Skip to main content

SUMMER SAVINGS 90% OFF QuickBooks for 3 months* Ends 8/27

Buy now
Switch to QuickBooks and 70% off for 3 Months
May 28, 2026
Question

Are your clients ready for the NACHA June 22 ACH vendor verification changes?

  • May 28, 2026
  • 1 reply
  • 67 views

Hey everyone — wanted to flag something that's been coming up with several of my clients lately and curious if others are seeing the same thing.

NACHA's updated rules go live June 22, and they raise the bar for verifying vendor bank account details before sending ACH payments. Basically, if a client sends an ACH payment to an unverified vendor account and it turns out to be fraudulent (account takeover, fake vendor, etc.), they have significantly less protection under the new rules.

A few of my clients have dozens of vendors in QuickBooks with bank details that were never formally verified — just entered from an email or phone call years ago. That's a real exposure right now.

I've been running quick vendor bank account verification checks before the deadline. Curious what workflows others are using:

  1. Are you proactively telling clients about the June 22 changes?
  2. Do you have a process for verifying vendor bank details in bulk?
  3. Has anyone had a client get hit with ACH vendor fraud already?

Would love to hear how others are handling this — feels like a ticking clock with 25 days left.

1 reply

OTI-Labs
New Member
October 4, 2026

Worth being precise about what the rule asks for, because it's easy to over-read. Phase 2 (in effect since June 22) requires every business that originates ACH payments to have risk-based processes reasonably intended to catch entries that are unauthorized or made under false pretenses (vendor impersonation, business email compromise, payroll diversion), and to review them at least once a year. It doesn't prescribe a specific verification method, or require re-verifying every existing vendor.

For most small clients the practical version is:

  1. Treat any request to change a payee's bank details as unverified until it's confirmed by a call to a number already on file, not one from the request.
  2. Have a second person approve the change before the first payment goes to the new details.
  3. Log who verified, how and when. That's the kind of record banks are asking customers for.
  4. Review the process once a year.

For the existing vendor list, a one-off pass ordered by payment size is more realistic than verifying everyone at once.

On spotting the fake requests themselves: most come from a lookalike of the vendor's domain that was registered days before the email, or have a Reply-To that points somewhere else. Checking how old the sender's domain is (any WHOIS lookup shows the registration date) takes a minute, but it doesn't replace the call-back.