Bank account verification · methods compared
Is this account real, and is it theirs?
Money sent to a wrong account is hard to get back. Checking an account before paying it takes seconds. This guide compares the ways to check, explains the part that's actually hard (matching names) and shows where each check belongs in your flow.
Why check before you pay
A transfer to the wrong account usually succeeds. The bank doesn't know the account number was mistyped or supplied by a fraudster; it just credits the account it was given. Getting the money back then depends on the receiving bank and the account holder's cooperation, and it can take weeks, or never happen.
A check before the first payment costs little and stops three expensive problems:
Typos. One wrong digit sends the money to a stranger, or fails and delays a payment someone was counting on.
Closed accounts. Old details on file: the payment fails or comes back days later.
Someone else's account. The details belong to a real account, just not to the person you meant to pay. Often, that's fraud.
What a check can tell you, and what it can't
It can tell you
- The account number and IFSC point to a real account
- The account can receive money, at least for now
- The name the bank holds for the account, in most checks
It can't tell you
- That the person in front of you is that account holder
- That the account will still be open next month
- Anything about the person's identity beyond the name. That's KYC
Choosing a method
An account number and IFSC
and you want: A name back, from the widest range of banks
→ Penny dropSend ₹1; the bank's name for the account comes back with the credit.
An account number and IFSC
and you want: No money moved, nothing on their statement
→ Penny-less checkAn enquiry confirms the account without a transfer, where the bank supports it.
A UPI ID
and you want: Confirm the UPI ID before paying it
→ UPI ID checkValidates the UPI ID and returns the name registered against it.
| Penny drop | Penny-less | UPI ID check | Document (cheque, statement) | |
|---|---|---|---|---|
| Money moves | Yes, a small credit such as ₹1 | No | No | No |
| Name returned | Usually | Often, depends on the bank | The name registered to the UPI ID | Read by a person |
| Appears on their statement | Yes | No | No | No |
| Speed | Seconds, when the bank is up | Seconds | Seconds | Hours to days |
| Coverage | Widest | Varies by bank | UPI IDs only | Any account |
| Best for | Default for bank accounts | High volumes; no statement entry | UPI payouts | When automated checks fail |
Methods described generally. In depth: penny drop and penny-less verification.
Name matching: the hard part
Knowing an account exists is only half the check. The other half is whether the name the bank returns belongs to the person you meant to pay. And banks don't record names the way people type them.
Exact matching rejects too many genuine accounts. Loose matching lets the wrong ones through. Most businesses score how close the two names are, pay automatically above a threshold, reject below another, and send the band in between to a person. Set the thresholds for your risk: a ₹500 refund and a ₹5 lakh loan disbursal don't deserve the same tolerance.
| You have | Bank returns | Usually |
|---|---|---|
| Priya Ramesh Iyer | PRIYA R IYER | Match |
| Priya Iyer | IYER PRIYA | Match (order differs) |
| Mr Arjun Mehta | ARJUN MEHTA | Match (salutation) |
| Kaveri Packaging | KAVERI PACKAGING PVT LTD | Review: trade vs legal name |
| Priya Iyer | RAHUL SHARMA | No match: stop |
Illustrative names. Whether Peneu returns a match score, and how, is confirmed during onboarding.
Checking a UPI ID
When you pay people by UPI ID, the check is simpler: validate the UPI ID before the first payout. It confirms the UPI ID exists and returns the name registered against it, which you compare with your records just as you would for a bank account.
UPI IDs change more often than bank accounts: people switch apps and create new IDs. Re-check whenever someone gives you a new one, and don't reuse an old UPI ID from your records without asking.
Where a check belongs in your flow
| Moment | Why | If the check fails |
|---|---|---|
| Onboarding a seller, supplier or partner | You'll pay them repeatedly | Onboarding pauses until details are fixed |
| An employee's first salary | Payday failures are costly | HR asks for correct details before the payroll cut-off |
| Any change of bank details | The moment fraud most often happens | The change isn't saved; the old details stay |
| Loan disbursal | The money must reach the borrower's own account | Disbursal waits; the borrower confirms details |
| A refund to a different account | It isn't going back where it came from | Refund to the original method instead |
More on each flow: payouts, vendor payments, salary payments, NACH mandates.
Collecting details so the check passes first time
Many failed checks are really failed forms. The account number was typed on a phone keyboard, the IFSC was copied from an old cheque book, or the person pasted their UPI ID with a space at the end. A few small choices on the form prevent most of them.
There's also a privacy decision here. It's tempting to show the bank's name back to whoever typed the details (“We found an account in the name of PRIYA R IYER”), but that also shows an account holder's name to anyone who types an account number. Many businesses prefer to say only whether the details matched, and let a person look at mismatches.
Ask for the account number twice
And compare them before running any check.
Look up the IFSC
Show the bank and branch it belongs to, so a wrong code is obvious to the person typing it.
Trim and normalise
Remove spaces and stray characters from account numbers and UPI IDs before checking.
Say why
One line explaining that you'll check the account, and, for a penny drop, that a ₹1 credit will appear.
Fail helpfully
“We couldn't confirm this account. Please check the number, or use a different account” beats a code.
Different accounts, different names
The name a bank returns depends on what kind of account it is. Knowing that in advance saves a lot of false alarms at review.
| Account | Name the bank usually holds | Watch for |
|---|---|---|
| An individual's savings account | The person's name, often abbreviated | Initials, surname first, missing middle names |
| A joint account | Often the first-named holder only | A second holder whose name doesn't come back |
| A company or LLP current account | The registered legal name | Trade names, “Pvt Ltd” vs “Private Limited” |
| A proprietorship's current account | The business name, the owner's name, or both | Both are legitimate; decide which you'll accept |
What verification catches, and what it can't
Verification is very good at catching mistakes and simple fraud: a typo, a closed account, a fraudster's own account given in place of a supplier's. The name comes back wrong, and you stop.
It can't catch a fraudster who controls an account in the right name. So-called mule accounts, opened or rented in someone else's name, pass a name check because the name is genuinely the account holder's. Account verification is one layer; it works best alongside identity checks, limits on first payments and watching for unusual patterns.
Catches
Typos, closed accounts, wrong-person accounts, most bank-detail-change fraud
Doesn't catch
Accounts genuinely held in the right name but controlled by someone else
Add
Identity checks at onboarding, lower limits on first payouts, alerts on unusual changes
Recording results you can stand behind
Months later, someone will ask why you paid a particular account. “It was verified” is only an answer if you can show what was verified, how, and what came back. Keep the result alongside the account details it applies to.
When the account changes, the old result no longer applies. Keep it for the record, but pay the new account only once it has a result of its own.
- Account
- Masked number, IFSC, or UPI ID
- Method
- Penny drop, penny-less, UPI ID check or document
- Outcome
- Valid / invalid / no answer, with the bank's reason
- Name returned
- Exactly as the bank sent it
- Decision
- Auto-accepted, reviewed by whom, or rejected
- When
- Date and time of the check
When the answer isn't clear
Not every check ends in a clean yes or no. Treat the grey answers as “don't know yet”, and never as permission to pay.
The bank didn't respond
Retry later, or try the other method.
Account valid, no name returned
Try a method that returns a name, or ask for a document.
Name is a partial match
Send to review; ask the person to confirm the account holder's name.
Account can't receive this kind of credit
Ask for a different account.
Checking a whole list at once
Sometimes the accounts already exist and have never been checked: a supplier master inherited from an old system, a seller base migrated from another platform, a payroll moved from a previous provider. Checking them in one batch before the first run is much cheaper than discovering bad rows one failed payout at a time.
Plan it as a small project. Run the checks, sort the results into clear matches, clear failures and everything else, and fix the last two groups before they're due a payment. Contact people through channels you already trust, not by replying to whatever address is on file.
| Result | Next step |
|---|---|
| Valid, name matches | Mark verified |
| Valid, name differs | Review; confirm with the account holder |
| Invalid or closed | Ask for new details before the next payment |
| No answer | Re-run later or use another method |
Bulk checks usually run on the penny-less method first, to avoid sending hundreds of ₹1 credits.
Consent, purpose and what you keep
A verification result is personal data: an account number tied to a name. Tell people you'll check their account and why, use the result for that purpose, and keep it only as long as you need it. India's Digital Personal Data Protection Act, 2023 and your sector's own rules set what that means for you; check with your adviser.
Show account numbers masked everywhere except where they're strictly needed, and never paste them into chat or email to confirm them.
Wiring verification into your systems
Treat verification as a gate in front of paying, not as a report. The payment step should refuse an account that doesn't have a current result, and the result should belong to that exact account: a changed digit is a new account with no result.
- Tie results to the details. Store the result against the account number and IFSC (or UPI ID) it was produced for, so a change clears it.
- Make the check idempotent.Your own reference per check means a retried request after a timeout doesn't send a second ₹1.
- Keep the decision separate from the result.The bank's answer is data; “accepted by rule” or “approved by a reviewer” is your decision, recorded with who made it.
- Rate-limit by user.Especially for checks that return names, so the flow can't be used to look up strangers' accounts.
Account verification questions
How is bank account verification priced?
Usually per check, and it differs by method: a penny drop includes the ₹1 credit and a transfer, a penny-less check doesn't. How checks are priced on Peneu is confirmed per business on the pricing page.
What's the right order: KYC first or bank verification first?
Usually identity first, then the bank account, so you can compare the name the bank returns with a name you've already verified. Checking the account first only tells you whose account it is, not whether that's the person signing up.
Do I need to re-verify accounts periodically?
Not on a timer. Re-verify when details change, when a payment to the account fails as invalid, or when your own risk review asks for it. Accounts paid successfully and regularly are, in effect, being verified by every payment.
Should I verify an account before refunding a customer to it?
If the refund is going back to the original payment method, no. If it's going to a bank account the customer has just given you, yes: it's a new account, and refunds to a fraudster's account are a known pattern.
Can verification tell me if an account is a savings or current account?
Sometimes, depending on the method and the bank, but don't rely on it. If the account type matters to you, for example because you only pay businesses into current accounts, ask for it and confirm it with a document where needed.
Does verification guarantee the payment will succeed?
No. It tells you the account was valid when checked. The account can be closed or frozen later, and a payment can fail for reasons unrelated to the account. Always read each payment's own status.
Should I verify accounts that were given to me on a cancelled cheque?
It's still worth it. Cheque images can be old, edited or someone else's. An automated check confirms the account is current and whose it is, and the cheque becomes supporting evidence rather than the only evidence.
What does bank account verification confirm?
That an account number and IFSC point to a real account that can receive money, and, in most checks, the name the bank holds for that account. It doesn't prove that the person giving you the details is that account holder; that's what comparing the name, and your own identity checks, are for.
What's the difference between penny drop and penny-less verification?
Penny drop sends a small real credit, typically ₹1, and reads the result and the account holder's name that come back with it. Penny-less verification confirms the account through an enquiry without moving money. Penny drop tends to work across more banks; penny-less leaves nothing on the customer's statement.
Why doesn't the name returned match exactly?
Banks record names their own way: initials instead of first names, a different order, a salutation, or the legal name instead of a trading name. Exact matching rejects too many genuine accounts, so most businesses score how closely the names match and send borderline cases for a person to review.
When should I verify a bank account?
Before the first payment to it, and whenever the details change. That covers onboarding customers, sellers, suppliers and employees; loan disbursals; and refunds to an account other than the one that paid.
Can I verify a UPI ID too?
Yes. A UPI ID can be validated before you pay it, which confirms it exists and returns the name registered against it. It's the natural check for payouts to UPI IDs.
Do I need the account holder's consent?
Tell people why you're checking their account and use the result only for that purpose. What consent and notice you need, and how long you may keep the result, is governed by data protection law and your sector's rules; check with your adviser.
What if the check doesn't return a clear answer?
Treat it as unknown, not as failed. Banks are sometimes unavailable, and some don't return a name. Retry later, try the other method, or ask for a document such as a cancelled cheque, but don't pay the account until you have an answer you trust.
Which verification methods does Peneu provide?
Which methods are available, what each returns and how results are delivered is confirmed during onboarding. This guide explains the methods generally so you can decide what you need.
Check accounts before money moves
Tell us where you pay people and how many new accounts you see. We'll walk through the checks that fit.
Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.
