Payment Screening for Incoming ACH Credits
Important
According to Nacha rules, all incoming ACH credit transactions must undergo screening for credit-push fraud. Financial institutions are required to establish procedures by March 2026 to identify and address credit entries suspected of being either unauthorized or authorized through false pretenses.
Payment screening is a fraud-detection service designed to help prevent fraudulent incoming ACH credits by flagging high-risk deposits for manual review. By combining manual reviews with automated processing for recurring deposits, the service helps provide efficient handling of direct deposits while minimizing risk. Whether reviewing first-time deposits, flagging irregular transactions, or creating custom rules to meet specific needs, this feature empowers you to maintain robust fraud-prevention measures. For advanced integrations or support, SoFi Tech Solutions provides dedicated tools and expert teams to assist your operations.
Additionally, SoFi Tech Solutions offers the flexibility to handle flagged transactions either internally or via SoFi Tech Solutions' dedicated Fraud Operations Team. For integration specifics, contact SoFi Tech Solutions.
Key capabilities
- Screen all incoming ACH credits for manual review, or send tax credits only.
- Following manual reviews, you can either post transactions on their scheduled settlement date or force-post them immediately, overriding load-limit checks when necessary.
- Ensure appropriate return codes are applied to transactions.
- Flag a transaction for a second review after an initial inspection.
- Produce reports detailing transactions sent to manual review, including the actions executed.
How it works
This feature is based on an ordered set of rules that you define to apply during incoming transaction processing. SoFi Tech Solutions applies the rules based on preset thresholds (standard and premium) and can include optional keyword searches within transaction details. You can use these thresholds and searches to approve or reject an incoming credit or send it to manual review. The goal of deposit reviews is to complete proactive examinations of pending deposit details and associated account holder information for evidence of fraud. While reviewing transactions under manual review, recurring deposits can be set to be automatically approved, rejected, or watched (not applicable to receiver-name mismatches).
Note
Recurring deposits must contain identical data strings. If any of the data changes on the next deposit, it will not be auto-approved and will go to manual review. This includes variations in the name, punctuation, capitalization, spacing, dollar amount, originator, receiver, category, and account number (PRN).
Standard rules
These standard rules are the most commonly used from program to program. SoFi Tech Solutions will work with you to establish custom rules suitable for your program.
- Unverified Direct Deposit — Applies to direct deposits that are from an unfamiliar originator for the receiving cardholder. Each new direct deposit will be manually reviewed the first time it is received. Once approved, repeats of the same direct deposit can be processed automatically.
- Use case — You want anything over $100 without a matching name (data stream) or prior approval to be held for manual review and approval. After a deposit is approved, you only want to see the payment hold again if it exceeds 5000.00. Anything 9500.00 or higher should be auto-rejected. Any payment below 100.00 can be auto-posted by the system (as long as it doesn’t trigger any of these other parameters).
- Large Amount — Maximum amount limits applied to all ACH direct deposit transactions. Once approved, future matching deposits will automatically post unless they exceed the premium threshold amount.
- Use case — You want any non-tax deposit 2000.00 or higher without prior approval to be held for manual review. After a deposit is approved, you don’t want to see it held again unless it exceeds 6000.00. Anything 9500.00 or higher should be auto-rejected. Any payment below 2000.00 can be auto-posted by the system (as long as it doesn't trigger any other parameters).
- Tax — Limits applied to all ACH tax return direct deposits. Once approved, future matching deposits will automatically post unless they exceed the premium threshold amount.
- Use case — You want any tax deposit 1.00 or higher without prior approval to be held for manual review. After a deposit is approved, you don’t want to see it held again unless it exceeds 1000.00. Anything 9500.00 or higher should be auto-rejected. Any payment below 1.00 can be auto-posted by the system (as long as it doesn’t trigger any of the other parameters).
- International – Applies to any direct deposit originating from a country listed on your auto-return or manual review lists.
- Use case — You want any direct deposit from Albania, Bosnia, or Iraq to be queued for manual review. Any direct deposits from Cuba, Burma, or Sudan are to be automatically returned.
- Payday Loans — Applies to any direct deposit from a payday company listed on your payday companies list.
- Use case — You want any payday deposit 1000.00 or higher without prior approval to be held for manual review. After a deposit is approved, you don’t want to see it be held again unless it exceeds 5000.00. Anything 9500.00 or higher should be auto-rejected. Any payment below 1000.00 can be auto-posted by the system (as long as it doesn’t trigger any of the other parameters).
Name matching
SoFi Tech Solutions offers two different methods for handling name verification on incoming ACH credits: a standard manual review process and an automated premium feature.
- Unverified Direct Deposit — This standard process flags certain incoming credits (based on originator, PRN, and amount) for manual agent review. It does not perform automatic name checking.
- Receiver Name Matching — This premium feature uses SoFi Tech Solutions' name matching service to automatically compare the name on incoming ACH credits against the name stored in the system and applies custom name matching thresholds. To set custom thresholds, configure the
NMSMTparameter.
Note: Refer to SoFi Tech Solutions setup for details on setting this parameter.
The following sections explain these methods in detail.
Unverified Direct Deposit
Use the Unverified Direct Deposit process to flag incoming ACH credit transactions that meet specific criteria (such as a new ACH originator and PRN combination above a set dollar amount) for manual review. By default, incoming ACH credits do not undergo automatic name checking. Instead, an agent manually reviews the deposit and the names on the transaction. The agent then decides whether to approve or reject the deposit and whether to add the originator to the allowlist for future automatic posting.
Receiver Name Matching
Use the Receiver Name Matching feature to automatically detect potential fraud by inspecting incoming ACH credit transactions for receiver name mismatches. This is a premium feature that must be enabled for your program.
When enabled, this feature uses the name matching service to compare the name in the incoming Nacha file with the name stored in SoFi Tech Solutions' database. It verifies whether the name associated with the transaction aligns with the name on the receiving account.
- If the names match (based on configured scoring thresholds), the transaction proceeds to regular processing and other validation checks.
- If the names mismatch, the transaction is flagged for manual review.
You can configure this feature to screen all incoming ACH credits or to focus only on tax-specific credits, where only federal tax and selected state tax credits are verified for name alignment. See the Questionable tax refunds example below for more details.
Note
Auto-posting future transactions based on past manual approvals cannot be configured when using Receiver Name Matching.
Name matching service
SoFi Tech Solutions' name matching service compares the name in the incoming NACHA file with the first name, the last name, and the full name stored in SoFi Tech Solutions' database, generating a similarity score for each. By default, your program applies the global thresholds for these scores.
The default global thresholds are:
- First name similarity threshold = 0.7 (70%)
- Last name similarity threshold = 0.75 (75%)
- Full name similarity threshold = 0.8 (80%)
A "match" occurs only when all three scores (first, last, and full name) exceed the defined threshold. Conversely, even a single score falling short yields a "mismatch."
Example
The following example compares the input name "MOSLEY, KIM" with the first and last name in SoFi Tech Solutions' database, which is "kimberly Mosley", with no middle name. The name matching service provides a score for the first name, last name, and full name and whether or not it's a match or mismatch overall. This first example shows results provided by comparing against the global thresholds (listed above) for each field:
- First name similarity score = 0.558134478735267
- Last name similarity score = 0.9058776113123939
- Full name similarity score = 0.6690445015976381
Match result = MISMATCH
This example compares the same name "MOSLEY, KIM" with the name in SoFi Tech Solutions' database, "kimberly Mosley", against custom thresholds (0.5, 0.5, 0.5):
- First name similarity score = 0.9818302547115786
- Last name similarity score = 0.965009127333520
- Full name similarity score = 0.9437461195000485
Match result = MATCH
Questionable tax refunds
Payment screening can be set up to help identify suspicious tax refunds when the standard rule for tax deposits is configured and Receiver Name Matching is enabled.
ACH transactions are automatically inspected to determine if they are a federal deposit or a tax return. The payment screening function proceeds to compare the name in the incoming ACH transaction to the name in SoFi Tech Solutions' system (Receiver Name Matching).
If name-matching is a success, the transaction is processed as normal and validated against any other rules configured for the program.
If name-matching fails, the transaction is sent to manual review, where it requires further action from the operations manager (either on your side or SoFi Tech Solutions'). The category of the transaction is flagged as RNM. See the Payment screening process section, below, for more details.
This scenario can be tested in a CV environment. Refer to the Payment screening for tax refunds simulation guide for step-by-step instructions.
Payment screening process
This process applies to deposits that have triggered a hold for manual processing based on various thresholds and dollar amounts. SoFi Tech Solutions offers two methods to perform manual review: the CST or with the Get Pending Deposits and Modify Pending Deposits endpoints.
Via CST
Access the queue in the Payment Posts & Returns page. Review the basic cardholder information and basic deposit sender information to determine if the deposit should be approved, watched, or rejected. This is where name matching can be performed, as the account holder information includes the name on the account and the recipient name for the deposit . Once actioned to be posted, deposits can be viewed on the Direct Deposit View page.
Reach out to SoFi Tech Solutions for access to the Payment Posts & Returns guide for more information.
Via Program API
When using the Program API, this workflow consists of three simple steps:
- Call Get Pending Deposits to retrieve a list of incoming ACH credits pending manual review.
- Look for transactions with
category_code: RNM(name mismatch). - Call Modify Pending Deposit Status with the decision to approve or reject each
RNMtransaction. You will modify the following fields:
| Field | Value | Description |
|---|---|---|
actionType | P (post) or R (return) | Action to take on the pending deposit. |
categoryCode | View list of deposit category codes | Category to assign to the deposit. |
categoryType | A (approve), D (decline), or W (watch) | Action to take on future deposits that match the program settings for the current deposit. |
retCode | View list of return codes | (Returns only.) Reason for returning the deposit. |
Note
If you reject the transaction, use the return code
R17to indicate that the entry was initiated under questionable circumstances. This return code is available only to programs with sponsor bank approval.
Events API
The receiver_name field can be added to the BPMT message by request. This adds the name field from the ACH record to ACH payments. This field will be blank or may contain other information on non-ACH payments.
SoFi Tech Solutions setup
Refer to the ACH table on the Parameters page for details on ACH-related settings.
| Parameter | Description |
|---|---|
| RNMCK | Controls when to perform name matching for incoming ACH credit transactions. A name mismatch queues up the transaction for manual review. Must be set to A to enable validation for all incoming ACH credits, or set to Y for tax credits only. |
| NMSMT | Contains the override thresholds for Receiver Name Matching on incoming ACH transactions as comma-separated values applied to the first, last, and full name. You assume full responsibility for determining the custom values and for the results those values provide. Each threshold has a maximum value of 99%. |
Updated 5 days ago

