[Treasury Prime docs]: the receiving bank has 2 business days to return most ACH payments, but up to 60 calendar days for unauthorized consumer transactions. When a return arrives, Treasury Prime flips the ACH status to returned and populates the error field with the return code (R01 insufficient funds, R02 account closed, R10 unauthorized). The ach.update webhook fires: use it to notify the customer their payment failed and needs follow-up. In sandbox, drive this with simulation calls like achStatus settled.

Context: A settled ACH can still come back. Know the return windows.