Scrutineer · By framework
NACHA compliance software for the annual NACHA audit
NACHA compliance is an evidence problem with a hard date on it. Every Third-Party Sender, Third-Party Service Provider and Participating DFI owes an ACH Rules compliance audit by December 31, and since October 2025 Nacha can ask for the proof through an automated request with a 30-day clock.
Scrutineer holds the audit, the risk assessment and the 2026 fraud monitoring review as dated evidence, so that request becomes a lookup rather than a scramble.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with NACHA
The annual audit nobody else can do for you
Nacha is explicit that the Rules compliance audit and the Third-Party Sender risk assessment cannot be passed onto another party: each participant conducts or has conducted its own, and a Third-Party Sender cannot rely on one completed by another sender in the chain. Scrutineer keeps your audit, its date, its findings and the remediation behind them in one place, retained for the six years the Rules require.
A 30-day answer to an automated request
Since October 2025 Nacha sends proof-of-audit requests through its Risk Management Portal, which lets it contact far more institutions each quarter than the old manual process did. The recipient has 30 calendar days, and a bank asked about a Third-Party Sender customer decides whether to accept that sender's own attestation or ask for proof. Scrutineer keeps the proof ready before anyone asks.
Fraud monitoring you can show, reviewed every year
The 2026 risk management rules require ODFIs, non-consumer Originators, Third-Party Senders and Third-Party Service Providers to run risk-based processes to identify entries that are unauthorized or induced under False Pretenses, and to review them at least annually. The Rules do not require screening every entry or monitoring before processing. What they require is a documented, risk-based process, and that is what Scrutineer evidences.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Holds the annual ACH Rules compliance audit, its completion date and its workpapers, retained for the six years Article One, Subsection 1.2.2 requires
- Keeps the Third-Party Sender risk assessment and the risk management program built on it current, because the Rules make both non-delegable
- Documents your fraud monitoring procedures by role and records the at-least-annual review the 2026 rules require
- Maps where DFI account numbers are stored, including authorization records, against the requirement to render them unreadable at rest
- Tracks which obligations a bank or processor carries for you by contract and which stay with you, so reliance is written down rather than assumed
- Holds origination agreements across a nested Third-Party Sender chain, with the dates each was executed
- Reuses the encryption, access control and vendor evidence you already keep for SOC 2 or PCI DSS instead of collecting it twice
- Keeps an attestation-ready record so a proof-of-audit request from your bank or from Nacha is answered inside the 30 days
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
NACHA obligation reference
Every NACHA obligation, who owes it, and whether anyone else can carry it for you
Published NACHA compliance guides list the rules. The question that decides your audit is a different one: which obligations can a bank, a processor or another sender carry on your behalf, and which stay with you no matter what the contract says. The Rules answer it differently rule by rule. Fraud monitoring can be allocated by contract if the reliance is verified. The Rules compliance audit and the Third-Party Sender risk assessment cannot be passed to anyone. Read the third column before you assume someone upstream has it covered.
| NACHA obligation | Who owes it | Can someone else carry it for you? | The clock | What to hold as evidence |
|---|---|---|---|---|
| Annual ACH Rules compliance audit | Participating DFIs, Third-Party Service Providers and Third-Party Senders | No. Each participant conducts or has conducted its own, and a Third-Party Sender cannot rely on an audit completed by another sender in its chain | By December 31 every year, with supporting documentation kept for six years from the date of the audit | The audit report, workpapers, the completion date and the remediation plan for anything it found |
| Proof-of-audit request | Financial institutions, attesting for themselves and, where applicable, for their Third-Party Sender customers | Partly. The bank chooses whether to accept the sender's own attestation or to ask the sender for proof | 30 calendar days from the automated request, sent through the Risk Management Portal since October 2025 | The completion date ready to hand over, plus the underlying proof in case your bank asks for it |
| Third-Party Sender risk assessment | Every Third-Party Sender, nested or not, together with a risk management program built on it | No. The Rules say the risk assessment cannot be passed onto another party | Made explicit by the rule effective September 30, 2022. No method or topic list is prescribed | The assessment, the risk categories it covered and the controls you implemented because of it |
| Fraud monitoring on the originating side | All ODFIs, plus non-consumer Originators, Third-Party Service Providers and Third-Party Senders | Conditionally. An ODFI may consider other participants' procedures, where the reliance is allocated by contract and verified by appropriate oversight | Phase 1 on March 20, 2026 for all ODFIs and parties above 6 million entries in 2023; Phase 2 for everyone else, practically June 22, 2026; reviewed at least annually | A risk assessment separating higher-risk from lower-risk entries, written procedures and the dated annual review |
| Credit monitoring on the receiving side | RDFIs | An RDFI may use a Third-Party Service Provider to carry it out, but the originating side's procedures do not reduce its obligation | Phase 1 on March 20, 2026 above 10 million receipts in 2023; Phase 2 for all other RDFIs, practically June 22, 2026 | Procedures for flagging and handling suspect credits, and the annual review |
| Account numbers unreadable at rest | Non-FI Originators, Third-Party Service Providers and Third-Party Senders above 2 million entries a year | Yes, in one sense: having the financial institution store, host or tokenize the numbers is a listed option | June 30 of the year after you cross 2 million entries, counted across all clients and all ODFIs | An inventory of every place account numbers are stored, including authorizations, and how each is protected |
| Nested Third-Party Sender relationships | The ODFI registers them; the sender needs an origination agreement with each nested sender | The ODFI carries the registration, but the chain of agreements has to exist at every level | Registered within the later of 30 days of the first entry or 10 days of the ODFI becoming aware; updated within 45 days of a change | Executed origination agreements down the chain, with dates |
| PAYROLL and PURCHASE entry descriptions | Originators of consumer payroll credits and of consumer debits for online purchases of goods | Your payroll or payment software may format the file, but the obligation sits with the Originator | March 20, 2026 | Sample files or processor confirmation showing the descriptions in use |
Sources: the Nacha Operating Rules pages for the ACH Rules Compliance Audit Requirements, Third-Party Sender Roles and Responsibilities, Supplementing Data Security Requirements and Risk Management Topics (Fraud Monitoring Phases 1 and 2), and ACH Operations Bulletin #3-2025. Nacha set June 19, 2026 for Phase 2 and moved the practical date to June 22 because the 19th is a federal holiday. Scrutineer prepares you for the ACH Rules compliance audit and keeps the evidence behind it. It is not an ACH auditor or a Payments Association, and it does not screen or block ACH entries.
Good questions
Questions about NACHA
Keep reading
Guides that go deeper on this framework
ACH audit services for third-party senders
Payments Associations, CPA firms, an internal audit or a platform: what each option produces and what the proof-of-audit clock needs.
Read the guidePCI compliance for service providers
Where card-data obligations overlap with ACH data security, and the requirements that land only on service providers.
Read the guideVendor tiering that holds up
How to decide which processors and nested senders get a full review and which get an attestation.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification