Through Nacha's Risk Management Portal that includes Third-Party Sender Registration, Direct Access Registration, the Terminated Originator Database, and the Financial Institution Contact Database, ACH Network participants can help enhance Network quality and security, fueling innovation and the continued growth of the Network.
For a detailed Risk Management Portal Instruction Manual, please click here.
For a list of Frequently Asked Questions & Answers, please click here.
Databases in the Portal
The Third-Party Sender Registration Rule requires all ODFIs to either register their Third-Party Sender (TPS) relationships or state that they do not have any. Once registered, just provide updates following any change to the information you've provided (including termination). Need more information? Get the Risk Management Portal Instruction Manual.
Registrations are completed through either an individual upload or bulk upload process. The individual upload process allows for quick registration, editing and deactivating of individual TPS relationships, while the bulk upload (available in XML, Excel, and CSV) allows for registering, editing, deactivating, and maintaining groups of TPS relationships. Nacha provides templates that ODFIs can use to build their own internal systems to the Database specifications. The templates include a Word document outlining the specific fields for the Third-Party Sender Registration database and a description of those fields, along with a sample XML, Excel, and CSV file with the database fields included.
If you are unsure whether or not your third-party customers are also Third-Party Senders, use the Third-Party Sender Identification Tool, or contact your local Payments Association, or Nacha. Remember to provide your financial institution’s routing number in all communications, since this helps to identify you and your information in the database.
The Direct Access Status Registration Rule requires every ODFI to register its Direct Access Debit Participant Status by either acknowledging that it has no Direct Access Debit Participants or providing specific information about each Direct Access Debit Participant. Once registered, just provide updates following any change to the information you've provided (including termination). Need more information? Get the Risk Management Portal Instruction Manual.
If you’re unsure whether your ODFI maintains Direct Access Debit Participant relationships, see our definitions and example scenarios, contact your local Payments Association (link is external), or Nacha. Remember to provide your financial institution’s routing number in all communications, since this helps us to identify you in our database.
Nacha offers the Termination Originator Database (TOD) service in order for ODFIs and Third Parties to perform part of their due diligence for KYC (“Know Your Customer”) by being able to add information on, investigate new and periodically verify Originators and Third-Party Senders.
Inclusion in the TOD, after being terminated for cause, does not mean an Originator or Third-Party Sender is prohibited from working with another ODFI. However, it allows educated business decisions about new Originators or Third-Party Senders.
Nacha encourages ODFIs and Third Parties to use the NACHA TOD service in the following ways:
To add information on terminated Originators and Third-Party Senders.
To investigate new Originators and Third-Party Senders before onboarding.
To periodically verify your current Originators and Third-Party Senders, ensuring they haven’t been recently terminated by another ODFI.
NACHA provides a Financial Institution Contact Database as a vehicle for communication during operational and risk/fraud events: financial institutions can collaborate and share information as needed to mitigate the impact these events can have on day-to-day operations.
Nacha is committed to taking appropriate steps to secure the data collected and stored in the Risk Management Portal. The Portal is a hosted solution built with security and business continuity in mind, including physical security, encryption, user authorization and authentication processes, and auditing to verify satisfaction of privacy and security requirements. Authorized users must use the secure Risk Management Portal to access the Third-Party Sender Registration Database, the Direct Access Registration Database, the Terminated Originator Database, and the Financial Institution Contact Database. Data is encrypted while it is in transit to Nacha and remains encrypted while it is at rest in the solution. Moreover, compliance of the underlying cloud platform with key industry standards is certified by the cloud service provider.
Threats and fraud can be perpetuated through cyberattacks, email compromise, account takeover, social engineering, and even vendor impersonation fraud. While these threats are not about a direct compromise of the ACH Network or other payment systems, they exploit vulnerabilities or gaps in…
Gain exposure throughout the year
Produced annually, the Nacha Operating Rules & Guidelines is the foundation needed for every ACH payment. Understanding the Rules & Guidelines keeps your organization at the top of its field — ensuring efficient ACH payments, strengthening risk management…
BillGO constantly creates and innovates past what exists. That drive powers the BillGO team to relentlessly advance payment systems to accelerate speed, efficiency and security. BillGO’s technology, currently used by 8,000 banks and more than 30 million consumers, provides a simple integration into…