Rules 4 min read
What counts as valid ACH authorization?
How Originators must obtain, document, and retain authorization for debits — the single most scrutinized area of any ACH audit.
Authorization is the beating heart of ACH compliance. For any debit to a consumer account, the Originator must have the Receiver’s authorization; that authorization must be in a form the Rules recognize; and the Originator must be able to produce it on request. When auditors talk about the highest-risk area of ACH, they almost always mean authorization — because an unauthorized debit is both a rule violation and, for consumer entries, a potential violation of Regulation E.
What valid authorization requires
The Rules require that a consumer’s authorization be readily identifiable and, for debits, that it clearly and conspicuously state its terms so that the consumer understands what they agreed to.
- Clear terms: the amount (or a clear method for determining it), the timing or frequency of the debits, and how the consumer can revoke the authorization.
- An affirmative act by the Receiver: a signature, a similarly authenticated online consent, or a recorded/confirmed oral authorization, depending on the channel and SEC code.
- Retention: the authorization (or a copy) must be retained for two years following its termination or revocation.
- Producibility: the Originator must be able to provide an accurate copy of the authorization when the ODFI or RDFI requests it.
Authorization by channel
Because the SEC code sets the authorization standard, the practical requirements change with the channel through which you collected consent.
- PPD debits require a written authorization that is signed or similarly authenticated by the consumer.
- WEB debits require an authorization obtained over the internet or a mobile device, plus a commercially reasonable fraudulent-transaction-detection system and validation of the Receiver’s account number.
- TEL debits require an oral authorization that is either recorded or confirmed in a written notice sent to the consumer before settlement.
Retention and record-keeping
Two retention rules dominate this area. First, consumer debit authorizations must be kept for two years after they are terminated or revoked — not two years after they were signed. Second, more generally, records of entries must be retained for six years (Article One). In practice, organizations that centralize authorization storage, tie each authorization to the entries it supports, and index by customer and SEC code find audits dramatically easier, because the single most common request — “show me the authorization for this debit” — becomes a lookup rather than a search.
What goes wrong
The classic finding is simple: a debit exists, but the authorization behind it cannot be located or produced. Others include authorizations that omit revocation instructions, WEB debits with no account-validation control, TEL debits with neither a recording nor a written confirmation, and authorizations retained only until the account closed rather than for two years after revocation. Each of these is avoidable with a documented process and periodic self-testing.
If you cannot produce proof of authorization for a debit, for audit purposes that debit is unauthorized.
A practical rule of thumb used by many ACH auditors
Channel matters
WEB and TEL entries carry heightened requirements — WEB adds fraud-detection and account-validation obligations, and TEL requires either a recording or a written confirmation before settlement. Match your controls to the channel, and keep the authorization for two years after it is revoked.
Frequently asked questions
- How long must I keep ACH authorizations?
- Consumer debit authorizations must be retained for two years after they are terminated or revoked. Note that the clock starts at revocation, not at signing, so an active recurring authorization must be kept for the life of the arrangement plus two years.
- Does a consumer need to sign an ACH authorization?
- For PPD debits, the authorization must be signed or similarly authenticated in writing. For WEB debits, consent is obtained online or via mobile with additional fraud and account-validation controls. For TEL debits, an oral authorization must be recorded or confirmed in writing before settlement.
- What information must an ACH debit authorization include?
- It must clearly state the amount or how it will be determined, the timing or frequency of the debits, and how the consumer can revoke authorization. It must also be readily identifiable and producible on request.
- What happens if I cannot produce an authorization during an audit?
- For audit purposes, a debit whose authorization cannot be produced is treated as unauthorized. That can result in a finding, contribute to your unauthorized return rate, and for consumer entries raise Regulation E exposure.
- Do business-to-business (CCD) debits need the same authorization?
- CCD debits are governed by the agreement between the trading partners rather than the consumer authorization rules that apply to PPD, WEB, and TEL. You should still have a documented agreement authorizing the debits.
Go to the source
Use Nacha's official resources to confirm current requirements and effective dates.
This resource is published by Clusia for educational purposes and is not legal, accounting, or compliance advice. This site is independent of Nacha. Always confirm requirements against the current Nacha Operating Rules and your own institution's policies.