Nacha Is Live. What Changed, and Why Your Tools Miss It

 

Nacha's Phase 2 rules took effect June 22, 2026. They extended the fraud monitoring obligation to both sides of the ACH transaction: originator and receiver. If the proceeds of a scam land in one of your accounts, whether the victim banks with you or elsewhere, your institution now carries a detection duty.

Most institutions will say they comply. Far fewer can show it, and the consequences of a weak answer are not abstract. A defined standard now exists to hold you to, which means findings, remediation timelines, and follow-up exams for the institutions that fall short.

The hard part is not the rule. It is that the tools most institutions rely on were built for a different threat, and cannot see the fraud the rule is aimed at. This two-page summary shows you where, and why.

 

Download the Nacha 2-pager

 

What's inside

Two pages, built to be read in five minutes and shared across your team. It covers:

  • The blind spot: a clear map of why each layer of the fraud stack, new-account fraud, device intelligence, strong authentication, and transaction monitoring, waves an authorized-fraud payment straight through.

  • The receiving-side obligation. the new duty most programs cannot answer for, and the three kinds of mule accounts, unwitting, witting, and complicit, you are now expected to spot in your own book.

  • What the rule actually targets: why False Pretenses means impersonation, business email compromise, vendor and payroll fraud, and not consumer scams over fake goods.

  • Where the picture changes: how account-level intelligence sees the setup, and lets you intervene before a transaction is initiated.

For a scored assessment and action plan, download the full Nacha Audit-Readiness Guide.

what
 

Who it's for

This is a starting-point document, written for fraud and financial crime leaders at US banks and credit unions who need to understand what the rules actually say before they can assess where their program stands.

If you own fraud detection, AML, BSA, compliance, or enterprise risk, or if you will be expected to speak to Nacha readiness when asked, this is the right place to begin. So is anyone who needs to brief other stakeholders on what Phase 2 actually changed.

It does not score your program or walk through audit questions. It covers the mechanics: what the obligation requires, which fraud categories it targets, and the account-level risk it asks you to manage. That foundation is what makes the full Nacha Audit-Readiness Guide actionable rather than abstract.

who (1)
 

Why the rules alone won't stop the fraud

Here is the part the rules do not say out loud. Meeting the letter of the obligation is not the same as stopping the fraud. Transaction monitoring, device intelligence, and strong authentication were all built to catch an intruder. Authorized fraud has no intruder to catch. Your controls see a genuine customer doing genuine things and wave the payment through. Generative AI has made it harder: voice clones, deepfakes, and personalized scripts that manipulate your customers at machine speed. The rules set a minimum standard. The fraud has already moved past it.

Stopping it means watching the account, not the transaction, and doing it early. That is where the loss is decided, and where nothing is watching. Acoru's Continuous Account Intelligence operates in that window, classifying every account, correlating signals across digital, call center, and payment channels, and surfacing risk before a transaction is initiated, so your team can intervene while it still matters.

The guide is where to start. Download it today.

Continuous Account Intelligence uses omnichannel orchestration