11.2 Auditor Independence & 6-Year Audit Record Retention

Key Takeaways

  • Nacha Operating Rules Article One, Subsection 1.2.2 requires the annual ACH Rules compliance audit to be performed under the direction of the audit committee, audit manager, a senior level officer, or an independent external examiner or auditor.
  • Operations personnel cannot audit their own workflows; qualified alternatives include internal audit staff outside ACH operations, a Payments Association, or an external CPA or payments consulting firm.
  • A sound audit report documents findings, management responses, responsible owners, target dates, and follow-up. These records support remediation even though the Rules expressly frame the retention mandate as proof of audit completion.
  • Proof of completion of the audit must be retained for at least six (6) years from the date of the audit and provided to Nacha upon request.
  • Since October 2025, a registered financial-institution administrator has 30 calendar days to complete Nacha's automated proof-of-audit attestation in the Risk Management Portal; no further documentation is required for that automated response.
Last updated: August 2026

11.2 Auditor Independence & 6-Year Audit Record Retention

Core Principle: An ACH compliance audit is only as reliable as the objectivity of the auditor and the rigor of its documentation. Nacha Operating Rules Article One, Subsection 1.2.2 establishes the direction-and-independence standard for internal and external audit personnel, mandates board-level governance through corrective action plans, requires proof of audit completion to be retained for six (6) years, and supports Nacha's current automated 30-calendar-day Portal attestation process.


1. Auditor Qualification and Independence Standards

The Rules do not name a required credential. Subsection 1.2.2 requires that the audit be performed under the direction of the audit committee, audit manager, a senior level officer, or an independent external examiner or auditor of the DFI, Third-Party Service Provider, or Third-Party Sender. Audits may be performed internally or externally, provided that direction requirement is satisfied and the auditor does not review their own operational work.

+---------------------------------------------------------------------------------------------------------+
|                                 AUDITOR INDEPENDENCE & QUALIFICATION OPTIONS                             |
+------------------------------------+--------------------------------------------------------------------+
| Audit Delivery Model               | Qualifications & Independence Criteria                             |
+------------------------------------+--------------------------------------------------------------------+
| 1. Internal Audit Staff            | • Must be organizationally independent of daily ACH operations.    |
|                                    | • Cannot audit their own operational or processing work.           |
|                                    | • Must report functionally to the Board of Directors, Audit        |
|                                    |   Committee, or Chief Risk Officer rather than ACH operations.     |
+------------------------------------+--------------------------------------------------------------------+
| 2. Regional Payments Associations  | • Highly specialized payment industry associations (e.g., NEACH,   |
|    (RPAs / Direct Payments Bodies) |   ePayResources, EPCOR, WesPay, Southern Payments Alliance, UMACHA)|
|                                    | • Staffed by Accredited ACH Professionals (AAPs) and APRPs.       |
+------------------------------------+--------------------------------------------------------------------+
| 3. External CPA & Consulting Firms | • Independent accounting or financial risk advisory firms.         |
|                                    | • Must demonstrate subject-matter expertise in Nacha Rules,        |
|                                    |   payment regulations (Reg E, UCC 4A), and FFIEC payment booklets. |
+---------------------------------------------------------------------------------------------------------+

The Operational Segregation Rule

An ACH Operations Manager, Payment Processing Supervisor, or Treasury Operations Specialist cannot perform the institution's Rules compliance audit. Allowing operational personnel to audit their own workflows defeats the direction-and-independence requirement of Subsection 1.2.2 and will not stand up to Nacha or examiner scrutiny.


2. Audit Methodology: Sampling, Evidence & Working Papers

An effective compliance audit cannot rely solely on policy reviews or verbal interviews. Auditors must perform substantive transaction testing, sample real-world exception files, and compile comprehensive working papers.

+---------------------------------------------------------------------------------------------------------+
|                                 AUDIT SAMPLING & WORKING PAPER COMPONENTS                               |
+---------------------------------------------------------------------------------------------------------+
| 1. Sample Size Methodology | Statistically valid or risk-based sample sizes reflecting transaction      |
|                            | volumes across all active SEC codes and high-risk Originators.             |
| 2. Substantive File Logs   | Documenting specific Entry Trace Numbers, batch headers, and timestamps.   |
| 3. Contractual Testing     | Examining physical and electronic signatures, terms, and exposure limits.  |
| 4. Exception Item Logs     | Cross-checking WSUD execution dates against R10 return transmittal dates.  |
| 5. Working Papers File     | Detailed test scripts, interview notes, screenshots, and findings logs.    |
+---------------------------------------------------------------------------------------------------------+

Core Working Paper Requirements:

  • Audit Program / Checklist: The specific, line-by-line audit testing guide utilized. Because Nacha eliminated the Appendix Eight checklist in 2019, the program must map to the Rules themselves (and to the audit chapter of the Nacha Operating Guidelines or a commercial audit workbook), not to a retired appendix.
  • Testing Scope and Methodology: Clear documentation explaining how sample files were selected (e.g., random sampling across peak volume days, targeted high-risk Originator sampling, 100% review of third-party contracts).
  • Evidence Logs: Detailed schedules recording sampled transactions, trace numbers, account numbers (masked/redacted in accordance with data security rules), and verification results.
  • Exceptions Matrix: An itemized log of all rule non-compliance events, operational deficiencies, missing agreements, late returns, or unencrypted data flows discovered during testing.

3. Management Response and Corrective Action Plan (CAP)

Once testing is complete, the audit process transitions to executive governance, corrective remediation, and board oversight.

+---------------------------------------------------------------------------------------------------------+
|                                 EXECUTIVE GOVERNANCE & REMEDIATION WORKFLOW                             |
+---------------------------------------------------------------------------------------------------------+
| Step 1: Draft Audit Report    | Auditor documents all findings, risk ratings, and rule citations.       |
| Step 2: Management Response   | ACH management provides formal written responses to each finding.      |
| Step 3: Action Plan (CAP)     | Detailed corrective plan specifying remediation steps & target dates.  |
| Step 4: Board Submission      | Final report, responses, and CAP presented to Board / Audit Committee. |
| Step 5: Remediation Validation| Independent follow-up testing to verify that corrective fixes work.    |
+---------------------------------------------------------------------------------------------------------+

Essential Elements of the Corrective Action Plan (CAP):

  1. Root Cause Analysis: Explaining why the compliance breakdown occurred (e.g., software parameter misconfiguration, employee turnover, inadequate training, lack of pre-release limit checks).
  2. Specific Remedial Actions: Concrete operational, technical, or contractual measures implemented to correct the deficiency.
  3. Designated Accountability: Naming specific management personnel responsible for executing each remedial milestone.
  4. Target Implementation Dates: Clear, binding calendar deadlines for completing corrective actions.
  5. Validation Testing: Re-auditing or sampling corrected processes within a reasonable timeframe (e.g., 60–90 days post-remediation) to ensure full operational compliance.

4. The Six-Year Proof-of-Completion Rule

Under Nacha Operating Rules Article One, Subsection 1.2.2, a participating financial institution and Third-Party Sender must retain proof that the annual compliance audit was completed for six years from the audit date. The express rule is proof of completion; it should not be restated as a universal command that every workpaper, sample log, board minute, transaction record, or source item has the same six-year Nacha retention period.

A defensible proof package ordinarily includes the dated final report or completion certification, the scope and entity covered, and evidence of the person or function directing the audit. Institutions commonly retain workpapers, findings, management responses, corrective-action plans, and follow-up testing because they substantiate the conclusion and remediation, but the governing retention period for each other record may come from a different rule, regulation, agreement, litigation hold, or institutional policy.

Keep the Clocks Separate

RecordHigh-value exam rule
Annual ACH compliance auditRetain proof of completion for six years
Consumer ACH debit authorizationOriginator generally retains the record for two years after termination or revocation
Written Statement of Unauthorized DebitApply the Rules-specific WSUD retention requirement; do not substitute the audit clock
SAR and supporting documentationFederal BSA rules use a separate five-year retention period

The lesson is methodological: identify the record and controlling authority before applying a number. The six-year audit-proof rule is not a blanket retention rule for all ACH operational data.


5. Nacha's 30-Calendar-Day Automated Proof-of-Audit Attestation

Article One, Subsection 1.2.2 requires participants to retain proof of completing the annual audit. Under ACH Operations Bulletin #3-2025, automated proof requests now arrive through the Risk Management Portal.

+---------------------------------------------------------------------------------------------------------+
|                             AUTOMATED PROOF-OF-AUDIT RESPONSE                                          |
+---------------------------------------------------------------------------------------------------------+
| 1. Portal Request          | Nacha sends the request to registered financial-institution administrators.|
| 2. 30-Calendar-Day Clock   | An administrator attests whether the institution or specified TPS completed|
|                            | its annual audit and supplies the completion date.                         |
| 3. Documentation           | No further documentation is required to fulfill the automated attestation. |
| 4. Enforcement             | Attesting that the audit was not completed may result in a Rules violation.|
+---------------------------------------------------------------------------------------------------------+

Do not substitute a separate 10-Banking-Day exception or enforcement clock for this automated process. Institutions should still retain the underlying audit evidence for six years and make it available when another lawful request or examination calls for it.

Examination by Federal and State Regulatory Agencies

Separate from Nacha's automated Portal attestation, financial institution regulators (including the OCC, FDIC, Federal Reserve Board, NCUA, and state banking authorities) routinely examine ACH Rules compliance audit reports and CAPs during annual FFIEC Safety and Soundness and Compliance Examinations. Deficiencies identified in Nacha audits that lack proper management remediation frequently result in formal regulatory supervisory findings or Matters Requiring Attention (MRAs).

Loading diagram...
Audit Lifecycle, Board Governance, 6-Year Retention & Nacha Production Framework
Test Your Knowledge

Which of the following operational arrangements satisfies the auditor direction and independence requirement in Nacha Operating Rules Article One, Subsection 1.2.2?

A
B
C
D
Test Your Knowledge

Under Article One, Subsection 1.2.2, how long must a participating DFI retain proof that its annual ACH Rules compliance audit was completed?

A
B
C
D
Test Your Knowledge

Under Nacha's automated proof-of-audit process launched in October 2025, how long does a registered administrator have to complete the Risk Management Portal attestation, and what must be attached?

A
B
C
D
Test Your Knowledge

An ACH Rules compliance audit identifies operational deficiencies. Which response best demonstrates sound governance and creates evidence for follow-up?

A
B
C
D