Skip to main content

ACH

The Automated Clearing House (ACH) is the foundational bank-to-bank electronic payment network in the United States. It processes tens of billions of transactions annually, powering corporate payroll, business-to-business supplier settlements, recurring subscription debits, and consumer utility payments.

ACH is structurally inexpensive, batch-oriented, and asynchronous. Unlike card payments, where an issuing bank approves or declines a charge before merchandise leaves the warehouse, an ACH pull debit has no upfront reservation of funds. You submit a batch file to your bank, the network clears the transactions on a deferred schedule, and you learn about failures days or even weeks later.

All procedures, return timeframes, and validation rules discussed here are governed by Nacha, the rule-making body for the US ACH network. While European bank rails like SEPA and UK Bacs share the same underlying batch mechanics, their specific legal frameworks, return windows, and dispute rights differ significantly.

Network Topology and Directionality

ACH transactions move through a strict hub-and-spoke institutional hierarchy. Two central ACH operators handle file processing and interbank clearing across the United States: the Federal Reserve Banks (FedACH) and The Clearing House (EPN).

Every transaction involves two distinct financial institutions:

  • The ODFI (Originating Depository Financial Institution): the bank that packages payment files from the merchant or sender and transmits them into the ACH operator network.
  • The RDFI (Receiving Depository Financial Institution): the bank holding the customer's or recipient's account, responsible for posting debits and credits.

Transactions flow as either credits or debits:

  • ACH Credit (Push): The originator instructs their bank to send money out to the recipient's account. This is how employers disburse salaries and companies pay trade invoices. Funds cannot be clawed back for insufficient funds because the sending bank verifies available liquidity prior to origination.
  • ACH Debit (Pull): The originator instructs the receiving bank to draw funds from a customer's account. This is the standard rail for utility billing, loan repayments, and recurring consumer subscriptions.

The Operational Risk: Negative Confirmation

The defining operational trap of ACH debits is the negative confirmation model: the network never transmits a success message.

When a card payment succeeds, the gateway returns a clear 200 OK with an authorization code within hundreds of milliseconds. When an ACH debit succeeds, the network remains completely silent. An originator only hears back from the RDFI when something goes wrong.

This makes fulfillment timing a fundamental business risk. If an e-commerce platform treats an ACH debit as settled the instant the file is uploaded, goods will be shipped before the RDFI has even processed the ledger entry. Three business days later, the RDFI may return the debit for non-sufficient funds, leaving the merchant with an unrecoverable loss.

Operational DimensionCard RailACH Debit Rail
Balance VerificationReal-time authorization check against account or lineNo real-time check; balance inspected only when RDFI posts file
Failure NotificationSynchronous (within 1 to 2 seconds)Asynchronous via return file (2 banking days to 60 calendar days)
Transaction CostPercentage-based interchange plus network fee (1.5% - 3%+)Low flat fee per item (typically $0.05 to $0.30)
Settlement FinalityHigh after clearing; subject to formal chargeback rulesLow initially; exposed to technical returns and consumer disputes
Dispute Reversal RightIssuer representment and arbitration frameworkStrict consumer protection rules; no representment mechanism
Settlement Velocity1 to 3 banking days1 to 2 banking days (or Same Day ACH windows)

Return Codes and Operational Windows

When an RDFI cannot post an entry, it generates an ACH return file containing a standardized three-character code (such as R01 or R10). The rules govern how quickly an RDFI must transmit that return back to the ODFI, creating two critical operational clocks.

The Two-Day Administrative Window

For administrative, technical, and liquidity failures, the RDFI must transmit the return so that it is available to the ODFI no later than the opening of business on the second banking day following the settlement date:

  • R01 (Insufficient Funds): The account did not have adequate available funds when the debit was posted. Can be retried up to two times within 180 days.
  • R02 (Account Closed): The customer closed the account. Retrying is prohibited; updated account details are required.
  • R03 (No Account / Unable to Locate): The account number does not match any ledger entry at the RDFI.
  • R04 (Invalid Account Number Structure): The account number fails digit checks or formatting rules.
  • R09 (Uncollected Funds): The ledger balance is sufficient, but funds are held pending other check or clearing settlements.
  • R29 (Corporate Customer Untrusted / Unauthorized): A business account holder notifies their bank that a corporate debit was unauthorized. Business accounts are held to the strict two-day return deadline.

The 60-Day Consumer Protection Window

Federal regulations (Regulation E) and Nacha rules grant individual consumers an extended window to challenge unauthorized debits. If a consumer submits a formal Written Statement of Unauthorized Debit (WSUD) to their bank, the RDFI can transmit a return up to 60 calendar days from the transaction's original settlement date:

  • R05 (Unauthorized Debit to Consumer Account Using Corporate SEC Code): A consumer account was debited using a corporate entry format without authorization.
  • R07 (Authorization Revoked): The customer formally revoked billing permission with the merchant prior to the debit being originated.
  • R10 (Customer Advises Originator is Not Authorized): The consumer claims they never authorized the merchant to initiate the debit.
  • R11 (Customer Advises Entry Not in Accordance with the Terms of Authorization): The debit occurred on the wrong date, for an incorrect amount, or improperly followed a canceled schedule. (Nacha repurposed R11 in 2020 specifically to separate authorization errors from outright unauthorized claims).

Because consumer returns have an open 60-day window, originators must retain verifiable proof of authorization (signed agreements, voice recordings, or digital timestamp logs) for a minimum of two years.

Return CodeDescriptionTransmission DeadlineAllowable Next Action
R01Insufficient funds2 banking daysRetry up to twice after waiting 1-2 banking days
R02Account closed2 banking daysDo not retry; collect new payment instrument
R03No account found2 banking daysDo not retry; verify bank routing and account data
R04Invalid account format2 banking daysCorrect formatting errors before re-originating
R05Corporate code on consumer account60 calendar daysHalt debits; correct SEC code and re-authorize
R07Authorization revoked60 calendar daysHalt all debits immediately; obtain fresh mandate
R09Uncollected funds2 banking daysRetry after allowing pending checks to clear
R10Customer disputes authorization60 calendar daysHalt debits; review audit trails and customer records
R11Terms of debit incorrect60 calendar daysCorrect debit schedule or amount before re-initiating
R29Corporate debit unauthorized2 banking daysHalt debits; contact corporate treasury department

Notifications of Change (NOC)

Not every asynchronous message indicates a failed payment. When an RDFI recognizes that an account or routing number has changed—often due to bank mergers, branch consolidations, or account restructuring—it may choose to post the payment anyway and send a NOC (Notification of Change, prefixed with C codes like C01 or C02).

Under Nacha rules, an originator is legally obligated to update their internal customer records with the corrected account or routing details within six banking days of receiving the NOC, or prior to originating the next transaction—whichever is later. Ignoring NOCs results in administrative fines and eventual transaction rejection.

Standard Entry Class (SEC) Codes and Timing

Every ACH batch header contains a three-letter SEC code that specifies the legal and operational context under which authorization was captured:

  • PPD (Prearranged Payment and Deposit): Used for consumer recurring debits and direct deposit payroll. Requires written authorization or a cryptographically signed electronic consent.
  • CCD (Corporate Credit or Debit): Used exclusively for business-to-business payments. CCD entries do not provide consumer 60-day dispute rights; RDFIs and originators are bound by corporate banking agreements.
  • WEB (Internet-Initiated Entry): Used when a consumer authorizes a payment or sets up recurring billing over the internet or mobile app. Nacha mandates that WEB originators perform commercially reasonable fraudulent transaction detection, including validating account existence and ownership prior to the first debit.
  • TEL (Telephone-Initiated Entry): Used when consumer consent is captured over an oral telephone call, requiring specific verbal disclosure recordings.

Each ACH file also distinguishes between two critical dates:

  • Effective date: The date chosen by the originator indicating when the transaction is intended to post and settle.
  • Settlement date: The actual date on which funds are transferred between the ODFI and RDFI through the Federal Reserve or Clearing House ledger. If an originator submits a file after daily clearing cutoffs, the operator adjusts the settlement date forward.
Handling ACH returns

Inspect the three-character return code before triggering any automated workflow.

  1. If the return code is R01 or R09, retry only after waiting at least one full banking day. Never retry more than twice.
  2. If the return code is R02, R03, or R04, cancel the billing schedule immediately and request updated banking information from the customer.
  3. If the return code is R05, R07, R10, R11, or R29, immediately cease all origination against the account. Never retry an unauthorized or revoked debit without obtaining a newly executed authorization.
  4. If an RDFI delivers a Notification of Change (NOC), update your database records within six banking days before originating subsequent entries.

Nacha Return Rate Monitoring

To protect the integrity of the network, Nacha actively monitors return thresholds across every originator. An originator whose return volume breaches prescribed caps faces compliance enforcement, mandatory remediation audits, and revocation of ACH origination privileges:

  • Unauthorized Return Rate (R05, R07, R10, R11, R29): Must stay below 0.5% of originating volume over any 60-day evaluation period. Because this threshold is so strict, any spike in fraud or unclear merchant descriptors can quickly shut down a merchant's origination line.
  • Administrative Return Rate (R02, R03, R04): Must stay below 3.0%. This monitors the hygiene of your account collection pipelines; submitting outdated or mistyped account numbers will rapidly breach this ceiling.
  • Overall Return Rate (All codes combined): Monitored at an informal benchmark of 15.0%, primarily policing excessive NSF retries.

Integrating bank account validation services (such as micro-deposits, instant open banking credentials via API, or database ownership verification) prior to originating the first WEB debit is the primary defense against administrative and unauthorized return penalties.

Terms introduced

  • ODFI / RDFI: Originating Depository Financial Institution and Receiving Depository Financial Institution; the respective originating and receiving banks in an ACH transaction.
  • Return: an asynchronous message sent by an RDFI rejecting an ACH entry and detailing the operational reason code.
  • NOC: Notification of Change; a non-rejection record instructing an originator to correct routing or account numbers before the next transaction.
  • SEC code: Standard Entry Class code; a three-letter identifier specifying the authorization framework, customer category, and transmission channel of an ACH entry.
  • Effective date: the calendar date specified by the originator on which a payment is intended to settle and post to the recipient account.

Check your understanding

0 of 4 answered

  1. What is the dangerous assumption when applying card thinking to ACH?
  2. How long can a consumer's bank take to return an ACH debit as unauthorized?
  3. Why does R29 carry a two-banking-day window when R10 gets 60 calendar days, given both mean "not authorized"?
  4. You receive a notification of change (NOC) on an ACH debit that otherwise succeeded. What does it mean?