Decorative title card illustration for ACH compliance article
Back to Blog

Nacha Compliance in 2026: What Your Business Must Do Now

Merchant Solutions Corp8/23/2026

Nacha Compliance in 2026: What Your Business Must Do Now

Decorative title card illustration for ACH compliance article

Nacha compliance in 2026 means three things: risk-based fraud monitoring with documented annual reviews, adoption of two new standardized Company Entry Descriptions, and clear proof that your organization knows its role in the ACH Network. Phase 1 of Nacha’s risk management rules took effect on March 20, 2026, and Phase 2 follows on June 19, with a practical compliance date of June 22, 2026. That gap between the two phases is not an accident. Nacha built it to let large-volume institutions absorb new fraud controls first, then extend the same expectations across the rest of the ACH Network months later.

If you originate ACH transactions, process them, receive them, or sit anywhere in a Third-Party Sender chain, one of these dates applies to you. Here is the immediate triage:

  • ODFIs and RDFIs — you carry direct monitoring and documentation duties under both phases.
  • Originators, TPSs, and TPSPs — your obligations hinge on your 2023 origination volume.
  • Third-Party Senders, including nested arrangements — you need your own risk assessment, not a borrowed one from an upstream partner.

Pro Tip: Don’t wait for your processor to tell you which phase applies. Pull your 2023 ACH volume today and check it against the thresholds in the next section.

Key Takeaways

Nacha compliance in 2026 requires documented, risk-based fraud monitoring, correct use of the PAYROLL and PURCHASE descriptors, and clear proof of which ACH Network role your organization holds.

Point Details
Know your critical dates Phase 1 took effect March 20, 2026; Phase 2 follows June 19, with a practical date of June 22, 2026.
Check your 2023 volume Originators, TPSs, and TPSPs at 6 million or more transactions fall under Phase 1, as do RDFIs with high receipt volume.
Update descriptors now PAYROLL and PURCHASE must correctly tag PPD credits and WEB debits at the file level.
Document everything Auditors expect written risk assessments, annual review logs, and TPS registration evidence on demand.
Nested TPS needs its own review Each Third-Party Sender must complete its own risk assessment, not inherit one from an upstream partner.
Merchant Solutions Corp handles the file layer Its ACH and eCheck processing configures compliant descriptors and monitoring support as part of onboarding.

Table of Contents

What Changed in Nacha Compliance for 2026

The 2026 amendments center on two problems Nacha has flagged for years: fraud detection that reacts too late, and transaction descriptions too vague to monitor effectively. Phase 1 requires larger ODFIs, RDFIs, and non-consumer originators to stand up risk-based fraud monitoring programs. Phase 2 widens that requirement to essentially everyone else moving meaningful ACH volume, with a practical effective date of June 22, 2026.

The second major shift is descriptive, not procedural, and it changes how every ACH file gets tagged. Starting March 20, 2026, Nacha requires two standardized Company Entry Descriptions:

  • PAYROLL — for PPD credit entries that represent wage payments.
  • PURCHASE — for WEB debit entries tied to e-commerce transactions.

Consistent labeling gives RDFIs a real basis for anomaly detection. A payroll credit that suddenly shows up mislabeled, or a purchase debit with no matching descriptor, becomes a visible red flag instead of background noise. The roadmap also includes RDFI credit monitoring expansions and an R90 return code addressing sanctions screening, both of which extend the same logic: standardize the data, then monitor it.

Who Must Comply, and on What Timeline

Nacha’s rules apply differently depending on where you sit in the transaction chain. Four roles matter here.

  1. ODFI (Originating Depository Financial Institution) — the bank that sends ACH entries into the network on behalf of an originator or Third-Party Sender.
  2. Originator — the business initiating payments, such as a retailer collecting WEB debits or an employer sending payroll.
  3. Third-Party Sender (TPS) and Third-Party Service Provider (TPSP) — intermediaries that process or transmit entries for originators, including nested TPS arrangements where one sender relies on another.
  4. RDFI (Receiving Depository Financial Institution) — the bank on the receiving end of the transaction.

Phase 1 applies to ODFIs plus non-consumer originators, TPSs, and TPSPs whose 2023 origination or transmission volume hit 6 million transactions or more. RDFIs with high ACH receipt volume in 2023 fall under Phase 1 as well. Everyone below those thresholds gets folded in under Phase 2, effective June 19 with a practical compliance date of June 22, 2026.

Determining where you land takes one afternoon: pull your 2023 ACH volume reports, check them against the thresholds above, and confirm your role with your ODFI in writing. If you’re a Third-Party Sender working through a nested relationship, you cannot lean on your upstream partner’s risk assessment. Nacha requires each TPS to perform its own.

Building the Controls Nacha Actually Expects

Reading the rule text is one thing. Building a program that satisfies an auditor is another. Four control areas do most of the work.

Risk-based fraud monitoring. Nacha doesn’t hand you a specific technology mandate. It expects a documented, risk-based process with a real baseline of normal transaction behavior, defined anomaly indicators, and an escalation path when something trips a threshold. Your monitoring should flag things like sudden spikes in origination volume, entries that don’t match a customer’s typical pattern, or descriptor mismatches now that PAYROLL and PURCHASE are standardized. Nacha’s own guidance stresses that this monitoring must be active and reviewed at least annually, not set once and forgotten.

Hands connecting payment terminal cable

RDFI credit monitoring. If you’re on the receiving side, build in indicators for accounts suddenly receiving unusual credit volume or velocity. Have a documented process for placing a hold or suspending activity when those indicators trip, and know when Reg CC funds-availability rules intersect with a hold decision.

TPS and TPSP data security. Above certain volume thresholds, Nacha’s data security requirements call for rendering stored account data unreadable. Document how you meet that standard and keep the evidence on file.

File-level implementation. Update your ACH file mapping now so PAYROLL and PURCHASE descriptors populate correctly at the point of origination, not as a manual patch after a return or an RDFI inquiry.

  • Document your fraud-monitoring baseline and thresholds in writing.
  • Assign a named owner for the annual review requirement.
  • Confirm your file specifications generate the correct Company Entry Description by March 20, 2026.
  • Verify TPS/TPSP data-handling practices meet the unreadable-data-at-rest standard.

Merchant Solutions Corp’s ACH and eCheck processing tools handle descriptor mapping at the file level, which removes one of the more error-prone manual steps in this list.

Your 30/60/90-Day Nacha Compliance Checklist

Treat this as a sequence, not a wish list. Skipping the first step tends to create rework in the second and third.

  1. This week: Map your organization’s exact role (ODFI, Originator, TPS, TPSP, or RDFI). Pull 2023 origination and receipt volumes. Inventory every Third-Party Sender relationship, including nested ones, and confirm which party owns which risk assessment.
  2. Within 30 days: Implement your fraud-monitoring rule set and document your baseline. Update origination agreements to reflect new descriptor requirements and TPS registration status. Configure ACH file specifications to output PAYROLL and PURCHASE correctly.
  3. Within 60 to 90 days: Test your monitoring alerts against real transaction data. Run a tabletop exercise simulating a flagged transaction end to end. Document your annual review cadence and assign a named process owner. Complete vendor due diligence on any TPSP touching your files.
  4. Ongoing: Conduct the annual review Nacha’s rules require, refresh your nested-TPS documentation whenever a relationship changes, and retain audit artifacts for as long as your compliance policy specifies.

Pro Tip: Build your tabletop exercise around a fake return, not a fake fraud alert. Return handling exposes more gaps in ODFI and TPS coordination than fraud alerts ever do.

Merchant Solutions Corp’s payment processing integrations support this timeline directly, particularly the file-configuration and monitoring-setup steps in the 30-day window.

How Nacha Enforcement and Audits Actually Work

Nacha enforcement typically starts with a complaint or a pattern report, often flagged by an RDFI or through Nacha’s own monitoring, and it flows to the responsible ODFI for investigation. From there, the ODFI is expected to remediate, and unresolved or repeated issues can escalate to formal Nacha enforcement action, which can include fines.

Auditors reliably ask for the same set of documents:

  • Your written risk assessment and fraud-monitoring policy.
  • Annual review logs showing who reviewed what, and when.
  • Current origination agreements, including any TPS or nested TPS chain-of-agreement language.
  • Evidence of TPS registration where applicable.

Practitioner reporting notes that ODFIs frequently set exposure limits stricter than Nacha’s own baseline, and exceeding those internal limits is a common reason accounts get suspended even when the underlying activity is technically rule-compliant. Being “Nacha compliant” on paper doesn’t guarantee your ODFI signs off on a volume increase or a new descriptor pattern without a conversation first.

How Merchant Solutions Corp Supports Compliant ACH Processing

Merchant Solutions Corp builds ACH and eCheck processing with the 2026 descriptor requirements handled at the file level, so PAYROLL and PURCHASE tagging happens automatically instead of through manual correction after the fact. Onboarding includes ongoing monitoring support so your fraud-detection baseline stays current as your transaction volume shifts.

Hands configuring payment terminal hardware settings

For businesses running Third-Party Sender relationships, Merchant Solutions Corp helps with vendor due diligence and documentation review, the exact records auditors ask for first. POS integrations stay synced with file-format updates, which matters most for e-commerce operations processing WEB debits under the new PURCHASE descriptor. Compliance posture and data-handling practices are documented on the security and compliance page.

Why the 2026 Rules Reward Preparation Over Reaction

Most compliance advice treats regulatory change as a checklist exercise: read the rule, update a policy document, move on. That approach fails here because the 2026 changes aren’t really about paperwork. They’re about whether your monitoring can tell the difference between a normal Tuesday and a fraud pattern before money leaves an account.

The conventional advice to “wait for guidance from your processor” undersells how much of this sits on the originator and TPS side. Nacha built Phase 1 and Phase 2 around volume thresholds precisely because it expects mid-size and smaller players to have less mature fraud programs, not none at all. If your monitoring today consists of a monthly report someone glances at, June 22, 2026, will expose that gap fast.

The single highest-leverage move is inventorying your Third-Party Sender relationships now. Nested TPS chains are where documentation breaks down first, because everyone assumes someone upstream already did the risk assessment. Nobody did. Fix that before an auditor asks.

Get Your ACH Processing Ready for 2026

Updating fraud monitoring, descriptor mapping, and TPS documentation on your own timeline means diverting staff from running the business to reading rule text. Merchant Solutions Corp handles the ACH file-level changes, PAYROLL and PURCHASE descriptor configuration, and ongoing monitoring setup as part of standard onboarding, so your compliance posture doesn’t depend on someone remembering to update a spec sheet before March 20.

That matters most for retailers, restaurants, and service businesses layering ACH and eCheck acceptance onto an existing POS setup, where a missed descriptor update can mean returned transactions and RDFI friction down the line. Merchant Solutions Corp’s payment processing solutions fold compliance directly into setup rather than treating it as a separate project. Reach out for a compliance review of your current ACH configuration and a clear implementation plan before the June deadline.

Sources

  • Breaking Down Nacha’s New Risk Management Rules for ODFIs

FAQ

What Are the New Nacha Requirements for 2026?

The 2026 rules require risk-based fraud monitoring with documented annual reviews, plus two new standardized Company Entry Descriptions, PAYROLL and PURCHASE, effective March 20, 2026. Phase 2 extends fraud-monitoring obligations to a broader set of originators, TPSs, and TPSPs starting June 19, with a practical date of June 22, 2026.

Who Is Required to Comply With Nacha Rules?

Any organization that originates, receives, or processes ACH transactions falls under Nacha’s rules, including ODFIs, RDFIs, originators, and Third-Party Senders. Specific fraud-monitoring deadlines depend on your 2023 transaction volume relative to the Phase 1 thresholds.

Is Nacha a Federal Regulation?

No. Nacha is a private, self-governing rules body that administers the operating rules for the ACH Network, not a federal regulatory agency. The Federal Reserve operates FedACH as one of the network’s processing rails, but Nacha’s rules are contractual obligations financial institutions and their customers agree to follow.

Does ACH Only Work in the U.S.?

ACH is a domestic U.S. payment network, and Nacha’s rules govern transactions moving through it within the United States. Cross-border payment needs typically route through separate international payment rails rather than the ACH Network directly.

How Can Merchant Solutions Corp Help With Nacha Compliance?

Merchant Solutions Corp configures ACH and eCheck processing to apply the PAYROLL and PURCHASE descriptors correctly at the file level and provides ongoing monitoring support tied to your transaction patterns. That reduces the manual work of tracking each 2026 rule change independently.

nacha compliance

Share this article: