
The workload
A SaaS founder billing customers by ACH bank debit instead of card takes on a rule that card payments do not carry: before debiting a customer's bank account for the first time, or after any change to that account number, NACHA's own rule page for Supplementing Fraud Detection Standards for WEB Debits requires the originator to validate that "the account to be used is a legitimate, open account to which ACH entries may be posted at the RDFI." NACHA is explicit that validating existence is not the same as verifying ownership: the rule "does not require verification of account ownership — only that the account exists and accepts ACH transactions."
What the documents show
Verified: NACHA's own Account Validation Resource Center states the rule's effective date as "March 19, 2021," after the board pushed back an originally approved January 1, 2020 start "to allow additional time, education and guidance to be provided to the industry." Verified, same source: NACHA also allowed "an additional period of one year from the effective date" during which it would not enforce the rule against originators "working in good faith toward compliance," meaning real enforcement pressure began closer to March 2022 than March 2021. Verified: the rule is explicitly risk-based rather than prescriptive — NACHA's page states "the Rule is neutral regarding specific methods or technologies used" and lists acceptable approaches (prenotification entries, ACH micro-transaction verification, third-party validation services, or prior successful payment history) as examples, not requirements.
The operating cost
Neither NACHA page states a dollar cost of compliance; validation is typically bought as a service from a bank or a third-party vendor whose own pricing page, not NACHA's rule text, states the fee per lookup or per month. Estimated: for a low-volume SaaS business using ACH only for annual or high-value invoices, the marginal cost is small per transaction but recurring for every new bank account a customer adds, since the rule requires validation before first use and again after any account-number change, not once per customer relationship.
The stop condition
Verified: the obligation to validate does not expire — it applies at every first use and every account change, with no stated sunset. Editorial: the point at which a business should upgrade from a manual or prenotification-based approach to a paid validation service is a volume and fraud-loss threshold NACHA's rule does not set; it only sets the requirement to validate something.
- Does this business's ACH originator or payment processor already perform account validation automatically, or is that step being skipped?
- Which validation method is actually in use, and does it get reapplied when a customer updates their bank details?
- Is the business still inside, or already past, the one-year non-enforcement grace period NACHA described for good-faith compliance efforts?
NACHA wrote a requirement, not a technique. The rule closes the door on skipping validation altogether but leaves the actual method, and its cost, to whatever the originator's bank or processor decides to sell.
Sources & reading trail
NACHA's own summary stating the 19 March 2021 effective date, the one-year non-enforcement grace period, and the risk-based, method-neutral design.
Source published: Not established · Retrieved: 16 September 2026
NACHA's own rule detail page defining what account validation means and confirming it does not require verifying account ownership.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.