Through Nacha's Risk Management Portal that includes Third-Party Sender Registration, Direct Access Registration, the Terminated Originator Database, and the Emergency Financial Institution Contact Database, ACH Network participants can help enhance Network quality and security, fueling innovation and the continued growth of the Network.
For a detailed Risk Management Portal Instruction Manual, please click here.
For a list of Frequently Asked Questions & Answers, please click here.
Databases in the Portal
The Third-Party Sender Registration Rule requires all ODFIs to either register their Third-Party Sender (TPS) relationships or state that they do not have any.
Registrations are completed through either an individual upload or bulk upload process. The individual upload process allows for quick registration, editing and deactivating of individual TPS relationships, while the bulk upload (available in XML, Excel, and CSV) allows for registering, editing, deactivating, and maintaining groups of TPS relationships. Nacha provides templates that ODFIs can use to build their own internal systems to the Database specifications. The templates include a Word document outlining the specific fields for the Third-Party Sender Registration database and a description of those fields, along with a sample XML, Excel, and CSV file with the database fields included.
If you are unsure whether or not your third-party customers are also Third-Party Senders, use the Third-Party Sender Identification Tool, or contact your local Payments Association (link is external), or Nacha. Remember to provide your financial institution’s routing number in all communications, since this helps to identify you and your information in the database.
The Direct Access Status Registration Rule requires every ODFI to register its Direct Access Debit Participant Status by either acknowledging that it has no Direct Access Debit Participants or providing specific information about each Direct Access Debit Participant.
If you’re unsure whether your ODFI maintains Direct Access Debit Participant relationships, see our definitions and example scenarios, contact your local Payments Association (link is external), or Nacha. Remember to provide your financial institution’s routing number in all communications, since this helps us to identify you in our database.
Nacha offers the Termination Originator Database (TOD) service in order for ODFIs and Third Parties to perform part of their due diligence for KYC (“Know Your Customer”) by being able to add information on, investigate new and periodically verify Originators and Third-Party Senders.
Inclusion in the TOD, after being terminated for cause, does not mean an Originator or Third-Party Sender is prohibited from working with another ODFI. However, it allows educated business decisions about new Originators or Third-Party Senders.
Nacha encourages ODFIs and Third Parties to use the NACHA TOD service in the following ways:
- To add information on terminated Originators and Third-Party Senders.
- To investigate new Originators and Third-Party Senders before onboarding.
- To periodically verify your current Originators and Third-Party Senders, ensuring they haven’t been recently terminated by another ODFI.
Threats and fraud can be perpetuated through cyber attacks, email compromise, account takeover, social engineering, and even vendor impersonation fraud. NACHA provides an Emergency Financial Institution Contact Database as a vehicle for communication during a such events: financial institutions can collaborate and share information as needed to mitigate the impact these events can have on day-to-day operations. This database is designed to include contact information for the financial institution’s key personnel responsible for coordinating threat response activity.
Nacha is committed to taking appropriate steps to secure the data collected and stored in the Risk Management Portal. The Portal is a hosted solution built with security and business continuity in mind, including physical security, encryption, user authorization and authentication processes, and auditing to verify satisfaction of privacy and security requirements. Authorized users must use the secure Risk Management Portal to access the Third-Party Sender Registration Database, the Direct Access Registration Database, the Terminated Originator Database, and the Emergency Financial Institution Contact Database. Data is encrypted while it is in transit to Nacha and remains encrypted while it is at rest in the solution. Moreover, compliance of the underlying cloud platform with key industry standards is certified by the cloud service provider.