Short of it is that, no, they do not need your specific authorization to initiate a withdrawal. Here's how ACH works:
1. One banking institution is the ODFI - originating depository financial institution, that makes the request. The other is the RDFI - receiving depository financial institution. In order to make a withdrawal, the ODFI sends the RDFI an ACH request that says "For this routing number (which determines the RDFI), for this account number and account holder name, debit $XXX amount and send it to me, the ODFI." No other authorization is necessary from the account holder.
2. The RDFI will send the ODFI (basically, the ACH process is more complicated) the money, BUT the RDFI has 90 days I believe (maybe longer) to pull the money back (search for "R10 ACH response code). If they do, the ODFI is left "holding the bag" and must return the funds. Thus, it's up to the ODFI to ensure that the user who initiated the withdrawal in the first place is authorized to do so.
Thus, a common ACH scam is:
1. Bad guy opens account at some financial institution with a stolen identity.
2. Many fintechs and online banks use Plaid to link to an account at an external institution to transfer funds. If the bad guy somehow has stolen credentials, then they link Plaid to that external account.
3. Bad guy initiates the ACH. Most ODFIs will then hold the funds for 2-5 days (depends on how long the account has been open, there are banking rules about how long they can hold it) specifically because of this return possibility.
4. Bad guy then tries to withdraw the money as soon as they can. If the original account holder doesn't notice the money missing from their account for, say, 2 weeks, the bad buy will have gotten the money and the ODFI is the one that has to make good on the stolen funds.
Google "ACH Fraud". It's a common problem with startups that don't realize all the intricacies and problems of the NACHA rules.
Thank you for taking the time to share this information about ACH scams.