NACHA UPDATES 2026
& Fraud Prevention Tips
A risk-based approach to helping prevent ACH fraud.
Effective June 19, 2026, NACHA will require all non-consumer ACH Originators to establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud.
This rule requires non-consumer ACH Originators to establish and maintain risk-based processes and procedures designed to identify ACH entries initiated as a result of fraud. The broader rule also applies to ODFIs and Third-Party Service Providers/Senders, but this guidance is focused on ACH Originators. The rule is intended to reduce fraud in ACH transactions, with particular focus on Unauthorized Entries—transactions initiated without the account holder’s permission, such as account takeover when a fraudster compromises online banking credentials—and Entries Authorized Under False Pretenses—payments approved because of deception, such as business email compromise (BEC), vendor impersonation, payroll impersonation, or payment redirection scams.
Under the new rule, your business must establish and maintain a proactive, risk-based fraud monitoring program that includes the following:
This rule applies to all Dedham Savings Bank business customers that originate ACH files. Any business, government entity, or organization that initiates ACH transactions—such as payroll, vendor payments, or collections—is considered a non-consumer Originator.
No. This is a NACHA rule change that applies broadly to financial institutions serving business customers that originate ACH payments.
Your business should be prepared to comply with these fraud monitoring requirements by June 19, 2026. Dedham Savings Bank may review your fraud monitoring processes as part of your established annual ACH review, unless changes to your ACH service require an earlier review.
“False Pretenses” refers to fraud scenarios in which a payment is authorized because of deception. It is an important risk to consider when building your fraud monitoring procedures. This addition to the NACHA rules reflects the growing impact of fraud schemes such as the following:
Effective fraud monitoring should be layered and tailored to your business. The controls you use should reflect the nature of your ACH activity, such as payroll, vendor payments, or customer collections. A risk-based approach does not require screening each individual ACH payment, and it does not need to be fully automated. However, businesses are expected to take reasonable steps to detect suspicious activity, document their procedures, and review and update them regularly—at a minimum annually. Having no monitoring is not acceptable.
In addition to the rule’s requirements, your fraud monitoring program should also consider the following risks:
No. This is a principles-based rule, not a prescriptive one. It requires your business to implement risk-based processes and procedures that are appropriate for your specific operations. Depending on your needs, this may include:
No. This rule establishes a compliance standard for Originators, Third-Party Senders, and financial institutions. It does not change the underlying allocation of liability for ACH fraud under existing law, but it does require businesses to strengthen controls designed to mitigate fraud risk.
Your ACH fraud monitoring procedures should reflect your business structure, payment volume, and specific risk profile. The examples below are provided for general guidance and are not intended to serve as a complete checklist. Depending on your needs, your program may include a combination of the following procedural and technical controls:
Additional practical steps to prepare may include verifying account information associated with first-time payments, independently authenticating any change in payment instructions or payment method through a trusted previously known phone number, and reminding staff never to share online banking credentials or account information in response to an incoming call, email, text message, fax, or letter—even if the request appears to come from the financial institution.
We encourage all Dedham Savings Bank business ACH Originators to review their current fraud controls as soon as possible. These examples are not intended to be all-inclusive or one-size-fits-all; your risk-based processes and procedures for detecting fraud should be tailored to your organization and payment activities. Please work with your compliance, legal, and technology teams to ensure your organization is prepared ahead of the required deadline.
On 3/25/26, Dedham Savings hosted a special event for businesses. We shared information about the latest NACHA (National Automated Clearing House Association) updates for companies that originate ACH transactions. And, we partnered with Harbor IT: Integrated IT, Cybersecurity, and Cloud Services, who presented the latest in Fraud prevention tactics.
We appreciate your business and consider ourselves your partner in safeguarding your financial accounts and information. As a precautionary measure, we remind Business Online Banking clients about Corporate Account Takeover fraud.
Corporate Account Takeover occurs when criminals gain unauthorized access to business financial accounts to conduct fraudulent transactions. If this occurs, contact us immediately and follow the Checklist steps.
Cyber Insurance is one option that can help protect your business against losses resulting from a cyber attack. Here are some general tips to consider.
Our experienced professionals will help you choose the best treasury management solutions so you can expedite collections, maximize your funds, and make critical business decisions faster. Choose the services that work for you, and we’ll go with the flow. The cash flow, that is.
Please note: You are about to leave the Dedham Savings website. Dedham Savings does not endorse or guarantee the products, information, or recommendations provided by linked sites and the Bank is not liable for any products or services advertised in these sites. The linked site may have a different privacy policy or provide less security than our website. We recommend you review these policies on the linked site. Thank you.