An ACH debit is a payment a business pulls from a customer's bank account, with the customer's authorization. That authorization is called a mandate. For recurring debits from a consumer account, Regulation E requires it in writing, signed or similarly authenticated. The consumer can stop a debit by telling their bank at least three business days before it. A consumer can dispute a debit for up to 60 calendar days, and a business account for two business days. Disputes inside those windows are final.
What is an ACH debit?
An ACH debit moves money out of a bank account at the request of the business being paid. Nacha's example is a utility bill. The customer gives a standing authorization, or authorizes one payment on the utility's website. The utility then originates the payment through its bank. An ACH credit works the other way: the payer pushes the money. See ACH payment for how the network carries both.
What does the customer have to authorize?
Every ACH debit needs the account holder's authorization first. Stripe calls it a mandate. Stripe's mandate records:
- the business name
- whether the authorization is one-time or recurring
- the date and method of acceptance (IP address, user agent and timestamp for online flows)
Nacha's rules require you to give the customer a copy of the mandate, electronic or on paper. If a bank asks for proof of authorization, you must provide it.
What does Regulation E require for recurring debits?
Regulation E covers preauthorized transfers from a consumer's account at 12 CFR 1005.10:
- Written authorization. Recurring debits from a consumer account may be authorized only by a writing signed or similarly authenticated by the consumer.
- Right to stop payment. The consumer can stop a preauthorized debit by telling their bank, orally or in writing, at least three business days before the scheduled date.
- Notice when the amount changes. If a debit will differ from the previous one or from the authorized amount, the payee or the bank must send written notice of the amount and date at least 10 days before.
Stripe adds its own rule for recurring debits. You must tell the customer how amounts are calculated, or the range to expect. You must give at least seven calendar days' notice before you change the timing.
How long can a customer dispute an ACH debit?
Per Stripe's documentation:
| Account | Dispute window |
|---|---|
| Personal (consumer) account | Up to 60 calendar days after the debit |
| Business account | Up to two business days |
Disputes inside these windows are final. They can't be contested through the ACH network, so you settle them with the customer directly. In rare cases a bank accepts a dispute after these windows. Stripe calls this a late return.
What makes a mandate stop working?
On Stripe, a mandate becomes inactive when:
- the customer disputes a payment
- certain payment failures occur
- Stripe learns the payment method is no longer valid, such as a blocked bank account
Customers can also revoke a mandate at any time by contacting you. A debit after a canceled mandate fails. After a dispute, you need a new mandate before you debit that account again. If the same customer disputes a second payment, Stripe blocks the bank account.
- CFPB: Regulation E, 12 CFR 1005.10, preauthorized transfers
- Stripe: ACH Direct Debit
- Stripe: blocked bank accounts
- Nacha: How ACH payments work
Every figure on this page was checked against these sources on Oct 6, 2026. General information, not legal or tax advice.