ACH Risk Assessment Template: 2026 Fraud Rules, SEC Codes, Vendors

A usable ACH risk assessment template gives your team a section for each risk category Nacha expects you to evaluate, a place to record the supporting data and controls behind each rating, and a corrective action plan tied to every deficiency. At a minimum it needs to cover operational, credit, fraud, compliance, and reputational risk; document your BSA/AML and OFAC screening; address the fraud monitoring rules taking effect in 2026; inventory your third-party relationships; and end with findings and remediation steps that go to the board.

Who Owes an Assessment

The obligation reaches further than ODFI compliance teams sometimes assume. Originating and Receiving Depository Financial Institutions, Third-Party Service Providers, and Third-Party Senders all have to complete a risk assessment and build a risk management program around the results. Since September 2022, the Nacha Operating Rules explicitly require every Third-Party Sender to perform its own assessment; it cannot be delegated to the ODFI or another party.1Nacha. Third-Party Sender Roles and Responsibilities

Non-consumer Originators, Third-Party Service Providers, and Third-Party Senders also owe risk-based fraud monitoring processes that are reviewed at least annually.2Nacha. Risk Management Topics – Fraud Monitoring Phase 1

Core Risk Categories the Template Must Cover

Examiners look for evidence that you evaluated every category Nacha identifies, not just the ones that felt most relevant to your business.3Nacha. Reminder: Each Third-Party Sender Must Conduct a Risk Assessment by March 31, 2023 Give each category its own section.

  • Operational risk covers how your organization initiates, transmits, and balances ACH files day to day, including dual controls for releasing entries, security of data transmission, and access to server environments.
  • Credit risk captures the exposure created when an originator’s entries are returned unpaid. Track return rates, evaluate originator exposure limits, and flag cases where return volumes suggest weak credit vetting.
  • Fraud risk covers the controls that detect and prevent unauthorized entries or entries authorized under false pretenses. This category expands significantly in 2026.
  • Compliance risk covers whether your organization tracks changes to the Nacha Operating Rules and applicable federal regulations like the Electronic Fund Transfer Act, and whether staff training keeps pace.
  • Reputational risk covers the downstream damage to your institution’s standing when ACH failures, fraud losses, or enforcement actions become public.

Documents and Data to Pull First

Most of the source material lives in different departments, so start collection early. Assigning owners and due dates for each document class saves weeks once drafting begins.

Prior Audit and Assessment

Start with last year’s Nacha Rules Compliance Audit and the prior risk assessment. These set your baseline: what was flagged, what corrective actions were promised, and whether those actions closed. Recurring findings need to reappear as tracked items in this year’s template. Participating DFIs, Third-Party Service Providers, and Third-Party Senders each owe a Rules compliance audit annually, with a December 31 deadline.4Nacha. ACH Rules Compliance Audit Requirements

Internal Policies

Gather your ACH Credit Policy, Operational Procedures manual, and return-handling procedures. They should reflect current protocols for processing returns, handling Notifications of Change, and setting originator exposure limits. If they haven’t been updated since the last cycle, that gap is itself a finding.

Transaction Volume by SEC Code

Pull twelve months of transaction reports broken out by Standard Entry Class code. Isolate PPD (prearranged consumer payments and deposits), CCD (corporate credits and debits), WEB (internet and mobile-initiated), and TEL (telephone-initiated).5Nacha. ACH File Details A full year reveals seasonal spikes a quarterly snapshot would miss. Also pull return data sorted by return reason code. Watch R01 (insufficient funds) and R09 (uncollected funds); elevated rates on those codes signal that originators aren’t verifying account balances or funding before submitting entries.

Third-Party Inventory

Compile a list of every Third-Party Service Provider and Third-Party Sender the institution works with, along with contracts and service-level agreements, and note the specific services each handles: file transmission, encryption, account validation. ODFIs must register information about their Third-Party Sender relationships through the Nacha Risk Management Portal, including names, business locations, routing numbers, and Company Identification numbers.6Nacha. Nacha’s Risk Management Portal Direct Access Debit Participant relationships register through the same portal.

Data Security Controls

The security section should evaluate how the organization protects ACH data in transit and at rest. Nacha rules require that DFI Account Numbers be rendered unreadable when stored electronically. The requirement is technology-neutral: encryption, truncation, tokenization, destruction, or having the financial institution host or tokenize the account numbers all qualify.7Nacha. Supplementing Data Security Requirements

The rule currently applies to non-consumer Originators, Third-Party Service Providers, and Third-Party Senders transmitting two million or more ACH entries per year. If volume crosses that threshold in any given year, compliance is required by June 30 of the following year. Below the threshold, documenting your data protection approach still belongs in the assessment.

Fraud Monitoring Sections for 2026

Two rule changes take effect in 2026 and directly shape what the template needs to say about fraud controls.

Phase 1: March 20, 2026

Every ODFI and every large non-consumer Originator, Third-Party Service Provider, and Third-Party Sender must establish and implement risk-based processes and procedures reasonably intended to identify ACH entries that are unauthorized or authorized under false pretenses.2Nacha. Risk Management Topics – Fraud Monitoring Phase 1 These processes must be reviewed at least annually and updated for evolving risks. Document the specific monitoring techniques deployed: transactional velocity tracking, SEC code and account type mismatches, account age and average balance checks.

Phase 2: June 22, 2026

Phase 2 extends the same obligation to all remaining non-consumer Originators, Third-Party Service Providers, and Third-Party Senders that fell below the Phase 1 threshold, along with all RDFIs not already covered. It also replaces the older “commercially reasonable” standard with a clearer requirement to maintain “risk-based processes and procedures” that are “reasonably intended to identify” suspect entries.8Nacha. Risk Management Topics – Fraud Monitoring Phase 2 Monitoring does not have to happen before posting, but it does have to happen, and the processes need to appear in your risk assessment.

For WEB debit entries, account validation remains a required component of fraud screening. Originators must use a commercially reasonable method to verify that the account number being debited belongs to a valid, open account. Each originator determines what level of validation meets the standard based on its business model and risk profile.9Nacha. Supplementing Fraud Detection Standards for WEB Debits

BSA/AML and OFAC Screening

Give BSA/AML controls their own section. Federal examiners evaluate ACH risk through the lens of BSA/AML compliance, and a template that ignores it looks incomplete during an exam.

The FFIEC BSA/AML examination manual directs examiners to evaluate whether the institution monitors ACH transactions by frequency, dollar volume, and type relative to bank size, location, and customer base. They look for systems that identify customers with frequent and large ACH transactions, flag unauthorized returns suggesting fraudulent or duplicate activity, and apply heightened scrutiny to higher-risk customers originating or receiving International ACH Transactions.10FFIEC BSA/AML InfoBase. Automated Clearing House Transactions

For International ACH Transactions, every party has OFAC screening obligations. The IAT entry should be screened by the Originator before sending, by the financial institutions processing it, and by the ACH Operator acting as Gateway Operator. Corporates face the same OFAC obligations as financial institutions, and violations can carry criminal imprisonment and civil fines reaching millions of dollars per count.11Nacha. International ACH Transactions (IAT) Frequently Asked Questions – Corporate Customers

Red flags the template should track: customers whose ACH activity doesn’t match their business type, accounts opened remotely that immediately generate high-volume ACH transactions, and customers producing high rates of unauthorized returns.

Business Continuity and Operational Resilience

The template should verify that incident and recovery plans covering ACH Critical Services exist, are reviewed and updated annually, and have been tested.12Nacha. Enhancing Operational Resilience for ACH Network Participants Document each of the following:

  • Minimum viable service levels, meaning the lowest level of ACH service delivery needed to keep customers and counterparties operating without significant disruption.
  • Service delivery objectives, meaning target timeframes for restoring ACH processing to an acceptable state after an outage.
  • Recovery infrastructure, meaning whether tested recovery environments and mechanisms are in place to meet those objectives.
  • Non-physical threat scenarios, including destructive malware, ransomware that encrypts primary and backup systems, and wiperware that destroys core infrastructure.

A plan last tested against a 2019 power outage probably doesn’t address the ransomware threats now dominating the risk picture. The assessment is where you flag that gap.

Third-Party Oversight

Every Third-Party Service Provider and Third-Party Sender adds risk to the payment chain, and the template needs to evaluate each. ODFIs must submit and maintain information about every Third-Party Sender relationship through the Nacha Risk Management Portal.6Nacha. Nacha’s Risk Management Portal Institutions with no Third-Party Sender relationships still have to acknowledge that fact through the portal.

When Nacha identifies that a specific Third-Party Sender poses an escalated risk, the ODFI must provide detailed information within ten business days of written notice. The template should track current registration status of each relationship, flag changes since the last assessment, and document the due diligence performed on each provider’s security controls, financial stability, and compliance posture.

The FFIEC manual calls out Third-Party Service Providers as a required component of ACH transaction monitoring. Examiners sample higher-risk third-party relationships and test whether monitoring matches the risk profile, so the assessment should show active oversight rather than a single onboarding review.10FFIEC BSA/AML InfoBase. Automated Clearing House Transactions

Corrective Action Plan

Every deficiency the template surfaces should feed a corrective action plan with four fields: the specific finding, the person or team responsible, the target completion date, and the method for verifying the fix.

Findings about return rates might drive tighter originator exposure limits or prefunding for high-risk originators. Findings about fraud monitoring might call for velocity checks or anomaly detection before the Phase 1 deadline. Be specific. “Improve fraud monitoring” is not a corrective action; “deploy transaction velocity alerts for CCD entries exceeding the 90th percentile of historical volume by February 2026” is.

Board Presentation and Record Retention

The finalized report, corrective action plan included, goes to the Board of Directors or a designated risk committee. Document the presentation in board meeting minutes; examiners treat those minutes as proof that senior leadership exercised oversight. NCUA examiner guidance specifically checks whether management performed a comprehensive risk assessment and whether it is reviewed and updated periodically or when services change.13National Credit Union Administration. Examiner’s Guide – ACH Review Procedures

Nacha Operating Rules require financial institutions to retain ACH records for six years from the date of receipt or transmission. Records can be kept in hard copy or electronic form and do not need to remain in the format used for processing. Some institutions keep records longer based on their own risk tolerance or state regulatory requirements.14Nacha. RMAG: Preventing and Recovering from Operational Errors and Accidents Store each completed assessment in a centralized digital repository with clear version history so successive years can be pulled side by side and prior corrective actions traced through to completion.