
Two Nacha rule changes that took effect in 2026 apply directly to businesses that collect payments by ACH or eCheck. Since June 19, 2026, every non-consumer ACH Originator has to run risk-based fraud monitoring on the entries it originates, regardless of how much volume it does. And since March 20, 2026, consumer e-commerce debits for goods have to carry the Company Entry Description "PURCHASE."
Neither change is optional, and neither one is aimed only at banks. If your business debits customer bank accounts, you are in almost all cases the Originator under the Nacha Operating Rules — even when your payment processor is the party that actually transmits the file. This guide covers what each rule requires, who it applies to, where the goods-versus-services line falls, and what to check with your processor.
What Changed for ACH Merchants in 2026
- March 20, 2026 — Phase 1 of the fraud monitoring rule took effect for all ODFIs and for larger originators and third parties.
- March 20, 2026 — The standardized Company Entry Descriptions "PAYROLL" and "PURCHASE" became mandatory for the payment types they cover.
- June 19, 2026 — Phase 2 of the fraud monitoring rule removed the volume threshold. All non-consumer Originators, Third-Party Service Providers and Third-Party Senders are now in scope.
- September 18, 2026 — A separate change accelerates funds availability for non-Same Day ACH credits.
Rule 1: Fraud Monitoring for ACH Originators
Before 2026, the Nacha Rules required Originators to use a commercially reasonable fraudulent transaction detection system in two narrow places: WEB debits and Micro-Entries. Those requirements, as Nacha puts it, did not encompass any other transaction types. The 2026 amendment widens the obligation considerably.
Who Has to Comply, and Since When
The rule arrived in two phases. Phase 1, effective March 20, 2026, applied to all ODFIs and to non-consumer Originators, Third-Party Service Providers and Third-Party Senders with 2023 ACH origination or transmission volume of 6 million entries or more. Phase 2, effective June 19, 2026, eliminated the volume threshold entirely.
That second date is the one that matters for most merchants. A business originating a few hundred eCheck debits a month was outside Phase 1 and is inside Phase 2. As of June 19, 2026, there is no longer a size at which an ACH originator is too small for this rule.
A parallel requirement applies to RDFIs — the banks receiving entries — which must monitor incoming credit entries for fraud on the same two effective dates, though Phase 1 there is set by a different threshold, based on 2023 receipt volume.
What the Rule Actually Requires
The obligation is deliberately non-prescriptive. Each covered party has to do two things:
- Establish and implement risk-based processes and procedures, relevant to the role it plays in the authorization or transmission of entries, reasonably intended to identify entries suspected of being unauthorized or authorized under false pretenses.
- Review those processes and procedures at least annually, and update them to address evolving risks.
Nacha does not mandate any method or technology. It describes a risk-based approach as applying more scrutiny where you have assessed risk as higher, basic precautions where it is lower, and possible exemptions for very low-risk activity. The limit is explicit: a risk-based approach cannot be used to conclude that no monitoring is necessary at all. At minimum, you are expected to run a risk assessment separating higher-risk transactions from lower-risk ones.
The rules also let originating participants allocate these procedures among themselves — an ODFI may take into account what other participants in the origination chain are doing, provided the basis for relying on them is reasonable and clear, for example allocated by contract and verified by appropriate oversight. That does not make your obligation disappear; it means the work can be divided, and the division should be written down.
One point deserves flagging, because Nacha's own materials are not consistent about it. Its credit-push resource centre describes the monitoring rules as aimed at identifying ACH credit entries initiated due to fraud. The rule page and its FAQs, however, describe the Originator obligation in terms of entries generally, and frame the amendment as widening a requirement that previously reached only WEB debits and Micro-Entries. If you originate debits and nothing else, the safe reading is that you are in scope.
What Counts as Fraud Under the Rule
The amendments introduced a defined term, False Pretenses. Nacha defines it as the inducement of a payment by a person who misrepresents their own identity, their association with or authority to act on behalf of someone else, or the ownership of an account to be credited. That covers business email compromise, vendor impersonation, payroll impersonation and other payee impersonations, and it sits alongside existing language on unauthorized entries, which covers account takeover.
There is an important boundary here, and merchants tend to get it backwards. Nacha states the definition does not cover scams involving fake, non-existent or poor-quality goods or services. A customer claiming the product never arrived or was not as described is a dispute, not a False Pretenses event under this rule. The obligation is about payments initiated by someone who is not who they say they are.
Rule 2: The PURCHASE and PAYROLL Company Entry Descriptions
The Company Entry Description is a ten-character field in the Company/Batch Header Record — positions 54 through 63 — that tells the receiver what a payment is for. Usually the Originator picks the wording. For certain payment types the Nacha Rules dictate it, and as of March 20, 2026 there are two more mandated values. The point is to give receiving banks a consistent signal they can monitor against.
When to Use PURCHASE
Any Originator collecting payment from a consumer by ACH debit for an online purchase of goods has to put "PURCHASE" in the Company Entry Description. Nacha's examples of when the descriptor applies:
- A one-time online purchase of a hard, tangible good — clothing or jewelry, for instance.
- A recurring monthly payment for a tangible product where the subscription was signed up for online, such as a monthly vitamin subscription.
- An online purchase of a tangible good that results in multiple payments from the consumer's account, such as Buy Now Pay Later.
These are WEB debits, except where the Nacha rule on Standing Authorization permits the TEL Standard Entry Class code instead.
When Not to Use PURCHASE
Services are outside the rule. Nacha's examples of payments that should not carry the descriptor:
- A one-time online payment for a service — a telehealth visit co-pay, or shipping and mail fees.
- Recurring payments for a service authorized online, including telephone and internet service, utilities, rent or lease payments, and installment loan payments.
- Payment for a license, such as a hunting, fishing or business license.
- Monthly insurance payments authorized online, such as car or life insurance.
- Gym memberships.
- Any business-to-business transaction.
The distinction is what the consumer is buying, not how the payment recurs. A recurring debit for a physical product shipped monthly takes the descriptor; a recurring debit for a membership does not.
Where Sources Disagree on Digital Goods
This is worth flagging because the public guidance is genuinely unsettled. Nacha's FAQ defines an e-commerce purchase for this rule as a debit authorized online by a consumer for the purchase of tangible, hard goods. Stripe's documentation describes the qualifying condition as a consumer authorizing the purchase of physical or digital goods.
Nacha writes the rule, so "tangible" is the safer reading. But if you sell downloads, digital subscriptions or software, do not settle this from a blog post — including this one. Ask your processor in writing how it classifies your transactions.
How the Field Is Populated
For payroll credits, Originators must place "PAYROLL" within the leftmost seven characters and may use the remaining three for their own purposes — "PAYROLL 02" or "PAYROLLEMP" both work. That allowance is specific to PAYROLL.
Two limits on enforcement are worth knowing. Nacha states that the ODFI has no obligation to verify the presence or accuracy of the word "PURCHASE," and RDFIs are not required to act on either descriptor. Neither makes it optional for you — the requirement falls on the Originator regardless of whether anyone downstream checks.
Why This Lands Differently for High-Risk Merchants
Businesses in verticals that mainstream processors decline tend to lean on ACH and eCheck harder than most, precisely because card acceptance is the part that keeps getting withdrawn. That makes these rules less of an administrative footnote and more of an operating requirement on a rail you may depend on.
- You are almost certainly the Originator. Working through a Third-Party Sender does not shift the obligation onto them by default — it makes the allocation between you a question your contract should answer.
- Subscription and continuity merchants have a classification decision to make. Nacha's own example of a qualifying recurring purchase is a monthly vitamin subscription, so nutraceutical and physical-product continuity programs sit inside the PURCHASE requirement, while membership and service programs sit outside it.
- The annual review is a standing obligation, not a one-time project.
- An annual review presumes something written to review, and sponsor banks or processors reassessing an account can reasonably ask to see it.
A Practical Checklist
- Confirm whether you originate ACH debits, credits, or both, and under which SEC codes.
- Run a written risk assessment separating higher-risk from lower-risk transactions in your own flow.
- Write down the monitoring you actually do — velocity checks, anomaly detection, dollar thresholds, and change controls on payment instructions and vendor or payroll detail changes.
- Put a recurring calendar entry on the annual review so it does not lapse.
- Ask your processor, in writing, how the Company Entry Description is set on your debits and whether your transactions are classified as goods or services.
- Check a recent ACH file or processor report to confirm the descriptor your entries actually carry, and read your origination agreement for how fraud monitoring duties are allocated.
What These Rules Do Not Require
- They do not require you to screen every ACH entry individually. Nacha answers that question with a flat no.
- They do not require monitoring to happen before entries are processed, though Nacha notes that pre-processing monitoring offers the best chance of stopping fraud.
- They do not prescribe a particular vendor, system or technology.
- They do not make you responsible for identifying buyer scams about goods that were fake, missing or poor quality — that falls outside the False Pretenses definition.
- They do not obligate receiving banks to act on the PAYROLL or PURCHASE descriptors.
One More Date: September 18, 2026
A separate change takes effect on September 18, 2026, and it affects when money lands rather than how you monitor it. RDFIs must make funds available for all non-Same Day ACH credits — next day and two-day credits — by 9 a.m. local time on the settlement date. The change removes the old condition that the credit had to arrive by 5 p.m. the previous day for that deadline to apply.
The obligation sits with the receiving bank, not with you. But if your business receives ACH credits — invoice payments, refunds, processor cashouts — it can mean earlier access to funds. A narrow exception covers certain RDFIs east of the Atlantic time zone and west of the international date line, including Guam and the Northern Mariana Islands.
The Bottom Line
As of June 19, 2026, there is no volume floor left on ACH fraud monitoring — if your business originates ACH debits, the rule reaches you. What it asks for is proportionate rather than heavy: assess your risk, write down the controls you run, review them once a year, and make sure whoever transmits your entries is labelling them correctly.
The two things most merchants still need to do are confirm with their processor how the Company Entry Description is populated, and get their fraud monitoring procedures onto paper. If ACH or eCheck is a meaningful part of how you collect — and for many high-risk businesses it is the part that stays available when card processing does not — both are worth handling before someone asks to see them.
Categories

Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a lea...
More from Kyle Hall
Mastercard Chargeback Monitoring Programs: ECM, HECM & EFM Explained
Most merchants find out they are in a Mastercard monitoring program when their processor forwards th...
Best Gun Shop Software & POS Systems for FFL Dealers
Running a gun store means juggling ATF compliance, serialized inventory, background checks, and paym...
Best Online Merchant Account Providers: How to Choose the Right Partner
Hundreds of online merchant account providers compete for your business, and the differences between...
Payment Methods for Online Success: What Every Merchant Needs to Know
In today’s digital economy, online sales are skyrocketing. Global e-commerce sales are projected to ...