Payments Glossary · Law & Regulation
Nacha Fraud Monitoring Rules
Also called Nacha risk management rules, ACH fraud monitoring, Phase 1 Phase 2
Nacha rules requiring risk-based ACH fraud monitoring, extended in June 2026 to essentially every business that originates ACH.
What it is
Nacha, which writes the operating rules for the ACH network, phased in fraud monitoring obligations across 2026. Phase 1 took effect March 20, 2026, requiring risk-based processes to detect ACH entries initiated due to fraud, and applying to all ODFIs, to originators, third-party senders and third-party service providers above a 6 million entry 2023 origination volume threshold, and to RDFIs above a 10 million entry 2023 receipt threshold. Phase 2 is the one that reaches ordinary businesses. Effective June 19, 2026, with the practical compliance date of Monday June 22, 2026, the same obligations extend to all remaining non-consumer originators, third-party service providers, third-party senders and receiving institutions below the Phase 1 thresholds. Receiving institutions must screen inbound credits for entries suspected to be unauthorized or authorized under false pretenses, and an annual review and update is required. The same March 20, 2026 date brought standardized company entry descriptions, requiring PAYROLL for wage credits and PURCHASE for consumer e-commerce debits. Other dated items follow: a Treasury ACH contact registry on July 24, 2026, IAT clarifications and funds availability changes on September 18, 2026, accepted characters and IAT amendments on January 1, 2027, an increase in the Same Day ACH per-entry limit from 1 million to 10 million dollars on September 17, 2027, and a new return reason code R90 for sanctions compliance on March 17, 2028. The obligation sits on the originator, not only on the bank.
Why it matters to your business
If your business originates ACH, and that includes recurring dues, membership billing, tenant or association collections, payroll through your own file, and business-to-business invoicing, then as of June 22, 2026 you are expected to have documented, risk-based fraud monitoring procedures, reviewed annually. Almost no small business has addressed this. The work is not exotic: written procedures describing how you verify a change in bank details, dual approval above a dollar threshold, callback verification on new payees using a number you already had, and a note of who reviews it and when. That is also the exact control set that stops business email compromise, which is the fraud most likely to actually take money from a Southwest Florida small business. This is education, not legal advice; your specific obligations flow from Nacha rules and your agreement with your ODFI.
Where it gets contested
The design question is whether a rule written for financial institutions can be meaningfully applied to a fifteen-person business that originates ACH for recurring dues. Nacha's answer is risk-based, which is genuinely flexible, but flexibility is not the same as clarity, and there is no published safe harbor describing what an adequate small-originator program looks like. Enforcement is the practical unknown. Nacha rules bind participants through the ODFI relationship, so in practice the obligation reaches a small originator through its bank's contract rather than through direct examination. Whether banks push documented programs down to small originators or simply attest on their behalf varies, and that variation is not public. What is not in dispute is the underlying problem. Authorized-under-false-pretenses fraud, which covers business email compromise and payment redirection scams, is the fastest growing loss category in business payments, and it sits outside traditional unauthorized transaction frameworks because the payment was authorized by the victim.
How to check it yourself
Ask your bank or ACH provider whether you are classified as an Originator under Nacha's rules and what documented fraud monitoring they expect from you. Then write a one-page procedure covering payee bank detail changes and callback verification, date it, and calendar an annual review.
Receipts
Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.
-
Nacha fraud monitoring Phase 2 effective June 19, 2026 extends risk-based fraud monitoring to remaining originators, third parties and receiving institutions, including screening for entries authorized under false pretenses
nacha.org ↗ -
Phase 1 effective March 20, 2026 with volume-based thresholds
nacha.org ↗ -
Nacha's index of new rules and effective dates including company entry descriptions, funds availability, Same Day ACH limits and R90
nacha.org ↗ -
2026 Nacha compliance guidance for businesses
bottomline.com ↗