How IBAN check digits work

The MOD-97 method step by step, with a worked example you can follow on paper and a few lines of code.

Updated

The third and fourth characters of every IBAN are check digits. They are calculated from all the other characters with a method called MOD 97-10, defined in the ISO/IEC 7064 standard. When you type an IBAN, software repeats the calculation; if the result is wrong, the IBAN has a typo.

Checking an IBAN in four steps

Take the German example IBAN DE89 3704 0044 0532 0130 00.

  1. Remove the spaces: DE89370400440532013000.
  2. Move the first four characters to the end: 370400440532013000DE89.
  3. Replace every letter with two digits, where A = 10, B = 11 and so on up to Z = 35. Here D becomes 13 and E becomes 14: 370400440532013000131489.
  4. Divide this number by 97 and keep the remainder. If the remainder is 1, the IBAN is valid.

For the example, 370400440532013000131489 divided by 97 leaves exactly 1, so the check digits are correct.

Calculating the check digits

To create the check digits for a new IBAN, use the same steps with 00 in place of the check digits:

  1. Write the country code followed by 00 and the BBAN: DE00370400440532013000.
  2. Rearrange and convert as above: 370400440532013000131400.
  3. Compute the remainder of the division by 97. Here it is 9.
  4. Subtract the remainder from 98: 98 − 9 = 89. Pad to two digits if needed (for example 7 becomes 07).

The check digits are 89, which gives DE89370400440532013000. Because the result of step 4 always falls between 2 and 98, the check digits of a valid IBAN are never 00, 01 or 99.

Working with long numbers

The converted number has 17 digits for Norway, 24 for Germany and more than 40 for a Maltese IBAN that contains letters. Most are too long for a normal calculator or a 64-bit integer, which holds about 19 digits. You can split the number into pieces. Take the first nine digits, compute the remainder, write that remainder in front of the next digits, and repeat:

Step Number Remainder after dividing by 97
1 370400440 23
2 23 + 5320130 = 235320130 70
3 70 + 0013148 = 700013148 38
4 38 + 9 = 389 1

The final remainder is 1, the same result as the full division.

The same check in code

JavaScript, processing one digit at a time so no big numbers are needed:

function isValidIban(input) {
  const iban = input.replace(/\s+/g, '').toUpperCase();
  if (!/^[A-Z]{2}\d{2}[A-Z0-9]{11,30}$/.test(iban)) return false;
  const rearranged = iban.slice(4) + iban.slice(0, 4);
  let remainder = 0;
  for (const ch of rearranged) {
    const value = parseInt(ch, 36); // 0-9 stay digits, A-Z become 10-35
    remainder = (value > 9 ? remainder * 100 : remainder * 10) + value;
    remainder %= 97;
  }
  return remainder === 1;
}

Python, where integers can be as large as needed:

def is_valid_iban(value: str) -> bool:
    iban = "".join(value.split()).upper()
    if not (iban.isascii() and iban.isalnum() and 15 <= len(iban) <= 34):
        return False
    rearranged = iban[4:] + iban[:4]
    digits = "".join(str(int(ch, 36)) for ch in rearranged)
    return int(digits) % 97 == 1

These functions only check the structure and the check digits. A real validator also checks that the country uses IBANs and that the length matches that country, which the country formats list for every country we support.

To check a single IBAN by hand, paste it into the IBAN validator: it shows which check fails and, when only the check digits are wrong, the digits that would fit. If you would rather not maintain this code yourself, iban-check is our open-source library for JavaScript and TypeScript. It runs the full set of checks against the SWIFT IBAN Registry and has no dependencies. Install it from npm with npm install iban-check.

What the check catches

The method is good at finding the mistakes people make when typing. Every single mistyped digit and every swap of two neighbouring digits changes the remainder, so they are always detected. Other errors slip through roughly once in a hundred cases.

The check cannot tell whether an account exists. An IBAN with correct check digits can still point to a bank code that does not exist or to an account that was closed. That is why the IBANs from our generator pass the check even though no bank issued them.

National check digits

Some countries add their own check digits inside the BBAN, calculated with national rules. Italy's IBAN starts the BBAN with a letter called CIN, France and Monaco end it with the two-digit "clé RIB", Spain has two control digits between the branch code and the account number, and Belgium ends with two check digits. These checks are separate from the IBAN check digits: an IBAN can pass MOD-97 and still fail a national check. National check digits in the IBAN explains every method, country by country.

Sources

Need a test IBAN?

Generate a valid IBAN for any of 91 countries, copy it in the format you need and see what each segment means.

Open the generator