ACH Fraud Prevention for Businesses: Rules and Controls

ACH moves an enormous amount of money with very little friction, which is exactly what makes it attractive to attackers. Nacha reported 35.2 billion ACH payments worth $93 trillion across the network in 2025, and the controls protecting that volume have tightened considerably over the past eighteen months. ACH fraud prevention for businesses has moved from best practice to written obligation.

For any company originating ACH, several of these controls now sit in the Nacha Operating Rules, with obligations that expanded twice in 2026 alone.

Here is what is required, what is merely sensible, and where most businesses have gaps.

Account Validation Is a Rule, Not a Recommendation

Since March 2021, originators of WEB debits, meaning consumer debits authorized over the internet or a mobile app, have been required to use a commercially reasonable fraudulent transaction detection system. At minimum, that system must include account validation.

Validation means confirming that the account you are about to debit is open, valid, and able to receive the transaction, before the first debit to that account. In practice this is usually handled through real-time verification at the moment the customer enters their bank details, rather than discovering the problem days later through a return.

The obligation applies to the first use of any account and to any account whose details change. It is not a one-time onboarding checkbox.

Validation is not required in the same way on the credit side, but skipping it there is a mistake. A credit pushed to a wrong account number is far harder to recover than a debit that simply returns, because the funds have already landed somewhere and getting them back depends on the receiving bank and the unintended recipient cooperating.

The 2026 Rule Changes That Widened the Net

Two sets of changes took effect this year, and together they represent the largest expansion of ACH fraud obligations in years.

Effective March 20, 2026, Nacha expanded its definition of ACH fraud to include payments authorized under false pretenses. This closes a real gap. Business email compromise, vendor impersonation, payroll redirection, and invoice fraud all involve a victim who genuinely authorized the payment, having been deceived about who was receiving it. Those scenarios previously sat outside the fraud framework, which limited both monitoring and recovery. The rule also places responsibility on receiving institutions, not just originating ones, to identify credits that appear unauthorized or obtained under false pretenses.

Effective June 22, 2026, risk-based fraud monitoring obligations extended to all remaining originating institutions and to all non-consumer Originators, Third-Party Senders, and Third-Party Service Providers, regardless of transaction volume. The volume-based exemptions that previously covered smaller originators are gone.

If your business originates ACH, this applies to you. Confirm with your provider what monitoring is running on your account and what your own obligations are under your origination agreement.

Return Rates Are Your Early Warning System

Nacha sets three return rate measures, and the distinction between them matters more than most originators realize.

The unauthorized return rate threshold is 0.5 percent, covering returns where the customer claims the debit was not authorized or the authorization was revoked. This is a hard threshold. Exceeding it is a direct rule violation and can trigger corrective action and enforcement through your originating institution.

The administrative return rate level is 3 percent, covering account closed, no account found, and invalid account number. This is a level, not a threshold, and the difference is deliberate. Crossing it is not automatically a violation. It permits Nacha to open a preliminary inquiry into your origination practices.

The overall return rate level is 15 percent, covering all debit returns for any reason. Same model as the administrative level: an inquiry, not an automatic violation.

The administrative rate is the most useful diagnostic of the three, because almost every administrative return is preventable at onboarding. A rising administrative rate means you are collecting bad account data, which is precisely the problem account validation solves.

Note also that a return coded R11, where the customer says the entry did not match the terms of the authorization, can be corrected and retransmitted without obtaining a new authorization, provided you send the corrected entry within 60 days after the return’s settlement date.

Controls Worth Having on the Collection Side

  • Validate every new account before the first debit, and revalidate whenever details change
  • Keep authorizations complete and retrievable, including the amount or how it is determined, the timing, and how the customer revokes; retain them for two years past termination or revocation
  • Monitor return rates monthly by category, not just in aggregate, so an administrative problem does not hide inside an acceptable overall number
  • Apply the correct Standard Entry Class code to every transaction, since authorization requirements differ by code
  • Set velocity and dollar limits appropriate to each customer relationship
  • Send advance notice of recurring debits so customers are not surprised into disputing them

Controls Worth Having on the Disbursement Side

Payroll and vendor payment fraud is where the large individual losses happen, and it rarely involves a technical compromise of the ACH network. It involves someone being persuaded to change a bank account on file.

The controls that work are procedural. Require dual approval for any change to vendor or employee banking details, and for any payment above a defined threshold. Verify change requests by calling a phone number you already have on record, never one supplied in the request itself. Treat urgency as a warning sign, since manufactured time pressure is the core technique in nearly every business email compromise attempt. Validate accounts before the first credit to a new payee. And train the people who process these changes, because they are the actual control surface.

Data Security Obligations

Non-consumer Originators, Third-Party Senders, and Third-Party Service Providers are required to render bank account information unreadable when it is stored electronically. Storing routing and account numbers in a plain spreadsheet, a shared drive, or an email folder does not meet this.

Beyond the rule itself, this is the single most common exposure in small businesses. Bank details accumulate in inboxes and files nobody has audited in years. Removing them is usually a short project with a large risk reduction.

Do Not Forget the Contact Registry and the Annual Audit

Two administrative obligations get overlooked. Contact details in the ACH Contact Registry must be kept current, because that registry is how other institutions reach you about a suspected fraudulent or erroneous entry, and stale information costs recovery time when hours matter. Separately, originators are expected to conduct an annual ACH rules compliance audit. Doing it properly surfaces gaps before an inquiry does.

ACH Fraud Prevention for Businesses With ReliaFund

ReliaFund has processed ACH for businesses since 2001, and our platform is built with the controls originators are now required to have. That includes secure handling of bank account data, advanced fraud filters, and transaction-level reporting that shows activity from origination through settlement, so return patterns are visible while they are still small.

Our U.S.-based team knows the Nacha rules thoroughly and can review your current origination practices against them. We are also members of the TPPPA, which means we track rule changes as they develop rather than after they take effect.

Want your ACH controls reviewed against current Nacha requirements? Schedule a free consultation with our payment processing experts.

GET TIPS & INDUSTRY INSIGHTS DELIVERED TO YOUR INBOX

Something went wrong. Please check your entries and try again.
RECENT POSTS

ACH Fraud Prevention for Businesses: Rules and Controls