ACH and Bank Payments: When Pulling From an Account Beats Taking a Card

ACH and Bank Payments: When Pulling From an Account Beats Taking a Card | HL Hunt
Payments & AI

ACH and Bank Payments: When Pulling From an Account Beats Taking a Card

Most merchants think about payment acceptance as a card question and treat bank payments as an afterthought — which leaves money on the table in one specific and predictable place. Card pricing is largely percentage-based; ACH pricing is largely flat per transaction. That single structural difference means the savings from moving a payment to bank rails scale with ticket size: negligible on a $30 sale, substantial on a $3,000 invoice, and transformative on recurring billing at volume. The trade-offs are real — slower settlement, a different failure profile, and a return category that behaves like a chargeback with a much longer window. This guide covers where ACH belongs, how to keep return rates low, and what the rules actually require.

By the HL Hunt Research Desk · 15 min read · Updated August 2026

The economics, honestly compared

The comparison that matters is structural rather than a rate table.

CardsACH
Pricing shapeLargely percentage of transactionTypically flat per transaction, sometimes a small percentage with a low cap
Cost on a small ticketModestComparable — no real advantage
Cost on a large ticketScales up linearlyRoughly unchanged — the advantage is here
SettlementFast, with the funding schedule in our funding guideSlower by default; same-day available at higher cost
Failure modeDecline at authorization, before you shipReturn after the fact, sometimes days later
Dispute windowChargeback rights measured in monthsAdministrative returns are quick; unauthorized consumer returns have a long window
Customer frictionLow — everyone has a cardHigher — requires account details or a bank connection

The row that determines strategy is the first one. Because ACH cost is roughly flat, its advantage is entirely a function of ticket size. A business invoicing in the thousands can save a meaningful percentage of revenue by moving customers to bank payments; a coffee shop cannot. That's not a matter of negotiation or provider selection — it's the pricing structure, and it's the honest answer to "should we accept ACH."

One frequently overlooked consideration: authorization is not verification of funds. A card decline tells you at the moment of sale that the payment won't work. An ACH debit that will fail for insufficient funds frequently doesn't tell you for days — which changes how you handle fulfillment on anything you'd ship before funds are certain.

Where ACH belongs

Strong fit:

  • B2B invoicing, where tickets are large, the customer relationship is established, and buyers frequently prefer bank payment anyway — the rail selection question in our B2B acceptance guide.
  • Recurring billing at meaningful amounts — rent, tuition, membership dues, service retainers — where the savings compound monthly and the customer relationship supports collecting bank details.
  • Payment plans, where the arrangement is already established and the customer has agreed to scheduled debits, per our plan design guide.
  • Large one-time payments — deposits, final invoices, professional fees.
  • Payouts to vendors and contractors, on the credit side.

Poor fit:

  • Small tickets, where the flat fee eliminates the advantage.
  • First-time customers you don't know, where the delayed failure signal is a real fraud and loss exposure.
  • Anything shipped immediately on a payment that hasn't settled.
  • Impulse and in-person retail, where the friction of collecting account details kills conversion.

The practical implementation for most businesses is both rails, with pricing that reflects the difference. Offering ACH alongside cards and giving customers a reason to choose it — a small discount on large invoices, or simply making it the default option on invoices above a threshold — moves the transactions where the savings actually are without forcing anything.

Flat fee, not a percentage
ACH's entire advantage is that its cost barely moves with ticket size. On a $3,000 invoice that's a large saving; on a $30 sale it's nothing. Route by amount, not by preference.

Authorization and retention

ACH debits require authorization in a form the network rules recognize for the transaction type, and the retention requirement matters as much as the collection.

What proper authorization generally establishes:

  • The customer's agreement to the debit, in a recognized form for the entry type.
  • The amount, or where variable, how it will be determined and how the customer will be notified of changes.
  • The timing — one-time or recurring, and on what schedule.
  • Revocation — how the customer can stop it, which must be a workable method.
  • Identification of you as the originator, in a name the customer will recognize on their statement.

Requirements are more specific for recurring consumer debits than for one-time payments, and a recording, a signed form, or a properly constructed online authorization can each satisfy them depending on the entry type. Retain it for the required period and be able to retrieve it quickly, because when a customer claims a debit was unauthorized, producing the authorization is what determines whether you keep the money.

The single most common operational failure here is the same one our subscription compliance guide identifies: authorization collected but never versioned or retrievable. Six months later, nobody can produce what the customer actually agreed to, and the return stands.

Returns and what they mean

An ACH return is the payment coming back, and the reason code tells you what to do about it.

CategoryWhat happenedResponse
Insufficient fundsThe account lacked the balanceThe classic retry case — see the retry section below
Account closedThe account no longer existsDo not retry; obtain new details
Invalid or no account foundThe details were wrongVerification failure — correct the data, don't retry blindly
Stop paymentThe customer instructed their bank to block itContact the customer; something is wrong with the relationship
UnauthorizedThe customer asserts they didn't authorize itThe serious one — see below
Corporate not authorizedA business customer disputes authorizationSimilar seriousness on the business side

The practical distinction: funding and administrative returns are operational problems; authorization returns are compliance problems. A high insufficient-funds rate suggests you're debiting customers who can't pay, which is a collections and timing issue. A high unauthorized rate suggests customers don't recognize or didn't agree to your debits, which attracts network attention far faster and can end your ability to originate.

Network rules set thresholds for return rates in defined categories, with the unauthorized threshold set far tighter than the administrative ones. Exceeding them triggers review through your originating institution, and the consequence — losing origination capability — is the same category of existential risk as the dispute-ratio problem our chargeback guide describes for cards.

The unauthorized return window

This deserves separate treatment because merchants coming from cards consistently underestimate it.

Administrative returns — insufficient funds, closed account, bad details — arrive quickly, typically within a couple of business days. Unauthorized consumer returns have a much longer window, extending well beyond the point where funds have settled and been spent.

Which produces the operating principle: settlement is not finality. Money that appeared in your account weeks ago can still come back. For a business with thin margins or one that treats settled funds as available immediately, that's a genuine working capital exposure worth planning around rather than discovering.

The defenses are all upstream:

  • Proper authorization, retained and retrievable. This is the whole game — an unauthorized return you can rebut with documentation is defensible; one you can't is a loss.
  • A recognizable descriptor on the customer's statement. A debit from an unfamiliar name generates unauthorized claims from customers who genuinely don't recognize it — the same self-inflicted problem our refund guide identifies for cards.
  • Advance notice before each debit on recurring arrangements, which prevents the surprise that produces the claim.
  • Easy cancellation, since a customer who can't stop a debit any other way will call their bank — the friction-becomes-dispute dynamic again.
  • Responsive support reachable before the customer reaches their bank.

Verification and return prevention

Most administrative returns are preventable, and the tooling has improved substantially.

  • Account validation before the first debit confirms the account exists and is open, eliminating the invalid-account and no-account categories almost entirely. Network rules require a reasonable validation method for certain internet-initiated consumer debits, so this is frequently an obligation rather than an option.
  • Bank account connection through a consented data connection is the strongest method — it verifies ownership and the account simultaneously, and it can surface balance information that helps with timing. It's the same connection layer our cash flow guide describes in an underwriting context.
  • Ownership verification, confirming the account belongs to your customer, which is a fraud control as much as a return control.
  • Debit timing aligned to when customers are paid, which measurably reduces insufficient-funds returns on recurring billing.
  • Pre-notification before debits, which reduces both funding failures and unauthorized claims.

Manual entry of routing and account numbers is the largest source of avoidable returns, which makes replacing it with a verified connection the single highest-return improvement available in an ACH program.

Settlement timing and finality

Standard ACH settles in a small number of business days depending on the window selected. Same-day options exist for eligible transactions within cutoff times at higher cost, and are worth using selectively rather than by default — the speed matters for payouts and time-sensitive collections and rarely for routine invoicing.

Three timing realities to build around:

  • Business days only. Weekends and holidays extend everything, which matters for payment plan due dates and payroll-adjacent timing.
  • Cutoff times are real, and a submission after cutoff moves to the next window.
  • Settlement precedes finality, per the return windows above.

For merchants considering faster rails, the instant payment systems in our real-time payments analysis offer settlement finality that ACH doesn't — with the corresponding consequence that irreversibility requires controls before the payment rather than recourse after it.

Retries and customer harm

Network rules limit how many times a returned entry may be re-presented, and there's a customer-outcome dimension that merchants should weigh independently of the rules.

Each failed debit attempt can trigger a fee at the customer's bank. A merchant re-presenting aggressively against an account with insufficient funds can generate multiple overdraft or returned-item charges — the fee cascade our overdraft analysis documents, imposed on precisely the customer least able to absorb it, by a merchant trying to collect a payment they will now be less likely to receive.

The practices that handle this well:

  • Respect the retry limits, and stay well within them.
  • Space retries to align with likely deposit timing rather than retrying immediately.
  • Stop retrying and contact the customer after a failure or two, offering a plan rather than another attempt.
  • Never retry a closed-account or invalid-account return — it cannot succeed and it counts against your return rate.
  • Fold ACH failures into your dunning sequence, per our failed payments guide, so a return becomes a conversation rather than a silent loop.

What to measure

  • Return rate by category, tracked separately — administrative, funding, and unauthorized. The blended number is not useful because the categories carry entirely different consequences.
  • Unauthorized return rate specifically, against the network threshold, since this is the one that ends programs.
  • Cost per transaction by rail, and total processing cost as a percentage of revenue — which is the number that shows whether the ACH program is delivering its purpose.
  • ACH share of volume by ticket band, to see whether large transactions are actually migrating.
  • Days to funds availability, and how that interacts with your working capital cycle.
  • Return rate before and after verification, which quantifies the value of the validation layer.

Both rails, priced properly

HL Hunt Pay handles cards and ACH in one integration — with account verification before the first debit, authorization capture and retention, recognizable descriptors, pre-debit notices, and return reporting split by category so the unauthorized rate never surprises you.

Get Started with HL Hunt Pay

Frequently asked questions

Is ACH cheaper than credit card processing?

On large tickets, substantially — because ACH is typically a flat fee while card pricing is percentage-based. On small tickets there's little advantage.

How long do ACH payments take to settle?

A small number of business days by default, with same-day options at higher cost. More importantly, settlement isn't finality — unauthorized consumer returns have a long window.

What are the most common ACH return codes?

Insufficient funds, account closed, and invalid account dominate by volume. Unauthorized returns matter disproportionately — longer window, chargeback-like economics, and tighter network thresholds.

Do I need written authorization to debit a customer's bank account?

You need authorization in a form the rules recognize for the entry type, stating amount, timing, and revocation — and you need to retain and be able to produce it.

Key takeaways

  • ACH's advantage is structural: flat pricing means the saving scales with ticket size and disappears on small transactions.
  • Route by amount — B2B invoicing, large recurring billing, and payment plans belong on bank rails; retail and impulse don't.
  • Authorization must match the entry type, state amount, timing, and revocation, and be retrievable when challenged.
  • Separate administrative returns from unauthorized ones: the first is operational, the second attracts network scrutiny fast.
  • Settlement is not finality — unauthorized consumer returns can arrive long after funds appear.
  • Verify accounts before the first debit, use recognizable descriptors and pre-debit notices, and space retries to avoid generating overdraft fees.

Move the big invoices off card rails

Sign up for HL Hunt Pay to accept cards, ACH, and wallets through one integration — with AI fraud screening, transparent reporting by rail, and cost analytics that show exactly where routing by ticket size pays for itself.

Sign Up for HL Hunt Pay


This guide is educational and does not constitute legal or compliance advice. ACH network rules, authorization requirements, return windows, and return rate thresholds are set by the governing operating rules and change periodically; confirm current requirements with your originating institution or processor.