Understanding Mastercard’s New Scam Monitoring Requirements

Understanding Mastercard’s New Scam
Monitoring Requirements

As fraud and scam activity continue to evolve across the payments ecosystem, Mastercard is introducing enhanced monitoring standards designed to help identify and prevent scam-related merchant activity before it can cause significant harm to consumers, issuers, and the payments industry.

Effective July 24, 2026, Mastercard will require acquiring banks, payment processors, and payment facilitators to implement additional monitoring and investigation procedures for merchants that exhibit characteristics commonly associated with scam activity.

The payments industry has experienced a growing number of scams that can be difficult to detect through traditional fraud monitoring methods. While many businesses operate responsibly, scammers often use legitimate-looking websites, advertisements, and payment acceptance channels to deceive consumers.

Mastercard’s revised standards are intended to strengthen oversight, improve consumer protection, and ensure that acquiring institutions can quickly identify potentially harmful activity before it impacts larger numbers of cardholders.

A scam merchant is generally a business that uses deceptive practices to persuade consumers to make purchases, subscriptions, investments, or other payments under false or misleading circumstances.

Examples may include:

  • Misleading subscription offers
  • Investment or cryptocurrency scams
  • Fake product or service websites
  • Deceptive trial offers
  • Businesses using false advertising or misrepresentation to obtain payments

The new standards focus on identifying unusual transaction behavior that may indicate these types of activities.

Mastercard already requires ongoing merchant monitoring, but the revised standards introduce additional triggers that may require a formal investigation.

Some examples include:

  • Sudden increases in chargebacks or refund activity
  • Significant drops in authorization approval rates
  • Reports from card issuers indicating potential scam activity
  • Alerts from approved monitoring services
  • Transaction activity that appears inconsistent with the merchant’s stated business model

For newly boarded merchants, special attention will be given to refund and chargeback activity during the first six months of processing.

For legitimate businesses, these changes should have minimal operational impact.

However, merchants should be prepared to provide additional information if unusual activity is detected. This may include:

  • Clarification regarding business practices
  • Marketing materials and advertisements
  • Customer service procedures
  • Refund policies
  • Evidence supporting product or service delivery

Maintaining transparent business practices and responding promptly to information requests can help avoid unnecessary disruptions.

To minimize risk and maintain a healthy processing relationship, merchants should:

  • Clearly disclose products, pricing, and subscription terms
  • Maintain responsive customer service channels
  • Process refunds promptly when appropriate
  • Monitor chargeback activity closely
  • Ensure advertising accurately reflects products and services offered
  • Review website disclosures and terms regularly

Merchants with strong operational controls and transparent customer communications are generally far less likely to encounter issues under Mastercard’s monitoring programs.

At Viking, we continuously monitor regulatory and card brand developments to help protect both our merchants and sponsoring financial institutions.

Our compliance, underwriting, and risk teams work closely with merchants to identify potential concerns early, provide guidance when needed, and ensure that businesses remain aligned with Mastercard and Visa requirements.

These new standards represent another step toward creating a safer and more trustworthy payments ecosystem for merchants, consumers, processors, and financial institutions alike.

If you have questions regarding Mastercard’s revised scam merchant monitoring requirements or how they may impact your business, please contact your Viking representative today.entation, our team is ready to assist. reach out to your Viking representative today.

June 2, 2026

About Robert Hollifield

He is an accomplished director with 15 years of experience in underwriting, risk management, and compliance in the payments space. He specializes in high-risk merchant oversight, regulatory adherence, and improving end-to-end payment processes to ensure secure, reliable operations. He received his BS from the University of New Hampshire.

Bigger Possibilities Await.

Contact Us


Read More

Same Day ACH Tops $1.1 Trillion: What Record Growth Means for Lenders

Same Day ACH Tops $1.1 Trillion

What the Latest Growth Mean for Lenders

Borrowers have become accustomed to instant access. They can order products online, transfer money between accounts, and receive payments within seconds. As these expectations continue to shape consumer behavior, they are increasingly influencing the lending industry as well.

When a loan is approved, borrowers no longer compare their experience solely against other lenders. They compare it against every other digital experience in their lives. Waiting days for funds to arrive can feel outdated, particularly when the need for funds is urgent.

Recent ACH Network growth data suggests that financial institutions and businesses are responding to this demand for faster payments. During the first quarter of 2026, Same Day ACH volume increased 23.6% year-over-year to 403 million payments, while the value of those payments reached $1.1 trillion, an increase of 22.1%.

These numbers demonstrate that faster payment capabilities are becoming increasingly important across the financial ecosystem, including lending.

Same Day ACH volume reached 403 million payments during the first quarter of 2026, while payment value exceeded $1.1 trillion for the second consecutive quarter.

For many borrowers, access to funds is the most important part of the lending experience.

A streamlined application process and quick approval lose much of their value if borrowers must wait days to receive their money. Whether funding is needed for emergency expenses, home repairs, vehicle repairs, medical bills, or short-term cash flow needs, delays can negatively impact borrower satisfaction.

Faster funding can help lenders:

  • Improve borrower satisfaction
  • Increase repeat borrowing activity
  • Strengthen customer retention
  • Differentiate themselves in a competitive market
  • Reduce funding-related support inquiries

As borrower expectations continue to evolve, funding speed has become an important part of the overall customer experience.

While much attention has been focused on real-time payment networks such as RTP and FedNow, Same Day ACH continues to experience significant growth.

One reason is accessibility.

Most financial institutions already participate in the ACH Network, making Same Day ACH a practical option for many lenders that want to accelerate funding without implementing entirely new payment workflows.

Same Day ACH can help lenders:

  • Deliver funds faster than traditional ACH
  • Improve operational efficiency
  • Reduce delays caused by batch processing
  • Provide more predictable settlement timing
  • Expand funding options for borrowers

For many lending organizations, Same Day ACH serves as an effective bridge between traditional ACH processing and real-time payment solutions.

The first-quarter ACH data also showed strong growth in business-to-business payments and continued expansion across internet-based transactions.

This broader growth reflects an ongoing migration away from paper-based payment methods and toward digital payment experiences.

For lenders, this trend extends beyond loan funding. ACH remains a critical tool for:

  • Recurring loan payments
  • Account verification processes
  • Consumer disbursements
  • Collections and repayment programs
  • Settlement and reconciliation operations

As lending becomes increasingly digital, ACH continues to provide the foundation for many borrower-facing payment experiences.

The continued growth of Same Day ACH provides an opportunity for lenders to evaluate whether their payment strategy aligns with borrower expectations.

Consider the following questions:

  • How quickly can borrowers receive funds after approval?
  • Are funding delays creating friction in the borrower experience?
  • Could Same Day ACH improve customer satisfaction or retention?
  • Are there opportunities to incorporate RTP or FedNow alongside existing ACH processes?

Lenders that proactively evaluate their payment capabilities today will be better positioned to meet the expectations of tomorrow’s borrowers.

The first quarter of 2026 highlighted the continued strength of the ACH Network, but the most significant takeaway for lenders may be the ongoing growth of Same Day ACH.

As borrowers increasingly expect faster access to funds, lenders must balance speed, efficiency, risk management, and operational simplicity. Same Day ACH continues to provide a practical solution that helps bridge those competing priorities.

At Viking, solutions such as VIKExpress, VIKEdge, and VIKEngage help lenders modernize payment operations, improve funding experiences, and maintain visibility into transaction performance as payment expectations continue to evolve.

May 7, 2026

About John O’Shea

He is a former founder and owner of Triad Financial Services and has served in similar roles at GMAC/Residential Funding, AllianceOne and ICT Group (now Sykes). He has performed for 28 years as a senior executive in the ARM, Customer Contact and BPO markets. He is a graduate of St. Olaf College.

Bigger Possibilities Await.

Contact Us


Read More

The Real-Time Lending Advantage

The Real-Time Lending Advantage

How Instant Payments Are Reshaping Borrower Expectations and Lender Strategies

We live in an economic era defined by immediacy. Consumers can order groceries with a tap, stream any movie on demand, and transfer funds between accounts in seconds. Against this backdrop, the traditional lending model (filled with processing windows, banking hours, and settlement delays) feels increasingly outdated. For many borrowers, the expectation of speed is no longer aspirational. It is assumed.

This expectation is particularly pressing in lending, where delays in access to funds can have real-life consequences. A borrower seeking emergency funds to avoid eviction, cover a medical expense, or fix a vehicle can’t wait until the next business day. For them, funding delays aren’t just an inconvenience …they’re a liability.

The advent of Real-Time Payments (RTP), including the RTP® network and the Federal Reserve’s FedNow℠ Service, offers a transformative solution. These payment rails allow funds to be delivered to a borrower’s bank account within seconds, 24/7, including nights, weekends, and federal holidays. And yet, adoption within the lending industry (especially among traditional lenders) remains patchy.

This article explores the gap between borrower expectations and lender capabilities, the strategic advantages of real-time funding, and why institutions that act now will define the next generation of consumer finance. From borrower loyalty and operational efficiency to fraud mitigation and competitive positioning, the case for real-time disbursement has never been stronger or more urgent.

Today’s borrowers do not compare lenders to each other, they compare them to every other modern digital experience they engage with. When ridesharing apps, food delivery services, and peer-to-peer payments all operate in real-time, any financial service that introduces friction or delay feels archaic.

This shift is particularly acute among:

  • Gig economy workers, who expect same-day access to earnings.
  • Freelancers and consultants, who often rely on immediate cash flow between contracts.
  • Low-to-moderate income borrowers, for whom a one-day delay could mean an overdraft or a missed bill.

A recent study by the Federal Reserve found that 78% of consumers prefer faster payment methods when available, with 82% valuing real-time confirmation of funds. Furthermore, 26% of consumers identified last-minute bill payment as one of the top use cases where real-time payments would provide the most benefit.

Notably, 25% of respondents cited slow speed of funds as one of their most frustrating pain points in payments, second only to fees. As one millennial respondent put it: “Some apps charge a significant fee to move money or take 2–3 days to transfer. Eliminate fees and speed up the transfers.”

Borrowers aren’t just reacting to delays, they’re building their financial behaviors around speed.

Borrower Takeaway: If the funds aren’t available instantly, the lender isn’t either.

Loan disbursement isn’t just a back-office function. It’s the moment of truth in the borrower journey. Delays at this critical stage diminish the borrower’s perception of the lender, even if the application and approval processes were seamless.

RTP changes that. With instant funding, a borrower can go from application to funds-in-hand in under a minute. That kind of performance creates what behavioral economists call a “gratification anchor” …a strong positive association that makes the borrower more likely to return, and more likely to recommend.

What this translates to in practice:

  • Higher reloan rates
  • Lower first-payment defaults (FPD)
  • Better Net Promoter Scores (NPS)
  • Reduced abandonment during application flow

According to the Fed’s 2024 Consumer Payments Study, consumers cited immediate notifications, the ability to use funds 24×7, and ease of sending as top motivators for choosing real-time payment methods.

Example:
A mid-sized lender using VIKExpress saw a 27% increase in same-month repeat borrowing after enabling real-time disbursement. Their marketing and acquisition costs didn’t change. Their retention strategy simply became faster.

Real-time payments are not just faster, they’re always on. That matters more than most lenders realize.

In today’s lending environment, loan applications peak during off-hours. Evening and weekend traffic accounts for over 40% of all digital applications across short-term and installment loan platforms. Traditional ACH infrastructure forces lenders to delay funding until the next business day, creating a disconnect between borrower action and lender response.

According to the Federal Reserve’s 2024 data, Gen Z and Millennials rank last-minute bill payment and digital wallet top-ups as top use cases for faster payments. Baby Boomers and Gen X prioritize loan disbursements and real estate or auto-related payouts, making RTP a cross-generational benefit.

With RTP or FedNow:

  • Applications at 10pm on Sunday can be funded at 10:01pm.
  • Loans approved on Thanksgiving can be delivered within 60 seconds.
  • Borrowers on the West Coast applying after East Coast banking hours aren’t left waiting until morning.

Use Case:
A tribal lender operating nationally found that enabling 24/7 funding helped them increase weekend originations by 46% year-over-year. The most common feedback in their borrower reviews? “I got my money right away.”

Beyond the borrower experience, real-time disbursement offers critical backend advantages.

1. Elimination of card funding risks:
Unlike push-to-debit solutions, RTP does not require lenders to collect or store card data. This minimizes exposure to fraud vectors like synthetic identity, card cycling, and prepaid reload scams.

2. Superior reconciliation:
Each RTP transaction posts individually and immediately, with detailed confirmation. This eliminates batch files, delayed returns, and uncertainty about when funds will settle.

3. Fewer failed disbursements:
Since RTP relies on DDA account data validated in advance, there’s less room for error. Combined with tools like VIKEdge (which verify account balances in prior to debit origination), lenders can create a tightly managed funding and repayment cycle with fewer break points.

4. Faster issue resolution:
When disbursement questions arise, RTP provides instant confirmation, something ACH systems often cannot do for 24–48 hours.

Bottom line: RTP reduces funding exceptions, improves cash management, and simplifies audit trails.

The assumption that RTP requires months of technical work or massive IT investment is outdated. Today’s platforms are built for flexibility.

With VIKExpress, for example:

  • Existing ACH clients can activate RTP with a simple addendum.
  • Clients can use the RTP-enabled virtual terminal while integrating APIs in parallel.
  • Production credentials and sandbox access are provisioned within 24–48 hours.

Some lenders go live in under a week.

Integration Approaches:

  • Direct API (ideal for scale lenders with dev resources)
  • LMS plug-ins (supported in platforms like Infinity, QFund, EPIC, and others)
  • Manual transactions via web-based portal (for low-volume or transitional use)

Whether you’re a high-frequency originator or a niche tribal lender, the barrier to entry is no longer technical.

The longer a lender waits to adopt real-time payments, the more likely they are to fall behind.

Why?
Because RTP is not just a differentiator, it’s rapidly becoming table stakes.

PYMNTS and Fed data show that:

  • 89% of surveyed companies have used RTP for at least one type of payout
  • Gen Z and Millennials are 2x as likely to use real-time payments compared to older cohorts
  • Instant disbursement usage is growing across verticals including insurance, auto lending, and online marketplaces

The Federal Reserve’s study also found that consumers using real-time payments rated their satisfaction with their financial institution 8% higher than those who did not. This suggests that beyond borrower acquisition and retention, RTP can also boost your institutional brand.

What this means for lenders:

  • Affiliate marketers increasingly prioritize lenders who fund instantly
  • Licensing renewals and state reviews now evaluate speed and transparency
  • Borrower churn rises when competitors offer a faster experience

As borrower demands and partner expectations increase, lenders without RTP will not just lose deals… they’ll lose credibility.

The case for real-time disbursement is no longer theoretical. It’s here. It’s proven. And it’s what borrowers expect.

Lenders who embrace RTP now position themselves as forward-looking, borrower-first institutions. They also position themselves for operational scale, lower risk, and higher return.

Those who wait will find themselves explaining delays that borrowers (and the market) no longer tolerate.

Next Steps for Lenders:

  • Audit your disbursement timelines. How long do borrowers really wait?
  • Identify your weekend and off-hours volume. Are you missing revenue?
  • Talk to your payments partner. Can they activate RTP now? (If not, you may need a new partner.)

Real-time lending is not just the future. It’s the new baseline. Don’t fall behind.

December 19, 2025

About Adam Garrett

He has spent almost 20 years building successful merchant acquiring programs and is a proven sales leader who brings his expertise in team management, business development, and strategic planning to Viking Payments. He received his MBA from the University of Texas at Dallas, and his BS at Missouri State University.

Bigger Possibilities Await.

Contact Us


Read More

Nacha Fraud Monitoring Updates, Risk Management

Nacha Fraud Monitoring Updates

As 2025 comes to a close, attention is shifting to 2026 and the next wave of changes in the ACH Network. Nacha has announced several upcoming rule amendments that strengthen risk management expectations, clarify existing requirements, and introduce new monitoring obligations for ACH participants. This article outlines the key updates so businesses can understand what to expect as these Rules take effect throughout 2026.

Some of the changes are minor clarifications that will have limited impact on most participants. Others, particularly those related to fraud monitoring, represent more meaningful shifts in expectations. Not all changes will apply to every Originator, Third Party Sender, or ODFI, but all ACH participants should be aware of what is coming.

Use of Return Code R17 “Questionable”
This update clarifies the proper use of R17 rather than introducing a new return code. Under the revised definition, an RDFI may return an entry as “Questionable” when it believes the transaction or Receiver information is inaccurate, incomplete, or inconsistent with what it knows about the account. This change provides clearer guidance for RDFIs and creates earlier feedback for Originators when something about the entry appears suspicious.

Banking Day Definition Clarification
This is not a substantive change but a clarification. It confirms that a “Banking Day” is defined as a day on which the ACH Operator is open for business. The goal is to remove ambiguity and ensure uniform interpretation across the network.

RDFI Requirement to Provide Payment-Related Information
Several SEC Codes require RDFIs to provide Payment-Related Information to Receivers. These include CCD, CTX, CIE and IAT. The updated Rule clarifies that this requirement does not apply if these entries post to a consumer account. The expectation only applies when the Receiver is a non-consumer.

Company Entry Descriptions
These amendments take effect March 20, 2026 and apply to both credits and debits. Originators may adopt the new descriptions before the effective date. The changes support standardization and enhanced monitoring across the network.

ACH Credit Entry
The Company Entry Description for credits that represent wages or other compensation must contain the description PAYROLL.

ACH Debit Entry
For ACH WEB debits that represent the online purchase of goods, including recurring purchases first authorized online, the Company Entry Description must contain the description PURCHASE.

Risk Management Rule Updates
The most significant changes relate to fraud monitoring. Nacha is introducing new requirements for Originators, ODFIs, Third Party Service Providers, and Third Party Senders, along with a separate monitoring requirement for RDFIs. These Rules are being phased in during 2026.

These new expectations apply to ODFIs, non-consumer Originators, TPSPs, and TPSs. The requirements take effect in two phases.

Phase 1: March 20, 2026
Applies to participants with annual origination volume of 6 million or more in 2023.

Phase 2: June 19, 2026
Applies to all remaining non-consumer Originators, TPSPs, and TPSs not included in Phase 1.

The purpose of the amendment is to ensure participants establish and implement risk-based processes and procedures designed to identify potentially fraudulent entries. Routine monitoring is expected to reduce the likelihood of successful fraud attempts and strengthen the entire ACH ecosystem.

Today, Originators of WEB debits and users of Micro-Entries must utilize a “commercially reasonable fraudulent transaction detection system”. The updated Rule removes that terminology. The phrase “commercially reasonable” and the expectation of a “transaction detection system” are replaced with more practical language that focuses on processes and procedures.

This shift clarifies that Nacha is not prescribing specific technologies. Instead, entities must maintain documented processes that demonstrate how they reasonably identify and respond to fraud risks, based on the role they play in the ACH Network. The flexibility allows organizations of different sizes and risk profiles to implement approaches appropriate to their environments.

Nacha requires that these processes and procedures be reviewed at least annually, or sooner if material changes occur during the year.

This update adds new expectations for RDFIs related to monitoring of incoming ACH credits. The Rule does not impose new obligations on Viking Originators but is part of Nacha’s broader fraud prevention strategy.anges, reach out to your Viking representative today.

As these updates take effect in 2026, ACH participants should take time to review their current practices, confirm that documentation is up to date, and ensure fraud monitoring processes align with Nacha’s expectations. While some of the changes are minor clarifications, others require operational adjustments that strengthen risk management across the network. Viking will continue to monitor these developments and support our clients through each phase of implementation to ensure a smooth and compliant transition.

December 9, 2025

About Megan Williams

She is a dedicated payments professional with a passion for operational processes, efficiencies and a love for the Rules. She has been in the financial services industry since 2016, strengthening her understanding of the space and obtaining her ACH Certification (AAP). She specializes in optimizing operations, enhancing payment processes and ensuring compliance in all matters of her job and this industry. 

Bigger Possibilities Await.

Contact Us


Read More

Understanding VISA VAMP

Understanding VISA VAMP

Visa’s Acquirer Monitoring Program, known as VAMP, is a global compliance and risk oversight framework designed to ensure that acquirers, payment processors, and merchants operate safely, consistently, and in alignment with Visa’s rules. VAMP helps protect the payments ecosystem by reducing fraud, monitoring unusual or high-risk activity, and confirming that underwriting and portfolio management practices remain strong.

VAMP is not a penalty program. It does not function the way Visa’s dispute monitoring programs work. Instead, it is a structured method for Visa to confirm that acquirers have appropriate controls, documentation, and oversight in place. When Visa detects elevated dispute activity, irregular transaction patterns, outdated merchant files, or missing documentation, it may request clarification or remediation. The goal is to improve stability across the network and prevent issues before they impact merchants.

VAMP was developed in response to increased fraud trends, evolving digital payment behaviors, and growing regulatory expectations worldwide. Visa is placing greater emphasis on the accuracy of merchant onboarding, the completeness of underwriting files, the use of correct MCCs, and the ongoing monitoring of merchant portfolios. By strengthening these areas, Visa helps acquirers prevent unauthorized activity, reduce misuse of merchant accounts, and ensure that high-risk behaviors are detected early.

For most merchants, VAMP requires little to no direct action. Visa’s inquiries flow to the acquirer and processor, not to individual merchants. Your processing continues without interruption. In some situations Viking may reach out for small updates such as a current business license, ownership verification, a website review, or a clarification about your products and services. These requests are simple, quick, and designed solely to maintain alignment with Visa’s guidelines.

Viking is approaching VAMP with a proactive, portfolio-wide strategy that protects merchants and strengthens long-term processing reliability. Our compliance, underwriting, and risk teams have expanded documentation standards, improved MCC accuracy, and upgraded identity, KYB, and bank-account verification tools. We have also enhanced transactional monitoring to identify early indicators of fraud or unusual behavior across the portfolio.

In partnership with our sponsor banks, Viking has increased transparency through improved reporting, updated merchant files, and ongoing communication around risk trends. This allows potential concerns to be addressed early and keeps merchant processing stable and uninterrupted.

  • Earlier fraud and dispute monitoring thresholds with automated pattern detection
  • Comprehensive audits of all merchant underwriting files to confirm Visa and bank compliance
  • Updated training for onboarding, underwriting, and compliance teams
  • Deployment of advanced KYB and KYC tools to reduce onboarding risk
  • Continuous policy updates to match Visa and sponsor-bank expectations
  • Strengthening of MCC classification and merchant data accuracy
  • Portfolio-wide merchant reviews to ensure proper business information and operational descriptions

A stronger compliance and monitoring environment reduces fraud, lowers dispute exposure, improves portfolio health, and helps preserve long-term access to card processing. Merchants benefit from:

  • Continued, uninterrupted processing
  • Faster identification of operational issues or fraud patterns
  • Fewer unexpected disputes and chargebacks from upstream problems
  • A more secure environment for accepting Visa cards
  • A more stable relationship between Viking, our sponsor banks, and the Visa network

For most merchants nothing will change. From time to time Viking may request updated documentation to ensure your file remains compliant. These requests are routine and typically take only a few minutes to complete. Payment processing continues as normal and real-time funding through VIKExpress is unaffected.

Viking is committed to making the VAMP process seamless and supportive. Every action taken under VAMP is designed to strengthen merchant protections, maintain high-quality bank relationships, and ensure long-term access to secure payment processing. If you have questions or need help with any compliance documentation, our team is ready to assist. reach out to your Viking representative today.

December 1, 2025

About Robert Hollifield

He is an accomplished director with 15 years of experience in underwriting, risk management, and compliance in the payments space. He specializes in high-risk merchant oversight, regulatory adherence, and improving end-to-end payment processes to ensure secure, reliable operations. He received his BS from the University of New Hampshire.

Bigger Possibilities Await.

Contact Us


Read More

New ACH Rules: What Originators and RDFIs Must Know in 2025

New ACH Rules
What Originators and
RDFIs Must Know in 2025

With ACH fraud risks rising, Nacha has introduced key updates, some in effect now and others phasing in through 2026. Here’s what you need to know and act on today.

Credit push fraud, such as Business Email Compromise(BEC) or vendor impersonation, is a growing threat,  and Nacha has reinforced roles and protocols to combat it. In a typical BEC scenario, fraudsters gain access to or spoof a legitimate business email account to trick someone into sending an ACH credit or wire transfer to a fraudulent destination. These attacks often involve fake invoices, altered payment instructions, or urgent requests that appear to come from a trusted internal or external source. As these scams become more sophisticated, financial institutions and businesses must adapt their defenses accordingly.

Receiving institutions must now monitor incoming credits and have risk-based procedures to identify and act on suspicious entries.

ODFIs and RDFIs are encouraged to communicate when suspected fraud is identified. A secure exchange portal is now available for handling return requests, particularly under R06.

Institutions should also educate business and consumer clients about common fraud tactics to increase vigilance before a transaction is initiated.

Nacha has introduced a new classification called False Pretenses (which is included in the R17 return code). This covers payments induced by misrepresentation of identity, authority, or account ownership. Examples include payroll impersonation and vendor fraud. It does not apply to scams involving fake products or services.

RDFIs can now use R17 to return entries they believe may be fraudulent, even if the receiving account is valid.

The word “QUESTIONABLE” must be included in the addenda record when this return reason is used.

ODFIs can now request returns through the Letter of Indemnity (LOI) process using R06 for other reasons that are applicable to the scenario, such as suspected fraud.

RDFIs must respond to R06 requests within 10 Banking Days. That response can be either a return or a formal status update. A secure exchange portal is available to facilitate these requests and responses.

The Written Statement of Unauthorized Debit (WSUD) no longer needs to be signed by the settlement date. It may now be signed on or after the effective date of the debit, offering greater flexibility for account holders disputing unauthorized transactions.

Beginning in 2026, Nacha will require risk-based fraud detection processes for all Originators and ODFIs. The requirement will take effect in two phases.

Phase 1 begins in March 2026 and applies to Non-consumer Originators (and vendors) with 2023 ACH origination volume of 6 million or greater.

Phase 2 begins in June 2026 and applies to all others.

Processes must be reviewed annually. There is no requirement to review each individual transaction or to conduct manual review before file submission. Instead, participants must establish reasonable procedures to flag suspicious activity based on patterns, amounts, frequency, or account behavior.

Receiving institutions must implement a risk-based credit monitoring process and respond appropriately when suspicious activity is identified.

This process should be reviewed annually to ensure it remains effective. Monitoring does not require line-by-line transaction reviews, but should include logic to detect red flags such as:

  • SEC codes that do not match account types
  • Unusually large credit amounts
  • Multiple credits from different states
  • Update your fraud detection processes
  • Train your staff on new classifications like False Pretenses and changes to R17 and R06
  • Ensure your systems support the new entry descriptions PAYROLL and PURCHASE
  • Prepare for the phased rollout of the fraud monitoring requirements
  • Review WSUD policies to allow for signature on or after the effective date
  • Test your response time and documentation process for R06 return requests

These updates strengthen the ACH ecosystem and clarify roles and responsibilities across all parties. With deadlines extending into 2026, now is the time to make adjustments, train your staff, and ensure your ACH operations align with Nacha’s evolving standards.

At Viking, we build solutions like VIKEngage, VIKExpress, and VIKEdge with these compliance needs in mind. Whether you need real-time monitoring, simplified return processes, or tools to minimize fraud risk, we’re here to help.

If you have questions about your readiness or need support implementing these changes, reach out to your Viking representative today.

July 17, 2025

About Megan Williams

She is a dedicated payments professional with a passion for operational processes, efficiencies and a love for the Rules. She has been in the financial services industry since 2016, strengthening her understanding of the space and obtaining her ACH Certification (AAP). She specializes in optimizing operations, enhancing payment processes and ensuring compliance in all matters of her job and this industry. 

Bigger Possibilities Await.

Contact Us


Read More

Payment Processing FAQ

Payment Processing FAQ
What Every Merchant Should Know

Whether you’re new to payment processing or a seasoned operator, the landscape is constantly evolving. From faster ACH return options to the latest tools in transaction management, merchants need to stay current to reduce risk and operate efficiently. Below, we answer some of the most common questions we hear from clients.

Yes, and it can be a significant improvement for your operations.

Under Nacha and UMACHA guidelines, ACH returns can be processed using Same-Day ACH, even if the original transaction was not sent as a same-day item.

Here’s what you need to know:

  • No Same-Day Entry Fees for Returns – RDFIs are not charged fees for initiating returns using the Same-Day ACH window
  • Faster Return Resolution – Same-day returns reduce liquidity exposure, accelerate reconciliation, and minimize the risk of downstream errors
  • Improved Risk Management – Quicker returns help detect and respond to issues such as fraud or invalid accounts faster
  • Everyone Benefits – Faster return processing supports ODFIs, RDFIs, and Originators by reducing uncertainty and improving settlement timelines

If your return process still follows next-day timing by default, we recommend evaluating a same-day return process to improve overall performance and responsiveness.

Yes. Viking offers Viking VRM (Viking Relationship Manager), a secure online portal where you can manage card activity, monitor chargebacks, and review reporting, all in one place.

Key features include:

  • Real-time visibility into card transactions and funding activity
  • Chargeback management, including retrieval request tracking and resolution statuses
  • Batch and individual transaction lookup, with exportable reports for reconciliation
  • Detailed fee reporting, including interchange and processor-level assessments
  • User-level access controls, so teams can manage workflows without overexposing sensitive data

If you don’t already have access to Viking VRM, contact your Viking representative. We’ll get your user credentials set up and walk you through how to get the most from the platform. It’s a powerful resource for day-to-day card operations and dispute management.

Viking provides clients with access to VIKEngage, a powerful transaction insight platform designed to give real-time visibility into ACH activity and return rates.

With VIKEngage, you can:

  • Track ACH debits, credits, and returns by code and date in real time
  • Monitor your return ratios to ensure you stay below NACHA’s thresholds
  • Filter, review, and export transaction data for compliance reporting or internal audits
  • Identify operational trends or problem accounts that may need attention
  • Access intuitive dashboards that simplify ongoing compliance and risk oversight

VIKEngage is available via a user-friendly web portal and requires no additional integration or setup for existing clients. If you’re not already using it, reach out to your Viking representative and we’ll get you connected.

We’re investing heavily in the future of payments through our VIKEngine suite, a set of connected tools designed to bring speed, intelligence, and risk reduction to your operations.

Here’s a look at what’s currently available:

  • VIKExpress – Enables real-time disbursements through both the RTP and FedNow networks. Funds are delivered instantly, 24/7, improving borrower satisfaction and reducing operational delays
  • VIKEdge – Combines ACH processing with real-time bank balance verification, reducing NSF returns and giving you confidence before initiating debits
  • VIKEngage – A transaction insight platform that gives you real-time visibility into ACH activity, return codes, and performance trends to help you stay below NACHA thresholds and make informed decisions
  • VIKExclude – A pre-funding screening tool that checks routing and account numbers against a proprietary database of accounts with known fraud or return history, helping prevent losses before funds are sent

Each of these tools is available individually or as part of a broader VIKEngine integration, and all are designed to help merchants operate faster, smarter, and more securely.

At minimum, payment processing policies and procedures should be reviewed and updated annually.

Doing so helps ensure:

  • Compliance with NACHA, PCI DSS, and card brand requirements
  • Internal controls remain aligned with evolving risk
  • Documentation accurately reflects current systems and staff responsibilities
  • You’re prepared for audits or external reviews

Reviews should also be triggered after any major operational changes, system upgrades, or security incidents. An annual review is a simple but critical part of keeping your business compliant and audit-ready.

We’re always here to help. Whether you’re looking to streamline your return process, access Viking VRM, or explore the VIKEngine platform, your Viking representative is just a call or email away.

Let us know what you’d like to see covered in a future FAQ. We’re always listening.

July 9, 2025

About Adam Garrett

He has spent almost 20 years building successful merchant acquiring programs and is a proven sales leader who brings his expertise in team management, business development, and strategic planning to Viking Payments. He received his MBA from the University of Texas at Dallas, and his BS at Missouri State University.

Bigger Possibilities Await.

Contact Us


Read More

Common ACH Audit Findings

Common ACH Audit Findings
and How to Stay Compliant

Every year, businesses that originate ACH transactions are subject to an ACH audit, as required by the NACHA Operating Rules. While many audits go smoothly, there are a handful of recurring issues that pop up year after year. Some are simple, others potentially serious. Whether you’re preparing for an upcoming audit or looking to tighten up your existing ACH practices, understanding these common findings is a smart place to start.

Below are some of the most frequent ACH audit findings, along with insights and recommendations for how to avoid them:

Chapter 56 of the NACHA Rules covers the audit requirements that every ACH Originator and Third-Party Sender must follow. It requires an annual audit to ensure compliance with the NACHA Operating Rules and recommends documentation for each key function. Failure to perform this audit or maintain documentation can result in non-compliance findings.

Tip: Make sure your audit is performed annually by a qualified party and that you retain clear documentation of the audit scope, findings, and corrective actions taken.

NACHA requires that each company maintain and annually review its contact information in NACHA’s database. This ensures that your organization can be contacted in the event of a network or transaction issue.  [When working with Viking, this information is located on Schedule E of your ACH Origination Agreement]

Tip: Set a calendar reminder to review and update your NACHA contact list every 12 months.

The Risk Assessment is more than a formality. NACHA expects a formal risk assessment document that includes risk ratings for each threat and control in your ACH process.

Tip: Document not only risks, but also the impact, likelihood, and controls in place. Assign risk levels to each category, such as Low, Medium, or High.

Improper use of Standard Entry Class (SEC) Codes, such as using PPD instead of WEB for internet-authorized transactions, is a frequent finding.

Tip: Confirm that every transaction is being coded appropriately. For example:
• PPD: Prearranged payment and deposit (consumer, pre-authorized)
• WEB: Consumer-initiated internet or mobile transactions
• TEL: Telephone-initiated

Originators are required to have signed agreements with all parties involved in ACH transactions, including clear authorization language and responsibilities.

Tip: Review your agreements annually and ensure all parties are documented and acknowledged in writing.

When a financial institution issues a Notice of Change, you’re required to update your records before the next transaction or within six banking days, whichever comes first.

Tip: Assign ownership of NOC monitoring and include this step in your daily ACH processing checklist.

ACH returns must be processed quickly and accurately. A delay in responding to unauthorized debits or incorrect return coding is a compliance risk.

If a payment is reinitiated due to insufficient funds, NACHA rules require the word “RETRY PYMT” in the Company Entry Description field. Without it, the transaction could be flagged as unauthorized.

Tip: Automate the insertion of “RETRY PYMT” into all reinitiated NSF entries to ensure compliance.

Many businesses fail to create or test a formal Business Continuity Plan for ACH operations, which is a NACHA expectation.

Tip: Draft a documented plan outlining how ACH processing will continue in the event of a disruption. Test it annually and keep logs of those tests.

The Electronic Funds Transfer Act (Regulation E) requires specific consumer disclosures, such as dispute rights and liability limits. These must appear on account statements or statement backers.

Tip: Review your Reg E disclosures annually and confirm that consumers receive them through appropriate channels.

Many merchant agreements and consumer-facing Terms and Conditions lack clear language about ACH authorization, dispute procedures, and usage of recurring entries.

Tip: Add a section to your Terms and Conditions that explains how ACH transactions are authorized and handled. Include clear consent language.

Being prepared for your next ACH audit starts with awareness. These common findings don’t just reflect compliance oversights, they point to real operational risks that could lead to fines, returns, or customer dissatisfaction.

Want help tightening up your ACH processes? Reach out to your Viking representative today.

June 22, 2025

About Tracey Gibson

She is an accomplished compliance executive with extensive experience in overseeing and managing compliance functions and initiatives of an organization. She has expertise in ensuring organizations comply with regulatory requirements and brings a strong background in ethical business practice, risk management, privacy, employee management and customer service.

Bigger Possibilities Await.

Contact Us


Read More