Nacha Phase 2 (June 22, 2026): What Changes for QuickBooks Online Bill Pay Users
If you run accounts payable in QuickBooks Online, you have probably heard "Nacha Phase 2" from a CPA partner, an ACH bank rep, or a cyber-insurance broker. The references are usually vague, and the underlying rule is short on plain English. This post walks through what the rule actually says, what changes on June 22, 2026, and what a reasonable, documented control looks like for a small QBO shop. It is informational, not legal, accounting, or Nacha advice.
What the rule is, in plain English
Nacha writes the operating rules for the ACH network. In 2024 it added a set of risk-management rules aimed at reducing credit-push fraud. That term covers payments the sender authorizes, but only because they were tricked. The rule text specifically covers payments "authorized under false pretenses." The everyday version of that is vendor-impersonation business email compromise (BEC): someone poses as a vendor you already pay, says their bank account changed, and gets your next ACH credit routed to an account they control.
The new obligation is straightforward to state. Covered parties must "establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud." Two things in that sentence matter for a QBO shop.
First, it is risk-based. There is no checklist of mandated steps. You tailor controls to your own risk profile, and you are expected to be able to show what you do.
Second, it sits on the Originator side. The obligation is not only on the receiving bank that takes in a fraudulent credit. It reaches the business sending the ACH credit and the providers in that chain: the Originators, Third-Party Service Providers, and Third-Party Senders. If your bookkeeper releases vendor payments through QuickBooks Online Bill Pay, you are operating on the origination side of these transactions, and your bank is a participant subject to the rule as well.
Source: Nacha — Risk Management Topics, Fraud Monitoring Phase 2.
Phase 1 vs Phase 2: the dates, and the part that now applies to you
The rule rolls out in two phases.
Phase 1, effective March 20, 2026. This phase applies to all ODFIs (the originating banks) plus non-consumer Originators, Third-Party Service Providers, and Third-Party Senders that had a 2023 ACH origination or transmission volume of 6 million entries or more. That threshold means Phase 1, by design, covered larger originators. Most SMBs and the bookkeeping firms that serve them sat below it.
Source: Nacha — Risk Management Topics, Fraud Monitoring Phase 1.
Phase 2, effective June 22, 2026. This is the part that matters for a small shop. Phase 2 eliminates the 6-million-entry volume threshold. After this date, all non-consumer Originators, Third-Party Service Providers, and Third-Party Senders must establish and implement risk-based fraud-monitoring processes, regardless of size. (June 19, 2026 is the Juneteenth federal holiday, so the practical effective date is the next banking day, Monday June 22.)
The framing matters here. June 22, 2026 is not an expiry or a one-time event you wait out. It is the date the obligation turns on for everyone. A two-person bookkeeping practice running QBO Bill Pay for a handful of clients is in scope on June 22 in a way it was not before. The obligation is permanent and recurring, not a deadline that passes.
Source: Nacha — New Nacha Risk Management Rules Now in Effect and the Credit-Push Fraud Monitoring Resource Center.
What "risk-based processes to identify entries initiated due to fraud" means for a small QBO shop
For a large originator, this language implies transaction-monitoring systems and dedicated risk staff. For a 3-to-25-person CPA firm or a fractional bookkeeper, it means something more grounded. You need a defined, repeatable process for the moments where fraud actually enters your AP workflow, and you need to be able to show that the process ran.
The single highest-risk moment in SMB AP is the vendor bank-change request. A vendor you already pay says their banking details changed. If you update the vendor record in QuickBooks and pay the next bill, the money is gone the moment the ACH settles, and credit-push fraud is hard to claw back. This is the exact scenario Nacha's fraud-monitoring rules are written to address, and it is the one place a small shop can put a concrete, documentable control without buying an enterprise platform.
A "risk-based process" for this scenario does not have to be elaborate. It has to be defined, applied consistently, and recorded. In practice that means: when a bank-change request arrives, you verify it through a channel the requester does not control, you capture what happened, and you retain that record so an auditor or insurer can see the control operated.
The specific scenario this targets: vendor bank-change BEC
The numbers explain why this is the priority. The FBI's IC3 2024 Internet Crime Report put reported business email compromise losses at $2.77 billion across 21,442 complaints in 2024, roughly $129,000 per reported incident. BEC is not a tail risk. It is a routine, well-resourced attack pattern, and the vendor bank-change request is a common entry point into AP.
The mechanics are familiar to anyone who has worked a bill run. An email arrives from what looks like a known vendor contact. It is polite, it references a real invoice, and it asks you to update the remittance bank details before the next payment. The address may be spoofed, or the vendor's own mailbox may be compromised, so the message can be genuinely indistinguishable from a legitimate one on its face. If your only check is "the email looked right," you do not have a control. You have a habit, and it is the habit the attacker is counting on.
What a reasonable, documented control looks like
Here is a control a small QBO shop can actually run, and one that produces the kind of evidence an auditor would expect to see.
Log the request, do not just act on it. When a vendor claims new bank details, record it as an event: which vendor, the new account's last four digits, who logged it, and when. The point is to create a deliberate checkpoint before the vendor record changes and the next ACH goes out.
Verify out-of-band, to the previously verified contact. Send a one-time confirmation code to the contact you had on file before the change request arrived, not to the email that asked for the change. The reasoning is simple: the channel that requested the change is, by definition, the channel you cannot trust to confirm it. Reaching the prior contact forces a compromised or spoofed requester to also control the legitimate contact, which raises the bar.
Be precise about what this is. A callback or email confirmation to a previously verified contact is a workflow control, not independent verification that a bank account belongs to the vendor. It confirms that someone at the known contact attests to the change; it does not prove account ownership. For high-value or suspicious changes, layer additional controls: a phone call to a number you already had on file (never the number in the request), and dual approval before release.
Retain the evidence. Keep a structured record of each verification: timestamps, the channel used, the attestation text in the recipient's own words, and a hash of the record so later alteration is detectable. That retained record is what turns "we usually call vendors" into a documented, auditable control. It is the kind of evidence an auditor or insurer can review to see that the control operated. Check your own carrier's renewal questionnaire for what it asks of you specifically.
Keep the decision with you. None of this releases or holds a payment automatically. The decision to release, hold, or escalate stays with your team, and the ACH origination itself stays with you and your bank. The control gives you a documented basis for that decision; it does not make it for you.
An honest note: Nacha is technology-neutral and certifies nothing
This part matters, because the market is full of overclaiming. Nacha's rules are technology-neutral. Nacha does not mandate a specific method or tool, and it does not certify, validate, or endorse third-party fraud-monitoring products. Any vendor that tells you their software is "Nacha-certified" or "makes you Nacha-compliant" is describing something that does not exist.
What you can do is implement risk-based processes and procedures, tailored to your risk profile, and retain evidence that they ran. The useful question to ask of any tool in this space is whether it helps you operate and document a control, not whether it confers compliance. Compliance is a property of your process and your judgment, interpreted by your CPA, auditor, and bank. It is not a badge a vendor can hand you.
Where BankChangeGuard fits
BankChangeGuard is one SMB-priced way to operate and document this specific control inside QuickBooks Online. It connects to QBO with read-only access on the vendor and bill scopes. It does not touch bank credentials, does not originate ACH, and does not move money. When a vendor claims new bank details, your bookkeeper logs the request against the synced QBO vendor list, BankChangeGuard emails a one-time code to the previously verified contact, and you export a structured audit record (timestamps, channel, attestation text, SHA-256 evidence hash) to review before deciding to release, hold, or escalate.
It supports your Nacha Phase 2 fraud-monitoring obligations by giving you the documented control and retained evidence an auditor would expect to see for vendor bank-change verification. It does not make you compliant, does not verify bank-account ownership, and does not replace your bank's own Nacha obligations. The email confirmation is a workflow control, not independent verification that the new account belongs to the vendor. Pricing is $99/month flat: single seat, one QBO company, self-serve, built for the bookkeeper rather than the enterprise procurement team.
If you want to see the artifact before anything else, the simplest first step is to look at a sample audit PDF and read the compliance page, which spells out exactly what the records do and do not claim.
FAQ
Does Nacha Phase 2 apply to me if I am just a small bookkeeper using QuickBooks Online Bill Pay? After June 22, 2026, Phase 2 removes the 6-million-entry volume threshold, so the risk-based fraud-monitoring obligation reaches all non-consumer Originators, Third-Party Service Providers, and Third-Party Senders regardless of size. Whether and how it applies to your specific arrangement is a question for your bank and your CPA, but Phase 2 is explicitly designed to bring smaller originators into scope. See Nacha — Fraud Monitoring Phase 2.
Is BankChangeGuard "Nacha-certified" or does it make me compliant? No. Nacha does not certify or validate third-party fraud-monitoring tools, and no software can make you compliant on its own. BankChangeGuard helps you operate and document a vendor bank-change verification control and retain the supporting evidence. Compliance remains a function of your overall process and your bank's and CPA's judgment.
What happens to the rule after June 22, 2026? Is this a deadline that passes? No. June 22 is the date the obligation turns on, not a deadline that expires. The fraud-monitoring requirement is ongoing. Most SMBs still have no documented vendor-verification control on that date, so the practical work, putting a repeatable and evidenced process in place, is the same before and after.
Does email callback verification actually prove the vendor's new bank account is legitimate? No, and it is important to be honest about this. A one-time code sent to a previously verified contact is a workflow control: it confirms that the known contact attests to the change. It does not independently verify that the bank account belongs to the vendor or that the contact's mailbox is uncompromised. For high-value or suspicious changes, add a phone call to a number you already had on file and require dual approval before releasing payment.
This article is informational and does not constitute legal, accounting, insurance, or Nacha compliance advice. Confirm current requirements against the Nacha rulebook and consult your bank, CPA, and counsel for your specific situation.