Beginning June 19, 2026, new ACH Rules amendments will require all non-consumer ACH Originators to take a more active role in preventing fraud within the ACH Network.
What’s Changing?
Under the new Rules, ACH Originators must establish and implement risk-based processes and procedures designed to identify entries that are unauthorized or originated under false pretenses. These fraud-monitoring processes must be:
- Tailored to your operations, not a one-size-fits-all checklist
- Reviewed and updated at least annually
- Focused on higher-risk areas, where fraud attempts are more likely to occur
Why the Change Matters
The ACH Network relies on every participant to play a role in keeping payments secure — and Originators are uniquely positioned to spot suspicious activity early. By monitoring authorizations and transmission processes, Originators can catch fraud before it spreads through the network.
To comply, Originators must create documented, risk-based fraud monitoring processes that are “reasonably intended” to detect entries suspected of being unauthorized and entries authorized under false pretenses.
Building Your Risk-Based Fraud Monitoring Process
The Rules don’t prescribe specific steps, but focusing your efforts on two high-risk areas is a great place to start:
1. New Receivers
When establishing new Receiver relationships, take steps to verify legitimacy:
- Request proper documentation
- Verify identity and authorized personnel
- Conduct background checks when appropriate
- Use secure transmission methods for account data
- Ensure authorization forms meet ACH Rules requirements
Pro Tip: Keep a verified contact person on file for future verification and encrypt stored account data for added protection.
2. Account Change Requests
When an existing Receiver provides new account details, treat it as a red flag. Verify carefully and keep the following in mind:
- Accept only valid, signed or authenticated authorization requests — not email, fax or phone messages
- Confirm changes using the contact on file, not the contact provided in the change request
- Apply Know-Your-Customer (KYC) practices
- Follow dual-control or multi-factor authentication procedures
Hint: If you’re not already using dual-factor authentication, now’s the time! Two layers of protection make life much harder for fraudsters.
Ongoing Review Is Key
Fraud tactics evolve constantly — and so should your defense. ACH Originators must review and update their risk-based processes at least annually to ensure they stay effective against emerging threats.
By staying proactive, you’ll not only meet compliance requirements but also help strengthen the overall integrity of the ACH Network. Stay vigilant, tailor your risk-based processes to your organization’s needs and review them regularly to keep your fraud defenses strong.
For more details, please consult NACHA Operating Rules & Guidelines using the subscription code provided to you by Southern Bank. https://nachaoperatingrulesonline.org/
For further guidance or questions, call 573-778-1990.