The National Automated Clearing House Association (Nacha) has announced revised fraud monitoring rules for financial institutions, aiming to strengthen the detection and prevention of fraudulent transactions within the ACH network. Under the proposed 2026 rules, banks and other financial institutions must now demonstrate that their fraud monitoring practices are 'reasonably intended' to identify fraud, moving beyond the previous standard of merely being 'commercially reasonable.' This shift emphasizes the effectiveness of fraud detection outcomes rather than adherence to industry benchmarks, requiring institutions to take proactive measures against suspicious activity.
Devon Marsh, Nacha's managing director for ACH network rules and risk management, clarified that simply maintaining routine or low-value monitoring is insufficient, and inaction on fraudulent transactions will not be tolerated. Institutions must be able to justify their monitoring processes to auditors and compliance officers, ensuring that their efforts are outcome-focused and responsive to evolving fraud tactics. The new rules are designed to raise the bar for fraud risk management across the ACH ecosystem and hold financial institutions more accountable for preventing financial crime.

See the actors and campaigns active against you right now.
1 event from the most recent confirmed update back to the earliest known activity.
Nacha revised its fraud monitoring rules for financial institutions, according to the referenced reports. No additional details or a more specific event date are provided in the source content.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.