News·4 min read

The Biggest Fraud-Related Change This Year Is a Change in Responsibility

From June 20th, every organisation that originates ACH payments must have documented, risk-based processes to identify potential fraudulent payments - covering 35.2 billion ACH payments worth $93 trillion in 2025.

IH

Idan Hayon

Co-Founder & CEO

The biggest fraud-related change this year is a change in responsibility.

From June 20th, every organisation that originates ACH payments must have documented, risk-based processes to identify potential fraudulent payments.

We are talking about 35.2 billion ACH payments worth $93 trillion that were processed in 2025.

Historically, fraud prevention has often been viewed as the responsibility of banks and payment providers. The new Nacha Rules make it clear that businesses originating payments also have responsibility for preventing fraud before payments enter the network.

That's an important change in mindset.

From response to prevention

Good fraud prevention is no longer just about responding when something goes wrong. It's about demonstrating that you have processes to detect suspicious activity before money leaves the account.

The interesting part is that Nacha deliberately requires organisations to build controls appropriate to their own level of risk. That means understanding:

  • Where payment instructions originate
  • How payment changes are verified
  • Who can approve payments
  • What unusual behaviour should trigger additional review
  • How fraud incidents are investigated and improved upon

The biggest takeaway

To me, that's the biggest takeaway. Compliance is becoming less about ticking boxes and more about demonstrating that fraud risk is actively managed.

If you're working through how to document and operationalise risk-based controls on your payment flows, we're happy to walk through it.

Originally shared on LinkedIn.

FAQ

What changed in Nacha ACH fraud rules in June 2026?
From June 20th, organisations that originate ACH payments must maintain documented, risk-based processes to identify potential fraudulent payments before those payments enter the network. That shifts more fraud-prevention responsibility onto originating businesses, not only banks and payment providers, and requires proof that suspicious activity can be detected before money leaves the account.
Why does ACH fraud responsibility matter now?
ACH volume is enormous - about 35.2 billion payments worth $93 trillion in 2025. When originating businesses must prove they manage fraud risk before money moves, reactive controls after an incident are no longer enough. Teams need documented processes that match their risk level and show fraud is actively managed, not only investigated after losses appear.
What should businesses document under the new Nacha expectations?
Controls should match your risk level and typically cover where payment instructions originate, how payment changes are verified, who can approve payments, what unusual behaviour should trigger additional review, and how fraud incidents are investigated and improved. The point is demonstrating that fraud risk is managed continuously, not only ticking a compliance checklist after something goes wrong.

More buyer questions on Radar, Protect, chargebacks, and Signifyd alternatives.

View FAQ

Ready to See It on Your Data?

Book a live walkthrough and see how FraudPulse turns your payment data into actionable fraud intelligence.

Book a Demo