Audit 7 min read
What is an ACH audit?
Understand annual ACH and Nacha audit requirements: who needs a review, the December 31 deadline, what auditors examine, and which records to keep.
An ACH audit — often called a Nacha audit or an ACH rules-compliance audit — is a review of whether an organization follows the provisions of the Nacha Operating Rules that apply to its ACH activities. It is a distinct exercise from a financial-statement audit, from an ACH risk assessment, and from an examination performed by a banking regulator. Its single purpose is to answer one question: does what you actually do match what the Rules require of your role?
The requirement to conduct this audit lives in the Nacha Operating Rules at Article One, Subsection 1.2.2, “Audits of Rules Compliance.” (Rule locations can shift between editions, so confirm the exact citation in your current Rules book.) Historically, Nacha prescribed detailed, checklist-style audit procedures in Appendix Eight. Those prescriptive steps were eliminated effective January 1, 2021. The obligation to perform an annual audit remains firmly in place — but Nacha no longer dictates the exact procedures, which means each organization is responsible for designing a review that genuinely covers the Rules applicable to it.
Who needs an annual ACH audit?
The Rules require each participating Depository Financial Institution (DFI), each Third-Party Service Provider, and each Third-Party Sender to conduct an annual audit of compliance with the applicable provisions of the Nacha Operating Rules. The precise scope depends on which ACH functions the organization performs.
- A financial institution that originates and/or receives entries audits the rules that apply to ODFIs and RDFIs.
- A Third-Party Service Provider audits the functions it performs on behalf of its clients.
- A Third-Party Sender audits its origination activity, its origination agreements, and its oversight of the Originators it sends for.
- An ordinary business that simply originates its own payroll or collections is typically bound by the Rules through its ODFI agreement; it should confirm its specific obligations with its ODFI rather than assume the annual audit rule applies identically to it.
This nuance matters. A common mistake is for a small business Originator to assume it must produce a formal Nacha audit identical to a bank’s, or conversely for a Third-Party Sender to assume it has no obligation at all. The correct move is always to map your role first, then confirm the scope with your ODFI and your own reading of the current Rules.
When is the ACH audit due?
The annual audit of Rules compliance must be completed by December 31 of each year. There is no single prescribed start date, so organizations are free to schedule the work whenever suits them — but the review, its findings, and evidence of completion must all be in place by year-end. Treating December as the deadline rather than the start date is one of the most common and avoidable sources of year-end scramble.
Mark the deadline
Plan the scope, evidence collection, and review early enough to fully document results by December 31. Build a repeatable annual calendar so the audit becomes a scheduled confirmation rather than a fourth-quarter fire drill.
What an ACH auditor specifically checks
Because Nacha no longer prescribes exact steps, the substance of the audit is defined by the Rules that apply to your role. In practice, a thorough review examines the following areas, gathering evidence for each rather than relying on attestation.
- Authorization: that debits and credits are properly authorized under the correct standard, that authorizations are readily identifiable, and that copies can be produced on request.
- Record retention: that records of entries and authorizations are retained for the required periods (six years for records of entries; two years after termination or revocation for consumer debit authorizations).
- SEC code usage: that each entry carries the correct Standard Entry Class code and meets that code’s format and authorization requirements.
- Returns and Notifications of Change: that returns are transmitted within the Rules’ timeframes and that NOCs are acted on correctly.
- Prenotifications and account validation: that prenotes and, for WEB debits, commercially reasonable account validation are handled as required.
- Data security: that account numbers and other sensitive data are protected at rest and in transit, consistent with the Rules’ security requirements.
- Origination controls: that origination agreements, exposure limits, and Third-Party Sender oversight and registration are documented and enforced.
- Return-rate monitoring: that unauthorized, administrative, and overall return rates are tracked against Nacha’s thresholds.
Who can perform the audit
Nacha does not mandate a specific auditor or credential. The review can be performed internally by qualified staff who are independent of the function being audited, by an internal audit department, or by an external firm or payments association. Many organizations use staff who hold Nacha’s Accredited ACH Professional (AAP) or Accredited Payments Risk Professional (APRP) credentials, but that is a best practice, not a requirement. What the Rules care about is competence, independence from the audited activity, and documented evidence that the audit was genuinely performed.
An example in practice
Consider a mid-sized software company that debits customers monthly for subscriptions using the WEB SEC code. Its annual audit would, at minimum: pull a sample of customer authorizations and confirm each can be produced and matches the WEB standard; verify that the company runs a commercially reasonable account-validation and fraud-detection process for WEB debits; confirm that returns (including any unauthorized returns) are monitored against the 0.5% unauthorized, 3% administrative, and 15% overall thresholds; and confirm that authorization records are retained for two years after a customer cancels. Findings — say, a batch of authorizations that could not be located — would be documented with an owner and a remediation date, and the completed workpapers would be retained for six years.
Keep the proof
Nacha (through your ODFI) can request evidence that the audit was completed. Retain the audit workpapers and results for at least six years from the date the audit was conducted, and keep any corrective-action tracking alongside them.
Frequently asked questions
- When is the annual ACH audit due?
- The audit of Rules compliance must be completed by December 31 each year. Nacha does not set a start date, so you can schedule the work whenever you like, but the completed review and its evidence must be in place by year-end.
- Where in the Nacha Operating Rules is the audit requirement?
- The annual audit obligation is in Article One, Subsection 1.2.2, “Audits of Rules Compliance.” The prescriptive procedures formerly in Appendix Eight were removed effective January 1, 2021, so organizations now design their own review scope. Confirm the exact citation against your current edition of the Rules.
- Who is required to perform an ACH audit?
- Each participating Depository Financial Institution, Third-Party Service Provider, and Third-Party Sender must conduct an annual audit of compliance with the Rules applicable to its role. Ordinary business Originators are bound through their ODFI agreement and should confirm their specific obligations with their bank.
- How long must I keep ACH audit records?
- Retain the audit workpapers and results for at least six years from the date the audit was performed. Records of entries are also kept for six years, and consumer debit authorizations are retained for two years after they are terminated or revoked.
- Does Nacha require a specific auditor or certification?
- No. The audit can be performed by qualified internal staff independent of the audited function, internal audit, or an external firm. Nacha requires competence, independence, and documented evidence — not a specific credential — though AAP or APRP holders are commonly used.
- Is an ACH audit the same as an ACH risk assessment?
- No. The audit asks whether you followed the Rules; the risk assessment asks what could go wrong and how you control it. Both are expected under the Rules, and a strong risk assessment makes the annual audit far smoother.
Go to the source
Use Nacha's official resources to confirm current requirements and effective dates.
This resource is published by Clusia for educational purposes and is not legal, accounting, or compliance advice. This site is independent of Nacha. Always confirm requirements against the current Nacha Operating Rules and your own institution's policies.