Know Your Rights and Responsibilities: A Guide to RDFI Obligations Under NACHA
The Basic Obligation: Post or Return, and Do It on Time
An RDFI's foundational obligation is to accept all compliant ACH entries and either post them or return them in a timely manner. That sounds straightforward, but the specifics matter enormously. Under the NACHA Operating Rules, the reliance rules for posting are based on three elements: the account number in the entry, the SEC code, and the settlement date. Not the customer's name. If an entry contains an incorrect name but a valid account number and SEC code, the RDFI is generally obligated to post it.
Timing is equally important. For standard credit entries made available before 5 p.m. local time on the banking day before settlement, funds must be available by 9 a.m. on the settlement day. Same-day credits have their own cutoff times. Debit entries cannot be processed early. Knowing these windows and building them into your processing schedules is a basic but critical operational requirement.
Stop Payments: Consumer vs. Non-Consumer Accounts
Stop payment rules differ significantly depending on whether the account is consumer or non-consumer, and getting the details right matters for both compliance and customer service.
For consumer accounts, a stop payment order must be received at least three banking days before the scheduled debit date to be effective. Verbal stop payment orders are valid but expire after fourteen days unless the customer confirms them in writing. For non-consumer accounts, written stop payment orders remain effective for up to six months unless the customer withdraws them or the entry is returned first.
Re-credit obligations apply when a debit transaction was improperly authorized, improperly executed, or improperly originated. Understanding the grounds for re-credit, including situations where authorization was revoked, where the amount exceeded what was authorized, or where an RCK entry was improperly originated, helps your team respond correctly when customers dispute transactions.
Returns, Extended Returns, and What You Need in Writing
Standard ACH returns must be sent within two banking days of the settlement date. Extended returns for unauthorized consumer debits give the RDFI up to sixty days, but they come with requirements. Before sending an extended return, your institution must obtain a written statement from the consumer that includes specific information: the customer's name and account number, the transaction details, the reason for the return, and a proper signature.
These written statements are not just good practice. They are a warranty requirement. By sending an extended return, your institution is warranting to the ODFI that the return is legitimate and that the written statement exists. NACHA requires those statements to be retained for at least one year from the settlement date of the extended return.
Common return codes your team should know include R05 for unauthorized debits to consumer accounts using corporate SEC codes, R29 for corporate customer advisement that a debit was not authorized, and R17 for questionable entries. When a return is dishonored, your institution has three options within two banking days: accept the dishonor, correct the return using R74, or contest it using return reason code R73.
Notifications of Change: Accuracy Is Your Responsibility
When your institution receives an entry with incorrect account information, you may have an obligation to send a Notification of Change rather than simply returning the entry. NOCs are non-monetary notifications sent to the ODFI and ultimately to the originator to correct errors like wrong account numbers, wrong routing numbers, or incorrect individual identification numbers.
NOCs must generally be transmitted within two banking days. The SEC code for NOC entries is COR, and the addenda type code is 98. Here is the critical accountability piece: when your institution sends a NOC, you are warranting to the ODFI that the corrected information is accurate. If it is not, your institution is liable for any damages that result. Making sure your team verifies the corrected information before transmitting is not optional.
New in 2026: Fraud Monitoring Is Now a Formal Requirement
One of the most significant rule changes in recent years is the formal fraud monitoring requirement for RDFIs that took effect in 2026. RDFIs must now establish risk-based processes for identifying suspicious credit entries, with particular attention to high-dollar transactions and entries that are inconsistent with the typical activity on an account.
This is not just a best practice anymore. It is a NACHA rule requirement. Institutions that do not have documented, risk-based fraud monitoring processes in place are out of compliance. What that monitoring looks like will vary by institution size and risk profile, but it must exist, it must be documented, and it must be capable of flagging entries that warrant further review before funds are made available.
Stay Current, Stay Compliant
NACHA updates its Operating Rules regularly, and keeping your team current on those changes is an ongoing operational necessity. The 2026 fraud monitoring requirements are a good example of how the rules can add meaningful new obligations without much fanfare.
For ACH operations staff and compliance professionals at banks and credit unions, staying sharp on RDFI obligations protects your institution from costly errors and positions your team to respond quickly and correctly when edge cases arise. Explore our ACH Returns and RDFI Requirements on-demand course to make the rules practical and accessible, whether you are preparing for certification or simply keeping your team up to date.