As financial institutions prepare for 2026 ACH audit testing, two compliance areas are already standing out: fraud monitoring expectations for Originators and Third-Party Service Providers/Senders, and proper use of the new PAYROLL standard Company Entry Description.
Both updates are intended to strengthen fraud detection and reduce risk in the ACH Network. But testing is showing that the challenge for many institutions is not simply understanding the rules. It is documenting how those rules are implemented, verified, and reviewed on an ongoing basis.
Fraud Monitoring: Move Beyond Communication to Verification
Under the Nacha Fraud Monitoring by Originators, Third-Party Service Providers/Senders, and ODFIs Rule, each non-consumer Originator, ODFI, and TPSP/S must establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud. These processes and procedures must be reviewed at least annually and updated as appropriate to address evolving risks.
The rule took effect in two phases. Phase 1 began March 20, 2026, for entities with annual ACH origination volume exceeding 6 million entries in 2023. Phase 2 began June 19, 2026, for all others.
One common testing issue is that institutions may have notified Originators and third-party providers about the new fraud monitoring requirements but have not fully updated their own internal policies and procedures to document how compliance will be verified.
For example, an institution may need to strengthen documentation around how it confirms Originators and TPSP/S maintain risk-based processes designed to identify ACH entries that may be unauthorized or authorized under false pretenses. Institutions should also be able to show how those controls are reviewed and updated at least annually.
A practical step is to incorporate a certification, attestation, or similar confirmation into an existing annual Originator review process, such as the annual exposure limit review. This can help document that Originators and TPSP/S have implemented appropriate fraud monitoring procedures and are reviewing them regularly as risks change.
PAYROLL Descriptions: Accuracy Depends on Standardization
The standard Company Entry Descriptions rule established two new Company Entry Descriptions: PAYROLL and PURCHASE. For PPD credit entries related to wages, salaries, and similar types of compensation, the Company Entry Description PAYROLL must be used. The purpose of the standardized PAYROLL designation is to help identify payroll transactions and reduce the risk of payroll redirection fraud.
The rule also established the Company Entry Description PURCHASE for applicable e-commerce purchase transactions. For financial institutions, however, payroll file review is likely to be one of the more visible areas during ACH testing.
The effective date for this rule is March 20, 2026.
Testing has identified instances where payroll files were originated using Company Entry Descriptions other than PAYROLL, including descriptions such as “PAY,” “WAGES,” or payroll dates. While those descriptions may clearly identify the purpose of the transaction, the rule requires the standardized PAYROLL description for applicable payroll entries.
Institutions should review payroll files originated by the institution, its Originators, and TPSP/S to confirm the Company Entry Description is PAYROLL when required. If exceptions are identified, the applicable Originator or TPSP/S should be notified and asked to update the description to comply with Nacha requirements.
What Financial Institutions Should Review Now
Before or during ACH testing, financial institutions can reduce the risk of repeat findings by focusing on the documentation and verification steps behind these rule changes. Consider whether your institution has:
- Updated internal policies and procedures to reflect the new fraud monitoring requirements.
- Documented how Originators and third-party providers will be reviewed for compliance.
- Added a certification, attestation, or other confirmation to an existing annual review process.
- Established a process to confirm fraud monitoring procedures are reviewed and updated at least annually.
- Reviewed payroll files to confirm PAYROLL is used when required.
- Communicated exceptions to Originators and TPSP/S and documented follow-up.
Prepare Now to Strengthen ACH Compliance
ACH rule changes continue to place more emphasis on fraud detection, documentation, and ongoing monitoring. By reviewing procedures now, financial institutions can identify gaps, support a smoother audit process, and better protect customers from evolving fraud risks.
If your institution is preparing for ACH audit testing or reviewing its 2026 Nacha compliance procedures, contact a Pinion advisor to talk through potential gaps, strengthen documentation, and reduce the risk of repeat findings.
__PRESENT



