Oscilar Team

NACHA Rules Explained: What Changed in 2026

Posted

Posted

Oscilar Team
Contents

Share this article

Last updated: September 2026

Most coverage of the 2026 NACHA rule changes treats them as a date to clear. Read the rule text and it asks for something else: a working fraud-detection capability, described in those words, extended to a much wider set of parties than before. Teams that plan for the date will meet the date. Whether they meet the requirement is a separate question.

TL;DR

  • The NACHA Operating Rules are the private rulebook governing the ACH Network. Nacha is a rule-making body, not a government regulator, and the Rules bind participants by agreement.

  • The 2026 Risk Management package rolled out fraud monitoring in two phases: 20 March 2026 and 19 June 2026. Nacha gives Monday 22 June 2026 as the practical Phase 2 date, because 19 June is a federal holiday.

  • The obligation is to "establish and implement risk-based processes and procedures reasonably intended to identify ACH Entries initiated due to fraud." That is a capability, not a filing.

  • The volume thresholds differ: 6 million for origination, 10 million for receipt, both measured on 2023 volume. They staged the timing only — Phase 2 closed the gap.

  • False Pretenses is a newly defined term covering business email compromise and impersonation. It does not cover scams involving fake or poor-quality goods.

  • More changes land through 2027 and 2028, including a Same Day ACH limit increase and a new sanctions-related return code.

What the NACHA Operating Rules are

The NACHA Operating Rules are the rulebook that governs the ACH Network. They define the roles and responsibilities of the financial institutions and other participants that send and receive ACH payments, and they set the conditions under which those payments move.

The scale is worth holding in mind, because it is what makes a rule change consequential rather than administrative. By Nacha's own count there were 33.6 billion ACH Network payments in 2024, valued at $86.2 trillion.

Two things about that are worth stating plainly.

First, Nacha is not a government agency. It is the rule-making body for the ACH Network, and the Rules bind participants through their agreements to take part in it rather than through statute. That does not make them optional — enforcement is real, and we come to it below.

Second, the Rules are organized by effective date. Nacha publishes them that way, which is a good indication of how the industry actually consumes them: the live question is almost never "what are the Rules" but "what is changing and when does it hit us."

The authoritative text is the published rulebook, available through Nacha. This page is a reading of it, not a substitute for it.

Who the Rules apply to

Every threshold and obligation below is expressed in these terms, so they are worth having straight before the dates.

  • ODFI — Originating Depository Financial Institution. The institution that originates entries into the network.

  • RDFI — Receiving Depository Financial Institution. The institution that receives them.

  • Originator — the company or person initiating the payment.

  • Third-Party Service Provider (TPSP) and Third-Party Sender (TPS) — intermediaries performing ACH functions on behalf of others.

Nacha's position on scope is broader than the labels suggest. Any entity performing an RDFI function in delivering transactions to a Receiver should implement monitoring and detection controls based on the functions it performs. If you do the job, you carry the obligation.

What changed in 2026: the Risk Management package

The 2026 changes come from a package of amendments intended to reduce successful fraud attempts and improve recovery of funds after fraud has occurred.

Fraud monitoring arrived in two phases. Phase 1 took effect on 20 March 2026. Phase 2 took effect on 19 June 2026 — with Nacha itself noting that because 19 June is a federal holiday, the practical effective date is the next banking day, Monday 22 June 2026. Standardized Company Entry Descriptions also took effect on 20 March 2026.

The scope change is the part worth pausing on. Before this package, the Rules required Originators to use a commercially reasonable fraudulent transaction detection system only for WEB debits and Micro-Entries. Those requirements did not encompass any other debits, and did not apply to any credits other than Micro-Entries.

So for a large share of ACH traffic — including the credit-push payments where impersonation fraud actually lives — there was no monitoring requirement at all. That is what changed.

What takes effect and when

Rule

Who it binds

Effective

Fraud Monitoring — Phase 1

All ODFIs; non-consumer Originators, TPSPs and TPSs with 2023 origination volume ≥ 6 million. RDFIs with 2023 receipt volume ≥ 10 million

20 Mar 2026

Company Entry Descriptions

Originators using the standardized descriptions

20 Mar 2026

Fraud Monitoring — Phase 2

All other non-consumer Originators, TPSPs and TPSs; all other RDFIs

19 Jun 2026 (practical date 22 Jun 2026)

U.S. Treasury Bureau of the Fiscal Service added to the ACH Contact Registry

Participating DFIs

24 Jul 2026

Funds availability at 9:00 a.m. on Settlement Date for non-Same Day credits

RDFIs

18 Sep 2026

Definition of IAT Entries

Participating DFIs

18 Sep 2026

Registration of IAT contacts in the ACH Contact Registry

Participating DFIs

1 Jan 2027

Currently accepted characters in the ACH Network

Participating DFIs

1 Jan 2027

Same Day ACH per-entry limit raised from $1 million to $10 million

Network-wide

17 Sep 2027

New return reason code R90 for sanctions compliance obligations

RDFIs

17 Mar 2028

Effective dates move. Check the current position against Nacha's published rules before you plan against any row here.

The fraud-monitoring obligation, precisely

The rule requires each covered party to "establish and implement risk-based processes and procedures reasonably intended to identify ACH Entries initiated due to fraud."

Read that as a capability requirement. There is no form to file and no certification to obtain. What is required is that the processes exist, that they are risk-based, and that they are reasonably intended to do the job.

On the origination side, Phase 1 covered all ODFIs, plus each non-consumer Originator, Third-Party Service Provider and Third-Party Sender with 2023 annual ACH origination volume of 6 million or greater. Phase 2 extended it to all other non-consumer Originators, TPSPs and TPSs.

On the receipt side, Phase 1 covered RDFIs with 2023 annual ACH receipt volume of 10 million or greater. Phase 2 extended it to all other RDFIs.

Two details get reported wrong often enough to call out. The thresholds are different numbers for different sides of the transaction — 6 million for origination, 10 million for receipt. And both are measured on 2023 volume, not current volume.

If your institution sat below a threshold, that bought you three months. It did not exempt you. Phase 2 closed the gap.

False Pretenses: what the new term covers, and what it does not

The package introduces a defined term. False Pretenses means:

"the inducement of a payment by a Person misrepresenting (a) that Person's identity, (b) that Person's association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited."

In practice that covers business email compromise, vendor impersonation, payroll impersonation and other payee impersonations. It complements the existing language on unauthorized credits, which addresses account takeover.

What it does not cover is as important. It does not extend to scams involving fake, non-existent or poor-quality goods or services. A customer who was sold nothing has a dispute; a customer who paid the wrong party because someone misrepresented who they were falls inside the definition.

Getting that boundary wrong in either direction produces the wrong control and the wrong expectation about what the Rules do for you.

What a compliant control actually looks like

Nacha describes what it has in mind for RDFI credit monitoring, and its own example is more useful than anything invented for the purpose. A risk-based approach can consider transactional velocity, anomalies such as an SEC Code mismatch with the account type, and account characteristics such as the age of the account and the average balance.

Nacha also says the approach aligns with the AML monitoring practices institutions already run, and adds two clarifications that matter for scoping: pre-posting monitoring of credit entries is not required, and solutions may be developed in house or bought.

The rationale Nacha gives for the requirement is worth repeating, because it explains what "reasonably intended" means: regular fraud detection monitoring establishes baselines of typical activity, which is what makes atypical activity identifiable in the first place.

There is an honest objection here, and it comes up in practice. An operations leader at a payments processor described their position simply: they do transaction monitoring in house, manually, and in their reading that satisfies the rule.

That is a defensible reading. The rule is risk-based and does not prescribe automation. The questions worth asking are whether it stays defensible as volume grows, whether a manual process applied under time pressure is genuinely consistent, and whether the reasoning behind a given decision can be reconstructed six months later. If the answer to all three is yes, the process is doing its job. If it is not, the deadline was never the real problem.

The practical question: do you have the data to monitor on?

Look again at the signals in Nacha's example — velocity, SEC Code against account type, account age, average balance. Then look at what your core banking system actually exposes to the systems doing the monitoring.

This is where implementations stall. An operations leader at a credit union described wanting to load the raw ACH and wire files directly rather than relying on the transaction information available through the core, because the core did not carry the detail their team needed and reconstructing it by hand was costing them.

Our view is that this is a data-layer problem before it is a detection problem. Patching another connector onto a core that does not carry the field is not the same as having the signal, and the difference only surfaces when someone asks why an entry was not flagged. The same underlying issue shapes how ACH fraud detection works in practice, and it is why we treat transaction fraud as a data problem first.

The second-order point: risk teams should be able to change monitoring policy without waiting on an engineering cycle. A rule you cannot adjust is a rule that gradually stops matching the fraud you are seeing.

For what it is worth on where we sit: in December 2025 Nacha named Oscilar a Preferred Partner for Account Validation, Fraud Monitoring, and Risk and Fraud Prevention. The programme is open to any provider whose offerings align with Nacha's strategy, so read it as a statement of focus rather than an endorsement of any particular product.

How the Rules are enforced

Nacha enforces the Rules through a national system of fines, an arbitration process for claims between participants, and a route for reporting a violation.

We are deliberately not quoting fine amounts or tiers here. The schedule changes, and a stale number in an article is worse than no number — check Nacha's own rules compliance pages for the current position. If you are working through what compliance looks like operationally rather than what the Rules say, our guide to NACHA compliance covers that ground.

Frequently asked questions

What are the NACHA Operating Rules? They are the rulebook governing the ACH Network, defining the roles and responsibilities of financial institutions and other participants and setting the conditions under which ACH payments move. Nacha is the rule-making body, not a government regulator, and the Rules bind participants by agreement. The authoritative text is the rulebook published by Nacha.

What are the new NACHA rules for 2026? The main change is the Risk Management package, which extended fraud-monitoring obligations in two phases — 20 March 2026 and 19 June 2026, with a practical date of 22 June 2026 for the second — and introduced standardized Company Entry Descriptions from 20 March 2026. Later in 2026, the U.S. Treasury's Bureau of the Fiscal Service joins the ACH Contact Registry on 24 July, and funds availability for non-Same Day credits moves to 9:00 a.m. on Settlement Date from 18 September.

What is NACHA rules compliance, and who enforces it? Rules compliance means meeting the obligations the Operating Rules place on your institution for the roles it performs. Nacha enforces through a national system of fines, an arbitration process for claims between participants, and a violation-reporting route.

Do the NACHA Rules apply to us if we are below the volume thresholds? Yes. The 6 million origination and 10 million receipt thresholds staged the timing of the fraud-monitoring rule, not its scope. Phase 1 covered institutions above them from 20 March 2026, and Phase 2 extended the same obligation to everyone else from 19 June 2026.

What counts as False Pretenses under the Rules? Inducing a payment by misrepresenting your identity, your association with or authority to act on behalf of another person, or the ownership of an account to be credited. That covers business email compromise, vendor impersonation and payroll impersonation. It does not cover scams involving fake, non-existent or poor-quality goods or services.

Where can teams find the primary source for the NACHA Rules? Nacha publishes the Operating Rules, and its new rules pages list approved changes with their effective dates. Anything date-sensitive should be verified there rather than in secondary coverage, including this page.

Oscilar Team

The Oscilar Team is comprised of experts from many domains of risk operations. These articles express viewpoints and knowledge from a variety of sources and contributors across the organization.