11.1 Annual ACH Rules Compliance Audit (Article One, §1.2.2): Scope & Requirements

Key Takeaways

  • Under Nacha Operating Rules Article One, Subsection 1.2.2 (Audits of Rules Compliance), every Participating DFI (ODFI and RDFI), Third-Party Sender, and Third-Party Service Provider performing ACH functions must complete an annual ACH Rules compliance audit by December 31 of each calendar year.
  • The former Appendix Eight audit checklist was eliminated effective January 1, 2019 and the audit obligation moved to Article One, Subsection 1.2.2; current Appendix Eight covers Arbitration Procedures.
  • The audit scope is comprehensive: general rules (Article One Section 1.6 security requirements), ODFI origination controls (agreements, exposure limits, authorization retention, WEB account validation, Same Day ACH caps), and RDFI processing duties (mandatory receipt, funds availability, return timeframes, WSUDs, and NOCs).
  • Beginning in October 2025, Nacha automated proof-of-audit requests through its Risk Management Portal and contacts randomly selected financial institutions each quarter; registered administrators have 30 calendar days to attest, and the automated response requires no further documentation.
  • Third-Party Senders must conduct their own annual Rules compliance audit and must be registered by their ODFI in the Nacha Third-Party Sender Registration Portal.
Last updated: August 2026

11.1 Annual ACH Rules Compliance Audit (Article One, Subsection 1.2.2): Scope & Requirements

Core Principle: The Automated Clearing House (ACH) Network relies on a private-contract warranty framework where every participant depends upon the legal compliance and operational diligence of every other participant. To preserve network integrity, Nacha Operating Rules Article One, Subsection 1.2.2 (Audits of Rules Compliance) mandates that every Participating DFI (ODFI and RDFI), Third-Party Sender (TPS), and Third-Party Service Provider (TPSP) performing ACH origination or receipt functions must conduct a comprehensive, independent compliance audit annually, no later than December 31 of each calendar year.


1. Legal and Regulatory Framework of the Compliance Audit

Nacha Operating Rules are legally binding private contracts incorporated into financial institution operating agreements, corporate treasury contracts, and clearinghouse rules. Unlike federal statutory examinations (such as FFIEC or CFPB audits) which evaluate systemic safety, soundness, and consumer protection regulations, the Nacha Rules compliance audit specifically measures adherence to the operational, technical, data security, and settlement warranties of the Nacha Operating Rules.

Where the audit rule actually lives — a high-value exam point. Until 2019 the detailed audit checklist sat in Appendix Eight (Rule Compliance Audit Requirements). Effective January 1, 2019, Nacha consolidated the core audit obligation into Article One, Subsection 1.2.2 (Audits of Rules Compliance) and eliminated that audit appendix and renumbered the later appendices; current Appendix Eight is Arbitration Procedures. There is no longer a prescribed Nacha checklist: you must audit against all relevant Rules, not a fixed appendix list. Nacha's own ACH Operations Bulletin #3-2025 cites Subsection 1.2.2 as the governing authority, and Nacha publishes audit guidance in the Operating Guidelines rather than in a rule appendix.

+---------------------------------------------------------------------------------------------------------+
|                                 ARTICLE ONE COMPLIANCE AUDIT MANDATE                                 |
+---------------------------------------------------------------------------------------------------------+
| Governing Rule Authority   | Nacha Operating Rules: Article One, Subsection 1.2.2                       |
| Mandatory Completion Date  | December 31 of EACH calendar year (January 1 - December 31 audit cycle)     |
| Covered Institutions       | • All Originating Depository Financial Institutions (ODFIs)                |
|                            | • All Receiving Depository Financial Institutions (RDFIs)                  |
|                            | • All Third-Party Senders (TPS) & Nested Third-Party Senders               |
|                            | • All Third-Party Service Providers (TPSPs) performing DFI functions       |
| Enforcement Mechanism      | Nacha National System of Fines (Appendix Nine); failure to audit is a       |
|                            | Class 2 Rules Violation                                                    |
| Proof of Audit             | Requested through Nacha's Risk Management Portal; automated outreach began |
|                            | October 2025 (ACH Operations Bulletin #3-2025). Attest within 30 calendar days |
+---------------------------------------------------------------------------------------------------------+

Proof of Audit: Nacha's 2025 Automated Attestation

Beginning in October 2025, Nacha automated proof-of-audit requests through the Risk Management Portal. Nacha now contacts more randomly selected financial institutions each quarter. A registered financial-institution administrator has 30 calendar days to attest whether the institution (or specified Third-Party Sender) completed the annual audit and to provide the completion date. No further documentation is required for the automated request and attestation process. This clock is distinct from other 10-Banking-Day Rules requests.

Annual Completion Cycle (The December 31 Rule)

An institution must perform and complete its Rules compliance audit between January 1 and December 31 of each calendar year. The audit is not an open-ended review; it requires formal sampling of live transactions, evaluation of written procedures, verification of technical parameters, and delivery of a finalized report with executive sign-off prior to the midnight December 31 deadline.


2. General Compliance Audit Scope (All Participants)

Every participating entity—whether operating strictly as an RDFI, an ODFI, or a Third-Party intermediary—must be audited against the foundational general operational and security requirements of the Rules:

+---------------------------------------------------------------------------------------------------------+
|                                  GENERAL AUDIT TESTING REQUIREMENTS                                     |
+------------------------------------+--------------------------------------------------------------------+
| Audit Area                         | Core Verification & Testing Objectives                             |
+------------------------------------+--------------------------------------------------------------------+
| 1. Data Security (Art. One, §1.6)  | Verify banking information transmitted over unsecured electronic   |
|                                    | networks is encrypted, and that covered non-FI Originators, TPSPs  |
|                                    | and TPSs (over 2 million Entries a year) render stored DFI account |
|                                    | numbers unreadable.                                                |
+------------------------------------+--------------------------------------------------------------------+
| 2. Physical & Logical Access       | Test access controls to ACH origination software, terminals, core  |
|                                    | processing engines, file transmission servers, and key stores.     |
+------------------------------------+--------------------------------------------------------------------+
| 3. Data Destruction Policies       | Verify documented, compliant procedures for shredding and secure   |
|                                    | digital sanitization of physical source documents and ACH media.  |
+------------------------------------+--------------------------------------------------------------------+
| 4. Record Retention Systems        | Audit institutional capabilities to store and reproduce records,   |
|                                    | agreements, and return records for required retention timeframes.  |
+---------------------------------------------------------------------------------------------------------+

Data Security Rule Verification (Article One, Section 1.6 — Security Requirements)

Know the scope precisely, because the exam tests who is actually covered:

  • All participants must establish, implement and update security policies, procedures and systems for the initiation, processing and storage of Entries, and must protect the confidentiality and integrity of Protected Information — this is the ACH Security Framework.
  • Transmission over unsecured networks: banking information transmitted over an unsecured electronic network must be encrypted using a commercially reasonable security technology. In practice auditors test for TLS 1.2 or higher, SFTP with SSH key authentication, or AS2 with encrypted payloads.
  • Rendering stored account numbers unreadable: the Supplementing Data Security Requirements rule (Phase 1 effective June 30, 2021; Phase 2 effective June 30, 2022) applies to each non-Consumer Originator that is not a Participating DFI, each Third-Party Service Provider and each Third-Party Sender whose annual ACH origination or transmission volume exceeds 2 million Entries. Those parties must render DFI Account Numbers unreadable when stored electronically. Nacha is technology-neutral: encryption, truncation, tokenization, destruction, or letting the financial institution host the numbers all qualify.
  • Who is NOT covered by the 2-million rule: Participating DFIs are excluded, because their own prudential regulators already impose equivalent standards (GLBA Interagency Guidelines Establishing Information Security Standards). A party that first crosses 2 million Entries in a calendar year has until June 30 of the following year to comply.

3. ODFI Compliance Audit Scope & Sample Testing

An ODFI bears substantial warranty liabilities under Nacha Rules. The Rules compliance audit program for an ODFI evaluates credit underwriting, contract execution, authorization maintenance, SEC-code compliance, and anomaly monitoring.

+---------------------------------------------------------------------------------------------------------+
|                                      ODFI AUDIT CHECKLIST DOMAINS                                       |
+---------------------------------------------------------------------------------------------------------+
|  1. ACH Origination Agreements & Terms         5. Same Day ACH Eligibility & Volume Caps                |
|  2. Originator Underwriting & Exposure Limits   6. Return Rate Tracking & Threshold Controls             |
|  3. Authorization Retention & 10-Day Copies     7. Third-Party Sender Due Diligence & Registration       |
|  4. SEC-Code Specific Rules (WEB/TEL/Micro)     8. Reversals & Erroneous File Protocols                  |
+---------------------------------------------------------------------------------------------------------+

Detailed ODFI Audit Verification Points:

  1. ACH Origination Agreements:

    • Sample commercial Originator and Third-Party Sender contracts to verify that valid, executed agreements exist for 100% of active originators.
    • Ensure agreements include mandatory covenants: the Originator agrees to be bound by Nacha Operating Rules, acknowledges that entries may not be initiated in violation of U.S. law (OFAC), grants the ODFI the right to audit origination processes, and acknowledges established exposure limits.
  2. Originator Underwriting and Exposure Limits (Rule 2.2.3):

    • Verify that the ODFI establishes and formally documents Single-Day Exposure Limits (SDEL), Multi-Day Exposure Limits (MDEL), and dedicated Same Day ACH limits for every Originator and TPS.
    • Confirm that limits are formally reviewed and re-approved by credit authorities at least annually.
    • Test operational controls (automated hard stops, pending approval queues) to confirm that files exceeding approved limits are blocked from release pending credit officer authorization.
  3. Authorization Retention and Document Production:

    • Audit sampling of Originator authorizations to verify that Originators obtain proper written, electronic, or oral consent prior to initiating entries.
    • Verify that the ODFI enforces the rule requiring Originators to retain consumer debit authorizations for two (2) years from the termination or revocation of the authorization.
    • Test the ODFI's operational mechanism to obtain and deliver a copy of an authorization to an RDFI upon written request within ten (10) banking days.
  4. SEC Code Specific Rule Compliance:

    • WEB Entries (Internet-Initiated Debits): Verify that WEB Originators utilize a commercially reasonable fraudulent transaction detection system that includes mandatory Account Validation (verifying routing and account number validity prior to the first debit or upon any account modification).
    • TEL Entries (Telephone-Initiated Debits): Verify that Originators obtain oral authorizations that are either audio-recorded or confirmed by written notice mailed/delivered to the consumer prior to settlement date.
    • Micro-Entries: Verify that Originators use the exact standard Company Name format, adhere to dollar caps ($0.01 to $1.00), transmit credit Micro-Entries of less than $1.00, use ACCTVERIFY, and ensure any offsetting debits do not exceed the corresponding credits.
    • Same Day ACH: Confirm that originated Same Day batches do not exceed the per-transaction limit ($1,000,000) and do not contain ineligible SEC codes (e.g., IAT entries are eligible if domestic leg; automated reversals permitted).
  5. Return Rate Monitoring:

    • Review the ODFI's automated monitoring system for tracking Originator return rates against Nacha enforcement thresholds:
      • Unauthorized Entry Return Rate: Must not exceed 0.5% (R05, R07, R10, R11, R29, R51).
      • Administrative Return Rate Level: 3.0% (R02, R03, R04).
      • Overall Return Rate Level: 15.0% (all R-codes combined).
  6. Third-Party Sender (TPS) Registration:

    • Confirm that the ODFI has registered all TPS relationships in Nacha's Risk Management Portal within 30 days of the TPS transmitting its first Entry, and updated registry data within 45 days of any change to the information previously provided.

4. RDFI Compliance Audit Scope & Sample Testing

For financial institutions acting as RDFIs, the Rules compliance audit evaluates incoming file processing, funds availability, return timeframes, consumer dispute handling, and Notification of Change origination.

+---------------------------------------------------------------------------------------------------------+
|                                      RDFI AUDIT CHECKLIST DOMAINS                                       |
+---------------------------------------------------------------------------------------------------------+
|  1. Mandatory Receipt & Timely Account Posting  4. Written Statement of Unauthorized Debit (WSUD)       |
|  2. Funds Availability Mandates (Standard/Same) 5. Notification of Change (NOC / COR) Accuracy & Timing |
|  3. Return Timeliness (2-Day Admin / 60-Day)    6. Government Reclamations & UCC 4A Payment Orders       |
+---------------------------------------------------------------------------------------------------------+

Detailed RDFI Audit Verification Points:

  1. Mandatory Receipt & Account Posting:

    • Verify that the RDFI receives and processes all ACH entries delivered by its ACH Operator without arbitrary discrimination or manual cherry-picking.
    • Verify that credit and debit entries post accurately based on the account number in Record Type 6.
  2. Funds Availability Schedules:

    • Standard ACH Credits: Sample incoming PPD/CCD credit batches to confirm that funds are made available for cash withdrawal and electronic transfer no later than 9:00 a.m. local time on the Settlement Date (or opening of business for non-consumer accounts).
    • Same Day ACH Credits: Verify availability schedules for Same Day windows:
      • Morning Window (10:30 a.m. ET cutoff / 1:00 p.m. ET settlement): Available by 1:30 p.m. RDFI local time.
      • Afternoon Window (2:45 p.m. ET cutoff / 5:00 p.m. ET settlement): Available by 5:00 p.m. RDFI local time.
      • Late Afternoon Window (4:45 p.m. ET cutoff / 6:00 p.m. ET settlement): Available by end of RDFI processing day.
  3. Return Entry Processing & Timeliness:

    • Administrative Returns (R01, R02, R03, R04, etc.): Sample return logs to verify that return entries are deposited with the ACH Operator so that they are available to the ODFI no later than the opening of business on the second banking day following the Settlement Date.
    • Unauthorized Consumer Returns (R05, R07, R10, R11): Confirm that returns for unauthorized consumer debits are transmitted within the 60-calendar-day return window (calculated from the settlement date of the original entry).
  4. Written Statement of Unauthorized Debit (WSUD) Execution & Retention:

    • Audit consumer dispute records to verify that the RDFI obtains a properly executed, signed, or electronically authenticated WSUD prior to transmitting an R05, R07, R10, or R11 return.
    • Confirm that the WSUD explicitly attests under penalty of perjury that the debit was unauthorized, revoked, or improper.
    • Verify that the RDFI retains the original or an electronic copy of the WSUD for at least one (1) year from the settlement date of the return entry, and provides a copy to the ODFI within ten (10) banking days upon written request.
  5. Notification of Change (NOC / COR) Processing:

    • Sample automated NOC entries (SEC code COR, Addenda Type Code 98) to confirm they are transmitted within two (2) banking days of posting the original entry.
    • Verify the accuracy of Change Codes (C01 through C07) and ensure that the Corrected Data field (positions 36–64) contains valid account, routing, or transaction code information.

5. Third-Party Sender (TPS) and Service Provider (TPSP) Scope

Third-Party Senders (entities that act as an intermediary between an Originator and an ODFI, where no direct banking relationship exists between the ODFI and Originator) have direct compliance obligations under Nacha Rules:

  • Direct Audit Requirement: A TPS must complete an annual Rules compliance audit of its origination operations by December 31, or provide documentation demonstrating that its operations were audited by a qualified independent party.
  • Nested Third-Party Sender Due Diligence: If a TPS originates transactions for Nested Third-Party Senders, the audit must evaluate the agreements, risk policies, KYC reviews, and exposure limits applied down the chain to nested entities.
  • Contractual Alignment: The audit must confirm that all agreements between the TPS and its customer Originators bind the Originators to Nacha Rules and grant audit rights.

6. Comprehensive Audit Comparison Matrix: ODFI vs. RDFI

Audit DomainODFI Audit RequirementRDFI Audit RequirementPrimary Testing Mechanism
Agreement Execution100% active Originators & TPS must have executed contracts binding them to RulesDFI-to-Operator and Account Agreements bound to RulesContract file sampling & legal covenant review
Credit & Risk LimitsBoard-approved policies; SDEL, MDEL & Same Day limits for every Originator; annual limit reviewCredit monitoring of daylight overdrafts / settlement positionsRisk policy inspection & core system limit testing
Authorizations & ConsentVerify Originator obtains consent; retain 2 years; furnish copies in 10 banking daysObtain and retain signed/authenticated WSUD for 1 year prior to R10/R11 returnSample test authorization requests & WSUD archives
SEC Code ComplianceWEB account validation; TEL recording/notice; Micro-entry formatting; Same Day $1M capVerification of proper transaction codes & SEC mapping on postingSystem parameter testing & transaction log sampling
Processing TimelinesDeposit files to meet Operator windows; process NOC updates in 6 days / next runPost credits by 9:00 AM; Same Day availability; return within 2 banking days / 60 daysSettlement ledger sampling & time-stamp validation
Data Security (Art. One, §1.6)Security policies and procedures; encrypt banking information sent over unsecured networks; confirm covered Originators/TPSPs/TPSs over 2M Entries render stored account numbers unreadableSecurity policies and procedures; encrypt banking information sent over unsecured networks; DFIs are excluded from the 2M-Entry storage rule but bound by GLBA standardsIT vulnerability scans & cryptographic architecture review
Loading diagram...
Annual ACH Rules Compliance Audit Framework & Operational Domains
Test Your Knowledge

Under Nacha Operating Rules Article One, Subsection 1.2.2, what is the mandatory annual completion deadline for participating financial institutions to finalize their ACH Rules compliance audit?

A
B
C
D
Test Your Knowledge

During a Nacha Rules compliance audit of an ODFI's WEB debit origination operations, which of the following controls is an auditor strictly required to verify under Nacha Rules?

A
B
C
D
Test Your Knowledge

When auditing an RDFI's exception processing under Article One, Subsection 1.2.2, which operational requirement must be verified regarding consumer returns transmitted with return reason codes R05, R07, R10, or R11?

A
B
C
D
Test Your Knowledge

Which of the following entities is subject to the mandatory annual compliance audit requirement in Nacha Operating Rules Article One, Subsection 1.2.2?

A
B
C
D