ACH Fraud Prevention & Risk Management
Adopted: 9-9-26
Philosophy:
To protect the District from financial loss, data breaches, and reputational harm by establishing controls over ACH (Automated Clearing House) transactions in compliance with NACHA Operating Rules and sound internal control practices.
Policy:
This policy applies to:
- All ACH credits (payroll, vendors, reimbursements)
- All ACH debits (tuition, fees, donations, etc.)
- All employees involved in initiating, approving, processing, or reconciling ACH transactions
- All systems used to store or transmit bank account information
Roles and Responsibilities
Business Administrator – Oversight of the ACH program, policy enforcement, vendor setup, ACH credit initiation, periodic audits and compliance checks
Accounting Director – Employee direct deposit processing
IT Director – Cybersecurity controls & system protection
Core Fraud Prevention Controls
Segregation of Duties
- Separate responsibilities for:
- ACH file creation
- ACH file approval
- Bank release
- No single employee should control the entire process
Dual Approval (Dual Control)
- All ACH transactions must require at least two approvals
- Bank portal access must enforce:
- Unique login IDs (no shared credentials)
- Multi-factor authentication (MFA)
Vendor & Employee Banking Changes
High-risk area for fraud
- All new ACH setups or changes must:
- Be verified using a known, independent contact method (not via email request alone)
- Require documented approval
- Use a callback verification procedure
- Maintain a change log of all updates
NACHA Account Validation (WEB Debits)
For online payments (if applicable):
- Implement commercially reasonable account validation as required by NACHA (effective March 2022):
- Prenotification (optional but recommended)
- Micro-deposit verification OR
- Third-party validation services
- Maintain evidence of validation
ACH File Security
- ACH files must:
- Be stored securely with restricted access
- Never be transmitted via unsecured email
- Use:
- Encrypted channels (SFTP or secure bank portal)
- Endpoint protection (anti-malware software)
Payment Limits & Alerts
- Establish:
- Daily ACH limits
- Per-transaction thresholds
- Enable bank alerts for:
- Unusual activity
- New payees
- Changes to payment instructions
Reconciliation & Monitoring
- Daily review of ACH activity
- Monthly reconciliation of:
- Payroll ACH
- Vendor ACH
- Investigate discrepancies immediately
Cyber Fraud Prevention Measures
Email Security
- Train staff to recognize:
- Phishing emails
- Business Email Compromise (BEC)
- Never process payment changes from email alone
Access Controls
- Limit ACH system access to essential personnel only
- Require:
- Strong passwords
- Multi-factor authentication
- Automatic session timeouts
System Updates
- Maintain up-to-date:
- Operating systems
- Accounting software
- Antivirus tools
Incident Response Procedures
If fraud or suspected fraud occurs:
- Immediately contact the bank
- Place a hold or reverse transaction if possible
- Notify:
- District leadership
- IT Department
- File reports:
- Law enforcement (if necessary)
- Insurance provider
- Document the incident and corrective actions
Employee Training
- Annual training on:
- ACH fraud risks
- NACHA rules
- Cybersecurity awareness
- Training required for:
- Finance staff
- Payroll staff
- Anyone with ACH access
Audit & Compliance
- Conduct periodic internal reviews of:
- ACH processes
- User access rights
- Vendor change procedures
- Maintain documentation for:
- NACHA compliance
- External audits
Record Retention
- Retain ACH authorization records:
- Minimum 2 years (NACHA requirement)
- Secure storage of sensitive banking data
Policy Review
- Review annually or when NACHA rules change
- Update procedures as needed to address emerging fraud risks
