Every receiving depository financial institution (RDFI) on the ACH Network, whatever its size, must now screen the payments it receives for fraud. The second phase of Nacha’s fraud monitoring rule took effect on June 19, 2026, and removed the volume thresholds that had limited the first phase to the largest players. The wider scope is reshaping the compliance market: on August 24, Nacha added Flagright to its Preferred Partner program for ACH compliance, fraud monitoring, and risk and fraud prevention.
The Automated Clearing House (ACH) is the US batch network for credit transfers and direct debits. Its rules are written by Nacha, the association of participating institutions, and updated through amendments put to a vote. The network carried 35.2 billion payments in 2025, up 4.9%, worth $93 trillion, up 7.9%. Same Day ACH accounted for 1.4 billion of those payments and $3.9 trillion. Business-to-business payments rose 9.9% to 8.1 billion, from 7.4 billion a year earlier.
The rule sets no dollar threshold and prescribes no tool
Nacha wrote the fraud monitoring requirement into its risk management rules. The rule sets no dollar threshold and does not prescribe any particular tool. Covered parties must “establish and implement risk-based processes and procedures reasonably intended to identify Entries that are suspected of being unauthorized or authorized under False Pretenses,” and review them at least once a year. Institutions are expected to document the systems they use, the alerts those systems raise and what happens when a transaction is flagged.
The requirement was phased in. Phase 1, effective March 20, 2026, applied to all originating depository financial institutions (ODFIs); to non-consumer Originators, third-party service providers (TPSPs) and Third-Party Senders with ACH origination volume of 6 million or more in 2023; and to RDFIs that received 10 million or more ACH entries in 2023. Phase 2, effective June 19, 2026, extended the rule to everyone else, regardless of volume.
| Phase | Effective date | Who is covered |
|---|---|---|
| Phase 1 | March 20, 2026 | all ODFIs; non-consumer Originators, TPSPs and Third-Party Senders with 6 million or more entries in 2023; RDFIs that received 10 million or more entries in 2023 |
| Phase 2 | June 19, 2026 | all other non-consumer Originators, TPSPs and Third-Party Senders; all other RDFIs |
To that end, the rules introduce the concept of False Pretenses, defined as “the inducement of a payment by a Person misrepresenting (a) that Person’s identity, (b) that Person’s association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited.” The target is business email compromise, payroll impersonation, vendor impersonation and romance scams. In practice, an institution’s documentation is expected to cover:
- the detection systems it uses and the alerts they generate;
- the person or team responsible for monitoring;
- when monitoring takes place, in real time or after processing;
- what to do when a transaction is flagged;
- the annual review of the program.
Monitoring vendors vie for a larger pool of clients
With no volume threshold since June 19, 2026, the number of institutions and businesses covered jumped overnight. So did demand for monitoring vendors, whether specialist software firms or the risk modules already built into payment platforms.
Nacha has run its Preferred Partner program for several years. It is open to vendors whose products and services “align with Nacha’s core strategies to advance the modern ACH Network.” The program had 27 members in the summer of 2024, when four new categories brought the total to seven. Flagright, admitted on August 24, 2026, qualifies under three of them: ACH compliance, fraud monitoring, and risk and fraud prevention.
Flagright says its tool tracks incoming and outgoing payments, compares activity with expected behavior and ranks alerts according to the institution’s risk policy. Configurable rules look for rapid movement of funds, unusual payment patterns, signs of account takeover, money mule activity and multi-account abuse. Scoring draws on the amount, the customer’s and counterparty’s history, and machine-learning anomaly detection.
“Safety is paramount to all ACH Network payments, and fighting fraud is of the highest importance for Nacha,” said Jane Larimer, Nacha’s president and CEO. Baran Özkan, Flagright’s co-founder and CEO, said the network’s “continued growth depends on fraud and compliance controls that can keep pace with changing criminal behavior.”