ACH fraud in business lending hides inside routing numbers, deposit timing, and account velocity that a human reviewer skims past in under a minute. This guide walks through the exact detection workflow underwriters and MCA brokers use in 2026 to catch fraudulent ACH activity before funding, not after a default.
- Detect ACH fraud in business lending by checking routing numbers, deposit velocity, and 27+ automated signals — manual review misses most of it.
- ClearStaq flags fraudulent ACH activity in under 5 seconds per statement versus 20+ minutes of manual line review.
- Structuring, commingled funds, and duplicate deposits are the three ACH fraud patterns underwriters miss most often in 2026.
- Lenders running automated bank statement parsing catch synthetic revenue before funding, not after the first missed payment.
Why this matters
ACH fraud in business lending doesn't look like a bounced check. It looks like a legitimate deposit that arrived on the 1st and 15th of every month for six straight months, timed to smooth out a cash flow gap an underwriter would otherwise flag. By 2026, MCA brokers and non-bank lenders are underwriting off bank statement data faster than ever, and speed without signal detection is exactly what fraud rings exploit.
A single missed structuring pattern or a doctored ACH deposit can turn into a defaulted advance that never should have funded. ClearStaq parses statements and runs 27+ fraud signals in the same pass, which means the detection work happens before the funding decision instead of during a post-default forensic review.
What you'll need
- Full transaction-level ACH history for the applicant's business account, minimum 3 months, ideally 12
- Routing and account number verification against the issuing bank's published ranges
- A baseline of expected deposit frequency and amount for the stated industry
- Cross-reference data: merchant processing statements, invoices, or 1099s if self-employed
- Bank statement parsing software that flags velocity, structuring, and duplicate-deposit anomalies automatically
- 30-45 minutes if done manually, under 5 seconds per statement if automated
The steps
1. Pull the full ACH transaction history, not a summary
A PDF summary page hides the line-item detail where fraud lives. Request the full transaction export, every credit and debit, with dates, amounts, and counterparty descriptions intact.
Underwriters who work off summary pages miss same-day round-trip deposits almost every time, because those transactions never make it into the summary total. Pull raw statement data for at least 3 months, and pull 12 months whenever the applicant's revenue looks seasonal. Expected outcome: a transaction ledger with no gaps and no rounded totals. Common mistake: accepting a screenshot instead of the exportable statement, which strips metadata needed for routing verification.
2. Verify routing and account numbers against issuing bank records
This step catches the crudest form of ACH fraud: a routing number that doesn't match the stated bank, or an account number formatted incorrectly for that institution's system. Every US bank publishes ABA routing number ranges, and a mismatch here is disqualifying on its own.
Check the routing number's checksum digit — the ninth digit of every valid US routing number is a mathematical checksum of the first eight. A failed checksum means a fabricated or altered number, full stop. Expected outcome: confirmed match between routing number, account number format, and the bank name on the statement header. Common mistake: skipping this check on applicants who "look legitimate" based on revenue size alone.
3. Check deposit velocity and timing patterns
Velocity is how often money moves, and fraud rings use predictable velocity to fake a stable revenue base. Real businesses have irregular deposit timing tied to actual sales cycles; synthetic revenue has deposits that land suspiciously close to the same day each month.
Map every deposit over $1,000 against its exact date and look for clusters within 48 hours of each other, or deposits that repeat at 15-day intervals with near-identical amounts. Expected outcome: a velocity chart showing natural variance, or a red flag if variance is under 5%. Common mistake: treating consistent revenue as a positive signal without checking whether the consistency is too perfect to be organic.
4. Cross-reference deposit sources against reported revenue
An applicant claiming $50,000 in monthly revenue from a retail business should show deposits from payment processors like Square, Stripe, or Clover, not unexplained third-party transfers. When the deposit source doesn't match the stated business model, that's a structuring or commingled-funds signal.
Line up every deposit description against the applicant's stated industry and processing partners. Deposits labeled "Zelle transfer" or "P2P payment" replacing expected merchant processor deposits point toward funds run through a third party to obscure the real source. Read more on detecting commingled funds in business underwriting for the full pattern breakdown. Expected outcome: deposit sources match the applicant's business type. Common mistake: assuming any deposit is legitimate revenue just because it clears the account.
5. Run automated fraud signal detection across the full statement set
Manual review catches maybe 3-4 fraud patterns reliably. A 27+ signal automated pass catches structuring, duplicate deposits, altered PDFs, inconsistent metadata, and velocity anomalies in the same pass, in under 5 seconds per statement.
Run every statement through parsing software before a human underwriter touches the file, so the flagged items are the only ones that need manual eyes. Expected outcome: a scored fraud risk output per statement, with specific flagged transactions cited. Common mistake: running fraud detection after the credit decision instead of before, which defeats the point.
6. Flag structuring and commingled funds patterns specifically
Structuring is deposits deliberately broken into smaller amounts to stay under reporting thresholds or to fake steady revenue. It's one of the most common ACH fraud patterns in MCA underwriting in 2026, and it's also one of the easiest to automate detection for once you know the shape.
Look for multiple same-day deposits from the same or similar sources that sum to a round number. See the full method in how to spot structuring patterns in business bank statements. Expected outcome: structuring flags isolated from normal split-payment behavior (like a retailer with two processor accounts). Common mistake: flagging every multi-deposit day as fraud without checking whether the business genuinely runs multiple payment channels.
7. Document findings and route for manual review
Every flagged transaction needs a paper trail: what was flagged, why, and what the underwriter decided. This protects the lender in an audit and builds the fraud pattern library for future applicants.
Attach the fraud signal report to the credit memo before the final funding decision, not after. Expected outcome: a documented fraud review that took minutes instead of hours. Common mistake: verbally noting a concern without logging it, which leaves no record if the loan defaults later.
Run ACH fraud detection automatically
Parse statements and flag fraud signals in under 5 seconds per file.
Troubleshooting
- Deposits look consistent but the business claims seasonal revenue. Pull 12 months instead of 3. Seasonal businesses with perfectly flat deposits are a bigger red flag than businesses with visible peaks and troughs.
- Routing number passes checksum but the bank name doesn't match. Cross-check against the actual ABA directory, not just the checksum math — some fabricated statements use a real routing number from a different bank.
- Multiple small deposits sum to a suspiciously round number. This is a structuring pattern, not a coincidence. Isolate the transactions and request source documentation before funding.
- PDF metadata shows an edit date after the statement period. That's a doctored document. Reject or escalate to manual forensic review immediately.
- Applicant's stated industry doesn't match deposit source descriptions. Request merchant processor statements directly instead of relying on the bank statement alone.
- Automated fraud score flags a file but the underwriter can't see why. Use a tool that cites the specific flagged transaction and signal, not just a risk score, so the review isn't a black box.
Tools and resources
- Bank statement parsing software with automated fraud signal detection built into the same pass as income verification
- ABA routing number checksum validators, free and built into most banking APIs
- ACH fraud detection software built for community bank underwriting teams for a deeper look at signal categories
- A documented fraud review template attached to every credit memo
- Historical fraud pattern logs from prior declined or defaulted applicants, used to calibrate what "normal" looks like for your book of business
What to do next
Detection only matters if it plugs into the underwriting workflow before the funding decision, not after. For the full integration pattern, read how to integrate fraud detection into a loan origination workflow.
FAQ
What is ACH fraud in business lending?
ACH fraud in business lending is the manipulation of bank deposit data — structured deposits, altered statements, or third-party transfers — to fake stable revenue and qualify for a loan or cash advance. It shows up most in MCA and working capital underwriting where approval decisions rely heavily on bank statement data.
How do underwriters detect ACH fraud manually?
Underwriters manually detect ACH fraud by checking routing numbers, mapping deposit velocity, and cross-referencing deposit sources against the applicant's stated business type. Manual review typically takes 20-45 minutes per file and catches fewer patterns than automated signal detection.
What's the fastest way to detect ACH fraud in 2026?
The fastest method in 2026 is automated bank statement parsing that runs 27+ fraud signals in a single pass, completing in under 5 seconds per statement. This replaces manual line-by-line review with a scored, documented fraud output.
Is manual bank statement review enough to catch ACH fraud?
No, manual review reliably catches only a handful of fraud patterns, mainly obvious routing mismatches or missing documentation. Structuring, commingled funds, and duplicate deposits are far easier to miss without automated velocity and pattern detection.
What are the warning signs of structured ACH deposits?
Structured ACH deposits show up as multiple same-day transfers from similar sources that sum to a round number, timed to avoid reporting thresholds or fake consistent revenue. Look for deposit clusters within 48 hours that repeat monthly.
Can AI catch fraudulent bank statements before funding?
Yes, AI-based parsing tools flag altered PDFs, inconsistent metadata, and fabricated routing numbers before the credit decision is made. In 2026, this detection runs in the same pass as income verification, not as a separate post-funding audit step.
How long does automated ACH fraud detection take per applicant?
Automated ACH fraud detection takes under 5 seconds per statement when running through parsing software with built-in fraud signals. A 12-month statement history for one applicant typically processes in well under a minute total.
How many fraud signals should an underwriting tool check?
A strong underwriting tool checks 27 or more distinct fraud signals per statement, covering routing verification, velocity, structuring, and document metadata. Fewer than 10 signals leaves most structuring and commingled-funds patterns undetected.
One last thing
The routing number checksum check takes ten seconds and catches fabricated statements that pass every other visual inspection — most underwriters skip it because it feels too simple to matter, and that's exactly why fraud rings rely on it going unchecked.
Related guides
ClearStaq Team
Content Team
The ClearStaq team builds AI-powered tools for bank statement parsing, fraud detection, and income verification.



