The companion episode of Status: Secure — Episode 021, AI Voice Fraud, Payment Breaches, and Everything You Need to Know About PCI DSS & NACHA — opened with the two threats reshaping finance in 2026: AI-driven voice and deepfake fraud aimed at the people who approve payments, and the payment breach pattern stealing card data in the browser. The episode then walked through PCI DSS for cards and introduced NACHA for ACH — the two payment-compliance standards every financial organization now has to satisfy.
This Sitrep goes deep on the half of that conversation that just became urgent: NACHA. The podcast told you the NACHA rules exist and that they went live. This is the operational guide to what they actually require, who is now in scope, and how to build the fraud monitoring program the rules demand — because as of this week, the grace period is gone and the volume threshold is gone with it.
Here is the part most organizations have not caught up to. On March 20, 2026, NACHA’s Phase 1 fraud monitoring rules took effect for the largest players. And on June 19, 2026 — with a practical compliance date of Monday, June 22 because the 19th was a federal holiday — Phase 2 went live and eliminated the volume threshold entirely. If your organization originates ACH payments and is not a consumer, these rules now apply to you regardless of how many transactions you move. Most finance and compliance teams outside the banking sector have never heard of them.
What NACHA Is, and Why It Suddenly Matters
NACHA — formerly the National Automated Clearing House Association — governs the ACH Network, the rails behind direct deposit, payroll, vendor payments, and bank-to-bank transfers across the United States. If PCI DSS is the rulebook for card payments, NACHA’s Operating Rules are the rulebook for ACH. And like PCI DSS, NACHA is not a government regulation. It is enforced contractually, through the financial institutions in the network rather than by a federal agency.
That contractual structure is exactly why it catches organizations off guard. There is no regulator sending you a notice. The obligation flows through your bank relationships and your ACH agreements, quietly, until a fraud event or an audit surfaces the gap. A compliance team sitting inside a GovCon contractor, a healthcare system, or a tech company has no reason to be watching NACHA rulemaking — and yet if that organization runs payroll or pays vendors over ACH, the rules now reach it.
For years, NACHA’s fraud rules were narrow. They required originators to use a vague “commercially reasonable” detection system, and only for a small subset of debit transactions. The 2026 amendments are a structural shift: they replace “commercially reasonable” with “risk-based processes and procedures,” and they expand the obligation from a niche debit requirement into a network-wide fraud monitoring program covering the dominant modern threat.
The Threat NACHA Is Actually Targeting: Credit-Push Fraud
The old fraud model was about unauthorized debits — money pulled out of an account without permission. The new NACHA rules flip to the threat that now causes the most damage: credit-push fraud, where money is sent out of an account because someone was tricked into authorizing it.
This is the precise threat the companion episode opened with. An employee receives a call in the AI-cloned voice of their CFO, or an email that perfectly mimics a vendor’s communication style, and authorizes a wire or an ACH payment. The transaction is, technically, authorized. The employee approved it. And that is exactly why traditional fraud controls miss it — they are built to catch unauthorized activity, and this activity carries valid authorization obtained through deception.
NACHA created a new defined category for this: False Pretenses. The Operating Rules define it as a payment induced by a person misrepresenting their identity, their authority to act on behalf of another party, or the ownership of the account meant to receive the funds. That definition maps directly onto Business Email Compromise, vendor-payment diversion, payroll diversion, and the AI voice fraud that has supercharged all three. NACHA has, in effect, written the 2026 social-engineering threat into its rulebook and made monitoring for it mandatory.
The scale behind the rule change is the same scale the episode cited: Business Email Compromise drove $2.77 billion in reported losses in 2024 alone, with cumulative losses topping $8.5 billion since 2022, and AI has made the underlying deception dramatically more convincing. The rule exists because the losses became impossible to ignore.
Who Is in Scope — and the Two Phases That Got Us Here
The 2026 fraud monitoring requirements rolled out in two phases, and the distinction matters for understanding why your organization may have been swept in only this week.
Phase 1 — effective March 20, 2026.
This applied to the large players: all Originating Depository Financial Institutions (ODFIs — the originating banks), and any non-consumer Originator, Third-Party Service Provider, or Third-Party Sender whose 2023 ACH origination volume was 6 million transactions or greater. On the receiving side, it applied to RDFIs (Receiving Depository Financial Institutions) whose 2023 ACH receipt volume exceeded 10 million entries.
Phase 2 — effective June 19, 2026, practical date June 22, 2026.
This eliminated the volume threshold entirely. Every remaining non-consumer Originator, Third-Party Service Provider, and Third-Party Sender — regardless of transaction volume — is now subject to the fraud monitoring requirement. Every remaining RDFI is now subject to the credit monitoring requirement. There is no longer a size at which an ACH originator is too small to be in scope.
That Phase 2 expansion is the part that reaches organizations far outside traditional banking. If you originate ACH payments to run payroll, pay vendors, or move money between accounts, and you are not a consumer, you are now responsible for risk-based fraud monitoring on those transactions.
There is one more first-in-history change worth naming. For the first time, the receiving institution carries monitoring responsibility, not just the sending one. Previously, the party sending money bore the accountability. Now, RDFIs must implement risk-based processes to identify incoming credits that appear to be unauthorized or authorized under false pretenses — because the receiving bank can see the destination account’s profile, age, balance history, and the velocity of incoming transactions in ways the sending side cannot. Credit-push fraud requires both ends of the payment to be watching, and the rules now reflect that.
// INCOMING TRANSMISSION
Status: Secure Episode 021 — AI Voice Fraud, Payment Breaches, and Everything You Need to Know About PCI DSS & NACHA covers the 2026 fraud landscape, the foundational PCI DSS walkthrough, the v4.0.1 payment-page changes, the NACHA rules in context, and the Heartland paradox — why a fully compliant company was still breached. Listen for the full briefing.
INITIATE PLAYBACK »What the Rules Actually Require You to Do
The NACHA amendments are deliberately technology-neutral. They do not prescribe a specific tool or vendor. They require a documented, risk-based program — meaning you assess your own fraud risk and build proportionate monitoring around it. Here is what that program has to contain.
Risk-based fraud monitoring processes.
You must establish and implement processes reasonably intended to identify ACH entries initiated due to fraud — both unauthorized entries and entries authorized under False Pretenses. “Risk-based” means you can apply heavier scrutiny to high-risk transactions and lighter controls to low-risk ones, but you must be able to show the analysis behind those choices. NACHA points to techniques like velocity checks, anomaly detection, behavioral tolerances, and pattern recognition.
Documented procedures for verification, approval, and escalation.
The monitoring has to be written down. Informal “we usually double-check large transfers” is not a program. You need documented procedures for how a flagged transaction gets verified, who approves it, and how an escalation is handled.
Heightened scrutiny on the known high-risk scenarios.
NACHA compliance specifically calls for elevated attention to the transaction types fraudsters exploit: vendor banking-detail changes, payroll updates, and first-time payments to a new beneficiary. These are the exact moments a False Pretenses attack lands — the fraudulent “please update our bank account” email is the canonical vendor-payment-diversion attack.
An annual review.
The rules require you to review and update your fraud monitoring at least annually. NACHA has been explicit that this is not a “set it and forget it” obligation — fraudsters evolve, and your monitoring is expected to evolve with them. This mirrors the continuous-assurance shift happening across compliance frameworks, including the PCI DSS v4.0.1 move toward year-round operation rather than point-in-time validation.
Vendor accountability if you use third parties.
If a Third-Party Service Provider or Third-Party Sender handles your ACH processing, they are directly subject to the rules — but you, the originator, remain ultimately responsible. That means verifying your providers’ compliance readiness, reviewing and updating your service agreements to reflect the new requirements, and confirming what verification methods and evidence they actually maintain. A provider’s verbal assurance is not evidence.
Why Manual “Four-Eyes” Checks Are Not Enough Anymore
A common reaction to credit-push fraud is to add a second human approver — the “four-eyes” principle, where two people must sign off on a payment. It is a sound control, and the episode’s first marching order — an out-of-band callback to a known-good number before money moves — is exactly the kind of human verification every organization should implement immediately.
But at scale, manual review alone breaks down. Human reviewers introduce their own error rate, they slow down legitimate payment operations, and they cannot maintain consistent vigilance across thousands of transactions. The False Pretenses problem is specifically designed to defeat human judgment — the whole point of an AI-cloned executive voice is that it passes the human check.
The durable answer pairs the human control with automation: automated pre-payment scoring, velocity checks, anomaly detection, and beneficiary-change controls that flag the high-risk transaction before it reaches the approver, so the human attention lands where it matters. The out-of-band callback remains the backstop; the automated monitoring is what makes the callback fire on the right transactions. Done well, this actually accelerates payment operations rather than slowing them, because low-risk transactions flow through while the system concentrates scrutiny on the anomalies.
How NACHA and PCI DSS Fit Together
For a finance leader, the practical takeaway from the companion episode is that payment compliance is no longer a single-standard exercise. PCI DSS governs the card side. NACHA governs the ACH side. They come from different bodies, cover different rails, and are enforced through different contracts — but they now apply in parallel to most financial organizations, and both moved toward continuous, documented, risk-based assurance in 2026.
The unifying lesson is the one the episode anchored on with the Heartland breach: Heartland Payment Systems was fully PCI DSS compliant at the time it suffered one of the largest card breaches in history. Compliance established the floor; it did not stop a live adversary. The same logic applies to NACHA. Standing up a documented fraud monitoring program satisfies the rule — but the goal is not to satisfy the rule. The goal is to actually catch the credit-push fraud the rule was written to address. Treat the NACHA program as the floor, build real detection on top of it, and the compliance takes care of itself as a byproduct.
Marching Orders: Building Your NACHA Program Now
The grace period is over, so the sequencing is compressed. Here is the practical path.
This week — confirm scope and stand up the verification protocol.
Determine definitively whether you originate ACH payments as a non-consumer entity. If you do, Phase 2 applies to you as of June 22, 2026. Immediately implement the out-of-band verification control: no wire, ACH origination, payment-detail change, or vendor banking update above a defined threshold executes on the strength of a voice or an email alone — a callback to a known-good number is mandatory. This single policy directly addresses the False Pretenses threat and costs nothing but discipline.
This month — run an ACH-specific fraud risk assessment.
If you have not performed a fraud risk assessment specific to your ACH activity, do it now. Map your high-risk scenarios — vendor changes, payroll updates, first-time payments — and evaluate your current detection capability against them. The results of this assessment are what the rules expect you to use to design your risk-based monitoring, and the assessment itself is part of the documentation an audit will look for.
This quarter — build the documented, automated monitoring program and the annual-review cadence.
Stand up the risk-based monitoring with automated pre-payment scoring and anomaly detection layered under your human controls. Document the verification, approval, and escalation procedures. Update your agreements with any third-party ACH providers to reflect the new requirements and confirm their compliance readiness in writing. And build the annual review into your calendar now, because the rules require it and “set it and forget it” is explicitly non-compliant.
Execute the Standard
NACHA’s 2026 fraud monitoring rules are live, the volume threshold is gone, and most non-bank originators do not yet know the obligation reaches them. The rules target credit-push fraud and the new False Pretenses category — the exact AI-voice and Business Email Compromise threat reshaping finance this year — and for the first time they put both the sending and receiving institution on the hook for watching.
Payment compliance in 2026 is a two-standard discipline: PCI DSS for cards, NACHA for ACH, both demanding documented, risk-based, continuously-operating programs. And the Heartland lesson governs both — the standard is the baseline, not the finish line. The organizations that come through this well are the ones that build real fraud detection and treat the compliance as the natural result, not the goal.
If your organization needs help standing up a NACHA-compliant ACH fraud monitoring program, running an ACH-specific fraud risk assessment, or building a combined PCI DSS and NACHA payment-compliance posture before an audit or a deal demands it, that is the work we do. Verify your security posture at watchur6.com/secure, or establish a secure line at watchur6.com/contact.
Trust but verify your own posture. Stand up the verification protocol. Run the risk assessment. Build the monitoring program. Execute the standard.