Salta al contenuto principale

Nacha's 2026 ACH Fraud Monitoring Rule: What Every Business Must Do

8 minuti di letturaMike ThriftMike Thrift
Nacha's 2026 ACH Fraud Monitoring Rule: What Every Business Must Do

The Rule That Quietly Changed How Every ACH Payment Gets Checked

If your business has run payroll, paid a vendor, or collected a customer payment by direct deposit this year, you've already been affected by a rule change you probably never heard announced. Starting in the spring of 2026, Nacha — the organization that governs the ACH network carrying more than $90 trillion a year in direct deposits, vendor payments, and bill pay — began requiring nearly every company that originates ACH transactions to run active fraud monitoring on those payments. Not "should." Required, under the Nacha Operating Rules that every bank and payment processor in the network has agreed to enforce.

For years, ACH fraud prevention was mostly a best-practices conversation: banks recommended controls, some companies adopted them, and enforcement was inconsistent. That changed because ACH credit-push fraud — criminals tricking a business into sending money to an account they control, usually through a compromised email or a fake vendor invoice — has exploded as check fraud and wire fraud have gotten harder to pull off. Nacha's response was to write monitoring into the rulebook itself, with real deadlines and real consequences for skipping it.

Here's what actually changed, who has to comply, and what a small or mid-size business needs to do about it.

The Two-Phase Rollout, in Plain Terms

The rule didn't arrive all at once — Nacha staged it so the network's biggest players went first, giving smaller originators more runway.

Phase 1 — March 20, 2026. This phase applied to all Originating Depository Financial Institutions (ODFIs — the banks that submit ACH files on behalf of businesses), plus any Originator, Third-Party Sender, or Third-Party Service Provider whose 2023 origination or transmission volume exceeded 6 million entries. In practice, this meant large payroll processors, big banks, and high-volume payment platforms had to have fraud monitoring live first.

Phase 2 — June 19, 2026 (practically, Monday, June 22, since the 19th fell on a federal holiday). This is the phase that swept in everyone else: every remaining Originator, Third-Party Sender, and Third-Party Service Provider, plus Receiving Depository Financial Institutions (RDFIs — the banks that receive ACH deposits into accounts). If your business originates ACH payments at any volume and your bank or payment processor wasn't already covered under Phase 1, this is the deadline that applies to you. There is no small-business carve-out. A five-person consultancy paying two contractors by ACH is technically under the same rule as a national retailer, though the sophistication expected of the monitoring scales with the size and risk of the originator.

Alongside the monitoring requirement, Nacha also standardized two "Company Entry Description" fields that show up on bank statements: PAYROLL, which must now label ACH credit entries representing wages, salaries, or similar compensation (technically, Prearranged Payment and Deposit — PPD — credits), and PURCHASE, used for consumer e-commerce debit entries. Both took effect March 20, 2026. If you run payroll through a provider and have noticed your employees' pay stubs or bank statements now consistently say "PAYROLL" instead of your company name or an inconsistent internal code, this is why — and it's a deliberate anti-fraud measure, not a cosmetic change. A consistent, predictable descriptor makes it easier for banks (and employees) to spot a fraudulent look-alike transaction.

What "Fraud Monitoring" Actually Requires You to Do

Nacha's rule doesn't hand businesses a rigid checklist of software to buy. It requires a risk-based process — documented, reasonably designed to catch fraud, and consistently applied — rather than any single specific tool. In practice, based on how banks and payment platforms have implemented it, that process needs to cover a few things:

  • Account ownership verification. Before releasing funds, especially to a new payee or an account that recently changed, there should be a process to confirm the receiving account actually belongs to the person or business you intend to pay — not just that the account number is formatted correctly.
  • Change monitoring. When a vendor "updates" their bank details, or an employee's direct deposit account changes right before a payroll run, that event should trigger extra scrutiny rather than an automatic update. This is the single most common vector for ACH fraud: a convincing email from "accounts payable" or a compromised vendor account asking you to redirect payment to a new account.
  • Anomaly detection. Unusually large payments, first-time payees, off-cycle or emergency payroll runs, and payments that don't match a business's normal pattern should be flagged for a second look before they're released.
  • Documentation and audit trail. Whatever process you use, you need to be able to show — with dates, methods, and outcomes — that you checked. A verbal "we always call to confirm" isn't enough if there's no record of the calls actually happening.
  • Escalation procedures. A documented path for what happens when something looks off: who reviews it, who has authority to hold or reject a payment, and how quickly that happens.

Manual, one-person "four-eyes" approval on payments is generally considered insufficient on its own at any meaningful transaction volume — the expectation is that controls are consistent and repeatable, which usually means at least some automation, even if it's just a rules-based flag inside your accounting or payroll software rather than a dedicated fraud platform.

Who's On the Hook, and What Happens If You Skip It

The rule places direct responsibility on Originators, Third-Party Senders, and Third-Party Service Providers — but the ODFI that submits your ACH file to the network is also required to have oversight in place, which means your bank has every incentive to make sure you're actually complying, not just to assume you are. If you use a payroll provider, invoicing platform, or payment processor to originate ACH transactions on your behalf, ask them directly: are they Nacha-compliant under Phase 2, and what verification evidence can they provide you if your bank asks?

The consequences for non-compliance run in two directions. First, there's the direct exposure: Nacha rule violations can carry fines, and repeated or serious violations can put a bank's or processor's ability to originate ACH transactions at risk — which trickles down to you if your provider loses that access. Second, and more immediately relevant for most small businesses, is the fraud exposure itself. Under Nacha's rules, an originator that fails to exercise reasonable care in verifying a payment can bear more of the loss when that payment turns out to be fraudulent, compared to one that followed a documented process. In other words, the monitoring requirement isn't just regulatory box-checking — skipping it can mean your business eats a fraud loss that a documented verification process might have caught or shifted.

A Practical Compliance Checklist for a Small Business

You don't need an enterprise fraud platform to meet the spirit of this rule. A few concrete steps cover most of what's expected:

  1. Ask your bank and payroll/payment provider what they've changed. Many banks rolled monitoring into their existing ACH origination portals automatically — find out whether you're covered by their controls or whether you're expected to run your own layer on top.
  2. Write down your verification process, even if it's simple. "Any new vendor bank account, or any change to an existing one, gets confirmed by phone at a known number before the first payment" is a real, documented, risk-based control. The key is that it's written down, followed consistently, and produces a record.
  3. Never update payment details based on an email or invoice alone. This single habit stops the majority of business email compromise and vendor-impersonation fraud, which is exactly the fraud pattern this rule targets.
  4. Flag payroll and vendor changes for a second reviewer. If you're a solo operator, that might mean a fixed 24-hour delay before a new bank account receives its first payment, giving you time to independently verify.
  5. Keep records of your checks. A simple log — date, what was verified, how, and by whom — is enough for most small-business risk profiles and gives you something to point to if a payment is later disputed.

Where Bookkeeping Fits Into Fraud Prevention

Fraud monitoring and clean bookkeeping solve overlapping problems. A payment redirected to a fraudulent account is much easier to catch quickly — before the money is unrecoverable — when your books are current enough to notice an unfamiliar payee or an amount that doesn't match your normal vendor pattern. Businesses that reconcile weekly or monthly, rather than quarterly, tend to catch anomalies while there's still a chance to claw the payment back through their bank.

This is one of the quieter arguments for keeping your accounting records transparent and easy to audit rather than locked inside a black-box tool you only open at tax time. Beancount.io gives you plain-text, version-controlled accounting, so every transaction — including every ACH payment you originate — is a reviewable, diffable line in your ledger rather than a record buried in someone else's database. Get started for free and see what it's like to have full visibility into your books whenever you need it, not just when something's already gone wrong.

Condividi questo articolo