Practical ACH setup guidance for businesses
What information is needed for an ACH payment?
An ACH payment commonly requires the receiving bank or credit union's routing number, the relevant bank-account number, and enough payment details to identify the transaction. Depending on the direction and purpose of the payment, a business may also need the account holder's name, the account type, the payment amount, the requested date, a customer or invoice reference, and an authorization completed through the provider's approved process. The exact fields are not universal, so the business should follow the secure workflow supplied by its bank or payment provider.
The core bank-account details
Nacha's consumer guidance says people often need their financial institution's routing number and their own account number to enroll for Direct Deposit or make another ACH payment. The Consumer Financial Protection Bureau likewise explains that businesses often allow bill payment by ACH using an account number and bank routing number. A routing number identifies the financial institution involved in routing the entry, while the account number identifies the account to be credited or debited.
Those numbers should come from the account holder's bank or credit union, its authenticated website or mobile app, or another source the financial institution recommends. A debit-card number is not a substitute for a bank-account number. Businesses seeking a broader explanation of this payment channel can start with the ACH, eCheck and bank payments FAQ hub.
Payment details that give the transaction context
Who and which account
A provider may ask for the account holder's name, the financial institution's name, and whether the account is checking or savings. Business-account workflows may request additional identifying information. Use only the fields shown by the approved payment system.
Amount and direction
The workflow should make clear how much is moving and whether the entry sends money to the account or collects money from it. Staff should not infer the direction from an informal email or a customer note.
Date and frequency
A one-time payment needs a requested date or processing instruction. A scheduled or recurring arrangement needs a clearly presented frequency and duration through a provider-supported flow. Do not assume one authorization covers a different payment pattern.
Business reference
An invoice number, customer ID, order number, or internal memo can help the business match the payment to its records. Keep references descriptive without putting complete bank credentials into accounting notes or shared messages.
Information varies by ACH workflow
A customer paying an invoice, an employer setting up Direct Deposit, and a business paying a supplier do not necessarily use the same screen or provide the same supporting details. The payment provider may collect bank information directly, let the account holder connect through an authenticated bank experience, or use information already stored under an approved customer profile.
Payment direction matters too. A credit sends funds to an account, while a debit draws funds from an account under the applicable authorization. The business should identify the intended use case before asking for data and should have its provider demonstrate the exact customer-facing steps. For related channel planning, review virtual terminals, invoicing and payment links and ecommerce and online payments.
Authorization is separate from account information
Possessing a routing number and account number does not by itself show that a person authorized an ACH payment. Nacha has specifically noted that permission to access account data is distinct from permission to initiate a payment. The business should use the authorization language, confirmation method, and recordkeeping process supplied or approved for the chosen ACH workflow rather than improvising its own form.
A clear experience should identify the business, payment amount, intended date, and whether the instruction is one-time or recurring. It should also give the payer a confirmation or other record through the approved channel. Requirements can vary with the entry type, payer, payment direction, and provider, so this page is operational guidance rather than legal or compliance advice.
Collect bank details through a secure path
- Use a purpose-built payment experience. Direct customers to the provider's secure checkout, invoice page, portal, or account-connection flow.
- Request only what the workflow needs. Avoid collecting extra identity or bank information simply because a general form has space for it.
- Limit employee access. Give team members only the permissions needed for their roles and remove access promptly when responsibilities change.
- Keep credentials out of messages. Never ask for online-banking passwords, one-time passcodes, complete account numbers, or secret API keys through ordinary email, chat, or a general inquiry form.
- Verify unexpected changes. Use a trusted contact method before acting on new bank instructions received through an unusual channel.
The fraud prevention and security FAQ hub provides additional national guidance for evaluating payment controls.
A simple readiness checklist
Before enabling ACH, document who will pay, whether the business will send or collect funds, whether payments are one-time or recurring, where bank details will be entered, and how the team will reconcile each transaction. Then ask the bank or payment provider to show which fields are required, how routing information is validated, how authorization is captured, what confirmation the payer receives, and where payment status or exceptions appear.
This review helps prevent a common mistake: treating a list of bank details as a complete payment process. The details matter, but the secure collection method, customer instructions, staff access, and reconciliation path are equally important. Businesses still choosing a collection channel can also review how businesses can accept ACH online.
Choose the next step
Prepare a short description of the payer type, payment direction, frequency, customer experience, and accounting references your business needs. Ask your bank or payment provider to map that use case to its current ACH workflow and demonstrate the required fields before requesting bank information from customers or vendors.
If you contact Payments Max to discuss payment options, share only general business and workflow information. Do not send bank credentials, complete account numbers, cardholder data, passwords, one-time passcodes, or secret API keys through a general contact form.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US