Nacha Return Rate Thresholds: 0.5%, 3%, and 15% Rules

Nacha enforces three return rate thresholds on businesses that originate ACH debits: 0.5% for unauthorized returns, 3.0% for administrative returns, and 15.0% for overall returns. Cross any one of them and Nacha opens an inquiry through your bank; keep crossing them and you face per-transaction fees, fines from the Rules Enforcement Panel, and potential removal from the ACH network.

What Each Threshold Measures

The three limits apply to ACH debit transactions and are measured over a rolling 60-day period or two calendar months. Your Originating Depository Financial Institution (ODFI) — the bank that sends payments on your behalf — is on the hook for making sure you stay within them.

  • The 0.5% unauthorized return rate means no more than 1 in 200 debits should come back marked unauthorized. Nacha watches this one most closely because unauthorized debits mean consumers say they never approved the withdrawal.
  • The 3.0% administrative return rate covers returns caused by basic data errors: closed accounts, invalid account numbers, accounts the receiving bank cannot locate.
  • The 15.0% overall return rate captures virtually every return reason code combined. Re-presented check (RCK) entries and their returns may be excluded from both the numerator and denominator.
  • ul>

    The calculation is a simple ratio: returned debits in the category divided by total debit entries originated during the preceding 60 days or two calendar months.1Nacha. Administrative or Overall Return Rate A business running 10,000 debits a month with 60 unauthorized returns across two months sits at 0.3% and is safe. At 110 unauthorized returns the rate hits 0.55%, and the threshold is breached.

    Which Return Codes Count Toward Each Threshold

    Not every ACH return code counts against the same limit. Knowing which codes land where tells you whether you have an authorization problem, a data quality problem, or both.

    Unauthorized Return Codes (0.5%)

    The unauthorized rate covers return reason codes R05, R07, R10, R29, and R51.2Nacha. ACH Network Risk and Enforcement Topics Nacha also added R11 to the unauthorized return rate definition when it differentiated unauthorized return reasons.3Nacha. Differentiating Unauthorized Return Reasons

    • R05: A consumer account was debited without proper authorization.
    • R07: Authorization existed but was revoked before the transaction posted.
    • R10: The consumer disputes the debit as unauthorized and the receiving bank obtains a written statement.
    • R11: Authorization exists, but the payment doesn’t match the agreed terms (wrong amount, wrong date). Nacha treats R11 the same as R10 for threshold and fee purposes.3Nacha. Differentiating Unauthorized Return Reasons
    • R29: The originator is not authorized by the receiver’s bank to debit the account.
    • R51: A re-presented check entry was ineligible for RCK processing.

    The pattern across all six is the same: either the account holder never agreed to the withdrawal or the withdrawal broke the terms of the agreement that did exist. A spike in R07 or R10 almost always points to weak authorization procedures on your end.

    Administrative Return Codes (3.0%)

    The administrative rate tracks R02 (closed account), R03 (no account or unable to locate), and R04 (invalid account number).1Nacha. Administrative or Overall Return Rate These are data hygiene problems, not fraud. Persistent hits usually mean stale account information or missing validation before entries are submitted.

    Overall Return Codes (15.0%)

    The overall rate includes every return reason code, from insufficient funds (R01) to stopped payments (R08) to the unauthorized codes above, rolled into a single number.1Nacha. Administrative or Overall Return Rate The only carve-out is that RCK entries and returns may be excluded from both sides of the fraction.

    The $4.50 Unauthorized Entry Fee

    Threshold monitoring is not the only cost. Nacha imposes a $4.50 fee on every ACH debit returned as unauthorized.4Nacha. Improving ACH Network Quality – Unauthorized Entry Fee The ODFI pays it to the Receiving Depository Financial Institution, and most ODFIs pass the charge directly through to the originator.

    The fee applies to R05, R07, R10, R29, R51, and R11 returns.3Nacha. Differentiating Unauthorized Return Reasons It does not apply to International ACH Transactions.4Nacha. Improving ACH Network Quality – Unauthorized Entry Fee ACH Operators collect and distribute these fees monthly through participating banks’ billing statements. The fee applies to every unauthorized return, whether or not you have crossed the 0.5% line, so a business with volume can accumulate meaningful costs well before it triggers formal monitoring.

    What Happens When You Breach a Threshold

    Nacha’s Unauthorized Return Monitoring Program is the main enforcement tool for the 0.5% limit. When automated systems detect an originator or third-party sender above the threshold, Nacha notifies the ODFI, which then has to investigate its client and explain the spike.

    A vague response will not close the file. Nacha expects a detailed account of what went wrong and how the originator will fix it. If the rate stays elevated through a second consecutive measurement period, scrutiny intensifies. Persistent breaches escalate to the ACH Rules Enforcement Panel, which decides whether to impose a fine and can direct the ODFI to suspend the offending originator. Administrative and overall rate breaches trigger a parallel inquiry process at the 3.0% and 15.0% levels.1Nacha. Administrative or Overall Return Rate

    All violations are treated as alleged until the originator and its ODFI have had a chance to respond. First-time violations most often draw a warning letter. Repeat violations move to the Panel, which sets fine severity based on the violation level, how egregious the conduct was, and how cooperatively the ODFI responded.5Nacha. How Nacha Enforces Its Rules

    Suspension is the outer edge, and it stings beyond the transaction stop. Nacha maintains a Terminated Originator Database that other financial institutions consult, so a suspended business cannot easily switch banks and resume originating.

    Responding to a Nacha Inquiry

    Once an ODFI receives an inquiry, the response must include the originator’s legal name and identification number, the exact timeframe of the breach, and a comparison of total entries originated against the number of returns.

    The centerpiece is the root cause narrative. “System error” will not satisfy Nacha’s review team. The narrative has to identify the specific circumstances behind the spike: stale account data, a vendor change that introduced errors, a marketing campaign that pulled in customers who did not understand they were authorizing recurring debits, or an actual authorization defect. Nacha wants evidence that the originator understands the cause, not just the effect.

    Alongside the narrative, the originator submits a remediation plan with concrete steps to bring the rate back below the threshold. For third-party senders, Nacha’s certification criteria require written notice within 30 days of learning that a threshold has been exceeded, plus a correction plan and timeline.6Nacha. Nacha Third-Party Sender Certification Program Criteria

    A useful remediation plan fixes the cause, not the symptom. If unauthorized returns spiked because authorization language was confusing, the answer is rewriting the authorization, not scrubbing the return file faster. Typical steps include real-time account validation, clearer consumer disclosure and authorization workflows, tighter data entry controls, and internal dashboards that flag return rates daily. Once Nacha accepts the plan, an evaluation period follows during which the originator must show sustained improvement. Missing the agreed targets can push the file to the Rules Enforcement Panel; completing the evaluation restores normal operations.

    Your ODFI Is Watching Too

    The ODFI is not a passive conduit. Under the Nacha Operating Rules, the sending bank is responsible for the quality of the entries it originates and for the conduct of its clients.1Nacha. Administrative or Overall Return Rate Many ODFIs set internal triggers well below Nacha’s numbers, cutting off originators at 0.3% unauthorized rather than waiting for the 0.5% breach.

    Third-party senders, which process ACH payments on behalf of other businesses, carry their own monitoring duties. Nacha rules require them to monitor forward and return transaction volumes, dollar amounts, and rates as part of their risk management programs.7Nacha. Third-Party Sender Roles and Responsibilities When a client generates excessive returns, the sender is expected to identify and investigate the problem on its own initiative.

    A New Fraud Monitoring Layer in 2026

    Starting March 20, 2026, Nacha’s new fraud monitoring rule (Phase 1) requires all ODFIs and large-volume originators and third-party senders (those with 6 million or more ACH originations in 2023) to implement risk-based processes for identifying entries suspected of being unauthorized or authorized under false pretenses. Phase 2, effective June 19, 2026, extends the requirement to all remaining non-consumer originators and third-party senders, along with all RDFIs.8Nacha. RISK MANAGEMENT TOPICS – Fraud Monitoring Phase 1

    The rule does not prescribe a specific technology or process. Each party establishes procedures relevant to its role in originating or transmitting entries and reviews them at least annually. When monitoring flags a suspicious transaction, the ODFI can stop processing the entry, consult with the originator about its validity, coordinate with internal fraud teams, or contact the receiving bank to check whether the receiver’s account is showing warning signs.8Nacha. RISK MANAGEMENT TOPICS – Fraud Monitoring Phase 1 For an originator already close to any of the three return rate thresholds, this rule is another lens that makes proactive monitoring the safer bet.