Skip to content
All resources

Risk 4 min read

What does an ACH risk management program look like?

The risk assessment, exposure limits, and monitoring the Rules expect from ODFIs and Third-Party Senders, and how they show up in an audit.

A guide by Clusia Editorial

Last updated

Last reviewed by Clusia Editorial in September 2026 against the 2026 Nacha Operating Rules & Guidelines.

The Nacha Operating Rules require ODFIs to assess and manage the risk their ACH activity creates, and they extend related obligations to Third-Party Senders. This is distinct from the annual compliance audit: the audit asks whether you followed the Rules, while the risk program asks what could go wrong and how you keep it from happening. Auditors will expect to see evidence that the risk program is real, current, and actually used — not a document that was written once and filed away.

The building blocks

  • A written ACH risk assessment that identifies credit, fraud, operational, and compliance risks and is reviewed and updated on a regular cadence.
  • Exposure limits for each Originator, based on origination volume, settlement patterns, and financial condition.
  • Ongoing monitoring of origination activity against those limits, with a defined process when an Originator approaches or exceeds one.
  • Due diligence at onboarding and ongoing oversight of Third-Party Senders and the Originators they send for.
  • Return-rate monitoring against the unauthorized (0.5%), administrative (3%), and overall (15%) thresholds.
  • Business-continuity, data-security, and fraud-detection controls covering ACH data and files.

Exposure limits in practice

An exposure limit caps how much credit risk an ODFI takes on from a given Originator — essentially, the maximum unsettled origination it is willing to warrant at any time. Setting the limit is only half the job; the Rules expect the ODFI to monitor activity against it and to have a plan when an Originator pushes toward the ceiling. For a growing merchant whose volume is climbing, that might mean re-underwriting the relationship and raising the limit deliberately, rather than simply letting entries through.

The rising bar on fraud monitoring

Recent Nacha rulemaking has expanded expectations around fraud detection, including requirements that reach both sending and receiving institutions and that emphasize monitoring for fraudulent or unusual activity. A modern ACH risk program therefore treats fraud monitoring as a continuous control — anomaly detection on origination patterns, account validation for WEB debits, and prompt investigation of return spikes — rather than a periodic review. Because these requirements have firm effective dates, they belong on the same compliance calendar as any other rule change.

How the program shows up in an audit

During the annual audit, the risk program is checked for existence, currency, and use. Existence: is there a written risk assessment and a set of exposure limits? Currency: has the assessment been reviewed recently and updated for new products and rule changes? Use: is there evidence that monitoring actually happened — records of limit reviews, Third-Party Sender due diligence, and responses to return-rate movement? A strong risk program makes the compliance audit far smoother, because most of the evidence the auditor wants already exists as a byproduct of running the program.

Assessment vs. audit

The risk assessment asks “what could go wrong and how do we control it?” The audit asks “did we follow the Rules?” Both are expected, they are not interchangeable, and doing the first well makes the second dramatically easier.

Frequently asked questions

Is an ACH risk assessment required by the Nacha Rules?
The Rules require ODFIs to assess and manage the risks of their ACH activity, and they extend related obligations to Third-Party Senders. A written, regularly updated risk assessment is the standard way to demonstrate compliance.
How often should the ACH risk assessment be updated?
There is no single mandated interval, but the assessment should be reviewed and refreshed on a regular cadence and whenever there is a material change — a new product, a new Originator type, or a relevant rule change. Annually is a common baseline.
What is an ACH exposure limit?
An exposure limit is the maximum unsettled origination an ODFI is willing to warrant for a given Originator at any time. The ODFI sets it based on volume and financial condition and monitors activity against it.
How is risk management different from the annual ACH audit?
Risk management is an ongoing program that identifies and controls what could go wrong. The annual audit is a point-in-time review of whether you followed the Rules. Both are expected, and a strong risk program supplies much of the evidence the audit needs.

Go to the source

Use Nacha's official resources to confirm current requirements and effective dates.

This resource is published by Clusia for educational purposes and is not legal, accounting, or compliance advice. This site is independent of Nacha. Always confirm requirements against the current Nacha Operating Rules and your own institution's policies.