Glossary
The vocabulary of ACH assurance.
Terms that appear in Nacha audits and in Eviqly deliverables, defined plainly.
- ACH
- Automated Clearing House — the U.S. electronic network for batch-processed credit and debit transfers, governed by the Nacha Operating Rules.
- AAP
- Accredited ACH Professional. A Nacha-administered credential recognizing expertise in ACH rules, risk, and operations. Eviqly reports are reviewed and signed by U.S.-based AAPs.
- Nacha Operating Rules
- The rules that govern participation in the ACH network, including the requirement for participating DFIs, Third-Party Senders, and Third-Party Service Providers to conduct an annual compliance audit.
- Originator
- A company or individual that initiates ACH entries under an agreement with an ODFI.
- ODFI
- Originating Depository Financial Institution — the bank that receives entries from Originators and introduces them into the ACH network.
- RDFI
- Receiving Depository Financial Institution — the bank that receives entries and posts them to its account holders.
- Third-Party Sender (TPS)
- An entity that originates entries on behalf of its own customers through an ODFI, taking on additional due diligence, registration, and oversight obligations.
- Third-Party Service Provider (TPSP)
- An entity that performs ACH processing functions on behalf of an Originator, TPS, or DFI.
- SEC code
- Standard Entry Class code — a three-letter code identifying the type of ACH entry (for example PPD, CCD, WEB, TEL, IAT), each with its own authorization and handling requirements.
- WEB
- An SEC code for consumer debits authorized over the internet or a mobile device; subject to account validation requirements for first-use accounts.
- Return rate
- The proportion of originated entries returned, monitored against Nacha thresholds for unauthorized, administrative, and overall returns.
- Exposure limit
- The maximum ACH origination volume or value an ODFI allows an Originator or TPS, subject to periodic review.
- Punch list
- In Eviqly’s workflow, the list of unsupported requirements (gaps), each assigned to an internal owner for resolution.
- Pull date
- The date on which Eviqly read a piece of evidence from a system or received it as an upload; recorded with every source.
- Completion statement
- The signed statement closing an engagement, naming the participant type, SEC codes, period reviewed, and the accredited reviewer.
- Immutable trail
- Eviqly’s append-only record of who drafted, confirmed, closed, and signed each item, and when.
- SOC 2 Type I
- An independent examination of a service organization’s controls relevant to security at a point in time, based on the AICPA Trust Services Criteria.
Need a term mapped to your program?
We’ll tell you which requirements apply to your participant type and SEC codes.