Skip to content
  • Advanced Vendor Onboarding
  • AP Automation
  • Vendor Automation
  • Vendor Management
October 6, 2026

Nacha’s 2026 fraud monitoring rules: What AP teams need to know

Post Author
Marlin Boggs
Senior Product Manager

What are Nacha’s new fraud monitoring rules?

Nacha’s fraud monitoring rules require businesses that originate ACH payments to establish and implement risk-based processes and procedures reasonably intended to identify entries that are unauthorized or authorized under “false pretenses” (Nacha). Businesses must also review those processes at least once a year and update them as risks change.

The rules are part of a broader Nacha risk management package aimed at credit-push fraud, where a payer is tricked into sending money rather than having it pulled from their account (Nacha). Previously, the Nacha Rules required originators to use fraud detection only for WEB debits and micro-entries. Vendor payments sent by ACH credit were outside of scope.

What does “false pretenses” mean?

Nacha defines false pretenses as inducing a payment by misrepresenting someone’s identity, their authority to act for another party, or the ownership of the account being credited. Nacha states that this covers business email compromise, vendor impersonation, and payroll impersonation (Nacha).

In other words, one of the exact scenarios that cost AP teams the most, a fraudulent request to change a vendor’s bank account, is now squarely what Nacha expects originators to monitor.

Who do the Nacha rules apply to, and when did they take effect?

The rules rolled out in two phases, and both are now in effect. Phase 2 removed the volume threshold, so there is no longer a business too small to be covered.

PhaseEffective dateWho it applies to
Phase 1March 20, 2026All ODFIs (originating banks), plus non-consumer originators and third parties with 2023 ACH origination volume of six million entries or more.
Phase 2June 19, 2026All remaining non-consumer originators and third parties, regardless of volume.

Source: Nacha, Fraud Monitoring Phase 1. As June 19 is a federal holiday, the practical effective date for these rules to be implemented is Monday, June 22, 2026, the next banking day.

A “non-consumer originator” is any business or organization that initiates ACH entries. If your company sends vendor payments, payroll, or refunds by ACH, it almost certainly qualifies. Banks receiving payments (RDFIs) have separate monitoring requirements on a similar timeline.

What counts as fraud monitoring for a business sending ACH payments?

Nacha does not prescribe a specific tool or process. The rules are intentionally risk-based: each business assesses where its fraud risk is highest and applies stronger controls there (Nacha).

A few points from Nacha’s own FAQ help clarify what that means in practice:

  • A risk assessment is the minimum. A risk-based approach can’t be used to conclude that no monitoring is needed. At a minimum, a business should identify which transactions are higher risk and which are lower risk.
  • Not every entry needs individual screening. The rules don’t require reviewing each ACH entry one by one.
  • Pre-payment monitoring isn’t mandatory, but it’s most effective. Nacha notes that monitoring before processing gives the best chance to catch fraud, even though it isn’t required.
  • Annual review is required. Processes must be reviewed at least once a year and updated as fraud tactics change.
  • Liability doesn’t change. Nacha states the rules don’t alter how liability is allocated between parties under existing law.

Most relevant for AP, Nacha specifically suggests that originators may be best placed to protect against unauthorized payments through “change controls regarding payment information and instructions for vendor and payroll payments” (Nacha).

How do vendor master data controls support Nacha compliance?

For most AP teams, the highest-risk moment in the ACH process is a change to vendor banking details. That’s where business email compromise and vendor impersonation succeed, and it’s exactly the kind of false pretenses fraud rules are designed to catch. Strong vendor master controls address that risk before a payment is ever created. Nacha doesn’t prescribe controls. Here’s how we map them:

Nacha expectationVendor master control that supports it
Identify entries authorized under false pretensesNever accept bank changes from inbound email; send a secure form to the vendor contact already on file
Apply stronger controls to higher-risk transactionsTreat new vendors and bank detail changes as high risk, with automatic bank account and account-name validation
Change controls for vendor payment instructionsRequire approval for every vendor master change, with separation between the person entering and the person approving
Monitoring is most effective before processingHold changes in review so nothing writes to the vendor record until a person approves
Review processes at least annuallyKeep a complete audit trail of every change, validation result, and approval in one system

These controls work best when they’re enforced by the system rather than by memory. A written policy tells people what to do. A workflow inside your ERP ensures every step happens, even at quarter-end. Charted Advanced Vendor Onboarding runs these controls natively inside NetSuite, from secure vendor forms and bank validation through approvals and ongoing monitoring of incoming invoices for bank detail changes.

Vendor master controls are one part of a fraud monitoring program, not the whole thing. Your bank and your own risk assessment will determine what else your business needs.

Your bank (the ODFI) has its own obligations under the rules and may already be asking questions about your fraud controls. Nacha allows responsibilities to be allocated across the parties involved in originating a payment, but that allocation should be clear and documented (Nacha). Useful questions to bring to that conversation:

  1. What fraud monitoring does the bank already perform on our outgoing ACH entries, and what does it expect from us?
  2. Is the division of monitoring responsibilities documented in our treasury services agreement?
  3. Which of our payment types does the bank consider highest risk?
  4. Does our written risk assessment identify vendor bank changes and new vendors as high-risk events?
  5. Who owns the annual review of our fraud monitoring processes, and when is it scheduled?

Making fraud monitoring part of the AP workflow

Nacha’s rules formalize what experienced AP teams already know: the business sending the payment is often in the best position to spot fraud before it happens. For vendor payments, that starts with controlling how bank details get into the vendor master in the first place. Read more on vendor automation here.

Webinar banner: headline on vendor fraud; left-aligned text, right side shows a man at a computer in an office.

Related Posts
View All
Charted named one of the most promising NetSuite solution providers by CIOReview
Blog
March 22, 2018
Take control of NetSuite’s Advanced PDF Templates
Blog
March 26, 2018
Document Management in NetSuite: Which option is right for you?
Blog
April 29, 2018