How an ACH payment works
The Automated Clearing House is a batch network operated by the Federal Reserve and The Clearing House under rules written by Nacha, the industry body. Unlike a card authorization, which asks the bank a question and gets an answer in two seconds, an ACH entry is an instruction dropped into a batch, forwarded through the network, and posted by the receiving bank hours later. Nothing is confirmed at the moment of payment; you find out that an entry failed when it comes back.
The parties, in Nacha's vocabulary:
- The Originator is the business initiating the entry. In a debit, that is you, pulling money from the customer's account.
- The ODFI (Originating Depository Financial Institution) is your bank or your payment provider's bank, which submits the entry to the network and is responsible to Nacha for your compliance.
- The RDFI (Receiving Depository Financial Institution) is the customer's bank, which posts the debit or returns it.
- The Receiver is the customer whose account is debited.
Two directions exist. An ACH debit pulls funds from the customer's account on your instruction, which is what "pay by bank account" on an invoice means. An ACH credit pushes funds from the payer's account, which is how payroll and most B2B bill-pay work; the customer initiates it from their own bank and you simply receive it. Debits are what a payment platform handles for you; credits are what your customer's accounts-payable department sends.
A typical debit timeline: the customer authorizes on Monday, the entry is submitted Monday afternoon, the customer's bank posts it Tuesday, funds are available to you Tuesday or Wednesday depending on your provider's policy, and the ordinary return window closes Wednesday. Nothing about the payment is final until the return windows pass.
SEC codes: how the customer authorized decides the rules
Every ACH entry carries a three-letter Standard Entry Class code that describes how the authorization was obtained. The code determines what authorization you must hold, whether the account is consumer or business, how long the customer has to dispute, and what your provider will let you do. Getting it wrong is the most common ACH compliance failure.
| SEC code | Used for | Authorization required | Notes |
|---|---|---|---|
| PPD Prearranged Payment and Deposit | Consumer accounts, authorization obtained in writing (paper or electronic signature) | Signed authorization, retained for two years after it ends | The classic recurring debit: gym memberships, insurance premiums, installment plans signed on paper or by e-signature. |
| CCD Corporate Credit or Debit | Business accounts | An agreement between the two businesses; Nacha does not prescribe the form | B2B invoices. Business customers have far shorter return rights than consumers (see returns). |
| WEB Internet-Initiated / Mobile | Consumer accounts, authorization obtained online or on a mobile device | Electronic authorization with the required disclosures, plus account validation and a commercially reasonable fraud detection system | Payment links, hosted checkout and customer portals. Since 2021 the first debit to a new account must be preceded by validating the account (see below). |
| TEL Telephone-Initiated | Consumer accounts, authorization obtained by phone | Recorded oral authorization, or written confirmation sent before settlement; single or recurring must be stated | Phone orders where the customer reads out routing and account numbers. Only permitted with an existing relationship or a customer-initiated call. |
| ARC / BOC / POP | Paper checks converted to ACH at the lockbox, back office, or point of purchase | The check itself plus posted notice | Check conversion; rare for businesses that take payments online. |
| CTX Corporate Trade Exchange | Business accounts, with remittance data attached | As CCD | B2B payments carrying invoice detail; more common for credits. |
Nacha Operating Rules; the codes shown are the ones a business taking payments will encounter.
Two practical rules follow. If the account is a business account, use CCD; a consumer code on a business account gives the customer consumer return rights they should not have, and the reverse exposes you to an R05 return for using a corporate code on a consumer account. And if the authorization was collected on a web page, it is WEB and the account validation rule applies whether or not the payment is recurring.
What a valid authorization contains
Because there is no real-time check with the customer's bank, the authorization record is your only defense if a debit is disputed. Nacha requires the authorization to be clear and readily understandable, and for consumer debits it must state:
- The customer's name and the account to be debited (routing and account number, or the last four digits for a stored account).
- The amount, or for variable amounts, how the amount will be determined and how the customer will be notified.
- The timing: a single debit on a date, or a recurring schedule with the start date and frequency.
- Whether the authorization is for a single entry or recurring entries.
- How the customer can revoke the authorization, and how far in advance.
- For WEB, that the customer authorizes the business to debit the account electronically, and the language that a returned entry may incur a fee if you charge one.
The customer must receive a copy (on screen with the ability to print or save counts). You must keep the authorization for two years after it terminates and be able to produce it within ten banking days when your ODFI asks, which it will whenever a customer claims a debit was unauthorized.
Account validation for WEB debits
Since March 2021, the first WEB debit to an account, and the first after any change to the account number, must be preceded by validating that the account is open and can accept debits. Accepted methods include instant account verification through a bank-login service, micro-deposits that the customer confirms, a prenotification entry (a zero-dollar ACH that returns if the account is bad), or a validation service that checks the account against a database. Micro-deposits add two or three days before the first payment; instant verification adds thirty seconds and is what most platforms use for a payment link.
Changing amounts and dates
For recurring consumer debits, a change to the amount requires notice to the customer at least ten calendar days before the debit (or a written range the customer agreed to). A change to the date requires seven days' notice. A debit that is larger than the notified amount or earlier than the agreed date is an R10 waiting to happen.
Settlement, same-day ACH and funds availability
Standard ACH settles on the next banking day for entries submitted before the provider's cutoff, and the day after that for entries submitted later. Since 2016, same-day ACH allows entries submitted in one of three daily windows to settle the same day; the per-payment limit was raised to $1 million in 2022. Providers charge a small premium for same-day entries and set their own cutoffs ahead of the network's, which are early morning, early afternoon and late afternoon Eastern.
Settlement is not the same as availability. Your provider decides when settled funds reach your account, and most hold ACH debits for one to several days beyond settlement because the entry can still be returned. A typical schedule:
| Step | Standard ACH | Same-day ACH |
|---|---|---|
| Customer authorizes and entry is submitted | Day 0 (before cutoff) | Day 0 (before a same-day window) |
| Entry posts to the customer's account | Day 1 | Day 0 |
| Ordinary returns (R01, R02, R03, R04 and most others) must be received by | Day 3 (two banking days after settlement) | Day 2 |
| Funds typically available to the business | Day 2 to Day 4, depending on provider risk policy | Day 1 to Day 3 |
| Extended returns (unauthorized, consumer) may still arrive until | Day 60 from settlement | Day 60 from settlement |
Banking days exclude weekends and Federal Reserve holidays, so a Friday afternoon submission posts on Monday at the earliest.
For comparison, a card payment is authorized instantly, settles in one or two days, and is subject to chargebacks for 120 days or more. The card's advantage is certainty at the moment of sale; ACH's advantage is that once the short return window closes, most payments cannot come back at all.
Returns: the codes, the deadlines and the thresholds
An ACH debit that cannot be posted, or that the customer disputes, comes back as a return with a code. Returns are the ACH equivalent of declines and chargebacks combined, and the code tells you which.
| Code | Meaning | Return window | What to do |
|---|---|---|---|
| R01 | Insufficient funds | 2 banking days | The ACH equivalent of a soft decline. You may resubmit up to two more times within 180 days, marked as a retry ("RETRY PYMT" in the description). Most businesses retry once after a few days. |
| R02 | Account closed | 2 banking days | Hard. Get new account details. |
| R03 | No account / unable to locate | 2 banking days | Hard, usually a typo. Re-collect and validate the account. |
| R04 | Invalid account number structure | 2 banking days | Hard, data error. Validate before resubmitting. |
| R05 | Unauthorized debit to a consumer account using a corporate SEC code | 60 days | You used CCD on a consumer account. Refund is automatic; fix the SEC code. |
| R07 | Authorization revoked by customer | 60 days | The customer told their bank they revoked. Stop all further debits under that authorization immediately. |
| R08 | Payment stopped | 2 banking days | The customer placed a stop payment on this entry. Contact the customer; do not resubmit without a new authorization. |
| R09 | Uncollected funds | 2 banking days | Deposits not yet cleared. Treat as R01. |
| R10 | Customer advises: not authorized, or originator not known | 60 days | The consumer version of a fraud chargeback, except there is no representment: the return stands. Produce the authorization to your ODFI if asked, and never debit that account again without new authorization. |
| R11 | Customer advises: entry not in accordance with the authorization | 60 days | The authorization exists but the debit was wrong: wrong amount, wrong date, debited after revocation. Since 2020 this is separate from R10. You may correct and resubmit within 60 days. |
| R16 | Account frozen | 2 banking days | Legal or bank action. Contact the customer. |
| R20 | Non-transaction account | 2 banking days | A savings or other account that does not accept ACH debits. Get a checking account. |
| R29 | Corporate customer advises not authorized | 2 banking days | The business-account version of R10. Note the short window: business customers get two days, not sixty. |
Return windows run from the settlement date. R05, R07, R10 and R11 are the "extended" consumer returns; everything else must come back within two banking days.
The return-rate thresholds
Nacha holds originators to three limits, measured over a rolling 60 days, and ODFIs will suspend an originator that breaches them:
| Category | Return codes counted | Threshold |
|---|---|---|
| Unauthorized | R05, R07, R10, R11, R29 | 0.5% of debit entries |
| Administrative | R02, R03, R04 | 3% |
| Overall | All returns | 15% |
The unauthorized limit is the one that matters. Half a percent is low, and a single bad month of misdated debits (R11) or of debiting cancelled customers (R07) can breach it. Account validation, clean SEC codes and honoring revocations the day they arrive keep it near zero.
Reversals
A business may reverse its own erroneous entry (duplicate, wrong amount, wrong account) within five banking days of settlement, with notice to the customer. Reversals are for your mistakes only; using one to claw back a legitimate payment violates the rules.
What ACH costs
| Item | Typical cost | Notes |
|---|---|---|
| Per-debit fee | $0.20 to $1.50 flat | The headline number. Some providers instead charge 0.5% to 1% with a cap (often $5 to $10), which is still far below cards on anything over a hundred dollars. |
| Same-day surcharge | $0.50 to a few dollars per entry | Optional; only when you need same-day settlement. |
| Return fee | $2 to $10 per return | Charged on every return regardless of reason. |
| Account validation | $0.30 to $1.50 per verification, or included | Instant verification services charge per account; micro-deposits are usually free but slow. |
| Monthly fee | $0 to $30 | Often bundled with card processing. |
| Reserve or hold | Days of float rather than dollars | Providers hold funds against the return window; the delay is a cost. |
Typical US pricing at the time of writing.
Against a card at 2.5 to 3 percent, ACH wins on cost at roughly $30 and above, and the gap grows with the ticket: on a $5,000 invoice the difference is around $125 per payment. The cost of ACH shows up elsewhere: slower certainty, the handling of returns, and the customer-side friction of entering bank details, which is why the decision is by payment type rather than all-or-nothing.
ACH and cards side by side
| Card | ACH debit | |
|---|---|---|
| Cost | 1.5% to 3.5% plus a per-item fee | Flat $0.20 to $1.50, or a small percentage with a cap |
| Confirmation at time of payment | Instant approve or decline | None; failures arrive as returns in one to three days |
| Settlement | 1 to 2 days | 1 to 2 days standard; same day available |
| Funds availability | Usually next business day | 2 to 4 days as providers hold against returns |
| Failure rate | 5% to 15% declines on card-not-present | Typically 1% to 3% returns, mostly R01 |
| Dispute rights | Chargebacks for 120 days or more, with representment | Consumer: unauthorized returns for 60 days, no representment. Business: 2 days |
| Customer friction | Card number, expiry, CVV; wallets make it one tap | Routing and account number, or a bank login; higher abandonment for first-time payers |
| Recurring | Stored credentials, account updater keeps cards current | Bank accounts rarely change; authorization rules for amount and date changes |
| Limits | Card limits set by the issuer | Same-day capped at $1M per entry; provider limits per debit and per day |
| Best for | Retail, e-commerce, small tickets, first-time customers, anything needing instant confirmation | Invoices above a few hundred dollars, B2B, rent and tuition, installment plans, repeat customers |
Two other rails deserve a sentence. Real-time payments (RTP and FedNow) settle in seconds and are final immediately, but they are credit-push only: the customer sends the money from their bank, so they suit invoices the customer pays proactively rather than debits you initiate. Wire transfers are final, expensive and manual, and remain the tool for very large one-off payments.
A decision table
| Payment | Recommendation | Why |
|---|---|---|
| Retail or restaurant sale | Card | Instant confirmation; small tickets where a flat ACH fee is not much cheaper anyway. |
| E-commerce order to a new customer | Card, with ACH as an option above a threshold | Cards convert better; ACH friction costs more sales than it saves in fees on small orders. |
| Invoice under $200 | Card by link | Speed and certainty matter more than a few dollars. |
| Invoice from $200 to $2,000 | Offer both; default to ACH for repeat customers | ACH saves $5 to $60 per invoice; a repeat customer with a stored bank account has no friction. |
| Invoice above $2,000, B2B | ACH, with card as a surcharged alternative where permitted | Card fees are large; business customers expect ACH; business-account returns close in two days. |
| Rent, tuition, dues, installment plans | ACH (PPD or WEB), card as fallback | Predictable recurring amounts, low return rates, bank accounts do not expire. |
| Deposits and down payments | Card | Immediate confirmation before work starts or goods ship. |
| Phone orders | Card by text-to-pay link, or ACH link for large amounts | Avoid TEL debits: keyed bank details over the phone carry the same risks as keyed cards plus the recorded-authorization burden. |
| Refunds | Same rail as the original payment | Card refunds go to the card; ACH refunds are credit entries to the same account. |
Running ACH well
- Collect bank details on a hosted page, never by email or on paper, and validate the account instantly before the first debit.
- Use the right SEC code: WEB for online authorization, PPD for signed forms, CCD for business accounts, TEL only for genuine phone authorizations with a recording.
- Store the authorization with the customer record: the text shown, the timestamp, the IP address, the account last four, and the schedule. Keep it two years past the end.
- Show the debit clearly on the customer's statement: your business name in the company name field and the invoice reference in the description. "Not recognized" is the leading cause of R10.
- Notify before variable or changed debits: ten days for an amount change, seven for a date change, and a reminder before any large scheduled debit regardless.
- Handle returns by code: retry R01 and R09 once or twice, re-collect on R02 through R04 and R20, stop immediately on R07, R08, R10 and R29, and correct and resubmit on R11.
- Track the three return ratios monthly, especially unauthorized returns against the 0.5 percent line.
- Do not release goods or services on submission for new customers. Wait for the ordinary return window to pass, or take a card for the first payment and ACH after.
- Tokenize bank accounts as you would cards, so repeat debits and refunds run against a saved token and account numbers never sit in your systems.
Where FloPay fits
FloPay ACH puts a bank-account option next to the card option on the same hosted page, whether the customer arrives by text, email or invoice link, validates the account, stores it as a token for repeat debits, and tracks settlement and returns across every connected gateway so a return is matched to the original payment automatically. Installment plans and subscriptions can run on a saved bank account instead of a card, and reconciliation normalizes ACH settlement timing alongside card batches so the ledger matches the bank.
Put a bank-account option on every invoice
FloPay ACH validates the account, stores it as a token, and tracks settlement and returns next to your card payments on any gateway. Ask us what your last quarter of invoices would have cost on ACH.
See ACH Payments