9.5 The 2026 Fraud Monitoring Rules: ODFIs, Originators, TPSPs & Third-Party Senders
Key Takeaways
- Effective March 20, 2026, Phase 1 of Nacha's fraud monitoring Rule applies to ALL ODFIs and to each non-Consumer Originator, Third-Party Service Provider and Third-Party Sender whose 2023 annual ACH origination or transmission volume was 6 million Entries or greater.
- Phase 2 removes the volume threshold and extends the requirement to every remaining non-Consumer Originator, TPSP and TPS; Nacha's current Summary of Upcoming Rule Changes lists it as June 22, 2026, while the Phase 1 rule page still shows the originally announced June 19, 2026.
- Covered parties must establish and implement risk-based processes and procedures, relevant to the role they play, reasonably intended to identify Entries suspected of being unauthorized or authorized under False Pretenses — and must review those procedures at least annually.
- The Rule is technology-neutral: velocity checks, anomaly detection, behavioral tolerances and pattern recognition all qualify. Nacha prescribes no specific tool, and monitoring is not required pre-processing.
- Before this Rule, Nacha only required a commercially reasonable fraudulent transaction detection system for WEB debits and Micro-Entries — credits other than Micro-Entries were not covered at all.
9.5 The 2026 Fraud Monitoring Rules: ODFIs, Originators, TPSPs & Third-Party Senders
Why this matters for the exam: Risk Management is 20% of the AAP blueprint, and the 2026 Risk Management package is the single largest expansion of ACH risk obligations in years. It took effect during the 2026 calendar year, which means it is squarely in scope for the October 2026 exam window. Candidates who studied from a 2024 handbook will not have seen it.
1. What Changed, and Why
Traditional ACH risk controls were built around debit-pull fraud: someone pulls money out of an account they have no right to touch. Regulation E and the 60-day unauthorized return window give consumers strong recourse, so those controls matured early.
Credit-push fraud inverts the problem. The victim is socially engineered into authorizing and sending a payment to an account the fraudster controls — business email compromise (BEC), vendor impersonation, payroll diversion. The payment is technically authorized by the account holder, so the classic unauthorized-return machinery does not fit, and until 2026 the Nacha Rules imposed almost no monitoring duty on the parties best positioned to spot it.
Before the 2026 Rules, Nacha required only:
- a commercially reasonable fraudulent transaction detection system to screen WEB debits, and
- fraud monitoring on Micro-Entries.
That covered no other debit type and no credit at all other than Micro-Entries. The 2026 package closes that gap by following the payment end-to-end: monitoring at origination (this section) and monitoring at receipt (Section 9.6).
2. Phase 1 — Effective March 20, 2026
+---------------------------------------------------------------------------------------------+
| FRAUD MONITORING PHASE 1 — EFFECTIVE MARCH 20, 2026 |
+---------------------------------------+-----------------------------------------------------+
| Party | Applicability |
+---------------------------------------+-----------------------------------------------------+
| Every ODFI | ALL ODFIs — no volume threshold whatsoever |
+---------------------------------------+-----------------------------------------------------+
| Non-Consumer Originators | 2023 annual ACH origination volume >= 6,000,000 |
| Third-Party Service Providers | Entries (origination OR transmission volume) |
| Third-Party Senders | |
+---------------------------------------+-----------------------------------------------------+
| Consumer Originators | NEVER covered — the Rule reaches non-Consumer |
| | Originators only |
+---------------------------------------+-----------------------------------------------------+
Two details the exam loves:
- The threshold is a 2023 volume snapshot, not a rolling figure. A Third-Party Sender that crossed 6 million Entries in 2025 but not in 2023 fell into Phase 2, not Phase 1.
- Every ODFI was in on day one. There is no small-bank carve-out for ODFIs. If you originate at all, you were covered on March 20, 2026.
3. Phase 2 — June 2026
Phase 2 eliminates the volume threshold and extends the requirement to all other non-Consumer Originators, Third-Party Service Providers and Third-Party Senders, regardless of volume.
Date caution — read this carefully. Nacha's current Summary of Upcoming Rule Changes lists Phase 2 as June 22, 2026. Nacha's Fraud Monitoring Phase 1 rule page, which has not been re-cut since the original announcement, still states June 19, 2026. Both dates come from Nacha itself. If an exam item forces a single date, the maintained summary table (June 22, 2026) is the newer publication; if the item simply asks when Phase 2 landed, the answer is June 2026. Do not treat either date as evidence that only one phase exists.
4. What a Covered Party Must Actually Do
The obligation has two limbs, and candidates routinely remember the first and forget the second:
- Establish and implement risk-based processes and procedures — relevant to the role the party plays in the authorization or Transmission of Entries — that are reasonably intended to identify Entries suspected of being unauthorized or authorized under False Pretenses.
- Review those processes and procedures at least once a year and update them to address evolving risks.
Note what the Rule does not do:
- It does not prescribe a technology. Nacha explicitly lists velocity checks, anomaly detection, behavioral tolerances and pattern recognition as acceptable approaches, and permits in-house or vendor solutions.
- It does not require monitoring pre-processing. An Originator is not obliged to screen every entry before it is built into a file.
- It does not shift liability. The 2026 Rules add monitoring duties; they do not rewrite who bears the loss on a credit-push payment.
- The old "commercially reasonable" formulation is gone for this obligation; the standard is now risk-based processes and procedures.
5. Role-Relevant Monitoring in Practice
Because the standard is "relevant to the role it plays," the same Rule looks different at each participant:
| Party | Signals it is uniquely positioned to see | Typical control |
|---|---|---|
| Non-Consumer Originator (e.g., a corporate AP department) | A vendor's banking details changed; a first-ever payment to a brand-new account; an off-cycle payroll run; an "urgent" wire-like ACH request | Callback verification to a known-good phone number, dual approval on master-data changes, tolerance limits per payee |
| Third-Party Service Provider / Third-Party Sender | Cross-client patterns: the same receiving account appearing under several unrelated Originators | Consortium account blacklists, velocity ceilings per Originator, anomaly scoring across the client book |
| ODFI | File-level anomalies against a customer's own baseline: a $50,000/day merchant suddenly submitting a $500,000 batch | Exposure-limit hard stops, batch-level anomaly alerts, out-of-band confirmation before release |
Worked Scenario
Meridian Components' controller receives an email that appears to come from a long-standing supplier, asking that this month's $480,000 invoice be paid to a new account. The controller updates the vendor master and releases a CCD credit.
- Originator control that should have fired: the vendor banking-detail change is exactly the pattern the Rule expects a non-Consumer Originator to monitor; a callback to the number on file — not the number in the email — breaks the scheme.
- ODFI control that should have fired: $480,000 to a payee never before paid, on a day the customer does not normally originate, is an anomaly against the customer's own baseline.
- Downstream: if the payment goes out, Section 9.6's RDFI credit-monitoring duty is the last line of defence, and the ODFI may use its expanded R06 Request for Return to ask the RDFI to send the funds back.
Exam framing: when a question describes BEC, vendor impersonation or payroll diversion and asks what the Rules require, the answer is a risk-based process reasonably intended to identify entries authorized under False Pretenses, reviewed at least annually — not a specific product, and not a guarantee of detection.
A Third-Party Sender originated 4.1 million Entries in 2023 and 9.2 million in 2025. Which phase of the Nacha fraud monitoring Rule first applied to it?
Beyond establishing risk-based fraud monitoring processes, what recurring obligation does the 2026 Rule impose on every covered party?
Which statement correctly describes what Nacha's fraud monitoring Rule requires of the monitoring method itself?
Before the 2026 Rules, which ACH activity did Nacha require Originators to screen with a fraudulent transaction detection system?