Secure payments for businesses

Electronic payments are an integral part of day-to-day business operations. Companies should therefore be aware of the legal provisions and technical requirements governing electronic payments. Above all, they should ensure that their payment transactions are safe.

Smooth and safe cashless payments for businesses

Within the Single Euro Payments Area (SEPA), cashless euro payments are processed efficiently, cost-effectively and securely – following a standardised procedure in a secure environment.

Two security mechanisms are in place to prevent incorrect transfers and online fraud: the IBAN-name check (verification of payee) and strong customer authentication (two-factor authentication – 2FA).

Learn more about IBAN-name check and 2FA

What is the difference between the IBAN-name check and 2FA?

The main difference is that the IBAN-name check verifies the payees’ account details, whilst 2FA verifies the identity of the senders of payment orders.

The IBAN-name check is carried out automatically for every SEPA credit transfer (both standard and instant credit transfers). It uses a traffic light system, indicating whether the payee’s name matches the IBAN provided. A warning will be displayed if the two don’t match.

2FA is used to verify the identity of anyone accessing an account and initiating payment orders from it.

For recurring payments (direct debits), 2FA is only required when setting up, amending or initiating the payment order for the first time. 2FA is not required for the recurring payments that are subsequently carried out automatically under the direct debit mandate.

EU: Delegated Regulation (EU) 2018/389 - strong customer authentication

What does this mean for businesses?

This means that businesses should ensure that they

  • the account holder’s name and IBAN stated on their invoices are  
  • keep their own payment systems up to date with latest technological developments
  • coordinate any technical adjustments with their payment service provider in good time
Learn more about the IBAN-name check

What legal requirements must be observed?

Throughout the European Economic Area (EEA), electronic payments in euro are subject to the uniform requirements set out in the EU’s Single Euro Payments Area (SEPA) Regulation.

EU: Single Euro Payments Regulation

What does this mean for businesses?

For businesses, this means that they

  • must accept IBANs from other EEA countries for payments (i.e. credit transfers and direct debits) and may not reject them solely on the basis of the IBAN’s country of origin
  • electronic transfers must generally be processed within one banking day
  • bear in mind, when making payments to SEPA countries outside the EEA, that EU legal requirements (such as those relating to charges and fees) do not apply to these countries
Learn more about SEPA

Adequate safety measures are important

Around the world, cyberattacks on the systems and data of companies and their customers are on the rise. Payment fraud is particularly common. It mostly relates to credit transfers and card payments. To prevent financial loss and data misuse, companies should therefore take steps to effectively protect themselves and their customers – for example, through secure payment processing.

What does this mean for businesses?

This means that businesses should ensure that they

  • transmit sensitive payment data in encrypted form
  • clearly regulate access rights to payment systems
  • protect payments by using strong authentication
  • as a security measure, convert sensitive data into nonsensitive digital tokens where appropriate (tokenisation)
  • regularly check payment processes for potential security gaps
  • work only with trustworthy payment service providers
  • use up-to-date software and carry out regular security updates
  • set up firewalls
  • implement systems to detect fraudulent transactions

In addition to these technical measures, it is advisable to adopt an appropriate security strategy, comprising

  • clear security guidelines and procedures
  • regular security checks
  • policies for dealing with security breaches
  • regular reviews and updates of the security strategy