Nacha’s Risk Management Portal
Through Nacha’s Risk Management Portal, ACH Network participants can help enhance Network quality and security, fueling innovation and the continued growth of the Network.
Nacha Portal Support: Tel: 703-349-4556 or Email: [email protected]
Databases in the Portal
ACH Contact Registry
The ACH Contact Registry - is for financial institutions to be able to more easily connect with other financial institutions about ACH operations, exceptions and risk management. All ODFIs and RDFIs are required to register contact information for ACH Operations and ACH Risk/Fraud. Optional contact categories are also available.
Third-Party Sender Registration
Third-Party Sender Registration - all ODFIs are required to either register their Third-Party Sender (TPS) relationships or acknowledge that they do not have any TPS relationships. Once registered, just provide updates following any change to the information you’ve provided (including termination).
ODFIs have an obligation to fulfill regarding 'Nested Third-Party Senders' as of Sept. 30, 2022. Enforcement on this rule will be effective after March 30, 2023.
The Rules define Nested Third-Party Senders as any Third-Party Sender that has an origination agreement with another Third-Party Sender to act on behalf of an Originator and does not have a direct agreement with the Originating Depository Financial Institution (ODFI). ODFIs will be required to identify all Third-Party Senders which permit Nested Third-Party Sender origination relationships. Complete details on the Rule, as well as a one-page PDF summary, are available on the Third-Party Sender Rule Page on Nacha.org.
ODFIs will identify these Nested Third-Party Senders in Nacha's Risk Management Portal. Nacha has created a video to walk ODFIs through the process, and you may watch it here.
Terminated Originator Database (TOD)
Nacha offers the Terminated Originator Database (TOD) service in order for ODFIs and Third Parties to perform part of their due diligence for KYC (“Know Your Customer”) by being able to add information on, investigate new and periodically verify Originators and Third-Party Senders.
Inclusion in the TOD, after being terminated for cause, does not mean an Originator or Third-Party Sender is prohibited from working with another ODFI. However, it allows educated business decisions about new Originators or Third-Party Senders.
Nacha encourages ODFIs and Third Parties to use the NACHA TOD service in the following ways:
- To add information on terminated Originators and Third-Party Senders.
- To investigate new Originators and Third-Party Senders before onboarding.
- To periodically verify your current Originators and Third-Party Senders, ensuring they haven’t been recently terminated by another ODFI.
Direct Access Status Registration
Direct Access Status Registration - all ODFIs are required to either register their Direct Access Debit Participant Status by providing specific information about each Direct Access Debit Participant or acknowledge that it has no Direct Access Debit Participants. Once registered, just provide updates following any change to the information you've provided (including termination).
If you’re unsure whether your ODFI maintains Direct Access Debit Participant relationships, see our definitions and example scenarios, contact your local Payments Association (link is external), or Nacha. Remember to provide your financial institution’s routing number in all communications, since this helps us to identify you in our database.
Securing the Data Collected and Stored in the Risk Management Portal
Nacha is committed to taking appropriate steps to secure the data collected and stored in the Risk Management Portal. The Portal is a hosted solution built with security and business continuity in mind, including physical security, encryption, user authorization and authentication processes, and auditing to verify satisfaction of privacy and security requirements. Authorized users must use the secure Risk Management Portal to access the ACH Contact Registry, Third-Party Sender Registration, Direct Access Registration, and/or the Terminated Originator Database. Data is encrypted while it is in transit to Nacha and remains encrypted while it is at rest in the solution. Moreover, compliance of the underlying cloud platform with key industry standards is certified by the cloud service provider.
SOC 2 Type II Certified
Nacha's data procedures, controls, and security practices have been audited by outside firms with a focus on our availability, security, and confidentiality. For more information, please contact your account representative.