9.3 Third-Party Sender (TPS) Due Diligence, Monitoring & Registration
Key Takeaways
- A Third-Party Sender (TPS) is a specialized Third-Party Service Provider that acts as an intermediary between an Originator and an ODFI, establishing a direct contractual relationship with the Originator.
- Under the Nacha Third-Party Sender Registration Rule, ODFIs must register all TPS relationships in the Nacha Risk Management Portal within 30 days of the TPS transmitting its first Entry, and must update the registration within 45 days of any change to the information previously provided.
- Nested Third-Party Senders (multi-tiered processing) occur when a TPS contracts with another TPS; ODFIs must identify nested relationships and maintain policies and oversight over all tiers.
- Third-Party Senders are legally required under Nacha Operating Rules to conduct an annual ACH Rules Compliance Audit (Article One, Subsection 1.2.2) no later than December 31 each year and retain proof of completion for 6 years.
- ODFI-TPS agreements must contain pass-through warranties, strict exposure limits for the TPS and every underlying Originator, and explicit rights for the ODFI to inspect records and audit compliance.
9.3 Third-Party Sender (TPS) Due Diligence, Monitoring & Registration
Core Principle: In modern payment ecosystems, many businesses originate ACH payments through intermediary software platforms, payroll bureaus, and payment processors rather than establishing direct banking lines with an ODFI. Under the Nacha Operating Rules, when an entity acts as an intermediary between an Originator and an ODFI and holds a direct contractual relationship with the Originator, it is classified as a Third-Party Sender (TPS). Because the ODFI lacks direct contractual visibility over the underlying Originators, TPS arrangements present elevated credit, operational, and compliance risks that demand strict regulatory controls.
1. Third-Party Participant Taxonomy: TPS vs. TPSP
It is critical on the AAP exam to distinguish between a Third-Party Sender (TPS) and a Third-Party Service Provider (TPSP).
+---------------------------------------------------------------------------------------------------------+
| THIRD-PARTY ENTITY TAXONOMY IN ACH |
+---------------------------------------------------------------------------------------------------------+
| Direct Originator Model: |
| [ Originator ] ================= (Direct Contract) ================> [ ODFI ] |
| |
| Third-Party Service Provider (TPSP) Model (Data Processor): |
| [ Originator ] ================= (Direct Contract) ================> [ ODFI ] |
| | ^ |
| +-----> [ TPSP (Transmits file on behalf of ODFI/Orig) ] ---------+ |
| |
| Third-Party Sender (TPS) Model (Intermediary): |
| [ Originator ] <=== (Contract) ===> [ Third-Party Sender ] <=== (Contract) ===> [ ODFI ] |
| (No direct agreement exists between Originator and ODFI) |
+---------------------------------------------------------------------------------------------------------+
Key Distinctions
- Third-Party Service Provider (TPSP): An entity that performs processing, file translation, software transmission, or data delivery services on behalf of an Originator, ODFI, or RDFI. The TPSP does not contract directly with the Originator to transmit entries into the ACH Network and does not stand in the flow of funds.
- Third-Party Sender (TPS): A specialized type of TPSP that acts as an intermediary between an Originator and an ODFI. The TPS executes the origination contract with the Originator, aggregates or transmits the files, and settles transactions through the ODFI. Under Nacha Rules, the TPS is legally deemed an Originator in its relationship with the ODFI, but acts as an intermediate processor for underlying customers.
2. Mandatory Nacha Third-Party Sender Registration Rule
To provide comprehensive network-wide transparency and monitor systemic processor risk, Nacha established the mandatory Third-Party Sender Registration Rule.
Registration Mandate & Timelines
- Risk Management Portal Registration: Every ODFI must register every TPS relationship in the secure Nacha Risk Management Portal.
- New TPS Registration (30 Calendar Days): The ODFI must register a new TPS within 30 calendar days of the TPS originating its first ACH entry through the ODFI.
- Updates & Terminations (45 Days): If any registration details change, or if the ODFI terminates its relationship with a TPS, the ODFI must update the portal record within 45 days of the change to the information previously provided.
- Nacha Request for Additional Information (10 Banking Days): Nacha reserves the right to request comprehensive additional information regarding any registered TPS (including underlying merchant lists, volume metrics, and risk assessment documents). The ODFI must provide the requested data within ten (10) banking days of receiving Nacha's written request.
+---------------------------------------------------------------------------------------------------------+
| TPS REGISTRATION TIMELINES & MILESTONES |
+---------------------------------------------------------------------------------------------------------+
| Event | Mandatory Nacha Deadline |
+------------------------------------------------+--------------------------------------------------------+
| Initial Registration of New TPS | Within 30 calendar days of first ACH entry origination |
| Update of Registration Details or Termination | Within 45 days of the change to prior information |
| Response to Nacha Request for Information (RFI)| Within 10 banking days of formal written request |
+---------------------------------------------------------------------------------------------------------+
3. Nested Third-Party Senders (Multi-Tiered Processing)
In complex fintech and payment aggregation ecosystems, multi-tiered processing architectures have emerged where one TPS provides origination services to another intermediary TPS.
Definition of Nested TPS
A Nested Third-Party Sender is an entity that acts as a Third-Party Sender by contracting with another Third-Party Sender (the "Direct TPS") rather than directly with the ODFI. The Direct TPS transmits files on behalf of the Nested TPS, which in turn aggregates payments from multiple downstream Originators.
+---------------------------------------------------------------------------------------------------------+
| NESTED THIRD-PARTY SENDER ARCHITECTURE |
+---------------------------------------------------------------------------------------------------------+
| [ Originator A ] --+ |
| [ Originator B ] --+---> [ Nested TPS ] ===> [ Direct TPS ] === (Contract) ===> [ ODFI ] |
| [ Originator C ] --+ |
+---------------------------------------------------------------------------------------------------------+
ODFI Regulatory & Rule Obligations for Nested Senders
- Identification Mandate: The ODFI must determine whether any of its direct TPSs originate on behalf of Nested Third-Party Senders.
- Portal Registration: When registering a TPS in the Nacha Risk Management Portal, the ODFI must explicitly disclose whether the TPS processes for Nested Third-Party Senders.
- Pass-Through Risk Governance: The agreement between the ODFI and the Direct TPS must obligate the Direct TPS to perform full underwriting, KYC/CDD, exposure limit setting, and ongoing monitoring on all Nested TPS entities.
- Nested Chain Liability: The ODFI remains fully liable to the ACH Network for all warranties breached by any nested entity in the chain.
4. Mandatory TPS Risk Assessments & the Annual Article One, Subsection 1.2.2 Compliance Audit
Third-Party Senders are subject to stringent compliance oversight under the Nacha Operating Rules:
A. Annual Rules Compliance Audit under Article One, Subsection 1.2.2 (December 31 Deadline)
- Rule Requirement: Every TPS is legally obligated under Nacha Operating Rules Article One, Subsection 1.2.2 to conduct an annual ACH Rules Compliance Audit.
- Deadline: The audit must be completed no later than December 31 of each calendar year.
- Audit Scope: The audit evaluates authorization storage, SEC-code compliance, record retention, exposure limit adherence, and data security standards.
- Record Retention: The TPS must retain all audit reports and supporting working papers for a minimum of six (6) years from the audit completion date and provide them to the ODFI upon request.
B. Comprehensive TPS Risk Assessment
An ODFI must conduct a formal risk assessment of each TPS prior to onboarding and annually thereafter. The assessment evaluates:
- Financial Viability: Audited financial statements, capital adequacy, credit facilities, and liquidity cushions.
- AML / BSA & OFAC Program: Verification of the TPS's internal Anti-Money Laundering procedures, customer screening algorithms, and OFAC compliance.
- Information Security (PCI DSS / SOC 2): Verification of robust cybersecurity protocols, data encryption at rest and in transit, intrusion detection, and disaster recovery readiness.
5. Contractual Framework: ODFI-TPS Pass-Through Agreements
Because the ODFI does not execute bilateral agreements with the underlying Originators, the ODFI-TPS Origination Agreement must contain rigorous contractual safeguards:
- Pass-Through Warranties: The TPS must warrant that all entries transmitted comply with Nacha Rules, that valid authorizations have been obtained and retained for 2 years, and that all entries are legal under federal and state law.
- Underlying Originator Exposure Limits: The agreement must establish separate, enforceable exposure limits for the TPS in the aggregate and specific exposure limits for each underlying Originator.
- Direct ODFI Auditing & Inspection Rights: The ODFI must reserve the contractual right to inspect the books, records, audit reports, and authorization files of the TPS and its underlying Originators at any time.
- Immediate Termination & Suspension Rights: The ODFI must maintain the unilateral right to immediately suspend or terminate the TPS agreement upon rule violations, excessive return rates, fraud alerts, or regulatory orders.
6. FFIEC Supervisory Guidance on Payment Processor Relationships
The FFIEC Guidance on Managing Risks of Third-Party Relationships and FDIC/OCC Guidance on Payment Processor Relationships outline specific regulatory expectations for financial institutions partnering with processors:
| Supervisory Pillar | Regulatory Requirement | Key ODFI Action |
|---|---|---|
| Due Diligence | Evaluate processor management, background, and financial stability | Review audited financial statements, Dun & Bradstreet, executive backgrounds |
| Underwriting Standards | Ensure processor enforces rigorous merchant acceptance criteria | Review processor's merchant underwriting guidelines and prohibited lists |
| Ongoing Monitoring | Continuously track processing volume, return rates, and velocity | Monitor daily transaction volume against limits; review weekly return trends |
| Independent Audit Verification | Confirm processor undergoes independent compliance & security audits | Collect annual Rules compliance audit certificates and SOC 2 Type II reports |
Under Nacha Operating Rules, what is the mandatory timeframe for an ODFI to register a new Third-Party Sender (TPS) relationship in the Nacha Risk Management Portal following the origination of the TPS's first ACH entry?
What is the regulatory definition of a 'Nested Third-Party Sender' in the ACH Network?
By what annual deadline must a Third-Party Sender complete its mandatory Nacha Operating Rules Compliance Audit under Article One, Subsection 1.2.2, and for how long must proof of that audit be retained?
If Nacha submits a formal written Request for Information (RFI) to an ODFI regarding a registered Third-Party Sender, within what timeframe must the ODFI provide the requested detailed merchant and volume information?