity that a verification check is designed to resolve.
Crucially, every member of staff was being paid to the right place. Not one salary had gone to a wrong account. But the review still produced real value: it allowed PayPoint to update married names, correct divorced names, and confirm that the accounts being paid were the correct target for the money. In total, 63 staff records were updated for consistency – again, the product of ordinary life changes rather than wrongdoing.
One detail from the exercise is worth dwelling on, because it is a misconception many organisations share. The HR team had a checker on their digital banking that validated the format of a payment file, and reasonably assumed this was a Confirmation of Payee check. It was not. It confirmed only that the file being submitted was in a Bacs-acceptable format – a useful control, but one that says nothing about whether the money is going to the right person. Recognising that gap led the team to trial a file-checking service that validates the file format and, in the same pass, confirms that the records within it have been CoP-checked. That single change turns a purely technical validation into a genuine beneficiary control.
6. What the findings tell us
Taken together, the supplier and payroll reviews point to a set of durable lessons that apply well beyond PayPoint.
- Not all changes are malicious. The overwhelming majority of beneficiary changes are entirely innocent, which is exactly why they are dangerous to ignore – the noise hides the signal.
- Things change over time. Businesses restructure and re-bank; people marry, divorce and switch accounts. Stored beneficiary data decays continuously, whether or not anyone updates it.
- Fraud hides inside the innocent change. Attackers deliberately use the ruse of a routine ‘we’ve updated our details’ to slip a malicious change past weak controls.
- Organic drift is the norm. Many businesses and employees change details and simply forget to tell you, leaving records quietly out of date.
- Early sight of life changes prevents disruption. Staff life events can look like risk, but catching them early prevents any interruption to payment rather than causing one.
- Suppliers are the highest-value target. They are both the highest-risk point and the most valuable takeover for a fraudulent actor, because the values involved are simply greater.
- Bank channels will not do this for you. The technology to detect beneficiary problems is not readily available in bank channels, and access to those channels is historically restricted to a few people.
7. A practical framework
The lesson is emphatically not that PayPoint had a problem; it did not. It is that assurance comes from process rather than assumption, and that the beneficiary is where that process should be concentrated. For any organisation making supplier or payroll payments, the review translates into a clear, implementable set of actions.
- Verify who you pay before the point of payment. Checking at the moment money moves is too late — by then the payment is already leaving. Build beneficiary verification into onboarding and into the ongoing maintenance of the record, so the check happens well ahead of the transaction.
- Confirm the account is a business account, not a personal one. A large share of issues comes down to a personal account sitting where a business account should be. Confirming account type is a cheap check that removes a whole class of risk.
- Correlate name changes with other records. When a name changes, checking it against public and corporate records turns a bare change into corroborated assurance – and makes a fraudulent ‘change’ far harder to land.
- Never rely on aged data. Stale beneficiary records are the single biggest weakness. Treat verification as a recurring and event-triggered activity, not a one-off performed at onboarding and forgotten.
- Check at the file level, not just the format. Ensure that whatever validates your payment files confirms the records have been CoP-checked, rather than merely confirming the file is technically well-formed.
- Augment, don’t accuse. This is not about finding fault or implying that current records are wrong. Confidence that details are correct is healthy; verifying that confidence is healthier, and it protects the people running the process as much as the organisation’s money.
8. Conclusion
PayPoint began this exercise confident that everything was correct, and in substance it was: no invoice fraud in three years, no salary paid to a wrong account, and a clean bill of health across suppliers and staff alike. Yet the review still delivered tangible value – updated records, confirmed business accounts, a corrected assumption about what a routine ‘checker’ actually checked, lowered risk, and measurable time saved. That is precisely the point. Verification is not an accusation that something is wrong; it is the discipline that keeps ‘right’ true as the world changes around it.
The risk in a payment lives in the beneficiary details and how you manage them over time, not in the payment itself. Verify who you pay, keep that verification current, and correlate change against reliable sources, and the largest category of payment risk shrinks – quietly, continuously, and before it can ever cost you. For a business like PayPoint, which already builds these capabilities for the wider market, turning them inward is less a project than a homecoming. For everyone else, it is one of the highest-return moves available in payment security today.
About obconnect
obconnect is a Confirmation of Payee and Verification of Payee provider, and part of the PayPoint Group. It handles around 20% of all UK CoP requests – roughly 35 million API calls a month – as both requester and responder, holds Pay.UK Aggregator status, and delivered the national account-verification scheme for New Zealand. obconnect helps banks, corporates and financial institutions verify the beneficiary before the money moves, turning ‘who you pay’ from the biggest gap in payment security into a controlled, continuous check.
Source: UK Finance, Annual Fraud Report 2025 (APP fraud losses of £450.7m in 2024).

