New NACHA Rules for ACH Validation? Streamline Compliance with Our Supplier Portal
If your AP team pays suppliers by ACH, you need tighter checks on vendor bank data in 2026. NACHA’s updated rules put more focus on fraud monitoring, especially for new vendors, bank account changes, and first payments to a new account.
Here’s the short version:
- ACH fraud often starts during vendor setup, not at payment time
- Account validation alone is not enough because it can confirm an account is open without confirming who owns it
- Ownership checks, dual approval, and trusted callbacks matter most for bank changes
- Manual email and spreadsheet workflows create risk through spoofing, rekeying errors, and weak audit records
- A supplier portal can help AP teams document controls with self-service entry, approval flows, and time-stamped logs
A few numbers show why this matters:
- The ACH Network processed 35.2 billion payments worth $93 trillion in 2025
- 79% of organizations faced payment fraud attacks or attempts in 2024
- The median loss per vendor fraud incident was $120,000
At a basic level, this article explains one thing: AP teams should treat supplier bank setup and bank changes as a fraud control step, not just data entry. I’ll walk through the rule change, the gap between account and ownership checks, where manual processes fail, and how a supplier portal helps keep records clean for review.
ACH Validation Requirements AP Leaders Need to Know
Account Validation vs. Ownership Verification
For AP teams, this is the control gap that matters most: account validation checks that a bank account is open, correctly formatted, and able to receive ACH entries. Common methods include prenotifications, which are zero-dollar tests sent three days before a live payment, and micro-deposits, which are small credits between $0.01 and $1.00 that the recipient confirms. These steps show that the account can receive ACH. They do not show that the supplier owns it.
Ownership verification goes one step further. It matches the account number and routing code against independent banking data to confirm that the account holder’s name matches the named supplier. This control helps stop bank-account substitution, which Nacha now treats as “False Pretenses.”
That’s where the risk shows up. If AP stops at account validation and skips ownership verification, a fraudster can submit a real, open bank account that sails through a prenotification check. Only ownership verification catches the fact that the account belongs to someone else, not your vendor.
| Method | Confirms Account Is Open | Confirms Ownership | Catches “False Pretenses”? |
|---|---|---|---|
| Prenotification | Yes | No | No |
| Micro-deposits | Yes | No | No |
| Real-time API | Yes | Yes | Yes |
| Controlled callback | Yes | Yes | Yes |
Key AP Use Cases Affected by Validation Controls
These differences matter most at three points in AP: new vendor onboarding, first payments to a new account, and bank account change requests for existing suppliers.
New vendor onboarding is the clearest entry point. A fraudster posing as a real vendor submits banking details during setup, and if ownership is never checked, those details can land in the vendor master and move into payment runs with no extra review.
Bank-change requests bring the same kind of risk. While 74% of companies check vendor data during onboarding, only 20% verify it again before payment runs. Nacha’s 2026 rules call for tighter scrutiny at these exact trigger points: new vendor onboarding, first payments to a new account, and any change to existing banking details.
Dormant vendor reactivations deserve the same attention. If a supplier has been inactive for six months or more, that vendor should go through the same validation steps as a new onboarding.
ACH Risk Signals AP Teams Should Watch
Some signals should trigger an immediate review before any payment goes out. Repeated R03 or R04 returns point to bad bank data. R17 means identity review should happen before any reissue.
Return codes are only part of the story. Behavior matters too. Urgent requests to update bank details, threats of service interruption, or any request that pushes you to skip a verification step are common social engineering moves. High-value first payments should also get extra review.
The median loss per vendor fraud incident in 2024 was $120,000. That’s a painful number, and it makes the point fast: spotting these signals before a payment run is far less expensive than trying to recover funds after the money is gone.
These triggers are much easier to handle when they’re built into supplier intake and change control.
How Manual ACH Setup Creates Compliance and Fraud Risk
Email and Spreadsheet Workflows Increase Exposure
Those validation requirements can fall apart fast once supplier data starts moving through email and spreadsheets.
Email-based bank-detail collection creates a risky handoff. Suppliers send forms or PDFs, and AP rekeys that data into the ERP. On the surface, it feels normal. In practice, it’s one of the most exposed parts of the payment flow.
Why? Because when bank data comes through email, there is no independent proof that the supplier controls the account. Then the risk stacks up: bank details sit in spreadsheets, which opens a security gap and adds more room for manual-entry mistakes.
Business Email Compromise (BEC) often starts with a spoofed supplier email asking for a bank change. If AP replies to the contact in that same email thread, the callback goes straight to the fraudster.
Uncontrolled Bank Change Requests Create Payment Risk
The biggest danger point isn’t the first setup form. It’s the bank-change request that comes after.
Manual change requests often get processed from a single email or phone call, without dual approval, a trusted callback, or a hold period before payment goes out. That’s the gap fraudsters look for.
NACHA’s 2026 rules require documented, risk-based fraud monitoring procedures for non-consumer originators.
Missing Audit Trails Make Reviews Harder
When AP can’t trace the approval path, defending the control gets a lot harder.
If an internal audit or external review asks who changed a supplier’s bank account, when it happened, and how it was checked, manual processes usually don’t offer a clean answer. The proof is scattered across email threads, side notes, and different spreadsheet versions.
Without a central, timestamped log that shows who verified the account, who approved the change, and what source was used, AP can’t show that the process was consistent or defensible.
| Manual Process Gap | Risk |
|---|---|
| Email-based collection | Business Email Compromise (BEC) and spoofing exposure |
| Manual data entry | Typos, transposition errors, payment delays |
| Ad hoc change requests | No dual approval or independent verification |
| Paper/PDF records | No proof of who changed what, when, or how |
| Informal callbacks | Attacker-provided numbers defeat verification |
A controlled supplier portal replaces those manual handoffs with structured intake, approval, and audit logs.
How the AP Express Supplier Portal Supports ACH Validation and Control

Supplier Self-Service Data Entry with Built-In Controls
A controlled supplier portal helps shut down the manual gaps that often lead to errors. With the AP Express Supplier Portal, suppliers enter contact and bank details through a secure self-service portal instead of sending them over for AP staff to retype.
That matters because the data goes straight into structured fields from the start. Suppliers can enter ABA routing numbers, account numbers, and tax form details like W-9 information themselves. AP teams don’t have to rekey that data by hand, which cuts back on mistakes and saves time. It also makes onboarding faster and reduces the back-and-forth over missing or wrong information.
Validation and Approval Workflows for New and Changed Bank Accounts
Collecting bank details is only step one. AP Express also supports prenotes, micro-deposit checks, and third-party account ownership verification. Prenotes and micro-deposits confirm that the supplier can access the account. Ownership verification checks that the account belongs to the named supplier.
When a supplier asks to change bank details, AP Express adds control where it counts. Configurable workflows support dual approval and role separation, which means the person who enters a change isn’t the same person who approves it for payment.
For higher-risk changes, AP teams can also use out-of-band verification. For example, they can call a trusted phone number already on file instead of relying on contact details included in the request. That simple extra step can help stop a bad actor from slipping fake banking details into the process. Once verified, the record flows into Oracle without manual re-entry.
Audit-Ready Records and Oracle Synchronization
Every data entry, upload, approval, and change is time-stamped in a single audit trail. The portal also keeps supplier communications in a centralized Message Center, which gives teams a clear record to review later during audits or internal checks.
After banking information passes the approval workflow, the verified data syncs straight into Oracle EBS, Oracle ERP Cloud, or JD Edwards. That removes manual re-entry and helps make sure payment data lines up with the approved supplier record.
| Portal Capability | Risk Area Addressed | Compliance Benefit |
|---|---|---|
| Structured self-service data entry | Inconsistent supplier master data | Consistent supplier data at the source |
| Account ownership verification | Unauthorized or fraudulent bank changes | Supports risk-based ACH validation |
| Dual approval and role separation | Unauthorized bank changes | Enforces internal controls at the system level |
| Time-stamped audit trail | Missing or incomplete audit records | Defensible records for internal and external review |
| Direct Oracle synchronization | Mismatch between approved supplier data and payment records | Single verified source of truth for payment execution |
Once validation and control sit in one place, AP can apply them based on supplier risk tier.
EPCOR Payments Insights: A Deep Dive on ACH Fraud Monitoring Rules with EPCOR’s CEO

A Practical Framework for Reducing ACH Returns and Staying Audit-Ready

Set Validation Tiers Based on Supplier and Payment Risk
The controls above work best when AP applies them based on supplier and payment risk. Not every supplier carries the same level of risk, and not every payment deserves the same level of review. A tiered approach helps teams put tighter checks where they matter most.
- Low risk – Established vendors receiving routine CCD payments. Use basic entity and TIN matching.
- Medium risk – New vendor onboarding or recurring supplier payments. Use prenotes, micro-deposits, or account validation before the first payment.
- High risk – Any bank account change, high-value payment, or international account. Require out-of-band callbacks to a trusted number already on file, dual approval, and real-time account ownership verification.
Treat every bank change like a new onboarding event: freeze the old account, verify the new one, and hold the first payment for 3–5 business days.
Track Return Rates and Audit Trails
After controls are in place, the next step is simple: check whether they’re working. Unauthorized returns must stay below 0.5%, administrative returns below 3%, and overall returns below 15%. If you get an R17 (“suspicious transaction”) return, investigate it right away and do not reissue payment by check without verification.
You also need a clear audit trail for every vendor action. That includes submissions, approvals, and verification results. Timestamped records support audit readiness and make your controls easier to defend.
Manual ACH Setup vs. AP Express Supplier Portal: Side-by-Side Comparison
Manual workflows leave holes in validation and audit records. Here’s the day-to-day difference between manual processing and a controlled validation process.
| Feature | Manual Workflow | AP Express Supplier Portal |
|---|---|---|
| Data Collection | Email, spreadsheets, and PDF attachments | Secure supplier self-service entry with built-in validation |
| Validation Method | Manual phone callbacks and visual document review | Automated bank ownership and identity verification |
| Bank Change Approval | Informal exceptions and single-person updates | Enforced dual-approval and out-of-band confirmation |
| Audit Trail | Fragmented across inboxes, screenshots, and paper files | Centralized, timestamped logs of all changes |
| Fraud Exposure | Vulnerable to Business Email Compromise (BEC) and social engineering | Ownership matching prevents fraudulent bank changes. |
Strong ACH validation controls push verification upstream, before bad data turns into returns, delays, or fraud. AP teams need processes they can repeat, apply the same way each time, and prove with documentation. A supplier portal that enforces structured data entry, ownership verification, dual approvals, and timestamped logs gives AP teams the supplier bank data, controlled change requests, and audit-ready records needed to stay compliant and reduce payment risk.
FAQs
Do the 2026 NACHA updates apply to every ACH payment?
Yes. The 2026 NACHA rules apply to all non-consumer ACH originators, no matter the size of the organization or how many payments it sends.
The rules don’t directly say that bank account validation is required for every single transaction. But they do require risk-based processes to spot and stop fraud.
In plain English: for businesses and third-party service providers that originate ACH credits, account verification has become a standard part of compliance.
How does ownership verification differ from account validation?
Account validation checks the bank details themselves. It looks at things like whether the routing number is valid, whether the account exists and is open, and whether it can receive ACH payments.
Ownership verification confirms that the account belongs to the specific vendor you plan to pay. That matters because fraud doesn’t always look sloppy. Sometimes the bank details look fine, but they belong to someone else.
What controls should we add for vendor bank changes?
Use layered controls to cut fraud risk and back up compliance:
- Dual approval for all bank detail changes
- An out-of-band callback to a trusted number from your vendor master file, not the number in the request
- Automated account ownership verification
- Document authenticity screening at intake
- An immutable, audit-ready record of the verification method, date, and outcome
Related Articles
The Time to Implement AP Express is Always Now!
January 25, 2022 The Greeks knew better About 2000 years ago, the Greek philosopher Heraclitus...
Solving AP Sustainability Challenges with E-Payments
July 15, 2026 If you still pay suppliers by check, your AP process is slower,...