Skip to content
RiskTemplates · The Daily Brief Tuesday, September 15, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Operational Risk

NACHA Just Approved a $10 Million Same Day ACH Limit. Your Fraud Controls Were Built for $1 Million.

NACHA approved a $10 million per-transaction limit for Same Day ACH in April 2026, effective September 2027. That's a 10x increase from the current $1 million cap. Most financial institution fraud controls, velocity limits, and risk-based monitoring thresholds weren't built for that exposure. Here's what needs to change before the September 2027 effective date.

By Rebecca Leung · September 13, 2026 ·
Table of Contents

TL;DR

  • NACHA approved a $10 million per-transaction limit for Same Day ACH on April 27, 2026, effective September 17, 2027 — a 10x increase from the current $1 million cap.
  • The RTP network hit $10 million in June 2025; FedNow hit $10 million in November 2025. ACH is now catching up to the instant rails on transaction size, but with different fraud exposure because of same-day settlement windows and return mechanisms.
  • FBI IC3 data puts BEC losses at $3.046 billion in 2025, with 86% executed via wire or ACH. At $10 million per transaction, a single successful BEC attack on an ACH originator gets proportionally more expensive.
  • Institutions have 17 months to review and update fraud monitoring thresholds, velocity controls, customer agreements, and front-line verification procedures. The window is real; the risk is real.

Same Day ACH launched in 2016 with a $25,000 per-transaction limit. That number was deliberately conservative — NACHA wanted to grow the channel carefully, prove the infrastructure worked, and build financial institution confidence before expanding exposure.

It worked. Same Day ACH volume grew quickly. The limit went to $100,000 in 2020. It went to $1 million in March 2022. And on April 27, 2026, NACHA’s membership voted to raise the per-transaction limit to $10 million, effective September 17, 2027.

That’s a 10x increase from where the limit sits today. And it creates a gap that most financial institution fraud and risk teams have not yet fully mapped: the space between what your current controls were built to handle and what you’ll be exposed to eighteen months from now.

How We Got Here — And Why the Timing Makes Sense

The NACHA rule change didn’t happen in isolation. It’s a response to where the payments landscape has already moved.

The Real-Time Payments network — operated by The Clearing House — raised its transaction limit to $10 million in June 2025. FedNow, the Federal Reserve’s instant payment network, followed in November 2025. For B2B payments at scale, the practical ceiling on what could move through instant or same-day channels has been $10 million for over a year on those rails.

NACHA surveyed its members before the rule change. 117 institutions submitted responses to the request for comment; 87% supported the increase. The business case is straightforward: large-dollar B2B transactions — supplier payments, payroll, insurance settlements, intercompany transfers — often exceed $1 million. Until the rule change, anything over that threshold had to wait for next-day ACH settlement, go through wire, or route to RTP or FedNow if the counterparties were connected. Moving that volume into same-day ACH simplifies settlement mechanics and reduces float for treasury teams.

NACHA estimates the change makes an additional $7 to $8 trillion in annual ACH dollars eligible for same-day settlement. That’s the scale of the opportunity — and it’s the scale of the exposure financial institutions need to plan around.

The Fraud Problem Is Real, and BEC Is the Primary Vector

When you increase the maximum possible loss from a single fraudulent transaction by a factor of ten, the fraud controls protecting that exposure need to scale too. Most of them haven’t been tested at $10 million.

The FBI’s 2025 Internet Crime Report puts Business Email Compromise losses at $3.046 billion for the year — the second-largest category of internet crime loss, and one of the most consistent year-over-year. Critically, 86% of BEC losses are executed via wire transfer or ACH. BEC isn’t a theoretical threat to payment systems; it’s the primary mechanism by which large-dollar fraudulent payments move.

BEC attacks work by impersonating a trusted party — a vendor requesting payment to a new bank account, an executive authorizing an urgent transfer, a bank contact with updated routing instructions — and convincing someone at the victim company to initiate a payment. At $1 million, that’s a severe outcome. At $10 million, the same attack pattern, against the same target institution, against the same business customer, with the same operational controls in place, produces ten times the loss.

The fraud typology doesn’t change with the limit. What changes is the ceiling on what any single successful attack can cost.

What Your Current Controls Were Built For

Most financial institution fraud controls for ACH were designed around the $1 million limit — and more practically, around the realistic volume of business customers who regularly originate payments in the $500,000 to $1 million range. Transaction monitoring rules, velocity thresholds, daily ACH limits for commercial customers, and alert parameters were calibrated to flag anomalies at the level where the real volume has historically lived.

That calibration is about to become outdated.

The specific gaps worth auditing before September 2027:

Transaction monitoring thresholds. Many rules-based monitoring systems flag ACH transactions above a set dollar amount — say, anything over $500,000 gets a manual review, or transactions above $750,000 trigger a callback requirement. If your rules top out at $1 million because that was the hard ceiling, you have no coverage above that threshold once the limit goes live. Transactions in the $1 million to $10 million range will be invisible to controls that weren’t written to look for them.

Velocity limits. Per-day or per-week ACH origination limits for commercial customers are often set based on historical patterns and the old per-transaction ceiling. A business that’s been originating $1 million in same-day ACH daily might request — or attempt — $10 million in a single transaction once the limit is available. If your velocity controls aren’t updated to reflect the new per-transaction maximum, a single fraudulent transaction could blow past your monitoring.

Call-back verification procedures. Many institutions require voice verification for high-value ACH requests — and the trigger point for “high-value” is often set around the old limit. A verification procedure that requires a call-back for payments over $750,000 may need to be revisited for the $1 million to $10 million range. That’s also likely the range where BEC attackers will focus, because it’s large enough to be worth the attack but potentially below the thresholds your controls were set to catch.

Customer agreements and origination limits. Commercial ACH origination agreements specify the maximum transaction and daily limits a business customer can originate. If your standard agreement specifies a $1 million per-transaction limit, your contract terms will need updating before September 2027 — and not every customer will be offered the higher limit without a risk assessment.

The 17-Month Window Is Shorter Than It Looks

September 2027 sounds distant from September 2026. It’s not.

Building effective fraud controls isn’t a documentation exercise — it’s an operational one. You need to identify which commercial customers would realistically use a $10 million same-day ACH limit, assess their current fraud controls and origination patterns, design the monitoring rules and velocity controls appropriate for that exposure, test those rules against historical transaction data, train front-line staff on the new verification procedures, update customer agreements, and then monitor the updated controls after go-live.

That’s a 12 to 18 month project at most institutions, not a weekend sprint. The institutions that start in Q4 2026 will have time to design, test, and validate. The ones that start in Q2 2027 will be scrambling to have anything ready before the effective date — and in payments risk, controls built in a hurry frequently have calibration problems that you don’t find until something goes wrong.

The instant payments fraud control guidance published earlier this year laid out a framework for risk-based approach to high-value instant payments — the same logic applies here. The question isn’t whether to allow $10 million Same Day ACH; it’s how to build the risk appetite, controls, and monitoring structure that lets you offer it safely.

What Good Controls Look Like at $10 Million

A well-designed Same Day ACH fraud control program for the $10 million limit has several components that go beyond extending existing thresholds upward.

Risk-tiered customer access. Not every commercial customer should be eligible for $10 million Same Day ACH on day one. A risk-tiered approach segments customers by their origination history, the nature of their business, their fraud history, and the strength of their internal controls. Customers with high-volume, high-value origination patterns, good fraud records, and established relationships might qualify for the full limit. Newer customers, or those with inconsistent patterns, start with lower limits and earn access over time.

Behavioral baseline per customer. Effective transaction monitoring at this level requires knowing what’s normal for a specific customer, not just what’s normal for the population. A manufacturing company that pays suppliers in $2 to $4 million increments is going to look very different from an insurance carrier processing settlements. Monitoring that flags everything above a universal threshold will generate noise; monitoring that detects deviations from each customer’s own baseline will surface actual anomalies.

Positive pay or confirmation for new payees. The most effective BEC countermeasure is confirming payment instructions through a channel independent of the request. Requiring customers to pre-register high-value payees, or to confirm new payee additions through a separate authenticated channel, prevents the most common BEC attack vector — redirecting a payment to a new account under attacker control. This is already standard practice at many institutions for wire transfers; extending it to same-day ACH at $10 million is the logical step.

ACH return rate monitoring. High return rates on ACH transactions are a leading indicator of fraud or error. NACHA’s Phase 2 fraud monitoring rules — which took effect in June 2026 — require ODFIs and RDFIs to monitor for fraudulent or erroneous ACH entries. At $10 million transaction sizes, the financial impact of unauthorized returns is proportionally larger, making return rate monitoring a priority KRI for any institution offering the higher limit.

KRIs that track the new exposure. Once the $10 million limit is live, risk management needs the right metrics to detect emerging problems early. The key risk indicators worth tracking include: volume and dollar amount of Same Day ACH transactions in the $1 million to $10 million range by customer segment; number of same-day transactions above $5 million per day; unauthorized return rate on high-value same-day items; number of payment instruction change requests for high-value payees; and number of verification callbacks initiated versus completed. These metrics create an early warning system for control failures before they produce material losses.

What NACHA’s Rule Change Doesn’t Cover

The NACHA limit increase is a network rule, not a comprehensive risk management framework. What institutions choose to offer their customers, and what controls they put around that offer, is their own decision.

NACHA’s Phase 2 fraud monitoring rules require ODFI and RDFI monitoring for fraudulent or erroneous entries — but the rules don’t specify what your transaction monitoring thresholds should be, how you should tier customer access, or what your verification procedures should look like. Those are institution-level decisions, and examiners will evaluate them as operational risk management questions.

OCC and FFIEC third-party risk guidance also applies to any ACH network dependencies. If your Same Day ACH origination runs through a third-party origination platform, that platform’s controls are part of your control environment — and examiners will ask about them. The interagency TPRM guidance from 2023 is explicit that institutions are responsible for the controls their critical third parties implement on their behalf.

So What? The Practitioner To-Do List

You have 17 months. Here’s how to use them:

  1. Map your current exposure. Pull your last six months of Same Day ACH origination data. Identify customers originating $500,000 or more in a single same-day transaction. That’s your likely early adopter population for the $10 million limit — and your highest-risk segment.

  2. Audit your monitoring rules. Find every transaction monitoring rule, velocity limit, and alert threshold that has a dollar ceiling tied to the current $1 million limit. Document the gap between your current coverage ceiling and $10 million. That gap is your first control upgrade priority.

  3. Review your verification procedures. Map your current callback and payee verification procedures. Identify the dollar triggers. Decide whether those thresholds need to be extended or whether you’ll create new procedures specific to the $1 million to $10 million range.

  4. Update customer agreements. Start the legal review of your commercial ACH origination agreements. Not every customer needs immediate access to $10 million; most will need updated agreement language before they can originate at the new limit. Start that contract review now, before September 2027 makes it urgent.

  5. Build KRIs for the new limit. A risk indicator library calibrated for $10 million Same Day ACH exposure belongs in your operational risk monitoring before go-live, not after. The KRI Library & Key Risk Indicators Template includes payment risk indicators you can adapt for high-value ACH monitoring — build them into your KRI framework now so you’re not starting from scratch in 2027.

  6. Run a tabletop BEC scenario. Simulate a BEC attack against a commercial customer attempting to redirect a $7 million same-day ACH payment. Walk through detection, escalation, and response. The gaps your tabletop exposes are the controls you need to build.

The institutions that treat the September 2027 effective date as a hard deadline — and work backward from it — will have tested, validated fraud controls when the limit goes live. The ones that treat it as distant will be implementing controls in parallel with go-live, which is exactly when you discover the edge cases you didn’t anticipate.


External sources: NACHA Same Day ACH $10 million limit announcement | Payments Dive coverage of the rule change | iPiD analysis of fraud risk at $10 million | FBI IC3 2025 Annual Report

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

When does the $10 million Same Day ACH limit take effect?
NACHA approved the $10 million per-transaction limit for Same Day ACH on April 27, 2026. The effective date is September 17, 2027, giving financial institutions approximately 17 months from approval to update their fraud monitoring, velocity controls, operational procedures, and customer agreements. Institutions that begin planning now can validate controls before the limit goes live — those that wait will find themselves scrambling.
What was the previous Same Day ACH transaction limit?
The Same Day ACH limit has been raised three times. It launched at $25,000, increased to $100,000 in 2020, and increased again to $1 million in March 2022. The $10 million limit approved in April 2026 is a 10x increase from the current cap and represents the largest single Same Day ACH limit expansion in the network's history.
How does the new $10 million Same Day ACH limit compare to RTP and FedNow?
The Real-Time Payments (RTP) network raised its transaction limit to $10 million in June 2025. FedNow raised its limit to $10 million in November 2025. The NACHA Same Day ACH increase — effective September 2027 — brings ACH into parity with the instant payment rails on transaction size. The key difference is that ACH retains same-day settlement windows rather than immediate finality, and ACH includes return rights that instant payments typically do not.
What fraud risks does the $10 million Same Day ACH limit create?
The primary risk is Business Email Compromise (BEC). BEC attackers impersonate vendors, executives, or banks to redirect large payments — and according to the FBI IC3 2025 Annual Report, 86% of BEC losses are executed via wire transfer or ACH. At $1 million, ACH was already a high-value target. At $10 million, a single successful BEC attack could cause 10 times the damage. Financial institutions need to evaluate whether their current transaction monitoring rules, velocity limits, and call-back verification procedures are calibrated for $10 million exposures.
What operational controls should institutions update before September 2027?
Institutions should review and update: (1) transaction monitoring thresholds and alert rules for Same Day ACH; (2) velocity limits — daily and per-transaction — for business customers most likely to use the higher limit; (3) call-back verification procedures for high-value ACH originators; (4) customer agreements and origination limits; (5) front-line training on BEC red flags for large ACH requests; and (6) KRIs that track large-dollar Same Day ACH volume, return rates, and exception patterns. The 17-month runway is an opportunity to build and test these controls before the limit goes live.
Does the $10 million Same Day ACH limit apply to all transaction types?
The $10 million limit applies to Same Day ACH transactions. Standard ACH transactions (next-day and two-day) have a separate limit structure. Institutions should also note that NACHA's Phase 2 ACH fraud monitoring rules, which took effect in June 2026, require RDFIs and ODFIs to monitor for fraudulent or erroneous entries — and those monitoring requirements become more consequential at $10 million transaction sizes. NACHA's rules operate alongside, not instead of, institution-level controls.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.