Third Party Sender: Registration, Deadlines, and Penalties

An Originating Depository Financial Institution must complete third party sender registration in Nacha’s Risk Management Portal within 30 days of the first ACH entry the Third Party Sender transmits through it. There is no fee. Failing to register is a Class 2 Rules Violation that can lead to Nacha enforcement action against the ODFI.1Nacha. Third-Party Sender Registration The registration form itself is short. The obligations that surround it — annual verification, nested-sender disclosure, audits, data security, and due diligence — are where most of the work sits.

Who Counts as a Third Party Sender

A Third Party Sender (TPS) is a specific type of Third-Party Service Provider that transmits ACH entries to an ODFI on behalf of an Originator when the Originator has no direct agreement with the ODFI.2Nacha. Third Parties in the ACH Network That missing direct relationship is what pulls an entity into the TPS category. A payroll software company that formats files for a business to upload through its own bank isn’t a TPS. The same company becomes one if it holds the origination agreement with the bank and pushes entries through on the business’s behalf.

Why the distinction matters for registration: only TPSs need to be registered. A broader service provider that doesn’t transmit entries on the Originator’s behalf sits outside the registration rule. Registration also carries downstream consequences, since the TPS is treated as the sender of record and shoulders audit and data security obligations that ordinary service providers don’t have.3Nacha. Third-Party Sender Roles and Responsibilities

What the ODFI Submits

Initial registration in the Risk Management Portal requires a limited set of information the ODFI should already have on hand:1Nacha. Third-Party Sender Registration

  • ODFI name and contact information
  • TPS name and principal business location
  • The ODFI’s routing number from the Originating DFI Identification field used for entries originated for the TPS
  • The TPS’s Company Identification(s)

If Nacha follows up in writing, the ODFI has 10 banking days to provide additional details: any doing-business-as names, the TPS’s taxpayer identification number, street and website addresses, the TPS contact person, names and titles of the TPS’s principals, the approximate number of Originators served, and whether the TPS transmits debits, credits, or both.1Nacha. Third-Party Sender Registration The ODFI is responsible for keeping all of it accurate.

Deadlines and Cost

The standard deadline is 30 days from the date the TPS first transmits an entry through the ODFI. If the ODFI later realizes that an existing customer actually qualifies as a TPS and wasn’t recognized as one, the window tightens to 10 days from that discovery.1Nacha. Third-Party Sender Registration The discovery scenario is common. A relationship that began as ordinary file processing can drift into TPS territory as the customer’s role changes, and the ODFI has to catch it.

There is no registration fee. Nacha covers the cost of the registry through its existing Network Administration Fees.1Nacha. Third-Party Sender Registration

Nested Third Party Senders Must Be Disclosed

A Nested Third Party Sender is a TPS that has an agreement with another TPS rather than directly with the ODFI.3Nacha. Third-Party Sender Roles and Responsibilities Before transmitting entries on a nested entity’s behalf, the TPS must disclose that nested TPS’s identity to the ODFI. The ODFI then flags in the Risk Management Portal which of its registered TPSs have nested relationships.1Nacha. Third-Party Sender Registration

The timing for nested registration mirrors the standard rule: 30 days from the first transmitted entry, or 10 days from when the ODFI becomes aware, whichever is later.3Nacha. Third-Party Sender Roles and Responsibilities There are no volume or risk-based carve-outs. Nacha has stated that “exceptions to registration would lessen the effectiveness of the registry,” and every nested TPS must be identified regardless of size.1Nacha. Third-Party Sender Registration

Keeping the Registration Current

Registration isn’t one-and-done. When any previously submitted information changes, the ODFI has 45 days to update the portal. Independent of any change, the ODFI must verify all registration information at least once a year.4Nacha. ACH Contact Registry The same 45-day update window applies to nested TPS information.3Nacha. Third-Party Sender Roles and Responsibilities

Typical triggers: a TPS changes its legal name, moves its principal office, adds or drops Company Identifications, or begins using a different ODFI routing number. The annual verification exists because changes like these otherwise slip through, especially at institutions managing dozens of TPS relationships.

What Registration Doesn’t Cover on Its Own

Getting the TPS into the registry satisfies one rule. Several other obligations attach to the relationship and belong on the ODFI’s checklist alongside registration.

Annual Compliance Audit

Every TPS must conduct a rules compliance audit of its ACH operations each year under Article One, Subsection 1.2.2 of the Operating Rules.5Nacha. ACH Rules Compliance Audit Requirements The audit checks whether the TPS is retaining authorizations, monitoring for fraud, and following the Operating Rules in day-to-day processing. Documentation must be retained for six years and produced to Nacha on request. The audit can be internal or external. A risk assessment of the TPS’s financial stability and operational security runs alongside it.

Data Security Threshold

A TPS that transmits more than 2 million ACH entries per year, measured across all clients in aggregate, must render stored account numbers unreadable at rest.6Nacha. Supplementing Data Security Requirements Compliance is required by June 30 of the year after the threshold is crossed. Acceptable methods include encryption, truncation, tokenization, or destruction. The ODFI can also host or tokenize the account numbers on the TPS’s behalf. Access controls alone do not satisfy the rule; if the underlying data is readable in storage, restricted credentials aren’t enough. When a full account number is genuinely needed for a task like customer service, it can be accessed in readable form and must return to an unreadable state once the task ends. The scope covers every system where account numbers live, including databases, ACH platforms, and scans of paper authorizations.

ODFI Due Diligence

Third Party Senders are generally not directly subject to Bank Secrecy Act and anti-money laundering requirements; that responsibility falls on the ODFI.7FFIEC BSA/AML InfoBase. Third-Party Payment Processors At a minimum, the ODFI should:

  • Verify the TPS’s business operations, including background checks on the entity and its principals and a review of promotional materials and the website.
  • Evaluate the TPS’s own due diligence procedures for vetting new Originators.
  • Identify the TPS’s major Originator customers, including business activities, geographic locations, and transaction volumes.
  • Confirm Originator legitimacy against public record and fraud databases, directly or through the TPS.

Ongoing monitoring is expected, including periodic audits of the relationship and reviews of the Originator client list.7FFIEC BSA/AML InfoBase. Third-Party Payment Processors

State Money Transmitter Licensing

Depending on how the TPS handles funds, some states require a money transmitter license or registration as a money services business. Operating without a required license can trigger state and federal consequences.8Conference of State Bank Supervisors (CSBS). Third Party Payment Processors Job Aid Federal law makes operating an unlicensed money transmitting business punishable by up to five years in prison.9Office of the Law Revision Counsel. United States Code Title 18 – Section 1960 Not every TPS qualifies as a money transmitter; the analysis is state-specific.

Fraud Monitoring Deadlines in 2026

New Nacha rules require Third Party Senders to implement fraud monitoring on ACH transactions in 2026. The rollout is phased: large Originators, TPSPs, and TPSs must comply by March 20, 2026, and all remaining entities by June 22, 2026.10Nacha. Summary of Upcoming Rule Changes These obligations sit on the TPS itself, not just the ODFI.

Penalties for Failing to Register

An ODFI’s failure to register its Third Party Senders is a Class 2 Rules Violation under Appendix Ten, Subpart 10.4.7.4 of the Operating Rules. Nacha can sanction or fine the ODFI, but no fine is automatic. Enforcement begins with communication to the ODFI, which is given an opportunity to respond and show whether the violation has been remedied before penalties are assessed.1Nacha. Third-Party Sender Registration

Class 3 violations, which cover persistent non-compliance or systemic failures, can reach $500,000 per occurrence and can include a directive to suspend the Originator or TPS.11Nacha. ACH Network Rules – Reversals and Enforcement For most institutions the bigger risk isn’t the fine. A missed registration is typically read by examiners as a signal that the ODFI’s broader third-party risk management may have gaps.