See AP Express in action August 27th @ 2 p.m. ET – Click here to register.
AP Express by Nivo1 Meet with an Expert

New NACHA Rules for ACH Validation? Streamline Compliance with Our Supplier Portal


Read time: minutes July 7, 2026 | leanne Table of Contents
    Add a header to begin generating the table of contents

    If your AP team pays suppliers by ACH, you need tighter checks on vendor bank data in 2026. NACHA’s updated rules put more focus on fraud monitoring, especially for new vendors, bank account changes, and first payments to a new account.

    Here’s the short version:

    • ACH fraud often starts during vendor setup, not at payment time
    • Account validation alone is not enough because it can confirm an account is open without confirming who owns it
    • Ownership checks, dual approval, and trusted callbacks matter most for bank changes
    • Manual email and spreadsheet workflows create risk through spoofing, rekeying errors, and weak audit records
    • A supplier portal can help AP teams document controls with self-service entry, approval flows, and time-stamped logs

    A few numbers show why this matters:

    • The ACH Network processed 35.2 billion payments worth $93 trillion in 2025
    • 79% of organizations faced payment fraud attacks or attempts in 2024
    • The median loss per vendor fraud incident was $120,000

    At a basic level, this article explains one thing: AP teams should treat supplier bank setup and bank changes as a fraud control step, not just data entry. I’ll walk through the rule change, the gap between account and ownership checks, where manual processes fail, and how a supplier portal helps keep records clean for review.

    ACH Validation Requirements AP Leaders Need to Know

    Account Validation vs. Ownership Verification

    For AP teams, this is the control gap that matters most: account validation checks that a bank account is open, correctly formatted, and able to receive ACH entries. Common methods include prenotifications, which are zero-dollar tests sent three days before a live payment, and micro-deposits, which are small credits between $0.01 and $1.00 that the recipient confirms. These steps show that the account can receive ACH. They do not show that the supplier owns it.

    Ownership verification goes one step further. It matches the account number and routing code against independent banking data to confirm that the account holder’s name matches the named supplier. This control helps stop bank-account substitution, which Nacha now treats as “False Pretenses.”

    That’s where the risk shows up. If AP stops at account validation and skips ownership verification, a fraudster can submit a real, open bank account that sails through a prenotification check. Only ownership verification catches the fact that the account belongs to someone else, not your vendor.

    MethodConfirms Account Is OpenConfirms OwnershipCatches “False Pretenses”?
    PrenotificationYesNoNo
    Micro-depositsYesNoNo
    Real-time APIYesYesYes
    Controlled callbackYesYesYes

    Key AP Use Cases Affected by Validation Controls

    These differences matter most at three points in AP: new vendor onboarding, first payments to a new account, and bank account change requests for existing suppliers.

    New vendor onboarding is the clearest entry point. A fraudster posing as a real vendor submits banking details during setup, and if ownership is never checked, those details can land in the vendor master and move into payment runs with no extra review.

    Bank-change requests bring the same kind of risk. While 74% of companies check vendor data during onboarding, only 20% verify it again before payment runs. Nacha’s 2026 rules call for tighter scrutiny at these exact trigger points: new vendor onboarding, first payments to a new account, and any change to existing banking details.

    Dormant vendor reactivations deserve the same attention. If a supplier has been inactive for six months or more, that vendor should go through the same validation steps as a new onboarding.

    ACH Risk Signals AP Teams Should Watch

    Some signals should trigger an immediate review before any payment goes out. Repeated R03 or R04 returns point to bad bank data. R17 means identity review should happen before any reissue.

    Return codes are only part of the story. Behavior matters too. Urgent requests to update bank details, threats of service interruption, or any request that pushes you to skip a verification step are common social engineering moves. High-value first payments should also get extra review.

    The median loss per vendor fraud incident in 2024 was $120,000. That’s a painful number, and it makes the point fast: spotting these signals before a payment run is far less expensive than trying to recover funds after the money is gone.

    These triggers are much easier to handle when they’re built into supplier intake and change control.

    How Manual ACH Setup Creates Compliance and Fraud Risk

    Email and Spreadsheet Workflows Increase Exposure

    Those validation requirements can fall apart fast once supplier data starts moving through email and spreadsheets.

    Email-based bank-detail collection creates a risky handoff. Suppliers send forms or PDFs, and AP rekeys that data into the ERP. On the surface, it feels normal. In practice, it’s one of the most exposed parts of the payment flow.

    Why? Because when bank data comes through email, there is no independent proof that the supplier controls the account. Then the risk stacks up: bank details sit in spreadsheets, which opens a security gap and adds more room for manual-entry mistakes.

    Business Email Compromise (BEC) often starts with a spoofed supplier email asking for a bank change. If AP replies to the contact in that same email thread, the callback goes straight to the fraudster.

    Uncontrolled Bank Change Requests Create Payment Risk

    The biggest danger point isn’t the first setup form. It’s the bank-change request that comes after.

    Manual change requests often get processed from a single email or phone call, without dual approval, a trusted callback, or a hold period before payment goes out. That’s the gap fraudsters look for.

    NACHA’s 2026 rules require documented, risk-based fraud monitoring procedures for non-consumer originators.

    Missing Audit Trails Make Reviews Harder

    When AP can’t trace the approval path, defending the control gets a lot harder.

    If an internal audit or external review asks who changed a supplier’s bank account, when it happened, and how it was checked, manual processes usually don’t offer a clean answer. The proof is scattered across email threads, side notes, and different spreadsheet versions.

    Without a central, timestamped log that shows who verified the account, who approved the change, and what source was used, AP can’t show that the process was consistent or defensible.

    Manual Process GapRisk
    Email-based collectionBusiness Email Compromise (BEC) and spoofing exposure
    Manual data entryTypos, transposition errors, payment delays
    Ad hoc change requestsNo dual approval or independent verification
    Paper/PDF recordsNo proof of who changed what, when, or how
    Informal callbacksAttacker-provided numbers defeat verification

    A controlled supplier portal replaces those manual handoffs with structured intake, approval, and audit logs.

    How the AP Express Supplier Portal Supports ACH Validation and Control

    AP Express Supplier Portal

    Supplier Self-Service Data Entry with Built-In Controls

    A controlled supplier portal helps shut down the manual gaps that often lead to errors. With the AP Express Supplier Portal, suppliers enter contact and bank details through a secure self-service portal instead of sending them over for AP staff to retype.

    That matters because the data goes straight into structured fields from the start. Suppliers can enter ABA routing numbers, account numbers, and tax form details like W-9 information themselves. AP teams don’t have to rekey that data by hand, which cuts back on mistakes and saves time. It also makes onboarding faster and reduces the back-and-forth over missing or wrong information.

    Validation and Approval Workflows for New and Changed Bank Accounts

    Collecting bank details is only step one. AP Express also supports prenotes, micro-deposit checks, and third-party account ownership verification. Prenotes and micro-deposits confirm that the supplier can access the account. Ownership verification checks that the account belongs to the named supplier.

    When a supplier asks to change bank details, AP Express adds control where it counts. Configurable workflows support dual approval and role separation, which means the person who enters a change isn’t the same person who approves it for payment.

    For higher-risk changes, AP teams can also use out-of-band verification. For example, they can call a trusted phone number already on file instead of relying on contact details included in the request. That simple extra step can help stop a bad actor from slipping fake banking details into the process. Once verified, the record flows into Oracle without manual re-entry.

    Audit-Ready Records and Oracle Synchronization

    Every data entry, upload, approval, and change is time-stamped in a single audit trail. The portal also keeps supplier communications in a centralized Message Center, which gives teams a clear record to review later during audits or internal checks.

    After banking information passes the approval workflow, the verified data syncs straight into Oracle EBS, Oracle ERP Cloud, or JD Edwards. That removes manual re-entry and helps make sure payment data lines up with the approved supplier record.

    Portal CapabilityRisk Area AddressedCompliance Benefit
    Structured self-service data entryInconsistent supplier master dataConsistent supplier data at the source
    Account ownership verificationUnauthorized or fraudulent bank changesSupports risk-based ACH validation
    Dual approval and role separationUnauthorized bank changesEnforces internal controls at the system level
    Time-stamped audit trailMissing or incomplete audit recordsDefensible records for internal and external review
    Direct Oracle synchronizationMismatch between approved supplier data and payment recordsSingle verified source of truth for payment execution

    Once validation and control sit in one place, AP can apply them based on supplier risk tier.

    EPCOR Payments Insights: A Deep Dive on ACH Fraud Monitoring Rules with EPCOR’s CEO

    EPCOR

    A Practical Framework for Reducing ACH Returns and Staying Audit-Ready

    Manual ACH Workflow vs. Supplier Portal: Fraud Risk & Compliance Comparison
    Manual ACH Workflow vs. Supplier Portal: Fraud Risk & Compliance Comparison

    Set Validation Tiers Based on Supplier and Payment Risk

    The controls above work best when AP applies them based on supplier and payment risk. Not every supplier carries the same level of risk, and not every payment deserves the same level of review. A tiered approach helps teams put tighter checks where they matter most.

    • Low risk – Established vendors receiving routine CCD payments. Use basic entity and TIN matching.
    • Medium risk – New vendor onboarding or recurring supplier payments. Use prenotes, micro-deposits, or account validation before the first payment.
    • High risk – Any bank account change, high-value payment, or international account. Require out-of-band callbacks to a trusted number already on file, dual approval, and real-time account ownership verification.

    Treat every bank change like a new onboarding event: freeze the old account, verify the new one, and hold the first payment for 3–5 business days.

    Track Return Rates and Audit Trails

    After controls are in place, the next step is simple: check whether they’re working. Unauthorized returns must stay below 0.5%, administrative returns below 3%, and overall returns below 15%. If you get an R17 (“suspicious transaction”) return, investigate it right away and do not reissue payment by check without verification.

    You also need a clear audit trail for every vendor action. That includes submissions, approvals, and verification results. Timestamped records support audit readiness and make your controls easier to defend.

    Manual ACH Setup vs. AP Express Supplier Portal: Side-by-Side Comparison

    Manual workflows leave holes in validation and audit records. Here’s the day-to-day difference between manual processing and a controlled validation process.

    FeatureManual WorkflowAP Express Supplier Portal
    Data CollectionEmail, spreadsheets, and PDF attachmentsSecure supplier self-service entry with built-in validation
    Validation MethodManual phone callbacks and visual document reviewAutomated bank ownership and identity verification
    Bank Change ApprovalInformal exceptions and single-person updatesEnforced dual-approval and out-of-band confirmation
    Audit TrailFragmented across inboxes, screenshots, and paper filesCentralized, timestamped logs of all changes
    Fraud ExposureVulnerable to Business Email Compromise (BEC) and social engineeringOwnership matching prevents fraudulent bank changes.

    Strong ACH validation controls push verification upstream, before bad data turns into returns, delays, or fraud. AP teams need processes they can repeat, apply the same way each time, and prove with documentation. A supplier portal that enforces structured data entry, ownership verification, dual approvals, and timestamped logs gives AP teams the supplier bank data, controlled change requests, and audit-ready records needed to stay compliant and reduce payment risk.

    FAQs

    Do the 2026 NACHA updates apply to every ACH payment?

    Yes. The 2026 NACHA rules apply to all non-consumer ACH originators, no matter the size of the organization or how many payments it sends.

    The rules don’t directly say that bank account validation is required for every single transaction. But they do require risk-based processes to spot and stop fraud.

    In plain English: for businesses and third-party service providers that originate ACH credits, account verification has become a standard part of compliance.

    How does ownership verification differ from account validation?

    Account validation checks the bank details themselves. It looks at things like whether the routing number is valid, whether the account exists and is open, and whether it can receive ACH payments.

    Ownership verification confirms that the account belongs to the specific vendor you plan to pay. That matters because fraud doesn’t always look sloppy. Sometimes the bank details look fine, but they belong to someone else.

    What controls should we add for vendor bank changes?

    Use layered controls to cut fraud risk and back up compliance:

    • Dual approval for all bank detail changes
    • An out-of-band callback to a trusted number from your vendor master file, not the number in the request
    • Automated account ownership verification
    • Document authenticity screening at intake
    • An immutable, audit-ready record of the verification method, date, and outcome

    Related Articles

    Upgrades

    The Time to Implement AP Express is Always Now!

    January 25, 2022 The Greeks knew better About 2000 years ago, the Greek philosopher Heraclitus...
    Moving suppliers off paper checks to ACH, wires, and virtual cards cuts AP costs, CO2, errors, and speeds payments.

    Solving AP Sustainability Challenges with E-Payments

    July 15, 2026 If you still pay suppliers by check, your AP process is slower,...
    default - banner

    The Seven Best Reasons Not to Outsource Accounts Payable

    January 25, 2022 Digital transformation has moved from front office/customer facing initiatives and is now...