NACHA is committed to taking appropriate steps to secure the data collected and stored in the Risk Management Portal. The Portal is a hosted solution built with security and business continuity in mind, including physical security, encryption, user authorization and authentication processes, and auditing to verify satisfaction of privacy and security requirements. Authorized users must use the secure Risk Management Portal to access the Third-Party Sender Registration Database, the Direct Access Registration Database, the Terminated Originator Database, and the Emergency Financial Institution Contact Database. Data is encrypted while it is in transit to NACHA and remains encrypted while it is at rest in the solution. Moreover, compliance of the underlying cloud platform with key industry standards is certified by the cloud service provider.
Please see below to access the individual databases within the Risk Management Portal.
Detailed Risk Management Portal instructions and a Risk Management Portal User Guide are coming soon.
The Third-Party Sender Registration Rule goes into effect on Sept. 29, 2017, and requires all ODFIs to either register their Third-Party Sender (TPS) relationships or state that they do not have any. Initial registrations are due by March 1, 2018. ODFIs will be required to complete their registrations through the secure Third-Party Sender Registration Database located within the Risk Management Portal. ODFIs can register through either an individual TPS upload or bulk TPS upload process. The individual upload process allows for quick registration, editing and deactivating of individual TPS relationships, while the bulk upload (available in XML, Excel, and CSV) allows for registering, editing, deactivating, and maintaining groups of TPS relationships.
To support ODFIs as they prepare for implementation of the Rule, NACHA is providing templates that ODFIs can use to build their own internal systems to the database specifications. The templates include a Word document outlining the specific fields for the Third-Party Sender Registration database and a description of those fields, along with a sample XML, Excel and CSV file with the database fields included.
Every ODFI is required to register its Direct Access status with NACHA by either acknowledging that it has no Direct Access Debit Participants or providing specific information about each Direct Access Debit Participant relationship. ODFIs will be required to complete their registrations through the secure Direct Access Registration Database located within the Risk Management Portal.
ODFIs and Third Parties can participate in NACHA's Terminated Originator Database (TOD) service, which can be accessed through the Risk Management Portal. The service can be used in the following ways:
NACHA's Emergency Financial Instituion Contact Database provides a vehicle for communication during a crisis. The Database is designed to include contact information for your financial institution’s key personnel responsible for coordinating threat response activity.