2026 NACHA rule changes: Is your fraud monitoring program ready?
Read
There are two revisions to the 2026 NACHA Rules related to fraud monitoring that Participating Depository Financial Institutions (PDFIs) should be aware of, and the effective dates are approaching quickly. These rule changes have potential impact on both Originating Depository Financial Institutions (ODFIs) and Receiving Depository Financial Institutions (RDFIs). It’s important to understand these new rules and the potential impact these revisions may have on your operations and originating customers.
Under the current NACHA Rules, Originators are required to use a “commercially reasonable” fraudulent transaction detection system to screen WEB debits and when using micro-entries. With these new rules, NACHA eliminated the “commercially reasonable” standard and replaced it with “risk-based” processes and procedures. Fraud attempts are on the rise, according to data from the Federal Trade Commission. These attempts include both ACH debit (pull) and ACH credit (push) transactions. One reason for the rise in ACH credit scams is that social engineering has become more sophisticated. Advances in AI have enabled fraudsters to create more convincing scams, leading to a rise in account takeovers. ACH credit scams include Business Email Compromise (BEC), payroll diversion, vendor payment diversion, romance scams, and fake investment platforms. According to NACHA, the new Rule updates are intended to reduce the incidence of successful fraud attempts and improve the recovery of funds after frauds have occurred.
Understanding the 2026 NACHA Rule Changes
Fraud Monitoring by Originators, Third-Party Service Providers/Third-Party Senders and ODFIs
This Rule amendment requires each ODFI, non-consumer Originator, Third-Party Service Provider, and Third-Party Sender to establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud. Each of these parties will need to review at least annually their processes and procedures and make any appropriate updates to address evolving risks.
The Rule will be implemented in two phases:
- Phase 1 – March 20, 2026:
- Applies to all ODFIs
- Applies to non-consumer Originators, Third-Party Service Providers, and Third-Party Senders with an annual ACH origination volume exceeding 6 million entries in 2023
- Phase 2 – June 19, 2026:
- Applies to all other non-consumer Originators, Third-Party Service Providers, and Third-Party Senders.
New Requirements for RDFIs: ACH Credit Monitoring
This Rule amendment requires RDFIs to establish and implement risk-based processes and procedures reasonably intended to identify credit ACH entries initiated due to fraud. RDFIs will need to review at least annually their processes and procedures and make any appropriate updates to address evolving risks. This Rule will also be implemented in two phases:
- Phase 1 – March 20, 2026:
- Applies to RDFIs with an annual ACH receipt volume exceeding 10 million entries in 2023.
- Phase 2 – June 19, 2026:
- Applies to all other RDFIs.
It should be noted that the new Rules require monitoring for “False Pretenses”, a new term which covers common ACH credit scams. NACHA’s definition for False Pretenses is the inducement of a payment by a Person misrepresenting (a) that Person’s identity, (b) that Person’s association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited.
Company Entry Descriptions
To help PDFIs monitor payments for specific purposes, there are also rule amendments related to Company Entry Descriptions. For PPD credits for payment of wages and salaries, the Company Entry Description field must contain the description “PAYROLL”. In addition, e-commerce purchases must contain the description “PURCHASE”. ODFIs, Originators, and Third-Party Service Providers will be required to comply with this rule by March 20, 2026. RDFIs have the option of using this information as part of their fraud monitoring practices but are not required to do so.
Next steps for financial institutions
PDFIs should first confirm their financial institution has established and implemented risk-based processes and procedures reasonably intended to identify ACH entries (both debits and credits) that may be initiated due to fraud. This includes:
- Identifying the fraud monitoring systems being used.
- Activating specific alert flags to detect potential ACH fraud.
- Assigning responsibility for monitoring these alerts.
- Determining the timing of monitoring (e.g., real-time or post-transaction).
- Establishing procedures to follow when fraudulent activity is detected.
The Rule does not mandate specific dollar-value ‘threshold minimums’ for fraud detection, and PDFIs would be expected to maintain baselines to differentiate between typical activity and potentially anomalous activity. Additionally, integrating the results of fraud monitoring efforts into the broader compliance workflow is essential, as confirmed fraudulent activity exceeding regulatory reporting thresholds, including those initiated via “False Pretenses” triggers mandatory Suspicious Activity Reporting (SAR) filing obligations.
Financial institutions should also ensure their ACH fraud risk assessment is current and reflects the evolving fraud risks addressed in the new NACHA rules. If the institution has not recently performed a fraud risk assessment specific to ACH activity, management should consider conducting or updating one to evaluate potential vulnerabilities related to both ACH debit and credit transactions, including schemes involving false pretenses. The results of this assessment should be used to inform the design and implementation of risk-based monitoring processes and procedures required under the updated rules.
If it’s determined that fraud monitoring procedures will need to be updated to comply with the new Rules, applicable policies and procedures should be updated to reflect the new processes. PDFIs should update their policies to mandate an annual review of fraud monitoring processes, ensuring their effectiveness. The review should be documented, with results shared with executive management and/or the board. Training should be provided to applicable employees to ensure awareness and understanding of the processes and controls in place to comply with the new fraud monitoring rules.
ODFIs should also determine whether their financial institutions have non-consumer originators, third-party senders, or third-party service providers. While financial institutions are generally familiar with fraud monitoring practices, their non-consumer originators may not be. These Originators may not have procedures in place to identify ACH entries initiated due to fraud. ODFIs should ensure these parties are aware of the new rules and obtain an understanding of their plan to address and comply with the rule requirements by the applicable established deadline. In addition, Originator ACH agreements may need to be updated to ensure they address Originator fraud monitoring responsibilities.
Navigate compliance with confidence
If you have questions about how these new NACHA rules may affect your institution, contact a member of Kaufman Rossin’s risk advisory services team. Our experienced professionals can assist you in analyzing your current processes, identifying potential gaps, and provide recommendations on control enhancements to strengthen your fraud monitoring program and mitigate the risk of non-compliance with NACHA Rule requirements.
Sarah Fernandez, CIPP/US, CRCM, AAP, Risk Advisory Services Director at Kaufman Rossin, one of the Top 50 CPA and advisory firms in the U.S.
Yanelis Perez, CAMS, Financial Crime Risk Management Principal at Kaufman Rossin, one of the Top 50 CPA and advisory firms in the U.S.
Please correct the following errors: