The two digits after the country code are the IBAN check digits. They are designed to catch common human mistakes such as swapped digits or a mistyped character.

The four mod-97 steps that produce IBAN check digits

How they are created

  1. Take the country code and BBAN.
  2. Insert 00 as temporary check digits.
  3. Move the first four characters to the end.
  4. Convert letters to numbers (A=10, B=11, ... Z=35).
  5. Calculate 98 - (number mod 97).

Important

Check digits only prove structural consistency. They do not prove that the underlying bank account exists.

A complete German calculation

Take the BBAN 370400440532013000 and country code DE. To calculate the two international check digits, first form DE00370400440532013000. Move the first four characters to the end to obtain 370400440532013000DE00.

The letter mapping starts at A = 10. D becomes 13 and E becomes 14, giving the numeric string 370400440532013000131400. Its remainder modulo 97 is 9. Subtracting from 98 gives 89, so the completed documentation example is DE89370400440532013000.

Generation and validation use different endings

Generation uses temporary digits 00 and computes 98 - remainder. Validation uses the actual check digits already present and expects a remainder of 1. For the completed example, rearrangement produces 370400440532013000DE89, which becomes 370400440532013000131489. That value has a remainder of 1.

Do not compare a generated check digit with the validation remainder. They are different outputs from related operations. Keep the result as a two-character string so leading zeroes are preserved.

Avoid large-number rounding in JavaScript

The converted string can be much longer than JavaScript’s safe integer range. Calling Number() on the entire value can silently round it. A simple alternative processes one decimal digit at a time, keeping only the current remainder:

function mod97(decimalString) {
  let remainder = 0;
  for (const digit of decimalString) {
    remainder = (remainder * 10 + Number(digit)) % 97;
  }
  return remainder;
}

This helper expects an already converted string containing digits only. Country recognition, exact length, allowed characters and normalization must happen elsewhere. It is one part of a validator, not a complete implementation.

What a checksum cannot tell you

The check digits help detect input errors, but they are not a signature, password or ownership check. Someone can calculate new check digits for a changed account component. A resulting number can pass MOD-97 without identifying a real or intended account. National check characters inside some BBANs are a separate rule and are not replaced by the two international digits.

Sources and scope

Swift: national IBAN formats and registration authority.

Examples and test matrices are explanatory fixtures, not receiving instructions. This page covers format checks and software testing. It does not verify account ownership or provide a guarantee that a payment will succeed.

Technical notes updated 8 October 2026. Read the editorial policy. Send a correction.