
What an ACH Return Code Tells You
Every returned ACH debit comes back with a reason code: the letter R and two digits. That code, not the dollar amount, decides your next move. ACH return codes fall into three groups. R01 and R09 mean the money wasn't there, and you may try again. R02, R03, R04 and related codes mean the account details are wrong or the account is gone, so a retry will fail the same way. R05, R07, R10, R11 and R29 mean the customer told their bank the debit wasn't authorized, and that third group counts toward Nacha's strictest limit, the 0.5% unauthorized return threshold.
The code is one of the standardized Nacha return codes, attached by your customer's bank when it sends the debit back.
ACH Returns vs. Chargebacks
A return does the job a chargeback does for cards, but no card network sits in the middle. You are the Originator. The bank that sends your debits into the network is the ODFI (Originating Depository Financial Institution). Your customer's bank, the RDFI (Receiving Depository Financial Institution), sends the return.
A return isn't a way to dispute the product: Nacha states that the unauthorized codes R10 and R11 do not cover disputes about goods and services. And you have little to fight with. East West Bank's published guidance notes that once an R10 return is timely and follows Nacha's rules, there are no further actions under those rules to recover the funds. Any recovery happens between you and your customer.
Unlike a card decline code, which stops a sale before money moves, a return arrives after the debit looked settled. For how the rail works, see ACH payment processing, eCheck processing and our payments glossary.
The Two Return Clocks: 2 Banking Days vs. 60 Calendar Days
Most returns run on a two-banking-day clock. Insufficient funds, closed accounts, bad account numbers, stop payments, frozen accounts and most other account-level reasons have to be available to your bank by the opening of business on the second banking day after the original entry's settlement date. So these show up fast.
Unauthorized debits to consumer accounts (R05, R07, R10 and R11) get 60 calendar days, provided the customer's bank obtains a Written Statement of Unauthorized Debit from its customer. So a debit can look final for weeks and still come back.
For example, a consumer debit that settles Thursday, October 1, 2026 can come back as R01 only until opening of business Monday, October 5. As an R10, it can come back until about November 30, 60 calendar days later.
One detail catches B2B billers off guard. R29, a business customer's claim that a debit wasn't authorized, runs on the two-banking-day clock. If most of your debits go to other businesses, your unauthorized exposure is far shorter, which is part of why ACH suits B2B invoicing. If you need money that's final once processed, see our ACH vs wire transfer comparison.
ACH Return Reason Codes List: The Codes Merchants See
These are the codes merchants most often see. Names and return windows follow BMO's published ACH Return Reason Codes reference, except R10, which uses the definition Nacha adopted in its 2020โ2021 rule change. The "what to do" column draws on East West Bank's originator guidance and the Nacha reinitiation rules below.
| Code | Name | What it means | Return window | What to do |
| R01 | Insufficient Funds | Balance doesn't cover the debit | 2 banking days | May retry up to two times within 180 days of original settlement |
| R02 | Account Closed | A previously active account was closed by the customer or bank | 2 banking days | Stop; get authorization for a different account |
| R03 | No Account / Unable to Locate Account | Number is structurally valid but doesn't match the person named, or isn't open | 2 banking days | Stop; get the correct account information |
| R04 | Invalid Account Number | Account number structure isn't valid (wrong number of digits, etc.) | 2 banking days | Stop until corrected; usually a typo |
| R05 | Unauthorized Debit to Consumer Account Using Corporate SEC Code | A corporate-type debit (CCD, CTX or CBR) hit a consumer account without authorization | 60 calendar days | Stop; counts as unauthorized |
| R06 | Returned per ODFI's Request | The originating bank asked for the entry back | Not defined; set by the two banks | Accept it; ask your processor why |
| R07 | Authorization Revoked by Customer | Customer revoked the authorization they gave you | 60 calendar days | Stop until re-authorized; counts as unauthorized |
| R08 | Payment Stopped | Customer stopped payment on this specific debit | 2 banking days | Re-present only if the customer authorizes it after the return |
| R09 | Uncollected Funds | Ledger balance may be enough, but funds aren't collected | 2 banking days | Same retry rules as R01 |
| R10 | Customer Advises Originator is Not Known to Receiver and/or Originator is Not Authorized by Receiver to Debit Receiver's Account | Customer says they don't know you or never authorized the debit | 60 calendar days | Stop; pull your authorization; no retry; counts as unauthorized |
| R11 | Customer Advised Entry Not in Accordance with the Terms of the Authorization | Authorization exists, but the debit didn't match it (amount, date, etc.) | 60 calendar days | Fix the error; a corrected entry may go within 60 days without re-authorization |
| R12 | Account Sold to Another DFI | The account was sold to another bank | 2 banking days | Get the new routing and account details |
| R14 | Representative Payee Deceased or Unable to Continue in that Capacity | The person receiving payments for others can no longer act | 2 banking days | Stop; contact whoever now manages the account |
| R15 | Beneficiary or Account Holder Deceased | Account holder is deceased | 2 banking days | Stop all debits |
| R16 | Account Frozen | Funds unavailable due to bank or legal action | 2 banking days | Stop initiating entries |
| R17 | File Record Edit Criteria / Entry with Invalid Account Number Initiated Under Questionable Circumstances | Receiving bank couldn't post it due to a processing or format error | 2 banking days | Don't resend until your processor confirms the problem |
| R20 | Non-Transaction Account | Account where transactions are limited or prohibited under Regulation D | 2 banking days | Stop; ask for a checking account |
| R23 | Credit Entry Refused by Receiver | Recipient refused a credit you sent (refund or payout) | 2 banking days from receiver notice | Confirm details before resending |
| R24 | Duplicate Entry | Receiving bank spotted an apparent duplicate | 2 banking days | Accept it; check for a double submission |
| R29 | Corporate Customer Advised Not Authorized | A business customer says this entry wasn't authorized | 2 banking days | Stop until re-authorized; counts as unauthorized |
| R31 | Permissible Return Entry (CCD & CTX only) | Your bank agreed to accept a corporate return after the normal deadline | Not defined; set by the two banks | Reconcile; the late return was agreed on your side |
R13 (Invalid ACH Routing Number) and R28 (Routing Number Check Digit Error) mean the routing number itself is wrong, which almost always traces back to a typo at enrollment. Codes starting with C, such as C01 (Incorrect DFI Account Number) or C05 (Incorrect Transaction Code, meaning the wrong account type), are Notifications of Change, not returns. Treat one as an instruction to fix the customer's record before the next debit.
The Most Common ACH Return Codes
R01 Return Code: Insufficient Funds
The customer's balance didn't cover the debit, and their bank has two banking days to send it back. You may retry up to two times within 180 days of the original settlement date, for the same amount, with RETRY PYMT in the Company Entry Description. Time each retry for the customer's payday.
R02 Return Code: Account Closed
The account was open once and has since been closed by the customer or the bank. A retry will fail the same way, so stop the schedule and get a new authorization for a different account.
R03 Return Code: No Account or Unable to Locate Account
The account number is structurally valid, but it doesn't match the person named or isn't an open account. Pause debits, confirm the routing and account numbers with the customer, and validate the account before the next debit. R03 counts toward the 3% administrative return rate.
R10 Return Code: Customer Says the Debit Wasn't Authorized
The customer told their bank they don't know you or never authorized the debit. On a consumer account it can arrive up to 60 calendar days after settlement. Don't retry. Pull your signed authorization, contact the customer, and debit again only with a new authorization obtained after the return.
R29 Return Code: Business Says the Debit Wasn't Authorized
R29 is the business-account version of R10. It runs on the two-banking-day clock and counts toward the 0.5% unauthorized return rate. Stop debiting until the customer authorizes you again.
Which Nacha Return Codes Count as Unauthorized
Nacha treats R05, R07, R10, R11, R29 and R51 as unauthorized returns. R51 applies to re-presented check (RCK) entries that most merchants never originate. R11 has counted toward the unauthorized return rate since April 1, 2020.
Unauthorized returns carry three extra costs. First, these codes count against the tightest limit: the 0.5% unauthorized threshold is the only one of Nacha's three limits that's a hard threshold rather than a trigger for review. Second, they carry a fee. Under Nacha's Unauthorized Entry Fee rule, the ODFI pays the customer's bank a fee for every debit returned with these codes (R11 was added on April 1, 2021), and Nacha expects originators to bear at least some of that cost through their bank's transaction, return and service fees. Check your agreement. Third, they can't be retried: an unauthorized debit cannot be remedied by reinitiating it. The only path back is a new authorization obtained after the return.
R11 is the one unauthorized code you can fix without a new authorization. The customer did authorize you, but the debit was for a different amount, settled earlier than authorized, or was improperly reinitiated. You may correct the error and send a new entry without re-authorization, as long as it's transmitted within 60 days of the settlement date of the R11 return. It still counts toward your unauthorized rate, though.
Nacha Return-Rate Limits
| Return rate | Codes counted | Limit | What crossing it means |
| Unauthorized | R05, R07, R10, R11, R29, R51 | 0.5% | A threshold. The ODFI must present a plan to get below 0.5% within 30 days, and Nacha monitors for another 180 days |
| Administrative | R02, R03, R04 | 3.0% | A level. Opens a preliminary inquiry; not automatically a rules violation |
| Overall | All debit returns, excluding RCK entries | 15.0% | A level. Same inquiry process |
When Nacha lowered the unauthorized threshold from 1.0% to 0.5% (effective September 18, 2015), it noted that 0.5% was still more than 16 times the 2013 network average of 0.03%. Nacha notes that banks may require originators above these limits to bring them down, so your processor is watching.
Worked example 1: a gym's unauthorized return rate
A fictional gym drafts 400 memberships on the 1st of every month. Over two calendar months that's 800 debits, so each limit becomes a count:
- Unauthorized, 0.5% of 800: 4 returns
- Administrative, 3% of 800: 24 returns
- Overall, 15% of 800: 120 returns
Now say September and October bring these returns. Two members cancel at the front desk, the cancellation never reaches billing, and both revoke at their bank: two R07s. One member doesn't recognize the name on their bank statement: an R10. One draft goes out above the agreed rate: an R11. That's 4 of 800, exactly 0.5%. One more and the gym is over the threshold.
All four came from billing mistakes rather than fraud, and each has a fix, covered below. And the gym's R01s don't touch the 0.5% figure at all. They count only toward the 15% overall rate. If you run a gym, this is the calculation your bank runs on your account.
Debit prenotes count in the administrative and overall calculations, but Nacha's view is that a prenote returned as R02, R03 or R04 does its job by preventing the live debit from being returned.
When You Can Retry a Returned ACH Debit
Nacha calls resubmitting a returned debit a "reinitiation," and it's allowed only in these cases:
- R01 or R09: up to two more times after the return, no later than 180 days after the original entry's settlement date.
- R08: only if the customer separately authorizes it after the return.
- Other returns: only once corrective action has fixed the reason for the return.
- Unauthorized or revoked: never. A new authorization obtained after the return is a fresh start, and Nacha does not allow collecting that approval in advance.
A retry must carry RETRY PYMT in capital letters in the Company Entry Description field, and the Company Name, Company ID and Amount must match the original exactly.
Worked example 2: an R01 return code retried with real dates
A fictional member, Pat Example, owes $89 in monthly dues and tells you they're paid on the 15th and on the last business day of the month.
| Step | Date | What happens |
| Original debit settles | Thursday, October 1, 2026 | $89 draft |
| R01 comes back | By opening of business, Monday, October 5 | Second banking day after settlement |
| Retry 1 settles | Friday, October 16 | $89, marked RETRY PYMT, the day after a payday |
| Retry 1 returned R01 | By Tuesday, October 20 | Still short |
| Retry 2 settles | Friday, October 30 | $89, marked RETRY PYMT, on payday; the last retry allowed |
| 180-day limit | Tuesday, March 30, 2027 | Latest date a retry could settle |
The retries land on paydays, because a retry into an empty account wastes one of your two chances. Both are $89, not $89 plus a returned-payment fee: a different amount makes it an improper reinitiation, so handle any fee separately, and only as your authorization terms allow. If retry 2 bounces, you're done retrying, even though the 180-day window runs until March.
Two related traps. The regular November draft isn't a reinitiation, as long as it isn't contingent on whether the October one was returned. But don't fold October's missed $89 into November's draft. A $178 debit is not what Pat authorized, and that mismatch is exactly what R11 exists for.
How to Keep ACH Returns From Happening
Most returns trace back to a handful of habits, and each one below maps to specific codes:
- Validate before the first debit. It catches R03 and R04 problems before they count against you. For online (WEB) debits, the Nacha Rules already require a commercially reasonable fraudulent transaction detection system.
- Follow the authorization exactly. R11s come from debits that don't match what the customer agreed to, such as a different amount or an earlier date. Our ACH authorization form guide covers what the form should say.
- Honor cancellations the day you get them. Otherwise the customer revokes at their bank and you get an R07, which counts as unauthorized.
- Use a name customers recognize. R10 covers a customer who doesn't know who the originator is.
- Move repeat bouncers. Customers whose debits keep coming back R01 belong on a card or on prepayment, since NSF returns usually carry a return fee.
This matters most if you debit the same people every month: property managers, gyms, churches, nonprofits and anyone running recurring billing.
The 2026 fraud-monitoring rules
Watching returns is now a compliance matter too. Nacha's fraud-monitoring rules took effect in two phases: March 20, 2026 for all ODFIs plus non-consumer originators with 2023 origination volume of 6 million or more entries, then June 19, 2026 (effectively Monday, June 22, because June 19 was a federal holiday) for all other non-consumer originators, regardless of size. Each originator needs risk-based processes reasonably intended to identify entries suspected of being unauthorized or authorized under false pretenses, reviewed at least annually. For debits, Nacha says that solid monitoring of returns and return rates under the existing rules meets the minimum. For the card side, see our small business fraud prevention guide.
What to Do When You Get an ACH Return
- Read the code before the amount. It decides everything else.
- For R02, R03, R04, R12, R14, R15, R16 and R20, pause recurring debits until you have valid account details.
- For R05, R07, R10 and R29, don't retry. Pull the signed authorization, contact the customer, and debit again only with a new authorization obtained after the return.
- Fix and resend R11 errors within 60 days of the return's settlement date.
- Retry R01 and R09 on purpose: two retries at most, within 180 days, marked RETRY PYMT, for the same amount.
- Update the customer record for any C-code Notification of Change.
- Call your processor about repeat codes. Clustered R03s point to an enrollment problem. Clustered R10s point to an authorization or descriptor problem.
Some returns are a normal cost of taking bank payments. We provide ACH authorization forms and return management, and Payment USA quotes ACH pricing next to card pricing, with the fee structure in writing before you sign. To see what your payments cost to collect, card and ACH alike, send us a recent statement for a free statement review and we'll show you exactly what you're paying and where it can come down.
This guide is general information, not legal advice. The Nacha Operating Rules and your agreement with your processor and its bank govern the specifics of your program.
Sources
- BMO, "ACH Return Reason Codes" (May 2025), observed September 2026.
- East West Bank, "ACH Return Processing Guidelines" (August 2024), observed September 2026.
- Nacha, "ACH Network Risk and Enforcement Topics", observed September 2026.
- Nacha, "Improving ACH Network Quality" rules fact sheet, observed September 2026.
- Nacha, "Differentiating Unauthorized Return Reasons", observed September 2026.
- Nacha, "Improving ACH Network Quality - Unauthorized Entry Fee", observed September 2026.
- Nacha, "Risk Management Topics - Fraud Monitoring Phase 1", observed September 2026.
- Nacha, "Risk Management Topics - Fraud Monitoring Phase 2", observed September 2026.
- CRBT, "ACH Origination Rule Change", observed September 2026.
Frequently Asked Questions
What does the R01 return code mean?
R01 means Insufficient Funds: the customer's balance didn't cover the debit. The customer's bank has two banking days to send it back, and it's one of the few ACH return codes you're allowed to retry. Under the Nacha rules you can reinitiate an R01 up to two times after the return, within 180 days of the original settlement date, for the same amount and with RETRY PYMT in the Company Entry Description.
How long does a bank have to return an ACH debit?
It depends on the return reason. Most returns, including insufficient funds, closed accounts and invalid account numbers, must be sent within two banking days. Unauthorized debits to consumer accounts (R05, R07, R10 and R11) can be returned up to 60 calendar days after settlement, backed by the customer's Written Statement of Unauthorized Debit. A business customer's unauthorized claim (R29) runs on the two-banking-day clock.
Can I resubmit an ACH payment that was returned?
Only in limited cases. Debits returned for insufficient or uncollected funds (R01, R09) can be reinitiated up to two times within 180 days of the original settlement date, for the same amount. A stopped payment (R08) can be re-presented only if the customer authorizes it after the return, and other returns only once you've fixed the cause. Unauthorized returns can't be reinitiated, so you need a new authorization obtained after the return.
What is the difference between R10 and R11?
R10 means the customer says they don't know you or never authorized you to debit their account. R11 means an authorization exists but the debit didn't follow it, for example the wrong amount or an earlier date than agreed. Both have a 60-day return window and count as unauthorized, but after an R11 you may correct the error and send a new entry within 60 days without getting a new authorization.
What ACH return rate is too high?
Nacha sets three limits, measured over the preceding 60 days or two calendar months: 0.5% for unauthorized returns (R05, R07, R10, R11, R29, R51), 3.0% for administrative returns (R02, R03, R04), and 15.0% for all debit returns combined. Crossing the 0.5% unauthorized threshold requires your bank to present a plan to get back below it within 30 days. The 3% and 15% levels trigger a review rather than an automatic violation.
About Payment USAโs Founder
Published by Payment USA, a merchant services provider. Our guides and comparisons reflect that commercial perspective.

Chase James
CEO, Payment USA
Chase James is the founder and CEO of Payment USA, a merchant services company built on transparency and fair pricing. With over 15 years in the payments industry, Chase has helped thousands of businesses uncover hidden processing fees and switch to honest, interchange-plus pricing.
Contact Chase โ