Free AAP Exam Flashcards

Memorize 50 essential terms and definitions for the Nacha Accredited ACH Professional (AAP). See the term, recall the definition, then flip to check yourself.

50 Flashcards
5 Topics
100% Free
TermClick to flip

Originator

Tap to reveal definition
Card 1 of 50ACH Operations

Filter by Topic

Jump to Card

About These AAP Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the Nacha Accredited ACH Professional (AAP). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

ACH Operations18 cards
Rules & Regulations16 cards
Risk Management10 cards
ACH File Formatting4 cards
Other Payment Systems2 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

Originator

The party the Receiver has authorized to credit or debit the Receiver's account, which in turn authorizes an ODFI, directly or through a Third-Party Sender, to transmit the entry. It is bound to the Rules through its Origination Agreement with the ODFI or TPS, not through any agreement with an ACH Operator.

ODFI (Originating Depository Financial Institution)

The Originator's financial institution, which transmits entries into the ACH Network for its Originators and Third-Party Senders. It warrants that each entry is authorized and Rules-compliant and stays responsible for its customers' activity, including underwriting, exposure limits and return-rate monitoring, even when a Third-Party Sender sits in between.

RDFI (Receiving Depository Financial Institution)

The Receiver's financial institution. It posts incoming entries, sends Notifications of Change and returns, and must promptly recredit a consumer Receiver who reports an unauthorized or improper debit in time and signs a Written Statement of Unauthorized Debit, even though the RDFI played no part in creating the entry.

ACH Operator

The central clearing facility that switches entries between ODFIs and RDFIs — currently the Federal Reserve's FedACH and The Clearing House's EPN. An ACH Operator processes and forwards entries; it does not decide whether an entry is properly authorized.

Third-Party Sender vs. Third-Party Service Provider

A Third-Party Sender is the type of Third-Party Service Provider that holds the Origination Agreement with the ODFI and transmits entries for Originators that have no ODFI agreement of their own; it performs and warrants the ODFI's obligations. A processor that only builds or transmits files for an Originator that contracts directly with the ODFI is a Third-Party Service Provider, not a TPS.

PPD (Prearranged Payment and Deposit) SEC Code

Identifies a consumer entry, single or recurring, authorized in advance, such as payroll direct deposit or a monthly bill debit. A PPD debit authorization must be in writing and signed or similarly authenticated; a debit the consumer authorizes orally over the phone is a TEL entry instead.

CCD and CTX SEC Codes

Both identify entries to non-consumer (business) accounts. CCD can carry at most one addenda record for brief remittance data, while CTX can carry up to 9,999 addenda records for a full structured remittance message, such as an ANSI ASC X12 820 covering many invoices.

WEB SEC Code — what it covers

Identifies a consumer debit authorized via the Internet or a wireless network (an oral authorization over a wireless phone is TEL instead), and the debit authorization must be similarly authenticated. WEB is also the required code for every consumer-to-consumer (P2P) credit, however the consumer gave the payment instruction.

TEL SEC Code — authorization requirement

Identifies a consumer debit authorized orally by phone. For a single-entry TEL, the Originator must either audio-record the authorization or send written notice confirming it before the Settlement Date; for a recurring TEL it must do both: record it and give the consumer a copy as Regulation E requires.

IAT SEC Code

Identifies an entry that is part of a payment transaction involving a financial agency's office outside U.S. territorial jurisdiction, such as an office that holds the account, makes or receives the payment, or acts as a settlement intermediary. Every IAT carries seven mandatory addenda records, and IAT entries are not eligible for Same Day ACH.

ARC, BOC and POP SEC Codes

All three turn an eligible paper check into a one-time ACH debit using its MICR data, with notice to the check writer. POP converts the check at the point of purchase and voids and returns it on the spot; BOC accepts it at a point of purchase or manned bill-payment location and converts it later in the back office; ARC converts a bill-payment check received by mail, at a dropbox or at a manned location.

RCK (Re-presented Check Entry) SEC Code

Re-presents electronically a consumer check of less than $2,500 that was returned for insufficient or uncollected funds. The item can be presented no more than three times in total: one paper presentment plus up to two RCK entries, or two paper presentments plus one RCK entry. Checks returned for any other reason, such as a stop payment, are not eligible.

XCK (Destroyed Check Entry) SEC Code

Lets an ODFI collect a check through ACH when the original item was lost or destroyed during the check-collection process and can no longer be presented. It is not a way to re-present a check that was returned unpaid; that is RCK's role.

CIE and MTE SEC Codes

CIE is a credit pushed by a consumer, usually through an online bill-payment service, to a business Receiver's account. MTE is an entry created by a consumer's transaction at an electronic terminal such as an ATM, for example a cash withdrawal that debits, or a deposit that credits, the consumer's own account.

Same Day ACH — windows and dollar limit

Eligible entries submitted within the ACH Operators' same-day processing windows settle the same banking day. The per-entry limit is $1,000,000 through 2026; Nacha has approved a $10,000,000 limit effective September 17, 2027. An entry above the current limit, or any IAT entry, is not eligible for same-day settlement.

Notification of Change (NOC)

An RDFI sends an NOC (a COR entry) to report that information in an entry, such as the account number or account type, is wrong and should be corrected. For recurring entries, the Originator must make the change within six banking days of receiving the NOC or before its next entry to that Receiver, whichever is later. If the NOC itself is wrong or incomplete, the ODFI, not the RDFI, sends a refused NOC.

Reversing Entries

An Originator or ODFI may reverse an erroneous entry only for permitted reasons, such as a duplicate, the wrong Receiver, the wrong amount, or a debit dated earlier (or a credit dated later) than intended. The reversal must reach the RDFI within five banking days after the original Settlement Date and carry 'REVERSAL' in the Company Entry Description. An improper reversal can be returned with R11 on a consumer claim or with R17 otherwise.

Return time frames — 2-banking-day vs. 60-day extended returns

Most returns, including R01 (insufficient funds), R02 (account closed), R03 (no account), R04 (invalid account number), R08 (payment stopped) and R09 (uncollected funds), must reach the ODFI by the opening of business on the second banking day after Settlement. Consumer unauthorized-type returns R05, R07, R10 and R11 get the extended 60-calendar-day window, but only with the consumer's signed Written Statement of Unauthorized Debit (WSUD).

Nacha's role versus a government regulator

Nacha is the private rule-making body for the ACH Network — it writes and enforces the Nacha Operating Rules that participating depository financial institutions agree to follow by contract. It is not a federal regulator; the Federal Reserve, OCC, CFPB and other agencies keep their own independent authority over banks and consumer protection.

ODFI warranties under the Rules

By transmitting an entry, the ODFI warrants to each RDFI and ACH Operator that the entry was authorized by the Originator and the Receiver, is timely, and complies with the Rules, and it indemnifies them if a warranty is breached. Because the warranties travel with the entry by contract, an RDFI can recover through the Rules whether or not Regulation E applies.

General authorization standard

Every authorization must be readily identifiable as an authorization and have clear and readily understandable terms. A consumer debit authorization must also be in writing and signed or similarly authenticated, a copy must go to the consumer, and it must state that the Receiver can revoke it by notifying the Originator in the manner the authorization specifies.

Authorization retention period

An Originator must keep the original or a copy of each written or similarly authenticated authorization for two years after the authorization is terminated or revoked, not two years from signing. If an RDFI requests it, the ODFI must supply a copy within ten banking days, so the Originator must be able to produce it promptly.

Annual Rules compliance audit

Every Participating DFI, and every Third-Party Service Provider or Third-Party Sender that has agreed with a Participating DFI to process entries, must conduct (or have conducted) an audit of its Rules compliance by December 31 each year under Article One, Subsection 1.2.2, and keep proof that the audit was completed for six years.

ACH Rules Enforcement Panel

Nacha's ACH Rules Enforcement Panel decides whether a violation is an Egregious Violation, meaning willful or reckless conduct involving at least 500 entries or multiple entries totaling at least $500,000, and can classify it as a Class 2 or Class 3 Rules Violation. A Class 3 sanction can reach $500,000 per occurrence plus a directive for the ODFI to suspend the Originator or Third-Party Sender.

Regulation E error-resolution timeline

After a consumer reports an EFT error within 60 days of the statement on which it first appeared, the institution must determine whether an error occurred within 10 business days (20 if the transfer was within 30 days of the account's first deposit). It may take up to 45 days instead (90 in certain cases, such as new accounts) only if it provisionally credits the account within that 10- or 20-business-day period.

Regulation E unauthorized-transfer liability tiers

If a lost or stolen access device is reported within two business days of learning of the loss, the consumer's liability is capped at $50; reporting later raises the cap to $500. Separately, failing to report an unauthorized transfer within 60 days after the statement showing it is sent can leave the consumer liable for transfers that occur after that 60-day period.

Unauthorized debit to a business account

Regulation E covers only consumer accounts, so a business has no Reg E claim for an unauthorized CCD or CTX debit. Under the Rules, its RDFI returns the debit with R29 (Corporate Customer Advises Not Authorized), which must reach the ODFI within the standard two banking days; there is no 60-day window for non-consumer accounts.

UCC Article 4A and ACH credits

Under the Rules, ACH credit entries not subject to the Electronic Fund Transfer Act, such as CCD or CTX credits to business accounts, are treated as funds transfers governed by UCC Article 4A. Article 4A excludes any funds transfer any part of which is governed by the EFTA, so a consumer payroll credit is a Regulation E matter instead.

BSA/AML obligations for ACH participants

A DFI's Bank Secrecy Act program, including customer identification, due diligence and suspicious-activity monitoring and reporting, comes from federal law and its regulators, not from Nacha. The Rules reinforce it by requiring parties, including Originators through their Origination Agreements, to comply with U.S. law, but a suspicious ACH pattern is still reported to FinCEN through a SAR.

OFAC sanctions screening

No U.S. party may process an entry involving a sanctioned person. For domestic ACH, the ODFI is responsible for screening its Originator and the RDFI its Receiver, without having to unbatch files. For IAT entries, the mandatory addenda carry the names and addresses needed to screen every party to the cross-border payment.

31 CFR Part 210 and the Green Book

Part 210 governs federal government ACH entries: it adopts the Nacha Rules as the 'applicable ACH Rules' with listed exceptions and sets the reclamation process for benefit payments made after a recipient's death or legal incapacity. The Green Book is the Treasury Fiscal Service manual that gives financial institutions procedures for processing those government entries.

31 CFR Part 212 — garnishment of federal benefit payments

When served with a garnishment order, a financial institution must review the account within two business days for federal benefit payments, such as Social Security or VA benefits, directly deposited during a two-month lookback period, and protect that amount from the freeze. The protection does not apply when the order includes a Notice of Right to Garnish Federal Benefits from the U.S. or a state child-support agency.

How a Nacha Rules amendment is adopted

A rule change starts as an idea anyone can submit, goes to Nacha's Rules and Operations Committee, gets technical input and a public Request for Comment, and becomes a Rule only if a ballot of Nacha's voting members approves it. Nacha staff cannot impose a binding amendment alone.

Role of a Regional Payments Association

Regional Payments Associations, such as EPCOR, UMACHA or WesPay, provide ACH education, AAP/APRP/AFPP exam preparation, audit and advisory services, and advocacy for their member institutions. They do not enforce the Rules; violations go through Nacha's own enforcement process.

ODFI exposure limit requirement

An ODFI must assess the risk of each Originator's and Third-Party Sender's ACH activity, set a dollar exposure limit for it, and monitor and periodically review that limit, including activity across multiple settlement dates. A limit set once at onboarding and never revisited does not meet the requirement.

Third-Party Sender registration

Every ODFI must register each Third-Party Sender customer with Nacha, or state that it has none, within 30 days of the first entry. Registration gives the TPS's name and principal business location, the ODFI routing number used for its entries and its Company IDs; it must be updated within 45 days of any change, and there is no low-volume exemption.

Nested Third-Party Sender visibility

A Nested Third-Party Sender has an agreement with another TPS, not with the ODFI. The ODFI's Origination Agreement must say whether nesting is allowed and push the agreement requirement down the chain, the ODFI must flag TPSs with nested relationships in Nacha's Risk Management Portal, and each TPS must perform its own risk assessment and Rules compliance audit rather than rely on another TPS's.

2026 fraud-monitoring Rule — Phase 1

Effective March 20, 2026, all ODFIs, plus non-consumer Originators, Third-Party Service Providers and Third-Party Senders with 2023 ACH origination volume of 6 million or more, must have risk-based processes reasonably intended to identify entries suspected of being unauthorized or authorized under False Pretenses, reviewed at least annually. Monitoring need not occur before processing or screen every entry individually.

2026 fraud-monitoring Rule — Phase 2

Phase 2 removes the volume threshold: every remaining non-consumer Originator, Third-Party Service Provider and Third-Party Sender must meet the same fraud-monitoring requirement. The official effective date is June 19, 2026, but because that is a federal holiday, Nacha treats Monday, June 22, 2026 as the practical compliance date.

RDFI ACH credit monitoring Rule

RDFIs must have risk-based processes to identify incoming credits suspected of being unauthorized or sent under False Pretenses: Phase 1 (March 20, 2026) for RDFIs that received 10 million or more ACH entries in 2023, Phase 2 (June 19, 2026) for all other RDFIs. A flagged credit can be held under the funds-availability exemption, returned with R17 'QUESTIONABLE', or returned with R06 at the ODFI's request.

'False Pretenses' (Nacha Rules definition)

Added to the Rules on October 1, 2024: the inducement of a payment by someone misrepresenting their identity, their authority to act for another person, or the ownership of the account to be credited, as in business email compromise or vendor or payroll impersonation. The Originator did authorize the credit, so it is not 'unauthorized'; scams over fake or poor-quality goods are not False Pretenses.

PAYROLL and PURCHASE Company Entry Descriptions

Since March 20, 2026, Originators must use the Company Entry Description 'PAYROLL' on PPD credits paying wages, salaries and similar compensation, and 'PURCHASE' on consumer e-commerce debits for the online purchase of goods (normally WEB). Pensions, expense reimbursements and online payments for services do not take these labels.

Account Validation Rule (WEB debits)

Since March 19, 2021, the commercially reasonable fraudulent-transaction detection system required for WEB debits must include account validation: confirming the account is a legitimate open account that can accept ACH entries, for example by prenote, micro-entries or a validation service. It applies on the first use of an account number and whenever the number changes, not to every later recurring debit.

Data security Rule — Article One, Section 1.6

Requires non-FI Originators, Third-Party Service Providers and Third-Party Senders above a volume threshold to render DFI account numbers unreadable when stored electronically, by encryption, truncation, tokenization, destruction or having the FI store them. It phased in for volume above 6 million entries (2019) by June 30, 2021, and above 2 million (2020) by June 30, 2022.

ACH file record structure

Every ACH file is built from fixed 94-character records in a strict hierarchy: File Header (Record Type 1), Company/Batch Header (5), Entry Detail (6), Addenda (7, optional), Batch Control (8), and File Control (9). The numeric Record Type Code at the start of each line — not its position in the file — identifies its role.

Entry Detail Record (Record Type 6)

Carries the actual payment instruction: a transaction code for debit or credit to checking or savings, the RDFI routing number, the receiving DFI account number, the dollar amount, the individual name, and a trace number used to track that specific entry. A return or NOC ultimately points back to this record.

Addenda Record (Record Type 7)

Carries supplemental data tied to one Entry Detail Record: remittance detail for CTX, the extra cross-border fields IAT requires, or the specific reason code for a return or Notification of Change. A basic PPD or CCD entry can settle with zero addenda records; an IAT entry or a return/NOC cannot.

Entry hash field

A control total formed by adding the 8-digit RDFI routing numbers (without check digits) of every Entry Detail Record in a batch and keeping only the rightmost 10 digits if the sum overflows. It lets the receiving system detect a dropped or altered entry; it has no relationship to the batch's dollar totals.

Fedwire and CHIPS vs. ACH

Fedwire Funds settles each wire individually and immediately in central-bank money (real-time gross settlement); CHIPS also gives large-value payments real-time finality but uses a netting algorithm to save liquidity. Both are credit-only and governed by UCC Article 4A, whereas ACH batches debits and credits for net settlement and has Rules-based returns and reversals.

RTP and FedNow vs. ACH

RTP (The Clearing House) and FedNow (Federal Reserve) are credit-push-only instant payment systems: each payment clears and settles individually in seconds, 24/7/365, with immediate finality, and both now allow up to $10 million per payment. ACH settles in scheduled windows on banking days and supports debit pulls, which RTP and FedNow do not.

Frequently Asked Questions

What is the format of the Nacha AAP exam?

The AAP exam is 120 multiple-choice questions — 100 scored and 20 unscored pilot items — delivered as a computer-based test at Pearson VUE testing centers in 3 hours. The 2026 test window runs October 5 through October 31, 2026.

What is the passing score for the AAP exam?

Nacha does not publish a cut score or percentage. Results are reported only as pass or no pass, with the cut score set by Nacha together with the AAP Blue Ribbon Panel; candidates see their result immediately after the exam, and final letters and a diagnostic report follow about six to eight weeks after the testing window closes.

What are the AAP exam prerequisites?

Nacha requires at least 1 year of payments industry experience, with a waiver available from an employer or Payments Association for candidates with less. Nacha strongly encourages 2 years of ACH-specific experience, though this is not a strict eligibility rule.

How is the AAP credential renewed, and what happens if I don't pass?

AAP accreditation lasts 5 years and renews with 60 continuing education credits (no more than 20 earned in any one year) or by retaking the exam. Nacha offers the AAP exam only once a year, so a candidate who does not pass must register again for the next annual October testing window and pay a new fee.

What 2026 Nacha Operating Rules changes matter most for the AAP exam?

The 2026 Risk Management Rules phase in fraud monitoring and RDFI ACH credit monitoring (Phase 1: March 20, 2026; Phase 2: June 19, 2026, practically June 22) and add the required PAYROLL and PURCHASE Company Entry Descriptions (March 20, 2026). Separately, a funds-availability change effective September 18, 2026 requires non-Same Day ACH credits to be available by 9 a.m. RDFI local time on the Settlement Date. The Same Day ACH per-payment limit stays at $1,000,000 through 2026; the approved $10,000,000 limit takes effect September 17, 2027.