Skip to content
IBANforge
Provenance

Every answer names its source

Bank data is worth exactly as much as the register it comes from. That is why every IBANforge response carries the name and the date of the reference set that produced it — and where a publisher attaches conditions, they are honoured in the product: most travel inside the response itself, the rest live in the documentation that describes it.

Three habits, enforced by tests

Named and dated

Responses carry source and as_of fields read from the loaded data, never written by hand. A claim about being measured has to be measured.

Absent, never guessed

When a register does not answer, the field is null or absent. An absence is information, and each docs page spells out what it means for that register.

Guarded on every push

Tests fail the build if a served figure drifts above the live count, if a surface names an authority the shipped data no longer supports, or if any language promises account-level verification.

With written permission

Where we asked, and the publisher answered.

Bank of England — List of Banks (PRA)

Used with the Bank of England's written permission (August 2026). Its condition — attribution together with the month of the list — travels inside every pra_authorisation block, read from the loaded data so a refresh can never leave a stale credit behind.

Public licences, honoured to the letter

Where the publisher's own terms authorise reuse, the condition is honoured — inside the response where it binds to served data, in the documentation otherwise.

European Banking Authority

The EBA's legal notice authorises reproduction “provided the source is acknowledged”. The PSD register data therefore carries its source and copy date on every answer — and it is served only where the join to an IBAN's bank code is proven, which today means Spain.

FATF

The FATF permits commercial use of its country-list data with credit. The exact attribution line is published in our data-sources documentation, and the requirement carries onward to reuse of this API's FATF-derived fields.

Deutsche Bundesbank

The Bankleitzahl file is used with the attribution in the register's own wording — “Quelle: Deutsche Bundesbank” — and refreshed monthly.

European Central Bank & Banco de España

Both MFI lists require telling users the data is available free of charge at the source. Every official_identity block therefore says so explicitly: free_of_charge is a licence condition served as a field.

National registers, consulted and named

Switzerland and Liechtenstein resolve against SIX BankMaster, Germany against the Bundesbank, Austria against the OeNB, Belgium against the Banque nationale de Belgique, Finland against Finance Finland — each hit names its register in bank_code_check.register and dates it in as_of. Where no national register is consulted, the composite BIC map answers instead, and the response says it is not authoritative.

The long version, register by register

What we do not claim

  • No account-holder verification: validation proves structure, checksum and the institution behind the code — never that an account exists or who holds it.
  • Sanctions screening is at bank level (BIC8), not name level, and the compliance response repeats this itself. It is not a regulated AML/CFT product.
  • No “CBPR+ conformity” boolean: that guideline is unreachable to automated readers, and a verdict quoting an unread document would be a guess. The address check says so on every answer.
  • This page lists only what is settled. It grows as publishers answer — never ahead of them.