ACH Rules Compliance Audit Requirements

This rule changes the structure of the audit requirement within the Rules, but does not change the requirement to conduct a Rules compliance audit annually.  

Detail Icon

Detailed Information

This rule change modifies the Rules to provide financial institutions and third-party service providers with greater flexibility in conducting annual Rules compliance audits.  The rule does not change the requirement to conduct a Rules compliance audit annually, but rather changes the structure of the audit requirement within the Rules by consolidating requirements for the annual Rules compliance audit into one section and removing redundant material.

This Rule modifies the following areas of the NACHA Operating Rules:

  • Article One, Subsection 1.2.2 (Audits of Rules Compliance) – consolidates the core audit requirements described within Appendix Eight under the general obligation of participating DFIs and third-party service providers/senders to conduct an audit
  • Appendix Eight (Rule Compliance Audit Requirements) – eliminates the current language contained within Appendix Eight; combines relevant provisions with the general audit obligation required under Article One, Subsection 1.2.2

The language changes become effective on January 1, 2019 to apply to audits required to be conducted by December 31, 2019.

The language changes become effective on January 1, 2019 to apply to audits required to be conducted by December 31, 2019.

Some organizations may decide to change or modify their methodologies for conducting audits

  • Parties that currently rely exclusively on Appendix Eight as a checklist for conducting their audits should be aware of its limitations (noted earlier) and should be prepared to audit on all relevant rules, even those not currently expressly listed within current Appendix Eight language
  • Current users of Appendix Eight’s checklist should already be consulting the language within the Articles themselves and the remaining Appendices to ensure compliance with all relevant sections of the Rules

For those financial institutions and third-parties that may prefer a workbook or guide to facilitate their annual audit, more robust educational resources exist separately in the form of audit guides

Q. Will this change the current audit requirements?
A. No, the requirements for annual ACH Rules Compliance Audits will not change. They will be located in Article One, Subsection 1.2.2 Audits of Rules Compliance.

Q. Will this change how these audits are performed?
A. If you currently use Appendix Eight of the Rules to perform the audit for your FI or your audit client, you may need to choose a new resource tool. You may reference all rules in the rules pages of the NACHA Operating Rules & Guidelines that are applicable to the functions of the participant being audited or you may look to the NACHA Operating Guidelines or an RPA produced Audit Guide. Resources for purchase are available at https://www.nacha.org/estore/category/risk-compliance

  • 83% of respondents supported moving the Appendix Eight introduction and Part 8.1 into the existing audit discussion of Article One, Section 1.2.2 (Audits of Rules Compliance)
  • 87% supported moving the prescribed list of topics in Appendix Eight from the Rules and into the Guidelines to be included as guidance for performing the annual ACH rules compliance audit
  • 79% supported the proposed effective date of January 1, 2019 to apply to audits due by December 31, 2019

Strong support was received to this proposal and no changes were made from the RFC.