ACH audit services for third-party senders
Four ways a Third-Party Sender can get its annual ACH Rules audit done, what each one produces, and what the 30-day Nacha proof-of-audit clock now demands.
By the Scrutineer team
September 2026 · 9 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
A Third-Party Sender has four realistic ways to get its annual ACH Rules compliance audit done: a Payments Association audit, a CPA or consulting firm, an internal audit run under the direction of a senior officer, or any of those backed by a platform that keeps the evidence organized all year. The right choice is the one your bank will accept, that covers the 2026 fraud monitoring rules, and that lets you answer a proof-of-audit request inside 30 days.
Who actually needs an ACH audit service
The Nacha Operating Rules, at Article One, Subsection 1.2.2, require every Participating DFI, Third-Party Service Provider and Third-Party Sender to complete an audit of its compliance with the Rules by December 31 of each year. The documentation behind that audit has to be kept for six years from the date of the audit and produced if Nacha asks for it.
If you are a payroll provider, a billing platform, a payment facilitator or any business that originates ACH entries on behalf of other companies through its own bank relationship, you are almost certainly a Third-Party Sender. If you only send your own payroll and vendor payments through your bank, you are an Originator, and the annual audit is not yours under the Rules, although your origination agreement may still ask for something similar. Read the agreement before you buy anything.
Most Third-Party Senders do not have an ACH specialist on staff, which is why an audit service market exists at all. The question is which kind to buy.
The four ways to get the annual ACH audit done
The options are not interchangeable. They differ in who signs off, what you receive, how much of your own time they consume, and what is still sitting on your desk when the auditor leaves.
| Option | Who performs it | What you get | Where it stops | Best fit |
|---|---|---|---|---|
| Payments Association audit service | ACH specialists at a regional Payments Association, on site or remote | A findings report and recommendations from people who work in the Rules daily | Scheduling is seasonal and the report is a point in time. The evidence is still yours to assemble | Senders that want a recognized name on the report and have not audited before |
| CPA or consulting firm | An external auditor, often bundled with SOC or other assurance work | An independent report, sometimes combined with the ACH risk assessment | Quality depends heavily on the firm's ACH depth, which varies more than the price does | Senders already paying a firm for SOC 1 or SOC 2 that want one engagement |
| Internal audit with a workbook | Your own staff, under the direction of an audit committee, audit manager or senior-level officer | A Rules-compliant audit at the lowest cash cost, usually built on a purchased audit workbook or guide | Only as good as the reviewer's knowledge of rules added since the workbook was written | Mature senders with a compliance lead who knows the Rules well |
| Any of the above, backed by a compliance platform | The same auditor, working from evidence you kept all year | Faster fieldwork, a dated evidence trail and a proof-of-audit answer ready on request | A platform is not an auditor and cannot sign the audit for you | Senders that have been through one painful audit and do not want a second |
The last row is not a fifth option. It changes how the first three go. The auditor's time is the expensive part of every engagement, and most of that time is spent waiting for evidence.
What the auditor will actually look at
Nacha's ACH Operations Bulletin #3-2025 describes the scope of a Rules compliance audit as including, but not limited to, a review of policies and procedures for processing ACH transactions, an evaluation of risk management practices, an assessment of compliance with data security protocols, verification of customer due diligence and onboarding, testing of error resolution, and a review of transaction monitoring and reporting.
Two things have changed that plenty of audit programs have not caught up with.
The old checklist is gone. Nacha removed the Appendix Eight audit checklist from the Rules effective January 1, 2019, and moved the core requirement into Subsection 1.2.2. Nacha's own guidance warns that parties relying on Appendix Eight as their checklist should be prepared to audit every relevant rule, including ones the old list never named. An audit service still working from that list is auditing an incomplete scope.
The 2026 fraud monitoring rules are now in scope. Phase 1 took effect on March 20, 2026 for all ODFIs and for Originators, Third-Party Senders and Service Providers above 6 million entries in 2023. Phase 2 removed the threshold for everyone else, effective June 19, 2026 and practically June 22, since the 19th was a federal holiday. Each covered party must run risk-based processes to identify entries that are unauthorized or induced under False Pretenses, and review them at least once a year. So this year's audit is the first one that should test whether that annual review happened. Ask any provider you are considering how they test it.
If you cross 2 million entries a year, counted across all your clients and all your ODFIs, the audit will also look at whether DFI account numbers are unreadable wherever you store them electronically, which includes authorization records. Much of that evidence overlaps with what you already hold for PCI DSS compliance, so do not collect it twice.
The part no ACH audit service can take off your hands
This is the detail that most buyers of audit services miss. Nacha's Third-Party Sender Roles and Responsibilities rule, effective September 30, 2022, states that the risk assessment obligation and the required Rules compliance audit cannot be passed onto another party. Each participant conducts or has conducted its own, and a Third-Party Sender cannot rely on an audit or a risk assessment completed by another sender in its chain.
An audit firm can perform the work, but the obligation and the result stay yours. If you have nested senders, meaning other senders that reach the ODFI through you rather than directly, each of them owes its own audit and its own risk assessment too, and you need an origination agreement with each one.
Fraud monitoring works differently, which is why it is worth being precise. There the Rules let an ODFI's processes take account of procedures run by other participants, provided the reliance is allocated by contract and verified by appropriate oversight. So one obligation can be shared on paper and the others cannot. Treating your processor's monitoring as covering you is only defensible if the contract says so and you have checked. That is ordinary third-party risk management applied to your own payment chain, and tiering those vendors by the obligations they carry for you is how you keep the checking proportionate.
The 30-day proof-of-audit clock
For more than a decade Nacha requested proof of audit by hand, which limited how many institutions it could contact. Since October 2025 it has sent those requests through its Risk Management Portal, and the stated aim is to contact more financial institutions every quarter.
The recipient has 30 calendar days to attest either that the annual audit was completed, with the date, or that it was not. Answering that it was not completed could result in a Rules violation. When a bank is asked about a Third-Party Sender customer, it decides whether to let the sender attest for itself or to ask the sender for the proof. Expect some to ask. If your audit report and workpapers live in someone's inbox, those 30 days go quickly.
How much do ACH audit services cost?
We are not going to quote a figure, because published prices vary too widely to be useful and depend on scope you do not share with whoever published them. What moves the number is predictable, though:
- How many ACH functions you perform. Originating debits and credits, transmitting files, handling returns and onboarding Originators are each separate areas of testing.
- Nested senders. Every level in the chain adds agreements to review and relationships to test.
- Originator volume and onboarding. The auditor samples customer due diligence and authorization quality, and more Originators means larger samples.
- Whether the risk assessment is bundled. Some providers price the audit and the risk assessment together, others separately.
- How organized your evidence is. This is the only driver you fully control, and it is usually the biggest source of billed hours.
The cost of not doing it is clearer. Under the enforcement rule in force since 2021, an egregious violation, one that is willful or reckless and involves at least 500 entries or $500,000, can be classed as a Class 3 violation carrying a sanction of up to $500,000 per occurrence and a directive to the ODFI to suspend the Originator or Third-Party Sender.
How to choose an ACH audit service
Five questions separate a provider that will pass you from one that will protect you:
- Does your program test the 2026 fraud monitoring rules, including evidence of the annual review?
- Do you audit against the full Rules, or against a checklist, and when was that checklist last updated?
- How do you handle nested senders and the chain of origination agreements?
- Will you perform or review our Third-Party Sender risk assessment, and is it priced separately?
- What exactly do we receive, in what format, and is it enough for our bank if it asks for proof rather than an attestation?
A Payments Association will usually answer the first two well. A CPA firm may win on the fifth if you already run SOC work with it. An internal audit is fine if you can answer all five yourself.
One adjacent point. Authorization quality is one of the things an auditor samples, and for senders whose clients originate debits to collect on invoices, the authorizations are only as good as the billing workflow that produced them. If that workflow is still spreadsheets and ad hoc emails, accounts receivable automation fixes the upstream mess, and that is a separate job from the audit itself.
Where Scrutineer fits
Scrutineer is not an ACH auditor, it is not a Payments Association, and it does not screen, block or return ACH entries. It is the evidence layer underneath whichever audit route you pick. It holds the annual audit with its completion date and remediation, keeps the Third-Party Sender risk assessment and the program built on it current, records the annual review of your fraud monitoring procedures, maps where account numbers are stored, and tracks which obligations a bank or processor carries for you by contract. When the proof-of-audit request arrives, the answer is already assembled.
The full obligation map, including which NACHA duties can be carried by someone else and which cannot, is on the NACHA compliance software page.
Can a third-party sender do its own NACHA audit?
Yes. The audit may be performed under the direction of an audit committee, audit manager, senior-level officer or an independent external examiner or auditor, so an internal audit meets the Rules. What a sender cannot do is rely on an audit or risk assessment completed by another Third-Party Sender in its chain. Some banks prefer an external report, so check your origination agreement first.
Is an ACH audit required for originators?
Not under the Rules' annual audit requirement, which applies to Participating DFIs, Third-Party Service Providers and Third-Party Senders. An ordinary Originator still has to follow the Rules, including the 2026 fraud monitoring duties for non-consumer Originators and, above 2 million entries a year, the data security requirement. Its bank can also require an audit by contract.
What happens if a third-party sender misses the ACH audit?
Missing it is a Rules violation that can lead to a fine, and admitting it in response to an automated proof-of-audit request can itself trigger one. The practical risk usually comes from the bank first: an ODFI that cannot show its senders were audited has its own exposure, and suspending the sender's origination privileges is the lever it holds.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.