For paying invoices
Payment diversion doesn't look like fraud. It looks like a supplier you know, an invoice you were expecting, an amount you agreed, and a short note explaining that the bank details have changed. Everything checks out except the twenty characters that decide where the money goes.
The control you already know
This is the standard recommendation against payment diversion, and it works. The problem has never been the advice — it's that following it means finding last quarter's statement, squinting at a twenty-character string, and doing it again for the next invoice. So it gets skipped.
DoublyCheck is that control, automated. Nothing about the idea is new to you. Only the ten seconds it now takes.
The first time you verify a supplier's IBAN properly, scan it and save it under their name. That entry becomes your reference.
Point the camera at the IBAN on the paper or the PDF on screen. The mod-97 check digits are validated, then it's matched against what you saved.
Unchanged, and you pay. Changed, and you phone the supplier — on a number you already had, never the one printed on the invoice.
The obvious objection
Yes — and it's a genuinely good change. Since 9 October 2025, under the EU Instant Payments Regulation, euro-area banks must check the payee name you enter against the account behind the IBAN before you confirm a transfer. Banks in non-euro EU states follow by 9 July 2027.
It closes the typo problem completely. It does not close this one.
| Verification of Payee | DoublyCheck | |
|---|---|---|
| What it compares | The payee name you typed against the account holder's name at the receiving bank | The IBAN on this invoice against the IBAN you paid this supplier before |
| Catches a mistyped IBAN | Yes — the names won't match | Yes — check digits and comparison both fail |
| Catches a mule account opened in a matching name | No — it reports a match, and you proceed | Yes — it isn't the IBAN you had on file |
| Knows your payment history with this supplier | No — it has no memory of prior transfers | Yes — that's the entire point |
| When you find out | At the moment of payment, in the banking app | When the invoice arrives, before it enters the payment run |
| Coverage | SEPA credit transfers in euro | Any IBAN, plus crypto addresses |
The two checks answer different questions. Your bank asks "does this name belong to this account?" DoublyCheck asks "is this the account I've been paying?" A fraudster who has done their homework passes the first and fails the second.
Before you rely on it
DoublyCheck is built for the one person who actually pays the invoices. If that's two or three people in your office, some of this will matter — better you know now than after you've built a process around it.
Any of these blocking for you? Tell us — it's how the roadmap gets decided.
For advisors
You're the one clients ask after they read about payment diversion in the news — and the one they call after it happens. We're putting together a one-page client handout on invoice fraud: the four-eyes principle, verifying any change of bank details by phone on a number you already had, and where a tool like this fits.
If you'd like it with your own logo on it, get in touch and we'll send you a draft. No cost and no strings — we'd rather your clients had the advice than not.
We're based in Vienna and would genuinely rather hear what you've seen happen to a client than show you a demo.
contact@doublycheck.appCaspari e.U. · Vienna, Austria
No account to create, no data leaving the phone, and nothing for your IT provider to review before you try it.
Also sending crypto? See the wallet-address use case.