New Nacha rules help the fight against payments fraud

Strengthening your businesses ACH security: Meeting new Nacha requirements for proactive fraud prevention.

Scams targeting electronic payments are on the rise, with fraudsters increasingly relying on deception to manipulate organizations into authorizing payments they shouldn’t. To combat this growing threat, organizations need to understand how these schemes work.

These attacks often exploit the ACH Network that participating businesses and financial institutions rely on for payroll, bill payments, and accounts receivable. For example, scammers might pose as a vendor to divert a payment to an account they control. Other variations include impersonating an executive to trigger a fraudulent transfer, diverting payroll direct deposits, or using fake payment instructions to trick employees.

Many businesses assume their bank’s tools are sufficient protection on their own. In reality, the most effective defense is a coordinated one—with financial institutions and businesses working together to actively monitor for threats. Nacha, the governing body that sets rules for the ACH Network, has embraced this approach. New Nacha rules require organizations that originate or receive ACH payments to review their policies, tools, employee training, and audit procedures to complement the measures financial institutions employ for fraud protection.

Email compromise and push-payment fraud

Attacks on a company's email system often enable payment scams. Business email compromise can happen when an employee clicks on a phishing attachment or is tricked into revealing a password. Scammers can intercept or spoof emails to mimic legitimate vendor requests.

These schemes fall under the category of push-payment fraud. Unlike attacks involving hacking or stolen credentials, which typically result in unauthorized transactions, push-payment fraud relies on deception, tricking victims into initiating payments that look legitimate and fully authorized. Because these transactions appear genuine, they often pass standard authentication systems, making proactive defensive tactics essential. 

The new Nacha rules aim to stop this unauthorized fraud and fraud committed under false pretenses. The new mandates are meant to ensure that financial institutions, third-party processors and businesses take greater responsibility for identifying and reducing fraudulent financial activity.

New risk-based fraud prevention rules

As of June 22, 2026, commercial ACH users must perform active monitoring to catch fraudulent activity. This rule applies to businesses and organizations that originate ACH payments and third parties that use the system, including organizations such as payroll processors and some software providers. The rules took effect in March for organizations that originate large volumes of payments and in June for all other businesses and groups.

“Businesses can reap many benefits as they respond to these new requirements,” says payments expert Nanci McKenzie, SVP, treasury management product operations. “Because these rules are risk-based, rather than following a check-the-box compliance procedure, they are likely to have fraud protection benefits that go well beyond the ACH payments fraud that is being targeted.” 

The new mandates state that businesses must have “risk-based processes and procedures in place” to identify fraudulent activity. This means businesses must have a documented plan describing the steps its employees will take when a request to update payment information is received or if a fraudulent payment gets entered. Nacha now requires organizations to review these plans at least once a year—recognizing that fraud risks change and evolve and responses must as well.

Building a well-managed fraud monitoring program

Businesses' may need to strengthen existing fraud-prevention plans and add new features. Nacha suggests that a business’s plan might cover: 

  • What policies, controls, training and audit procedures are in place for the detection and prevention of fraudulent transactions and the recovery of transactions that were not prevented? 

  • What current software is in place for fraud detection? What additional products and services might be purchased to improve fraud detection? 

  • What happens within the organization—what steps are taken immediately—if a fraudulent payment is sent?

  • Who within the organization would be involved if a fraudulent payment is sent?

  • What financial institutions or third parties would need to be notified if a fraudulent payment is sent? 

It is important to note that the rules do not require that fraud monitoring be done at the point of origination (in real-time). However, the sooner fraud is identified, the greater the likelihood that a payment can be stopped or recovered. 

To enhance its defenses, organizations should consider implementing specific safeguards, such as:

  • Reviews of vendor files (whether they should be kept, modified or deleted)

  • Onboarding procedures for new payment recipients 

  • Verification processes for changes to receiving accounts

  • Dual control procedures prior to delivering ACH entries to the bank

  • Know your customer (KYC) processes

  • Information security steps like IP address verification

  • Dollar amount limits per transaction

  • Velocity verification

The benefits of proactive fraud prevention

The wording Nacha uses for its new requirements is broad. The rules establish principles that will boost the level of fraud monitoring by businesses without dictating specific steps or processes to follow. Nacha wants to encourage businesses to take a more proactive role in catching fraudulent transactions—a nudge that most organizations will welcome.

Overall, the new initiative for the ACH Network is a reminder that organizations need to work continually to combat all types of fraud. Smart businesses will have fraud prevention plans in place and ensure they are updated as threats change, with constant education within the organization. Ensuring that all employees understand the threats—and know what to do—will go a long way toward protecting the business.  

These new Nacha mandates, and push-payment fraud in general, call for an all-hands-on-deck approach to prevention. While your organization is responsible for strengthening its internal monitoring, you don’t have to navigate these requirements alone. Capital One is ready to provide the guidance and support you need to simplify compliance and build a more resilient payments strategy. 

Learn how our Treasury Management Solutions can help you move forward with confidence.

 

Source: Information in this article is based on official regulatory updates from Nacha's announcement: "New Nacha Rules: New Fraud Compliance Responsibilities for All Organizations Sending ACH Payments."