Est.

How to Make an ACH Payment

Step through the exact sequence and timing of moving money between bank accounts without a card.

Editorial team · · 11 min read
Cover illustration for “How to Make an ACH Payment”
Payments Automation · September 18, 2026 · 11 min read · 2,466 words

ACH stands for Automated Clearing House, and it moves money directly between bank accounts without a card network or a paper check anywhere in the process. It sounds simple because, at a mechanical level, it is. What trips people up isn't the concept, it's the sequence: what to gather, what order to submit things in, and what to do when a payment stalls or bounces back. Nacha, the nonprofit that writes the rulebook, and two operators, the Federal Reserve and The Clearing House, run the plumbing that makes these payments happen. In 2025, that plumbing moved 35.2 billion payments worth $93 trillion, the 13th straight year total value climbed by at least a trillion dollars.

Business-to-business volume alone hit 8.1 billion payments in 2025, a sharp jump of 9.9% from the year before. That's not a rounding error. ACH has become a default rail for how companies pay each other. Part of the reason is cost: ACH processing runs $0.20 to $1.50 per transaction, compared to 1.5% to 3.5% for credit cards. Running payroll, paying vendors, or billing subscribers through a card network at those rates makes the math stop making sense fast. Payroll direct deposit, vendor invoices, subscription billing, tax payments, loan payments, utility bills, these are the workhorses, and most of them fall into one of two buckets: a one-time send with no standing permission, or a recurring pull that runs on a schedule under a single authorization signed once.

The two directions an ACH payment can travel: credit and debit

Every ACH transaction moves as either a credit or a debit, and mixing these up is where a lot of first-time confusion starts.

An ACH credit is a push. The payer sends money out: an employer funding payroll, a company paying a vendor, or a refund going back to a customer. The payer starts the transaction. An ACH debit is a pull, and it works the other way: a business reaches into a customer's account and takes payment, but only because that customer signed off on it beforehand. Subscription billing, recurring invoices, loan payments, and utility bills run this way.

The distinction changes the clock, too. ACH credits and debits follow different timing tracks, with debits generally posting sooner, but funds availability can lag behind in either case because banks run extra verification and have to account for the risk that the account doesn't have the money. Recurring debits carry a legal requirement most people underestimate: prior written or online authorization has to exist before a single dollar gets pulled. That's not a best practice, it's baked into Nacha's rulebook. There's also a third variant, the eCheck, which is really a paper check reimagined as an ACH debit. Online checkouts and invoice portals use it constantly, and it rides the exact same rails as everything else described here.

Knowing which direction applies before touching a keyboard determines what information gets collected and which platform makes sense. That's the next problem to solve.

What to gather before initiating a transfer

Four pieces of recipient data make or break the transaction. The full legal name or registered business name must match exactly as it sits on the bank account, along with the account number, the nine-digit routing number that identifies the recipient's bank, and the account type, checking or savings, since the network uses different transaction codes depending on which. Adding the exact payment amount and a short description, an invoice number or a service label, covers the recipient side.

The sender side has its own checklist. There needs to be a verified account with enough available funds sitting in it, access to online banking or a payment platform, authorization from whoever owns the account if it's a business account, and a clear read on whatever daily or monthly transfer limits the bank has set. A first transfer to a new recipient often involves a verification step, such as micro-deposits or a linked-account confirmation through secure banking authentication. First-time recipients should expect that step to add a day or two before anything moves.

Verify banking details through a phone call or a secure vendor portal, never through email alone. Email is exactly where fraudsters plant fake routing numbers, counting on someone to copy and paste without a second look. That single habit connects directly to the fraud controls Nacha now requires, covered further down.

The five steps to send an ACH payment

Once the information is in hand, the process itself breaks into five steps, and none of them are complicated on their own.

Step 1: Gather the recipient's bank details. Full name, routing number, account number, account type, all confirmed through a trusted channel, not an email attachment.

Step 2: Log in to a bank or payment platform. Three channels handle this differently. A bank's own online portal or app works fine for one-off transfers or businesses paying a handful of vendors directly. A payment processor makes more sense when recurring billing and reconciliation need to run automatically. Accounting-software integrations earn their keep when payments need to sync straight into the books and match against invoices without someone re-keying data.

Step 3: Find the transfer or ACH section. The navigation labels vary, "Transfer & Pay," "Pay & Transfer," "Wires & ACH." Paying someone new usually means clicking "add external account" or "new recipient" and entering their banking details there.

Step 4: Enter and review the payment details. Routing number, account number, recipient name, account type, amount, payment date, and a memo line for the books. This is the step where a typo turns into a rejected payment or, worse, money landing in a stranger's account. Slow down here.

Step 5: Submit and confirm. Save the confirmation number, screenshot it if the platform allows, and note the expected settlement date based on when the submission cleared relative to the day's cutoff. Setting up recurring billing adds one more sub-step here, saving the authorization itself and scheduling the cadence. Under Nacha's rules, that single authorization covers every future withdrawal tied to it, so getting it wrong once means every subsequent withdrawal built on it is compromised.

How ACH processing moves the payment from submission to settlement

What happens after Step 5 gets submitted isn't instant, and it isn't a black box either. It moves through five distinct stages, and each one has its own timing quirks.

Day 0 starts with initiation and batching: payment requests get formatted into standardized Nacha files, and banks group transactions into batches. Missing the daily cutoff rolls the whole batch to the next business day. From there, the originating bank (the ODFI) transmits those batched files to an ACH operator, either the Federal Reserve or The Clearing House, sorted by receiving bank. This happens multiple times a day during business hours, not just once overnight.

On the receiving end, the RDFI takes in the files and runs initial validation, checking account numbers and routing, while risk systems scan for anything that looks suspicious. Valid transactions get queued for posting. Settlement itself happens through FedACH or The Clearing House's Electronic Payments Network, the two national ACH operators, debiting the sender's account and crediting the recipient's. Funds availability is the last piece, and it varies: banks apply their own policies based on account history, large transactions can trigger manual review, and first-time recipients tend to face extra delay here too.

Most ACH payments clear within one to three business days start to finish. Same-Day ACH exists for anything more urgent, posting the same business day if it's submitted before cutoff, typically somewhere between 10:30 AM and 4:45 PM Eastern. It costs more, $0.50 to $10.00 per transaction depending on the institution and volume, but that's still far cheaper than a wire. The per-transaction cap on Same-Day ACH is $1 million as of 2026, and Nacha has already approved raising that ceiling to $10 million starting September 17, 2027.

A few timing traps can catch people off guard. The ACH network doesn't currently settle on weekends or federal holidays, so a payment submitted Friday afternoon may not start processing until Monday morning. And individual banks often set their own internal cutoffs 30 minutes to two hours ahead of the network's actual deadline. Missing a bank's cutoff by five minutes can cost a full extra business day.

Common ACH payment problems and their resolutions

Most ACH headaches trace back to a small number of root causes, and each one has a fairly direct fix.

Wrong routing or account numbers cause outright rejection or, in the worse case, misdirected funds. The fix is re-verifying through a trusted channel and resubmitting, since not every bank catches every typo before processing. Insufficient funds on the originating account will get an ACH debit rejected outright and can trigger return fees, so confirming balances ahead of time and setting up low-balance alerts heads that off.

Nacha also holds originators to an unauthorized return rate below 0.5%. Crossing that threshold triggers a compliance review, so any business running a recurring debit program needs to watch that number the way it watches cash flow.

Canceling a payment is possible, but only in a narrow window, before the ODFI actually submits the batch. Once it's submitted, a reversal entry has to be initiated instead, and Same-Day ACH leaves almost no room to catch a mistake before it's gone. That narrow window is why fraud prevention has to happen before submission, not after.

Business email compromise, vendor impersonation, and payroll diversion are the specific fraud patterns Nacha's 2026 rules target. All three work the same basic way: someone substitutes fraudulent banking details for real ones, usually through a convincing email. Verifying details through a phone call or a secure portal isn't optional anymore, it's a named control. Multi-factor authentication on banking platforms, callback verification any time a vendor's banking details change, and regular monitoring of return codes for patterns round out the practical defenses.

Nacha's 2026 rule changes for every ACH originator

ACH fraud, particularly credit-push schemes, vendor impersonation, and business email compromise, has climbed enough that Nacha rewrote its approach. Instead of selective monitoring aimed at specific participants, the new rules apply a risk-based standard across every non-consumer participant in the network.

The rollout comes in two phases. Starting March 20, 2026, originators have to use two newly standardized payment descriptions, PAYROLL for PPD entries and PURCHASE, cutting down on the reconciliation guesswork that vague descriptions used to cause. Then, effective June 22, 2026 (the practical date, since June 19 falls on a federal holiday), fraud monitoring requirements extend network-wide. Every relevant party has to build risk-based processes designed to catch suspicious transactions before they're released, not after.

Nacha explicitly names business email compromise, vendor impersonation, and payroll diversion as the scenarios these rules target, and the old "commercially reasonable" standard, always a bit fuzzy, is gone. What replaces it is a "false pretenses" standard that demands documented, documented procedures. Auditors are going to expect structured, time-stamped digital evidence, not an email thread someone can dig up if asked. The 0.5% unauthorized return rate threshold stays in place alongside all of this.

For finance leaders, the shift is from passive observation to active, documented compliance. That means keeping records of the processes used to catch suspicious entries, proof those processes actually ran, and a log of any flagged transaction along with how it got resolved. Trust-based habits, the kind built on a phone call and a handshake, now need a paper trail behind them.

Agentic AI's impact on ACH payment execution for banks and credit unions

Agentic AI, in payments terms, means software that takes a goal, breaks it into tasks, and acts on digital systems with limited human input at each step. Instead of a person clicking through every stage of a transfer, an agent handles initiation, chooses the best rail among ACH, RTP, SWIFT, or card networks, runs compliance checks, watches for settlement, and manages exceptions afterward, often in one continuous sequence.

Collections teams have historically absorbed a lot of manual grind here: watching return codes, chasing exceptions, tracking payment status one transaction at a time. That's precisely the category of work these agents are built to take over. Adoption numbers back up how fast this is moving. Capgemini's World Payments Report 2026 found 60% of paytech firms have already deployed generative AI to run payment operations more effectively. Credit unions, notably, are ahead of banks: Cornerstone Advisors' 2026 survey found 59% of credit unions have moved generative AI into production, against 49% of banks. Agentic AI specifically has already reached board-level discussion at more than half the institutions surveyed.

Vendors are responding accordingly. Kore.ai's 2026 roundup names Boost.ai, ServiceNow, Salesforce, and other platforms building out this space for banking and finance. Oracle Financial Services launched a suite of AI-infused applications, design tools, and pre-built agents in February 2026, aimed at conversational interfaces and autonomous execution across online, mobile, and branch banking.

The institutions gaining the most ground are the ones deploying agents that execute actual transactions, payments, transfers, account analysis, on top of existing banking rails, with a full audit trail and controls a compliance team can actually configure. That approach lines up almost exactly with what Nacha's 2026 rules now demand: documented, active, governed execution instead of passive after-the-fact monitoring. Legacy core systems are becoming the real bottleneck here. A number of credit unions are hitting a point where fragmented, older infrastructure simply can't support real-time AI-driven operations, which is part of why the more workable path is layering agents on top of existing rails rather than ripping out the core and starting over.

Governance and auditability requirements for AI executing ACH payments

Handing ACH execution to an autonomous agent doesn't loosen the compliance bar, it raises it. Every requirement Nacha put in writing for 2026, the false-pretenses standard, the documented risk-based processes, the sub-0.5% unauthorized return threshold, still applies in full when a machine is the one clicking submit.

That raises a fair question: what does "documented" even mean when no human touched the transaction? At minimum, it means an institution needs a real-time, time-stamped record of what the agent decided, what data it acted on, and why it flagged (or didn't flag) a given transaction as suspicious. Auditors already expect structured digital evidence over ad hoc notes; a payment carried out by an automated system can't fall back on a "someone reviewed it" explanation if no one did.

Governance, in other words, isn't a separate concern from adoption, it's the condition for adoption holding up under scrutiny. An institution moving payment execution to an agent needs the same audit trail Nacha's rules already require of any originator, just generated automatically instead of manually. Whether that record satisfies an examiner depends on how well it's structured, not on how sophisticated the underlying model happens to be.

Sources

  1. 2026 Small Business Guide to ACH Payments - Emburse
  2. How ACH Payments Work: Settlement & 2026 Compliance Guide
  3. stuut.ai
  4. nacha.org
  5. corporatecomplianceinsights.com
  6. nacha.org
  7. larsco.com
  8. nacha.org

More in Payments Automation