Nacha Operating Rules Update

Slides:



Advertisements
Similar presentations
Scan Checks Remotely Electronically Deposit and Clear YOU GET YOUR MONEY FASTER Your Location Bank.
Advertisements

Red Flags Rule BAS Forum August 18, What is the Red Flags Rule? Requires implementation of a written Identity Theft Prevention Program designed.
Detecting, Preventing and Mitigating Identity Theft Presented by the Bursar’s Office.
1 Exception Processing New Directions UMACHA August 14, :00 – 2:30 PM, CT.
© 2014 NACHA — The Electronic Payments Association. All rights reserved. No part of this material may be used without the prior written permission of NACHA.
Understanding SEC Codes: From ARC to XCK
Copyright © 2005 Secure Payment Systems, Inc. All Rights Reserved. Electronic Check Processing and Deposit Web-Based Accounts Receivable Conversion (ARC)
LEADERSHIP + INNOVATION 2013 OLA Conference |October |San Diego Get Educated on the NACHA Rules Marsha Jones, AAP, NCP, Director, TPPPA Lin Fellerman,
Check 21 and Image Exchange
The Advisers Act Custody Rule
Investment Association
OLA {DRAFT} BEST PRACTICES Revised 6/25/2013. Payments Landscape Update Ever increasing scrutiny and pressure from every agency OCC (J LaRoche, May, 2013)
Protect Yourself from Your Customer Kristin A. Stedman, AAP Senior Vice President Education Services 1 © 2014 TACHA. All Rights Reserved.
Four tips to keep ACH fraud in the past. 2 ACH Fraud Prevention Steps Businesses Can Take to Minimize Fraud Risk 1 1 b b c c d d e e f f g g a a Monitor.
1 Exemption AdministrationTraining Related to Accepting Certificates Prepared by the Streamlined Sales Tax Governing Board Audit Committee Prepared January.
Check 21 Changing How Banking is Done Today Presented by: Kimberly Feeney, Vice President Government Treasury Services Bank of America
Payments 101 Terms and Acronyms October 17, 2007.
Discussion agenda Volume trends Recent developments
2015 ANNUAL TRAINING By: Denise Goff
Secure Electronic Transaction (SET)
1 September 18, 2009 NACHA Rule Change International ACH Transactions (IAT) Transactions Involving a Foreign Financial Institution or Foreign Agency.
HIPAA PRIVACY AND SECURITY AWARENESS.
FTC RED FLAG RULE As many as nine million Americans have their identities stolen each year. Identity thieves may drain their accounts, damage their credit,
E-commerce Vocabulary Terms. E-commerce Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the Internet.
E-commerce Vocabulary Terms By: Laura Kinchen. Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the.
Traditional and Electronic Payment Methods Chapter 3.
Payments 101 Billie Higgins Kay Limbaugh. Central Banking system Created in 1913 Private banking system composed of Board of Governors appointed by the.
© 2015, EPCOR®. All Rights Reserved Northern Ohio AFP Conference ACH Rules Update September 21, 2015 Cleveland, Ohio.
New Identity Theft Rules Rodney J. Petersen, J.D. Government Relations Officer Security Task Force Coordinator EDUCAUSE.
© 2009 EPCOR. All Rights Reserved The Risks and Rewards of Remote Deposit Services 2009 Treasury Management Conference September 10, 2009 Omaha, Nebraska.
Amanda Johnson Utility Payment Conference September 19, 2011.
United States payments update Howard N. Forman, AAP Senior Vice President Electronic Payments Consultant © 2011 Wells Fargo Bank, N.A. All rights reserved.
Checking & Savings Accounts Economics What is a Checking Account?  Common financial service used by many consumers (a place to keep money)  Funds.
ACH Returns and Reversals. KeyCorp Classification Public What is ACH?  Automated Clearing House (ACH) is a funds transfer system governed by the rules.
Kim Folks, Tampa Electric Amanda Johnson, Utility Payment Conference Utility Payment Conference October 19, 2010.
Contract Compliance Training
ACH 101 Perspectives from a Processor and a Merchant
After the FCC Form 471 E-rate Program Applicant Training
ACH Basics for Businesses
BY GAWARE S.R. DEPT.OF COMP.SCI
Contract Compliance Training
Checking Account & Debit Card Simulation
Same Day ACH: How It Can Work for You
Depository Institution Essentials
Remittances Under UCC Article 4A: Unintended Consequences
7 Sarbanes-Oxley, Internal Control, and Cash
7 Sarbanes-Oxley, Internal Control, and Cash
Red Flags Rule An Introduction County College of Morris
Payments 101 Billie Higgins Kay Limbaugh.
Depository Institution Essentials
Current Privacy Issues That May Affect Your Credit Union
RECORDS AND INFORMATION
Same Day ACH; (And a Little on Faster Payments in General)
Regulation E vs. ACH Rules: Working Out Disputes Effectively
Identity Theft Prevention Program Training
Depository Institution Essentials
Reconciliation Copyright © Texas Education Agency, All rights reserved.
Electronic Services from a School's Perspective PESC Annual Conference on Standards in Higher Education Judith Nemerovski Flink Director of Student Financial.
2015 ACH Rule Changes for Greater Milwaukee APA
Same Day ACH Corporate Considerations and Opportunities
Colorado “Protections For Consumer Data Privacy” Law
DFI to DFI Messaging Concepts
Exemption AdministrationTraining Related to Accepting Certificates
Getting the Green Light on the Red Flags Rule
The ACH Network and the Future of Payments
AAP Trainer Module I ACH Primer
Distributed Digital Rights Management
Presentation transcript:

Nacha Operating Rules Update September 2019 Utility Payments Conference Danita T. Tyrrell AAP, APRP Director, ACH Network Rules

The Nacha Operating Rules Establish the legal foundation for the ACH Network Provides a common set of rules and formats Creates certainty and interoperability Defines roles and responsibilities for Network users

What is an Authorization? “An Originator must obtain authorization from the Receiver to originate one or more entries to the Receiver’s account.” 2019 Nacha Operating Rules, Article Two, Subsection 2.3.1

Consumer Authorizations Readily identifiable Have clear and readily understandable terms Provide that the Receiver may revoke only by notifying the Originator in the manner specified Originator must provide a copy Can be for a single entry or for a stream of recurring entries

Types of Consumer Authorizations Written Notice Oral Similarly Authenticated

Non-Consumer Authorizations Originator and Receiver must have an agreement that binds the Receiver to the Rules No specific agreement format Agreement should contain authorization for ACH transactions, as sell as any specific terms and conditions

Obligations of Originators Obtain proper authorization Retain authorization for the correct retention period Ensure transaction information is correct Provide proof of authorization when requested by ODFI

Standard Entry Class (SEC) Codes Three-letter acronym to identify the ACH transaction type Distinguishes key aspects surrounding the initiation of the ACH payment Indicates that certain provisions of the Nacha Operating Rules, risk management practices, and/or legal requirements apply to the transaction

SEC Codes for B2C Transactions PPD: Pre-arranged Payment or Deposit Entry Debit Credit TEL: Telephone Initiated Entry Debit only WEB: Internet/Mobile Initiated Entry Debit only for B2C

SEC Code for C2B Transactions CIE: Customer Initiated Entry Credit only

SEC Codes for B2B Transactions CCD: Corporate Credit or Debit Entry Credit Debit CTX: Corporate Trade Exchange Entry

SEC Code for P2P Transactions WEB: Internet/Mobile Initiated Entry Credit only

Hybrid SEC Codes Can be initiated to consumer or business accounts Are related to check conversion or check truncation ARC: Account Receivable Entry BOC: Back Office Conversion Entry POP: Point of Purchase Entry RCK: Re-presented Check Entry

What about Virtual Assistants? Payments can be initiated via Virtual Assistant Mainly B2C debits Voice instruction for payment Which SEC Code should Originators use?

Does TEL Fit? Currently used for voice based authorizations Phone representative VRU TEL definition: A debit entry initiated by an Originator to a Consumer Account of the Receiver based on an oral authorization obtained over the telephone TEL does not fit No telephone involved

Does WEB Fit? WEB definition: A debit entry initiated by an Originator to a Consumer Account of the Receiver based on An authorization that is communicated, other than by oral communication, from the Receiver to the Originator via the Internet or a Wireless Network Any form of authorization if the Receiver’s instruction for the initiation of the individual debit entry is designed by the Originator to be communicated, other than by an oral communication, to the Originator via a Wireless Network; or A credit entry initiated by or on behalf of the holder of a Consumer Account that is intended for the Consumer Account of a Receiver, regardless of whether the authorization of such entry is communicated vie the Internet or Wireless network obtained over the telephone

Does WEB Fit? WEB includes debit entries authorized under any form of authorization when the origination instruction is provided to the Originator, other than by oral communication, over a wireless network. Device is not being used as a telephone to initiate the payment Instruction is over the internet or wireless network WEB fits!

New and Upcoming Rules Same Day ACH Quality and Risk June 21, 2019 R17 for Questionable Transaction Sept 20, 2019 Faster funds availability March 20, 2020 Dollar limit increase April 1, 2020 Differentiating Unauthorized Return Reasons – New R11 becomes effective June 30, 2020 Account Information Security Requirements (annual ACH volume greater than 6 million) March 19, 2021 Same Day ACH Third Window Commercially Reasonable Fraud Detection for WEB debits April 1, 2021 Differentiating Unauthorized Return Reasons – R11 covered by Unauthorized Entry Fee June 30, 2021   Account Information Security Requirements (annual ACH volume greater than 2 million)

R17 Return for Questionable Transaction RDFIs will be allowed to use Return Reason Code R17 to return an entry that does not have a valid account number and indicate that the RDFI believes the entry was initiated under questionable circumstances RDFIs using R17 for this purpose will use the description “QUESTIONABLE” in the Addenda Information field of the return An R17 in conjunction with this description will allow these returns to be distinguished from returns for routine account number errors Originators that receive R17 returns should work with their ODFI to explore the reasons the RDFI believed the original entry was problematic beyond an invalid account number Effective Date: June 21, 2019

Commercially Reasonable Fraud Detection for WEB Debits ACH Originators of WEB debit entries are required to use a “commercially reasonable fraudulent transaction detections system” to screen WEB debits for fraud Originators are closest to the Receiver so Originators are in the best position to detect and prevent fraud related to payments they are initiating Some Originators do not have or use any such system to screen WEB debits

Commercially Reasonable Fraud Detection for WEB Debits Originators for WEB debit entries will be required to supplement a “commercially reasonable fraudulent transaction detection system” with account validation Rule applies on a “going-forward” basis to new account numbers obtained for initiating WEB debits Does not apply retroactively to account numbers that have already been used for WEB debits Effective Date extended to allow for additional time, education and guidance to the industry Effective Date: March 19, 2021

Commercially Reasonable Fraud Detection for WEB Debits How can Originators prepare for this new requirement? Examine current process: is it sufficient or are enhancements required? Free Nacha webinars Five Preferred Partners review their account validation offerings Recordings available to anyone via Nacha website Additional Nacha guidance on ways to comply with the Rule

Differentiating Unauthorized Return Reasons Return Reason Code R11 will be re-purposed to be used for a debit in which there is an error, but for which there is an authorization “Customer Advised Entry Not in Accordance with the Terms of the Authorization” 60 day extended return time frame in effect No new authorization required if Originator corrects the error Return Reason Code R10 will continue to be used whey a consumer claims to not know the Originator, does not have a relationship with the Originator, or did not give authorization “Customer Advises Originator is Not Known to Receiver and/or is Not Authorized by Receiver to Debit Receiver’s Account Effective Date: April 1, 2020

Account Information Security Requirements Rule will require large non-financial institution Originators, Third-Party Service Providers and Third-Party Senders to protect account numbers used for ACH entries by rendering them unreadable when stored electronically Aligns with existing language contained in PCI requirements Neutral as to methods/technology: encryption, truncation tokenization, destruction, date stored/hosted/tokenized by ODFI, etc. Does not apply to the storage of paper authorizations

Account Information Security Requirements Rule will implement in two phases, beginning with the largest Originators, Third- Party Service Providers and Third-Party Senders Those entities with total ACH volume of 6 million transactions annually or greater in 2019 will need to be compliant by June 30, 2020 Those entities with total ACH volume of 2 million transactions annually or greater in 2020 will need to be compliant by June 30, 2021

QUESTIONS? THANK YOU! Danita Tyrrell, AAP, APRP Director, ACH Network Rules dtyrrell@nacha.org THANK YOU!