ACH in 2026: every business that originates a payment now has to monitor it for fraud
Payment Review Editorial Team
Payment Review Editorial Team

If you take payments straight from customers' bank accounts — subscription dues, invoice payments, rent, tuition, a cheaper checkout option next to the card buttons — a Nacha rule that used to apply only to the largest originators now applies to you. It reached everyone else on 22 June 2026, and unlike most payments compliance it is not something your provider can quietly absorb on your behalf.
This article works from Nacha's own rule pages rather than from bank client bulletins, because the bulletins mostly describe what banks must do and skip the part that lands on the business originating the payment.
The rule text is short and, for once, worth reading in the original. It requires each non-consumer originator, third-party service provider and third-party sender to establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud. Phase 1 applied that to the big originators — six million entries or more in 2023 — and to every ODFI. Phase 2 applies it to everybody else.
Three drafting choices tell you how to read it. Nacha removed the phrase "commercially reasonable", which had been the standard for WEB debit screening, and it replaced "detection system" with "processes and procedures". It also wrote that the obligations apply to the extent relevant to the role the entity plays. Taken together, that is a rule aimed at what you do, not at what you buy. A five-person business originating a few hundred debits a month is not expected to run what a payroll bureau runs.
Two further clarifications matter in practice. Monitoring is not required before processing — you are not obliged to hold entries while something inspects them. And the processes must be reviewed at least annually, which is the part that turns this from a project into a recurring obligation. If nothing in your business writes down what you looked at and when, the annual review is the requirement you will fail first.
The same package added a defined term, False Pretenses, covering payments induced by someone misrepresenting their identity, their authority to act for another party, or the ownership of the account being credited. That is business email compromise, vendor impersonation and payroll diversion. Nacha is explicit that it does not cover scams involving fake, non-existent or poor-quality goods — a buyer who is disappointed is not a False Pretenses case.
Merchants routinely assume the originator is their bank or their payment provider. The originator is the party that authorises the entry to be sent — in a bank-debit checkout, that is you. Your provider is very often a third-party sender or third-party service provider, which means the rule lands on both of you, each to the extent of the role you play.
That split matters when you go looking for who does what. A platform that accepts money on behalf of its own users — the model Moov is built for — will usually carry its own obligations layered on top of yours, and is worth asking directly how it classifies itself. A gateway that hands you an ACH rail alongside cards, like PayTrace with its Trace ACH product for large-ticket B2B invoices, is not thereby doing your monitoring for you. And an API-first bank-transfer provider such as Dwolla gives you the hooks to build monitoring, which is not the same as having it.
The March 2026 package also standardised two company entry descriptions, and the second one catches a lot of online sellers by surprise.
The PURCHASE requirement is narrower than it first reads: it is about goods, not services, and about consumer authorisations, not business ones. But if you sell physical products and offer bank debit at checkout, the description field in your file has to carry that word now. Nacha wrote in an unusual escape hatch — the ODFI has no obligation to verify that the word is present or accurate — which means nobody upstream is likely to catch it for you. Check what your provider is populating rather than assuming it changed in March.
The next dated change is one you receive rather than one you do. From 18 September 2026, for any credit entry that is not a Same Day entry, the receiving bank must make the funds available for withdrawal no later than 9:00 a.m. in its local time on the settlement date. The old rule carried a condition — the credit had to have reached the bank by 5:00 p.m. on the prior day — and that condition is gone.
In practice this accelerates the tail: next-day credits that arrive in the late evening or in the early-morning operator file, which previously could sit until the afternoon. If your business is on the receiving end of ACH payouts, invoice payments or refunds, the worst case moves earlier. A related change effective the same day creates a limited exception for banks located east of the Atlantic time zone and west of the international date line, including Guam and the Northern Mariana Islands, where a next-day credit can physically arrive after 9:00 a.m. local time.
Further out, the Same Day ACH per-payment limit rises to $10 million on 17 September 2027. That is worth knowing now if you are choosing between ACH and a wire for large B2B settlements, because it changes the answer for a band of payments that currently have to go by wire.
Fraud monitoring is a process obligation with no metric attached. The metrics that do trigger attention are the return rates, and they have not changed — but they are what a bank will point at when it asks whether your new processes are working.
Administrative returns are the ones a merchant can usually fix cheaply, and there has been a rule pointing at the fix since 19 March 2021. Account validation is an explicit part of the fraud-detection system originators of WEB debits already had to run: the account must be validated before its first use and before any change to the account number. Nacha does not mandate a method — a prenotification, a micro-entry or a commercial validation service all qualify — and the minimum it asks you to establish is that the account is open and can accept ACH entries. If your administrative return rate is drifting toward 3%, that rule is where to look before you look anywhere else.
The useful questions are narrow and you should get them answered in writing. Which entry descriptions is my traffic carrying today? Am I the originator, and are you a third-party sender? What monitoring do you already run on my behalf, and what does it look at? What return-rate reporting do I get, broken out by unauthorised, administrative and overall? Providers vary a great deal here. CSG Forte documents its ACH settlement timing and verification tiers unusually plainly for the sector, which makes those questions easy to answer. GoCardless, built around recurring bank debit and mandate handling, prices failed payments explicitly at $5 each — a number that tells you exactly what a rising return rate costs. Card-first platforms like Stripe will hand you ACH as one more payment method, and the monitoring question there is genuinely worth asking rather than assuming.
One caveat on continuity: the bank-payments corner of this market has been consolidating. Dwolla was acquired by NMI on 19 May 2026, and an acquisition is a reasonable moment to ask a provider to restate in writing what it monitors and what it reports.
Nothing here obliges you to buy fraud-detection software, screen entries before you send them, or monitor credits you receive — that last one is a duty on receiving banks, not on you. Nothing here changes ACH authorisation requirements, mandate storage or the return windows. And nothing here makes ACH riskier than it was; the network moved 35.2 billion payments worth $93 trillion in 2025, and 18.2 billion payments worth close to $50 trillion in the first half of 2026 alone, with Same Day ACH volume up 26.6% year on year. The rule exists because that scale is now worth attacking.