When a payment fails: ACH returns, retries and stranded commission
A returned ACH debit is not a failed payment. It is a payment that succeeded, then reversed, with a two-character code attached that decides everything about what you are allowed to do next.
Most agencies find this out the way we did: by getting one and discovering that "try again" is sometimes correct, sometimes pointless, and sometimes the thing that ends your ability to debit anybody.
The codes that matter
| Code | What happened | Retry? |
|---|---|---|
| R01Insufficient funds | The account exists, the authorization was fine, the money was not there. | Yes |
| R09Uncollected funds | There is a balance, but part of it has not cleared yet. | Yes |
| R02 / R03 / R16Account closed, not found, frozen | There is nothing to debit. Retrying reaches the same wall. | No |
| R07 / R08Authorization revoked, stop payment | They told someone to stop it. That instruction stands. | No |
| R10 / R11Unauthorized, or not as authorized | They say they did not agree to this, or not to this amount. | Never |
Two of those five can be retried. The rest cannot, and the last one is in a category of its own.
Why R10 is different from every other failure
R01 costs you a few days. R10 costs you the business, eventually, if you collect enough of them.
Unauthorized returns are measured as a rate against a hard threshold — Nacha's limit is 0.5% — and crucially they are measured against the originator, not against you individually. If you move money through a shared originator, and most small operations do, then somebody else's bad month lands in the same number as yours.
What that means practically: R10 is not a collections problem to be worked. It is a signal that somebody was debited and did not recognize it, and the fix is always upstream of the debit.
The two things that actually cause R10
- They did not recognize the name on their statement. This is the most common cause of unauthorized returns anywhere in payments, and it has nothing to do with consent. Somebody signed an agreement with a company whose name they know, and a different string appeared on their bank statement. They called the bank. The bank asked "did you authorize this?" and the honest answer was "I don't know what this is."
- They were not told before it happened. If a varying amount arrives with no prior written notice, the first time they learn of it is on the statement, and a surprise debit is a disputed debit.
Both are preventable and neither is prevented by better collections. The descriptor and the notice are the whole defense.
How many times may you retry?
Fewer than you would like, and only for the retryable codes. The rule that matters more than the count: a re-presentment must be for the same amount as the original. You cannot return with a smaller figure because you think it has a better chance, and you cannot add a fee to it and send that.
Our own engine refuses to submit a retry whose amount differs from the first attempt, because that check is easier to enforce in code than to remember at 2am.
The failure mode nobody warns you about: stranded commission
This one is not in any rulebook. It is a bookkeeping trap, and it is the reason agencies quietly lose money they have already earned.
A commission is marked as invoiced or attempted. The debit fails with a non-retryable code. The system correctly marks it "not retryable" — and now the amount sits in a state that is neither collected nor collectable. It is not in your receivables, because it was attempted. It is not in your revenue, because it never arrived. Nothing lists it. Nobody looks for it, because there is nowhere for it to appear.
We have hit this three separate times in our own ledger. The fix is a rule rather than a feature: every commission must be in exactly one state, and "failed permanently" must be a state that appears on a screen somebody reads. The tie-out that enforces it is in the agency month-end close. If a failure can make an amount disappear from both the owed list and the collected list, it will.
What to do when one comes back
- R01 or R09: wait for the next payout rather than retrying immediately. Retrying into the same empty account produces a second return and doubles the cost of discovering the same fact.
- R02, R03, R16: stop. Contact them. The bank details are wrong or gone, and no number of attempts fixes a closed account.
- R07 or R08: stop, permanently, and treat the authorization as revoked from that moment. Continuing to debit after a revocation is the fastest route to an R10.
- R10: stop, and go and find out why. Look at what appeared on their statement and whether they were told. If the answer to either is uncomfortable, you have found a problem that affects every creator you have, not just this one.
Our engine will not fire a debit at all unless a written notice was confirmed delivered, and it quarantines a bank after a non-retryable return rather than letting a scheduler walk back into the same wall. Both rules exist because of returns we have already had.