ACH Debit Blocks, Filters, and Positive Pay: How Businesses Stop Unauthorized Debits on Their Own Account

ACH Debit Blocks, Filters, and Positive Pay: How Businesses Stop Unauthorized Debits on Their Own Account
By Gerardo Graham August 13, 2026

ACH debits make it easy for businesses to pay vendors, utilities, lenders, tax authorities, insurers, software providers, and other organizations directly from a bank account. That convenience also creates a risk: if an unexpected or unauthorized ACH debit reaches the account, money may leave before anyone on the finance team notices.

Businesses do not have to rely only on after-the-fact transaction review. Many financial institutions offer treasury management services designed to control incoming ACH debits before or as they post. Three common approaches are an ACH debit block, an ACH filter, and ACH positive pay.

An ACH debit block generally prevents ACH debit entries from posting unless the account or bank configuration specifically permits them. An ACH filter takes a more selective approach by allowing debits that match approved criteria, such as an ACH Company ID, originator, or amount limit where the bank supports those options. 

ACH positive pay typically compares incoming debits with predefined authorization rules and sends exceptions to designated users for a pay-or-return decision.

These services can be valuable components of business fraud prevention, but they are not interchangeable. Their exact operation, terminology, fees, exception handling, and decision deadlines depend on the financial institution.

They also do not guarantee that fraud will never occur. Strong corporate account fraud protection combines ACH debit controls with secure vendor management, account alerts, multifactor authentication, limited user privileges, reconciliation, documented authorization procedures, and fast incident response.

This guide explains how those controls work, where ACH Company IDs fit, how businesses can reduce the chance of blocking valid payments, and what to do when an unauthorized debit reaches an account.

How ACH Debits Work Before They Reach a Business Account

An ACH debit is an electronic entry that pulls money from the receiver’s bank account after an originator initiates the transaction under an applicable authorization. Understanding the basic flow makes ACH debit protection much easier to configure because filters and positive-pay rules evaluate information traveling with those entries.

A typical ACH transaction involves several participants. Nacha’s overview of how ACH payments work identifies the Originator, Originating Depository Financial Institution, ACH Operator, Receiving Depository Financial Institution, and Receiver as core participants in the flow.

The Originator is the organization initiating the ACH entry. For a debit reaching a business bank account, that might be an insurer collecting a premium, a lender withdrawing a scheduled payment, or a vendor collecting an authorized invoice.

The Originating Depository Financial Institution (ODFI) is the financial institution through which the originator sends the ACH transaction. The entry travels through an ACH Operator and ultimately reaches the Receiving Depository Financial Institution (RDFI), which holds the receiver’s account.

The Receiver is the person or organization whose account is being credited or debited. In this guide, the receiver is generally the business whose bank account is being protected.

ACH entries contain identifying and transaction information. One particularly important field for business fraud controls is the Company Identification, commonly called the ACH Company ID. Federal Reserve Financial Services describes this field as an alphanumeric identifier generally assigned by the ODFI to identify an originator.

Before an originator legitimately debits an account, there must also be appropriate ACH debit authorization. Authorization requirements differ depending on the type of transaction and applicable Standard Entry Class, or SEC, code. 

Businesses that want a broader introduction to the payment flow can review this guide to how ACH transactions work.

Finally, the ACH entry proceeds through clearing and settlement between participating financial institutions. A debit block, filter, or ACH positive pay service generally operates at the receiving bank side of this process, using information associated with the incoming transaction and the business’s established account controls.

What Is an ACH Debit Block?

An ACH debit block is a bank-account control designed to prevent ACH debit entries from posting to a designated account unless an exception or other permitted configuration applies. It is generally the most restrictive of the three controls discussed in this guide.

A business might use an ACH debit block on an account that should receive deposits but should almost never be debited electronically. 

For example, a company may maintain a collections account intended primarily for incoming customer payments and transfer those funds internally rather than authorizing outside parties to withdraw from the account.

With a restrictive block in place, an incoming ACH debit that does not meet the bank’s permitted conditions may be rejected or returned according to the institution’s service design and applicable ACH rules. 

The business is therefore controlling whether outside originators can successfully pull money from the protected account instead of depending solely on detecting an unwanted withdrawal afterward.

The main benefit is straightforward: the attack surface for unauthorized ACH withdrawals becomes smaller. A fraudulent or erroneous originator cannot simply rely on possessing valid routing and account information if the account rejects incoming ACH debits.

The limitation is equally important. A debit block cannot distinguish between fraud and a valid debit that the business forgot to accommodate unless the service includes an exception mechanism. 

Legitimate payments for insurance, taxes, loan obligations, software subscriptions, utilities, equipment leases, or other expenses may fail if they are not properly permitted.

Businesses therefore need to understand exactly what their financial institution means by “block.” Some institutions may offer a complete block, while others support authorized exceptions, allowlists, or related filter capabilities under different product names.

An ACH debit block is often attractive when a company has few or no legitimate ACH debits, wants unusually strict bank account security, or can route recurring debits through another controlled account.

It should not be treated as a substitute for monitoring. Fraud could involve other payment channels, internal transfers, compromised credentials, checks, wires, cards, or ACH credits initiated through an account takeover scenario.

What Is an ACH Filter?

An ACH filter is an account-level control that allows selected ACH debits to post when they match criteria established with the bank. Instead of rejecting essentially all incoming debits, the business creates rules defining which activity should be allowed.

One of the most common filtering criteria is the ACH Company ID associated with an approved originator. A business might authorize a tax payment provider, insurer, lender, utility company, or other recurring vendor by adding the correct Company ID to an ACH whitelist or approved-originator list.

Depending on the bank’s ACH debit filter service, rules may also consider transaction amount, maximum dollar limits, account information, transaction type, or other available fields. These capabilities should never be assumed to be universal. Banks design and name their treasury-management products differently.

A filter can be useful when legitimate ACH activity is predictable. Imagine a manufacturer that permits recurring debits from five established providers but does not expect any other company to withdraw funds electronically. 

An ACH filter could allow approved originators while rejecting or flagging unmatched entries under the bank’s service rules.

Filters require maintenance. A vendor might change its banking relationship, payment processor, ACH Company ID, or billing structure. A newly approved vendor may also need to be added before its first debit arrives.

That is why good unauthorized ACH debit protection depends on more than building a whitelist once. Treasury teams should review the list periodically, remove obsolete entries, validate changes independently, and document why each originator is permitted.

Amount controls deserve similar attention. Where supported, ACH transaction limits can help reduce exposure, but limits that are too low may cause a legitimate payment to fail. Limits that are extremely high may provide little practical protection.

The goal is to make the allowed activity closely resemble the company’s genuine payment requirements without creating an administrative process so rigid that the finance team routinely bypasses it.

What Is ACH Positive Pay?

ACH positive pay is a treasury-management control that generally compares incoming ACH debit activity against authorization rules and identifies exceptions that may require the business to make a pay-or-return decision. It gives the business an active role in reviewing transactions that do not match its established expectations.

Suppose the business authorizes debits from several known originators. If an incoming ACH entry matches the rules, the bank’s system may process it without requiring intervention. If the entry does not match, the transaction may appear in an exception queue and designated users may receive an alert.

An authorized employee then reviews available information and chooses how the item should be handled according to the bank’s service. The business must act within the applicable decision window, which varies by institution and product.

That deadline matters. A missed exception does not have one universal outcome. Depending on the bank’s configuration, an undecided item might be paid, returned, or treated according to a default instruction established when the service was configured.

An ACH positive pay service may therefore offer stronger oversight than a static filter for organizations with changing or higher-volume debit activity. It can also create operational demands because someone must reliably review exceptions on banking days.

Banks use different terminology for these services. Some combine filtering, authorization rules, exception review, and positive pay functions under one platform. Others separate them into distinct treasury products.

Businesses should also recognize that Positive Pay is widely associated with check fraud prevention. Traditional check positive pay usually compares checks presented for payment against information supplied by the company about checks it issued. 

ACH positive pay instead evaluates electronic ACH activity using ACH-related authorization rules. Neither version should be interpreted as a guarantee against all forms of business bank account fraud.

ACH Debit Block vs. ACH Filter vs. ACH Positive Pay

ACH payment security illustration showing debit block, transaction filtering, and positive pay verification

The core difference among these controls is how they treat an incoming ACH debit that reaches the business’s bank. A debit block begins from a restrictive position, an ACH filter permits entries that match approved rules, and ACH positive pay generally adds an exception-review process for transactions that need a decision.

FeatureACH Debit BlockACH Debit FilterACH Positive Pay
Primary purposePrevent unwanted ACH debits from postingPermit debits matching approved criteriaReview incoming debits against authorization rules
Default treatment of debitGenerally blocked unless permittedEvaluated against filter rulesCompared with rules; exceptions handled under service settings
Allows approved originatorsMay, if exceptions are supportedYes, typically a core functionCommonly through authorization rules
Uses Company IDsMay use them for permitted exceptionsOftenOften
Exception reviewLimited or product-dependentProduct-dependentTypically a central feature
Business involvementHigher during setup, often lower day to dayOngoing rule maintenanceRegular exception review may be required
Risk of blocking valid paymentsHigh if legitimate debits are not permittedModerate if rules are incomplete or outdatedPresent if rules or decisions are incorrect
Best suited forAccounts with few or no valid ACH debitsPredictable recurring originatorsBusinesses needing active oversight of variable activity

The right choice should follow the account’s actual use. A company that never intentionally permits third-party ACH debits may find a restrictive block easier to manage than maintaining a long authorization list.

A company with ten predictable recurring vendors may prefer an ACH filter or whitelist. It can authorize those originators while preventing unrelated ACH debits from moving through normally.

A company with larger, changing, or more complex payment activity may benefit from ACH positive pay because exception review can add human judgment. The tradeoff is operational responsibility: alerts must reach the right people, backups must exist, and reviewers must understand what they are approving.

Some organizations combine controls. They may block ACH debits on collection accounts, use filters on accounts with predictable withdrawals, and use positive pay on operating accounts requiring more flexible oversight.

The most effective configuration is not necessarily the product with the most features. It is the control that fits the account’s purpose, transaction pattern, staffing, and ability to manage exceptions consistently.

Understanding ACH Company IDs and Approved Originators

Secure ACH payment network with bank, ID verification, approval, and security icons

An ACH Company ID is an identifier carried in an ACH batch that helps identify the originator associated with the transactions. Federal Reserve ACH documentation describes Company Identification as an alphanumeric field generally assigned by the originator’s ODFI.

For ACH filters and positive-pay authorization rules, that identifier can be more useful than relying only on the name displayed on an account statement. The Company Name and Company ID are separate ACH data elements, and the wording a business recognizes on a statement may not be the best field for creating an authorization rule.

A business setting up an ACH whitelist should obtain the correct Company ID through a trusted source. That could mean contacting the vendor using independently verified contact information, reviewing established treasury documentation, or coordinating with the bank to identify recurring entries already posted to the account.

Do not approve an unfamiliar Company ID simply because someone sends it in an unexpected email. A compromised vendor mailbox could be used to introduce fraudulent payment information or convince employees to change financial instructions.

Businesses should also expect legitimate organizations to use more than one Company ID in some circumstances. A vendor may process different products through different entities or banking arrangements, for example. The finance team should verify each required ID rather than assuming one approved identifier covers every transaction.

A good authorization record connects the Company ID with the legal or recognized vendor, payment purpose, expected transaction pattern, internal approver, and date of verification.

This is also why replacing an entire vendor record based solely on an email request is risky. Independent verification gives the business a second source of evidence before it changes a control that determines who may withdraw money from its account.

How ACH Debit Blocks, Filters, and Positive Pay Work Step by Step

Although banks implement these products differently, understanding the typical workflow helps finance teams design practical controls and ask better questions during treasury-management setup.

How an ACH Debit Block Typically Works

The business first asks its bank to place ACH debit controls on a particular account. The bank configures the service based on the options it supports and any exceptions the business has requested.

A typical process looks like this:

  1. The business requests ACH debit protection: Treasury staff identify the account and clarify whether all debits should be blocked or certain exceptions should remain available.
  2. The bank activates the control: The financial institution applies its debit-block configuration to the account.
  3. An incoming ACH debit is evaluated: When a debit arrives, the bank checks it against the applicable account settings.
  4. Unapproved activity is handled according to the service: A debit that is not permitted may be rejected or returned according to the bank’s process and applicable rules.
  5. Approved exceptions proceed: If the service supports exceptions and the incoming entry satisfies them, the transaction may be posted.
  6. The business monitors activity: Treasury or accounting teams review reports, returned items, vendor notices, and account transactions.

The last step is essential. A blocked legitimate debit can lead to late payments, service interruptions, contractual problems, or vendor confusion. Businesses should therefore pair the block with reconciliation and an escalation process for rejected payments.

How an ACH Filter Typically Works

An ACH filter starts with an authorization list rather than a blanket restriction. The business identifies which originators should be able to debit the account and establishes available criteria with its financial institution.

A typical workflow is:

  1. Review historical ACH debit activity.
  2. Identify legitimate recurring originators.
  3. Obtain and independently verify their ACH Company IDs.
  4. Add the approved IDs to the bank’s filtering service.
  5. Apply amount limits or other supported criteria where appropriate.
  6. Determine how unmatched entries will be handled.
  7. Review rejected or exception activity.
  8. Update the rules when vendors, Company IDs, amounts, or account uses change.

A filter only remains reliable if the approved list stays current. Finance teams should therefore make filter maintenance part of vendor onboarding and offboarding rather than treating it as a separate treasury task.

How ACH Positive Pay Typically Works

ACH positive pay combines predefined rules with exception management. The objective is to identify entries requiring closer attention before the service’s decision process is complete.

A typical workflow is:

  1. The bank receives an ACH debit
  2. The entry is compared with authorization rules: These rules may include Company IDs or other supported criteria.
  3. Exceptions are identified: Activity that does not meet the rules enters the bank’s exception process.
  4. The business receives an alert or review item:
  5. An authorized user reviews the transaction: The reviewer decides whether to pay or return the item within the bank’s applicable decision window.
  6. The transaction is handled according to that decision and service rules

Never assume a universal positive-pay deadline. Ask the bank exactly when exceptions become available, what time decisions are due, what timezone applies, and what happens if nobody responds.

When Each ACH Control Makes Sense

ACH payment controls dashboard with security, approval, and workflow icons

Selecting a control should begin with how the account is actually used rather than with the product name. Different accounts within the same company may justify different levels of restriction.

Businesses That Rarely Allow ACH Debits

A business that rarely authorizes another party to pull money from its account may be a strong candidate for an ACH debit block. The control matches a simple operating rule: outside ACH debits are not normal activity.

This can be especially useful for accounts primarily used to receive funds. Instead of trying to identify suspicious debits after settlement, the organization restricts the payment channel at the account level.

Before enabling the block, however, the business should inspect prior account activity for overlooked recurring payments. Taxes, insurance premiums, loan payments, utilities, payroll-related services, subscription providers, and government obligations are easy to miss because they may post infrequently.

If even a small number of legitimate debits must continue, ask the bank whether the account can support controlled exceptions. Otherwise, the business may decide that those payments should be moved to a different operating account.

Businesses With Predictable ACH Vendors

An ACH filter often fits businesses that allow debits but know exactly which organizations should be initiating them. Predictability makes an approved-originator model practical.

The business can establish a list of verified Company IDs and, where supported, amount parameters or other criteria. Unexpected originators are then handled differently from recognized ones.

This approach can reduce disruption compared with blocking every debit. It also creates a governance benefit because the organization must explicitly document who has permission to withdraw money.

The weakness is maintenance. An outdated ACH Company ID or unrecorded vendor change can turn a legitimate debit into an exception. Vendor onboarding procedures should therefore include ACH-control setup, and vendor offboarding should remove permissions that are no longer necessary.

Businesses With High or Variable Transaction Volume

Organizations with significant or changing ACH activity may need more flexible oversight. ACH positive pay can help by separating routine transactions from items that require human review.

This does not mean every transaction needs manual approval. Authorization rules can allow expected activity while exceptions receive attention from designated treasury users.

High-volume companies should pay particular attention to staffing, escalation, and decision deadlines. An alerting system has little value if hundreds of notifications go unread or if the only authorized reviewer is unavailable.

Positive pay should also connect with reconciliation and fraud investigations. Exception decisions provide one layer of ACH fraud detection for businesses, but unusual activity outside the positive-pay workflow still deserves review.

Multi-User Finance Teams

As finance departments grow, account security becomes partly an access-governance problem. The same employee should not automatically control vendor creation, Company ID changes, positive-pay decisions, online-banking administration, and reconciliation simply because doing so is convenient.

Segregation of duties helps make inappropriate changes more visible. One employee might maintain vendor information while another independently approves ACH-control changes.

Where the bank supports it, organizations can use dual approval for sensitive administration, transaction limits, separate user roles, and audit logs. Former employees and unused accounts should be removed promptly.

The objective is not bureaucracy for its own sake. It is to prevent one stolen credential, compromised mailbox, or unauthorized internal action from becoming sufficient to defeat every payment fraud control.

Unauthorized ACH Debit Risks Businesses Should Plan For

Unauthorized ACH transactions do not all arise from the same cause. Some involve fraudulent originators, while others result from compromised credentials, incorrect vendor behavior, duplicate processing, or breakdowns in internal authorization.

A fraudulent originator may attempt to debit an account without legitimate permission. Account and routing information alone should not be treated as proof that a withdrawal was authorized.

An unauthorized recurring debit can also occur when a payment continues beyond the authorization the business believes it granted. Disagreements over cancellation, timing, or scope should be documented and escalated promptly.

Not every problematic debit is intentional fraud. A vendor may withdraw the wrong amount, debit the wrong account, or submit a transaction twice. Businesses still need an effective review process because an operational error can affect cash flow just as quickly as malicious activity.

Credential compromise creates another layer of risk. An attacker who gains access to online banking, accounting software, email, or vendor-management tools may attempt to alter financial workflows rather than simply initiate an obvious fraudulent withdrawal.

Business email compromise is particularly relevant to vendor management. The FBI warns that attackers may impersonate known sources or compromise email accounts to request changes in payment information and recommends independently verifying changes in account numbers or payment procedures. The FBI’s business email compromise guidance also recommends multifactor authentication where available.

Businesses can explore additional defensive practices in this guide to ACH payment security best practices and this overview of ACH fraud risks and prevention.

The key lesson is that ACH debit fraud prevention is layered. A filter can reject an unknown originator, but it cannot compensate for every internal approval failure or every compromised payment channel.

How to Stop Unauthorized ACH Debits on a Business Account

When an unfamiliar ACH withdrawal appears, speed matters because ACH return rights, contractual rights, bank procedures, and legal remedies can depend on the transaction type and timing. A business should contact its financial institution promptly rather than assuming the transaction can simply be reversed later.

A practical defensive response is:

  1. Contact the bank immediately: Use a known telephone number or secure banking channel and identify the transaction as potentially unauthorized.
  2. Gather transaction details: Record the posting or settlement information, amount, Company Name, ACH Company ID, trace information if available, and account affected.
  3. Ask about return or dispute options: The bank should determine which procedures and ACH return rules apply to the specific entry.
  4. Review the originator and Company ID: Determine whether the debit belongs to a legitimate vendor, an outdated authorization, or an unknown party.
  5. Adjust ACH controls where appropriate: Add or remove authorized Company IDs, change limits, or strengthen blocking rules with the bank.
  6. Review recent activity: Look for other suspicious debits, credits, account changes, new users, unusual login activity, or vendor modifications.
  7. Secure online-banking credentials: Change compromised credentials and reinforce multifactor authentication where available.
  8. Investigate vendor or account compromise: Independently contact involved vendors if their information may have been altered.
  9. Document the incident: Preserve communications, bank references, transaction details, screenshots, approvals, and investigation notes.
  10. Strengthen monitoring: Add alerts, improve reconciliation, revise permissions, and review the incident for process weaknesses.

Do not describe the transaction to the bank merely as a “chargeback.” ACH transactions follow their own return and dispute framework.

An ACH debit reversal also should not be confused with a consumer or corporate claim that a transaction was unauthorized. Nacha notes that ACH reversals are available only for specified types of erroneous entries and are subject to specific rules; they are not a universal mechanism for undoing any unwanted transfer.

ACH Returns, Unauthorized Transactions, and Business-Account Differences

An ACH return is an ACH entry sent back through the banking system because the original entry cannot be processed or is being returned for an applicable reason. Return reason codes identify why the transaction is being returned.

Nacha identifies several return codes associated with unauthorized entries, including R29, which is used in the corporate context for certain CCD and CTX entries to non-consumer accounts.

Business owners should be particularly careful about assuming that consumer protections apply to corporate accounts. They do not automatically operate the same way.

Nacha states that an RDFI returning an unauthorized debit to a non-consumer account must transmit the return so it is available to the ODFI no later than the opening of business on the second banking day following the settlement date. 

Nacha’s corporate guidance likewise distinguishes corporate entries’ standard return period from extended return treatment available for certain consumer entries.

That makes prompt account review especially important for businesses. It does not mean every commercial-account dispute has the same outcome, nor should a company assume that discovering a debit after the standard return window eliminates every possible contractual, warranty, fraud, or legal remedy.

The exact analysis can depend on the transaction, SEC code, account agreement, authorization status, applicable Nacha Rules, bank procedures, warranties, and other law. Financial institutions may also have specific documentation requirements for unauthorized-entry claims.

Federal Reserve Financial Services operates ACH exception processes used between financial institutions, including a Written Statement of Unauthorized Debit copy process and an ODFI Request for Return process. 

Those interbank mechanisms illustrate why customers should work through their own financial institution rather than attempting to manage ACH return processing themselves.

The practical rule for finance teams is simple: review commercial accounts frequently and report suspected unauthorized ACH activity immediately. Do not build an incident plan around the assumption that the organization will have weeks to react.

Preventing Legitimate ACH Payments From Being Blocked

ACH debit protection becomes counterproductive when it routinely stops valid obligations. The best control is restrictive enough to reduce unauthorized activity while accurately reflecting the organization’s real payment relationships.

Start by building a verified inventory of legitimate ACH debits. Review at least several months of transactions and account for payments that occur quarterly, semiannually, annually, or only after specific events.

Then obtain the correct Company IDs. Do not assume the vendor’s displayed name is sufficient. As Federal Reserve documentation shows, Company Name and Company Identification are separate ACH fields used for different purposes.

New vendor onboarding should include a specific question: Will this vendor ever debit one of our accounts by ACH? If so, determine which account, obtain appropriate authorization documentation, independently verify the vendor’s ACH information, and update the applicable filter or positive-pay rules before the first expected withdrawal.

If a bank supports testing or advance review, use it when making major changes. Where testing is not available, coordinate the timing of the first legitimate debit and monitor the account closely.

Businesses should also document what happens after a valid payment is blocked. The accounts-payable team may need to contact the vendor, arrange another payment method, resolve a return fee, and correct the bank rule before the next debit.

Exceptions deserve periodic review. If employees repeatedly approve the same legitimate originator in ACH positive pay, the rule may need to be updated. If an approved originator has not been used in a long time, determine whether its permission remains necessary.

ACH Positive Pay vs. Check Positive Pay

The term Positive Pay can cause confusion because it has long been associated with check fraud prevention. ACH positive pay and check positive pay serve related risk-management goals but evaluate different payment information.

With check positive pay, a business typically provides its bank with information about issued checks, such as check number, amount, and sometimes payee information. When a check is presented, the bank compares it with the company’s issued-check data and identifies discrepancies according to the service.

With ACH positive pay, the bank instead evaluates incoming electronic ACH activity against ACH authorization rules. Those rules may rely on Company IDs, transaction parameters, or other criteria supported by the institution.

Both systems may involve exception review. A finance employee could therefore have one queue for checks that do not match issued-check information and another for ACH entries that do not satisfy the company’s authorized-debit rules.

The controls address different fraud scenarios. Check positive pay can help detect checks that were altered, counterfeited, or otherwise inconsistent with the company’s issue file. ACH positive pay is designed around electronic entries rather than physical or imaged checks.

Businesses that use both checks and ACH debits should ask their bank whether the services share a dashboard, alert process, user permissions, and decision deadlines. Similar branding does not necessarily mean identical workflows.

Neither product protects every movement of funds. Wire transfers, card activity, internal transfers, account takeover, and other payment channels require their own controls.

That distinction matters when evaluating a bank’s “positive pay” offering. A business specifically seeking unauthorized ACH debit protection should confirm that the product covers ACH transactions rather than assuming a check-focused positive-pay service does.

ACH Controls, Vendor Management, Internal Fraud, and Business Email Compromise

Bank-side controls work best when the company’s internal processes support them. Vendor verification, user permissions, account alerts, and approval workflows determine whether the rules entered into the bank’s system remain trustworthy.

For vendor onboarding, record who authorized the relationship, what payment method is permitted, whether the vendor may initiate ACH debits, which Company IDs are approved, and which business account may be used.

Banking changes should receive special scrutiny. If a vendor suddenly requests a new bank account, payment method, Company ID, or collection procedure, verify the request through a communication channel already on file.

The FBI specifically advises organizations to verify changes in account numbers or payment procedures rather than relying only on the message requesting the change.

Internal access controls matter just as much. Follow least privilege by giving employees only the treasury and banking permissions necessary for their role. Administrator access should be limited because an administrator may be able to change users, alerts, filter rules, transaction limits, or approval settings.

Where supported, use dual approval for high-risk changes. One employee can initiate a new ACH Company ID authorization while a second employee independently reviews it before activation.

Segregate responsibilities where staffing permits. The person who creates a vendor should not automatically be the only person who approves banking changes and reconciles the resulting withdrawals.

Audit logs can help finance leaders understand who changed a rule and when. Periodic access reviews should remove former employees, contractors, obsolete user profiles, and privileges no longer required.

BEC defenses should extend beyond the bank. Employees should be trained to recognize requests involving sudden urgency, unusual secrecy, changed payment instructions, or pressure to bypass established approval procedures.

Bank Account Alerts, Monitoring, and Daily Reconciliation

An ACH debit block, filter, or positive-pay service should sit inside a broader ACH transaction monitoring program. Alerts and reconciliation can detect problems that preventive controls miss and reveal when legitimate payments are being rejected.

Useful bank alerts may include ACH debit notifications, large-transaction alerts, balance thresholds, account activity alerts, login or security alerts, and new-payee or originator notifications where the bank offers them.

Alert design matters. If every routine payment triggers a notification, employees may stop paying attention. Configure alerts to identify transactions that deserve action while making sure critical messages reach more than one qualified person.

Why Daily Reconciliation Matters

Daily reconciliation means comparing bank activity with accounting records, expected transactions, vendor obligations, and authorized payment activity frequently enough to identify anomalies quickly. 

For a business using ACH debits, that review can reveal an unknown originator, duplicate withdrawal, incorrect amount, unexpectedly repeated transaction, or payment that should have stopped.

The value is not just accounting accuracy. Timely review gives the organization more opportunity to contact its financial institution while relevant ACH return or dispute procedures may still be available.

A daily review can be lightweight for a small business. An owner, bookkeeper, or office manager might inspect the bank’s previous-day activity and match unusual withdrawals against invoices or scheduled payments.

Larger companies can automate part of the process through treasury and accounting systems, but automation should still produce actionable exceptions. A reconciliation report that nobody investigates does not provide meaningful cash management security.

Businesses should also reconcile rejected items. When a legitimate debit is blocked, the event can reveal an outdated Company ID, incorrectly configured amount limit, or vendor-change process that failed.

Separate Bank Accounts as a Risk-Control Strategy

Some businesses reduce payment exposure by separating financial activities across multiple bank accounts. The purpose is not to make fraud impossible but to limit which transactions are permitted to interact with particular pools of funds.

For example, a company might maintain separate accounts for collections, payroll, operating expenses, and disbursements. A collection account that primarily receives customer payments may have a more restrictive ACH debit block than an operating account that legitimately pays several vendors.

A payroll account can be funded according to expected payroll needs rather than serving as the company’s primary operating account. A controlled disbursement account may likewise be used for approved outgoing activity while excess liquidity remains elsewhere.

This structure can make ACH debit authorization controls easier to design because each account has a clearer purpose. The expected activity on a collections account looks very different from expected activity on a vendor-payment account.

There are operational tradeoffs. Additional accounts create more reconciliation work, more transfers, more bank administration, and potentially additional fees. Businesses also need procedures to maintain sufficient balances and avoid creating liquidity problems through excessive fragmentation.

Separate accounts do not eliminate account takeover, internal fraud, or unauthorized transactions. Poor user permissions could still expose multiple accounts through the same online-banking profile.

The strategy is most useful when combined with account-specific permissions, ACH filters or blocks, alerts, transaction limits, controlled transfers, and disciplined reconciliation.

Finance teams should evaluate account structure with their bank and accounting advisers based on transaction volume, liquidity needs, fraud exposure, operational capacity, and the company’s broader corporate cash management framework.

ACH Security for Small Businesses and Larger Treasury Teams

Effective ACH fraud prevention does not require every business to operate a large treasury department. The essential controls can be scaled to the organization’s size and transaction complexity.

For a small business, start with the highest-impact basics. Ask the bank whether ACH debit blocks, filters, or positive pay are available. Enable multifactor authentication where supported, avoid shared online-banking credentials, and give each employee an individual login.

Maintain a short list of vendors authorized to debit the account and verify their Company IDs. Review the bank account every business day, especially if the commercial account may have short ACH return windows.

Set alerts for significant withdrawals and unexpected ACH activity. Document what the employee reviewing the account should do when something appears suspicious.

Small companies should also be cautious about convenience-based exceptions. Giving several office employees administrator access or sharing one treasury password may seem efficient until the credential is compromised or an employee leaves.

For larger businesses, the same principles become formal treasury governance. Centralized treasury-management platforms may provide role-based permissions, dual approval, positive-pay workflows, bank reporting, transaction limits, and audit information.

Larger companies should define who owns ACH filters, who can add Company IDs, who reviews positive-pay exceptions, who reconciles accounts, and who investigates incidents.

High-volume environments benefit from exception-based monitoring. Automated rules can handle routine transactions while treasury staff investigate deviations.

Periodic reviews should compare authorized rules against active vendors and business operations. An approved originator that made sense two years ago may no longer need account access.

The goal at either scale is the same: reduce unnecessary payment permissions, make unusual activity visible, and ensure someone can respond quickly when an exception appears.

Setting Up ACH Debit Protection With Your Bank

ACH controls are bank-specific, so setup should begin with a review of your institution’s treasury-management options rather than assumptions about what a product called “ACH filter” or “positive pay” will do.

Use this implementation checklist:

  • Review historical ACH debit activity for each business account.
  • Identify which accounts genuinely need to accept third-party ACH debits.
  • Identify legitimate ACH originators.
  • Collect and independently verify their Company IDs.
  • Decide whether a block, filter, positive-pay service, or combination best fits each account.
  • Determine whether dollar limits or other transaction parameters are supported.
  • Assign authorized reviewers and backup reviewers.
  • Configure alerts for exceptions and suspicious account activity.
  • Document how unmatched entries will be handled.
  • Establish procedures for adding or removing approved originators.
  • Test or closely monitor legitimate debits after implementation where practical.
  • Reconcile accounts frequently.
  • Review settings, user access, and approved lists periodically.

When meeting with the bank, ask specific questions rather than stopping at “Do you offer ACH protection?”

Important questions include:

  • Do you offer an ACH debit block?
  • Do you offer an ACH debit filter?
  • Is ACH positive pay available for this type of account?
  • Can authorization rules use ACH Company IDs?
  • Can dollar limits be established by originator?
  • What happens to an ACH debit that does not match an authorization rule?
  • How are exceptions delivered?
  • How long do authorized users have to make an exception decision?
  • What happens if the business misses that deadline?
  • Can multiple employees receive alerts?
  • Is dual approval available for rule changes or exception decisions?
  • What reports and audit logs are available?
  • What fees apply?
  • How are rule changes authenticated?
  • What fraud-support and escalation procedures are available?

Record the answers in the company’s treasury procedures. If a bank changes its service, portal, default handling, or decision cutoff, update those procedures rather than relying on employee memory.

Common ACH Fraud-Prevention Mistakes and a Practical Checklist

One of the biggest mistakes is leaving ACH debits unrestricted simply because the company has never experienced a problem. Controls should reflect business need, not past luck.

Another common error is building an ACH whitelist and then forgetting about it. Company IDs can change, vendors can become inactive, and the company’s payment processes can evolve.

Whitelisting the wrong originator can be especially dangerous because the business may effectively tell its bank to trust future activity from that identifier. Verification should therefore occur before the rule is activated.

Ignoring positive-pay exceptions is another failure point. A sophisticated bank service provides little protection when users miss alerts or repeatedly approve entries without investigation.

Access problems are equally common: too many administrators, shared credentials, former employees who retain access, weak authentication, and lack of dual approval can undermine otherwise strong payment fraud controls.

Businesses should also avoid assuming that positive pay prevents every fraud scenario or that every unauthorized transaction will automatically be recoverable. ACH rules distinguish corporate and consumer transactions, and bank agreements and legal circumstances matter.

Use the following ACH fraud prevention checklist during treasury reviews:

ControlWhat to Verify
ACH debit block/filterSettings still match the account’s intended use
Approved Company IDsEvery ID belongs to a verified, active originator
User permissionsAccess follows least privilege
MFAEnabled wherever the bank and related systems support it
AlertsCorrect employees receive actionable notifications
Dual approvalUsed for sensitive changes where available
Vendor verificationBanking changes are independently confirmed
Daily reconciliationUnexpected activity is investigated promptly
Incident procedureBank and internal escalation contacts are documented
Periodic reviewRules, limits, users, and vendor permissions are reassessed

Businesses should also understand the underlying payment mechanics. This guide to e-check and ACH debit payments provides additional background on ACH-based bank transfers.

Frequently Asked Questions

What is an ACH debit block?

An ACH debit block is a bank-account control that generally prevents incoming ACH debit entries from posting unless the account configuration allows an exception. It is often appropriate for business accounts that should rarely or never be debited by outside ACH originators. 

Because a block can also stop legitimate payments, businesses should identify recurring debits before activation and ask their bank how permitted exceptions are handled.

What is an ACH filter?

An ACH filter allows incoming debits that match authorization criteria established with the financial institution. Those criteria commonly include approved ACH Company IDs and may include dollar limits or other parameters when supported. 

Entries that do not match are handled according to the bank’s service settings. Filters work best when legitimate originators are known and the authorization list is maintained carefully.

What is ACH positive pay?

ACH positive pay is generally an ACH debit-control service that evaluates incoming entries against predefined rules and identifies exceptions. 

Designated business users may then need to decide whether an exception should be paid or returned within the bank’s decision window. Banks vary significantly in terminology, available rules, alerts, default decisions, fees, and deadlines.

What is the difference between an ACH debit block and an ACH filter?

An ACH debit block starts from the position that ACH debits should generally not be allowed. An ACH filter selectively allows debits that match approved criteria. A company with no legitimate third-party debits may prefer a block, while a business with a predictable group of recurring originators may find a filter more practical.

How does ACH positive pay work?

The bank receives an ACH debit and compares the entry with the company’s authorization rules. If the transaction matches, it may process normally according to the service. 

If it does not match, the debit may appear as an exception. An authorized user reviews the information and makes a pay-or-return decision under the bank’s procedures and applicable deadline.

What is an ACH Company ID?

An ACH Company ID is an alphanumeric identifier associated with an ACH originator and carried in the ACH batch information. Banks may use it when building debit filters and positive-pay authorization rules. 

Because the Company ID can be more useful for rule matching than a familiar vendor name, businesses should obtain and independently verify the correct ID before adding an originator to an ACH whitelist.

Can a business block all ACH debits?

A financial institution may offer an account configuration that blocks ACH debits, but availability and implementation vary. 

Before using a complete block, review whether the account receives legitimate recurring withdrawals for taxes, insurance, loans, utilities, subscriptions, or vendors. Ask the bank whether specific exceptions can be permitted and what happens to a debit that is rejected.

Can an ACH filter allow only approved vendors?

Often, that is the basic objective. The business establishes approved-originator criteria, commonly using verified ACH Company IDs. Whether the bank can also enforce amount thresholds, transaction types, or additional parameters depends on its service. 

Businesses should ask how unmatched transactions are handled rather than assuming they will always receive the same treatment.

What happens if a legitimate ACH debit is blocked?

The debit may be rejected or returned according to the bank’s service and applicable ACH processing rules. The business may then have to contact the vendor, correct its filter or authorization settings, and arrange payment.

This is why recurring originators and Company IDs should be reviewed carefully before restrictive controls are enabled.

Can an unauthorized ACH debit be returned?

Potentially, but the applicable process depends on the transaction and circumstances. ACH return codes exist for unauthorized entries, including corporate scenarios, but commercial accounts should not assume they receive the same extended protections available for certain consumer transactions. 

Contact the bank immediately so it can evaluate the applicable ACH rules, account agreement, timing, and documentation.

How quickly should a business report an unauthorized ACH debit?

Immediately after discovery. Nacha states that an RDFI returning an unauthorized debit to a non-consumer account under the standard return framework must make the return available to the ODFI no later than the opening of business on the second banking day after settlement. 

Because transaction circumstances vary, businesses should not attempt to calculate their rights independently before calling the bank.

Is ACH positive pay the same as check positive pay?

No. Check positive pay typically compares checks presented for payment with check information supplied by the business. ACH positive pay evaluates electronic ACH entries using authorization rules. 

Both can involve exception decisions, but they protect different payment channels and use different transaction information.

Do all banks offer ACH positive pay?

No universal ACH positive-pay feature set exists. Availability, product names, authorization criteria, alerts, user roles, fees, exception handling, and deadlines are determined by individual financial institutions. 

Some banks combine ACH filtering and positive-pay functions, while others offer separate services. Ask for a demonstration or written service description before deciding how the control fits your workflow.

Can ACH controls prevent every type of account fraud?

No. ACH debit protection can reduce exposure to unauthorized incoming ACH debits, but it does not protect every payment channel or security failure. 

Organizations still need strong online-banking credentials, MFA where available, limited permissions, independent vendor verification, transaction alerts, reconciliation, incident procedures, and controls for checks, wires, cards, and other forms of payment.

What are the best ways to protect a business bank account from unauthorized ACH withdrawals?

Begin by limiting ACH debits to what the business actually needs. Consider a debit block for accounts that should not accept them, verified Company ID filters for predictable originators, and ACH positive pay where exception review is appropriate. 

Combine those controls with individual bank logins, MFA, dual approval where available, independent vendor-change verification, account alerts, daily reconciliation, and immediate bank contact when suspicious activity appears.

Conclusion

Stopping unauthorized ACH withdrawals is not about finding one perfect fraud product. It is about deciding which organizations should be allowed to debit each account, configuring the bank accordingly, and making unexpected activity visible quickly.

An ACH debit block provides the most restrictive approach when outside debits should rarely occur. An ACH filter is useful when legitimate originators are predictable and can be identified with verified Company IDs or other supported criteria. ACH positive pay can add an exception-review process when businesses need more flexible oversight.

The controls become much stronger when paired with secure vendor onboarding, independent verification of banking changes, least-privilege access, multifactor authentication, dual approval where available, transaction limits, alerts, daily reconciliation, and documented incident procedures.

Finance teams should periodically ask whether every approved originator still requires access, whether every bank user still needs current privileges, and whether exception alerts are actually reviewed. Corporate treasury fraud prevention depends as much on maintaining controls as installing them.

Most importantly, treat unexpected ACH activity as time-sensitive. Commercial-account procedures and ACH return timing are not automatically the same as consumer protections, so suspicious transactions should be reported to the bank as soon as they are identified. 

Nacha’s current rules and guidance emphasize the distinct treatment of non-consumer unauthorized returns.

A thoughtfully configured combination of ACH debit protection, bank account security, and disciplined financial operations can significantly reduce risk without making legitimate payments unnecessarily difficult.

Disclaimer: This article is for general educational purposes only. ACH rules, bank products, account agreements, return rights, legal obligations, fees, and exception procedures vary by financial institution and transaction. 

Businesses should consult their bank or treasury-management provider and, when appropriate, qualified legal, compliance, accounting, or cybersecurity professionals regarding their specific circumstances.