
Stronger ACH Fraud Controls Are Here: What Nacha's Rules Now Require
Nacha’s ACH fraud monitoring requirements are now in force.
Phase 2 eliminated the volume threshold, so any organization originating non-consumer ACH entries is in scope regardless of size. Covered participants need documented, risk-based processes designed to identify entries suspected of being unauthorized or authorized under false pretenses.
The need is growing with the network. In 2025, the ACH Network moved 35.2 billion payments worth $93 trillion. Volume increased 4.9% and value increased 7.9% year over year. Business-to-business ACH volume rose 9.9% to 8.1 billion payments.
Fraud exposure is significant. The 2025 AFP Payments Fraud and Control Survey found that 38% of organizations experienced ACH debit fraud, 20% experienced ACH credit fraud and 63% experienced check fraud in 2024. The FBI’s Internet Crime Complaint Center reported nearly $8.5 billion in business email compromise losses from 2022 through 2024, including nearly $2.8 billion in 2024.
Key takeaways
Phase 2 removed the volume threshold. There is no small-originator exemption for non-consumer ACH originators.
Nacha requires risk-based processes designed to identify unauthorized entries and entries authorized under false pretenses.
The rules do not require real-time monitoring of every transaction or a specific technology platform.
Covered participants must review their processes at least annually and update them for evolving risks.
What do Nacha’s fraud monitoring requirements now require?
For ACH participants involved in origination, Nacha requires two things:
Establish and implement risk-based processes and procedures relevant to the role your organization plays in authorizing or transmitting entries.
Design those processes to identify entries suspected of being unauthorized or authorized under false pretenses, then review and update them at least annually.
The requirement applies to ODFIs, non-consumer Originators, Third-Party Senders, and Third-Party Service Providers that perform ACH processing functions. The process should match your payment activity, risk profile and responsibilities.
What do the rules not require?
Nacha does not prescribe one operating model or one technology solution. The rules do not require you to:
Screen every ACH entry individually.
Monitor every transaction before processing.
Use a specific vendor, detection model, or workflow.
That flexibility does not make monitoring optional. Nacha states that a risk-based approach should not be used to conclude that no monitoring is necessary. At minimum, organizations should assess risk and distinguish higher-risk activity from lower-risk activity.
Who is in scope, and when?
Nacha implemented the requirements in two phases.
Phase 1 took effect March 20, 2026. It applies to all ODFIs, non-consumer Originators, Third-Party Senders, and Third-Party Service Providers with 2023 ACH origination volume of 6 million or more. It also applies to RDFIs with 2023 ACH receipt volume of 10 million or more for ACH credit monitoring.
Phase 2 took effect June 19, 2026. Because June 19 was a federal holiday, Nacha clarified that the practical compliance date was the next banking day, Monday, June 22, 2026. Phase 2 eliminated the volume threshold and extended the requirements to all remaining non-consumer Originators, Third-Party Senders, and Third-Party Service Providers, regardless of volume.
If your organization originates non-consumer ACH entries, you should treat the Phase 2 requirement as applicable now.
What does “false pretenses” mean?
Nacha defines false pretenses as inducing a payment by misrepresenting a person’s identity, association with, or authority to act on behalf of another person, or ownership of an account to be credited.
This definition brings scenarios such as business email compromise, vendor impersonation, and payroll diversion into the monitoring conversation. It complements rules covering unauthorized credits and account takeover.
The definition does not cover disputes involving fake, nonexistent, or poor-quality goods or services. Those are different types of commercial disputes, not the false-pretenses scenarios addressed by this rule.
What does risk-based fraud monitoring look like?
A risk-based program starts with a written assessment of where fraud could enter your ACH workflow. Consider how payment information is captured, changed, approved, and transmitted. Then document the controls that address those risks.
Your program should explain:
Which activity receives enhanced scrutiny.
What creates an alert or review.
Who investigates the alert.
Which actions are available.
What decision was made and why.
How evidence and outcomes are retained.
Nacha specifically points to factors such as volume, velocity, dollar amounts, and Standard Entry Class codes. Originators may also need change controls for vendor and payroll payment instructions.
As September planning begins, connect this annual review to your broader compliance calendar. The annual ACH rules compliance audit is due by December 31, making Q4 a practical time to test controls, review alert outcomes, and update procedures. A rules engine written three years ago reflects three-year-old customers, products, and fraud patterns.
Which red flags should a program monitor?
Use one consolidated set of risk indicators across payment operations, treasury, and accounts payable:
Sudden changes to vendor or employee payment details, especially when the request comes through an unusual channel.
Sharp increases in payment count or dollar volume compared with the account’s normal baseline.
Payment amounts outside the expected range for a vendor, employee, department, or transaction type.
Small-dollar test transactions followed by larger payments or withdrawals.
Multiple ACH credits from unrelated sources followed by rapid withdrawals, which may indicate mule-account activity.
These indicators do not prove fraud. They identify activity that may require additional review, confirmation, or escalation.
What should a non-consumer originator do now?
Start with five practical steps:
Map responsibilities. Identify your ODFI, Third-Party Senders, and Third-Party Service Providers. Document which party owns each control and what oversight your organization performs.
Create risk tiers. Define higher-risk activity using factors such as payment changes, velocity, dollar amounts, account history, and transaction type.
Document the response workflow. Specify how teams stop, review, confirm, escalate, or return suspicious activity.
Use return data as a diagnostic. Analyze return codes by business unit, channel, account type, and transaction pattern. The ACH returns explainer provides additional context.
Schedule recurring reviews. Test alert quality, investigate unexplained changes, and update controls at least annually—or more often when products, threats, or payment behavior change.
How CSG Forte supports a layered ACH risk program
A layered approach separates account checks before submission from behavioral monitoring as payment activity unfolds.
Before funds move, CSG Forte’s three verification services answer different questions. Validate asks whether the account details appear valid. Validate+ adds broader account-status and risk information when available, including closed accounts, stop-payment indicators, and insufficient-funds or returned-item history. Authenticate asks whether the personal or business name provided matches the account owner.
Read the ACH verification services comparison, verification solution overview, ACH validation page, and account authentication page for more detail.
Verification reduces avoidable risk, but it does not guarantee that a payment will clear. Verification occurs before an entry reaches the receiving bank. Account status, available funds, and payer behavior can change afterward. For example, R01 and R09 reflect funds problems; R07 and R08 reflect revoked authorization and stop payments; R10 and R29 reflect unauthorized debits; and R02 and R16 reflect closed or frozen accounts.
For ongoing monitoring, CSG PaymentsProtection.ai adds AI-supported, near-real-time monitoring across ACH and card activity, with configurable risk controls, alerts and reporting. It complements—not replaces—account validation and ownership checks.
For a broader view of monitoring design, read the transaction monitoring guide. Effective programs combine data, risk segmentation, alert review, case management, reporting, and ongoing tuning.
These services are components of a broader risk management program. They do not, by themselves, ensure compliance with the Nacha Operating Rules. Each organization remains responsible for its own policies, procedures, oversight, and compliance obligations.
Watch the on-demand webinar
Watch From Authorization to Recovery: Mastering Fraud & Risk Management with CSG Forte COO Jeanette Mbungo and Amy Morris, Senior Director of ACH Network Rules at Nacha.
The conversation examines what organizations should operationalize across authorization, monitoring, response, and recovery. If you want help reviewing your current posture, contact CSG’s risk management experts.
Frequently asked questions
When did Nacha’s ACH fraud monitoring requirements take effect?
Phase 1 took effect March 20, 2026. Phase 2 took effect June 19, 2026, with Monday, June 22, 2026, serving as the practical compliance date because June 19 was a federal holiday.
Does Phase 2 include small originators?
Yes. Phase 2 eliminated the volume threshold. Any organization originating non-consumer ACH entries is in scope regardless of size.
Do the rules require real-time monitoring?
No. Nacha does not require pre-processing monitoring or screening every entry individually. Organizations still need risk-based processes reasonably intended to identify suspected fraud.
How often should a fraud monitoring program be reviewed?
At least annually. The review should address evolving risks and may need to happen more frequently when payment behavior, products, or fraud patterns change.
Does account verification guarantee that an ACH payment will clear?
No. Verification occurs before settlement, and account status, funds, and payer behavior can change. The receiving bank makes the final decision when the entry is presented.