back to blog

After the Nacha Deadline: What ACH Fraud Monitoring Evidence Should Show

Read Time 3 mins | Written by: Karly Field

Documents and magnifying glass

Nacha’s 2026 fraud-monitoring rule changes are now in effect, including the Phase 2 requirements that expanded coverage to all remaining non-consumer Originators, Third-Party Senders, and Third-Party Service Providers, regardless of origination or transmission volume. Phase 2 also extended ACH credit-monitoring responsibilities to all Receiving Depository Financial Institutions, regardless of ACH receipt volume.

The rule became effective June 19, 2026. Because June 19 was a federal holiday, Nacha identified Monday, June 22 as the practical effective date. By now, the conversation should move beyond awareness of the deadline and toward a practical review of the process your institution has in place.

What the Phase 2 requirements mean

At a high level, the requirements call for risk-based processes and procedures reasonably intended to identify ACH entries suspected of being unauthorized or authorized under False Pretenses. Nacha’s definition of False Pretenses includes payment instructions based on misrepresented identity, authority, or account ownership—scenarios that can include business email compromise, vendor impersonation, payroll impersonation, and other payee impersonation schemes.

For RDFIs, the focus is incoming ACH credit monitoring. The institution has visibility into incoming transactions, the receiving account, account history, and other account characteristics. That context can help identify activity that is unusual for the account or inconsistent with the institution’s risk assessment.

Nacha does not prescribe one specific technology or process. It also does not require an RDFI to screen every ACH entry individually or to perform monitoring before processing. The requirement is risk-based, relevant to the role the participant plays, and subject to review at least annually with appropriate updates as risks evolve.

Nacha, Risk Management Topics – Fraud Monitoring Phase 2: https://www.nacha.org/rules/risk-management-topics-fraud-monitoring-phase-2

Five questions to ask about your ACH monitoring process

1. Is ownership clear? Who is responsible for ACH fraud monitoring, alert review, escalation, and reporting? If responsibilities are divided across fraud, operations, compliance, and relationship teams, are the handoffs documented?

2. Are you using the right context? Can your process evaluate ACH activity against account history, transaction behavior, velocity, amount, account characteristics, SEC Codes, and other relevant metadata?

3. What happens when activity looks unusual? Is there a defined path for review, customer contact, internal escalation, potential return decisions, and communication with the ODFI when appropriate?

4. Can you document the decision? Can your team record what triggered the review, what information was considered, who made the decision, and what action followed?

5. When will you review the process? Nacha requires the processes and procedures to be reviewed at least annually and updated for evolving risks. Is that review scheduled, assigned, and documented?

What a practical monitoring workflow can include

A bank’s approach will depend on its role, risk assessment, transaction profile, existing controls, and available data. A practical workflow may include:

  • Establishing normal activity baselines for accounts and transaction relationships
  • Identifying unusual amounts, velocity, frequency, timing, counterparties, or SEC Code patterns
  • Scoring or prioritizing activity based on risk and available historical context
  • Routing higher-risk activity for investigation and documented review
  • Escalating potential fraud to the appropriate operations, fraud, compliance, or relationship teams
  • Recording the rationale for the decision and the action taken
  • Reviewing the process at least annually and updating it as fraud patterns change

A better question than ‘Are we compliant?’

A yes-or-no compliance question can hide important operational gaps. A more useful question is: Can our team show how suspicious ACH activity is identified, who reviews it, what information supports the decision, and how the decision is documented?

That is where a repeatable, risk-based monitoring process matters. ACH RiskLens is designed to support risk-based monitoring of ACH originations and activity, identify anomalous behavior, use standardized ACH metadata, and provide visibility for investigation, review, and escalation. It can help financial institutions turn a broad rule requirement into a workflow their teams can operate and evaluate.

Ready to review your process?

Finovifi can help you evaluate your ACH workflow and determine whether ACH RiskLens fits your needs.

Framework Will Help You Grow Your Business With Little Effort.

Karly Field