Based on our conversations with regulators and auditors, the new Nacha Rules will have a profound effect on future ACH audits. Records that were reasonably required but were often disregarded in past audits will have a new prominence given the New Rules. Here’s how to prepare for future ACH audits by filling three conceptual buckets with relevant records.
If you manage ACH operations at a bank or credit union, you are very familiar with the annual routine: every year, your institution must complete its compliance audit with the Nacha Operating Rules – performed by your Payments Association, an outside firm, or your own internal audit team. And every year, someone (often you) spends weeks gathering the records that demonstrate your institution complies with the Rules in every role it plays.
If that gathering exercise feels harder than it used to, there’s a reason. In 2021, Nacha retired the old Appendix Eight audit checklist and made the audit principles-based. There is no longer a definitive list to work through. Instead, your institution must demonstrate compliance with all provisions of the Nacha Rules that apply to the roles it performs – scoped to your own operations and risk profile. That change asks more of institutions, and it rewards those who can show ongoing, risk-based oversight rather than a once-a-year checklist exercise.
The good news: the evidence your auditor could reasonably ask usually falls into one of three buckets. Thinking in buckets – rather than in tools or systems – makes the whole exercise more manageable, because every institution can fill these buckets in its own way, whether through vendor platforms, core reports, or well-run internal processes. And the buckets follow a natural order: your program defines the controls, your ACH transaction activity shows how things actually went, and your ACH Originator oversight shows you’re managing the risk at its source.
First, a quick refresher on what an audit generally covers:
What your auditor usually looks at
On the receiving side (RDFI):
- Timely funds availability, including Same Day ACH windows
- Returns processed within the two-banking-day deadline
- Handling of consumer unauthorized claims and Written Statements of Unauthorized Debit
- Notifications of Change, generated accurately and on time
- Stop payments and government reclamations
- OFAC screening on international (IAT) entries
On the origination side (ODFI):
- Originator and Third-Party Sender agreements containing the provisions the Rules require, including your right to audit the Originator
- Exposure limits – how they were set, whether they’re enforced systematically, and when they were last reviewed
- Return rate monitoring at the Originator level against the Nacha thresholds, and what you did in response to problematic rates
- Third-Party Senders are registered with Nacha on Nacha Compliance Portal
- Whether Originators’ authorization practices match the SEC codes they use
- Educating and sensitizing your Originators to the Rules and how they should comply
- Your risk-based oversight of each Originator – and the records that demonstrate it
As you think about the evidence you’ll need to produce, the three buckets can be a helpful place to start:
Bucket #1: Your ACH program, policies and procedures
Start here, because this is the architecture everything else flows from. Your program documentation establishes the controls your institution has put in place for itself – and the audit, at its core, tests whether your practice matches your program.
- Board-approved ACH policies and procedures
- Originator and Third-Party Sender agreements covering the controls and obligations you’ve established with your customers
- Your annual ACH risk assessment
- Exposure limit methodology and approvals
- Staff training records
- Prior audit reports, findings, and evidence of remediation
- Compliance tracking – whether that’s a GRC platform (governance, risk, and compliance software), a compliance tracker, or a well-maintained set of internal files
This bucket contains documentation of: what controls have you put in place, and how you have implemented them. Whatever means you use to keep it organized, the key is that these records exist, stay current, and connect to each other – the risk assessment should visibly inform the policies, and the policies should visibly govern the practice.
Bucket #2: A look-back at your ACH transaction activity
With the architecture established, the next bucket contains documentation of what actually happened – the record of money movement through the Network and how you monitored and responded to it.
- Entry volumes and activity by Originator
- Return rate data measured against the Nacha thresholds
- Fraud alerts, anomaly flags, and the follow-up they triggered
- Velocity and exposure tracking against the limits your program established
Many institutions fill this bucket with a transaction monitoring platform; others rely on operator reports and core system data. Either way, this bucket contains evidence that answers the question: what happened at the transaction level, and what did it tell you about relative risk? It’s essential – and it’s inherently a look back. By the time a problem shows up here, the risk has already reached the Network.
Bucket #3: ACH Originator oversight
This is the newest bucket, and for many institutions the hardest to fill – the record of how compliant your Originators actually are with the Rules and with your ACH program’s requirements.
- How each Originator obtains and retains authorizations
- How they secure the systems and credentials that touch payment data
- Whether their day-to-day practices align with their SEC codes and the obligations flowing down through your agreements
- What your institution did to determine your Originators’ compliance, what you did to educate and motivate them to meet the Rules that apply to them, and what you did if they had a gap
This is where Lexalign fits. Via guided diagnostics, your Originators complete a structured self-examination of its operational practices – how it is managing its own risk and compliance relevant to Rules and laws that apply to them individually. Each diagnostic maps to the Rules and translates the Originator’s obligations into plain language and identities gaps with remediation steps, because your business customers aren’t payments experts and shouldn’t have to be.
For your audit, that produces three key pieces of evidence you can share:
- A record of risk-based oversight, per Originator, per year. When your auditor asks how you oversee your ACH Originators, you can demonstrate it with documentation, not general anecdotes.
- A forward-looking view instead of a look back. A diagnostic identifies inadequate authorization practices or weak data security before they become a fraud loss – aligning with the risk-based principle that the Nacha Rules contemplates.
- Stronger Originators. The diagnostic educates as it assesses, extending compliance clarity to your customers and strengthening the entire chain your auditor examines – from the Nacha Rules, through your oversight, to your customer’s daily practice.
Putting the pieces together
No single bucket carries the full ACH audit. By completing each bucket, you can tell a unified story about your ACH risk management and oversight:
- Your ACH program, policies, and procedures establish the controls and the documentation behind them
- Your ACH transaction activity shows what actually happened and how you monitored and responded accordingly
- Your ACH Originator & TPS oversight shows you understand and actively manage the risk at its source – the businesses originating via your institution
The institutions that walk into their audit calmly rather than scrambling are the ones treating all three buckets as year-round practice rather than a seasonal project. Approached that way, the audit stops being an annual archaeology dig and becomes what Nacha intended: independent confirmation of a program that was working all along.
Want to go deeper? Watch our recent webinar on ACH audits and exams, where we walk through what auditors and examiners are asking for in 2026 – and how to build an Originator oversight record you can confidently stand behind.

