Explaining the Nacha Fraud Monitoring Rule to your ACH Originators.

The first step to Originator compliance.

Interpreting the new Nacha Fraud Monitoring Rules can be challenging, even for compliance professionals who work with the Rules every day. For your business and commercial customers – your non-consumer Originators – it is often entirely new territory. 

In focusing on the Originator, we’re specifically talking about the Rule in subsection 2.2.4 (the “New Rule”). 2.2.4 requires them to do something, but it doesn’t specify what that is, as there is no effective one-size-fits-all approach to fraud prevention. Particularly now that Phase 2 is in effect, your auditors and examiners may reasonably ask you to show them how you sensitized and empowered your Originators to comply.  

Explaining the New Fraud Monitoring Rules and motivating their compliance by enlightening them on the risks they face are necessary first steps. Lexalign does this for Originators every day – helping them understand the Rules that specifically apply, where they have gaps in compliance, and how to remediate. This is how we sensitize them to the New Rule. 

For your Originators:

The New Fraud Monitoring Rule

In a well-respected annual survey, 3 out of 4 organizations said they experienced actual or attempted fraud in 2025. Fraudsters are targeting deposit accounts like yours, using account takeover and/or pretenses. Nationally, losses in fraud are growing across payment channels, including ACH. Nacha has said that in order to combat this fraud, “all participants” have a role to play. 

“All participants” includes you

Nacha has introduced new rules and guidelines designed to protect you, while also requiring you to do more.

Nacha is the organization that governs the ACH Network, including by issuing and enforcing the Nacha Operating Rules that all ACH Network participants (including you) must follow. 

One very important new Rule is titled, “Identification of Unauthorized Entries or Entries Authorized Under False Pretenses.”  More commonly, it’s called the “Fraud Monitoring Rule.”

Under this Rule, “each non-consumer Originator” – including you – “must establish and implement risk-based processes and procedures…that are reasonably intended to identify Entries that are suspected of being unauthorized or authorized under False Pretenses; and …at least annually review these processes and procedures and make appropriate updates to address evolving risks.”

Your compliance with the New Rule is already enforceable. This means failure to have relevant processes and procedures may affect your access to ACH starting very soon.  

But it’s important to note that the New Rule was created to protect you based on significant new risks. It’s therefore prudent to implement relevant safeguards as soon as practical, and not just for compliance reasons.

Why do we need a new Rule and new fraud prevention?

Nacha adds Rules from time to time when new fraud patterns emerge that existing practices don’t adequately contain. Up until now, most Rules have focused on preventing debit fraud (debits that aren’t properly authorized). Today, credit fraud has begun to eclipse debit fraud as the number one threat to deposit account holders (including you).  

Credit fraud occurs when a bad actor causes money in your deposit account to be “pushed out” and sent to an account at another financial institution, from which the money is often sent on rather rapidly, before you can pull them back.  (The technical name is “Credit-Push Fraud.“)  

While not as numerically common as debit fraud, a Credit-Push Fraud attack is particularly bad, as it often involves removing all the funds from the account in an irretrievable way, leading in many cases to the sudden inability to continue normal operations. The New Rule is intended to address this fraud.

What the New Rule requires 

Basically, the New Rule requires each non-consumer Originator to create and implement practices designed to detect signals of attempted Credit-Push Fraud, in order to prevent it from happening – and to review the adequacy of those practices at least annually, to address emerging forms of fraud. Your participation is vital as you may see signals that are invisible to your financial institution.  

In particular, the required practices should ferret out signals of transactions that are either “unauthorized” or “authorized under False Pretenses.” Let’s unpack what is reasonably intended by those terms, so that you can determine the practices that make sense for the types of ACH transactions you originate.  

What an “unauthorized” Entry means in the New Rule

In the New Rule, an “unauthorized” Credit Entry is one where:

  • Someone who is not actually authorized by your organization to submit the payment instruction
  • has gained access to your online account (whether you gave them your credentials or not) and
  • sent an instruction to your financial institution to transfer funds from your deposit account to a third-party account (the “Credit Entry”).

In many cases, such scenarios relate to either (a) inadequate oversight of persons who have valid access to your online account, or (b) to some kind of breach of your security where an unauthorized insider or an outsider has gained access to your account credentials.

(It’s important for you to know that to your financial institution this is a valid Entry under your banking agreements, as you are responsible for securing your credentials and managing both access to and use of your banking accounts. This is a general rule in the US banking system, so switching banks would not change this. Even though Entries submitted for your account in such scenarios are your responsibility, your financial institution provides helpful guidance like this because it cares about your resilience and account security.)

What “False Pretenses” means in the New Rule 

Nacha defines “False Pretenses” as

“the inducement of a payment by a Person misrepresenting (a) that Person’s identity, (b) that Person’s association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited.” 

In other words, the Rule requires you to have systems that reasonably enable you to detect when someone is trying to get you to send money via ACH by:

 

  • Misrepresenting who they are (such as by impersonating one of your regular vendors or employees),
  • Falsely claiming that they have the right to act for a legitimate payee (such as by faking a legal relationship), or
  • Masking the true owner of the receiving account (such as by claiming it’s a new account for an existing vendor or employee, when it’s really owned by a fraudulent entity).

 

While the New Rule requires monitoring, it does not require you to screen every ACH Entry individually. The Rule requires “risk-based processes and procedures,” meaning you may determine which types of transactions present more or less risk, and apply a different level of scrutiny depending on the associated risk.  

A specific expectation if you use ACH for payroll or vendor payments

One particular area of fraud that Nacha has called for your assistance is fraud that involves changes in payment instructions for otherwise legitimate payments. Nacha has said:

“Originators may be best placed to implement procedures to protect against account takeover or other … unauthorized transactions. Such procedures could include change controls regarding payment information and instructions for vendor and payroll payments.”

If you use ACH for payroll (“direct deposit”) or vendor payments, the expectation is that you establish procedures for your staff to follow upon receiving instructions to alter a payee’s account information, to ensure they are properly authorized and valid before making the change. That means, at a minimum, not making the change until you’ve taken the necessary steps to be sure that the party requesting the change in payment information is who they say they are (identity verification). 

Notes for Financial Institutions:

One size does not fit all 

What the New Rule requires of each Originator depends on the types of Entries they are actually originating – not simply the SEC codes they use. 

Using PPD as an SEC code, for example, does not determine which fraud risks attach to a transaction. An Originator using PPD may be running payroll credits, which Nacha has specifically called out as a fraud vector requiring change control procedures. 

An Originator using CCD for vendor payments faces different false pretense risks than one using it for intercompany transfers.

These examples are necessarily general. Nacha’s expectations are specific to what your Originators are actually doing. Supplementing this general framework with guidance tailored to each Originator’s actual ACH activity is precisely where a structured assessment matters and where Lexalign can help.

Why the conversation is only the first step

Sharing a downloadable flyer with your Originators, or explaining the Rule in an email, helps them understand what is required. However, this is only the first step: Auditors and examiners could reasonably request records showing more than that your Originators received an explanation and acknowledged the New Rule. They could expect records showing that you assessed your Originators’ compliance with the New Rule and other applicable Rules, that you informed each of them of the Rules that actually apply, and where they have compliance gaps; that you empowered them with clear instructions on how to comply; and that you tracked their remediation as part of enforcing the agreement (under 2.2.3 of the Nacha Rules).

This is where Lexalign can help, with an automated solution that enables you to show records that you did all that, without the need to hire additional staff.  If you’d like a demo, please contact us.

 

Privacy Preference Center