SardineCon SF/2026

Learn More
FRAUDFORWARD
#106

負債から可視化へ:NACHA フェーズ2の真実の物語

14 min

やあ、フロードファイターのみんな、『Fraud Forward』へおかえり!

今日はACHコンプライアンスについてお話しします。「世界一ワクワクするオープニング」とは言えないかもしれませんが、もしあなたが不正対策、決済、オペレーション、コンプライアンス、財務、マネジメント、あるいはACHに少しでも関わる仕事をしているなら、これはとても重要なテーマです。なぜなら、ACHはこの国で最も広く使われている決済レールの一つだからです。そして、ひとたび問題が起きると、それは一つのチームの中だけにとどまりません。顧客への影響を生み、業務負荷を増大させ、規制上のリスクを高め、さらに、あなたの組織が不正を検知し対応する仕組みの抜け穴を露呈させる可能性があるのです。

ここ数か月の間に、地域銀行や信用組合の不正対策責任者たちと何度も話をしてきましたが、皆同じ疑問を抱いています。新しいテクノロジーは必要なのか?すべてのACH取引をリアルタイムで監視しなければならないのか?審査官は具体的に何を求めてくるのか?もしこうしたことで頭がぐるぐるしているなら、これだけは覚えておいてください。あなたは一人ではありません。

このエピソードでは、NACHA フェーズ2の本当の背景についてお話しします。私にとっての「本当の話」は、すべての金融機関が新たな不正検知プラットフォームを慌てて導入しなければならない、ということではありません。本質は、ACH コンプライアンスがこれまで以上に意図的で戦略的な議論の対象になっている、という点です。自社のリスクを正しく把握し、自社のプロセスを文書化し、誰が何を担当しているのかを理解し、自分たちの金融機関がなぜそのやり方で ACH 不正をモニタリングしているのかを説明できるようにすることが重要なのです。

実は、それは良いことだと私は思っています。というのも、あまりにも長い間、私たちの業界は「責任があるかどうか」だけをゴールラインとして頼りにしてきたからです。自分たちに法的な責任がなければ、それは本当の意味で自分たちの問題ではない、という考え方です。技術的・法的な意味では、確かにそう言える場面もあったかもしれません。しかし、業務運営の面でも、倫理の面でも、そして不正対策に取り組む者の視点から見ても、その考え方にはどうしても納得がいきませんでした。

不正行為はサイロの中だけで起こるものではありません。ACHの不正防止も同じであるべきではありません。

このエピソードでお届けする内容:

  • なぜNACHAフェーズ2は、単なるテクノロジーではなく「意図性」が重要なのか
  • 最終的なNacha ACH規則で何が変わり、その柔軟性がなぜ重要なのか
  • ACHコンプライアンスが、現在対象となっているコミュニティバンクおよび信用組合にどのように適用されるのか
  • なぜ多層的なコントロールが、必ずしも新たなベンダー製品の購入を意味するわけではないのか
  • 虚偽の口実がACH不正検知とACH不正防止にどのように関係するか
  • なぜRDFIコンプライアンスとODFIコンプライアンスには、チーム間での明確な責任分担が必要なのか
  • ACHコンプライアンスプログラムを審査する際に、検査官がどのような点を重視・期待するか
  • すべての金融機関がACH不正に関する文書について確認すべき5つの重要な質問

次のような方は、このエピソードをお聞きください:

  • 不正対策業務、決済コンプライアンス、ACHオペレーション、BSA、AML、または資金管理業務に携わっている方
  • あなたの金融機関は現在、NACHA フェーズ2の導入に取り組んでいます
  • プログラムを過剰に作り込みすぎることなく、ACH 審査官が何を求めているのかを理解しようとしている
  • あなたは地域の銀行または信用組合に勤務しており、実務的なACHコンプライアンスの指針を必要としています
  • 支払い詐欺において、責任追及中心の考え方から、可視性重視の考え方へと転換したいと考えている

このエピソードを気に入っていただけたら、ぜひ購読して、iTunes、Spotify、YouTube、またはお使いのポッドキャストアプリでレビューをお願いします。

エピソードノート

ACHコンプライアンスは、単なるテクノロジーではなくプロセスの問題です

これらの規則変更が最初に提案されたとき、多くの金融機関はすぐに最悪の事態を想定しました。「また新たな規制負担か」と。私は、ここから多くの混乱が始まったのだと思います。最初にこのルールが提案されたとき、誰もが「もっとテクノロジーが必要になり、もっとコストがかかり、もっとプレッシャーが増える」と受け止めました。しかし、NACHA が最終的に落ち着いた内容は、それよりもずっと現実的で地に足のついたものなのです。

本質的には、自分たちのリスクを正しく把握し、そのプロセスをきちんと説明できるようにすることが重要なのです。すべての機関が同じ体制を取る必要はなく、それは意図的なものです。大事なのは、自分たちの役割に合ったモニタリング体制を持ち、それを見直し、文書化し、なぜ自分たちにとって有効なのかを他者に分かりやすく説明できることです。これは「正しいツールを買ったか?」という話とはまったく別の次元の議論です。

多層的なコントロールが、必ずしもベンダーの数の増加を意味するわけではありません

私たちはいつの間にか、「多層防御」と聞くとすぐに「新しいシステムが必要だ」と考えるように自分たちを訓練してしまったのだと思います。ですが、多層化とはベンダーを積み重ねることではなく、導入しているコントロール同士がきちんと連携して機能するようにすることなのです。

多くの金融機関では、必要な要素自体はすでに揃っています。不正対策、マネーロンダリング対策(AML)、オペレーション、トレジャリーなど、各部門がそれぞれ何かしらを見ていますが、必ずしも連携しているわけではありません。本当に必要な対策は、新しいものを足すことではなく、すでに持っているものをつなぎ合わせ、責任範囲を明確にし、個々がサイロ化して動くのではなく、コントロール全体で一貫したストーリーを語れるようにすることなのです。

ACHコンプライアンスは、責任追及だけの発想から私たちを前進させるべきだ

ここで最も大きな変化の一つは、「自分に法的な責任がなければ自分の問題ではない」という考え方から離れることです。私はそのような考え方が昔から好きではありませんでしたし、今回のルールは、私たちを静かにその先へと進ませようとしているのだと思います。

不正対策に携わる人たちは、すでに「何かおかしい」と感じる瞬間をよく知っています。問題は、その違和感に基づいて行動するのか、それとも誰か別の人の責任になるまで待つのかという点です。ACHコンプライアンスとは、実際には、すでに持っている可視性を活かし、たとえ法的な責任が自分にない場合でも、「これはもっと注意深く確認すべきだ」と思える瞬間に踏み込む姿勢を持つことにほかなりません。

虚偽の名目自体は目新しいものではありませんが、その表現の仕方が重要です

「虚偽の名目(false pretenses)」と聞くと、まったく新しいカテゴリーのように聞こえるかもしれませんが、実際には、私たちが何年も前から目にしてきたものに名前を付けているだけです。たとえば BEC(ビジネスメール詐欺)やなりすまし詐欺、形式上は顧客が支払いを承認しているものの、その承認自体が誘導や操作によって引き出されたようなケースなどがそれにあたります。

ここで重要なのは、「承認されたからといって、必ずしも本人の意図どおりとは限らない」という認識です。すべての取引の裏で何が起きていたのかを、あなたが完全に把握している必要はありません。ただ、何かが噛み合わない、口座の動きと合致しない取引や、いつもと違う不自然なパターンが見えたとき――それが、詳しく確認すべきサインです。優れた不正対策は、いつだってそこから始まります。

ACHコンプライアンスの文書化は、まず所有者の特定から始まります

物事がうまくいかなくなりがちな一番の原因があるとすれば、それは「責任の所在」です。ACH には多くのチームが関わるため、そのような状況になると、誰が何を担当しているのかが非常にあいまいになりやすいのです。

最終的には、誰がレビューし、誰が意思決定を行い、誰が記録を残しているのかを、はっきり答えられる人がいなければなりません。これをうまく運用できている機関が、必ずしも最も多くのリソースを持っているとは限りません。プロセスが明確で、引き継ぎが筋が通っており、誰も「何の責任を誰が持っているのか」を手探りしていない、そういう機関こそがうまくいっているのです。

チームに持ち帰って検討したい5つのACHコンプライアンスに関する質問

自社の状況を把握しようとしているなら、まずはシンプルに考えましょう。自社のACHモニタリングプロセスを明確に説明できますか?各ステップの責任者が誰か把握していますか?導入している管理策が、自社のリスクに対して妥当であると説明・正当化できますか?

これらの質問に「ないもの」に注目してください。新しいテクノロジーを買うことについては一言も触れていません。ここで問われているのは、自分たちのプログラムをどれだけ理解しているかです。何か新しいものを追加する前に、すでに何を持っていて、それがどう機能していて、必要なときにチームが自信を持って説明できるかどうかを明確にしましょう。本当に強いプログラムは、まさにそこから始まります。

重要なポイント
  • ACHコンプライアンスとは、新しいテクノロジーを導入することだけでなく、明確で文書化されたプロセスを持つことを意味します
  • NACHAフェーズ2は柔軟性を提供し、各機関が自らの役割とリスクプロファイルに合わせてモニタリングを調整できるようにします
  • 多層的な管理体制は、ベンダーを増やす必要はなく、チーム間の連携と明確な役割分担を強化することが重要です
  • 責任追及の発想から脱却することで、金融機関は損失が発生してから対応するのではなく、詐欺を事前に積極的に防止できるようになります
  • 虚偽の口実自体は新しいものではありませんが、正式に認識されることで、金融機関などの組織がこれらの事例にどのように対処するかを標準化する助けになります
  • 不正検知は、多くの場合、想定される顧客行動のパターンから外れる兆候を見つけることから始まります
  • 不正対策、オペレーション、コンプライアンス、財務(トレジャリー)各チームの明確な責任分担は、効果的なACHモニタリングにとって極めて重要です
  • 審査官の期待に備えるうえでは、ツールの選定よりも文書化とガバナンスの方が重要です
  • コミュニティバンクや信用組合は、業界からの圧力ではなく、自らの固有のリスクを反映したACHコンプライアンスプログラムを構築すべきである
  • 適切な社内の問いを立てることが、ACHコンプライアンスプログラムを強化するための第一歩です

最終的なポイント:

このエピソードからぜひ持ち帰ってほしいポイントは次のとおりです。NACHA フェーズ2は、優れた不正対策プログラムがこれまで一貫して目指してきたことを本質的に変えるものではありません。それを正式な形にするものです。

不正対策の専門家は常に、筋の通らない取引を探してきました。私たちはいつも点と点を結びつけ、常に疑問を投げかけてきました。私たちはこれまでずっと、経験や好奇心、記録・文書化、そして協働に頼ってきたのです。

今では、そうした期待が規則の中により明確に書き込まれています。

そして、それは前向きな一歩だと考えています。なぜなら、不正行為は減速していないからです。決済に関する不正は、より組織化され、より自動化され、そしてより高度になってきています。成功する機関は、必ずしも最先端の華やかなテクノロジーを持っているところとは限りません。自らのリスクを理解し、部門横断でコミュニケーションを取り、意思決定を文書化し、自分たちの管理策が今も妥当かどうかを継続的に評価しているところこそが、成功するのです。

さらに詳しく知りたい場合は、Sardine のリソース(フェーズ1フェーズ2、および新たに示された「虚偽の申し立て(false pretenses)」」に関するガイダンス)をご覧ください。これらやその他のリソースへのリンクを以下に掲載しています。チームで ACH コンプライアンス文書を作成・検討する際の参考資料として最適です。

そしていつものように、このエピソードを不正対策、決済、オペレーション、財務、あるいはコンプライアンスに携わる方と共有してください。こうした対話は、組織全体を巻き込んで行われるときにこそ、最大の価値を発揮します。

常に警戒を怠らず、情報をアップデートし続け、フロードフォワードを前進させていきましょう。

Episode transcript
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
00:05
What’s up, fraud fighters? Welcome back to another episode of Fraud Forward. Today we’re talking about something that if you work in payments, fraud, operations, compliance, treasury management, or honestly anywhere near ACH, you’ve probably been hearing a lot about over the last few months. Nacha’s new fraud monitoring rules. Back in March, the team at Sardine published a deep dive breaking down the rule changes, explaining the differences between ODFI and RDFI responsibilities, and helping institutions understand what was actually changing. More recently, we followed that up with another article focused specifically on Phase 2 because as of June 22, these requirements now apply to many community banks and credit unions that weren’t previously in scope. Since then, I’ve had conversations with fraud leaders all over the country, and I keep hearing the same questions. Do we need technology? Are we expected to monitor every ACH transaction in real time? What exactly are examiners going to expect? And if that’s where your head is right now, hopefully by the end of this episode, you’ll realize something. The rule isn’t about technology. It’s about intentionality. It’s about understanding your risk, documenting your processes, and making sure your institution can explain why it monitors fraud the way that it does. And I mean, I think it’s a really good thing. So let’s jump into it.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
01:40
Okay, I think that we need to separate myth from reality. When these rules were first proposed, I think a lot of people immediately assumed the worst. It’s another regulatory burden, another expensive compliance project, another reason to buy yet another fraud detection platform. Fortunately, though, that’s not where Nacha landed. One of the biggest changes between the proposed rule and the final rule is that they intentionally built flexibility into the requirements.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
02:12
The phrase “commercially reasonable” disappeared. The expectation for detection systems became processes and procedures. Monitoring only applies to the role your institution actually plays in the ACH ecosystem. There’s no requirement for pre-processing monitoring, and institutions are expected to review their processes at least annually, not reinvent them every few months. Those aren’t small wording changes. Those are meaningful shifts. And to me, it signals that Nacha understands community FIs don’t all operate the same way. A billion-dollar community bank shouldn’t be expected to have the exact same fraud program as one of the nation’s largest financial institutions. Likewise, a small community credit union shouldn’t feel pressured to implement enterprise-level technology just because a new rule was published. Instead, the expectation is actually pretty straightforward. Know your risk. Have a process. Document that process. Review it periodically. Be able to explain why it makes sense. And I think that’s such a much different conversation than simply asking whether you purchased the latest fraud software. And that brings me to something I think we’ve gotten wrong as an industry. We’ve started equating layered controls with buying more technology. Those are not the same thing. When people hear the phrase layered controls, they often picture another vendor on top of a vendor, another dashboard, another alert queue, another subscription. But layered doesn’t necessarily mean adding more. Sometimes it means understanding the controls you already have. I’ve seen institutions where fraud is monitoring one thing, AML is monitoring something very similar, operations has another report, and treasury has yet another spreadsheet.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
04:02
Four different teams, four different processes, and no one has ever stepped back to ask whether they’re actually working together. Sometimes layering means improving communication instead of buying another solution. You know, at Sardine, we’ve spent a lot of time talking about risk orchestration instead of point solutions. The goal shouldn’t be to stack technology indefinitely, right? The goal should be making sure every control has a purpose and every layer complements the others. And here’s something I think every institution needs permission to hear. If you’re relying on the same fraud solution you selected 15 or 20 years ago, it’s okay to reevaluate that relationship. Fraud has changed dramatically. The way criminals operate has changed dramatically. AI has accelerated everything. It’s perfectly reasonable to ask whether your current tools are keeping pace. That doesn’t mean you need another vendor. Sometimes it means replacing one that no longer fits your institution’s needs. Technology should support your strategy. It shouldn’t become your strategy. Speaking of changing strategies, there’s one part of these rule updates that I genuinely love because I think it challenges a mindset our industry has carried around for far too long. And it’s the liability mindset. So one of the reasons I appreciate these rule changes so much is because they encourage institutions to look beyond liability. For years, I’ve heard variations of this same statement. If we’re not liable, it’s not really our problem. Okay, technically, sometimes that’s true. Operationally, it might even be accurate. But ethically, that’s a different conversation.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
05:51
I remember during the height of COVID and the PPP program reviewing incoming ACH files manually. There were business accounts that had averaged less than $1,000 for an entire year. Then almost overnight, they received PPP deposits well into six figures. Everything about those transactions stood out. The account history didn’t match. The balances didn’t make sense. The activity looked completely different than what we’d expect to come from those customers. Sure, my institution might not have been liable if something turned out to be fraudulent. And yes, our BSA team would eventually investigate suspicious activity and determine whether a SAR needed to be filed. But I kept asking myself the same question. How could I watch something that obviously didn’t fit the account’s history and simply ignore it because someone else technically owned the liability? That never sat well with me. Reporting suspicious activity after the money is gone isn’t the same as preventing fraud in the first place. What I appreciate about these rules is that they encourage institutions to use that visibility that they already have. Fraud fighters are naturally curious. We notice patterns. We recognize when something doesn’t fit. These rules don’t ask us to predict the future. They simply encourage us to act when something deserves a closer look. I think that’s a healthy shift for the industry. [Ad Break (7:20): Finally, I’m so happy to share with you all that The Saturday Fraud Strategist is now a podcast. What? Yeah. On top of my weekly newsletter, you can now listen to and watch me talk about my, and hopefully your, favorite topic: fraud strategy. And from time to time, I’ll be hosting operators and founders to discuss where the industry is headed and what we fraud fighters should pay attention to. I must say, I’m super excited, and if I’m being honest, a bit nervous about all of this. I’ve been debating with myself whether to start a podcast for ages, but kept putting it off. But now this is the result, so I guess there’s no turning back. So if you want to join me for the ride, head over to Sardine’s website and subscribe now. Are you ready? Am I ready? We’ll find out next Saturday.]
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
08:19
And speaking of things that don’t make sense, let’s talk about one of the most discussed additions to these fraud rules, and that’s false pretenses. I think one of the biggest additions in these updates is the formal definition of false pretenses. When you first read the definition, it sounds like something entirely new, but it really isn’t. Nacha defines false pretenses as inducing someone to make a payment by misrepresenting your identity, your authority, and/or who owns the account receiving the money. If you’ve worked fraud for any length of time, you’ve already investigated these cases. Business email compromise, vendor impersonation, payroll impersonation, executive impersonation, romance scams involving payment deception. The fraud itself isn’t new, but this language is. For years, fraud professionals have understood that a customer can willingly authorize a payment and still be the victim of fraud. Just because someone clicked send doesn’t mean they weren’t manipulated into doing so. Nacha is finally acknowledging that reality. And another question I hear all the time is: how is an RDFI supposed to know whether a payment was authorized under false pretenses? The answer is you probably won’t know with certainty, and that’s okay. The rule isn’t asking institutions to read people’s minds. It’s asking institutions to recognize patterns that don’t make sense. Maybe it’s a corporate ACH entry being sent into a consumer account. Maybe it’s a brand-new account suddenly receiving multiple payroll deposits. Maybe it’s a dormant account that suddenly comes to life with large incoming credits. Maybe it’s transaction activity that’s completely inconsistent with customers’ historical behavior. Those situations don’t automatically prove fraud. They simply justify taking a closer look. And honestly, that’s exactly how fraud investigations have always started. Not with certainty, but with curiosity. There’s one more thing I think these rules highlight that doesn’t get talked about nearly enough, and that’s ownership.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
10:19
What really stands out to me is how many different departments these rule changes touch. ACH isn’t owned by one team. Fraud touches it. Operations, compliance, treasury management, commercial banking, relationship managers, all touch it. We’re in the process of conducting the fraud benchmarking research, and one theme that keeps coming through over and over again is that fraud teams are stretched thin. Many institutions don’t have clear ownership over certain processes. Sometimes everyone assumes that someone else is responsible. These new expectations expose those gaps because eventually someone has to answer questions like who reviews this alert, who makes the decision, who documents why the institution did or didn’t take action. Technology doesn’t answer those questions. Governance does. Communication does. Leadership does. The institutions that will navigate these rule changes most successfully won’t necessarily have the biggest budgets. They’ll have the clearest processes. So if you’re wondering where to start, let me leave you with five questions. If I were sitting down with a community bank or credit union tomorrow, these are the five questions I’d ask. Can your institution clearly explain its ACH fraud monitoring process? Do you know who owns every step of that process? Are you relying on vendors or controls that haven’t been evaluated in years? Could you explain why your controls are appropriate for your institution’s risk profile? And finally, if an examiner walked into your institution tomorrow morning, could your team confidently explain your approach? Notice that none of those questions ask whether you purchased a new system. They’re all focused on understanding your own program. And that’s exactly where I think institutions should spend their time. As I wrap up today’s episode, here’s what I hope you’ll remember. Phase 2 doesn’t fundamentally change what good fraud programs have been doing all along. It just formalizes it. Fraud professionals have always looked for transactions that don’t make sense. We’ve always connected the dots. We’re always asking questions. We’ve always relied on experience, curiosity, and collaboration. Now those expectations are simply written into the rules.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
12:44
And I think it’s a positive step because fraud isn’t slowing down. It’s becoming more sophisticated. It’s becoming more organized. It’s becoming more automated. The institutions that will succeed aren’t necessarily the ones with the biggest budgets or the flashiest technology. They’re the ones that understand their risks, communicate across departments, document their decisions, and continuously evaluate whether their controls still make sense. At the end of the day, that’s what these rule changes are really asking us to do. If you’d like to go deeper into these rule changes, I’ve linked both Sardine articles in the show notes, including a webinar that we did on Phase 1, along with additional resources covering Phase 1, Phase 2, and the new guidance around false pretenses. They’re great companion pieces if you’re working through implementation with your team. As always, thank you for listening. If you’ve enjoyed today’s episode, I’d really appreciate it if you shared it with someone in fraud, payments, operations, or compliance. These conversations are most valuable when they happen across the entire institution. So until next time, stay vigilant, stay informed, and keep moving fraud forward.
A blonde woman in a black blazer smiles slightly against a purple background.
Hailey Windham
14:01
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today’s episode sparked an idea, share it with your team, or tag me on LinkedIn. I love hearing how you’re moving fraud forward in your own organization. Until next time, stay curious, stay resilient, and keep moving fraud forward.