• Aug 10, 2026
  • 11 min read

Nacha Operating Rules: A Guide for Businesses Using the US ACH Network

Nacha Operating Rules govern payments made over the United States ACH Network. See what they require, who must comply, and how to stay audit-ready.

Nacha Operating Rules govern the US Automated Clearing House (ACH) Network and establish the roles, responsibilities, and operating requirements applicable to ACH Network participants. Financial institutions, businesses, and third-party providers must comply with the requirements applicable to the role they perform when originating, transmitting, receiving, or supporting ACH payments. These requirements address areas including payment authorization and processing, risk management, fraud prevention, data security, returns, and compliance. 

In the first quarter of 2026 alone, Same Day ACH processed 403 million payments worth $1.1 trillion, up 23.6% and 22.1% year on year, respectively. Compliance requirements have tightened alongside it.

On June 22, 2026, the Phase 2 fraud monitoring requirements under the Nacha Operating Rules became applicable in practice to all remaining non-consumer Originators, Third-Party Senders, relevant Third-Party Service Providers, and Receiving Depository Financial Institutions (RDFIs) that were not already subject to Phase 1. Unlike Phase 1, the Phase 2 requirements apply regardless of transaction volume.

This guide explains which ACH participants are affected by the Rules, how their obligations differ by role, what changed in 2026, and how businesses can strengthen their compliance and audit readiness.

What is Nacha?

Nacha (originally known as the National Automated Clearinghouse Association) is the organization that administers the US ACH system.

It develops and enforces the Nacha Operating Rules, which establish how participants must initiate, receive, return, and manage ACH transactions. It is not a government agency and does not process payments. The Federal Reserve and The Clearing House operate the infrastructure that routes and settles transactions.

For businesses that participate in the US ACH Network, Nacha compliance means meeting the obligations that apply to their role, including authorization, fraud monitoring, data security, returns, account validation, and recordkeeping.

Nacha vs. ACH: What’s the difference?

In contrast to Nacha, which develops and enforces the Operating Rules, the ACH Network is the electronic payment network that enables ACH credit and debit entries to move between participating financial institutions.

The ACH Network supports a wide range of transactions, including payroll, supplier payments, bill collections, business-to-business transfers, and certain consumer payments.

Suggested read: Secure Digital Payments in 2025: A Complete Guide for Businesses

Who do the Nacha Operating Rules apply to?

The Nacha Operating Rules apply across the ACH payment chain, with obligations determined by each participant’s role:

  • ODFI: An Originating Depository Financial Institution is the participating financial institution that receives ACH entries from an Originator or the Third Party Sender and submits them to an ACH Operator. It is responsible for performing due diligence on Originators, maintaining appropriate agreements, managing risk, and ensuring that entries comply with the rules.
  • RDFI: A Receiving Depository Financial Institution receives entries from an ACH Operator and posts them to Receivers' accounts. Its responsibilities include processing entries and returns correctly, making funds available when required, and monitoring incoming ACH credits for suspected fraud.
  • Originators: An Originator is the person or organization authorized by the Receiver to initiate a credit or debit to the Receiver’s account, and that instructs an ODFI, directly or through a Third-Party Sender, to transmit the ACH entry. Employers sending payroll, companies paying suppliers, and utilities collecting bills are common examples. 
  • Third-Party Senders: It’s a type of Third-Party Service Provider that acts as an intermediary between an Originator and an ODFI and transmits ACH entries on behalf of an Originator that does not have a direct origination agreement with the ODFI. Examples may include payroll processors and payment platforms.
  • Third-Party Service Providers: These perform ACH-processing functions on behalf of another ACH participant. These functions may include creating ACH files, processing ACH data, or acting as a sending or receiving point. 
  • Merchants using ACH: These are authorized by a customer to initiate ACH debits to the customer’s account and generally act as the Originator and remain responsible for the Nacha requirements applicable to that role, even where a processor or other third party assists with transmitting the entries.
  • Consumers: They are generally classified as Receivers rather than operational participants. The rules nonetheless establish important protections and procedures for their accounts.

Key Nacha Operating Rules changes in 2026

The most important new Nacha rules for 2026 expand fraud prevention and standardize transaction data:

  • March 20: Phase 1 of the expanded fraud-monitoring rules took effect for all ODFIs; non-consumer Originators, Third-Party Senders, and relevant Third-Party Service Providers with 2023 ACH origination or transmission volume of at least six million entries; and RDFIs with 2023 ACH receipt volume of at least 10 million entries. The same date also introduced mandatory Company Entry Descriptions for certain transactions: “PAYROLL” for PPD credits involving wages, salaries, and similar compensation to consumer accounts, and “PURCHASE” for consumer ACH debits for online purchases of tangible goods.
  • June 22: Phase 2 removed the transaction volume thresholds, extending risk-based monitoring procedures to all non-consumer Originators, Third-Party Senders, relevant Third-Party Service Providers, and RDFIs.
  • September 18: A revised International ACH Transaction (IAT) definition will clarify when a payment must use the IAT code. RDFIs must also make every non-Same Day credit available by 9:00 am local time on its settlement date.

Nacha’s schedule lists the effective dates and supporting guidance.

ACH SEC codes and file formats explained

Standard Entry Class (SEC) codes are three-character identifiers that classify ACH entries according to factors such as the receiver, payment purpose, and authorization channel. 

Common SEC codes include:

  • PPD for consumer payments.
  • CCD for credits or debits between corporate accounts.
  • CTX for corporate payments carrying more extensive remittance information.
  • WEB for consumer entries initiated online or through a wireless network.
  • TEL for consumer debits authorized by telephone.
  • IAT for payments involving a financial agency outside the territorial jurisdiction of the United States.

A Nacha file is a standardized electronic file used to submit batches of ACH entries. Each record contains 94 characters and follows a defined hierarchy comprising file headers, batch headers, entry-detail records, optional addenda, and control records. These fields identify the parties, transaction type, amount, settlement date, and other payment information.

Suggested read: Transaction Monitoring in AML: Ultimate Guide For 2026

ACH returns and return rate thresholds

An ACH return occurs when an RDFI can’t post an entry or sends it back for another permitted reason. ACH return codes identify what happened and determine the applicable response and timeframe. 

Most routine returns must be sent within two banking days. However, consumers may have an extended 60-calendar-day period for certain unauthorized debits.

Businesses must also monitor return rates. The Nacha unauthorized return rate threshold of 0.5% applies to debit entries returned under codes R05, R07, R10, R29, and R51. Exceeding it can trigger investigation and enforcement action.

Nacha also establishes two return-rate levels:

  • 3% for administrative returns under R02, R03, and R04
  • 15% for overall debit returns, excluding RCK entries.

What do the Nacha Operating Rules cover?

The Nacha Operating Rules govern the full ACH transaction lifecycle. The exact Nacha compliance requirements depend on the organization’s role, the type of payment, and the SEC code used.

Authorization

An Originator must obtain the Receiver’s permission before initiating an ACH entry. For consumer debits, the ACH authorization must be clearly identifiable as an authorization and use clear, understandable terms. Depending on the payment and communication channel, it may be written, electronically authenticated, or obtained orally under specified conditions.

The authorization should explain what the customer is approving, including whether the payment is one-time or recurring. Recurring authorizations must also explain how future payments can be revoked. Business-to-business entries require an agreement between the parties. Originators must retain evidence of authorization, generally for two years, and be able to produce it when requested.

Account verification

Account verification helps prevent payments from being sent to closed, invalid, or incorrectly entered accounts. For WEB debits, Originators must use a commercially reasonable fraudulent transaction detection system and must validate the account number before its first use and after any change to it.

Nacha permits several validation methods, including prenotes, micro-entries, validation services, and APIs. The minimum standard verifies account status, not necessarily ownership. A higher-risk business may need both.

Fraud monitoring

Since June 22, 2026, Nacha’s expanded fraud-monitoring requirements apply to all ODFIs, all non-consumer Originators, all Third-Party Senders, relevant Third-Party Service Providers, and all RDFIs, regardless of transaction volume. Covered parties on the originating side must establish and implement risk-based processes and procedures appropriate to their role. These controls should be reasonably designed to identify ACH entries suspected of being unauthorized or initiated under false pretenses. RDFIs must maintain risk-based processes and procedures directed at incoming ACH credit entries and the handling of credits identified as potentially unauthorized or authorized under false pretenses. These processes and procedures must be reviewed at least annually and appropriately updated to address evolving risks.

An unauthorized entry may arise where a payment is initiated without the required authorization, including where a fraudster gains access to an account or payment system and initiates the transaction through account takeover.

An entry authorized under false pretenses involves a payment induced by a person misrepresenting their identity, their association with or authority to act on behalf of another person, or the ownership of the account to be credited. This may include business email compromise, vendor or payroll impersonation, executive impersonation, and other forms of payee impersonation. For example, an employee might receive what appears to be a legitimate request from a supplier to change its bank details. Although the employee follows the company’s normal approval process, the replacement account belongs to a fraudster. While the payment was authorized by the company, the authorization was obtained under false pretenses.

This definition does not cover every kind of scam and excludes disputes involving fake, nonexistent, or poor-quality goods and services.

Nacha does not prescribe a particular monitoring system or require each ACH entry to be screened before processing. Each organization, however, must assess its fraud risks and distinguish higher-risk transactions from lower-risk ones. Depending on the organization's role, this assessment may take into account the types of ACH entries processed, their purpose and payment channel, transaction volume and value, customer risk profile, known fraud risks, and the information available at the time a payment decision is made.

Controls may include transaction limits, behavioral monitoring, dual approval, account or payee verification, controls around changes to vendor and payroll instructions, and additional scrutiny of unusual payment instructions.

An ACH prenotification, or prenote, is an optional zero-dollar entry used to check whether account information is valid before sending a live payment. It can support fraud prevention by identifying incorrect account details, but it does not confirm account ownership or prove that a payment instruction is legitimate.

Data security

Organizations handling ACH information must protect account and routing data against unauthorized access, use, and disclosure. Non-consumer Originators, Third-Party Senders, and Third-Party Service Providers processing at least two million ACH entries annually must make stored account numbers unreadable. Nacha allows methods such as encryption, truncation, tokenization, or transferring storage responsibility to a financial institution.

Nacha fraud monitoring before and after the 2026 changes

The 2026 fraud-monitoring amendments expanded responsibility for detecting ACH fraud across the network.

Before the 2026 amendmentsAfter the 2026 amendments
Organizations coveredSpecific monitoring requirements primarily applied to Originators screening WEB debits and micro-entries. Nacha policy encouraged all network participants to maintain fraud controls, but the rules did not impose requirements across every role.All ODFIs, non-consumer Originators, Third-Party Senders, relevant Third-Party Service Providers, and RDFIs are covered, regardless of transaction volume.
Originating-side monitoringThere was no general fraud-monitoring requirement covering every type of ACH entry originated or transmitted by these participants.Affected participants must operate risk-based processes relevant to their role and reasonably intended to identify entries suspected of being unauthorized or authorized under false pretenses.
Receiving-side monitoringRDFIs were not subject to the specific requirement to monitor incoming ACH credits for fraud.RDFIs must establish risk-based processes for identifying incoming credit entries suspected of being unauthorized or authorized under false pretenses, including procedures for handling entries they flag.
Types of fraud coveredExisting requirements concentrated mainly on unauthorized transactions, particularly online debits and micro-entries.The rules expressly recognize payments authorized under false pretenses, including business email compromise and vendor, payroll, or other payee impersonation.
Monitoring approachRequirements referred to a “commercially reasonable” fraudulent transaction detection system for particular entry types.Nacha does not prescribe a particular technology or fixed set of controls. Processes must be risk-based, but organizations are not required to screen every entry individually or complete monitoring before processing.
Review and maintenanceThere was no comparable network-wide review requirement for general ACH fraud-monitoring processes.Affected organizations must review their processes and procedures at least annually and make appropriate updates to address evolving risks.

What’s next for Nacha?

Following the expansion of fraud monitoring, Nacha’s roadmap focuses on international-payment data, sanctions procedures, and faster high-value payments. 

From January 1, 2027, financial institutions must register IAT-handling contacts in Nacha’s ACH Contact Registry to simplify compliance queries. 

From March 19, 2027, IAT records gain an optional date-of-birth field for natural-person senders and receivers as well as support for non-bank foreign financial agencies. Businesses handling an international ACH transaction should review classification, data collection, security, and provider arrangements.

On September 17, 2027, the Same Day ACH limit rises from $1 million to $10 million for eligible credits and debits, which raises the potential impact of payment errors and fraud and the corresponding need for proportionate controls. IAT entries remain ineligible for Same Day ACH. 

On March 17, 2028, Nacha will introduce return code R90 to identify entries returned for sanctions-compliance reasons.

What happens if your business doesn’t comply with Nacha Operating Rules?

Common Nacha violations include initiating entries without valid authorization, exceeding return-rate thresholds, using incorrect SEC codes, mishandling returns, failing to protect account data, and not maintaining required fraud monitoring or audit processes. 

Rule enforcement generally begins when a financial institution reports a possible violation and supplies supporting documentation. Nacha evaluates it and sends the responding institution either a warning or a Notice of Possible Fine, which is reviewed by the ACH Rules Enforcement Panel.

The financial institution can acknowledge the violation and provide a remediation plan and completion date, or deny it and submit evidence.

Nacha fines are generally handled through the participating financial institution responsible for the entries. However, an ODFI may recover costs from an Originator or Third-Party Sender, require corrective action, or restrict the organization’s ACH access.

Depending on the violation, a business may face:

  • Mandatory remediation or enhanced monitoring
  • Lower transaction limits
  • Liability for returns, losses, or contractual penalties
  • Suspension of ACH origination privileges
  • Customer disputes and reputational damage
  • Separate legal or regulatory action where the conduct also breaches Regulation E, sanctions requirements, privacy laws, or other applicable obligations.

Nacha compliance audit: What to expect

A Nacha compliance audit evaluates compliance with the rules relevant to the functions performed. Participating financial institutions, Third-Party Senders, and Third-Party Service Providers that process entries under an agreement with a participating DFI must complete one annually by December 31. Ordinary merchants and Originators are not necessarily subject to this obligation, although their bank or processor may require an audit or self-assessment.

The Nacha audit requirements do not prescribe one testing method. A review typically covers due diligence, authorizations, file accuracy, account validation, fraud controls, return handling, data security, record retention, and previous remediation. Auditors examine policies, agreements, transaction samples, return reports, monitoring logs, and evidence of management oversight. Any deficiencies should be documented, assigned to responsible personnel, and addressed through a time-bound remediation plan. Proof of completion must be retained for six years and provided or attested to when requested.

Suggested read: Card Cloning Fraud in 2026: What It Is & How to Prevent It

How to make Nacha compliance readiness easier

Use the following checklist to identify gaps and build audit-ready evidence of compliance with the Nacha Operating Rules applicable to your organization’s ACH role and activities:

1. Map your exposure

☐ Identify every role your organization performs (Originator, ODFI, RDFI, Third-Party Sender/Service Provider)

☐ Map ACH flows, providers, SEC codes, transaction volumes, account types, and any international (IAT) participation

2. Assign ownership

☐ Name owners for authorization, monitoring, returns, data security, vendor oversight, and rules updates

☐ Set a recurring cadence for reviewing rule changes 

3. Standardize the fundamentals

☐ Document authorization, revocation, and record-retention procedures (two-year minimum for authorization evidence)

☐ Confirm account validation method(s) in place (prenotes, micro-entries, validation services, APIs)

4. Apply risk-based controls

☐ Set transaction limits and added approval for higher-risk payments

☐ Monitor for anomalies and verify any changed bank details independently

☐ Review fraud monitoring processes at least annually (required under Phase 2)

5. Monitor performance

☐ Track unauthorized, administrative, and overall return rates; for visibility, segment by customer and SEC code

☐ Flag anything approaching the 0.5% / 3% / 15% thresholds before it becomes a violation

6. Protect and sustain

☐ Define access, retention, deletion, and incident-response procedures for account data

☐ Vet third parties and train relevant employees

☐ Keep policies, agreements, monitoring logs, and remediation evidence audit-ready (6-year retention)

Note: The formal annual Nacha audit (due Dec 31) applies to participating financial institutions and Third-Party Senders/Service Providers under agreement with a participating DFI. Ordinary merchants and Originators aren't automatically subject to this requirement, though keeping records audit-ready is good practice regardless, since your bank or processor may still require it.

Nacha Operating Rules vs. Regulation E

The Nacha Operating Rules and Regulation E are separate frameworks with different legal authority and scope.

Nacha Operating RulesRegulation E
AuthorityPrivate network rules administered by NachaFederal regulation implementing the Electronic Fund Transfer Act
CoverageACH payments and their participantsElectronic fund transfers to or from consumer accounts
Main focusAuthorizations, ACH roles, file formats, SEC codes, returns, fraud controls, data security, and auditsConsumer disclosures, liability, stop-payment rights, preauthorized transfers, and error resolution
EnforcementWarnings, remediation, fines, and contractual actionRegulatory supervision, enforcement, and potential civil liability

The two frameworks overlap when a business initiates ACH transactions involving consumer accounts. For example, Regulation E requires recurring preauthorized debits from a consumer account to be authorized in writing or similarly authenticated, with a copy supplied to the consumer. The Nacha Operating Rules add requirements covering the appropriate SEC code, the form and retention of authorization evidence, transaction processing, and returns.

The deadlines also differ. Regulation E generally gives a consumer 60 days from when the statement showing an error is sent to notify the financial institution, while Nacha measures its extended return period for certain unauthorized debits from settlement. 

Nacha compliance FAQ

  • What does Nacha stand for?

    Nacha was originally formed as the National Automated Clearinghouse Association (NACHA). Today, Nacha is the organization’s official name and is not generally expanded as an acronym. Nacha administers the US ACH system, developing and enforcing the Nacha Operating Rules.

  • What is a Nacha file?

    A Nacha file is a standardized electronic file containing batches of ACH payment instructions. It uses fixed-width, 94-character records containing headers, transaction details, optional addenda, and control totals.

  • What is Nacha in banking?

    Nacha is the nonprofit organization that develops, administers, and enforces the operating rules for the US ACH Network. It governs the network but does not directly process or settle payments.

  • What are Nacha ACH return codes?

    Nacha ACH return codes are standardized codes explaining why an ACH entry was returned, such as insufficient funds or missing authorization. Each code determines the applicable return timeframe and what action the Originator or financial institution should take.

  • Does Nacha apply to Same Day ACH?

    Yes, Same Day ACH payments are governed by the Nacha Operating Rules.