Scrutineer.ai

Scrutineer · By framework

NACHA compliance software for the annual NACHA audit

NACHA compliance is an evidence problem with a hard date on it. Every Third-Party Sender, Third-Party Service Provider and Participating DFI owes an ACH Rules compliance audit by December 31, and since October 2025 Nacha can ask for the proof through an automated request with a 30-day clock.

Scrutineer holds the audit, the risk assessment and the 2026 fraud monitoring review as dated evidence, so that request becomes a lookup rather than a scramble.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with NACHA

The annual audit nobody else can do for you

Nacha is explicit that the Rules compliance audit and the Third-Party Sender risk assessment cannot be passed onto another party: each participant conducts or has conducted its own, and a Third-Party Sender cannot rely on one completed by another sender in the chain. Scrutineer keeps your audit, its date, its findings and the remediation behind them in one place, retained for the six years the Rules require.

A 30-day answer to an automated request

Since October 2025 Nacha sends proof-of-audit requests through its Risk Management Portal, which lets it contact far more institutions each quarter than the old manual process did. The recipient has 30 calendar days, and a bank asked about a Third-Party Sender customer decides whether to accept that sender's own attestation or ask for proof. Scrutineer keeps the proof ready before anyone asks.

Fraud monitoring you can show, reviewed every year

The 2026 risk management rules require ODFIs, non-consumer Originators, Third-Party Senders and Third-Party Service Providers to run risk-based processes to identify entries that are unauthorized or induced under False Pretenses, and to review them at least annually. The Rules do not require screening every entry or monitoring before processing. What they require is a documented, risk-based process, and that is what Scrutineer evidences.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Holds the annual ACH Rules compliance audit, its completion date and its workpapers, retained for the six years Article One, Subsection 1.2.2 requires
  • Keeps the Third-Party Sender risk assessment and the risk management program built on it current, because the Rules make both non-delegable
  • Documents your fraud monitoring procedures by role and records the at-least-annual review the 2026 rules require
  • Maps where DFI account numbers are stored, including authorization records, against the requirement to render them unreadable at rest
  • Tracks which obligations a bank or processor carries for you by contract and which stay with you, so reliance is written down rather than assumed
  • Holds origination agreements across a nested Third-Party Sender chain, with the dates each was executed
  • Reuses the encryption, access control and vendor evidence you already keep for SOC 2 or PCI DSS instead of collecting it twice
  • Keeps an attestation-ready record so a proof-of-audit request from your bank or from Nacha is answered inside the 30 days
NACHA readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

NACHA obligation reference

Every NACHA obligation, who owes it, and whether anyone else can carry it for you

Published NACHA compliance guides list the rules. The question that decides your audit is a different one: which obligations can a bank, a processor or another sender carry on your behalf, and which stay with you no matter what the contract says. The Rules answer it differently rule by rule. Fraud monitoring can be allocated by contract if the reliance is verified. The Rules compliance audit and the Third-Party Sender risk assessment cannot be passed to anyone. Read the third column before you assume someone upstream has it covered.

NACHA obligation Who owes it Can someone else carry it for you? The clock What to hold as evidence
Annual ACH Rules compliance audit Participating DFIs, Third-Party Service Providers and Third-Party Senders No. Each participant conducts or has conducted its own, and a Third-Party Sender cannot rely on an audit completed by another sender in its chain By December 31 every year, with supporting documentation kept for six years from the date of the audit The audit report, workpapers, the completion date and the remediation plan for anything it found
Proof-of-audit request Financial institutions, attesting for themselves and, where applicable, for their Third-Party Sender customers Partly. The bank chooses whether to accept the sender's own attestation or to ask the sender for proof 30 calendar days from the automated request, sent through the Risk Management Portal since October 2025 The completion date ready to hand over, plus the underlying proof in case your bank asks for it
Third-Party Sender risk assessment Every Third-Party Sender, nested or not, together with a risk management program built on it No. The Rules say the risk assessment cannot be passed onto another party Made explicit by the rule effective September 30, 2022. No method or topic list is prescribed The assessment, the risk categories it covered and the controls you implemented because of it
Fraud monitoring on the originating side All ODFIs, plus non-consumer Originators, Third-Party Service Providers and Third-Party Senders Conditionally. An ODFI may consider other participants' procedures, where the reliance is allocated by contract and verified by appropriate oversight Phase 1 on March 20, 2026 for all ODFIs and parties above 6 million entries in 2023; Phase 2 for everyone else, practically June 22, 2026; reviewed at least annually A risk assessment separating higher-risk from lower-risk entries, written procedures and the dated annual review
Credit monitoring on the receiving side RDFIs An RDFI may use a Third-Party Service Provider to carry it out, but the originating side's procedures do not reduce its obligation Phase 1 on March 20, 2026 above 10 million receipts in 2023; Phase 2 for all other RDFIs, practically June 22, 2026 Procedures for flagging and handling suspect credits, and the annual review
Account numbers unreadable at rest Non-FI Originators, Third-Party Service Providers and Third-Party Senders above 2 million entries a year Yes, in one sense: having the financial institution store, host or tokenize the numbers is a listed option June 30 of the year after you cross 2 million entries, counted across all clients and all ODFIs An inventory of every place account numbers are stored, including authorizations, and how each is protected
Nested Third-Party Sender relationships The ODFI registers them; the sender needs an origination agreement with each nested sender The ODFI carries the registration, but the chain of agreements has to exist at every level Registered within the later of 30 days of the first entry or 10 days of the ODFI becoming aware; updated within 45 days of a change Executed origination agreements down the chain, with dates
PAYROLL and PURCHASE entry descriptions Originators of consumer payroll credits and of consumer debits for online purchases of goods Your payroll or payment software may format the file, but the obligation sits with the Originator March 20, 2026 Sample files or processor confirmation showing the descriptions in use

Sources: the Nacha Operating Rules pages for the ACH Rules Compliance Audit Requirements, Third-Party Sender Roles and Responsibilities, Supplementing Data Security Requirements and Risk Management Topics (Fraud Monitoring Phases 1 and 2), and ACH Operations Bulletin #3-2025. Nacha set June 19, 2026 for Phase 2 and moved the practical date to June 22 because the 19th is a federal holiday. Scrutineer prepares you for the ACH Rules compliance audit and keeps the evidence behind it. It is not an ACH auditor or a Payments Association, and it does not screen or block ACH entries.

Good questions

Questions about NACHA

NACHA compliance means following the Nacha Operating Rules, the private rulebook every participant in the US ACH Network agrees to through its bank. For a business that originates or transmits ACH payments that covers authorizations, returns, data security, risk assessment, the 2026 fraud monitoring duties and, for Third-Party Senders and Service Providers, an annual Rules compliance audit.
Participating Depository Financial Institutions, Third-Party Service Providers and Third-Party Senders must each complete an annual audit of compliance with the Nacha Operating Rules under Article One, Subsection 1.2.2. An ordinary Originator sending its own payroll through its bank is not a Third-Party Sender, but its bank may still require it to meet audit-style terms by contract.
The ACH Rules compliance audit has to be completed by December 31 of each year. Documentation supporting it must be kept for six years from the date of the audit and provided to Nacha on request. Many banks set an earlier internal deadline for their Third-Party Sender customers, so check your origination agreement.
Yes. The Rules let the audit be performed under the direction of an audit committee, audit manager, senior-level officer or an independent external examiner or auditor, so an internal audit is permitted. What a sender cannot do is rely on an audit or a risk assessment completed by another Third-Party Sender in its chain. Each participant conducts or has conducted its own.
Three changes matter most. Fraud monitoring duties now cover ODFIs, non-consumer Originators, Third-Party Senders and Service Providers, with Phase 1 on March 20, 2026 and Phase 2 on June 22, 2026. RDFIs must monitor incoming credits on the same two phases. And consumer payroll credits and online purchase debits must carry the descriptions PAYROLL and PURCHASE from March 20, 2026.
No. Nacha answers this directly: the Rules do not require screening every entry individually, and they do not require monitoring before entries are processed. They require risk-based processes reasonably intended to identify unauthorized entries and those induced under False Pretenses, a risk assessment that separates higher-risk from lower-risk activity, and a review at least once a year.
Everyone Phase 1 did not reach. Phase 1 applied from March 20, 2026 to all ODFIs and to Originators, Third-Party Senders and Service Providers above 6 million entries in 2023. Phase 2 removes the volume threshold for every non-consumer Originator, Third-Party Sender and Third-Party Service Provider, effective June 19, 2026, practically June 22 because the 19th is a federal holiday.
Every participant must protect the security of ACH information. On top of that, non-FI Originators, Third-Party Senders and Third-Party Service Providers above 2 million entries a year must render DFI account numbers unreadable when stored electronically, anywhere they are stored, including authorization records. Encryption, truncation, tokenization, destruction or letting the bank hold the numbers all qualify.
Nacha treats it as a Rules violation that can lead to a fine. Answering an automated proof-of-audit request by saying no audit was completed can itself result in a violation. Under the enforcement rule in force since 2021, an egregious violation can be classed as Class 3, with a sanction of up to $500,000 per occurrence and a directive to suspend the Originator or Third-Party Sender.
Since October 2025 through its Risk Management Portal. The recipient gets 30 calendar days to attest either that the annual audit was completed, giving the date, or that it was not. No further documentation is needed to answer that automated request, but the six-year retention duty still applies, and your bank can ask you for the proof itself.
Not on its own. Nacha removed the Appendix Eight audit checklist from the Rules effective January 1, 2019, and moved the core requirement into Article One, Subsection 1.2.2. Nacha warns that relying on the old list leaves gaps, because the audit has to cover every rule relevant to the functions you perform, including anything added since, like the 2026 fraud monitoring duties.
Yes. A nested Third-Party Sender, one that works through another sender rather than directly with the ODFI, must complete its own Rules compliance audit and its own risk assessment. Since September 30, 2022 the Rules also require an origination agreement between each sender and its nested sender, and the ODFI must flag senders with nested relationships in the Risk Management Portal.
No. PCI DSS protects payment card data and is enforced through card brands and acquirers. The Nacha Rules govern ACH payments and are enforced by Nacha through your bank. The evidence overlaps, since encryption at rest, access control and vendor oversight appear in both, and Nacha itself points to PCI DSS and the NIST Cybersecurity Framework as sharing its data security objectives.
Published prices vary too widely to quote one honestly. What moves the number is whether you audit internally or hire a Payments Association or CPA firm, how many ACH functions you perform, whether you are a Third-Party Sender with nested senders, the number of Originators you onboard, and how much evidence you can hand over already organized. The last one is the cost you control.
No. Scrutineer organizes the evidence, keeps the risk assessment and fraud monitoring procedures current and records the annual review, so the audit goes faster and the proof is ready. The audit itself is performed under the direction of your audit committee, a senior officer or an independent examiner, and Scrutineer does not screen, block or return ACH entries.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification