Compliance guide

Nacha 2026 risk rules, the ACH fraud standard that holds both sides accountable

From reactive to proactive: Nacha's 2026 risk rules put new ACH fraud monitoring and account verification obligations on both ODFIs and RDFIs.

  1. Oct 1, 2024Up nextNew framework activeExpanded R17 use and "False Pretenses" definition become official.
  2. March 20, 2026Up nextPhase 1 complianceFraud monitoring rules apply to large-volume non-consumer Originators, ODFIs, and TPSPs.
  3. June 19, 2026Up nextTodayPhase 2 complianceFraud monitoring obligations expand to ALL Originators and RDFIs.
  4. Today

Core implications & account verification

The new rules mandate a fundamental change in fraud strategy, shifting accountability to both senders and receivers through risk-based detection and payee verification.

Is account verification mandatory?

Not explicitly, but effectively, yes.

While the rules don't mandate bank account verification for every single ACH credit, they require a "risk-based process" to detect fraud. Account verification is considered a primary tool to fulfill this requirement, making it a de facto standard for a compliant program.

The two-sided responsibility model

Sending side

Originators, ODFIs, TPSPs

Duty: Detect deceptive intent before money moves.

The obligation is to have a robust process to detect fraudulent outbound payments, especially those induced by "False Pretenses."

Pre-payment controlsMust implement pre-payout verification of payee information before payment initiation.

Validating changesStrong verification is crucial when onboarding new payees or changing existing details.

Sender obligationsMust implement risk-based monitoring for outbound credits to detect fraud like BEC and payroll redirection. This includes verifying payee information, especially for new or changed accounts.

Receiving side

RDFIs

Duty: Detect deceptive context after money arrives.

The obligation is to monitor incoming ACH credits, shifting the RDFI to an active participant role.

Inbound screeningMust implement systems to flag suspicious inbound credits.

Return rightsClarified use of Return Code R17 for "False Pretenses" scams.

Receiver obligationsMust monitor inbound credits for anomalies. They gain the explicit right to return suspicious payments using R17 and can delay funds availability to investigate potential 'False Pretenses' fraud.

Detailed rules breakdown

All non-consumer Originators, ODFIs, TPSPs, and RDFIs must establish and implement "risk-based processes and procedures reasonably intended to identify fraudulent Entries." This is the core of the new requirement, forcing a move towards proactive screening of ACH credits, not just debits. The standard is no longer a vague "commercially reasonable" but a more specific obligation to actively detect fraud.

The rules introduce a formal definition for "False Pretenses," covering scams where a payment is induced by misrepresenting identity, authority, or account ownership. This specifically targets common fraud types like Business Email Compromise (BEC), vendor impersonation, and payroll redirection.

The rules explicitly codify the use of Return Code R17 (with the descriptor "QUESTIONABLE") for RDFIs to return an entry suspected of being fraudulent or initiated under "False Pretenses." This gives receiving banks a clear, sanctioned mechanism to push back against suspicious credits and aids in fund recovery.

To improve data quality and help monitoring systems, two new standardized descriptions are required for specific credit types:

PAYROLL: Must be used for PPD credits paying wages, salaries, or similar compensation.

PURCHASE: Must be used for e-commerce purchase debits using the WEB SEC code.

The IPID solution

IPID's payee verification capabilities directly address the Nacha mandate for pre-transaction (sending) and post-receipt (receiving) risk management.

Request demo

For the sending side

Comprehensive real-time payee verification satisfying Nacha's Phase 1 and Phase 2 duties.

More for the sending side

Improve payout accuracy

Real-time validation halts fraudulent payments before initiation, helping to reduce real-time payment fraud globally.

Enhance customer trust

A clear record of verification helps build trust in payments and ensures audit-ready compliance.

For the receiving side

Automates risk screening of incoming ACH credits, matching incoming payments against internal records to identify payments that may have been authorised under False Pretenses, significantly enhancing automated R17 return capabilities.

Commonly asked

Questions

Is bank account verification mandatory under the new Nacha rules?

Not explicitly, but effectively yes. The rules require a "risk-based process" to detect fraud, and account verification is considered a primary tool to satisfy that requirement — making it a de facto standard for a compliant program.

When do the Nacha 2026 fraud monitoring rules take effect?

Phase 1 (March 20, 2026) applies to large-volume non-consumer Originators, ODFIs, and TPSPs. Phase 2 (June 19, 2026) expands the obligation to all Originators and RDFIs.

Who has to comply with Nacha's 2026 risk rules?

All non-consumer Originators, ODFIs, TPSPs, and RDFIs. The obligation splits by side: senders must detect deceptive intent before money moves, receivers must detect deceptive context after it arrives.

Do the new rules require verifying payee information before paying?

Yes for the sending side. Originators, ODFIs, and TPSPs must implement pre-payout verification of payee information before payment initiation, with strong verification specifically required when onboarding new payees or changing existing account details.

How does payee verification help meet Nacha's 2026 requirements?

Real-time payee name, account, and routing verification lets senders satisfy the Phase 1/2 pre-payment duty, while automated screening of inbound credits helps receivers flag payments authorized under False Pretenses and support R17 returns.

Key terms

Automated Clearing House (ACH)

It is the primary network used for moving money electronically between bank accounts across the United States.

False pretenses

A newly defined term covering fraud where a payment is induced by misrepresenting identity, authority, or account ownership, for example, Business Email Compromise (BEC), vendor impersonation, or payroll redirection.

Nacha

Nacha governs the ACH Network, the payment system that drives safe, smart, and fast Direct Deposits and Direct Payments with the capability to reach all U.S. bank and credit union accounts.

ODFI and RDFI

An ODFI (Originating Depository Financial Institution) receives payment instructions from the Originator and forwards the entry into the ACH Network. An RDFI (Receiving Depository Financial Institution) receives that entry and posts it to the Receiver's account.

Return code R17

R17, with the descriptor "QUESTIONABLE," lets RDFIs return an ACH entry suspected of being fraudulent or initiated under False Pretenses, giving receiving banks a sanctioned mechanism to push back on suspicious credits.

From reactive to proactive

Book a demo