Core Bank Business Account Agreement

ACH Returned Entry Thresholds


Last updated: Jan 20, 2026

Unauthorized Entry Return Rate (0.5%):

This threshold applies to the percentage of debit entries returned as unauthorized, including return reason codes R05, R07, R10, R29, and R51. The rate is calculated by dividing the number of debits returned as unauthorized by one of the following:

The total number of debit entries in original files, or The total number of debit entries originated. The Unauthorized Entry Return Rate must stay below 0.5%. Exceeding this threshold may result in further review and corrective action.

Administrative Return Rate (3%):

The Administrative Return Rate tracks return reason codes R02, R03, and R04. These returns must remain below 3%. If the administrative return rate exceeds this threshold, the Bank may initiate corrective measures to address any underlying issues.

Overall Return Rate (15%):

The Overall Return Rate includes all return reason codes (excluding RCK entries). This rate must stay below 15%. If the overall return rate surpasses this threshold, additional monitoring and corrective actions will be applied to ensure compliance and mitigate risks.

Errors and Discrepancies

If discrepancies arise between your records and those provided by the Bank, you agree to promptly notify the Bank. If you fail to notify the Bank within 30 days after the information about an Entry becomes available, the Bank will not be liable for any resulting losses, and you waive any claims for discrepancies.

If the Bank receives a notice of error or unauthorized transaction as an ODFI regarding an Entry, you must provide the Bank with documentation supporting the authorization and any relevant notices, within two (2) Business Days. Failure to provide sufficient proof may result in you being charged for the error.

Information regarding Entries is made available to you through the Platform, Bank, or the Increase Dashboard, as the case may be. You agree to notify the Bank promptly of any discrepancy between your records and the information the Bank provides you regarding Entries. If you fail to notify the Bank of a discrepancy within 30 days after information concerning an Entry first became available to you, the Bank will not be liable for any losses or costs resulting from your failure to give notice and you will be precluded from asserting such discrepancy against the Bank. If the Bank receives a notice of error or unauthorized transaction as ODFI concerning an Entry processed or authorized to be processed to an account with the Bank, you will, within two (2) Business Days after written or oral notice, provide the Bank with a copy of the authorization to debit or credit the Receiver's account and, if applicable, proof of sending notice to the Receiver of the varying amount, or other proof satisfactory to the Bank that the error alleged did not occur or resolve the error, to enable the Bank to fulfill its obligation to provide such records to the RDFI within ten (10) Banking Days as required by NACHA Rules. If the referenced documents or proof are not delivered timely, or the documents or proof do not give the Bank a reasonable basis for determining that no error occurred, or if the alleged error did occur, the Bank may charge you for the alleged error and for any penalty imposed upon the Bank.

You acknowledge and agree that if an Entry describes the Receiver inconsistently by name and account number, payment of the Entry transmitted to the Receiving Depository Bank may be made by the Receiving Depository Bank on the basis of the account number supplied by you, even if it identifies a person different from the named Receiver, and that your obligation to pay the amount of the Entry to us is not excused in such circumstances.

Indemnities

In addition to your limitations of liability and indemnification obligations set forth elsewhere in this Bank Agreement, with respect to ACH Services, the Bank will be liable only for gross negligence or willful misconduct in performing the ACH Services. You will indemnify and hold the Bank harmless against any loss, liability, or expense (including attorneys’ fees and expenses) resulting from any breach of any warranties contained in the NACHA Rules. If any party becomes liable for damages suffered by another party or a third party in connection with the ACH Services in this Section, the parties will undertake reasonable efforts to cooperate with each other, as permitted by applicable law, in performing loss recovery efforts and in connection with any actions that the relevant party may be obligated to defend or elects to pursue against a third party.

Representations, Warranties, and Agreements

You warrant to the Bank all warranties that the Bank is deemed by the NACHA Rules to make with respect to Entries originated by you. Further, the Bank has the right to audit Entries at any time to ensure compliance with your representation and warranties.

You warrant that you will retain all Entries you transmit on file and in a format adequate to permit remaking of Entries for seven (7) Business Days following the date of their transmittal and shall provide such data to us upon request. You warrant that you retain all authorization records for a minimum of two (2) years from the date of termination or revocation of the authorization, or as otherwise required by applicable law.

You warrant that you are bound by and will comply with the NACHA Rules, including that each Entry you transmit to the Bank is authorized and that the payment of an Entry by the Receiving Depository Bank to the Receiver is provisional until receipt by the Receiving Depository Financial Institution of final settlement for such Entry; if such settlement is not received, the Receiving Depository Financial Institution shall be entitled to a refund from the Receiver of the amount credited and you shall not be deemed to have paid the Receiver.

When you originate an Entry, you make each of the representations, warranties, and covenants of an Originator for the applicable Entry class code as set forth in the NACHA Rules.

Third-Party Senders and Third-Party Service Providers:

You must notify the Bank if you are a Third-Party Sender or if you intend to utilize a Third-Party Service Provider or Third-Party Sender (as defined by the NACHA Rules) in connection with ACH entries. You must secure the Bank's approval before transmitting any entries through such party or acting in such capacity. Any approved Third-Party Service Provider or Third-Party Sender shall not be deemed the agent or service provider of the Bank but shall serve in such capacity solely for you. You authorize the Bank to follow instructions provided by any approved Third-Party Service Provider or Third-Party Sender to the same extent and pursuant to the same terms that would apply if the instructions were provided directly by you. You are solely liable and responsible for compliance by the Third-Party Service Provider or Third-Party Sender with this Bank Agreement and the NACHA Rules. The Bank has no responsibility or liability for the acts or omissions of the Third-Party Service Provider or Third-Party Sender, and you shall indemnify and hold the Bank harmless from any losses caused by their acts or omissions. You shall require your Third-Party Service Providers and Third-Party Senders to permit the Bank to perform, at its option, on-site inspections upon reasonable notice during normal business hours.

You acknowledge that the Bank reserves the right to refuse to permit the use of any Third-Party Service Provider or Third-Party Sender, or to revoke such approval at any time. You or any agent acting on your behalf is solely responsible for the content of any instructions received by the Bank from the Third-Party Service Provider or Third-Party Sender and any errors or omissions in the performance of their duties.

Additional Requirements for Third-Party Senders:

If you are a Third-Party Sender or utilize a Third-Party Sender, the following additional requirements apply:

  • Registration and Disclosure: The Bank will register each Third-Party Sender with NACHA within 30 days of transmitting the first entry. You and the Third-Party Sender must provide all required registration information, including name, location, Company Identification, and contact information. The Third-Party Sender must disclose any Nested Third-Party Senders prior to transmitting entries on their behalf and must provide Originator identification information within two Business Days of the Bank's request. You must notify the Bank within 10 days of any changes to registration information.
  • Agreements: The Third-Party Sender must enter into compliant origination agreements with each Originator and Nested Third-Party Sender containing at least the same provisions required between an Originator and the Bank.
  • Compliance and Risk Management: The Third-Party Sender must conduct annual ACH Rules compliance audits and provide evidence to the Bank upon request, maintain written procedures addressing all ACH activities conducted on behalf of Originators, conduct OFAC screening of Originators and their transactions, set and monitor exposure limits for each Originator, and implement adequate data security policies and procedures.
  • Monitoring: The Third-Party Sender must monitor returns and origination activity for all Originators and enforce restrictions on the types of entries initiated.
  • Fraud Monitoring (Effective 2026): Beginning March 20, 2026 (or June 19, 2026, depending on volume), the Third-Party Sender must establish and implement risk-based processes to identify entries suspected of being unauthorized or authorized under False Pretenses, and must review and update these processes at least annually.
  • Financial Responsibility: The Third-Party Sender must indemnify the Bank against losses resulting from Originator or Nested Third-Party Sender failures to perform obligations under the NACHA Rules.
  • Nested Third-Party Senders: If the Third-Party Sender utilizes Nested Third-Party Senders, the Third-Party Sender is responsible for ensuring each Nested Third-Party Sender complies with all requirements applicable to Third-Party Senders.
  • Supplemental Information: Upon the Bank's request due to a risk event, you and the Third-Party Sender must provide supplemental information within ten Business Days, including business names, taxpayer identification, addresses, contact information, and principal names.

The Bank may immediately terminate or suspend your use of any Third-Party Sender or require termination of any Originator or Nested Third-Party Sender relationship for breach of this Bank Agreement, the NACHA Rules, or for risk management reasons.