A business may expect ACH debits from selected tax authorities, lenders, utilities and trading partners while wanting other debit attempts stopped. An ACH debit block or filter gives the bank structured instructions for handling incoming debits, but the control works only when its rules, exceptions and decision timing remain accurate.

01

A block and a filter set different starting positions

A debit block generally tells the bank not to post ACH debits to a designated account under the agreed service. A filter allows debits that match approved criteria and blocks or routes other entries for a defined response, so the customer can support legitimate activity without accepting every debit presented.

Service designs vary by bank. Criteria can include an originator’s company identification, transaction type, amount or another supported field, and the account agreement determines whether a mismatch is returned automatically or shown to an authorized user for a decision.

02

The business defines what legitimate activity should look like

During setup, the business identifies accounts in scope, permitted originators, applicable limits, authorized administrators and the people who may approve an exception. The bank authenticates the instructions and records them in the service used to screen incoming ACH entries.

This allowlist should come from verified payment relationships rather than from an unexpected email or invoice. A company name familiar to an employee may not match the identifier carried in the ACH entry, and a legitimate originator can use different identifiers for separate processing arrangements.

03

Incoming debit data are compared with the standing rules

When an ACH debit reaches the receiving bank, the service compares supported fields in the entry with the customer’s block or filter instructions. A match can proceed through normal posting, subject to the account’s status and other controls; a nonmatch follows the agreed exception or return path.

The comparison is rule-based, not a legal determination that the underlying payment was authorized. An entry can match the technical filter even when a business later disputes the transaction, while an authorized payment can fail because the originator’s identifier or amount changed.

04

Exception decisions are time-sensitive and controlled

Some services use an ACH positive-pay workflow that displays unmatched entries for an authorized pay-or-return decision before a cutoff. The bank defines notification, authentication, dual approval where appropriate and the default outcome when the customer does not respond in time.

The business needs daily coverage, including absences and unusual operating days, because ACH return rights and service deadlines do not wait for an internal investigation to finish. Decisions and rule changes remain traceable for reconciliation, dispute handling and review.

05

Maintenance and layered controls determine reliability

The business updates its filter when it adds or ends a vendor relationship, changes an authorized amount or learns that an originator will use a new company identifier. Periodic review can remove stale permissions and identify repeated overrides that suggest the rule set no longer reflects normal activity.

A block or filter does not replace account reconciliation, vendor-change verification, secure administration, transaction alerts or response procedures, and it does not govern wires, cards or checks. Narrow rules can stop valid payments; broad rules can admit unwanted entries, so the control balances prevention with operational continuity.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.