Where ACH losses usually begin
| Risk | Operational consequence |
|---|---|
| Compromised credentials | Unauthorized file or payment release |
| Vendor instruction change | Funds redirected to a fraudulent account |
| Weak debit authorization | Disputes and unauthorized return exposure |
| Poor return monitoring | Exceptions sit unresolved and recur |
Returns are operating signals
A return is not just an accounting reversal. Repeated insufficient-funds returns, invalid-account returns, unauthorized debits or unusual timing patterns can signal weak customer data, fraud or poor payment controls.
Separate creation from release
For material payment files, use dual approval and role-based limits so the same employee cannot freely create a new beneficiary and release a high-value payment without review.
Verify changed instructions independently
Never rely only on the email or message that requests a bank-account change. Confirm through a previously known phone number, portal or trusted contact.
Monitor unusual credits too
Federal Reserve material notes that 2026 ACH risk-management rules require receiving institutions to implement risk-based processes to identify credit entries initiated due to fraud. Businesses should likewise treat unexpected or anomalous ACH activity as something to investigate, not merely reconcile.
Primary sources and reference material
Design treasury around controls and exceptions, not only speed.
The strongest treasury setup combines the right payment rail with role separation, verification, reconciliation and enough visibility to catch unusual activity before it becomes a loss.