In Five Signs Your ACH Origination Program May Have Outgrown Its Controls, we looked at several warning signs that an ACH program may have evolved beyond the controls originally designed to support it. One of those signs deserves a closer look: the ACH risk assessment that does not drive action.
That matters because some of the most meaningful ACH risks I have seen were identified not through audit findings, but through questions asked during a risk assessment.
One of the most interesting things I have learned after years of ACH audits, risk assessments, and advisory engagements is that some of the highest-risk observations occur at institutions with no audit findings. Nothing is technically wrong. The Rules are being followed. Staff are doing their jobs. The institution is compliant.
Yet meaningful risks still exist.
That is because compliance and risk are not the same thing. An ACH audit asks whether the institution is following the Rules. An ACH risk assessment asks what risks exist that the institution may not be seeing. In my experience, that is where some of the most valuable conversations begin.
Some of the most significant ACH risks do not appear as audit findings. They appear as assumptions. Increasingly, those assumptions involve third-party relationships, fraud-monitoring responsibilities, and ownership of risk across an expanding ecosystem of service providers, fintech partners, processors, and vendors. Regulators continue to emphasize that outsourcing a function does not outsource responsibility for managing the associated risks. FDIC ACH Core guidance states that ODFIs are responsible for ACH payment activity initiated by their customers, including nested relationships, and OCC guidance addresses risks associated with third-party senders and service providers.
“We Didn’t Realize We Owned That Risk”
One of the most eye-opening moments during a risk assessment often begins when we map the transaction flow. A financial institution may offer ACH Origination through a digital banking platform, treasury management system, fintech relationship, payroll service, or third-party solution. Everyone understands how the service works operationally.
Then the questions begin. Who reviews unusual activity? Who evaluates exposure? Who monitors the relationship? Who escalates concerns? Who owns the risk?
Sometimes there is a pause. Not because anyone has done anything wrong, but because everyone assumed someone else was handling part of the process.
In one conversation, it became apparent that the institution assumed they were not the ODFI for certain transactions being originated, and that the Vendor was using a different ODFI. After much discussion and review of files, it was determined the Institution was the ODFI, which led to a great conversation on risk, monitoring, and responsibility. Nothing had gone wrong, and no loss had occurred, but the discussion revealed something important: ownership had never been clearly defined.
This is especially important in ACH environments that rely on third-party providers, payment processors, or fintech partners. One of the consistent themes in both regulatory guidance and risk assessments is that institutions remain responsible for understanding and managing the risks associated with activities performed on their behalf.
You cannot effectively manage a risk you do not realize you own.
“Wait, Are They a Third-Party Sender?”
This is another conversation that happens more often than people realize. When most people think of a Third-Party Sender, they picture a payroll company. Those relationships are usually obvious. Other relationships are not always as clear.
During risk assessments, we sometimes discover that a relationship creates Third-Party Sender considerations, but it has never been evaluated through that lens. The issue is not always that someone ignored a requirement. Often, the relationship simply was not assessed properly in the first place.
If a relationship is categorized incorrectly, onboarding, monitoring, contractual requirements, reporting obligations, and risk controls may not fully align with the activity being performed. Often, the issue is not compliance. It is awareness.
And awareness is exactly what a risk assessment is designed to create.
“Our Policy Says That?”
This is one of my favorite moments because it usually leads to a productive discussion. I may be reviewing procedures with staff when someone says, “We don’t actually do it that way anymore.” Almost immediately, someone else responds, “Wait, that’s what the procedure says?”
What follows is usually an acknowledgment that the ACH program evolved. Maybe new products were introduced. Maybe onboarding practices changed. Maybe fraud-monitoring tools were added. Maybe commercial services expanded. The program improved, but the documentation did not keep pace.
Staff may be performing the process correctly. The gap is not always operational. The gap is between how the institution believes the process works and how it actually works today.
An audit may never identify that as a Rules violation. A risk assessment almost certainly identifies it as an opportunity to strengthen the program.
The Originator That Has Not Been Reviewed in Years
Another common discovery involves long-standing commercial relationships. An Originator was onboarded years ago. Due diligence was completed. Exposure limits were established. Controls were implemented. Everything was appropriate at the time.
Fast forward several years. The customer has grown. Transaction volumes have increased. The business model may have changed. The customer may now Originate different types of transactions or substantially larger files.
Nothing is technically wrong. Returns remain acceptable. No audit findings exist. But the risk assessment asks a different question: would the institution make the same risk decision today that it made five years ago?
Sometimes the answer is yes. Sometimes that question starts an important conversation.
Final Thoughts
The most valuable risk assessments are not necessarily the ones that identify the most findings. They are the ones that help an institution see its ACH program differently than it did before.
The most valuable observations often come from questions no one has asked in a while — questions about growth, ownership, exposure, documentation, reporting, and whether the program people think they are operating is actually the program they operate today.
Sometimes the greatest ACH risk is not what you are doing wrong. It is what you have stopped noticing.
In next week’s article, The Exposure Limit Was Approved. The Risk Changed., we will look closely at one area where those assumptions show up often: ACH exposure limits.
Not Sure What You Might Be Missing?
Some of the most significant ACH risks do not appear in audit reports. They develop quietly through growth, operational changes, evolving fraud threats, and outdated assumptions about how the program works.
NEACH Payments Group helps financial institutions evaluate ACH risk from a broader perspective — identifying gaps, challenging assumptions, and providing practical recommendations that strengthen long-term risk management.
Let’s start with a conversation.
Call 781-321-1011 or email info@neachgroup.com.