Skip to main content

SSSD Logo Color 2024 01

ACH Fraud Prevention & Risk Management

Adopted:          9-9-26

Philosophy:   

To protect the District from financial loss, data breaches, and reputational harm by establishing controls over ACH (Automated Clearing House) transactions in compliance with NACHA Operating Rules and sound internal control practices.

Policy:                                    

This policy applies to:

  •       All ACH credits (payroll, vendors, reimbursements)
  •       All ACH debits (tuition, fees, donations, etc.)
  •       All employees involved in initiating, approving, processing, or reconciling ACH transactions
  •        All systems used to store or transmit bank account information

Roles and Responsibilities

Business Administrator – Oversight of the ACH program, policy enforcement, vendor setup, ACH credit initiation, periodic audits and compliance checks

Accounting Director – Employee direct deposit processing

IT Director – Cybersecurity controls & system protection

Core Fraud Prevention Controls

Segregation of Duties

  •         Separate responsibilities for:
    •       ACH file creation
    •        ACH file approval
    •        Bank release
  •      No single employee should control the entire process

Dual Approval (Dual Control)

  •        All ACH transactions must require at least two approvals
  •        Bank portal access must enforce:
    •       Unique login IDs (no shared credentials)
    •        Multi-factor authentication (MFA)

Vendor & Employee Banking Changes

High-risk area for fraud

  •         All new ACH setups or changes must:
    •       Be verified using a known, independent contact method (not via email request alone)
    •       Require documented approval
  •       Use a callback verification procedure
  •       Maintain a change log of all updates

NACHA Account Validation (WEB Debits)

For online payments (if applicable):

  •       Implement commercially reasonable account validation as required by NACHA (effective March 2022):
    •       Prenotification (optional but recommended)
    •       Micro-deposit verification OR
    •       Third-party validation services
  •      Maintain evidence of validation

ACH File Security

  •       ACH files must:
    •       Be stored securely with restricted access
    •       Never be transmitted via unsecured email
  •      Use:
    •       Encrypted channels (SFTP or secure bank portal)
    •       Endpoint protection (anti-malware software)

Payment Limits & Alerts

  •       Establish:
    •        Daily ACH limits
    •        Per-transaction thresholds
  •       Enable bank alerts for:
    •        Unusual activity
    •        New payees
    •        Changes to payment instructions

Reconciliation & Monitoring

  •        Daily review of ACH activity
  •        Monthly reconciliation of:
    •        Payroll ACH
    •        Vendor ACH
  •      Investigate discrepancies immediately

Cyber Fraud Prevention Measures

Email Security

  •       Train staff to recognize:
    •      Phishing emails
    •      Business Email Compromise (BEC)
  •      Never process payment changes from email alone

Access Controls

  •        Limit ACH system access to essential personnel only
  •        Require:
    •       Strong passwords
    •      Multi-factor authentication
    •      Automatic session timeouts

System Updates

  •      Maintain up-to-date:
    •       Operating systems
    •        Accounting software
    •       Antivirus tools

Incident Response Procedures

If fraud or suspected fraud occurs:

  1.       Immediately contact the bank
  2.      Place a hold or reverse transaction if possible
  3.        Notify:
    1.      District leadership
    2.       IT Department
  4.       File reports:
    1.       Law enforcement (if necessary)
    2.       Insurance provider
  5.        Document the incident and corrective actions

Employee Training

  •       Annual training on:
    •       ACH fraud risks
    •       NACHA rules
    •       Cybersecurity awareness
  •        Training required for:
    •        Finance staff
    •       Payroll staff
    •        Anyone with ACH access

Audit & Compliance

  •        Conduct periodic internal reviews of:
    •        ACH processes
    •        User access rights
    •       Vendor change procedures
  •       Maintain documentation for:
    •       NACHA compliance
    •       External audits

Record Retention

  •         Retain ACH authorization records:
    •      Minimum 2 years (NACHA requirement)
  •      Secure storage of sensitive banking data

Policy Review

  •        Review annually or when NACHA rules change
  •        Update procedures as needed to address emerging fraud risks