Dear Controller Running Manual AP
Dear Controller friends still running manual AP,
I see you. I'm writing because there's something on the horizon I think you need to hear about from someone who gets it.
I know why you haven't moved off your current setup. The tools weren't good enough last time you looked. They couldn't handle the multi-entity complexity, the project codes, the approval routing you actually need. I held off for years for exactly that reason in past roles.
Here's why it's different, and rather urgent now.
Essentially there's just so much damn fraud happening now that the governing body over ACH's (Nacha) is imposing new rules from June 20, 2026. Every business sending ACH payments needs documented risk-based processes to identify potentially fraudulent transactions. No size exemption. No grace period. Put it simply, there are fines that apply now and losses you will incur if you don't.
Fraud is hiding in plain sight. Apparently ~50% of vendor records change in any 12-month period. Half your vendor list, every year, generating legitimate-looking change requests. New banks, new addresses, new contacts. Most are real. Some aren't. Sorting one from the other through email and a spreadsheet was always risky. Now it's a risk regulators are saying you have to actively manage.
One thing worth understanding about ACH credit fraud before we go further: there was never really good recourse for this.
When you pay a vendor by ACH and the money goes to a fraudster's account, the funds typically settle within a day or two. Once settled, getting them back requires the receiving bank to cooperate, and by then the fraudster has usually moved the money out. The fraudster's bank isn't obligated to return funds unless they can identify them and the recipient agrees, or unless legal action compels it.
This is different from ACH debit fraud (where someone pulls money out of your account), where you have real dispute rights through your bank. It's different from credit card fraud with its chargeback protections. Credit-push fraud is closer to wire fraud: once the money moves, it's gone.
The reason is technical but important. You authorized the payment. Your bank executed your instructions. The fraud happened upstream of the payment itself, in the email that convinced your AP person to update the vendor's banking details. From the network's perspective, the transaction worked exactly as instructed.
The new Nacha rules don't change this. They're about prevention and detection, not recourse. The point is to catch fraud before the money moves, because once it moves, recovery is hard regardless of the rules.
The biggest exposure inside all this is vendor bank detail changes. Someone emails your AP person posing as a known vendor, says they've changed banks, money goes out to the wrong account, gone. The old-world fix is your AP team calls the vendor on a known number and verify before processing (did they though?). The modern fix is structural: the vendor owns their own record in a verified portal, authenticates to update it, and the change is logged automatically. Your AP person can't update banking details from an email even if they wanted to, because the email isn't the source of truth anymore. The fraud vector closes because the architecture closes it.
And the other thing that's changed: the tools have actually caught up. Ramp, Bill, Brex, Tipalti, Airbase, they've all matured. They handle the multi-entity stuff now. The project specific stuff. The weird and unique approval process you have. The fraud monitoring is built in, which means compliance becomes a side effect of just running a modern AP process.
There are other benefits of upgrading your processes. Last month at a 200+ person client, I walked their AP clerk through setting up coding rules in Ramp that dynamically updated by department and spend type. Three days a week back, in a matter of minutes (3 days!!). And consistency at a moment when their CFO had just rolled out a new chart of accounts she was still learning. The hidden benefit: she's now got the time to learn new skills and is on her way to being promoted.
Honest read on timing: Q2/Q3 is the window. Audit's behind you. Year-end is far enough away. You've got runway to migrate without it blowing up your close. Wait until fall and it'll be a mess.
The time is now - and Nacha is pushing the envelope.
Elvina
PS. Ramp put together a genuinely useful article on the changes, check it out here