ACH (Automated Clearing House) is one of the most widely used payment rails in the US, and it carries specific compliance obligations under Nacha Operating Rules and the Bank Secrecy Act. This guide explains what ACH compliance requires for fintechs operating as originators, third-party senders, or payment processors.
What Is ACH Compliance? BSA and Nacha Requirements for Fintechs
ACH — the Automated Clearing House network — processes billions of transactions annually, including direct deposits, bill payments, consumer-to-business payments, and business-to-business transfers. For fintechs that originate or facilitate ACH transactions, compliance is not optional. ACH compliance spans two distinct frameworks: Nacha Operating Rules (the private rulebook governing the ACH network) and the Bank Secrecy Act (the federal AML law that applies to money services businesses and financial institutions).
Understanding both frameworks — and how they interact — is essential for any fintech whose product touches ACH.
How ACH Works: The Key Participants
ACH transactions involve several distinct roles, each with different compliance obligations:
- Originator: The entity that initiates an ACH transaction. In consumer payments, this is typically the business collecting a payment (e.g., a subscription company debiting a customer's bank account).
- ODFI (Originating Depository Financial Institution): The bank or credit union that accepts the ACH entry from the originator and submits it to the ACH network. ODFIs are responsible for their originators' compliance under Nacha rules.
- ACH Operator: The network operator that routes ACH entries between ODFIs and RDFIs. There are two ACH operators in the US: the Federal Reserve (FedACH) and The Clearing House (EPN).
- RDFI (Receiving Depository Financial Institution): The bank or credit union that receives the ACH entry and credits or debits the receiver's account.
- Third-Party Sender (TPS): A non-bank entity that transmits ACH entries on behalf of originators through an ODFI. Many fintech payment platforms act as Third-Party Senders — a role that carries specific Nacha compliance obligations.
Nacha Operating Rules: What Fintechs Must Know
Nacha (previously known as NACHA — the National Automated Clearing House Association) publishes and enforces the Operating Rules that govern all ACH transactions in the US. Compliance with Nacha rules is required for any entity participating in the ACH network, directly or as a Third-Party Sender.
Originator Obligations Under Nacha Rules
- Authorization: Originators must obtain valid authorization from receivers before initiating ACH debits. Authorization requirements vary by ACH entry type (PPD, CCD, WEB, TEL, etc.) and must be documented and retained.
- Return rate monitoring: Nacha sets maximum unauthorized return rate thresholds. Originators with return rates exceeding these thresholds face investigation by their ODFI and potential suspension from the ACH network. The current thresholds are available in the Nacha Operating Rules and subject to periodic updates.
- Data security: Under Nacha's data security rule, originators that store account numbers electronically must protect that data using strong encryption or tokenization.
- WEB debit authentication: For internet-initiated debit entries (WEB), Nacha requires a commercially reasonable fraudulent transaction detection system to screen debits before transmission.
Third-Party Sender (TPS) Obligations
Fintechs that transmit ACH entries on behalf of other companies are classified as Third-Party Senders under Nacha rules. TPS status carries additional obligations:
- Registration with Nacha as a Third-Party Sender (required since 2022)
- Enhanced due diligence on the originators whose entries you transmit — equivalent to KYB for your originator portfolio
- Contractual responsibility for your originators' compliance with Nacha rules
- Monitoring of originator return rates and taking action when thresholds are breached
- Notification obligations to your ODFI of significant changes in originator activity
BSA and AML Obligations for ACH
In addition to Nacha rules, fintechs that qualify as money services businesses (MSBs) or that are otherwise subject to the Bank Secrecy Act must integrate ACH activity into their AML compliance program.
Transaction Monitoring for ACH
ACH transactions must be included in your transaction monitoring program. Common ACH-specific red flags include:
- Unusually high return rates suggesting unauthorized debit activity
- ACH debits to or from high-risk jurisdictions or counterparties on OFAC sanctions lists
- Structuring of ACH transactions to stay below reporting thresholds
- Rapid movement of funds through ACH followed by immediate withdrawal
- ACH activity inconsistent with the customer's stated business type or transaction history
SAR Filing for ACH Transactions
If your ACH monitoring identifies suspicious activity that meets BSA SAR thresholds, you must file a Suspicious Activity Report with FinCEN. ACH-related SARs should describe the specific pattern of ACH activity that raised concern, including return rates, transaction volumes, and counterparty details. See our guide on what is a SAR for filing thresholds and procedures.
BSA Recordkeeping for ACH
The BSA's recordkeeping requirements for funds transfers (31 CFR 1020.410) apply to ACH transactions of $3,000 or more when a financial institution is acting in a funds transfer capacity. Retain required records for five years and ensure they are retrievable on regulatory request.
OFAC Screening for ACH Transactions
All ACH transactions must be screened against OFAC sanctions lists before processing. This applies to both the originator and the receiver. An OFAC hit on an ACH transaction requires you to block the transaction, freeze the funds, and file a report with OFAC. See our guide on OFAC sanctions screening for procedures.
ACH Compliance and Money Transmitter Licensing
Fintechs that facilitate ACH payments on behalf of customers — particularly Third-Party Senders that hold and transmit funds — may trigger money transmitter licensing requirements in the states where they operate. The determination is fact-specific and depends on whether your platform holds or controls funds in transit. Consult qualified legal counsel to assess your licensing obligations before launching ACH-based payment products.
Frequently Asked Questions
What is the difference between ACH and wire transfer compliance?
ACH and wire transfers are subject to different regulatory frameworks. Wire transfers are subject to the BSA Travel Rule and $3,000 recordkeeping requirements under 31 CFR 1010.410. ACH transactions are governed by Nacha Operating Rules (a private rulebook) plus applicable BSA requirements, but are not subject to the same Travel Rule information-passing obligations as wires. See our guide on wire transfer compliance for a comparison.
Does my fintech need to register as a Third-Party Sender with Nacha?
If your company transmits ACH entries on behalf of other businesses — rather than just for your own direct payments — you likely qualify as a Third-Party Sender and must register with Nacha. Nacha began requiring TPS registration in 2022 as part of its risk management framework.
What happens if my ACH return rates exceed Nacha thresholds?
Exceeding Nacha's unauthorized return rate thresholds triggers a formal review by your ODFI. Persistent violations can result in termination of your ACH origination agreement, effectively removing your ability to originate ACH transactions. Return rate monitoring should be a core operational metric for any fintech originating ACH debits.
What is the WEB debit rule and who does it apply to?
The WEB debit rule applies to all ACH debit entries initiated via the internet (WEB entry type). It requires originators to use a commercially reasonable fraudulent transaction detection system to screen debits — meaning an automated system that evaluates transaction risk before submission, not just manual review.
This article is for educational purposes only and does not constitute legal or compliance advice. Nacha rules and BSA requirements are subject to change. Verify current requirements with Nacha and FinCEN guidance before building or modifying your compliance program.