Guide · Collections
Collect customer payments by ACH debit instead of waiting on checks
Most small businesses get paid one of two ways: they wait on checks, or they take payment by card or through the pay-now button in their accounting system. Checks arrive on the customer’s timetable and take effort to chase and to deposit, even digitally. Card and pay-now payments arrive faster and cost a percentage of every invoice. One is slow, the other takes a slice, and neither puts the timing in your hands.
There is a third option that many small businesses have never considered. With the customer’s authorization on file, you pull the payment from their bank account on the due date instead of waiting for it to arrive, and your bank charges you per item rather than per percent. It is called ACH debit, it is the same mechanism a gym or an insurer uses to collect monthly, and it runs through the same bank portal you may already use to pay vendors or payroll.
This guide covers what has to be true before you can do it: the customer’s authorization, what your bank has to switch on, and what the paperwork protects you from. Generating the file is the last and shortest section.
Last updated
Two ways to get paid by ACH, and which one you need
Money moves over ACH in two directions, and the first decision is which one you are asking for.
Your customer pushes an ACH credit. You give them your routing and account number; they set up the payment at their own bank and send it when they choose. Nothing to sign, nothing to enable on your side. The timing stays theirs.
You pull an ACH debit. The customer signs an authorization once; from then on you originate the debit on the date the invoice is due, from your own bank portal, for the amount owed. The timing becomes yours.
If your customers already push payments reliably, you do not need anything on this page. Debit origination is for the business whose customers agree to be debited but cannot be relied on to initiate the payment themselves.
The customer has to sign, and the easiest time to ask is at the start: the authorization can sit inside an engagement letter or a supply agreement, and the amount can vary with each invoice. It does not fix the customer who pays late on purpose; they will not sign, and this is not a collections tool.
The same applies to customers who pay by card. Many prefer to, for the float or the rewards, and asking them to sign a debit authorization instead is a real ask. Some will decline.
The authorization is what makes this possible
Everything else on this page follows from one document: the customer’s authorization to debit their account. It is required, it gives you the right to originate the entry, and it is what your bank will ask to see if a customer ever says they did not agree.
The rules differ depending on who the customer is.
Consumers (PPD)
A debit to a consumer’s account must be authorized in writing, signed or similarly authenticated, with a copy given to the consumer. That requirement comes from two places at once: the Nacha Operating Rules, which govern the ACH network, and Regulation E, the federal consumer-protection rule for electronic transfers. Nacha adds that the authorization must be readily identifiable as one, have clear and readily understandable terms including when the debits will happen, and state how the consumer can revoke it.
A form the customer completes and e-signs counts as similarly authenticated. Authorizations taken over the phone or on a web checkout are separate entry types, TEL and WEB, with obligations of their own; the generator this guide points at does not produce them. PPD means a signed or e-signed form.
Businesses (CCD)
A debit to a business account needs an agreement between the two businesses. Nacha does not prescribe the form and does not say what the agreement must contain, beyond both parties being bound by the Nacha rules. In practice a short signed agreement is what your bank will expect to see, and it is what the business template below provides.
What to put in it
Whichever version you need, the document should settle, as fields or as language: which account may be debited, with the routing number and account type that go with it; the amount, or how each amount will be determined when it varies; whether this is a single debit or a recurring one and, if recurring, the schedule; how the customer revokes the authorization and with how much notice; that the customer will be told before a recurring amount or date changes; and that the customer keeps a copy.
Two templates you can send today
- Consumer (PPD) authorization — editable Word document
- Business (CCD) authorization agreement — editable Word document
Both are editable Word documents. Add your name, contact details and terms; the required elements above are already in them. No email address is needed to download them.
These are a starting point, not legal advice, and your own bank may require you to use its authorization form instead of, or alongside, your own.
What your bank has to switch on
Being able to send ACH payments from your account does not mean you can pull them. Debit origination is enabled separately, and you must confirm with your bank that it is enabled before you send an authorization form to a customer.
It is separate because the risk is different. A credit is settled once your account funds it. A debit can be returned by the receiving bank weeks later. Nacha therefore requires your bank to hold an origination agreement with you and to set an exposure limit for your account, and bank supervisors expect the bank to assess you much as it would an unsecured borrower.
Ask for:
- ACH debit origination on the originating account, and confirmation that your originator profile accepts Service Class Code 225.
- The upload channel for debit files, and whether it is the same one you use for payments.
- Your per-file and daily exposure limits.
- Whether the bank requires its own customer authorization form.
- The per-item price for originated debits and for returned items.
Any US bank that accepts NACHA files accepts a debit file once the account is enabled for that direction: 220 for payments and 225 for collections are both standard service class codes. The generator produces one or the other, never both in one file.
Why the cost works differently
A percentage fee scales with the invoice. A per-item fee does not. As your average invoice grows, a percentage takes more of each one and a per-item charge stays what it was.
PayFile Pro charges one credit per file, whatever the total. Your bank’s per-item charge is separate and theirs to quote. There is no percentage anywhere in the chain.
What the paperwork protects you from
Debits can come back, and how far back depends on who signed.
Ordinary returns. Insufficient funds and closed accounts are the everyday reasons a debit is returned. They are handled with the customer, not with paperwork.
Unauthorized returns. If a consumer tells their bank a debit was not authorized, or did not match the terms they agreed to, the bank can return it on the consumer’s written statement for 60 calendar days after the settlement date. Debit a consumer monthly on a deficient authorization and the last two months of collections can be unwound.
For a business customer the window is much shorter: the receiving bank has until the opening of business on the second banking day after settlement to return an entry as unauthorized. After that it is a claim, not a return.
That difference is why the consumer template is the longer of the two.
Keep the authorization. Retain the original or a copy for two years after it is revoked or ends, and be able to produce it when your bank asks.
Give notice before a change. Under the Nacha rules you give at least seven calendar days’ notice before a debit on a different date than authorized, for consumers and businesses, and at least ten calendar days’ notice before a consumer debit for a different amount. Regulation E separately requires ten days’ written notice of the amount and date whenever a consumer debit varies, unless the consumer has chosen to be told only when the amount falls outside an agreed range. Variable invoices are fine; silent changes are not. Both templates carry the notice language.
Watch what you originate. Since June 2026 the Nacha rules expect every business that originates ACH entries, at any volume, to have risk-based procedures for spotting entries that may not be authorized. For a small business that means checking that what goes in the file matches what was signed; the guide to the 2026 rule changes covers the rest.
Collecting in Canada: not yet
Canadian pre-authorized debit uses a different file format, and PayFile Pro does not yet generate it. If you are a Canadian business that wants to collect by PAD, email hello@payfilepro.com and say which bank you would use.
Recording the payment in your books
Your accounting system does not have to sit in the payment path. You originate the debit from your bank portal on the due date and record the payment against the invoice afterwards, as you would a check or a wire. Customer banking details can stay outside the accounting file, in a spreadsheet you keep alongside your books; the QuickBooks guide covers that shape for vendor payments and it applies here unchanged.
Generating the file
The US ACH debit generator takes the same spreadsheet shape as the payment generator: one row per customer with name, routing number, account number and amount, plus a batch type of PPD for consumers or CCD for businesses. Your rows are checked against the NACHA layout as soon as you enter or upload them, without creating an account, and you are told what is wrong before anything else happens.
Two things are specific to the debit side. Before the originator fields and the Generate button unlock, you affirm in the first person that you hold a signed or electronically authenticated authorization from each account holder you are debiting, and that your bank has enabled ACH debit origination on the originating account. Those are attestations, not verification. And the debit generator refuses a payment spreadsheet: the debit template carries a direction marker, and a payroll or vendor spreadsheet uploaded by mistake is stopped before a preview is built, so last week’s payroll is never pulled from every employee.
Use an effective date at least one business day ahead and upload the file through the channel your bank enabled for debits. Generating the file uses one credit.
Rule references on this page were checked against Nacha’s published rule summaries and Regulation E on 10 September 2026.
Frequently asked questions
Do I need my customer’s permission to debit their account?
Yes, in advance and in a form you can produce later. A consumer must sign, or electronically authenticate, a written authorization and receive a copy of it. A business customer must agree in writing that you may debit its account. Without that document the debit can be returned as unauthorized.
What is the difference between PPD and CCD?
PPD is the entry type for a debit to a consumer’s account; CCD is for a debit to a business account. The authorization rules differ, and so does how long the receiving bank has to return an entry as unauthorized: 60 calendar days after settlement for a consumer, the second banking day after settlement for a business. Choose by who owns the account, not by the size of the invoice.
How long can a customer dispute an ACH debit?
Through their bank, a consumer can have a debit returned as unauthorized for 60 calendar days after the settlement date, on a written statement. A business customer’s bank has until the opening of business on the second banking day after settlement.
How long do I have to keep the authorization?
Two years after it is revoked or otherwise ends, as the original or a copy, or as a reproducible record for an authorization that was not on paper. Your bank can ask you to produce it.
Do I have to warn the customer before the amount or the date changes?
Yes. Under the Nacha rules you give at least seven calendar days’ notice before a debit on a different date than authorized, for consumers and businesses, and at least ten calendar days’ notice before a consumer debit for a different amount. Regulation E separately requires ten days’ written notice whenever a consumer debit varies in amount, unless the consumer has chosen to be told only when it falls outside an agreed range. Both templates include that language.
Can I collect by ACH debit if my bank only lets me send payments?
Not until they enable it. Debit origination is approved separately from credit origination: your bank needs an origination agreement with you and an exposure limit for your account, arranged through the treasury or cash management team. Confirm it before you send authorization forms to customers.
Can I use this to collect from customers in Canada?
Not yet. Canadian pre-authorized debit uses a different file format, which PayFile Pro does not generate. If you want it, email hello@payfilepro.com and name the bank you would use.
What happens if I upload my payroll spreadsheet to the debit generator by mistake?
It is refused before any preview is built. The debit template carries a direction marker that the payment template does not, so a payroll or vendor spreadsheet uploaded to the debit generator is stopped with a message, and a debit spreadsheet uploaded to the payment generator is stopped the same way. A file never contains both credits and debits.
PayFile Pro is an independent software product. We are not affiliated with, endorsed by, or sponsored by any bank or financial institution named on this page. Nacha is a trademark of the National Automated Clearing House Association. All other names and trademarks are the property of their respective owners and are used here for identification and descriptive purposes only. The templates on this page are a starting point, not legal advice. PayFile Pro generates payment files; it does not transmit them, process payments, or hold funds.