Skip to content
All resources

Audit 5 min read

How do you prepare for an ACH audit?

A practical, checklist-driven approach to the annual review — the documents to gather, the controls to test, and the findings to fix before the December 31 deadline.

A guide by Clusia Editorial

Last updated

Last reviewed by Clusia Editorial in September 2026 against the 2026 Nacha Operating Rules & Guidelines.

A well-run ACH audit is mostly preparation. The annual audit of Rules compliance must be completed by December 31, and if you gather the right evidence and test the right controls throughout the year, the review becomes a confirmation rather than a scramble. This guide walks through a practical, checklist-driven approach you can adapt to your role — Originator, ODFI, RDFI, or Third-Party Sender.

Start with scope

Before gathering a single document, define what the audit must cover. Scope is driven entirely by role, so pin that down first.

  1. Confirm your role(s): Originator, ODFI, RDFI, Third-Party Sender, or a combination — this scopes the entire audit and tells you which Articles of the Rules apply.
  2. Obtain the current year’s Nacha Operating Rules and note any amendments that took effect this year, especially in fraud monitoring and risk management.
  3. List the SEC codes you use and the channels you collect authorization through, so you know which authorization standards are in scope.

Assemble your evidence

The audit is an evidence exercise. Gathering these items before the review starts is what separates a smooth audit from a painful one.

  • Origination agreements and any Third-Party Sender agreements, plus registration records where applicable.
  • A representative sample of authorizations across each SEC code you use, with proof each can be produced.
  • Return reports and the return-rate calculations for the unauthorized (0.5%), administrative (3%), and overall (15%) thresholds.
  • Exposure limits and evidence they are monitored and enforced.
  • Your written ACH risk assessment and evidence of its most recent review.
  • Data-security documentation showing how account numbers are protected at rest and in transit.
  • Records of Notifications of Change and how they were applied.

What to test

With evidence in hand, test the controls that matter most — the ones that generate findings when they fail.

  • Sample authorizations and confirm each can be produced, matches its SEC code, and states amount, timing, and revocation terms.
  • Verify returns and Notifications of Change were handled within the Rules’ required timeframes.
  • Recalculate your three return rates and confirm they are monitored on an ongoing basis, not just at audit time.
  • Confirm account data is protected at rest and in transit and that access is appropriately restricted.
  • Check that exposure limits exist, are monitored, and are enforced.
  • Review Third-Party Sender registration, due diligence, and ongoing oversight.
  • Confirm records of entries are retained for six years and consumer debit authorizations for two years after revocation.

Document findings and close the loop

Findings only matter if they are fixed. For each issue, record what was found, assign an owner and a remediation date, and track it to completion. Keep this tracking alongside the audit workpapers so that next year’s reviewer — and any request from your ODFI — can see both the finding and its resolution. This is also where a “last reviewed” discipline pays off: noting the Rules edition you audited against makes it obvious next year what has changed.

Build a year-round calendar

The best-prepared organizations do not treat the audit as an event. They monitor return rates monthly, refresh the risk assessment on a schedule, sample authorizations quarterly, and track rule changes as their effective dates approach. By December, the annual audit is largely a matter of assembling evidence that already exists. That is the difference between an audit that confirms a healthy program and one that discovers problems too late to fix before year-end.

Close the loop

Findings only matter if they are fixed. Document each finding, assign an owner and a remediation date, retain the completed audit and workpapers for at least six years, and note the Nacha Rules edition you audited against so next year starts from a known baseline.

Frequently asked questions

When do I need to complete my ACH audit?
The annual audit of Rules compliance must be completed by December 31 each year. There is no mandated start date, so schedule the work early enough to gather evidence, test controls, and document findings before the deadline.
What documents do I need for an ACH audit?
At a minimum: origination and Third-Party Sender agreements, a sample of authorizations across each SEC code, return reports and return-rate calculations, exposure limits, your written risk assessment, data-security documentation, and Notification of Change records.
What are the most common ACH audit findings?
The most frequent findings are authorizations that cannot be produced, incorrect SEC codes, return rates that exceed thresholds without a documented response, missing or stale risk assessments, and authorizations not retained for the full two years after revocation.
Can I perform my own ACH audit internally?
Yes, provided the reviewer is competent and independent of the function being audited. Nacha does not require an external auditor or a specific certification, though many organizations use staff holding the AAP or APRP credential.
How long should I keep the completed audit?
Retain the completed audit, workpapers, and corrective-action tracking for at least six years from the date the audit was performed, consistent with the Rules’ record-retention requirements.

Go to the source

Use Nacha's official resources to confirm current requirements and effective dates.

This resource is published by Clusia for educational purposes and is not legal, accounting, or compliance advice. This site is independent of Nacha. Always confirm requirements against the current Nacha Operating Rules and your own institution's policies.