ACH may be one of the payments industry’s most established networks, but it’s far from standing still. With new Rules taking effect this September—and another significant change already slated for 2028—financial institutions are facing a steady stream of adjustments that could affect how they process transactions, make funds available, and manage compliance.
Earlier this year, Nacha implemented Rules aimed at bolstering financial institutions’ automated push payment fraud protections and cultivating a risk-based approach to fraud detection. This September, additional changes are coming down the pike, geared toward optimizing rules for International ACH Transactions (IATs) and funds availability for non-Same Day ACH transactions.
In a recent PaymentsJournal podcast, Devon Marsh. Managing Director of ACH Network Rules and Risk Management at Nacha, and Ben Danner, Senior Debit Analyst at Javelin Strategy & Research, discussed the reasoning behind the Rules and how financial institutions should adapt to new processes and strategies.
Understanding these Rules is critical, not just to maintain compliance, but also to increase efficiency and prepare for the next evolution of ACH.
Calibrating Cross-Border Payments
When a payment crosses a border, even if only part of the transaction does, the Rules governing it can become considerably more complicated. That is part of what Nacha is addressing with its definition of an International ACH Transaction.
One of the most significant imminent changes is that the definition of IATs will be recalibrated, not replaced.
“When people hear there’s a new definition, they think the definition has changed,” Marsh said. “The revision sought to provide clarity, so there is really no conceptual change in what type of transaction should be called an International ACH Transaction. What changed in the definition was the way it was worded—hopefully, it’s a more accessible definition now and Originators can understand better what they need to code as an IAT when they create an ACH entry.”
When approaching the new definition, the first step for any ACH Network participant that facilitates IAT entries—including Originators, Originating Depository Financial Institutions (ODFIs), and Receiving Depository Financial Institutions (RDFIs)—is to study the definition and compare it against the types of transactions they currently process.
In this process, some organizations that currently create IATs may discover that transactions they have historically considered IATs will not fall under the updated definition. Others may find that transactions previously treated as domestic payments actually meet the definition of an IAT.
Once institutions have ascertained how to appropriately apply the definition, the next step is to educate personnel and begin classifying transactions accordingly. This will make the process more streamlined and better suited to the growing global economy.
“It’s about clarity, which determines the obligations attached to the transaction,” Danner said. “Clarifying definitions around International ACH helps for more accurate compliance screening. It’s better, more accurate data to assess risk for all institutions across the [ACH] Network.”
“Part of a larger trend is that cross-border is growing,” he said. “According to Nacha data, over 121 million IATs were processed in 2024. This shift in thinking about screening and risk monitoring and definitional clarity is even more important as cross-border volume grows.”
But classification is only one part of the equation. For customers, one of the most tangible effects of a Nacha Rule change is much simpler—when can they actually use their money?
The Interest of Making Funds Available
That question sits at the center of another important change this September. The updated Rules around funds availability for non-Same Day ACH credit entries will change when RDFIs must make funds available—and remove a condition that has been in place for years.
For many years, the Nacha Rules have stated that an RDFI that receives next-day credit entries by 5 p.m. must make those entries available to receivers by 9 a.m. local time on the settlement date.
One component of the updated Rules will remove the 5 p.m. condition. Beginning Sept. 18, funds must be made available by 9 a.m. on the settlement date, regardless of when the file was received.
For example, if an RDFI receives a file in a 6 a.m. file distribution from its ACH Network Operator, the institution will be expected to make the credit entries with that settlement date available by 9 a.m.
“Most RDFIs that we talked with in developing this Rule already did that as a matter of practice,” Marsh said. “That 5 p.m. condition was a requirement, but posting transactions received after that wasn’t a violation. It didn’t say if you receive after 5 p.m. you can’t post; it was saying if you receive before 5 p.m., you must post.”
“Most RDFIs, in the interest of making funds available to their receivers, would receive files well after 5 p.m. and make those available by 9 a.m. on the settlement date,” he said. “So, most of the RDFIs probably didn’t have a change to implement, they just had to ensure they were complying with this new Rule.”
At first glance, that may sound like a relatively narrow operational adjustment. But the change illustrates a broader point: even seemingly small changes to Nacha Rules can force institutions to rethink how their systems, teams, and processes work together.
And Nacha has accounted for the fact that not every institution operates on the same clock. In exploring the removal of the 5 p.m. condition, Nacha considered that there are several financial institutions located significantly east of the Atlantic Time Zone and west of the international date line.
For example, there are financial institutions in the U.S. territory Guam. These institutions may receive files that are not even available to them before 9 a.m. local time on the settlement date. This is why Nacha established an exception—a carve-out for institutions that are not logically or physically capable of complying with the Rule.
While these changes may cause a short-term shift for financial institutions, they can have substantial impacts for customers, including potentially earlier access to payroll, benefits, refunds, and other ACH credits.
“If you think about what non-Same Day ACH credits are used for, it’s things like payroll benefits, government benefits, refunds, and invoice payments,” Danner said. “Perhaps with this change in window, it could be those payments could be available earlier, which could improve cash flow or reduce wait times—all the benefits of receiving a faster payment, particularly for these time-sensitive payments.”
Streamlining Return Codes
By the time the new return reason code R90 takes effect in March 2028, institutions will have plenty of time to prepare. The question is whether they will use it.
“The reason we developed the new code R90 is because R16 paired two return reasons that were not necessarily logically connected,” Marsh said. “There’s returning due to sanctions obligations that the new code will take on, and R16 will remain the return reason code for account frozen.”
“The best explanation for why we need to separate those out is because once the ODFI and the Originator receive a return back, they may need to do different things based on what the actual reason was,” he said.
Splitting these return reasons into two separate codes is designed both to provide clarity on the origination side and to offer the RDFI a discrete code for returns related specifically to sanctions compliance obligations.
There is another important difference with R90: when the clock starts.
Under the usual return process, institutions generally have two banking days to return an entry, with the clock tied to the settlement date. R90 works differently. The two-day window begins when an RDFI determines that the payment has triggered its sanctions compliance obligations.
In practice, this gives institutions more time to investigate a payment before the return deadline begins. For example, an RDFI might initially accept an entry but flag it for further review. If that review later determines that the payment has triggered its sanctions obligation, the two-day window starts at that point—not when the payment originally settled.
“This isn’t unprecedented,” Marsh said. “There is a return reason code R23 that is used when an RDFI is notified by a Receiver that the Receiver has declined a credit entry, and that’s when the clock starts. This is similar in that respect: the clock is still two banking days, but it starts at a specific point in time.”
A Long Lead Time
The R90 change exemplifies Nacha’s efforts to make the ACH Network more efficient and secure for banks and their customers—but banks must still do their share. That is precisely why 2028 may deserve attention now.
“It’s back to the theme of providing more accurate data,” Danner said. “It gives Originators better, clear information about what actions they’re going to need to take when a payment’s returned. This can affect the screening workflows and exceptions handling and communication and compliance procedures for OFAC compliance and risk monitoring. It’s important for ACH Operators and FIs to prepare to implement this new code.”
The temptation may be to focus on the September changes and worry about R90 later. But the institutions that wait until 2028 is around the corner may find that the hardest part was never the code itself; it was everything that had to change around it.
“The reason they need to start paying attention to it now is that developing a new return reason code requires programming and it requires technical development—and that could have a long lead time,” Marsh said. “Budget planning, IT planning, business requirement documentation, all those steps necessitate a longer lead time than simply a change in practice. Standing up the code is why it has a long lead time.”
The broader lesson is that ACH modernization is not happening in a single leap. It’s unfolding through a series or targeted Rule changes, each designed to improve clarity, speed, security, or efficiency.








