1.3 Third-Party Senders (TPS) and Third-Party Service Providers (TPSP)

Key Takeaways

  • A Third-Party Service Provider (TPSP) provides processing, data transmission, or hosting services without standing between the ODFI and Originator contractually.
  • A Third-Party Sender (TPS) is an intermediary where no direct contractual relationship exists between the ODFI and the Originator.
  • Nested Third-Party Senders introduce multi-tiered intermediary risk, originating transactions through an upstream intermediary TPS.
  • ODFIs are legally obligated under Nacha Rules to register all Third-Party Senders and Nested TPS in Nacha's Risk Management Portal within 30 days of the first Entry.
  • The ODFI remains fully liable for all Nacha participant warranties and cannot delegate away its network responsibilities to any third-party intermediary.
Last updated: August 2026

1.3 Third-Party Senders (TPS) and Third-Party Service Providers (TPSP)

Core Principle: In modern payment ecosystems, financial institutions frequently partner with specialized fintechs, software platforms, and payroll processors. Nacha Operating Rules establish a strict legal taxonomy in Article One distinguishing entities that merely provide technological services from entities that act as contractual intermediaries.


1. Intermediaries Under Nacha Rules: Article One Definitions

As payment technology evolved, entities emerged that sat between Originators and ODFIs to aggregate files, format transactions, or provide software interfaces. Nacha categorizes these entities into two fundamental classes:

  1. Third-Party Service Provider (TPSP)
  2. Third-Party Sender (TPS)

Understanding the exact boundary between these two classifications is a critical competency for payments professionals and a cornerstone of the AAP curriculum.

+---------------------------------------------------------------------------------------------------------+
|                                 TPSP vs. TPS STRUCTURAL COMPARISON                                      |
+---------------------------------------------------------------------------------------------------------+
|  TPSP Model: Direct Contract between Bank and Merchant; Vendor is an Outsourced Processor:             |
|  [ ODFI ] <================ (Direct Origination Agreement) ===============> [ Originator ]             |
|      ^                                                                             ^                    |
|      |---- [ TPSP / Software Vendor ] (Provides Technical / Transmission Services)-|                    |
|                                                                                                         |
|  TPS Model: Intermediated Chain; No Direct Contract between Bank and Merchant:                          |
|  [ ODFI ] <==== (Origination Agmt) ====> [ Third-Party Sender (TPS) ] <==== (Agmt) ====> [ Originator ] |
|    (No direct contractual relationship exists between ODFI and the Underlying Originator)               |
+---------------------------------------------------------------------------------------------------------+

2. Detailed Distinction: TPSP vs. TPS

Third-Party Service Provider (TPSP)

A Third-Party Service Provider is an entity that performs any function of ACH processing on behalf of an Originator, an ODFI, or an RDFI, pursuant to a direct contract with that participant.

  • Functions: Software hosting, data encryption, 94-character record formatting, file transmission, secure portal access, core banking platform processing (e.g., FIS, Fiserv, Jack Henry).
  • Key Legal Characteristic: The TPSP acts purely as an agent or technical vendor. A direct contractual origination agreement remains in place between the ODFI and the Originator.
  • Liability: The hiring participant (ODFI or Originator) is directly responsible for the actions, errors, or omissions of its TPSP.

Third-Party Sender (TPS)

A Third-Party Sender is a specific type of Third-Party Service Provider that acts as an intermediary in transmitting ACH entries between an Originator and an ODFI, where no direct contractual relationship exists between the ODFI and the Originator.

  • The Intermediary Triangle:
    1. The ODFI executes an origination agreement with the TPS.
    2. The TPS executes individual agreements with multiple underlying Originators.
    3. There is no contractual privity between the ODFI and the underlying Originators.
  • Common Real-World Examples:
    • Payroll Processors: A payroll company collects gross payroll from hundreds of employer clients into its own settlement account and originates Direct Deposit files to employee bank accounts through a single ODFI relationship.
    • Payment Facilitators (PayFacs): A SaaS platform aggregates payments for thousands of small e-commerce merchants, boarding them directly without individual bank underwriting.
    • Bill Payment Aggregators: A utility billing platform that originates consumer debits on behalf of multiple municipal water and electric districts.

3. Structural Comparison: TPSP vs. TPS

AttributeThird-Party Service Provider (TPSP)Third-Party Sender (TPS)
Contract with ODFIVendor/service agreement (or contracted by Originator)Direct ACH Origination Agreement
Contract with OriginatorService/software agreementDirect Origination / Client Agreement
Contract Between ODFI & Originator?YES (Direct contractual privity exists)NO (No direct relationship exists)
Flow of Settlement FundsFunds flow directly between ODFI and OriginatorOften pooled/cleared through TPS settlement accounts
Nacha Registration MandateNot subject to standalone registry (unless acting as TPS)Mandatory registration in Nacha TPS Portal
Annual Compliance AuditMust comply with Article One, Subsection 1.2.2 if performing DFI functionsMandatory annual compliance audit under Article One, Subsection 1.2.2
Primary Risk VectorOperational/technology downtime and data securityCredit risk, money laundering, fraud, unmonitored nesting

4. Nested Third-Party Senders (Nested TPS)

As the fintech sector expanded, multi-tiered intermediary relationships developed, introducing what Nacha explicitly defines as a Nested Third-Party Sender.

Definition of Nested TPS

A Nested Third-Party Sender is a Third-Party Sender that has entered into an agreement with another Third-Party Sender (often called the "Lead TPS" or "Intermediary TPS") to originate ACH entries through an ODFI, rather than maintaining a direct relationship with the ODFI itself.

+---------------------------------------------------------------------------------------------------------+
|                                 NESTED THIRD-PARTY SENDER TOPOLOGY                                      |
+---------------------------------------------------------------------------------------------------------+
|  [ ODFI ]                                                                                               |
|     | (Direct ACH Agreement)                                                                            |
|     v                                                                                                   |
|  [ Lead Third-Party Sender / Intermediary TPS ]                                                         |
|     | (Intermediary Agreement)                                                                          |
|     v                                                                                                   |
|  [ Nested Third-Party Sender ]                                                                          |
|     | (Originator Agreements)                                                                           |
|     +---> [ Underlying Originator A ]                                                                   |
|     +---> [ Underlying Originator B ]                                                                   |
|     +---> [ Underlying Originator C ]                                                                   |
+---------------------------------------------------------------------------------------------------------+

Associated Risks of Nested Arrangements

  1. Lack of Transparency & Visibility: The ODFI may have no operational insight into who the downstream Originators are, what industries they operate in, or what their risk profiles entail.
  2. Compounded Credit & Fraud Risk: If a nested Originator initiates unauthorized debits or experiences catastrophic insolvency, the return exposure cascades upward through the Lead TPS to the ODFI.
  3. AML / BSA & Sanctions Layering: Nested structures can be exploited by illicit actors to obscure the true originator of funds, creating severe Bank Secrecy Act / Anti-Money Laundering (BSA/AML) vulnerabilities.

5. Mandatory ODFI Registration of Third-Party Senders

To ensure network transparency and combat systemic risk, Nacha Operating Rules mandate that every ODFI must register all Third-Party Senders (and any Nested Third-Party Senders) with Nacha.

Key Registration Requirements

  • The Nacha TPS Registration Portal: ODFIs must use Nacha's secure online registration portal to submit detailed organizational data for each TPS.
  • Registration Timelines: An ODFI must register a TPS within 30 days of the TPS Transmitting its first Entry. A TPS that permits Nested Third-Party Senders must be identified as such within the later of that 30-day window or 10 days of the ODFI becoming aware of the Nested TPS.
  • Required Data Elements: Legal entity name, DBA name, physical address, employer identification number (EIN), contact details, whether the TPS originates on behalf of Nested Third-Party Senders, and whether the TPS provides services to high-risk business categories.
  • Updates & De-registration: The ODFI must update registration information within 45 days of any change to the information previously provided, including termination of a TPS relationship.

6. ODFI Due Diligence, Underwriting & Risk Management

Federal banking regulators (OCC, FDIC, Federal Reserve Board) and Nacha impose rigorous expectations on financial institutions sponsoring Third-Party Senders. Guidance highlights include OCC Bulletin 2006-39, FDIC FIL-44-2008, and the 2023 Interagency Guidance on Third-Party Relationships: Risk Management.

Mandatory ODFI Controls for TPS

  1. Comprehensive Initial Due Diligence: Reviewing audited financial statements, principal backgrounds, business models, client onboarding standards, and BSA/AML compliance programs.
  2. Pass-Through Contractual Enforceability: The contract between the ODFI and TPS must obligate the TPS to bind all underlying Originators to the Nacha Operating Rules, require valid authorizations, and grant the ODFI full audit rights.
  3. Exposure Limits & Real-Time Monitoring: Establishing distinct daily debit, credit, and Same Day ACH exposure limits for the TPS and monitoring for sudden velocity spikes or anomalous transaction volumes.
  4. Nacha Return Rate Threshold Monitoring: Enforcing Nacha's return rate limits across each TPS and underlying Originator:
    • Overall Return Rate Level: 15.0% for returned debit entries other than RCK; crossing it opens a preliminary inquiry rather than an automatic violation.
    • Administrative Return Rate Level (R02, R03, R04): 3.0% — crossing it opens a Nacha inquiry.
    • Unauthorized Entry Return Rate (R05, R07, R10, R11, R29, R51): Must remain below 0.5%.
  5. Annual Audit Enforcement: Ensuring that every TPS performs an annual Nacha Rules Compliance Audit in accordance with Article One, Subsection 1.2.2 of the Rules.
Loading diagram...
Contractual, Data & Warranty Flow in Intermediated TPS Architectures
Test Your Knowledge

What is the core defining structural distinction between a Third-Party Service Provider (TPSP) and a Third-Party Sender (TPS)?

A
B
C
D
Test Your Knowledge

What describes a 'Nested Third-Party Sender' arrangement under the Nacha Operating Rules?

A
B
C
D
Test Your Knowledge

What mandatory obligation does an ODFI have regarding Third-Party Senders under the Nacha TPS Registration requirement?

A
B
C
D
Test Your Knowledge

If a Third-Party Sender's client (an Originator) initiates fraudulent debit entries that result in substantial losses and return fees, who bears ultimate network liability to the RDFI under Nacha Rules?

A
B
C
D