Business

ACH fraud monitoring is now required: what your organization needs to know

ACH fraud monitoring information

If your organization initiates ACH transactions, Nacha Rules now require non-consumer Originators to maintain fraud monitoring processes1 and procedures in place designed to help identify potentially unauthorized or fraudulent ACH transactions.

The requirement became effective on June 19, 2026, for non-consumer Originators. Organizations should review their ACH fraud controls and confirm they are appropriate for the nature and risk profile of their ACH activity.

What the rule requires

Your organization must maintain fraud monitoring processes and procedures reasonably designed to identify ACH transactions that may be unauthorized or the result of fraud schemes, particularly fraud involving false pretenses such as business email compromise (BEC)vendor impersonation, payroll redirection, or account takeover.

The rule doesn’t require sophisticated technology or a dedicated fraud team. Your fraud monitoring processes and procedures simply need to be appropriate for the size of your organization, the volume of ACH activity you send, and the fraud risks most relevant to your business, and should be reviewed at least annually to address evolving risks. While Nacha does not prescribe a specific documentation format, maintaining written procedures can help support consistency and oversight.

What we may ask you to provide

As part of our ongoing risk management and compliance efforts, we may periodically request information about your ACH fraud prevention and monitoring processes and procedures. Understanding the controls you have in place helps us support your ACH services and maintain a secure payment environment.

You may be asked to:

  • Complete a questionnaire about your organization’s ACH fraud monitoring practices
  • Provide a brief overview of the controls and procedures you use to help detect fraud
  • Confirm that your fraud monitoring practices have been reviewed and remain appropriate for your organization’s ACH activity
  • Participate in a discussion with your relationship manager about your ACH risk management approach

Important: Nacha Rules require ACH Originators to maintain fraud monitoring processes and procedures and review them at least annually to help address evolving fraud risks. Organizations should take time to evaluate their existing ACH controls and determine whether updates are needed based on their payment activity and risk profile.

While Nacha does not require a specific monitoring method or documentation format, maintaining clear internal procedures and records of fraud prevention controls can help promote consistency and support ongoing oversight.

Disclosures

1This information is provided for general informational purposes only and does not constitute legal, compliance, or operational advice. Originators are responsible for ensuring their own compliance with the Nacha Operating Rules and applicable agreements.

Leave a Reply

Your email address will not be published. Required fields are marked *

FINANCIAL WELLNESS

Learning Center

Go beyond banking with resources and news to learn how to make informed financial decisions.

ACH fraud monitoring
Budgeting

ACH fraud monitoring requirements

business email compromise
Fraud

Business email compromise

Accounts payable fraud
Fraud

Accounts payable fraud