Two changes to the Nacha Operating Rules take effect September 18, giving banks, originators and third-party payment providers a near-term test of how they classify international ACH payments and when receiving institutions make non-Same Day ACH credits available.
The changes are not an enforcement action and Nacha describes them largely as clarifications or an alignment with existing practice. Even so, the operational consequences can be material where current classifications, posting schedules or screening workflows do not match the revised rules.
A clearer IAT definition can expose classification gaps
Nacha’s revised definition describes an International ACH Transaction, or IAT, as the U.S. ACH Network component of an international payment transaction. The definition covers a transfer that originates with, transits through or is delivered to an account at an office of a financial agency outside the United States. It also covers a transfer received from a sender or delivered to a receiver through a facility of a financial agency outside the country.
Nacha says the purpose of the IAT Standard Entry Class Code has not changed. The revision is intended to make it easier to determine when the code applies. That distinction matters: it is a clarification of the classification boundary, not a new category of cross-border payment.
Originators, originating depository financial institutions, third-party service providers and third-party senders should compare the revised definition with the transactions they currently label as domestic or international. Nacha says the review could identify transactions that were previously treated as domestic but should be IATs, or the reverse. Newly identified IAT activity may require onboarding changes, updated agreements, customer due diligence and additional receiver information.
Receiving depository financial institutions, or RDFIs, face a related control issue. Changes in classification can alter the volume of transactions entering IAT compliance screening. Operations and sanctions teams therefore need consistent logic across customer onboarding, payment coding, exception review and downstream screening rather than treating the wording change as a documentation-only exercise.
The 9 a.m. availability rule loses its 5 p.m. condition
A separate rule taking effect the same day removes the condition that a non-Same Day ACH credit had to reach an RDFI by 5 p.m. on the prior banking day for the 9 a.m. funds-availability requirement to apply. From September 18, an RDFI generally must make all non-Same Day ACH credits available by 9 a.m. in the institution’s local time on the settlement date, regardless of when its ACH operator delivered the entry.
Nacha says some RDFIs already follow that practice. Others may need to change posting processes for next-day credits received after 5 p.m., including entries delivered in the ACH operator’s 6 a.m. Eastern Time output file. The affected payments can include payroll, benefits, cashouts, refunds and invoice payments, so a missed implementation can directly delay access to funds for consumers and businesses.
A limited exception applies to certain RDFIs east of the Atlantic Time Zone and west of the international date line, including institutions in Guam and the Northern Mariana Islands. Nacha says alternative requirements apply where operator delivery timing makes the ordinary 9 a.m. local deadline impracticable.
What payment operations teams should test
The immediate control work is different for each rule. IAT readiness calls for transaction sampling and a documented comparison between current classification logic and the new definition. Funds-availability readiness calls for end-to-end testing of every relevant operator file, settlement-date calculation, core posting job and customer-facing availability timestamp.
Institutions should also confirm that exceptions are narrowly configured and evidenced. The time-zone exception is not a general waiver for late posting, while clearer IAT wording does not remove the need for sanctions screening or other compliance procedures that attach to international ACH activity.
PaymentsJournal highlighted the implementation issues on September 10 in a discussion with Nacha rules executive Devon Marsh and Javelin Strategy & Research analyst Ben Danner. The underlying requirements are independently set out on Nacha’s official rule and guidance pages.
A longer sanctions-code project remains ahead
A separate Nacha change scheduled for March 17, 2028 will create return reason code R90 for entries returned because of an RDFI’s sanctions-compliance obligations. The existing R16 code will revert to an account-frozen meaning. Nacha says R90 returns must be transmitted within two banking days after the RDFI makes its sanctions-compliance determination.
That 2028 change is not part of the September 18 implementation. It does, however, give institutions a longer planning horizon for programming, exception handling and communications that will need to distinguish sanctions returns from account restrictions.
The practical lesson is not that Nacha has introduced a single sweeping overhaul. It is that relatively focused rule changes can expose disconnects between payment classification, sanctions screening, ACH operator files and core posting systems. Institutions have until September 18 to determine whether those components already work as the revised rules require.