Share This Page

How Some RDFIs Review Customer Written Statements of Unauthorized Debits for First-Party Fraud

August 3, 2026 / Source: Nacha

Many financial institutions and ACH Originators have told Nacha that first-party fraud is of increasing concern. Nacha workgroups have been deliberating on a defined role for RDFIs in identifying instances of first-party fraud, just as previous deliberations identified a role for RDFIs in transaction monitoring for credit-push fraud that was ultimately approved as a Nacha Rule. The workgroups have also discussed what “prompt recredit” actually means, in an effort to help RDFIs understand how the Nacha Rules align with Reg E requirements.

One thing we have learned during these discussions is that some RDFIs already actively review customer claims of authorized and do not automatically return the ACH debit if a review deems the claim not credible. Other RDFIs do little or no review of claims and submit a return based only on the receipt of the customer’s signed WSUD. A 2025 survey by Nacha’s Risk Management Advisory Group (RMAG) found wide variation in RDFI practices regarding such reviews.

Although the Nacha Rules do not articulate and enumerate any requirements for the review of a Written Statements of Unauthorized Debit (WSUD) by an RDFI, nevertheless some RDFIs report that the factors discussed below can help determine the credibility of a customer’s claim of unauthorized.

  • Dollar amount – Establish thresholds or tiers and increase the level of scrutiny for claims as the dollar value of the claim increases.
  • Name match – Determine whether the name in the Individual Name field of the Entry matches or is similar to a name on the account. A name mismatch can be a corroborating indicator for an unauthorized transaction.
  • Account validation – An RDFI may be able to identify whether and how account validation took place, potentially through an ACH prenotification or Micro Entry, either of which would be retained as a record of an ACH transaction. An RDFI also might be able to tell whether open banking or an API call was used to validate access to the account and obtain account information, as the RDFI may have responded to such a request or call. 
  • Transaction history with the same Originator – A look-back on the account might show a transaction history with the same Originator for either recurring or multiple payments that were not disputed. A look-back could also show whether the Receiver received an ACH credit from the Originator to the same account that was not disputed.  
  • Negative balance – An RDFI can determine when a transaction caused a negative balance. Customers with a transaction that results in a negative balance may be incentivized to report the transaction as unauthorized to avoid overdraft fees and other complications associated with a negative balance. 
  • Age of the account and established history – Fraudsters open accounts at financial institutions for the purpose of committing fraud. While some fraudsters may season the accounts, many are opened and used quickly for illicit purposes. Accounts used for fraud may not reflect the anticipated income and spending patterns of transaction accounts associated with more typical consumers. 
  • Type of transaction – An RDFI can often determine the purpose of the transaction using details from the ACH record including the Company Entry Description, Company Name, and SEC Code. Debits from another financial institution, a cryptocurrency exchange, a brokerage, or a digital wallet could indicate a new account opening at that entity. Debits following a recent credit from the same Originator could indicate a loan repayment. 
  • History of unauthorized claims – The RDFI can review a consumer’s account history of payment dispute claims including debit card disputes, returned checks, or ACH unauthorized claims. If a consumer is routinely disputing transactions, the customer may need education on protecting their account, or the disputes could indicate the Receiver is abusing the return process.

Though Proof of Authorization (POA) is not readily available to the RDFI at the time a claim of unauthorized is made, an RDFI has the right under the Nacha Rules to request a POA from the ODFI, which must either provide such proof within 10 banking days or give permission to return. While a POA can provide additional information and insights into the validity of the original payment authorization, many RMAG members report that the POA request and provisioning process is too lengthy to assist with WSUD reviews. To improve process efficiency, Nacha reminds RDFIs that requests for POA can be made securely and electronically through Federal Reserve Financial Services’ Exception Resolution Service (ERS). If requested and received, the information included in the POA may help the RDFI in its decision to process or deny a claim of unauthorized debit.