By admin September 28, 2026
Dispensary ACH return rate thresholds require separate monitoring of unauthorized, administrative, and total returns. Nacha maintains a 0.5% unauthorized-return threshold, plus 3% administrative and 15% overall return-rate levels. Providers can impose tighter limits. R01 usually calls for controlled collection remediation; R10 or R29 demands an authorization investigation, not an automatic retry.
Dispensary ACH Return Rules at a Glance
| Issue | What It Means | Rule/Risk Category | Immediate Action |
| R01 | Insufficient funds | Funding return | Review whether controlled reinitiation is appropriate |
| R10 | Receiver does not know the Originator and/or did not authorize the debit | Unauthorized return | Stop automatic retry and retrieve authorization evidence |
| R29 | Corporate customer advises debit was not authorized | Unauthorized business-account return | Investigate account type and authorization |
| 0.5% | Unauthorized-return threshold | Nacha Rules | Investigate immediately and coordinate with provider/ODFI |
| 3% | Administrative return-rate level | Nacha inquiry level | Correct R02/R03/R04 account-data problems |
| 15% | Overall return-rate level | Nacha inquiry level | Segment all return causes and remediate |
| WEB validation | Validation of first-use consumer account information | Nacha WEB rule | Validate applicable account information before first use |
| Reinitiation | Resubmission of a returned entry under limited conditions | Nacha Rules | Apply return-code-specific logic; maximum two qualifying reinitiations |
The distinction between threshold and level matters when monitoring dispensary ACH return rate thresholds. Nacha maintains a 0.5% unauthorized-return threshold, while the 3% administrative and 15% overall figures are separate return-rate levels that can trigger review rather than automatic merchant termination under the ACH Network risk and enforcement framework.
Crossing either of the latter levels can begin an inquiry, but does not automatically constitute a Rules violation or automatically shut down a dispensary.
What an ACH Return Means at a Cannabis Dispensary
A dispensary checkout can make a bank payment look simple. Behind it, several parties may be involved:
Customer bank account → payment platform → Originator/Third-Party Sender → ODFI → ACH Network → RDFI
The Originator is the party that initiates the ACH entry under an authorization from the Receiver. A Third-Party Sender (TPS) may act as an intermediary between an Originator and an Originating Depository Financial Institution, or ODFI. The RDFI, or Receiving Depository Financial Institution, receives the ACH entry for the customer’s account.
The Receiver is the person or organization whose account is affected by the entry. A WEB debit is a consumer debit falling within Nacha’s Internet-initiated/mobile authorization framework.
Your dispensary may deal only with a payment platform. That does not mean the dispensary itself necessarily submits ACH files directly to an ACH Operator.
The payment provider, Third-Party Sender, sponsor bank and ODFI may therefore have obligations and risk controls that the merchant never sees at checkout. Understanding that chain helps explain why a provider can restrict an account before a merchant ever receives a communication from Nacha.
A dispensary deciding where ACH fits in its checkout stack should understand the operational differences between PIN debit, cashless ATM, and ACH payment models, because each method follows a different transaction flow and creates different settlement, return, and compliance considerations.
R01 vs R10 vs R29: What the Return Codes Actually Tell You

| Code | Plain-English Meaning | Typical Dispensary Scenario | Counts Toward Unauthorized Rate? | Reinitiation? | Best Response |
| R01 | Insufficient funds | Customer lacks available funds | No | Generally eligible under reinitiation rules | Controlled retry review |
| R10 | Originator unknown and/or not authorized | Customer denies authorizing dispensary debit | Yes | No automatic reinitiation | Stop and investigate |
| R29 | Corporate customer advises not authorized | Business account rejects debit | Yes | No automatic reinitiation | Investigate authorization/account type |
| R02 | Account closed | Old bank account supplied | No; administrative | Correct/remedy first | Obtain valid account |
| R03 | No account/unable to locate | Account information cannot be matched | No; administrative | Correct/remedy first | Validate data |
| R04 | Invalid account-number structure | Structurally invalid account data | No; administrative | Correct/remedy first | Correct data |
| R07 | Authorization revoked | Customer withdrew prior authorization | Yes | Do not simply retry | Stop debit activity |
| R11 | Entry not in accordance with authorization | Wrong amount/date or another authorization defect | Yes | Corrected new entry may be permitted | Correct underlying error |
| R20 | Non-transaction account | Account cannot accept the entry | No | Not without remedy | Obtain appropriate account |
R01 — Insufficient Funds
R01 is fundamentally a funding failure, not proof of an authorization failure. The account does not have sufficient available funds to satisfy the debit.
Nacha permits reinitiation of an entry returned for R01 insufficient funds or R09 uncollected funds, but not indefinitely. A returned debit may be reinitiated a maximum of two times, subject to the Rules. Nacha’s published guidance also states that qualifying reinitiation must occur within 180 days of the original entry’s Settlement Date.
A reinitiated entry must carry RETRY PYMT in the Company Entry Description. The Company Name, Company ID and amount must remain identical to the original entry; other fields may change only as permitted to correct an error or facilitate processing.
That does not make two retries a recommended default. If a dispensary indiscriminately retries every R01, it can increase total returns, push dispensary ACH return rate thresholds closer to provider or Nacha review levels, and create customer friction without solving the underlying funding problem.
R10 — Customer Advises Originator Is Not Known or Not Authorized
Nacha currently defines R10 as “Customer Advises Originator is Not Known to Receiver and/or Originator is Not Authorized by Receiver to Debit Receiver’s Account.”
It applies when, for example, the customer does not recognize the Originator, has no relationship with it, or says the Originator was not authorized to debit the account.
That makes R10 much more serious than R01 from an authorization perspective.
An R10 should trigger retrieval of the customer’s authorization, checkout record and relevant transaction evidence. For qualifying consumer unauthorized-return claims, the RDFI’s process includes obtaining a Written Statement of Unauthorized Debit.
Most importantly, Nacha states that an entry returned as unauthorized cannot simply be reinitiated. If the Originator obtains a new authorization after receiving the return, a later debit is not treated as reinitiation of the unauthorized entry.
That timing distinction prevents merchants from using pre-written language to evade the prohibition on repeatedly sending unauthorized debits.
R29 — Corporate Customer Advises Not Authorized
R29 applies to a non-consumer/corporate account when the customer advises that the debit was not authorized.
A dispensary might encounter R29 when someone enters a company bank account, when an account has debit blocks or controls, or when the person making the purchase lacks authority over the account.
R29 belongs in the current unauthorized-return-rate calculation. Do not exclude it merely because it involves a business account.
R11 Deserves Special Attention
R11 means the customer advises that the entry was not in accordance with the terms of the authorization. Unlike R10, an authorization exists, but the entry does not conform to it.
Examples include an incorrect amount or an entry submitted earlier than authorized. Nacha currently treats R11 as an unauthorized-return-rate code and requires a WSUD for the extended consumer-return process.
R11 also has an important remediation distinction: if the underlying error can be corrected, the Originator may submit a corrected new entry without obtaining a new authorization. Nacha says that corrected entry must be originated within 60 days of the R11 Return Entry’s Settlement Date.
Dispensary ACH Return Rate Thresholds: The Three Numbers That Matter

| Category | Current Nacha Figure | Included Returns | Consequence |
| Unauthorized | 0.5% threshold | R05, R07, R10, R11, R29, R51 | Rules enforcement implications; requires close ODFI monitoring |
| Administrative | 3% level | R02, R03, R04 | Can initiate preliminary inquiry |
| Overall | 15% level | All debit returns; RCK entries/returns may be excluded as specified | Can initiate preliminary inquiry |
The 0.5% Unauthorized-Return Threshold
Nacha’s current unauthorized-return calculation includes R05, R07, R10, R11, R29 and R51.
Under Nacha’s current unauthorized-return-rate calculation methodology, the unauthorized category includes R05, R07, R10, R11, R29, and R51. That current six-code list matters because older materials published before the R11 change can still appear in search results.
That current list matters. Older Nacha pages can still be found that predate the addition of R11 and therefore list only five codes. Nacha’s newer calculation guidance expressly includes R11, so the six-code list is the appropriate current list.
Nacha gives two approved calculation approaches. In broad terms, unauthorized debit returns are measured against the corresponding debit origination population for the preceding 60 days or two calendar months.
ODFIs are responsible for continuing to monitor the return rates of their Originators and Third-Party Senders.
The 3% Administrative Return-Rate Level
The administrative category contains R02, R03 and R04.
These returns generally point toward closed accounts, account-location problems or invalid account-number structures rather than customer claims that the debit was unauthorized.
Nacha’s July 2025 calculation guidance confirms that the 3% level uses the preceding 60 days or two calendar months methodology.
Exceeding 3% is not automatically a Rules violation. It provides an evaluation point at which Nacha can inquire into the Originator’s or Third-Party Sender’s origination practices.
The 15% Overall Return-Rate Level
The overall level captures debit returns across return reasons. Under Nacha’s current calculation guidance, RCK entries and RCK returns may be excluded from the numerator and denominator.
The same preceding 60-day/two-calendar-month measurement framework applies.
This is why a dispensary cannot monitor R10 alone. Heavy R01 activity can push total returns upward even when unauthorized activity remains low.
Worked Example: How Fast Can 0.5% Become a Problem?
Consider an illustrative merchant with 2,000 relevant debit entries during the applicable measurement period.
Suppose 12 corresponding returns carry codes included in the unauthorized-return calculation:
12 ÷ 2,000 = 0.60%
That illustrative result exceeds 0.5%.
It does not mean “12 returns automatically shut down the merchant.” It shows why lower-volume merchants should not wait for dozens of authorization disputes before investigating. With modest ACH volume, dispensary ACH return rate thresholds can move materially after only a small cluster of unauthorized returns.
Crossing a Nacha Level Does Not Necessarily Mean Instant Shutdown
Four different concepts need to stay separate:
- Nacha Rules establish ACH Network obligations.
- Nacha inquiry/enforcement provides mechanisms for investigating and addressing problematic activity.
- ODFIs monitor and manage Originators and Third-Party Senders.
- Payment providers and TPSs can impose their own contractual risk limits.
For the 3% and 15% levels, Nacha explicitly says exceeding the level does not automatically constitute a Rules violation or immediately trigger a fine. The inquiry can ultimately result in no further action or, depending on the findings, a directive to reduce returns.
Even when dispensary ACH return rate thresholds remain below Nacha’s published figures, your cannabis ACH provider can still act sooner under its own agreement. Possible provider actions include enhanced monitoring, authorization sampling, reserves, reduced limits, delayed settlement, temporary suspension or termination.
Those are possible contractual risk controls, not universal Nacha requirements. Never assume that being below 0.5%, 3% or 15% guarantees continued processing.
Why Cannabis ACH Providers May React Earlier
Cannabis banking risk now requires more precise language than the familiar statement that “all marijuana remains Schedule I.”
In April 2026, DOJ announced an order placing FDA-approved marijuana products and marijuana products subject to a qualifying state-issued medical marijuana license into Schedule III. DOJ and DEA simultaneously continued proceedings concerning broader marijuana rescheduling.
That limited action does not mean every state-licensed dispensary transaction now receives identical federal treatment. Adult-use activity and products outside the scope of the order still require careful federal-law analysis, and broader rescheduling remained the subject of the DEA proceeding described in its 2026 materials.
FinCEN’s marijuana-related-business guidance also remains important for banking relationships. It places due-diligence and BSA expectations on financial institutions that elect to serve marijuana-related businesses and makes clear that the decision to open, maintain or refuse a relationship depends on each institution’s risk assessment and capacity.
So ACH availability is not the same thing as federal approval of the dispensary. A bank, ODFI or provider can maintain its own cannabis risk appetite.
Nacha does not establish a separate 0.5%, 3% or 15% schedule specifically for marijuana merchants.
A New 2026 ACH Risk Requirement Also Matters
As of June 19, 2026, Nacha’s Phase 2 fraud-monitoring amendments apply to all non-consumer Originators, Third-Party Service Providers and Third-Party Senders that were not already covered by Phase 1.
Covered parties must establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud.
This requirement is broader than simply calculating return percentages. A cannabis ACH operation should therefore treat fraud monitoring, account validation, authorization controls and return-rate monitoring as related but distinct controls.
ACH Returns Are Not Card Chargebacks
| Issue | ACH Return / Unauthorized Debit | Card Chargeback |
| Primary framework | Nacha Rules plus applicable banking/EFT law | Card-network rules plus applicable law |
| Rail | ACH Network | Card network |
| Customer dispute path | Receiver/RDFI process | Cardholder/issuer/network dispute |
| Key merchant evidence | ACH authorization and transaction records | Network-specific transaction evidence |
| Timing | Depends on return reason and account type | Depends on card-network rules |
| Reinitiation | Specifically restricted by Nacha | Different dispute/representment structure |
| Risk measurement | ACH return rates/provider controls | Acquirer/network dispute monitoring |
Calling an ACH return an “ACH chargeback” may be convenient conversationally, but it obscures important operational differences.
What the Consumer “60-Day Rule” Actually Means
“Consumers can charge back ACH payments for 60 days” is too broad.
Under Regulation E §1005.11, a consumer generally must notify the financial institution of a qualifying EFT error no later than 60 days after the institution sends the periodic statement on which the alleged error first appears. Unauthorized EFTs are one category of error covered by that procedure.
Regulation E then governs the financial institution’s investigation and error-resolution obligations. Consumer liability for unauthorized EFTs is addressed separately under Regulation E, including §1005.6.
That statutory/regulatory framework is distinct from Nacha’s operational return deadlines.
For applicable consumer unauthorized ACH returns, Nacha provides an extended return process and requires a WSUD. Other ACH returns can have much shorter deadlines; for example, non-consumer returns commonly operate within the standard two-banking-day framework depending on the return reason.
Authorization Evidence: What the Dispensary Should Capture
In-Store Bank Payments
Do not label every bank-account payment a WEB debit.
The appropriate SEC code depends on the type of account, authorization method and transaction architecture. Ask your provider to identify the SEC code it originates and the authorization requirements that follow from that classification.
Using the wrong SEC code is not a harmless reporting choice.
Online or Mobile Pre-Pay
For applicable WEB debits, Nacha requires Originators to use a commercially reasonable fraudulent transaction detection system. Since March 2021, that system must include account validation for the first use of an account number and before the use of a changed account number, subject to specific rule details and exceptions.
Nacha defines the minimum account-validation standard as determining that the account is legitimate, open and capable of receiving ACH entries.
Critically, Nacha expressly says that this minimum standard does not require verification of account ownership. Depending on the Originator’s risk profile, stronger verification may still be appropriate.
Authorization Evidence Checklist
Rule-driven evidence, depending on the SEC code and transaction, may include:
- the authorization itself;
- identification of the Originator;
- authorized amount or method for determining it;
- single-entry, standing or recurring status where applicable;
- authorization method;
- records needed to provide proof of authorization when required.
Useful operational evidence may include:
- authorization timestamp;
- transaction/order identifier;
- checkout session records;
- account-validation result;
- confirmation or receipt;
- customer-service history;
- revocation records.
Provider-specific requirements may add:
- device or IP evidence;
- identity-verification results;
- particular authorization language;
- additional retention requirements.
Do not confuse recommended evidence with a universal Nacha field checklist. The applicable SEC code and provider architecture determine the actual rule requirements.
Account Validation Before the First WEB Debit
Nacha does not prescribe one validation technology.
Its guidance identifies options including prenotifications, micro-entry verification, commercially available validation services and API-enabled validation capabilities.
Validation can help catch invalid account information and some account-entry fraud before a live debit.
It cannot guarantee:
- sufficient funds on settlement day;
- that the person entering the account owns it;
- that the customer validly authorized the purchase;
- that a future debit will be authorized;
- that the customer will never dispute the transaction.
A dispensary trying to reduce ACH returns from cannabis payments therefore needs both account validation and authorization controls.
When You Can Re-Present an R01 — and When You Must Stop

| Return | Reinitiation Generally Possible? | Conditions | Stop/Correction Rule |
| R01 | Yes | Nacha reinitiation requirements; max two reinitiations | Stop after permitted attempts |
| R09 | Yes | Same limited reinitiation framework | Stop after permitted attempts |
| R08 | Only with separate Receiver authorization | Must meet applicable rule | No automatic retry |
| R10 | No automatic reinitiation | New authorization obtained after return can support a new entry | Investigate first |
| R07 | No simple retry | Prior authorization was revoked | New valid authorization needed |
| R11 | Corrected new entry may be possible | Correct defect; special R11 rules apply | Correct rather than blindly retry |
| R02/R03/R04 | Only after underlying problem is remedied where Rules permit | Correct valid account information | Never repeatedly submit known-bad data |
Nacha limits qualifying R01/R09 reinitiation to two attempts. It also prohibits changing entry information merely to evade that limit.
A legitimate later installment in a preauthorized recurring series is not automatically a reinitiation simply because an earlier installment returned, provided the later debit was not contingent on the earlier return.
That distinction matters for recurring or account-on-file arrangements.
Practical Ways to Reduce ACH Returns at a Cannabis Dispensary
Keeping dispensary ACH return rate thresholds under control requires more than lowering the total number of failed payments. The merchant needs to know which return codes are increasing, why they are occurring, and whether the correct response is account correction, authorization review, fraud investigation, or limited reinitiation.
- Validate applicable WEB accounts before first use: Do not use a live-dollar debit as an improvised validation process when Nacha’s WEB rules require account validation.
- Make authorization conspicuous: The customer should understand who is debiting the account, what is being authorized and whether the payment is single-entry or part of a broader arrangement.
- Use a recognizable bank-statement description: Customer recognition can reduce confusion, although a clear description cannot turn an unauthorized transaction into an authorized one.
- Separate NSF from authorization problems: Rising R01 activity needs different remediation from rising R10, R11, R29 or R07 activity.
- Set retry logic by return code: Never configure “retry every failed ACH twice.”
- Apply risk-based velocity controls: Monitor repeated attempts, unusual ticket sizes, rapid account changes, multiple accounts tied to one customer and clusters of failures. The exact limits are business/provider risk controls, not universal Nacha numbers.
- Calculate return rates before your provider contacts you: Monitor unauthorized, administrative and overall rates on the correct 60-day/two-calendar-month basis.
- Investigate sudden changes: Determine whether a spike comes from fraud, an integration defect, bad account entry, unclear authorization, an SEC-code problem, descriptor confusion or improper reinitiation.
Return monitoring should also connect to daily reconciliation. A consistent process for reconciling dispensary POS activity with seed-to-sale records makes it easier to distinguish an ACH payment failure from an inventory, register, refund, or reporting discrepancy.
A Weekly ACH Return Dashboard for Dispensaries
A weekly dashboard gives operators an early view of dispensary ACH return rate thresholds before a provider warning arrives. The goal is not merely to track the three external percentages, but to identify which return codes are driving them and whether the trend is worsening.
| Metric | This Period | Previous Period | Internal Alert | Action |
| Debit entries | ___ | ___ | Volume anomaly | Verify batches |
| Unauthorized returns | ___ | ___ | Set below external/contractual limit | Review authorization |
| Unauthorized rate | ___% | ___% | Below 0.5% and provider limit | Escalate rising trend |
| Administrative rate | ___% | ___% | Below 3% and provider limit | Review account data |
| Overall rate | ___% | ___% | Below 15% and provider limit | Segment causes |
| R01 count | ___ | ___ | Merchant-defined warning | Review NSF strategy |
| R10/R11/R29 | ___ | ___ | Merchant-defined low tolerance | Pull authorization evidence |
| Validation failures | ___ | ___ | Trend-based | Review checkout/account entry |
The internal alerts should be set below applicable contractual or external limits, based on the provider relationship and the merchant’s own risk tolerance.
There is no authoritative universal “safe cannabis ACH percentage” below which a provider cannot act.
What an ACH Program Warning May Look Like
A provider warning might request:
- a return-code report;
- authorization samples;
- account-validation procedures;
- explanation of elevated returns;
- fraud controls;
- transaction records;
- customer-support procedures;
- corrective actions and implementation dates.
That is an illustrative list, not a standardized Nacha warning letter.
Depending on its contract and risk policy, a provider could impose enhanced monitoring, restrict volume, change funding terms, require reserves, temporarily suspend origination or terminate service.
48-Hour Response Plan After a Provider Warning
- Stop indiscriminate automated retries.
- Export forward-entry and return data.
- Recalculate the three return-rate categories correctly.
- Segment every significant return code.
- Retrieve authorization records for R10/R11/R29/R07 activity.
- Review WEB account-validation records.
- Check SEC-code configuration and recent integration changes.
- Review statement descriptions and merchant identification.
- Contact the provider’s risk/compliance team.
- Submit a written corrective-action plan and monitor daily.
Do not attempt to protect the account by changing descriptors, entities, MCCs or transaction routing to conceal cannabis activity. That creates a different and potentially more serious compliance problem.
Common Mistakes That Threaten a Dispensary ACH Program
| Mistake | Better Approach |
| Retry every return | Apply code-specific rules |
| Treat R10 like R01 | Stop and investigate authorization |
| Ignore R11 | Count it in unauthorized monitoring and correct the defect |
| Assume account validation proves ownership | Treat validation and authorization separately |
| Ignore R02/R03/R04 | Investigate account-data quality |
| Calculate only weekly percentages | Maintain the applicable 60-day/two-month calculation |
| Treat 3% and 15% as automatic violations | Understand the Nacha inquiry process |
| Assume being below Nacha levels guarantees service | Review provider contractual limits |
| Use one SEC code for every bank payment | Match SEC code to actual authorization architecture |
| Treat ACH returns as card chargebacks | Use ACH-specific procedures |
| Change transaction information to evade retry limits | Follow Nacha reinitiation requirements |
ACH Program Survival Checklist
- Know the SEC codes being used.
- Validate applicable WEB account information.
- Maintain a commercially reasonable fraud-detection process.
- Capture valid authorization.
- Keep authorization records retrievable.
- Track R05/R07/R10/R11/R29/R51 as unauthorized returns.
- Track R02/R03/R04 as administrative returns.
- Calculate overall returns.
- Monitor R01 separately.
- Configure code-specific reinitiation logic.
- Enforce the two-reinitiation maximum where applicable.
- Use RETRY PYMT where the reinitiation rule requires it.
- Review merchant/statement descriptions.
- Set internal warning levels below contractual limits.
- Investigate unusual velocity and account changes.
- Document corrective actions.
- Know the provider’s risk escalation contact.
- Maintain lawful contingency payment methods.
- Never disguise the nature of cannabis transactions.
FAQs
What is the Nacha unauthorized ACH return-rate threshold?
The current Nacha unauthorized-return-rate threshold is 0.5%. Current calculation guidance includes R05, R07, R10, R11, R29 and R51 and uses the applicable preceding 60-day/two-calendar-month methodology.
Does R01 count toward the 0.5% unauthorized return rate?
No. R01 means insufficient funds and is not one of Nacha’s unauthorized-return codes. It can, however, contribute to the overall return rate.
Does R10 count as an unauthorized return?
Yes. R10 is included in Nacha’s current unauthorized-return-rate calculation. It addresses situations where the Receiver does not know the Originator and/or says the Originator was not authorized to debit the account.
Does R29 count toward the unauthorized return rate?
Yes. R29 is included in the current unauthorized-return calculation even though it concerns a corporate customer’s claim that a debit was not authorized.
How many times can an R01 ACH debit be retried?
A qualifying R01 entry can be reinitiated a maximum of two times under Nacha’s rules. Reinitiation must also meet the applicable timing, formatting and other requirements.
Can I retry an R10 after the customer says it was unauthorized?
Not as an automatic reinitiation. Nacha states that an unauthorized debit cannot be remedied through reinitiation. A new authorization obtained after receipt of the return can support a new entry, subject to the applicable rules.
What happens if my dispensary exceeds a 15% overall return rate?
The 15% level can initiate Nacha’s inquiry process into origination practices. It does not automatically constitute a Rules violation, create an immediate fine or require automatic merchant termination. Your provider may have stricter contractual policies.
Is an ACH return the same as a credit-card chargeback?
No. ACH returns operate under Nacha Rules, banking processes and applicable laws such as Regulation E. Card chargebacks use separate card-network dispute systems.
Does Nacha require account validation for every ACH debit?
No. The specific requirement discussed here concerns applicable WEB debits: the fraudulent-transaction-detection system must include account validation for first use of an account number and applicable account-number changes.
Can my cannabis ACH provider suspend me below a Nacha rate?
Yes. Nacha’s published threshold and levels do not prevent a provider, ODFI or Third-Party Sender from applying stricter contractual or risk-management requirements.
Keeping Dispensary ACH Return Rate Thresholds Under Control
Controlling dispensary ACH return rate thresholds starts with recognizing that not all returns mean the same thing.
R01 calls for funding and controlled-retry analysis. R02/R03/R04 point toward account-data quality. R10 and R29 demand authorization investigation. R11 requires attention to whether the entry actually matched the authorization.
The strongest ACH operation combines correct authorization, applicable WEB account validation, 2026 fraud-monitoring controls, return-code-specific remediation and accurate 60-day/two-calendar-month monitoring.
Just as important, keep Nacha rules separate from your provider’s cannabis risk policy. A dispensary can be below a Nacha benchmark and still violate its provider agreement, while crossing the 3% or 15% Nacha levels does not itself mean automatic shutdown.
Early detection is therefore the best survival strategy. Know which codes are rising, know why they are rising, preserve the evidence needed to explain them, and fix the underlying problem before returns become a banking-relationship problem.