Nacha’s new rules for reducing credit-push fraud and improving transparency are in effect. The rules usher in a new fraud-monitoring regime that expands who must detect and report suspicious ACH credit activity. The rules take aim at outcomes and governance; they do not prescribe a specific technology or tools. The rules impact nearly everyone involved in ACH payments.
As previously reported here, originators must conduct pre-origination monitoring. That means implementing tools, controls and processes that flag anomalous volumes, new high-value recipients, changes to vendor bank accounts or unusual originator behavior before entries hit the ACH network.
Should you care? If you are making ACH payments to vendors, you are an originator in Nacha parlance. So, what are the consequences of failing to implement validation and controls? VendorInfo spoke with Devon Marsh and Kerry Sellen at Nacha to find out.
Marsh first establishes context regarding the varies parties to ACH transactions. In any ACH transaction there are an ODFI, RDFI, Originator and Receiver, and may be a TPSP or TPS (see https://vendorinfo.com/faq-roles-in-ach-transactions/ for definitions.)
Originators are those organizations that initiate an ACH transaction. For example, organizations initiate payment to their vendors or employees. (The terminology can get slightly confusing between ACH Credit and ACH Debit—in an ACH debit situation, for example, wherein a Utility Company debits your account, they are the Originator–i.e. initiator of the transaction even though the payee, not the payer.)
The Rules Apply
Nacha rules apply to all the parties involved in a transaction. Marsh points out that Originators make up the largest pool of participants (as opposed to the ODFI and RDFI banks or TSPSs). Because there are so many originators, Nacha does not require a rules audit of them unless they are also a TPS (third party sender). However, they must comply with the rules on validation and controls. And any party in the chain (RDFI, ODFI etc.) can and will report apparent violations, which serves as a check on Originators.
On that latter point, Sellen says: “With any Nacha Rule, if a party to the transaction, ODFI, RDFI, ACH Operator, believes that another party violated an ACH Rule, they can file a Possible ACH Rules Violation against the offending party. These three parties can file a Possible Rules Violation as well as Nacha.
“When they file the Possible Rules Violation, they must submit specific information to Nacha that indicates why they believe a rules violation occurred. The party must provide documentation that includes the names, addresses, and telephone numbers of the complainant and the other participating DFI involved in the dispute (the respondent) and the routing number of the respondent. They must also include a document that summarizes the facts of the alleged violation as well as the sections of the rules violated and the information permitting identification of the particular transaction(s), the sequence of events involved, the precise nature of the violation(s), and the consequences to the complainant.”
Consequences of Non-Compliance
As to consequences, the rules were developed to respond to fraud risk. They are concerned about fraud protection and prevention in the cyber-era. They are designed to get Originators (as well as all other ACH transaction parties) to look at their processes, identify and correct weaknesses. Nacha stressed that controls must be implemented procedurally, not merely identified in policy.
In these new rules combating the cyber-vectors of fraud attacks, Nacha is calling attention to the risks presented by the development of large-scale fraud organizations. Fraud perpetrators are not 20-somethings in a hoodie, but large organizations with an organization chart and a CEO. Rather than a young man in a basement with a computer, think of a shiny modern office building. That’s the scale of cyber fraud.
The primary consequence of failing to act to comply with the new rules is to put your organization at risk for incurring significant fraud.
The consequences of falling victim to fraud include:
- the monetary loss, which may be substantial,
- work disruption,
- recovery costs,
- negative audit findings and increased audits,
- possible SOX failure,
- violations of privacy laws (some U.S. states and GDPR in Europe),
- vendor non-payment and relationship disruption
- AND non-compliance with Nacha rules.
Nacha rules require “commercially reasonable” fraud detection, bank account validation requirements, security of banking credentials and corporate account takeover prevention measures.
Nacha-specific Consequences
As for consequences specific to Nacha, under the new rules, Nacha may fine an Originator for failure to implement validation and controls up to $25,000 for a first violation and up to $100,000 for repeated violations. And if it finds an Originator (or any other party to the ACH transaction) is willfully negligent, the fine is $500,000 per violation.
So yes, there’s a price to be paid to Nacha if you fail to comply with its new rules. But the rules have been put in place to protect you from the bigger cost of falling victim to business email compromise, deepfake spoofing and other methods the criminal organizations now employ to lead you to pay them instead of your legitimate vendors.
To learn how VendorInfo can help you comply through its automated bank account verification, contact us.

