fbpx

< Back to Thought Leadership

Essential ACH Policies and Controls for Not-for-Profit Organizations

By Karen Dringenburg, CPA, Senior Accountant and Andrew Brock, CPA, Senior Manager at Blue & Co.

Are you a not-for-profit entity considering implementing ACH transactions? Or are you wondering if your current policies and internal controls are sufficient? If so, this guide is for you! Here are key considerations and recommended policies for managing ACH transactions effectively:

  • Establish an Approved Vendor Policy: Create and maintain an approved vendor list that includes verified routing information. Payments should only be made to this verified information, and any changes must be carefully reviewed and authenticated.
  • Review and Approve Transactions: Implement a method for reviewing and approving all ACH and wire transfer transactions. ACH transactions should be scrutinized at least as thoroughly as checks due to their potential risks.
  • Limit Wire Transfers: Adopt a policy to prohibit wire transfers unless absolutely necessary. Wire transfers are costlier and offer same-day guaranteed funds, which makes it more challenging to reverse in cases of fraud.
  • Adhere to Signer Policies: Ensure ACH transactions follow the same approval procedures as check payments, aligning with your existing check signer policy.
  • Consider Positive Pay Services: Positive pay services add another approval step to the process. While banks charge for this service, the added protection often justifies the expense.
  • Segregate Duties: Maintain robust segregation of duties – you do not want someone with sole power to initiate ACH transactions to also have the ability to make entries into books. The individual initiating ACH transactions also should not perform bank reconciliations.
  • Enable Bank Notifications: Set up bank notifications for ACH payment initiations. Ideally, these notifications should go to someone without authority to initiate payments, providing an additional review layer.
  • Stay Current on Cybersecurity Training: Regularly educate employees on cybersecurity to prevent fraud. For instance, ensure staff recognize phishing attempts, such as fake emails from executives requesting urgent payments.
  • Keep Accurate Records: Retain all documentation related to ACH payments, including invoices and approval records, and ensure they are accessible for review.

We hope these items are helpful in your consideration of ACH transactions. If you have any additional questions, we encourage you to reach out to the not-for-profit team here. If any of these items spark questions surrounding your current information technology (IT) environment, you can also contact us about doing an IT assessment of your organization.

Insight: Into How the Rural Health Transformation Program Will Impact Rural Providers

Insight: How the Rural Health Transformation Program Will Impact Rural Providers

On July 4, 2025, President Donald Trump signed into law the “One Big Beautiful Bill Act”, a sweeping budget reconciliation package that includes more than $1 trillion in estimated federal […]

Learn More
From Missed to Maximized: Medicare Bad Debt Crossover Potential Revealed | patient in a mask sitting on an examination table speaking to a doctor in a white coat and mask with a nurse in the background

Medicare Bad Debt Crossover Potential Revealed

Beginning June 7, 2024, Indiana Medicaid launched a transformative new program: PathWays, a managed long-term service and support (MLTSS) initiative designed to streamline care for aging Hoosiers. This program partners […]

Learn More
Upcoming Hospital 340B Program Recertification Window

Upcoming Hospital 340B Program Recertification Window

The Health Resources and Services Administration (HRSA) has set the annual recertification period for the 340B Drug Pricing Program for hospitals to begin on August 11, 2025, and end on […]

Learn More