ACH Returns at the Dispensary: R01 vs R10 Codes, Nacha Return-Rate Thresholds, and Keeping Your Cannabis ACH Program Alive

ACH Returns at the Dispensary: R01 vs R10 Codes, Nacha Return-Rate Thresholds, and Keeping Your Cannabis ACH Program Alive
By admin September 28, 2026

Dispensary ACH return rate thresholds require separate monitoring of unauthorized, administrative, and total returns. Nacha maintains a 0.5% unauthorized-return threshold, plus 3% administrative and 15% overall return-rate levels. Providers can impose tighter limits. R01 usually calls for controlled collection remediation; R10 or R29 demands an authorization investigation, not an automatic retry.

Dispensary ACH Return Rules at a Glance

IssueWhat It MeansRule/Risk CategoryImmediate Action
R01Insufficient fundsFunding returnReview whether controlled reinitiation is appropriate
R10Receiver does not know the Originator and/or did not authorize the debitUnauthorized returnStop automatic retry and retrieve authorization evidence
R29Corporate customer advises debit was not authorizedUnauthorized business-account returnInvestigate account type and authorization
0.5%Unauthorized-return thresholdNacha RulesInvestigate immediately and coordinate with provider/ODFI
3%Administrative return-rate levelNacha inquiry levelCorrect R02/R03/R04 account-data problems
15%Overall return-rate levelNacha inquiry levelSegment all return causes and remediate
WEB validationValidation of first-use consumer account informationNacha WEB ruleValidate applicable account information before first use
ReinitiationResubmission of a returned entry under limited conditionsNacha RulesApply return-code-specific logic; maximum two qualifying reinitiations

The distinction between threshold and level matters when monitoring dispensary ACH return rate thresholds. Nacha maintains a 0.5% unauthorized-return threshold, while the 3% administrative and 15% overall figures are separate return-rate levels that can trigger review rather than automatic merchant termination under the ACH Network risk and enforcement framework.

Crossing either of the latter levels can begin an inquiry, but does not automatically constitute a Rules violation or automatically shut down a dispensary.

What an ACH Return Means at a Cannabis Dispensary

A dispensary checkout can make a bank payment look simple. Behind it, several parties may be involved:

Customer bank account → payment platform → Originator/Third-Party Sender → ODFI → ACH Network → RDFI

The Originator is the party that initiates the ACH entry under an authorization from the Receiver. A Third-Party Sender (TPS) may act as an intermediary between an Originator and an Originating Depository Financial Institution, or ODFI. The RDFI, or Receiving Depository Financial Institution, receives the ACH entry for the customer’s account.

The Receiver is the person or organization whose account is affected by the entry. A WEB debit is a consumer debit falling within Nacha’s Internet-initiated/mobile authorization framework.

Your dispensary may deal only with a payment platform. That does not mean the dispensary itself necessarily submits ACH files directly to an ACH Operator.

The payment provider, Third-Party Sender, sponsor bank and ODFI may therefore have obligations and risk controls that the merchant never sees at checkout. Understanding that chain helps explain why a provider can restrict an account before a merchant ever receives a communication from Nacha.

A dispensary deciding where ACH fits in its checkout stack should understand the operational differences between PIN debit, cashless ATM, and ACH payment models, because each method follows a different transaction flow and creates different settlement, return, and compliance considerations.

R01 vs R10 vs R29: What the Return Codes Actually Tell You

R01 insufficient funds versus unauthorized ACH returns at a cannabis dispensary
CodePlain-English MeaningTypical Dispensary ScenarioCounts Toward Unauthorized Rate?Reinitiation?Best Response
R01Insufficient fundsCustomer lacks available fundsNoGenerally eligible under reinitiation rulesControlled retry review
R10Originator unknown and/or not authorizedCustomer denies authorizing dispensary debitYesNo automatic reinitiationStop and investigate
R29Corporate customer advises not authorizedBusiness account rejects debitYesNo automatic reinitiationInvestigate authorization/account type
R02Account closedOld bank account suppliedNo; administrativeCorrect/remedy firstObtain valid account
R03No account/unable to locateAccount information cannot be matchedNo; administrativeCorrect/remedy firstValidate data
R04Invalid account-number structureStructurally invalid account dataNo; administrativeCorrect/remedy firstCorrect data
R07Authorization revokedCustomer withdrew prior authorizationYesDo not simply retryStop debit activity
R11Entry not in accordance with authorizationWrong amount/date or another authorization defectYesCorrected new entry may be permittedCorrect underlying error
R20Non-transaction accountAccount cannot accept the entryNoNot without remedyObtain appropriate account

R01 — Insufficient Funds

R01 is fundamentally a funding failure, not proof of an authorization failure. The account does not have sufficient available funds to satisfy the debit.

Nacha permits reinitiation of an entry returned for R01 insufficient funds or R09 uncollected funds, but not indefinitely. A returned debit may be reinitiated a maximum of two times, subject to the Rules. Nacha’s published guidance also states that qualifying reinitiation must occur within 180 days of the original entry’s Settlement Date.

A reinitiated entry must carry RETRY PYMT in the Company Entry Description. The Company Name, Company ID and amount must remain identical to the original entry; other fields may change only as permitted to correct an error or facilitate processing.

That does not make two retries a recommended default. If a dispensary indiscriminately retries every R01, it can increase total returns, push dispensary ACH return rate thresholds closer to provider or Nacha review levels, and create customer friction without solving the underlying funding problem.

R10 — Customer Advises Originator Is Not Known or Not Authorized

Nacha currently defines R10 as “Customer Advises Originator is Not Known to Receiver and/or Originator is Not Authorized by Receiver to Debit Receiver’s Account.”

It applies when, for example, the customer does not recognize the Originator, has no relationship with it, or says the Originator was not authorized to debit the account.

That makes R10 much more serious than R01 from an authorization perspective.

An R10 should trigger retrieval of the customer’s authorization, checkout record and relevant transaction evidence. For qualifying consumer unauthorized-return claims, the RDFI’s process includes obtaining a Written Statement of Unauthorized Debit.

Most importantly, Nacha states that an entry returned as unauthorized cannot simply be reinitiated. If the Originator obtains a new authorization after receiving the return, a later debit is not treated as reinitiation of the unauthorized entry.

That timing distinction prevents merchants from using pre-written language to evade the prohibition on repeatedly sending unauthorized debits.

R29 — Corporate Customer Advises Not Authorized

R29 applies to a non-consumer/corporate account when the customer advises that the debit was not authorized.

A dispensary might encounter R29 when someone enters a company bank account, when an account has debit blocks or controls, or when the person making the purchase lacks authority over the account.

R29 belongs in the current unauthorized-return-rate calculation. Do not exclude it merely because it involves a business account.

R11 Deserves Special Attention

R11 means the customer advises that the entry was not in accordance with the terms of the authorization. Unlike R10, an authorization exists, but the entry does not conform to it.

Examples include an incorrect amount or an entry submitted earlier than authorized. Nacha currently treats R11 as an unauthorized-return-rate code and requires a WSUD for the extended consumer-return process.

R11 also has an important remediation distinction: if the underlying error can be corrected, the Originator may submit a corrected new entry without obtaining a new authorization. Nacha says that corrected entry must be originated within 60 days of the R11 Return Entry’s Settlement Date.

Dispensary ACH Return Rate Thresholds: The Three Numbers That Matter

Dispensary dashboard monitoring unauthorized administrative and overall ACH returns
CategoryCurrent Nacha FigureIncluded ReturnsConsequence
Unauthorized0.5% thresholdR05, R07, R10, R11, R29, R51Rules enforcement implications; requires close ODFI monitoring
Administrative3% levelR02, R03, R04Can initiate preliminary inquiry
Overall15% levelAll debit returns; RCK entries/returns may be excluded as specifiedCan initiate preliminary inquiry

The 0.5% Unauthorized-Return Threshold

Nacha’s current unauthorized-return calculation includes R05, R07, R10, R11, R29 and R51.

Under Nacha’s current unauthorized-return-rate calculation methodology, the unauthorized category includes R05, R07, R10, R11, R29, and R51. That current six-code list matters because older materials published before the R11 change can still appear in search results.

That current list matters. Older Nacha pages can still be found that predate the addition of R11 and therefore list only five codes. Nacha’s newer calculation guidance expressly includes R11, so the six-code list is the appropriate current list.

Nacha gives two approved calculation approaches. In broad terms, unauthorized debit returns are measured against the corresponding debit origination population for the preceding 60 days or two calendar months.

ODFIs are responsible for continuing to monitor the return rates of their Originators and Third-Party Senders.

The 3% Administrative Return-Rate Level

The administrative category contains R02, R03 and R04.

These returns generally point toward closed accounts, account-location problems or invalid account-number structures rather than customer claims that the debit was unauthorized.

Nacha’s July 2025 calculation guidance confirms that the 3% level uses the preceding 60 days or two calendar months methodology.

Exceeding 3% is not automatically a Rules violation. It provides an evaluation point at which Nacha can inquire into the Originator’s or Third-Party Sender’s origination practices.

The 15% Overall Return-Rate Level

The overall level captures debit returns across return reasons. Under Nacha’s current calculation guidance, RCK entries and RCK returns may be excluded from the numerator and denominator.

The same preceding 60-day/two-calendar-month measurement framework applies.

This is why a dispensary cannot monitor R10 alone. Heavy R01 activity can push total returns upward even when unauthorized activity remains low.

Worked Example: How Fast Can 0.5% Become a Problem?

Consider an illustrative merchant with 2,000 relevant debit entries during the applicable measurement period.

Suppose 12 corresponding returns carry codes included in the unauthorized-return calculation:

12 ÷ 2,000 = 0.60%

That illustrative result exceeds 0.5%.

It does not mean “12 returns automatically shut down the merchant.” It shows why lower-volume merchants should not wait for dozens of authorization disputes before investigating. With modest ACH volume, dispensary ACH return rate thresholds can move materially after only a small cluster of unauthorized returns.

Crossing a Nacha Level Does Not Necessarily Mean Instant Shutdown

Four different concepts need to stay separate:

  1. Nacha Rules establish ACH Network obligations.
  2. Nacha inquiry/enforcement provides mechanisms for investigating and addressing problematic activity.
  3. ODFIs monitor and manage Originators and Third-Party Senders.
  4. Payment providers and TPSs can impose their own contractual risk limits.

For the 3% and 15% levels, Nacha explicitly says exceeding the level does not automatically constitute a Rules violation or immediately trigger a fine. The inquiry can ultimately result in no further action or, depending on the findings, a directive to reduce returns.

Even when dispensary ACH return rate thresholds remain below Nacha’s published figures, your cannabis ACH provider can still act sooner under its own agreement. Possible provider actions include enhanced monitoring, authorization sampling, reserves, reduced limits, delayed settlement, temporary suspension or termination.

Those are possible contractual risk controls, not universal Nacha requirements. Never assume that being below 0.5%, 3% or 15% guarantees continued processing.

Why Cannabis ACH Providers May React Earlier

Cannabis banking risk now requires more precise language than the familiar statement that “all marijuana remains Schedule I.”

In April 2026, DOJ announced an order placing FDA-approved marijuana products and marijuana products subject to a qualifying state-issued medical marijuana license into Schedule III. DOJ and DEA simultaneously continued proceedings concerning broader marijuana rescheduling.

That limited action does not mean every state-licensed dispensary transaction now receives identical federal treatment. Adult-use activity and products outside the scope of the order still require careful federal-law analysis, and broader rescheduling remained the subject of the DEA proceeding described in its 2026 materials.

FinCEN’s marijuana-related-business guidance also remains important for banking relationships. It places due-diligence and BSA expectations on financial institutions that elect to serve marijuana-related businesses and makes clear that the decision to open, maintain or refuse a relationship depends on each institution’s risk assessment and capacity.

So ACH availability is not the same thing as federal approval of the dispensary. A bank, ODFI or provider can maintain its own cannabis risk appetite.

Nacha does not establish a separate 0.5%, 3% or 15% schedule specifically for marijuana merchants.

A New 2026 ACH Risk Requirement Also Matters

As of June 19, 2026, Nacha’s Phase 2 fraud-monitoring amendments apply to all non-consumer Originators, Third-Party Service Providers and Third-Party Senders that were not already covered by Phase 1.

Covered parties must establish and implement risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud.

This requirement is broader than simply calculating return percentages. A cannabis ACH operation should therefore treat fraud monitoring, account validation, authorization controls and return-rate monitoring as related but distinct controls.

ACH Returns Are Not Card Chargebacks

IssueACH Return / Unauthorized DebitCard Chargeback
Primary frameworkNacha Rules plus applicable banking/EFT lawCard-network rules plus applicable law
RailACH NetworkCard network
Customer dispute pathReceiver/RDFI processCardholder/issuer/network dispute
Key merchant evidenceACH authorization and transaction recordsNetwork-specific transaction evidence
TimingDepends on return reason and account typeDepends on card-network rules
ReinitiationSpecifically restricted by NachaDifferent dispute/representment structure
Risk measurementACH return rates/provider controlsAcquirer/network dispute monitoring

Calling an ACH return an “ACH chargeback” may be convenient conversationally, but it obscures important operational differences.

What the Consumer “60-Day Rule” Actually Means

“Consumers can charge back ACH payments for 60 days” is too broad.

Under Regulation E §1005.11, a consumer generally must notify the financial institution of a qualifying EFT error no later than 60 days after the institution sends the periodic statement on which the alleged error first appears. Unauthorized EFTs are one category of error covered by that procedure.

Regulation E then governs the financial institution’s investigation and error-resolution obligations. Consumer liability for unauthorized EFTs is addressed separately under Regulation E, including §1005.6.

That statutory/regulatory framework is distinct from Nacha’s operational return deadlines.

For applicable consumer unauthorized ACH returns, Nacha provides an extended return process and requires a WSUD. Other ACH returns can have much shorter deadlines; for example, non-consumer returns commonly operate within the standard two-banking-day framework depending on the return reason.

Authorization Evidence: What the Dispensary Should Capture

In-Store Bank Payments

Do not label every bank-account payment a WEB debit.

The appropriate SEC code depends on the type of account, authorization method and transaction architecture. Ask your provider to identify the SEC code it originates and the authorization requirements that follow from that classification.

Using the wrong SEC code is not a harmless reporting choice.

Online or Mobile Pre-Pay

For applicable WEB debits, Nacha requires Originators to use a commercially reasonable fraudulent transaction detection system. Since March 2021, that system must include account validation for the first use of an account number and before the use of a changed account number, subject to specific rule details and exceptions.

Nacha defines the minimum account-validation standard as determining that the account is legitimate, open and capable of receiving ACH entries.

Critically, Nacha expressly says that this minimum standard does not require verification of account ownership. Depending on the Originator’s risk profile, stronger verification may still be appropriate.

Authorization Evidence Checklist

Rule-driven evidence, depending on the SEC code and transaction, may include:

  • the authorization itself;
  • identification of the Originator;
  • authorized amount or method for determining it;
  • single-entry, standing or recurring status where applicable;
  • authorization method;
  • records needed to provide proof of authorization when required.

Useful operational evidence may include:

  • authorization timestamp;
  • transaction/order identifier;
  • checkout session records;
  • account-validation result;
  • confirmation or receipt;
  • customer-service history;
  • revocation records.

Provider-specific requirements may add:

  • device or IP evidence;
  • identity-verification results;
  • particular authorization language;
  • additional retention requirements.

Do not confuse recommended evidence with a universal Nacha field checklist. The applicable SEC code and provider architecture determine the actual rule requirements.

Account Validation Before the First WEB Debit

Nacha does not prescribe one validation technology.

Its guidance identifies options including prenotifications, micro-entry verification, commercially available validation services and API-enabled validation capabilities.

Validation can help catch invalid account information and some account-entry fraud before a live debit.

It cannot guarantee:

  • sufficient funds on settlement day;
  • that the person entering the account owns it;
  • that the customer validly authorized the purchase;
  • that a future debit will be authorized;
  • that the customer will never dispute the transaction.

A dispensary trying to reduce ACH returns from cannabis payments therefore needs both account validation and authorization controls.

When You Can Re-Present an R01 — and When You Must Stop

ACH return workflow showing when to retry stop review or correct a bank debit
ReturnReinitiation Generally Possible?ConditionsStop/Correction Rule
R01YesNacha reinitiation requirements; max two reinitiationsStop after permitted attempts
R09YesSame limited reinitiation frameworkStop after permitted attempts
R08Only with separate Receiver authorizationMust meet applicable ruleNo automatic retry
R10No automatic reinitiationNew authorization obtained after return can support a new entryInvestigate first
R07No simple retryPrior authorization was revokedNew valid authorization needed
R11Corrected new entry may be possibleCorrect defect; special R11 rules applyCorrect rather than blindly retry
R02/R03/R04Only after underlying problem is remedied where Rules permitCorrect valid account informationNever repeatedly submit known-bad data

Nacha limits qualifying R01/R09 reinitiation to two attempts. It also prohibits changing entry information merely to evade that limit.

A legitimate later installment in a preauthorized recurring series is not automatically a reinitiation simply because an earlier installment returned, provided the later debit was not contingent on the earlier return.

That distinction matters for recurring or account-on-file arrangements.

Practical Ways to Reduce ACH Returns at a Cannabis Dispensary

Keeping dispensary ACH return rate thresholds under control requires more than lowering the total number of failed payments. The merchant needs to know which return codes are increasing, why they are occurring, and whether the correct response is account correction, authorization review, fraud investigation, or limited reinitiation.

  1. Validate applicable WEB accounts before first use: Do not use a live-dollar debit as an improvised validation process when Nacha’s WEB rules require account validation.
  2. Make authorization conspicuous: The customer should understand who is debiting the account, what is being authorized and whether the payment is single-entry or part of a broader arrangement.
  3. Use a recognizable bank-statement description: Customer recognition can reduce confusion, although a clear description cannot turn an unauthorized transaction into an authorized one.
  4. Separate NSF from authorization problems: Rising R01 activity needs different remediation from rising R10, R11, R29 or R07 activity.
  5. Set retry logic by return code: Never configure “retry every failed ACH twice.”
  6. Apply risk-based velocity controls: Monitor repeated attempts, unusual ticket sizes, rapid account changes, multiple accounts tied to one customer and clusters of failures. The exact limits are business/provider risk controls, not universal Nacha numbers.
  7. Calculate return rates before your provider contacts you: Monitor unauthorized, administrative and overall rates on the correct 60-day/two-calendar-month basis.
  8. Investigate sudden changes: Determine whether a spike comes from fraud, an integration defect, bad account entry, unclear authorization, an SEC-code problem, descriptor confusion or improper reinitiation.

Return monitoring should also connect to daily reconciliation. A consistent process for reconciling dispensary POS activity with seed-to-sale records makes it easier to distinguish an ACH payment failure from an inventory, register, refund, or reporting discrepancy.

A Weekly ACH Return Dashboard for Dispensaries

A weekly dashboard gives operators an early view of dispensary ACH return rate thresholds before a provider warning arrives. The goal is not merely to track the three external percentages, but to identify which return codes are driving them and whether the trend is worsening.

MetricThis PeriodPrevious PeriodInternal AlertAction
Debit entries______Volume anomalyVerify batches
Unauthorized returns______Set below external/contractual limitReview authorization
Unauthorized rate___%___%Below 0.5% and provider limitEscalate rising trend
Administrative rate___%___%Below 3% and provider limitReview account data
Overall rate___%___%Below 15% and provider limitSegment causes
R01 count______Merchant-defined warningReview NSF strategy
R10/R11/R29______Merchant-defined low tolerancePull authorization evidence
Validation failures______Trend-basedReview checkout/account entry

The internal alerts should be set below applicable contractual or external limits, based on the provider relationship and the merchant’s own risk tolerance.

There is no authoritative universal “safe cannabis ACH percentage” below which a provider cannot act.

What an ACH Program Warning May Look Like

A provider warning might request:

  • a return-code report;
  • authorization samples;
  • account-validation procedures;
  • explanation of elevated returns;
  • fraud controls;
  • transaction records;
  • customer-support procedures;
  • corrective actions and implementation dates.

That is an illustrative list, not a standardized Nacha warning letter.

Depending on its contract and risk policy, a provider could impose enhanced monitoring, restrict volume, change funding terms, require reserves, temporarily suspend origination or terminate service.

48-Hour Response Plan After a Provider Warning

  1. Stop indiscriminate automated retries.
  2. Export forward-entry and return data.
  3. Recalculate the three return-rate categories correctly.
  4. Segment every significant return code.
  5. Retrieve authorization records for R10/R11/R29/R07 activity.
  6. Review WEB account-validation records.
  7. Check SEC-code configuration and recent integration changes.
  8. Review statement descriptions and merchant identification.
  9. Contact the provider’s risk/compliance team.
  10. Submit a written corrective-action plan and monitor daily.

Do not attempt to protect the account by changing descriptors, entities, MCCs or transaction routing to conceal cannabis activity. That creates a different and potentially more serious compliance problem.

Common Mistakes That Threaten a Dispensary ACH Program

MistakeBetter Approach
Retry every returnApply code-specific rules
Treat R10 like R01Stop and investigate authorization
Ignore R11Count it in unauthorized monitoring and correct the defect
Assume account validation proves ownershipTreat validation and authorization separately
Ignore R02/R03/R04Investigate account-data quality
Calculate only weekly percentagesMaintain the applicable 60-day/two-month calculation
Treat 3% and 15% as automatic violationsUnderstand the Nacha inquiry process
Assume being below Nacha levels guarantees serviceReview provider contractual limits
Use one SEC code for every bank paymentMatch SEC code to actual authorization architecture
Treat ACH returns as card chargebacksUse ACH-specific procedures
Change transaction information to evade retry limitsFollow Nacha reinitiation requirements

ACH Program Survival Checklist

  • Know the SEC codes being used.
  • Validate applicable WEB account information.
  • Maintain a commercially reasonable fraud-detection process.
  • Capture valid authorization.
  • Keep authorization records retrievable.
  • Track R05/R07/R10/R11/R29/R51 as unauthorized returns.
  • Track R02/R03/R04 as administrative returns.
  • Calculate overall returns.
  • Monitor R01 separately.
  • Configure code-specific reinitiation logic.
  • Enforce the two-reinitiation maximum where applicable.
  • Use RETRY PYMT where the reinitiation rule requires it.
  • Review merchant/statement descriptions.
  • Set internal warning levels below contractual limits.
  • Investigate unusual velocity and account changes.
  • Document corrective actions.
  • Know the provider’s risk escalation contact.
  • Maintain lawful contingency payment methods.
  • Never disguise the nature of cannabis transactions.

FAQs

What is the Nacha unauthorized ACH return-rate threshold?

The current Nacha unauthorized-return-rate threshold is 0.5%. Current calculation guidance includes R05, R07, R10, R11, R29 and R51 and uses the applicable preceding 60-day/two-calendar-month methodology.

Does R01 count toward the 0.5% unauthorized return rate?

No. R01 means insufficient funds and is not one of Nacha’s unauthorized-return codes. It can, however, contribute to the overall return rate.

Does R10 count as an unauthorized return?

Yes. R10 is included in Nacha’s current unauthorized-return-rate calculation. It addresses situations where the Receiver does not know the Originator and/or says the Originator was not authorized to debit the account.

Does R29 count toward the unauthorized return rate?

Yes. R29 is included in the current unauthorized-return calculation even though it concerns a corporate customer’s claim that a debit was not authorized.

How many times can an R01 ACH debit be retried?

A qualifying R01 entry can be reinitiated a maximum of two times under Nacha’s rules. Reinitiation must also meet the applicable timing, formatting and other requirements.

Can I retry an R10 after the customer says it was unauthorized?

Not as an automatic reinitiation. Nacha states that an unauthorized debit cannot be remedied through reinitiation. A new authorization obtained after receipt of the return can support a new entry, subject to the applicable rules.

What happens if my dispensary exceeds a 15% overall return rate?

The 15% level can initiate Nacha’s inquiry process into origination practices. It does not automatically constitute a Rules violation, create an immediate fine or require automatic merchant termination. Your provider may have stricter contractual policies.

Is an ACH return the same as a credit-card chargeback?

No. ACH returns operate under Nacha Rules, banking processes and applicable laws such as Regulation E. Card chargebacks use separate card-network dispute systems.

Does Nacha require account validation for every ACH debit?

No. The specific requirement discussed here concerns applicable WEB debits: the fraudulent-transaction-detection system must include account validation for first use of an account number and applicable account-number changes.

Can my cannabis ACH provider suspend me below a Nacha rate?

Yes. Nacha’s published threshold and levels do not prevent a provider, ODFI or Third-Party Sender from applying stricter contractual or risk-management requirements.

Keeping Dispensary ACH Return Rate Thresholds Under Control

Controlling dispensary ACH return rate thresholds starts with recognizing that not all returns mean the same thing.

R01 calls for funding and controlled-retry analysis. R02/R03/R04 point toward account-data quality. R10 and R29 demand authorization investigation. R11 requires attention to whether the entry actually matched the authorization.

The strongest ACH operation combines correct authorization, applicable WEB account validation, 2026 fraud-monitoring controls, return-code-specific remediation and accurate 60-day/two-calendar-month monitoring.

Just as important, keep Nacha rules separate from your provider’s cannabis risk policy. A dispensary can be below a Nacha benchmark and still violate its provider agreement, while crossing the 3% or 15% Nacha levels does not itself mean automatic shutdown.

Early detection is therefore the best survival strategy. Know which codes are rising, know why they are rising, preserve the evidence needed to explain them, and fix the underlying problem before returns become a banking-relationship problem.