August 14, 2026 · 7 min read
ACH and eCheck for High-Risk Merchants: A Real Hedge Against the Card Networks
How ACH debit works for high-risk ecommerce: Nacha return thresholds, what it really costs, where it beats cards, and the ratio trap most merchants walk into.
Every high-risk founder eventually has the same idea at the same moment. The card account is on a reserve, the chargeback ratio is creeping, and someone says the answer is bank debits. No interchange, no chargebacks, no Visa program to fall out of. It sounds like an exit from the whole problem. It is not an exit, but it is a useful second rail, and most merchants add it in the order that hurts them most. ACH has its own rulebook, its own return codes, its own shutoff thresholds, and its own sponsor bank that can dislike your product as much as any acquirer does. This post covers what ACH is, the returns and Nacha thresholds that decide whether you keep the rail, where bank debit genuinely beats cards, and the ratio trap that turns a sensible hedge into a worse card account.
What ACH actually is
ACH is the US domestic bank transfer network, governed by the Nacha Operating Rules and cleared through two operators, FedACH at the Federal Reserve and EPN at The Clearing House. When you take an eCheck, you are originating a debit against your customer's checking account through a sponsor bank called the ODFI. "eCheck" is marketing language for the same thing.
Every transaction carries a three-letter SEC code describing how the authorization was obtained. WEB is an internet-initiated consumer debit and is what almost all ecommerce runs on, while TEL covers telephone authorizations, PPD prearranged consumer debits, and CCD business-to-business. Return rights differ by code, and using the wrong one is a rules violation your provider eventually notices.
Standard ACH settles in one to two banking days, and Same Day ACH is available with a per-transaction limit currently set at 1 million dollars, though providers apply their own lower caps and cutoff times. When the money reaches you is a separate question, set by your provider's funding schedule and any reserve.
All of this is US only, and the equivalents elsewhere carry their own rules. SEPA Direct Debit in Europe, for one, gives consumers an unconditional refund right for eight weeks after the debit, which changes the economics substantially.
There are no chargebacks, but there are returns
This is the part that gets oversold. ACH has no card-network dispute process, no representment cycle, and no chargeback fee schedule. What it has instead is returns, and unauthorized returns behave a lot like disputes.
The ones that matter day to day:
- R01 insufficient funds. No money in the account, common on subscriptions and when a pay cycle shifts.
- R02 account closed and R03 no account. Stale account data, a typo, or a customer who changed banks.
- R07 authorization revoked and R08 stopped payment. The customer told their bank to stop it.
- R10 originator not known and R29 corporate customer not authorized. The unauthorized returns, and the expensive ones.
Administrative returns like R01 through R03 usually come back within two banking days, so you learn quickly. Unauthorized returns are different. A consumer can sign a written statement of unauthorized debit and have the entry returned within 60 calendar days of settlement, and their bank does not weigh your evidence the way a card issuer weighs a representment. There is no meaningful way to fight it after the fact. Your only defense is the authorization record you captured before the debit.
The thresholds that actually end the relationship
Cards have monitoring programs with published thresholds, and ACH has the Nacha equivalent. Three return rates are the ones your provider watches, measured against your debit volume over the prior 60 days:
| Return type | Codes it covers | Threshold |
|---|---|---|
| Unauthorized | R05, R07, R10, R29, R51 | 0.5 percent |
| Administrative | R02, R03, R04 | 3 percent |
| Overall | all debit returns | 15 percent |
The unauthorized rate is the one that gets accounts closed. Half a percent is tighter than it sounds, because a merchant with a recognition problem generates unauthorized returns for the same reason they generate card disputes, which is a customer who cannot connect the debit on their statement to the purchase they made. The fix is the same on both rails, a descriptor that names the brand the customer bought from.
Nacha also requires originators of WEB debits to run fraud detection that includes validating a receiving account the first time it is used. Account validation through a bank-linking provider is now standard, and skipping it is both a rules problem and a direct cause of R03 returns. Nacha has been phasing in broader fraud-monitoring obligations for originators through 2026, so confirm the current specifics with your provider rather than treating any list as settled.
ACH is not a way around underwriting
The most common misconception is that bank debits escape the risk appetite that got you terminated on cards. They do not. Behind every ACH provider is a sponsor bank taking real credit exposure, and it underwrites your product, your fulfillment timeline, and your history the way an acquirer does. Some are more conservative than card acquirers, because the exposure sits on a depository institution's balance sheet with a federal regulator attached.
That means the same document pack, the same disclosures, and the same reserve conversation. Products that are federally ambiguous or state-restricted stay hard, and anything with a long fulfillment window still gets priced for delivery risk. Hemp and CBD merchants find some ACH appetite but should expect the same THC threshold documentation and lab reporting described on the CBD industry page.
So ACH is a second processor relationship under the same scrutiny, and it belongs in the redundancy plan alongside a second card MID rather than in place of one.
Where bank debit genuinely wins
High ticket. At a 2,000 dollar coaching program or a 5,000 dollar wholesale order, card processing costs real money and card limits cause declines. ACH pricing is typically a flat per-transaction fee or a small percentage with a cap, so the economics improve as the ticket rises. Sellers there should still read the dispute-risk section of the coaching and info products page, because refund pressure does not disappear when the rail changes.
Recurring billing with an engaged customer. A member who consciously connected a bank account and understands the schedule returns less often than a card that expires or gets reissued. Involuntary card churn is a real cost, and the mechanics are in the subscription and continuity guide.
Payment plans. Splitting a purchase across months on a card exposes you to a dispute on every installment, while on ACH the authorization is one record for a defined schedule.
Volume that never needed the card networks. Wholesale, invoiced orders, and repeat B2B belong on ACH by default, and moving them off cards is pure margin.
The honest cons: no confirmation of good funds, R01 returns you learn about days later, a 60-day unauthorized window, US-only reach, and a conversion cost. Asking a first-time buyer to link a bank account converts worse than a card field nearly every time.
The ratio trap
Here is the mistake that turns a sensible hedge into a worse position.
A merchant with a chargeback problem moves their best customers to ACH first, because those are the people who agree to it. Repeat buyers, subscribers who never dispute, the loyal base. What is left on the card account is cold traffic and the refund-prone cohort.
Your chargeback count did not change. Your card transaction count fell. The ratio is a fraction, and you just shrank the denominator, which is how a merchant lands in a monitoring program the month after doing something they believed was risk reduction. The full arithmetic is in the chargeback ratio guide.
Do it the other way. Offer ACH where it wins on economics, meaning high ticket, payment plans, and B2B, and keep ordinary retail volume on cards so the denominator stays healthy. If the card account is genuinely unstable, the answer is another card MID and proper routing rather than evacuation to a different rail, which is the argument in the MID load balancing guide.
Rolling it out
Capture and store the authorization exactly. The debit terms, amount or amount range, frequency, start date, and cancellation method belong on screen, affirmatively agreed to, and retained with a timestamp and IP. Confirm every enrollment by email with the same terms, because a customer who reads that email does not file an unauthorized return in week six.
Validate the account on first use, then keep retry discipline on R01 returns instead of hammering the account. Nacha permits only a limited number of reinitiations, so space them out and stop when the code is not a funding code. An R02 or R03 needs new account data, and retrying it only accumulates administrative returns against your 3 percent line. Watch the unauthorized rate weekly, because 0.5 percent of a small volume is very few returns.
Practical takeaway
The path that fails is treating ACH as an escape hatch. It gets adopted in a panic, the best customers move first, the card ratio worsens, the authorization records are thin, unauthorized returns climb past half a percent, and six months later the merchant has lost both rails instead of one.
The path that lasts treats bank debit as what it is, a second rail with its own rulebook and sponsor bank, added deliberately while the card account is still healthy. Put it where the economics are better rather than where the fear is loudest, capture authorizations like you will have to prove them, and keep enough card volume flowing that the ratio math stays on your side. The broader version of that argument is in the high-risk merchant account guide. If you want a look at whether ACH belongs in your stack and where it should sit, apply for an architecture review.