Building a payment form or writing unit tests? You may need checksum-valid IBAN-shaped values to exercise formatting and validation. A value that passes MOD-97 is not automatically a payment-provider test credential and is not safe to submit to a live payment system.
Using customer IBANs in development is risky:
- A misconfigured staging environment could initiate real transfers
- An IBAN linked to an identifiable person can be personal data under applicable privacy law
- Copying production banking data into development can violate your organisation's access, retention, and test-data policies
Sample Test IBANs by Country
The values below are public format examples that pass length and MOD-97 checks. They are not guaranteed to be unassigned accounts or accepted sandbox values. Use them only in isolated validator tests, never on a payment rail.
Western Europe
| Country | IBAN | Length |
|---|---|---|
| Germany | DE89 3704 0044 0532 0130 00 |
22 |
| France | FR76 3000 6000 0112 3456 7890 189 |
27 |
| Spain | ES91 2100 0418 4502 0005 1332 |
24 |
| Italy | IT60 X054 2811 1010 0000 0123 456 |
27 |
| Netherlands | NL91 ABNA 0417 1643 00 |
18 |
| Belgium | BE68 5390 0754 7034 |
16 |
| Austria | AT61 1904 3002 3457 3201 |
20 |
| Ireland | IE29 AIBK 9311 5212 3456 78 |
22 |
Northern Europe
| Country | IBAN | Length |
|---|---|---|
| United Kingdom | GB29 NWBK 6016 1331 9268 19 |
22 |
| Sweden | SE45 5000 0000 0583 9825 7466 |
24 |
| Denmark | DK50 0040 0440 1162 43 |
18 |
| Norway | NO93 8601 1117 947 |
15 |
| Finland | FI21 1234 5600 0007 85 |
18 |
Eastern Europe
| Country | IBAN | Length |
|---|---|---|
| Poland | PL61 1090 1014 0000 0712 1981 2874 |
28 |
| Czech Republic | CZ65 0800 0000 1920 0014 5399 |
24 |
| Hungary | HU42 1177 3016 1111 1018 0000 0000 |
28 |
| Romania | RO49 AAAA 1B31 0075 9384 0000 |
24 |
Need format fixtures for countries not listed here? Use our random IBAN generator to create synthetic values for supported patterns. The generator does not verify bank-code currency, account existence, or provider-sandbox compatibility.
How Test IBANs Are Generated
The process involves four steps:
- Pick a country — determines the IBAN length and format
- Fill the bank-code position — match the country's character pattern; use a provider-supplied value when testing an integration
- Generate an account number — random digits matching the country's length
- Calculate check digits — using the MOD-97 algorithm
For a detailed explanation, see our IBAN validation guide.
Unit Testing with IBANs
Your test suite should cover:
Checksum-valid cases:
DE89370400440532013000✓GB29NWBK60161331926819✓FR7630006000011234567890189✓
Invalid cases:
- Wrong check digits:
DE00370400440532013000✗ - Invalid country:
XX89370400440532013000✗ - Incorrect length ✗
- Empty string ✗
Edge cases:
- IBANs with spaces
- Lowercase letters
- Mixed formatting
Payment Provider Test IBANs
Payment-provider sandboxes often reserve specific account values for success, refusal, verification, or pending scenarios. Those values and behaviours are provider-specific and can change. Copy them from the current official documentation for the exact API, country, payment method, and test environment you use. A RandomIBAN output or a public SWIFT format example must not be presented as a Stripe, Adyen, Mangopay, or other provider sandbox credential unless that provider currently documents it.
Form Testing Checklist
| Scenario | Expected |
|---|---|
| Standard checksum-valid IBAN | Accept the checksum layer |
| Checksum-valid IBAN with spaces | Accept after cleanup |
| Checksum-valid IBAN in lowercase | Accept after normalization |
| Wrong check digits | Reject with clear error |
| Wrong length for country | Reject |
| Invalid country code | Reject |
| Empty field | Required field error |
| Random text | Format error |
Best Practices
Do:
- Use format- and checksum-valid synthetic IBAN fixtures
- Test multiple countries (not just German IBANs)
- Test edge cases: shortest (Norway, 15 chars) and longest (Malta, 31 chars)
- Separate test and production environments
- Document test IBANs in a shared test data dictionary
Don't:
- Use real IBANs in tests (even your own)
- Hardcode test IBANs in production code
- Assume all IBANs are the same length (15–34 characters)
- Skip country-specific testing
- Use test IBANs from one payment provider with another
Multi-Currency Testing
| Currency | Country | Public format example |
|---|---|---|
| EUR | Germany | DE89 3704 0044 0532 0130 00 |
| GBP | UK | GB29 NWBK 6016 1331 9268 19 |
| CHF | Switzerland | CH93 0076 2011 6238 5295 7 |
| SEK | Sweden | SE45 5000 0000 0583 9825 7466 |
| NOK | Norway | NO93 8601 1117 947 |
| PLN | Poland | PL61 1090 1014 0000 0712 1981 2874 |
| CZK | Czech Republic | CZ65 0800 0000 1920 0014 5399 |
The practical rule is to use synthetic, access-controlled fixtures for local format tests and the payment provider's current designated values for sandbox integration tests. Keep both categories blocked from production. You can generate fresh structural fixtures with our Random IBAN Generator, subject to its documented limits.