← Back to News
Fraud

ACH receiving banks must now screen incoming credits for fraud

Nacha’s fraud monitoring rule has covered every ACH participant regardless of volume since June 19, 2026, putting receiving banks on the hook for suspect incoming credits. The widened scope is reshaping demand for monitoring vendors.

Every receiving depository financial institution (RDFI) on the ACH Network, whatever its size, must now screen the payments it receives for fraud. The second phase of Nacha’s fraud monitoring rule took effect on June 19, 2026, and removed the volume thresholds that had limited the first phase to the largest players. The wider scope is reshaping the compliance market: on August 24, Nacha added Flagright to its Preferred Partner program for ACH compliance, fraud monitoring, and risk and fraud prevention.

The Automated Clearing House (ACH) is the US batch network for credit transfers and direct debits. Its rules are written by Nacha, the association of participating institutions, and updated through amendments put to a vote. The network carried 35.2 billion payments in 2025, up 4.9%, worth $93 trillion, up 7.9%. Same Day ACH accounted for 1.4 billion of those payments and $3.9 trillion. Business-to-business payments rose 9.9% to 8.1 billion, from 7.4 billion a year earlier.

The rule sets no dollar threshold and prescribes no tool

Nacha wrote the fraud monitoring requirement into its risk management rules. The rule sets no dollar threshold and does not prescribe any particular tool. Covered parties must “establish and implement risk-based processes and procedures reasonably intended to identify Entries that are suspected of being unauthorized or authorized under False Pretenses,” and review them at least once a year. Institutions are expected to document the systems they use, the alerts those systems raise and what happens when a transaction is flagged.

The requirement was phased in. Phase 1, effective March 20, 2026, applied to all originating depository financial institutions (ODFIs); to non-consumer Originators, third-party service providers (TPSPs) and Third-Party Senders with ACH origination volume of 6 million or more in 2023; and to RDFIs that received 10 million or more ACH entries in 2023. Phase 2, effective June 19, 2026, extended the rule to everyone else, regardless of volume.

PhaseEffective dateWho is covered
Phase 1March 20, 2026all ODFIs; non-consumer Originators, TPSPs and Third-Party Senders with 6 million or more entries in 2023; RDFIs that received 10 million or more entries in 2023
Phase 2June 19, 2026all other non-consumer Originators, TPSPs and Third-Party Senders; all other RDFIs
The two phases of the fraud monitoring rule
🔑
Receiving banks now have to screen credits
Until now, ACH risk management focused mainly on debits, for which the ODFI is accountable to the network. The 2026 rule requires the RDFI to examine incoming credits and catch those that are unauthorized or were obtained under false pretenses.

To that end, the rules introduce the concept of False Pretenses, defined as “the inducement of a payment by a Person misrepresenting (a) that Person’s identity, (b) that Person’s association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited.” The target is business email compromise, payroll impersonation, vendor impersonation and romance scams. In practice, an institution’s documentation is expected to cover:

  • the detection systems it uses and the alerts they generate;
  • the person or team responsible for monitoring;
  • when monitoring takes place, in real time or after processing;
  • what to do when a transaction is flagged;
  • the annual review of the program.
Server racks in a data center
The rule leaves the choice of tools open. It requires the setup to be documented, assigned an owner and reviewed every year.

Monitoring vendors vie for a larger pool of clients

With no volume threshold since June 19, 2026, the number of institutions and businesses covered jumped overnight. So did demand for monitoring vendors, whether specialist software firms or the risk modules already built into payment platforms.

Nacha has run its Preferred Partner program for several years. It is open to vendors whose products and services “align with Nacha’s core strategies to advance the modern ACH Network.” The program had 27 members in the summer of 2024, when four new categories brought the total to seven. Flagright, admitted on August 24, 2026, qualifies under three of them: ACH compliance, fraud monitoring, and risk and fraud prevention.

Flagright says its tool tracks incoming and outgoing payments, compares activity with expected behavior and ranks alerts according to the institution’s risk policy. Configurable rules look for rapid movement of funds, unusual payment patterns, signs of account takeover, money mule activity and multi-account abuse. Scoring draws on the amount, the customer’s and counterparty’s history, and machine-learning anomaly detection.

“Safety is paramount to all ACH Network payments, and fighting fraud is of the highest importance for Nacha,” said Jane Larimer, Nacha’s president and CEO. Baran Özkan, Flagright’s co-founder and CEO, said the network’s “continued growth depends on fraud and compliance controls that can keep pace with changing criminal behavior.”

ℹ️
A private rulebook, not federal law
The requirement applies in the US. It comes from the rules of Nacha, the private association that governs the ACH Network, not from a federal statute. The closest European mechanism, Verification of Payee under the EU Instant Payments Regulation, works differently: it runs before the payment is executed and is triggered by the payer’s PSP.

Provenance

Published August 24, 2026

6 sources, 4 distinct domains

↗ Nacha, “Risk Management Topics (Fraud Monitoring Phase 1)” · nacha.org↗ Nacha, “Risk Management Topics (Fraud Monitoring Phase 2)” · nacha.org↗ Nacha, “Flagright Now a Nacha Preferred Partner for ACH Compliance, Fraud Monitoring, and Risk and Fraud Prevention,” August 24, 2026 · uk.finance.yahoo.com↗ PYMNTS, “ACH B2B Volume Hits 8.1 Billion Payments,” January 29, 2026 · pymnts.com↗ Kaufman Rossin, “2026 NACHA Rule Changes: Is Your Fraud Monitoring Ready?” · kaufmanrossin.com↗ Nacha, “Nacha Preferred Partner Program Adds Four New Categories” · nacha.org
← All news