How to Manage ACH Risk as Volume Grows and Nacha Rules Tighten

Fraud

By Jim Young

26 Aug, 2026

ACH isn’t the flashiest payment rail, but it’s the one nearly everyone depends on. Payroll, vendor payments, consumer bill pay all run through it, and it’s not slowing down. ACH network volume grew 7.9% in 2025, while same-day ACH grew 16.7%. That growth is good news for financial institutions and the businesses they serve. But it’s also more transaction volume for risk and operations teams to manage, at the same time regulators are raising expectations for how that risk gets monitored.

Nacha’s 2026 rule updates have pushed both sides of the network toward more proactive, data-driven fraud monitoring. On the origination side, financial institutions need documented processes to identify entries suspected of being initiated due to fraud and to review and update those processes regularly. This includes cases in which a transaction was technically authorized but obtained under false pretenses, like business email compromise or vendor impersonation.

On the receiving side, institutions are expected to factor in things like account age, balance history, transaction velocity, and behavioral anomalies—treating dormant or new accounts, and high-dollar or rapid-repeat credits, as higher risk.

More volume plus more scrutiny equals a lot of pressure on ACH teams that, in many cases, have not grown headcount to match. That was the theme that Jordan Brockman, Solutions Consultant at and Kyle Schultz, Technical Product Manager at First Merchants explored during “ACH Under Pressure,” a session at Q2’s CONNECT26 conference.

Where ACH risk management breaks down

For many financial institutions, their ACH processes can seem overwhelming. Risk reviews are often built on spreadsheets, data is spread across multiple different systems, and reporting is compiled by hand. Schultz described First Merchants’ prior state bluntly: “We were kind of engaged in an archaic solution when it came to ACH credit risk management and fraud management.”

It’s a slow way to manage a fast-growing, increasingly scrutinized payment channel. Pulling a single originator’s full risk picture might mean logging into the core, a lending system, and a separate reporting tool just to get a baseline … and then doing it all again for the next review.

A single view of ACH risk

First Merchants turned to Q2 Centrix ACH Processing and Risk Management (also known as Payments I.Q. System, or PIQS) to bring that data together. In 2025 alone, the bank originated $16 billion in ACH volume through PIQS while managing more than 3,500 companies spanning over 11,000 subsidiaries.

The bank built a model around 29 configurable risk categories, rolled up into a single risk score that refreshes weekly. Each originator falls into one of four risk tiers, with review frequency matched to that tier. Low-risk originators get reviewed periodically and at a lower rate, while high- and very-high-risk originators get more frequent attention. That weekly refresh also makes trend lines visible: An originator drifting from low into medium risk shows up before it becomes a bigger problem.

“PIQS has significantly improved our efficiency in evaluating ACH originator risk by centralizing all relevant ACH and credit risk data into a single form,” Schultz said. “This consolidation has reduced data-gathering time and enabled a more nuanced, informed approach to client risk management.”

That single form pulls in account balances and overdraft data from a nightly core extract, along with ACH origination activity and loan performance, including originator-specific risk indicators like unauthorized returns. It also captures the split between pre-funded and settlement-date-funded originators, a distinction that materially changes an originator's risk profile. Supporting documentation can be attached directly, and the system recommends limits based on where an originator falls in the risk model.

The result: Reviews that used to take four or more hours per company are now completed in minutes, and Schultz estimates the bank has realized roughly a tenfold gain in efficiency.

“It used to take a long time to get it from start to finish,” he said. “Now there’s not really a reason for us to have to wait that long, and there’s less likelihood for error in this process.”

That efficiency also freed up First Merchants’ relationship-facing staff. Treasury management officers, who know the customer relationships best, still kick off the review process and retain visibility into it. But the operational work now runs through a centralized treasury management operations team, with credit reviews routed to the right regional team through a queue.

“What you want from your treasury management officers is to go out there and sell,” Schultz said. Consolidating the workflow meant the bank could do that without losing the relationship insight those officers bring.”

The financial impact showed up quickly. By right-sizing limits for settlement-date-funded originators whose actual activity didn’t justify their existing exposure, First Merchants cut $300,000 in ACH exposure almost immediately.

“Those were limits customers didn’t need based on their actual activity,” Schultz said. “Removing them lowered the bank’s risk profile and reduced their exposure, too.”

The bank has since used those same limits proactively with customers in digital banking, giving them visibility into their own boundaries, and giving the bank an early signal if a customer needs to request more.

Reporting and processing that keep pace

Risk reviews are only part of the picture. First Merchants also uses PIQS for board and exception reporting. Return percentages, over-limit activity, and trend analysis that used to be assembled manually now run on a schedule and land automatically wherever the bank needs them. Configurable report tags let the bank flag specific populations, like third-party ACH originators, so the activity and due diligence tied to those higher-risk relationships is easy to pull on demand.

On the processing side, PIQS validates files, formats, and limits before anything reaches the core, catching issues earlier and reducing the manual research that used to happen after the fact. It also replaced a process that once relied on customers calling in to request a file be pulled or corrected after submission with a structured ACH reversal process built into the system.

Closing the loop on corrections and inbound risk

One of the more requested recent additions to PIQS addresses a persistent headache: Notifications of Change, or NOCs, and the originators who keep making the same correctable mistakes. Brockman described the fix as “keeping the originator out of the penalty box.” 

Rather than having the bank silently auto-correct recipient information or chase originators down after the fact, a new featured called NOC Recipient Hold puts the correction back in the originator’s hands, with the change documented for audit purposes.

NOC Recipients Hold

“We’ve gone the known routes, we’ve charged fees for NOC violations, but we don’t want that to be the case,” Schultz said. “We want customers to understand how this works. It didn’t feel right to auto-correct these without the customer being part of the workflow.”

It’s a small design choice with an outsized effect: fewer repeat NOCs, fewer processing delays, and a better-informed originator on the other end.

That same philosophy of giving institutions clearer signs of risk without taking humans out of the loop extends to the receiving side, where Nacha’s 2026 changes put more responsibility on RDFIs to monitor inbound activity. PIQS now includes anomaly detection for incoming ACH, flagging cases like mismatches between the name on an incoming file and the name on the receiving account, so institutions can catch a potential problem before funds move rather than after.

What’s coming next

Q2 continues to invest in the parts of ACH risk management that are hardest to scale by hand: judgment and consistency. On the roadmap is an agentic AI capability, tentatively called Risk Review Intelligence, designed to surface the most relevant data points during a risk review and guide reviewers to their next step. It’s useful both for newer staff still learning the process and for keeping decisions consistent across different credit teams. It’s explicitly not about removing humans from higher-risk decisions; rather, the goal is to let low-risk, well-behaved originators move through review faster, with people focused where judgment matters most.

The bottom line

ACH volume isn’t going to level off, and neither is regulatory expectation around how it’s monitored. For institutions still managing that risk with spreadsheets and manual lookups, the pressure compounds every year. First Merchants’ experience shows what the alternative looks like: centralized data, risk-tiered review cycles, and a process fast enough that growth doesn’t have to mean falling behind.

That’s the outcome Brockman said Q2 is aiming for across the board. “We’re here to help take the pressure off of your teams,” he said, “and help you sleep easier at night.”

Want to see how Q2 Centrix ACH Processing and Risk Management could work for your institution? Schedule a demo to learn more.