9.6 RDFI ACH Credit Monitoring & the False Pretenses Definition
Key Takeaways
- The 2026 Rules impose a monitoring duty on RDFIs for the first time: RDFIs must establish and implement risk-based processes and procedures designed to identify credit Entries initiated due to fraud.
- Phase 1 (March 20, 2026) applies to RDFIs with annual ACH receipt volume of 10 million or greater in 2023; Phase 2 in June 2026 extends the duty to all other RDFIs.
- False Pretenses is a newly defined term: inducing a payment by misrepresenting the person's identity, their association with or authority to act on behalf of another person, or the ownership of an account to be credited.
- False Pretenses does NOT cover scams involving fake, non-existent or poor-quality goods and services — that boundary is a favorite exam distinction.
- The Rule does not require pre-posting monitoring of credit Entries, and it deliberately aligns with the RDFI's existing BSA/AML suspicious-activity monitoring rather than creating a parallel system.
9.6 RDFI ACH Credit Monitoring & the False Pretenses Definition
Core Principle: For decades the Nacha Rules treated the RDFI as an essentially passive recipient — obliged to accept and post entries, not to interrogate them. The 2026 Risk Management package changed that. RDFIs now carry an affirmative, risk-based duty to look for credit Entries initiated due to fraud.
1. Applicability and Effective Dates
+---------------------------------------------------------------------------------------------+
| RDFI ACH CREDIT MONITORING RULE |
+---------------------------+------------------------------------------------------------------+
| Phase 1 | Effective March 20, 2026 |
| | RDFIs with annual ACH RECEIPT volume of 10,000,000 or greater |
| | in 2023 |
+---------------------------+------------------------------------------------------------------+
| Phase 2 | June 2026 — all other RDFIs, no volume threshold |
| | (Nacha's current summary lists June 22, 2026; the Phase 1 rule |
| | page still shows the announced June 19, 2026) |
+---------------------------+------------------------------------------------------------------+
Contrast the two thresholds carefully, because they are different numbers measuring different things:
| Rule | Threshold | Measured on |
|---|---|---|
| Fraud monitoring by Originators / TPSPs / TPSs | 6 million Entries | 2023 origination or transmission volume |
| ACH credit monitoring by RDFIs | 10 million Entries | 2023 receipt volume |
| Fraud monitoring by ODFIs | No threshold | All ODFIs, Phase 1 |
An entity that performs an RDFI function in delivering transactions to a Receiver — the receiving-side analogue of a Third-Party Sender — should implement monitoring and detection controls based on the functions it performs.
2. What the RDFI Must Do
The RDFI must establish and implement risk-based processes and procedures designed to identify credit Entries initiated due to fraud, and must review those processes and procedures at least annually.
Nacha's stated rationale is that the RDFI holds information nobody else in the chain has:
- the incoming transaction stream across all Originators;
- the account profile of the Receiver (age of account, average balance, typical activity);
- historic activity patterns on that account.
A risk-based approach can therefore consider:
- transactional velocity — five payroll-sized credits from five unrelated companies into a three-week-old account;
- anomalies — an SEC Code that does not fit the account type, such as a stream of PPD payroll credits landing in an account with no prior employment activity;
- account characteristics — newly opened accounts, dormant accounts suddenly reactivated, thin-file accounts receiving large corporate credits.
The Rule explicitly:
- does not require pre-posting monitoring of credit Entries;
- aligns with, rather than duplicates, the institution's existing regulatory obligation to monitor for suspicious transactions under BSA/AML;
- encourages internal information flow between compliance monitoring, operations, product management and relationship staff — Nacha calls this out because the intelligence usually exists somewhere in the bank but never reaches the operations team in time.
3. False Pretenses — The Definition That Anchors the Package
The 2026 Rules introduce False Pretenses as a defined term:
the inducement of a payment by a Person misrepresenting (a) that Person's identity, (b) that Person's association with or authority to act on behalf of another Person, or (c) the ownership of an account to be credited.
Map the three prongs onto real schemes:
| Prong | Scheme | Example |
|---|---|---|
| (a) Identity | Impersonation | A fraudster poses as the CFO in an email demanding an urgent payment |
| (b) Association / authority | Vendor and payroll impersonation | A caller claims to be "from ACME's AR department" and supplies new banking details |
| (c) Ownership of the account to be credited | Payee-account substitution | The payment instruction is genuine, but the account number belongs to a mule |
What False Pretenses does NOT cover — memorize this line. It does not cover scams involving fake, non-existent, or poor-quality goods or services. A consumer who buys a "designer handbag" from a fraudulent website and receives a counterfeit has been defrauded, but that is not False Pretenses under the Nacha Rules: nobody misrepresented their identity, authority, or account ownership in the payment itself.
False Pretenses complements the existing concept of an unauthorized credit, which covers the account-takeover scenario where the account holder never initiated the payment at all.
Credit-push harm, two distinct legal concepts
┌────────────────────────────────┐ ┌────────────────────────────────┐
│ UNAUTHORIZED │ │ FALSE PRETENSES │
│ Account takeover: the account │ │ The account holder DID send │
│ holder never initiated it │ │ it — but was induced by a │
│ │ │ misrepresentation of identity,│
│ │ │ authority, or account owner │
└────────────────────────────────┘ └────────────────────────────────┘
Both are in scope for the 2026 monitoring Rules
4. What an RDFI Can Do With a Hit
Detection is only useful if the RDFI can act. The 2026 package, read together with earlier rule changes, gives an RDFI three levers:
- Delay funds availability — within the limits of Regulation CC — to examine a suspicious credit more closely. Nacha built the Additional Funds Availability Exceptions rule for exactly this purpose.
- Contact the ODFI to determine the validity of the transaction, using the ACH Operations or Fraud/Risk contacts in the ACH Contact Registry.
- Return the Entry. The RDFI may return a suspicious transaction on its own initiative, without waiting for a request from the ODFI or a claim from a customer. Separately, the ODFI's expanded R06 (Returned per ODFI's Request) lets the ODFI ask for the funds back for any reason — the RDFI's compliance with an R06 request remains voluntary.
Exam trap: the monitoring Rule does not make an RDFI liable for a fraudulent credit it fails to detect, and it does not require the RDFI to make the Originator whole. It requires a documented, risk-based, annually reviewed process. Answer choices promising a liability shift or a guarantee of recovery are wrong.
A consumer pays a website $900 by ACH for a laptop that never ships and the seller vanishes. Under the 2026 Nacha Rules, does this fit the definition of False Pretenses?
Which volume threshold determined whether an RDFI fell into Phase 1 of the ACH credit monitoring Rule on March 20, 2026?
An RDFI's monitoring flags a $310,000 CCD credit landing in a two-week-old business account. Which combination of actions is consistent with the Nacha Rules?
Which statement about the RDFI credit monitoring Rule is correct?