The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/The Treasury Update Podcast
The Treasury Update Podcast artwork

ACH Rule Changes for 2026: What Treasury Needs to Know

The Treasury Update Podcast · 2026-07-06 · 11 min

0:00--:--

Key moments - from our scoring

Substance score

65 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality11 / 20
Guest Caliber15 / 20
Specificity & Evidence13 / 20
Conversational Craft12 / 20

Craig Jeffrey, managing partner at Strategic Treasurer, outlines the two most impactful 2026 ACH rules for corporate treasury teams. The Company ID rule requires specific text identifiers for payroll and web entry class code transactions and has been in effect since March - any company not yet compliant needs immediate remediation. The risk-based fraud monitoring requirement, due June 22, 2026, applies to all non-consumer ACH originators and represents a major expansion from previous limits on web debits and microentries. This requires written policies, an organization-specific ACH fraud risk assessment by payment type, operational monitoring with exception handling, and documented annual reviews of effectiveness. Jeffrey emphasizes the principle of "appropriate to risk" - controls must be proportional to exposure, not absent regardless of volume. Small originators might use simpler, manual processes, while high-volume entities like insurance companies processing 10 million ACH transactions monthly need sophisticated automation and systematic review. He urges treasurers to act immediately on Company ID compliance and begin planning risk frameworks, either internally or with external assistance, framing the treasurer as the "superintendent of payments" responsible for ensuring all compliance activities are completed and documented.

Key takeaways

  • →The Company ID rule requiring payroll or web purchase identifiers has been effective since March 2025, and any company still non-compliant faces penalties and must remediate immediately.
  • →Risk-based fraud monitoring is due June 22, 2026, for companies sending 6 million or more ACH transactions annually, requiring written policies, organization-specific fraud risk assessments, and documented annual reviews.
  • →Fraud risk assessments must identify vulnerability by payment type (payroll, corporate payments, consumer payments, debits) and be customized to your organization, not copied from templates.
  • →Controls must be proportional to risk exposure - companies don't need dollar-level controls for quarter-level risk, but controls cannot be absent regardless of transaction volume.
  • →Treasurers should coordinate across departments to verify compliance status, collect assessment artifacts, and determine whether to build capabilities internally or engage external resources before the June 2026 deadline.

Guests

Craig Jeffrey

Topics in this episode

PCI DSSBusiness email compromiseACH rule changes 2026Company ID specificationsRisk-based fraud monitoringACH fraud risk assessmentUnauthorized ACH returnsPrinciple of appropriate to riskACH compliance frameworkSwift CSP

Questions this episode answers

What are the two most important ACH rule changes for corporate treasury in 2026?

The Company ID rule (effective since March) requiring specific text identifiers for payroll and web purchases, and the risk-based fraud monitoring requirement (due June 22, 2026) that applies to all non-consumer ACH originators and requires written policies, fraud risk assessments, operational monitoring, and annual reviews.

Who is required to comply with the 2026 ACH rules?

Non-consumer entities of any size that originate ACH payments - both inbound and outbound. The risk-based fraud monitoring applies to all such originators, expanding requirements beyond the previous limits on web debits and microentries only.

What does the ACH fraud risk assessment need to include?

It must be specific to your organization, identify where ACH fraud risk is most likely by payment type (payroll, corporate payments, consumer payments, debits), and be supported by documented annual reviews showing whether the policy remains effective against evolving fraud tactics.

What does 'appropriate to risk' mean in the context of ACH controls?

Controls must be proportional to your level of exposure and transaction volume - companies with low volume and manual processes may have simpler controls, while high-volume originators like insurance companies need sophisticated automation and systematic review, but no organization can have absent controls.

When is the June 2026 deadline specifically, and who does it apply to?

June 22, 2026 is the deadline for companies sending 6 million or more ACH transactions per year to have their risk-based fraud monitoring framework in place, though all ACH originators ultimately need to comply.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode delivers concrete regulatory requirements and implementation guidance that a treasury practitioner would genuinely need, such as company ID specifications, risk assessment components, and the proportionality principle. However, it relies heavily on explanation of compliance mechanics rather than novel insights into *why* these rules matter or how to operationalize them effectively, and includes filler moments ('this is a good topic', throat-clearing transitions).

You have to monitor your ACH activity for unauthorized returns and authorized under false pretenses items
Your fraud risk assessment has to be specific to your organization. It has to identify where the ACH fraud risk is most likely to happen, by payment type

Originality

11 / 20

The content faithfully explains published regulatory requirements but offers minimal original thinking or contrarian perspective. Craig does articulate the proportionality principle clearly, but the overall framing - compliance rules, checklists, risk frameworks - follows standard regulatory podcast templates without fresh angles or unexpected insights.

Just like card had PCI DSS about 20 years ago to protect card information, uh, that expanded to Swift messaging with Swift csp
the treasurer is the superintendent of payments, not doing everything, but making sure everything happens

Guest Caliber

15 / 20

Craig Jeffrey is identified as managing partner of Strategic Treasurer, suggesting operational and advisory experience in treasury compliance. He speaks with authority about implementation and demonstrates practical knowledge of how rules apply across organization sizes and payment types. However, the transcript provides limited evidence of his direct operational experience running a treasury function at scale.

I'm Craig Jeffrey, our managing partner
If someone has extremely low volume, uh, maybe has limits set on things, while their, their elements of risk management might be a little bit more manual, a little simpler, uh, someone who's doing, let's say an insurance company is doing 10, uh, million ach is a month, they're going to have a lot more automation

Specificity & Evidence

13 / 20

The episode names specific rules (company ID, risk-based fraud monitoring), references a concrete deadline (June 22nd), and provides threshold guidance (6 million ACH transactions annually). However, it lacks named company examples, actual penalty amounts, detailed case studies, or quantified impacts of non-compliance. The guidance is prescriptive but largely abstract in application.

June 22nd where you have to have the, your risk based framework
sending things without that, you're not in compliance. There's, you know, the potential for all the penalties

Conversational Craft

12 / 20

Lee asks clarifying follow-up questions ('Who do these rules apply to and why is that important?', 'can you talk a little bit about the principle of appropriate to risk') and invites Craig to explain practical implications. However, questions tend to be surface-level invitations to explain rather than challenging or probing deeper; there is no productive disagreement or pressure testing of claims, and some transitions feel scripted.

Okay, a little bit more specifics. Who do these rules apply to and why is that important?
can you talk a little bit about the principle of appropriate to risk and what does that mean?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C81%
  • Speaker B14%
  • Speaker D3%
  • Speaker A2%

Most-used words

risk18fraud11treasury10corporate8payment7based7monitoring7started7podcast6treasurer6elements6payments6assessment6strategic5rules5payroll5

Episode notes

In this episode, Lee Patton speaks with Craig Jeffery of Strategic Treasurer about the 2026 ACH rule changes and what they mean for corporate treasury teams. They discuss the new company ID requirements, expanded risk-based fraud monitoring requirements, and which organizations must comply. Craig explains the importance of ACH fraud risk assessments, written policies and procedures, annual reviews, exception handling, and maintaining documentation that demonstrates compliance. The discussion also explores the concept of risk-proportionate controls, practical steps for organizations that have not yet completed compliance efforts, and why treasury should act as the coordinator for ACH payment governance across the organization. Links Mentioned: ACH Rules Overview: Company Websites : Strategic Treasurer:

Full transcript

11 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Treasury Update podcast presented by Strategic Treasurer, your source for interesting treasury news, analysis and insights in your car, at the gym or wherever you decide to tune in.

Speaker B: So welcome to today's Treasury Update podcast. I'm Lee Patton of Strategic Treasurer. Joining me today is Craig Jeffrey, our managing partner and today's topic is payment compliance achievement 2026 rules. Craig, thank you for joining us.

Speaker C: Hey, this is a good topic. Um, I'm glad to chat with you about this.

Speaker B: This is great. So let's start it off. Craig, what 2026 ACH rules are of particular importance to corporate treasury departments?

Speaker C: Yeah, so I like how you narrowed it down to what's of particular importance to corporate treasury departments. Two rules are the most important ones. One is the company id. There's some specifications on what you include in the company ID related to payroll or web purchases or the web standard entry class code. You uh, have to include that information, some text uh, in the company ID that you send to the bank. Now that rule has been in place since March, uh, that it was effective. Um, if you haven't done it you still need to do that. The second, um, for most companies it's due by during June is the risk based fraud monitoring. So those two elements are the key uh, elements for corporate treasury for the 2026 rule changes.

Speaker B: Okay, a little bit more specifics. Who do these rules apply to and

Speaker C: why is that important? It's they apply to and the purpose of this podcast is to talk about the corporate, uh, treasury or corporate people who are doing payments, uh, as opposed to consumers. So it's really non consumer entities. Anybody who originates ACH payments of any kind. The second rule that I mentioned is applicable to everyone though the risk based fraud monitoring, every non consumer. So the questions might come up, what if you have a third party making payments on your behalf, uh, or um, some other element like what is the requirement that you still have? Uh, the other aspect uh, of why this is important is this represents a significant change for corporate originators. So anybody who's initiating a uh, payment, an inbound or an outbound payment via the ACH network, if you're a non consumer, you're a company, a business. This expands requirements to all originators for all payment types. So the risk based monitoring um, applies essentially to everyone. Uh, it was previously limited to web debits and microentries where there was some risk based monitoring. So now there's this idea of the whole network has to have a proportional way of managing risks.

Speaker B: Fantastic. That's helpful with uh, these rules. Now being enforced uh, for 2026. Walk uh, me through some of the requirements that are going to be needed from the corporates.

Speaker C: So um, on the company ID you have to enter know payroll or purchase if it's payroll related or if it's um, a web debit entry. Um, so that's a requirement that exists there. And there's materials you can read on that. We can probably put some links in the show. Notes on the risk based fraud monitoring. There's a couple elements to that. One is you have to monitor your ACH activity for unauthorized returns and authorized under false pretenses items. Right. So there's a, uh, someone does business email compromise, they authorize it, but it was under false pretenses. Both of those have to be looked at. As you monitor the ach, you need written policy and procedures. Um, you have to do a ACH fraud risk assessment. And that risk assessment doesn't mean you can just take a document, copy it over. It has to be specific to your organization. It has to identify where uh, the ACH fraud risk is most likely to happen, um, by payment type. So whether that's payroll, uh, corporate payments, consumer payments, debits. So you have to identify where that is. So the fraud risk assessment has to be done and then there's an annual aspect to that. So the operational monitoring would include, you know, monitoring controls, exception handling and escalation procedure. So is there an exception? Is there something that has uh, had a problem? How do you resolve it? So that has to be identified ahead of time. And so part of the goal of that is to make sure anytime there's a fraud there's a way to handle it and to handle it quickly as opposed to letting these things linger and protecting the entire ACH network, the entire payment rail. Just like card had PCI DSS about 20 years ago to protect card information, uh, that expanded to Swift messaging with Swift csp. And so we see this uh, this type of activity happening now in terms of protecting the payment rail on a regular basis. And then the last one that I'll mention here is there's an annual review process of your overall fraud, uh, risk policy, uh, and the assessment that takes place. So you have to assess the ongoing effectiveness m of your policy and your structure in light of morphing and changing fraud tactics. Criminals are adjusting. And so your defense and your policy and your risk framework has to adjust as well. That makes perfect sense. And this is formalizing it. Um, and updates need to be made based upon that review. It might be no changes were Necessary it might be we're doing this, we have this additional control, we have this service, we put this automation in place. And then finally you have to have an artifact or documentation that shows that the annual review has happened and what, what was done by that and what did you, what did you complete? So those are, those are some of the key elements for the requirement. So it impacts almost every single commercial and corporate, uh, business, uh, entity that, that does ACH activity.

Speaker B: Okay, as you're talking about policy and controls and the importance of the uh, required now the ACH fraud risk assessment, can you talk a little bit about the principle of appropriate to risk and what does that mean?

Speaker C: Yeah, uh, you wouldn't use a dollar to protect the quarter. Right? So it's like it has to be proportional. What that means is that it's appropriate to the risk or it's proportional to the level of exposure. So if someone has extremely low volume, uh, maybe has limits set on things, while their, their elements of risk management might be a little bit more manual, a little simpler, uh, someone who's doing, let's say an insurance company is doing 10, uh, million ach is a month, they're going to have a lot more automation, a uh, more rigorous routine that's systematically reviewing these uh, across the board so the controls cannot be absent. So this whole proportional. Doesn't mean it's so little we don't care about it, or it's so little we don't care about it because we have insurance coverage. They uh, have to be proportionate. So the sophistication, the level of automation would be proportionate to what you're doing. So the people that say we don't need to do anything, that's incorrect. You will need to do something. But like we were saying, you don't need a dollar chasing a nickel or a quarter or whatever.

Speaker B: That makes sense. So over the last few months I've had numerous, uh, conversations with uh, treasurers and some of this is newer to them or it's been at least put on the uh, back burner in their mind. Uh, what would you say to those practitioner teams that have not started looking into this, becoming compliant, or if they have not completed it ahead of the due date, uh, or is it just too late, what should they be doing as we rush toward, uh, well, if

Speaker C: you haven't, it's never too late to move towards fixing things. So let's say you didn't, uh, you didn't do the company ID changes you needed for payroll or for purchase. Well, go ahead and get that fixed. But because that's already passed, the timeframe is passed. If you're sending things without that, you're not in compliance. There's, you know, the potential for all the penalties. But I think the key thing is to move to, to fix that. If you haven't reviewed it, go review it. You may already be in compliance, you may not be, but you should review it and make, make sure that's the case. Um, for those that are not sending, 6 million or more, ACH is a year. June. There's a deadline in June, uh, June 22nd where you have to have the, your risk based framework for uh, managing, uh, ACH risk, fraud risk through the program. So you would need to get started. So if your bank may have notified you of that, um, maybe you're, maybe it's underway. Uh, maybe everyone thought, you know, AP is doing that, Treasury's doing that, it is doing that, whatever those elements are. If you're in treasury, our view is that the treasurer is the superintendent of payments, not doing everything, but making sure everything happens. And so that you should pull those, everybody together. Has this been accomplished? Is this formally documented? Do you have the artifacts of the assessment? What's going on? Do you need resources to do that? Can you get that all done within your team? Do you need assistance to do that? Um, we can share more information on that, but that's a good way for, um, organizations to get started. Um, get started, figure out if you can do it on your own, uh, or if it's going to be better and faster, especially as you get things started, to get help. Maybe on an annual basis, uh, you want to check in with someone else, but you might find it pretty easy to do it on your own going forward. But either way, if you haven't started, get started. Um, now.

Speaker B: Great. Craig, this has been very interesting, incredible information that you shared with us. Thank you. Uh, and I enjoyed it.

Speaker C: Thank you.

Speaker D: You've reached the end of another episode of the Treasury Update podcast. Be sure to follow Strategic Treasurer on LinkedIn. Just search for Strategic Treasurer. This podcast is provided for informational purposes only, and statements made by Strategic Treasurer LLC on this podcast are not intended as legal, business consulting or tax advice. For more information, Visit and bookmark StrategicTreasurer.com.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Deepfakes & Payments Fraud: Is Treasury Prepared?OpenTreasury · features Craig Jeffrey49 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Business email compromise86 / 100
  • 2026 Payments Outlook: Staying Ahead of AI-Driven ThreatsThe Payments Podcast · on Business email compromise81 / 100
  • 401 Access Denied Podcast Ep. 124 | 2025 State of Cybersecurity with Dan Lohrmann401 Access Denied · on Business email compromise81 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Business email compromise80 / 100
  • Navigating the Complexities of API Protection and ComplianceEncrypted Ambition: Where Ambition Meets Encryption · on PCI DSS80 / 100

More from The Treasury Update Podcast

All episodes →
  • Turning Fragmented Payment Data into Actionable Treasury Intelligence (Deluxe)63 / 100
  • Liquidity Stress Testing: Preparing Treasury for Shock Events48 / 100
  • The Hidden Costs of Complexity in Treasury Operations43 / 100
  • AI Transitions: The Corporate View (Transform Labs)
  • Architecting Modern Payment Security
Explore the best B2B Finance podcasts →
All The Treasury Update Podcast episodes →