ACH SEC Codes: Full List of PPD, CCD, WEB, TEL and the Rest
Jul 19, 2026
Convert your bank statement to Excel now
PDF, JPG, PNG, BMP, HEIC, TIFF, MT940
Upload your bank statement
Drop file here or click to upload
PDF, JPG, PNG, BMP, HEIC, TIFF, MT940
Uploading...
Last updated July 2026.
An ACH SEC code is a three-letter Standard Entry Class code that tells the banks in an ACH payment how that payment was authorized. PPD covers prearranged consumer payments like payroll and recurring bills. CCD covers business-to-business transfers. WEB covers payments a consumer authorized online, and TEL covers a consumer authorization taken over the phone. Every ACH entry, debit or credit, carries exactly one SEC code, and NACHA (the body that runs the ACH network) defines the full set so every bank reads them the same way.
If you originate ACH payments or reconcile them against a bank statement, the SEC code tells you what kind of transaction you are looking at, what authorization the originator had to keep, and which return rules apply. This guide lists the codes you actually run into, in one table, and shows how to read them off a statement once it is in a spreadsheet.
What is an ACH SEC code?
An ACH SEC (Standard Entry Class) code is a three-letter code carried in the batch header of an ACH file that describes how the receiver authorized the payment. NACHA requires one on every entry, so a bank always knows whether it is handling a payroll deposit, a business vendor payment, an online debit, or a converted paper check. The code is not the same thing as a return code (the R01 to R85 reason a payment failed); the SEC code describes the authorization method, while the return code describes a failure.
The code matters in practice because it drives the rules. Consumer codes (PPD, WEB, TEL, and the check-conversion codes) get the 60-calendar-day unauthorized dispute window; corporate codes (CCD, CTX) do not. Some codes are debit-only, some are credit-only, and some allow both. Getting the code right is part of staying compliant as an originator, and reading it correctly is part of reconciling cleanly as the receiver.
Full list of ACH SEC codes
The table below lists the Standard Entry Class codes you are most likely to see, what each one means, whether it is used for debits, credits, or both, and a typical example. The first four (PPD, CCD, WEB, TEL) account for the large majority of everyday ACH volume.
| Code | Name | What it authorizes | Debit / Credit | Typical example |
|---|---|---|---|---|
| PPD | Prearranged Payment and Deposit | A standing written authorization between a company and a consumer. | Both | Direct-deposit payroll, recurring utility or subscription debit. |
| CCD | Corporate Credit or Debit | A business-to-business payment between two company accounts. | Both | Paying a vendor, moving cash between company accounts. |
| CTX | Corporate Trade Exchange | A B2B payment like CCD but carrying structured remittance detail (up to 9,999 addenda records). | Both | Paying many invoices in one entry with EDI remittance data. |
| WEB | Internet-Initiated / Mobile Entry | A consumer authorization captured online or in an app. | Both | Paying a bill on a website, funding a wallet from a phone. |
| TEL | Telephone-Initiated Entry | A consumer oral authorization taken over the phone. | Debit | A one-time payment set up during a phone call. |
| ARC | Accounts Receivable Entry | A mailed or dropbox paper check converted to a single ACH debit. | Debit | A check mailed to a lockbox and processed electronically. |
| BOC | Back Office Conversion | An in-person check converted to ACH later, in the back office. | Debit | A check handed over at a register, converted after close. |
| POP | Point of Purchase | An in-person check converted at the counter, then handed back. | Debit | A check scanned and returned to you at checkout. |
| RCK | Re-presented Check Entry | Re-presenting a paper check that bounced for insufficient funds. | Debit | Collecting on a returned NSF check electronically. |
| CIE | Customer-Initiated Entry | A consumer pushing a payment to a company through bill-pay. | Credit | Online bill pay initiated from the customer's bank. |
| IAT | International ACH Transaction | Any ACH entry that touches a financial institution outside the U.S.; carries extra screening data. | Both | A cross-border payroll or vendor payment. |
| POS | Point of Sale Entry | A debit at a point-of-sale terminal using a card or code. | Debit | A POS debit at a merchant terminal. |
| MTE | Machine Transfer Entry | A transaction started at an ATM or similar machine. | Both | An ATM withdrawal cleared through ACH. |
| CTX/EDI | Corporate Trade Exchange with addenda | B2B payment with full ANSI X12 remittance in the addenda. | Both | Health-plan or supplier payments with invoice detail. |
PPD vs CCD: the two you will see most
PPD and CCD are the workhorses. PPD (Prearranged Payment and Deposit) is the consumer code: direct-deposit payroll lands as a PPD credit, and a recurring gym membership or utility bill leaves as a PPD debit. It relies on a standing written authorization, and because it hits a consumer account it carries the 60-day unauthorized dispute window.
CCD (Corporate Credit or Debit) is the business code. When you pay a vendor by ACH or sweep cash between two company accounts, that is almost always a CCD entry. CCD authorizations sit in an agreement between the two businesses rather than a signed consumer form, and corporate entries do not get the 60-day consumer window; a business that wants to dispute has two banking days and usually relies on ACH blocks and filters instead. If your books show a lot of CCD activity, that is a sign to automate how you pay and approve those bills so each entry ties back to an approved invoice.
WEB and TEL: how online and phone payments are coded
WEB is the Internet-initiated code. Any time a consumer authorizes a payment on a website or in a mobile app, the resulting ACH entry should be a WEB entry, and NACHA requires the originator to use commercially reasonable fraud detection (such as account validation) on WEB debits. TEL is the telephone code, used when a consumer gives an oral authorization over the phone, and it is limited to situations where there is an existing relationship or the consumer called the company. Both are consumer codes, so both fall under the 60-day dispute window.
The check-conversion codes: ARC, BOC, POP, RCK
Four codes exist because paper checks still move through the ACH network. ARC (Accounts Receivable Entry) converts a check you receive by mail or dropbox into a single ACH debit. BOC (Back Office Conversion) converts an in-person check to ACH after the fact, in the back office. POP (Point of Purchase) converts a check at the counter and hands it back to the customer. RCK (Re-presented Check Entry) lets you collect electronically on a check that already bounced for insufficient funds. All four are single-entry debits against consumer accounts, and all four require specific notice to the check writer.
How to read SEC codes on your bank statement
On a converted statement, the SEC code often appears inside the transaction description alongside the company name and a trace number, especially on business accounts. To work with it, get the statement into rows first. Convert the PDF or the raw ACH file to a spreadsheet so every entry sits in dated columns with the amount, description, trace number, and any SEC code preserved. From there you can filter by code (all the PPD payroll credits, all the CCD vendor debits) and tie each batch back to what you expected.
The mechanics are the same whether you start from a statement PDF or a NACHA file. Our guide to opening a NACHA ACH file in Excel or converting it to CSV walks through the record types and where the SEC code sits in the batch header, and the bank statement converter turns a statement PDF into the same structured rows. Once the entries are in a sheet, use transaction categorization to sort payroll, vendor payments, and fees so the ACH activity lines up with your ledger. And if an ACH entry comes back, our list of ACH return codes R01 to R85 explains why.
Why SEC codes matter for compliance and reconciliation
For originators, using the wrong SEC code is a rules violation. A consumer payment authorized online has to go out as WEB, not PPD; a check converted at the register has to go out as BOC or POP, not as a plain debit. Using the correct code keeps you inside NACHA rules and keeps the right dispute window attached to the entry. For receivers and bookkeepers, the SEC code is a fast filter: it separates payroll from vendor payments from card-style debits without reading every line, which is exactly what you want when you reconcile a month of activity at once.
Key points
- An ACH SEC code is a three-letter Standard Entry Class code that describes how an ACH payment was authorized; NACHA requires one on every entry.
- PPD (consumer, payroll and recurring bills) and CCD (business-to-business) are by far the most common.
- WEB and TEL cover online and phone consumer authorizations; ARC, BOC, POP, and RCK cover paper checks converted to ACH.
- Consumer codes carry the 60-day unauthorized dispute window; corporate codes (CCD, CTX) do not.
- Convert the statement or NACHA file to a spreadsheet to filter by SEC code and reconcile each batch against your ledger.
Ready to convert your bank statement?
Upload a PDF and get clean Excel or CSV in seconds. Works with statements from any bank.
Convert to Excel nowFree to try, no credit card required