Nacha Rules Compliance
Risk management is every financial institution's responsibility. Three types of risk affect ACH payment processing, and each one has its own controls.
All ACH participating financial institutions and Third-Party Service Providers must conduct an audit of ACH Rules compliance annually, by December 31.
Risk management and assessment
Three types of risk affect ACH payment processing.
| Type of risk | What it is |
|---|---|
| Credit risk | The risk that a party to a transaction cannot provide funds for settlement |
| Operational risk | The risk of loss due to unintentional error |
| Fraud risk | The risk that a transaction may be initiated or altered in an intentional effort to misdirect or misappropriate funds |
The ACH Rules require all financial institutions to perform a risk assessment of their ACH activities and to implement risk management programs based on the assessment, in accordance with the requirements of their regulators.
ACH credit risk
Credit risk is generally associated with ACH origination activities, but Receiving Depository Financial Institutions (RDFIs) are also exposed to credit risk when they do either of the following:
- Post a credit entry before the Settlement Date.
- Fail to return a debit entry in a timely manner.
Controlling credit risk
To control credit risk, develop and implement processing procedures, understand compliance obligations, and ensure ACH operations staff are properly trained.
ACH operational risk
Operational risk represents the amount of loss related to unintentional errors, which may occur due to a hardware or software failure, or to clerical errors such as untimely returns or the incorrect use of return reason codes. Any disruption in ACH processing can jeopardize the accurate and timely processing of ACH entries.
Controlling operational risk
The evaluation of ACH operational risk and the determination of procedures to control those risks should include participation of auditors and outside professionals to ensure objectivity. Operational risk may be managed through automated security methods and through controlled operational procedures, which include cross-training of staff, dual controls, and a contingency plan.
ACH fraud risk
Fraud risk represents the risk that a transaction may be initiated or altered in an intentional effort to misdirect or misappropriate funds. Internal and external factors both affect risks related to fraud. Fraudulent activities may be the work of dishonest employees, third-party processing personnel, originating company personnel, or other outside parties.
Controlling fraud risk
Controls related to ACH operational and credit risk may also be effective in diverting fraud. Additional areas include personnel practices and security practices.
Personnel practices
The following practices and procedures contribute to fraud risk management:
- Limit use of temporary employees.
- Screen potential full-time employees.
- Segregate duties.
- Change or rotate work assignments.
- Mandate physical security, such as individual passwords and physical locks.
Security practices
The financial institution is responsible for the security of its ACH operations. Sensitive operation sites, such as the area that houses the computer and communications equipment, should be kept secure. All portable data, such as CDs, USBs, reports, and physical file folders, should be kept in secure areas and protected from hazards such as flood or fire. Computer terminals should automatically log off after a set period of time.
ACH processing software should be safeguarded with controls in place to ensure that only authorized changes can be undertaken. Communications software should provide security features, such as encryption or authentication, to secure data during transmission. In general, ACH processing security should conform to the organization's data processing security policy.
ACH audit
All ACH participating financial institutions and Third-Party Service Providers must conduct an audit of ACH Rules compliance annually, by December 31, in accordance with the ACH Rules. This includes both Originating Depository Financial Institutions (ODFIs) and RDFIs, and their Third-Party Service Providers (Third-Party Sender, Sending Point, Receiving Point).
The audit may be performed externally, or internally under the direction of an audit committee, audit manager, or senior level officer of the participating Depository Financial Institution or the Third-Party Service Provider.
For detailed information on the ACH Audit, see the Operating Guidelines of the ACH Rules.
Data security requirements
The ACH Rules establish data security requirements for all ACH transactions, regardless of Standard Entry Class (SEC) code, that are transmitted or exchanged through an Unsecured Electronic Network (UEN). The Internet is an example of a UEN.
Any banking information transmitted or exchanged through a UEN must be either encrypted or transmitted through a secure session. In either case, the security used must be commercially reasonable and must comply with applicable regulatory requirements. Banking information includes, but is not limited to, an entry, entry data, a routing number, an account number, a PIN, or another identification symbol.
Third-Party Senders must also have policies, procedures, and systems in place designed to protect banking information from being breached. These policies, procedures, and systems must ensure banking information is secured throughout the ACH payment cycle, including the initiation, processing, and storage of entries until destruction.