In What ACH Risk Assessments Reveal That Audits Often Don’t, we looked at the assumptions and blind spots risk assessments often uncover, the risks that exist even when an institution is compliant. One of the most common places those assumptions appear is in ACH Exposure Limits.
The conversation often starts the same way: “We’ve had this customer for years.”
It is usually said with confidence, and often for good reason. The relationship is strong. The customer is well-known. There have been no significant issues. Returns are reasonable.
Everyone around the table feels comfortable.
That is precisely why the conversation becomes interesting.
As ACH professionals, we spend a great deal of time evaluating new relationships. We review financials, perform due diligence, assess risk, establish Exposure Limits, and document our decisions. New Originators receive scrutiny because they are unfamiliar.
Long-standing Originators are different. They are known. They are trusted. Over time, familiarity can create a blind spot — not because anyone is ignoring risk, but because the relationship has been successful for so long that the assumptions supporting the original risk decision become part of the background.
Then, during a risk assessment, we take a closer look. The Exposure Limit may still be in place, and the customer relationship may still appear strong. But the more important question is whether the original risk decision still reflects the activity taking place today.
The Number Everyone Knows
One of the easiest pieces of information to find in an ACH program is an Exposure Limit. Ask about a long-standing Originator and someone can usually identify the approved limit quickly. The number is known. The approval history may be documented. The relationship has likely been reviewed over the years.
At first glance, everything appears as it should.
But Exposure Limits were never intended to be static numbers sitting in a file or system parameter. They reflect a risk decision made at a point in time. When the limit was approved, it represented what the institution understood about the customer then — the business model, transaction activity, operational practices, financial condition, anticipated ACH exposure, and overall risk profile.
The number itself is not the control. The thinking behind the number is the control.
That distinction matters because Exposure Limits serve a broader purpose than many institutions realize. In addition to helping manage credit risk, properly established and monitored exposure limits can help identify unusual transaction activity, duplicate payments, operational errors, unexpected SEC Code usage, fraud attempts, and debit return exposure. They are designed not only to limit loss, but to create visibility into activity that deserves a closer look. Nacha’s Risk Management Advisory Group has stated that Exposure Limits protect against fraud risk, operational risk, and credit risk associated with returned debits, and that they can help identify anomalies such as larger-than-expected entries, multi-day variances, unexpected SEC Codes, and duplicate activity.
The Story Behind the Number
Some of the most revealing conversations during a risk assessment happen when discussing a relationship that has been around for years. The customer is trusted. Volumes are strong. No significant issue has occurred.
Then we talk through the history of the account.
What began as a relatively small commercial relationship may now involve substantially larger files, expanded payroll activity, new markets, additional customers, or new services. In many cases, the Exposure Limit was adjusted along the way. Each increase may have been reasonable. Each approval may have been documented. Nothing about that is inherently concerning.
What becomes interesting is when we ask whether the institution would make the same risk decision if the customer walked through the door for the first time today.
Sometimes the answer is immediately yes. Sometimes the room gets quiet — not because anyone made a mistake, but because everyone realizes they may be evaluating today’s relationship using assumptions established years ago.
When Familiarity Becomes a Risk Factor
One of the great strengths of community financial institutions is that they know their customers. Relationships matter. History matters. Trust matters.
But from a risk management perspective, familiarity can occasionally create a subtle challenge. The customers we know best are often the customers we question the least. Meanwhile, their ACH activity may be evolving significantly.
The goal is not to become suspicious of long-standing customers. The goal is to ensure risk management practices evolve alongside the relationship.
Because familiarity should never replace review.
Questions Worth Asking
When reviewing high-volume Originators, I often encourage institutions to ask five questions:
- When was the exposure limit last formally reviewed, not simply increased?
- Has the customer’s business changed significantly since onboarding?
- Does current ACH activity still align with the assumptions used when the limit was established?
- Do monitoring practices still align with the level of risk?
- Would the institution approve the same exposure today?
These questions are simple, but they often generate meaningful discussion because they shift the focus from whether a limit exists to whether the limit still reflects reality.
Final Thoughts
Exposure Limits are often viewed as a control. In reality, they are a reflection of a risk decision, and every risk decision has a shelf life.
The strongest institutions are not necessarily the ones with the lowest limits or the most sophisticated monitoring tools. They are the institutions willing to revisit assumptions. They ask whether the number still tells the whole story, whether monitoring still aligns with the activity, and whether the relationship still reflects the risk profile that originally justified the approval.
Nacha’s Risk Management Advisory Group has emphasized that Exposure Limits should be established, monitored, enforced, and periodically reviewed because they help identify changes in customer behavior and emerging risk.
The exposure limit may not have changed. But the risk almost certainly has.
In next week’s article, Your ACH Expert Is Not a Control, the final article in this series, we will turn from a specific control to one of the most human risks in ACH operations: what happens when too much critical knowledge lives with one person.
Unsure Whether Your Exposure Management Practices Still Align With Risk?
Exposure limits are most effective when they evolve alongside customer activity, business growth, and changing risk profiles. Periodic reviews can help identify gaps before they become losses, findings, or operational challenges.
NEACH Payments Group helps financial institutions evaluate ACH exposure management practices, strengthen risk controls, and ensure oversight remains aligned with today’s ACH environment.
Let’s start with a conversation.
Call 781-321-1011 or email info@neachgroup.com.