Nacha 2026 Fraud Rule: What AP Teams Must Do

By ApprovedAP Team · July 19, 2026 · 7 min read

The ACH network quietly moves trillions of dollars every year through payroll runs, vendor payments, and automated transactions. On June 22, 2026, the rules governing who is responsible for detecting fraud on that network changed in a fundamental way — and most AP teams have not yet caught up. Nacha's Phase 2 Fraud Monitoring Rule is now in effect. If your organization originates ACH payments — even a single payroll run or vendor payment — you are in scope. Here is what changed, what auditors may request, and what your AP team needs to do.

What Changed on June 22, 2026

Nacha's fraud monitoring requirements rolled out in two phases. Phase 1, effective March 20, 2026, applied only to large originators: non-consumer originators and third-party senders that originated more than six million ACH entries in 2023. Phase 2 removed that volume threshold entirely. As of June 22, 2026, every non-consumer originator, every third-party sender, and every ODFI is required to have documented, risk-based processes reasonably intended to identify ACH entries initiated due to fraud — including entries made under "false pretenses." That phrase explicitly covers business email compromise (BEC), vendor impersonation, and payroll diversion schemes. The rule also requires that these processes be reviewed at least annually as fraud threats evolve. Sending a policy document to employees or posting a compliance page on your intranet does not satisfy the requirement. Auditors may look for records of actual oversight activity dated back to June 22.

Why the Rule Was Written This Way

Nacha's reasoning is straightforward: fraudsters do not attack the ACH network directly. They attack the people who originate entries — your AP staff. A business email compromise scheme does not need to defeat your bank's fraud detection if it can convince your AP team to update a vendor's bank account number. An account takeover does not look suspicious when it uses your customer's own stolen credentials to initiate a normal-looking ACH credit. The 2026 AFP Payments Fraud and Control Survey found that 74% of US organizations were hit by BEC in 2025, and 76% experienced attempted or actual payments fraud. The fraud is not happening at the network layer. It is happening at the origination layer — inside AP departments.

What "Appropriate Oversight" Actually Requires

Nacha's rule does not prescribe specific controls. It requires "appropriate oversight" — a standard that is intentionally flexible so it can apply across organizations of different sizes and risk profiles. What it does require is that your oversight be documented, risk-based, and actively maintained. In practice, this means three things. First, you need written procedures that describe how you identify and respond to potential fraud in your ACH origination process. Second, you need evidence that those procedures are actually being followed — not just filed away. Third, you need to review and update those procedures at least annually. The "appropriate" standard also means that a small organization with a handful of ACH transactions per month will be held to a different standard than a large enterprise with thousands of daily payments. But both are in scope, and both need to be able to demonstrate that they have thought about their fraud risks and taken reasonable steps to address them.

What Auditors May Request

Auditors and examiners may request records of compliance dated back to June 22, 2026. Organizations should begin retaining evidence of compliance activity as soon as possible. The records auditors may request include:
  • Evidence that you assessed your ACH origination processes and identified fraud risks
  • Documentation of staff training on BEC, vendor impersonation, and payment fraud
  • Written procedures for verifying vendor bank account changes
  • Records of any vendor master file audits conducted in the past year
  • Evidence that payment authorization controls were reviewed and are being followed
  • The good news is that none of this requires expensive technology. It requires documented processes, trained staff, and a vendor master file that is actively maintained.

    The Three Controls That Matter Most for AP Teams

    1. Vendor Bank Account Change Verification

    The most common ACH fraud vector targeting AP teams is a fraudulent request to update a vendor's bank account number. These requests arrive by email, often appearing to come from a known vendor contact. With AI now generating grammatically flawless, context-aware emails, the old "look for typos" advice is no longer sufficient. The control that works is an independent callback: before processing any bank account change, call the vendor at a phone number on file in your vendor master file — not a number provided in the change request. This is a compensating control that does not require any technology investment, and it directly addresses the false-pretenses language in the new rule.

    2. Segregation of Duties on Payment Runs

    No single employee should be able to add or modify a vendor record and also approve payments to that vendor. This is the core principle of segregation of duties in AP, and it is directly relevant to Nacha compliance because it prevents the internal fraud scenarios the rule is designed to catch. If your AP team is small and true SoD is not practical, document the compensating controls you have in place — management review, reconciliation procedures, periodic vendor master audits — and make sure those records are dated and retained.

    3. Annual Vendor Master File Review

    The Nacha rule requires annual review of your fraud monitoring processes. A vendor master file audit is the natural anchor for that review. Scan for vendors with P.O. box addresses, duplicate bank accounts shared across multiple vendors, vendors with no recent activity, and vendors added without proper documentation. Each of these is a red flag for a ghost vendor scheme. Document the audit, note what you found, and record what you did about it. That documentation is what auditors may request.

    The Connection to Your Existing AP Controls

    If your organization already has strong internal controls around vendor onboarding and payment authorization, you are closer to Nacha compliance than you might think. The new rule formalizes what good AP practice has always required: know your vendors, verify changes independently, and make sure no single person controls the full payment cycle. The audit trail you maintain for your AP processes — who added a vendor, who approved a payment, who changed a bank account number and when — is exactly the kind of documentation Nacha's oversight standard requires. If you do not currently have that trail, building it is both a Nacha compliance requirement and a fraud prevention investment.

    What to Do This Week

    The compliance clock started June 22. Here is a practical starting point for AP teams: First, document your current vendor bank account change procedure. If you do not have one, write it today. It should require an independent callback to a number on file before any change is processed. Second, review your segregation of duties on vendor setup and payment approval. Document who can do what, and note any compensating controls where true SoD is not possible. Third, schedule a vendor master file review for this quarter. Flag any vendors with missing W-9s, P.O. box addresses, or bank accounts shared with other vendors. Fourth, brief your AP team on BEC and vendor impersonation. Show them what a convincing fraudulent bank account change request looks like. The 2026 AFP survey found that 74% of organizations were hit by BEC — your team needs to know this is not a theoretical risk.

    Ready to tighten your AP controls?

    ApprovedAP gives you vendor compliance tracking, SoD violation detection, and payment controls in one place.

    Get started free