Small Business Signals

The Payment Fraud Fire Drill: Why Your ACH Runs Need a Two-Person Rule Before June 22

10:12 by The Mentor
ACH fraud controlsNacha June 22 2026small business payment fraudtwo person approval rulevendor bank account change fraudcheck fraud preventionACH fraud monitoring
Disclaimer

This episode is for informational purposes only and does not constitute financial advice. Always consult a qualified financial advisor before making investment decisions.

Show Notes

The Payment Fraud Fire Drill: Put Two Eyes on Every Risky Payment Before June 22

ACH fraud controls, vendor bank changes, and check fraud prevention don’t need to be complicated. They need to happen before money moves.

It’s 4:18 on a Thursday, and Devon is standing outside his HVAC shop with payroll due before breakfast and a supplier already asking about a late invoice. His phone buzzes. Same vendor name. Same tone. New bank details.

One click, one ACH batch, and $18,000 nearly walks out the door.

Nobody hacked Devon’s accounting software. Nobody cracked a password. The scam only needed one believable email to reach one busy person at exactly the wrong moment.

That’s the signal for small business owners right now: payment fraud is becoming less about breaking into your systems and more about tricking your process. And with the Nacha June 22 2026 fraud-monitoring deadline pulling more non-consumer ACH originators into the control conversation, now is the time to build a routine before the fire drill starts.

The scam doesn’t need your password

AFP’s 2026 survey found that 76% of organizations faced attempted or actual payments fraud in 2025. That sounds like an enterprise problem until you remember how small companies actually run.

One person prepares the payment. That same person may approve it. The owner signs off from a truck, a job site, a checkout counter, or a kitchen table at 10:30 PM.

That’s where vendor bank account change fraud thrives. The email looks normal. The invoice number is real. The sender knows the vendor’s name. The request is polite, specific, and urgent enough to make you move fast.

Nacha’s newer rules define fraud under “False Pretenses,” including business email compromise, vendor impersonation, payroll impersonation, and other payee impersonation scenarios. In plain English: fraud that looks like normal business.

Devon’s turning point came in a parking lot. Phone buzzing. Thumb hovering over approve. Mind already on the next broken compressor. That is the moment fraud wants: not your dumbest moment, your busiest one.

June 22 is a deadline, but the habit starts now

Nacha Phase 1 fraud-monitoring rules took effect March 20, 2026, for banks and larger ACH originators above certain volume thresholds. Phase 2 brings other non-consumer ACH originators, third-party senders, and service providers deeper into the same conversation, with a practical compliance date of June 22 because June 19 is a federal holiday.

If you’re a smaller business, don’t hear that and think, “This is for someone bigger.” Small does not mean invisible. Nacha has said a risk-based approach should not be used to decide that no monitoring is needed at all.

Your version of monitoring can be modest. Start with a payment map. List every way money leaves the business: payroll, vendor ACH, rent, refunds, owner draws, bill pay, checks, wires, and card chargebacks.

Then mark three events in red:

- A new vendor - A changed bank account - A payment above your chosen threshold

For Devon, that threshold became $5,000. Not because $5,000 is magic. Because it was high enough to catch painful mistakes without turning every utility bill into a committee meeting.

The two-person rule that fits a small shop

A two-person approval rule is not corporate red tape. For a small company, it’s a seatbelt.

One person enters or prepares the payment. A different person approves it. If you’re an owner-only operation, your accountant, bookkeeper, or trusted admin can be the second checkpoint for higher-risk changes.

The rule Devon wrote into his process was simple: no new destination gets paid until two people verify it through separate channels.

Separate channels matter. Email plus email is not separate. A request by email followed by a callback to a phone number already on file is much stronger.

When Devon received the fake bank change, he called the supplier using an old trusted contact from the onboarding packet, not the number in the email. The real supplier had never changed banks.

That one callback saved the payment.

If you use QuickBooks, Xero, Bill, Gusto, or your bank portal, look for approval workflows. If the software can’t handle it cleanly, use a manual backup: preparer initials, approver initials, callback date, and saved proof in a vendor-change folder.

Devon also built a vendor master list: vendor name, trusted contact, approved bank nickname, last verification date, and who checked it. Nothing fancy. Just enough structure to slow down the exact moment fraud wants speed.

Checks still deserve suspicion

ACH gets plenty of attention because it moves fast, but checks are still a fraud magnet.

AFP reported that 58% of organizations experienced check fraud in 2025. Federal Reserve Financial Services cited AFP’s 2025 survey showing 63% reported check fraud in 2024, while 91% still used checks. Federal Reserve Consumer Compliance Outlook also noted about 680,000 suspicious activity reports for possible check fraud in 2022, a sharp jump from 2021.

Checks expose routing and account information. They sit in mailboxes. They can be copied, washed, altered, or redirected.

If you still need checks, consider Positive Pay, tighter blank-check storage, fewer signers, and secure mailing routines. Store blank checks like cash. Review cleared check images if your bank provides them.

Ask your bank about ACH debit blocks, ACH filters, Positive Pay, wire templates, and same-day alerts for outgoing transactions above your threshold. A $30 monthly control looks different when you compare it with one bad $10,000 payment.

Run the ten-minute fire drill

This week, run one fake vendor change through your current process. Don’t announce the answer first. Ask: who verifies the request, who approves the payment, where is proof saved, and who calls the bank if money moves wrong?

Devon’s team found two gaps in their drill: nobody had the bank’s after-hours number, and refunds had no approval threshold.

That’s the point. A drill is not proof you’re careless. It’s how a careful business gets stronger.

By June 22, aim to have three things written down: a payment map, a two-person approval rule, and a one-page response plan.

This content is for educational and informational purposes only and does not constitute financial advice. Always consult with a qualified financial advisor or business consultant before making significant financial decisions.

Your bank, accountant, and processor can help tailor the controls to your setup. The big move is simple: slow down new bank details, big payments, and urgent requests.

The scam does not need to hack your business if it can trick one person. So don’t leave one person alone with the approve button.

Download MP3