ACH
The Automated Clearing House (ACH) is the foundational bank-to-bank electronic payment network in the United States. It processes tens of billions of transactions annually, powering corporate payroll, business-to-business supplier settlements, recurring subscription debits, and consumer utility payments.
ACH is structurally inexpensive, batch-oriented, and asynchronous. Unlike card payments, where an issuing bank approves or declines a charge before merchandise leaves the warehouse, an ACH pull debit has no upfront reservation of funds. You submit a batch file to your bank, the network clears the transactions on a deferred schedule, and you learn about failures days or even weeks later.
All procedures, return timeframes, and validation rules discussed here are governed by Nacha, the rule-making body for the US ACH network. While European bank rails like SEPA and UK Bacs share the same underlying batch mechanics, their specific legal frameworks, return windows, and dispute rights differ significantly.
Network Topology and Directionality
ACH transactions move through a strict hub-and-spoke institutional hierarchy. Two central ACH operators handle file processing and interbank clearing across the United States: the Federal Reserve Banks (FedACH) and The Clearing House (EPN).
Every transaction involves two distinct financial institutions:
- The ODFI (Originating Depository Financial Institution): the bank that packages payment files from the merchant or sender and transmits them into the ACH operator network.
- The RDFI (Receiving Depository Financial Institution): the bank holding the customer's or recipient's account, responsible for posting debits and credits.
Transactions flow as either credits or debits:
- ACH Credit (Push): The originator instructs their bank to send money out to the recipient's account. This is how employers disburse salaries and companies pay trade invoices. Funds cannot be clawed back for insufficient funds because the sending bank verifies available liquidity prior to origination.
- ACH Debit (Pull): The originator instructs the receiving bank to draw funds from a customer's account. This is the standard rail for utility billing, loan repayments, and recurring consumer subscriptions.
The Operational Risk: Negative Confirmation
The defining operational trap of ACH debits is the negative confirmation model: the network never transmits a success message.
When a card payment succeeds, the gateway returns a clear 200 OK with an authorization code within hundreds of milliseconds. When an ACH debit succeeds, the network remains completely silent. An originator only hears back from the RDFI when something goes wrong.
This makes fulfillment timing a fundamental business risk. If an e-commerce platform treats an ACH debit as settled the instant the file is uploaded, goods will be shipped before the RDFI has even processed the ledger entry. Three business days later, the RDFI may return the debit for non-sufficient funds, leaving the merchant with an unrecoverable loss.
| Operational Dimension | Card Rail | ACH Debit Rail |
|---|---|---|
| Balance Verification | Real-time authorization check against account or line | No real-time check; balance inspected only when RDFI posts file |
| Failure Notification | Synchronous (within 1 to 2 seconds) | Asynchronous via return file (2 banking days to 60 calendar days) |
| Transaction Cost | Percentage-based interchange plus network fee (1.5% - 3%+) | Low flat fee per item (typically $0.05 to $0.30) |
| Settlement Finality | High after clearing; subject to formal chargeback rules | Low initially; exposed to technical returns and consumer disputes |
| Dispute Reversal Right | Issuer representment and arbitration framework | Strict consumer protection rules; no representment mechanism |
| Settlement Velocity | 1 to 3 banking days | 1 to 2 banking days (or Same Day ACH windows) |
Return Codes and Operational Windows
When an RDFI cannot post an entry, it generates an ACH return file containing a standardized three-character code (such as R01 or R10). The rules govern how quickly an RDFI must transmit that return back to the ODFI, creating two critical operational clocks.
The Two-Day Administrative Window
For administrative, technical, and liquidity failures, the RDFI must transmit the return so that it is available to the ODFI no later than the opening of business on the second banking day following the settlement date:
- R01 (Insufficient Funds): The account did not have adequate available funds when the debit was posted. Can be retried up to two times within 180 days.
- R02 (Account Closed): The customer closed the account. Retrying is prohibited; updated account details are required.
- R03 (No Account / Unable to Locate): The account number does not match any ledger entry at the RDFI.
- R04 (Invalid Account Number Structure): The account number fails digit checks or formatting rules.
- R09 (Uncollected Funds): The ledger balance is sufficient, but funds are held pending other check or clearing settlements.
- R29 (Corporate Customer Untrusted / Unauthorized): A business account holder notifies their bank that a corporate debit was unauthorized. Business accounts are held to the strict two-day return deadline.
The 60-Day Consumer Protection Window
Federal regulations (Regulation E) and Nacha rules grant individual consumers an extended window to challenge unauthorized debits. If a consumer submits a formal Written Statement of Unauthorized Debit (WSUD) to their bank, the RDFI can transmit a return up to 60 calendar days from the transaction's original settlement date:
- R05 (Unauthorized Debit to Consumer Account Using Corporate SEC Code): A consumer account was debited using a corporate entry format without authorization.
- R07 (Authorization Revoked): The customer formally revoked billing permission with the merchant prior to the debit being originated.
- R10 (Customer Advises Originator is Not Authorized): The consumer claims they never authorized the merchant to initiate the debit.
- R11 (Customer Advises Entry Not in Accordance with the Terms of Authorization): The debit occurred on the wrong date, for an incorrect amount, or improperly followed a canceled schedule. (Nacha repurposed
R11in 2020 specifically to separate authorization errors from outright unauthorized claims).
Because consumer returns have an open 60-day window, originators must retain verifiable proof of authorization (signed agreements, voice recordings, or digital timestamp logs) for a minimum of two years.
| Return Code | Description | Transmission Deadline | Allowable Next Action |
|---|---|---|---|
| R01 | Insufficient funds | 2 banking days | Retry up to twice after waiting 1-2 banking days |
| R02 | Account closed | 2 banking days | Do not retry; collect new payment instrument |
| R03 | No account found | 2 banking days | Do not retry; verify bank routing and account data |
| R04 | Invalid account format | 2 banking days | Correct formatting errors before re-originating |
| R05 | Corporate code on consumer account | 60 calendar days | Halt debits; correct SEC code and re-authorize |
| R07 | Authorization revoked | 60 calendar days | Halt all debits immediately; obtain fresh mandate |
| R09 | Uncollected funds | 2 banking days | Retry after allowing pending checks to clear |
| R10 | Customer disputes authorization | 60 calendar days | Halt debits; review audit trails and customer records |
| R11 | Terms of debit incorrect | 60 calendar days | Correct debit schedule or amount before re-initiating |
| R29 | Corporate debit unauthorized | 2 banking days | Halt debits; contact corporate treasury department |
Notifications of Change (NOC)
Not every asynchronous message indicates a failed payment. When an RDFI recognizes that an account or routing number has changed—often due to bank mergers, branch consolidations, or account restructuring—it may choose to post the payment anyway and send a NOC (Notification of Change, prefixed with C codes like C01 or C02).
Under Nacha rules, an originator is legally obligated to update their internal customer records with the corrected account or routing details within six banking days of receiving the NOC, or prior to originating the next transaction—whichever is later. Ignoring NOCs results in administrative fines and eventual transaction rejection.
Standard Entry Class (SEC) Codes and Timing
Every ACH batch header contains a three-letter SEC code that specifies the legal and operational context under which authorization was captured:
- PPD (Prearranged Payment and Deposit): Used for consumer recurring debits and direct deposit payroll. Requires written authorization or a cryptographically signed electronic consent.
- CCD (Corporate Credit or Debit): Used exclusively for business-to-business payments. CCD entries do not provide consumer 60-day dispute rights; RDFIs and originators are bound by corporate banking agreements.
- WEB (Internet-Initiated Entry): Used when a consumer authorizes a payment or sets up recurring billing over the internet or mobile app. Nacha mandates that WEB originators perform commercially reasonable fraudulent transaction detection, including validating account existence and ownership prior to the first debit.
- TEL (Telephone-Initiated Entry): Used when consumer consent is captured over an oral telephone call, requiring specific verbal disclosure recordings.
Each ACH file also distinguishes between two critical dates:
- Effective date: The date chosen by the originator indicating when the transaction is intended to post and settle.
- Settlement date: The actual date on which funds are transferred between the ODFI and RDFI through the Federal Reserve or Clearing House ledger. If an originator submits a file after daily clearing cutoffs, the operator adjusts the settlement date forward.
Inspect the three-character return code before triggering any automated workflow.
- If the return code is R01 or R09, retry only after waiting at least one full banking day. Never retry more than twice.
- If the return code is R02, R03, or R04, cancel the billing schedule immediately and request updated banking information from the customer.
- If the return code is R05, R07, R10, R11, or R29, immediately cease all origination against the account. Never retry an unauthorized or revoked debit without obtaining a newly executed authorization.
- If an RDFI delivers a Notification of Change (NOC), update your database records within six banking days before originating subsequent entries.
Nacha Return Rate Monitoring
To protect the integrity of the network, Nacha actively monitors return thresholds across every originator. An originator whose return volume breaches prescribed caps faces compliance enforcement, mandatory remediation audits, and revocation of ACH origination privileges:
- Unauthorized Return Rate (R05, R07, R10, R11, R29): Must stay below 0.5% of originating volume over any 60-day evaluation period. Because this threshold is so strict, any spike in fraud or unclear merchant descriptors can quickly shut down a merchant's origination line.
- Administrative Return Rate (R02, R03, R04): Must stay below 3.0%. This monitors the hygiene of your account collection pipelines; submitting outdated or mistyped account numbers will rapidly breach this ceiling.
- Overall Return Rate (All codes combined): Monitored at an informal benchmark of 15.0%, primarily policing excessive NSF retries.
Integrating bank account validation services (such as micro-deposits, instant open banking credentials via API, or database ownership verification) prior to originating the first WEB debit is the primary defense against administrative and unauthorized return penalties.
Terms introduced
- ODFI / RDFI: Originating Depository Financial Institution and Receiving Depository Financial Institution; the respective originating and receiving banks in an ACH transaction.
- Return: an asynchronous message sent by an RDFI rejecting an ACH entry and detailing the operational reason code.
- NOC: Notification of Change; a non-rejection record instructing an originator to correct routing or account numbers before the next transaction.
- SEC code: Standard Entry Class code; a three-letter identifier specifying the authorization framework, customer category, and transmission channel of an ACH entry.
- Effective date: the calendar date specified by the originator on which a payment is intended to settle and post to the recipient account.