What are Nacha’s new fraud monitoring rules?
Nacha’s fraud monitoring rules require businesses that originate ACH payments to establish and implement risk-based processes and procedures reasonably intended to identify entries that are unauthorized or authorized under “false pretenses” (Nacha). Businesses must also review those processes at least once a year and update them as risks change.
The rules are part of a broader Nacha risk management package aimed at credit-push fraud, where a payer is tricked into sending money rather than having it pulled from their account (Nacha). Previously, the Nacha Rules required originators to use fraud detection only for WEB debits and micro-entries. Vendor payments sent by ACH credit were outside of scope.
What does “false pretenses” mean?
Nacha defines false pretenses as inducing a payment by misrepresenting someone’s identity, their authority to act for another party, or the ownership of the account being credited. Nacha states that this covers business email compromise, vendor impersonation, and payroll impersonation (Nacha).
In other words, one of the exact scenarios that cost AP teams the most, a fraudulent request to change a vendor’s bank account, is now squarely what Nacha expects originators to monitor.
Who do the Nacha rules apply to, and when did they take effect?
The rules rolled out in two phases, and both are now in effect. Phase 2 removed the volume threshold, so there is no longer a business too small to be covered.
| Phase | Effective date | Who it applies to |
|---|---|---|
| Phase 1 | March 20, 2026 | All ODFIs (originating banks), plus non-consumer originators and third parties with 2023 ACH origination volume of six million entries or more. |
| Phase 2 | June 19, 2026 | All remaining non-consumer originators and third parties, regardless of volume. |
Source: Nacha, Fraud Monitoring Phase 1. As June 19 is a federal holiday, the practical effective date for these rules to be implemented is Monday, June 22, 2026, the next banking day.
A “non-consumer originator” is any business or organization that initiates ACH entries. If your company sends vendor payments, payroll, or refunds by ACH, it almost certainly qualifies. Banks receiving payments (RDFIs) have separate monitoring requirements on a similar timeline.
What counts as fraud monitoring for a business sending ACH payments?
Nacha does not prescribe a specific tool or process. The rules are intentionally risk-based: each business assesses where its fraud risk is highest and applies stronger controls there (Nacha).
A few points from Nacha’s own FAQ help clarify what that means in practice:
- A risk assessment is the minimum. A risk-based approach can’t be used to conclude that no monitoring is needed. At a minimum, a business should identify which transactions are higher risk and which are lower risk.
- Not every entry needs individual screening. The rules don’t require reviewing each ACH entry one by one.
- Pre-payment monitoring isn’t mandatory, but it’s most effective. Nacha notes that monitoring before processing gives the best chance to catch fraud, even though it isn’t required.
- Annual review is required. Processes must be reviewed at least once a year and updated as fraud tactics change.
- Liability doesn’t change. Nacha states the rules don’t alter how liability is allocated between parties under existing law.
Most relevant for AP, Nacha specifically suggests that originators may be best placed to protect against unauthorized payments through “change controls regarding payment information and instructions for vendor and payroll payments” (Nacha).
How do vendor master data controls support Nacha compliance?
For most AP teams, the highest-risk moment in the ACH process is a change to vendor banking details. That’s where business email compromise and vendor impersonation succeed, and it’s exactly the kind of false pretenses fraud rules are designed to catch. Strong vendor master controls address that risk before a payment is ever created. Nacha doesn’t prescribe controls. Here’s how we map them:
| Nacha expectation | Vendor master control that supports it |
|---|---|
| Identify entries authorized under false pretenses | Never accept bank changes from inbound email; send a secure form to the vendor contact already on file |
| Apply stronger controls to higher-risk transactions | Treat new vendors and bank detail changes as high risk, with automatic bank account and account-name validation |
| Change controls for vendor payment instructions | Require approval for every vendor master change, with separation between the person entering and the person approving |
| Monitoring is most effective before processing | Hold changes in review so nothing writes to the vendor record until a person approves |
| Review processes at least annually | Keep a complete audit trail of every change, validation result, and approval in one system |
These controls work best when they’re enforced by the system rather than by memory. A written policy tells people what to do. A workflow inside your ERP ensures every step happens, even at quarter-end. Charted Advanced Vendor Onboarding runs these controls natively inside NetSuite, from secure vendor forms and bank validation through approvals and ongoing monitoring of incoming invoices for bank detail changes.
Vendor master controls are one part of a fraud monitoring program, not the whole thing. Your bank and your own risk assessment will determine what else your business needs.
What should AP teams discuss with their bank and legal team?
Your bank (the ODFI) has its own obligations under the rules and may already be asking questions about your fraud controls. Nacha allows responsibilities to be allocated across the parties involved in originating a payment, but that allocation should be clear and documented (Nacha). Useful questions to bring to that conversation:
- What fraud monitoring does the bank already perform on our outgoing ACH entries, and what does it expect from us?
- Is the division of monitoring responsibilities documented in our treasury services agreement?
- Which of our payment types does the bank consider highest risk?
- Does our written risk assessment identify vendor bank changes and new vendors as high-risk events?
- Who owns the annual review of our fraud monitoring processes, and when is it scheduled?
Making fraud monitoring part of the AP workflow
Nacha’s rules formalize what experienced AP teams already know: the business sending the payment is often in the best position to spot fraud before it happens. For vendor payments, that starts with controlling how bank details get into the vendor master in the first place. Read more on vendor automation here.
