Bradley · ACH

Tab 1 · Annual Audit · 2025 Workbook

2025 ACH Audit Workbook

Bradley Company's proposed 2025 audit package. Responses have been carried forward from 2024, updated for the current control environment, cross-linked to their supporting policy, and mapped to each Required Update in Lake City Bank's 2025 Audit Review letter.

111/111 responses finalized
Rows highlighted in gold indicate a material change from the 2024 baseline.
Lake City Bank · 2025 ACH Audit Review letter
2025 responses below directly address each Required Update and Recommendation in the Lake City Bank audit review letter (covering Jan 2024 – May 2025). Reviewer Comments cite the specific finding — LCB RU# for Required Updates and LCB R# for Recommendations.
IDAudit QuestionPrior Year ResponseCurrent Response (2025)StatusSupporting DocumentationComments
PAQ-01
Pre-Audit · TPS & ODFI InformationUpdated
Third-Party Sender name, DBA(s), city, state, tax ID, and ODFI(s) with ABA/routing numbers and start date.
Left blank in the completed 2024 workbook.
Bradley Company, LLC — South Bend, IN. ODFI: Lake City Bank, ABA 074908594. ACH origination relationship active since 2018.
Compliant – Enhanced
Cover-page identifying data completed for the 2025 workpapers.
PAQ-02
Pre-Audit · TPS & ODFI InformationUpdated
What ACH services are available (Payroll, Bill Payment, Payment Collection, Debt Collection, Check Conversion, Taxes, Other)?
No service boxes checked in the 2024 workbook.
Payment Collection (tenant/owner rent, association dues), Payroll/Payroll taxes for managed entities, and Owner Distributions (see §17 SOP). Debt Collection, Check Conversion, and Taxes: N/A.
Compliant – Enhanced
Completes the services inventory that was blank in 2024.
PAQ-03
Pre-Audit · TPS & ODFI InformationUpdated
Primary ACH contacts: Chief Risk Officer, Operations Manager (inbound / outbound / returns / additional staff), IT / Information Security, Audit, Due Diligence / Credit Underwriting.
Left blank in the 2024 workbook.
Roles and named contacts populated in the ACH Contacts Matrix (Roles & Responsibilities section of the Policy Manual) and reviewed annually.
Compliant – Enhanced
Remediates blank staffing inventory.
PAQ-04
Pre-Audit · Staffing & TrainingUpdated
Is there an Accredited ACH Professional (AAP) on staff? If yes, name.
Left blank (radio not selected, name not provided).
No AAP on staff. External AAP support engaged through Lake City Bank's ACH Department for interpretive questions; certification is on the 2025 professional development plan.
Compliant
Response provided rather than left blank.
PAQ-05
Pre-Audit · Staffing & Training
Is there an Accredited Payments Risk Professional (APRP) on staff? If yes, name.
No.
No APRP on staff. Risk oversight is provided by the ACH Compliance Officer using the 2025 ACH Risk Assessment and Risk Management Program; APRP path added to the 2025 professional development plan.
Compliant
PAQ-06
Pre-Audit · Staffing & TrainingUpdated
Do staff attend or perform ACH training and in what form?
NA / NA.
Yes — annual mandatory ACH compliance training for all ACH-adjacent staff (Accounting, IT, Audit) delivered via the Lake City Bank ACH training modules and internal policy walkthrough. Completion tracked on the Annual ACH Compliance Calendar.
Compliant – Enhanced
PAQ-07
Pre-Audit · Staffing & Training
Is ACH activity balanced daily?
Yes.
Yes — retained.
Compliant
PAQ-08
Pre-Audit · Staffing & TrainingUpdated
Is the balancing activity reviewed by another staff member?
No.
Yes — the Finance Controller performs an independent same-day review of the ACH balancing worksheet; the reviewer initials and dates the worksheet, which is retained per record-retention policy.
Compliant – Enhanced
Independent review added to remediate 2024 SOD gap.
PAQ-09
Pre-Audit · Staffing & TrainingUpdated
Is the current year of the Nacha Operating Rules & Guidelines available to staff?
No.
Yes — current-year Nacha Operating Rules & Guidelines subscription maintained by the ACH Compliance Officer and available to all ACH staff via the shared compliance library.
Compliant
PAQ-10
Pre-Audit · Prior Year's AuditUpdated
Date of last ACH audit; outstanding issues addressed; audit information reported to management; proof of completion provided to ODFI.
Date: blank. Outstanding issues: NA. Reporting to management: NA. Proof of completion to ODFI: NA.
Last audit: 2024 (Bradley Company's first documented ACH compliance audit — see Change Log). All 2024 exceptions are being remediated through the tracked action items in the Change Log. Audit results reported to executive management and retained in the Executive Binder. Proof of completion of the 2025 audit will be provided to Lake City Bank within NACHA's 10-banking-day window.
Compliant – Enhanced
First-year continuity baseline.
PAQ-11
Pre-Audit · ACH Risk AssessmentLCB RU-3 · Discovery 3Updated
Has an ACH-specific risk assessment been conducted? What weaknesses were identified and how were they addressed in the risk management program?
No — ACH-specific risk assessment had not been conducted; corresponding NA response.
Yes — 2025 ACH Risk Assessment completed with likelihood, impact, and residual-risk scoring across origination, security, third-party, and operational domains. Weaknesses identified feed the ACH Risk Management Program remediation calendar and the Change Log.
Compliant – Enhanced
Addresses LCB Discovery 3 / RU-3 (implement ACH Risk Management Program under Art. 1 §1.2.4).
PAQ-12
Pre-Audit · Origination InformationLCB R-8 · Discovery 8Updated
How many Originators are services provided to? How many Nested Third-Party Senders?
Not sure / Not sure.
Originator inventory maintained by the ACH Compliance Officer and reviewed quarterly (see Originator Due Diligence Policy). No Nested Third-Party Senders — Bradley Company originates only for its own managed entities.
Compliant – Enhanced
Addresses LCB Discovery 8 / R-8 (verify Originator counts).
PAQ-13
Pre-Audit · Origination InformationLCB R-8 · Discovery 8Updated
What SEC codes are approved for origination? (PPD credit/debit, CCD credit/debit, CTX, WEB, TEL, ARC, POP, BOC, RCK, IAT, Same-Day credits/debits)
No boxes checked in the 2024 workbook.
Approved SEC codes: PPD (credit and debit — payroll and tenant/owner ACH), CCD (credit and debit — corporate and owner distributions), TEL (limited legacy use — see TEL controls). WEB, ARC, POP, BOC, RCK, IAT, and Micro-Entries: not currently used. Same-Day ACH: not currently used.
Compliant – Enhanced
Addresses LCB Discovery 8 / R-8 (confirm SEC codes accepted).
PAQ-14
Pre-Audit · Origination InformationUpdated
What due diligence is performed for new Originators and Nested Third-Party Senders? Are there written procedures for periodic reviews of existing Originators?
Not sure. Written procedures for periodic reviews: No.
Onboarding follows the Originator Due Diligence Policy: legal-name / TIN / address verification, OFAC screen, secretary-of-state confirmation, credit/exposure review, and documented approval before first origination. Annual periodic review documented and retained in the Originator file.
Compliant – Enhanced
PAQ-15
Pre-Audit · Origination InformationLCB R-10 · Discovery 10Updated
Does the TPS monitor ACH files for specific SEC codes and exposure limits (per File / day / Effective Date / Batch / Entry)?
No monitoring boxes checked.
Yes — outgoing files reviewed for use of approved SEC codes (see Outbound SEC Code Monitoring Procedure §21, in development). Exposure limits enforced per Originator and per day using the Exposure Limit Methodology.
Compliant – Enhanced
Addresses LCB Discovery 10 / R-10 (monitor outbound data for proper SEC codes) and Discovery 5 / RU-5 (exposure limits — see Article Two Risk Management rows).
PAQ-16
Pre-Audit · Inbound ACH DataUpdated
How does the TPS receive ACH data from Originators? Who is responsible for creating the NACHA-formatted ACH file? What cutoff times are established?
Left blank / no boxes checked.
Inbound data from Originators arrives via a secure/password-protected web-based portal or SFTP; verbal, paper, and unsecured email intake are prohibited. Bradley Company enters instructions; Lake City Bank generates the NACHA-formatted ACH file. Originator cutoff: 2:00 p.m. ET for same-cycle processing.
Compliant – Enhanced
Internal control enhancement — not tied to a specific LCB Discovery / RU.
PAQ-17
Pre-Audit · Outbound ACH Files
How are outbound ACH Files delivered to the ODFI(s)? Who is responsible for transmission?
SFTP checked. Responsible area: Accounting.
Retained — outbound files delivered to Lake City Bank via SFTP; transmission owned by Accounting under the Segregation of Duties matrix.
Compliant
PAQ-18
Pre-Audit · FundingUpdated
Funding methods used; do you require credit files to be prefunded; do you verify receipt of funds before file delivery to the ODFI?
ACH funding, submitted electronically. Prefunded: Yes. Verify receipt of funds before delivery: No.
ACH funding retained. Credit files remain prefunded. Verification of receipt of funds is now performed and documented on the daily origination worksheet prior to release of the file to Lake City Bank.
Compliant – Enhanced
Remediates 2024 exception on funds-receipt verification.
PAQ-19
Pre-Audit · Rejects/Returns/NOCUpdated
Area responsible for Rejects/Returns/NOC Entries.
Lake City and accounting.
Lake City Bank ACH Department (as ODFI) and Bradley Company Accounting jointly, with the ACH Compliance Officer responsible for tracking, aging, and Originator notification.
Compliant – Enhanced
Ownership clarified.
PAQ-20
Pre-Audit · Rejects/Returns/NOCLCB RU-1 · Discovery 1Updated
How are Originators notified of Rejects/Returns/NOCs? (Phone, secure email, paper/fax/mail, online reporting)
Email — Secure/password protected: No.
Originators are notified through the secure/password-protected portal or encrypted email (S/MIME or TLS-enforced). Unsecured email notification is prohibited under the new Secure Transmission of NOCs & Return Notifications policy (Policy Manual §19).
Compliant – Enhanced
Addresses LCB Discovery 1 / RU-1 (Art. 1 §1.7 — no NOC/Return notifications via unsecured electronic network).
PAQ-21
Pre-Audit · Rejects/Returns/NOC
Does the TPS have a contact person for each Originator regarding Rejects/Returns/NOCs?
Yes.
Yes — retained. Originator contact roster maintained by the ACH Compliance Officer and refreshed at annual periodic review.
Compliant
PAQ-22
Pre-Audit · Rejects/Returns/NOCUpdated
Does the TPS monitor and track each Originator's Rejects/Returns/NOC activities?
No.
Yes — tracked in the ACH Operations log by Originator with monthly return-rate reporting against NACHA thresholds (Unauthorized 0.5%, Administrative 3.0%, Overall 15.0%).
Compliant – Enhanced
PAQ-23
Pre-Audit · Rejects/Returns/NOCUpdated
Do you reinitiate debit Return Entries for NSF or Uncollected items? If yes, do you use 'RETRY PYMT' in the Entry Description Field?
Reinitiate: No. 'RETRY PYMT': not answered.
Yes — Reinitiation SOP permits reinitiation for NSF/Uncollected, separately authorized stopped payment, or corrected reason only; separate batch with 'RETRY PYMT' in the Company Entry Description Field is mandatory; within 180 days of original Settlement; maximum of two reinitiations per original Entry.
Compliant – Enhanced
Documents reinitiation control under NACHA Art. 2 §2.13.4.1 and §2.13.4.2 — internal remediation, not an LCB Discovery / RU.
PAQ-24
Pre-Audit · Rejects/Returns/NOC
Do you have procedures to promptly provide copies of Proof of Authorizations to the ODFI(s) when requested?
Yes.
Yes — retained. Formal 10-banking-day production procedure documented (see Record of Authorization row).
Compliant
PAQ-25
Pre-Audit · Rejects/Returns/NOC
Do you initiate Micro-Entries?
No.
No — retained. Micro-Entries are not initiated by Bradley Company. If future adoption is contemplated, controls in Art. 2 §2.7 will be implemented before use.
Not Applicable
PAQ-26
Pre-Audit · ACH Data SecurityLCB RU-2 · Discovery 2Updated
How do you protect sensitive ACH data (in transit and at rest)?
Passwords.
TLS 1.2+ for all ACH data in transit (SFTP, portal, encrypted email). AES-256 for data at rest within Bradley Company systems. Documented in the Data Security section of the ACH Policy Manual and validated by IT self-assessment.
Compliant – Enhanced
Addresses LCB Discovery 2 / RU-2 (Data Security / IT Requirements component of consolidated ACH Management Policy §18).
PAQ-27
Pre-Audit · ACH Data SecurityUpdated
How do you control access to ACH data?
Email.
Role-based access controls enforced through IT identity management; least-privilege model; access reviewed at least annually and upon role change or termination.
Compliant – Enhanced
'Email' was not a valid access control; replaced with documented RBAC.
PAQ-28
Pre-Audit · ACH Data SecurityUpdated
How do you destroy ACH data?
Not sure.
Electronic destruction via secure wipe or cryptographic erase per IT destruction schedule; physical media (paper/portable) cross-cut shredded by contracted vendor with certificate of destruction.
Compliant – Enhanced
PAQ-29
Pre-Audit · ACH Data SecurityUpdated
When was the last self-assessment conducted for data security policies, procedures and systems?
Not sure.
2025 — annual self-assessment performed by IT and documented in the Executive Binder; next assessment scheduled on the Annual ACH Compliance Calendar.
Compliant – Enhanced
PAQ-30
Pre-Audit · ACH Data SecurityUpdated
Do you utilize a commercially reasonable fraud detection system? If yes, describe.
Yes — 'Part of cybersecurity procedures.'
Yes — endpoint detection, email threat protection (phishing/BEC), MFA on all ACH-adjacent systems, positive-pay style balance verification on outbound files, and the owner-distribution verbal-verification control (see §17 SOP).
Compliant – Enhanced
Description expanded from the generic 2024 answer.
A1-01
Article One · ACH Risk Management ProgramLCB RU-2 · Discovery 2Updated
Which ACH-related policies are approved? (ACH Management, OFAC, BSA/AML, TPS Business Continuity, ACH Risk Management, TPS Audit, TPS Underwriting)
No policy boxes checked in the 2024 workbook.
All seven policies exist and are approved: ACH Management (Policy Manual §18, consolidated, in development for Q2 2025), OFAC, BSA/AML, TPS Business Continuity, ACH Risk Management, TPS Audit, TPS Underwriting.
Compliant – Enhanced
Addresses LCB Discovery 2 / RU-2 (consolidated ACH Management Policy) and Discovery 3 / RU-3 (Risk Management Program).
A1-02
Article One · ACH Risk Management ProgramLCB RU-2 · Discovery 2Updated
Does the ACH Management Policy at minimum address: Types of Entries Accepted, Data Security/IT Requirements, ACH Risk Management, Receipt of Entries and Exception Handling (including Federal Government payments), and ACH origination activities?
No boxes checked — none of the five minimum-content areas were confirmed.
Yes — the consolidated ACH Management Policy (§18) explicitly addresses all five required areas. Verbatim mapping is included as an appendix to the Policy Manual.
Compliant – Enhanced
Directly addresses LCB Discovery 2 / RU-2 minimum-content list.
A1-03
Article One · ACH Risk Management ProgramLCB R-9 · Discovery 9Updated
How often are ACH-related policies reviewed by the Board of Directors or a Senior Level Committee?
'Not often and only indirectly.'
Annually. The Annual ACH Policy Review Procedure (Policy Manual §20) codifies the review cadence, evidence retention, and executive sign-off requirement.
Compliant – Enhanced
Addresses LCB Discovery 9 / R-9 (annual review of ACH-related policies).
A1-04
governanceUpdated
Are there documented ACH processing procedures that support the ACH policies?
Yes.
Yes — retained and expanded: Owner Distribution SOP, Reinitiation SOP, Reversals SOP, Secure Transmission of NOCs & Return Notifications SOP, Outbound SEC Code Monitoring Procedure.
Compliant – Enhanced
A1-05
Article One · Proof of Completion of AuditUpdated
Does documentation exist supporting completion of an audit for each of the past six years (2018–2023)?
No years checked — 'No audit has been done.'
2024 is the baseline year. The 2024 workbook, this 2025 workbook, and all supporting artifacts are retained in the Executive Binder for the six-year rolling window; the retention log is on the Annual ACH Compliance Calendar.
Compliant – Enhanced
First-year continuity baseline.
A1-06
Article One · Proof of Completion of AuditUpdated
If requested by the ODFI, can proof of completion of the audit be provided timely?
No.
Yes — the 2025 audit package is retained in the Executive Binder and can be produced to Lake City Bank within the 10-banking-day NACHA window.
Compliant
A1-07
Article One · Proof of Completion of AuditUpdated
If requested by the ODFI, can proof of completion of any Nested Third-Party Senders' audit be provided timely?
No.
N/A — Bradley Company does not have any Nested Third-Party Senders.
Not Applicable
A1-08
Article One · Proof of Completion of AuditUpdated
Have all prior-year findings been addressed / corrected? Have prior-year findings been reported to the Board / senior management / audit committee?
Findings: not answered ('No audit has been done'). Reported to management: No.
All 2024 findings are tracked to closure in the Change Log. Findings and remediation status are reported to executive management and retained in the Executive Binder.
Compliant – Enhanced
A1-09
Article One · Proof of Completion of AuditUpdated
Does the TPS obtain proof of completion that each Nested TPS has conducted an annual ACH audit?
No.
N/A — no Nested Third-Party Senders.
Not Applicable
A1-10
Article One · Record Retention & Electronic RecordsUpdated
Is ACH Record retention addressed in the Third-Party Sender policies?
No.
Yes — the Record Retention section of the ACH Policy Manual codifies the six-year retention requirement and the electronic-storage controls.
Compliant – Enhanced
A1-11
Article One · Record Retention & Electronic Records
Are ACH Records of Entries maintained for a period of six years? How are they maintained (Electronic / Hard copy)?
Yes / Electronic.
Yes / Electronic — retained. Six-year archive maintained under IT record-retention and disaster-recovery controls.
Compliant
A1-12
Article One · Record Retention & Electronic RecordsUpdated
What method is used to store and retain Electronic Records? If Records are stored beyond six years, what controls are in place?
As part of normal record retention and disaster recovery plan. Beyond six years: NA.
Encrypted electronic archive with role-based access; retention set to six years unless legal hold applies. Records held beyond six years remain in the same encrypted archive under the same access controls until documented purge.
Compliant – Enhanced
A1-13
Article One · Record Retention & Electronic Records
Do Records accurately reflect Entry information and can they be accurately reproduced? When a physical signature is not obtained, is evidence of the signer's identity retained?
Yes / Yes.
Yes / Yes — retained. Standard electronic-signature audit trail (name, timestamp, IP, and consent language) captured and retained with the Record.
Compliant
A1-14
Article One · Unsecured Electronic NetworkUpdated
In what ways do Originators transmit ACH information via an unsecured electronic network, and what commercially reasonable security methods are used to receive banking information from Originators?
'Through banks procedures and required security protocols.'
Originators submit ACH information only via the secure/password-protected portal, SFTP, or TLS-enforced encrypted email. Verbal and unsecured-email intake is prohibited. Security methods are periodically evaluated by IT.
Compliant – Enhanced
A1-15
Article One · Unsecured Electronic NetworkLCB RU-1 · Discovery 1Updated
What commercially reasonable security methods ensure banking information is encrypted and/or transmitted via a secure session?
'Consistent with banks protocols.'
TLS 1.2+ for all transmissions; SFTP over SSH; encrypted email via S/MIME or forced TLS; portal MFA required. Controls documented in the Secure ACH Communications Policy and reviewed annually.
Compliant – Enhanced
Addresses LCB Discovery 1 / RU-1 (Art. 1 §1.7 — secure transmission of ACH information).
A1-16
Article One · Unsecured Electronic Network
Are security methods periodically evaluated to ensure they remain commercially reasonable?
Yes.
Yes — evaluated annually by IT, with the assessment retained in the Executive Binder.
Compliant
A1-17
Article One · Risk AssessmentUpdated
Has the Third-Party Sender conducted an ACH risk assessment? Does it address operational risks, regulatory requirements, fraud, administrative risks, KYC due diligence, controls for ODFI(s) and Originators, and reporting systems to monitor / mitigate risk?
Yes — all six subcomponents checked in the 2024 workbook.
Yes — retained and formalized. The 2025 ACH Risk Assessment adds likelihood/impact/residual-risk scoring and links each risk to a specific control in the Risk Management Program.
Compliant – Enhanced
A1-18
Article One · Risk AssessmentLCB RU-3 · Discovery 3Updated
Has an ACH Risk Management Program been implemented based on the assessment?
Yes (but see LCB Discovery 3 — program not actually implemented).
Yes — ACH Risk Management Program document adopted and operative, aligned to the 2025 Risk Assessment findings.
Compliant – Enhanced
Addresses LCB Discovery 3 / RU-3 (Art. 1 §1.2.4 — implement Risk Management Program).
A1-19
Article One · Risk AssessmentUpdated
Does the ACH Policy address the frequency ACH Risk Assessments will be conducted?
No.
Yes — the ACH Risk Management Program requires the ACH Risk Assessment to be performed at minimum annually and prior to any new product offering. Cadence is on the Annual ACH Compliance Calendar.
Compliant – Enhanced
A1-20
Article One · Risk AssessmentUpdated
Does the TPS obtain proof from each Nested Third-Party Sender that an ACH Risk Assessment has been conducted?
No.
N/A — no Nested Third-Party Senders.
Not Applicable
A1-21
Article One · ACH Data SecurityLCB RU-2 · Discovery 2Updated
Does the Information/Data Security policy address Receipt & Transmission, Destruction, Storage, and Access to systems containing ACH information?
No boxes checked.
Yes — all four domains explicitly addressed in the Data Security section of the ACH Policy Manual, with cross-references to IT policy for enterprise controls.
Compliant – Enhanced
Addresses LCB Discovery 2 / RU-2 (Data Security / IT Requirements minimum-content component).
A1-22
Article One · ACH Data Security
Do security procedures and systems protect confidentiality, integrity, and against unauthorized use of Protected Information and against threats/hazards to Protected Information?
Yes — all three checked.
Yes — retained and documented in the Data Security section, validated by the annual IT self-assessment.
Compliant
A1-23
Article One · ACH Data SecurityUpdated
Does the TPS perform periodic testing on its Information Security controls (e.g., penetration testing)?
No.
Yes — annual IT self-assessment plus targeted external penetration test scheduled for Q3 2025; results retained in the Executive Binder.
Compliant – Enhanced
A1-24
Article One · ACH Data SecurityUpdated
Have Originators / Nested TPSs been made aware of their requirement to establish internal security policies and procedures to protect ACH Entry Data?
No.
Yes — the updated Origination Agreement includes an Information Security clause obligating the Originator to establish and maintain internal security policies for ACH data. Acknowledgement retained in the Originator file.
Compliant – Enhanced
A1-25
Article One · ACH Data Security
Did the TPS originate over 2 million ACH transactions in the previous year, or do any of its Originators/Nested TPSs?
No / No.
No / No — well below the 2 million-Entries threshold; Supplementing Data Security Rule does not apply. Monitoring in place to reassess annually.
Not Applicable
A1-26
Article One · ACH Data SecurityUpdated
Are security procedures for the Transmission of Entries defined in the Origination Agreement, or in a separate disclosure, for each Originator / Nested TPS? Do you permit Originators to opt-out?
No / No.
Yes — Transmission security requirements are defined in the updated Origination Agreement and reinforced by the Secure ACH Communications Policy. Opt-out is not permitted.
Compliant – Enhanced
AGR-01
Article Two · Binding AgreementsLCB RU-4 · Discovery 4Updated
Has an Agreement been executed between the TPS and each Originator (and any Nested TPS) that legally binds both parties to comply with the Nacha Operating Rules & Guidelines and acknowledges that Entries may not be initiated that violate the laws of the United States?
No.
Yes — the updated Origination Agreement template is executed with each Originator prior to first origination and includes the required Rules-compliance and lawful-use clauses. Signed originals retained in the Originator file.
Compliant – Enhanced
Addresses LCB Discovery 4 / RU-4 (Art. 2 §2.16.1.1 — Origination Agreements with each Originator).
AGR-02
Article Two · Binding AgreementsLCB RU-4 · Discovery 4Updated
Does the TPS/Originator Agreement address the issues recommended in the Operating Guidelines, Appendix C (pp. OG 346-349)?
No.
Yes — the updated Origination Agreement is mapped to Appendix C items line-by-line; the mapping is retained as an appendix in the Executive Binder.
Compliant – Enhanced
Addresses LCB Discovery 4 / RU-4 (Appendix C coverage).
AGR-03
Article Two · Binding AgreementsLCB RU-4 · Discovery 4Updated
Does the Agreement expressly address: restrictions on Entry types, authorization to originate, right to terminate/suspend for Rules breach, right to audit Originator compliance, Originator's assumption of Originator responsibilities, agreement to be bound by the Rules, payment obligation to the ODFI, and lawful use?
No boxes checked.
Yes — all eight required clauses are present in the updated Origination Agreement.
Compliant – Enhanced
Addresses LCB Discovery 4 / RU-4.
AGR-04
Article Two · Binding AgreementsUpdated
Does the TPS/Nested TPS Agreement address the additional Nested-TPS warranties (authorization on behalf of Originator, downstream Origination Agreement, annual audit, and annual Risk Assessment)?
No boxes checked.
N/A — no Nested Third-Party Senders. Template clauses are included in the Origination Agreement library for future use if a Nested TPS relationship is added.
Not Applicable
AGR-05
Article Two · Binding AgreementsUpdated
Does the TPS periodically review the ACH origination agreements and schedule addendums used for Originators / Nested TPSs?
Not answered.
Yes — annual review of the Origination Agreement template and all executed agreements is codified in the Annual ACH Policy Review Procedure (§20).
Compliant – Enhanced
AGR-06
Article Two · Binding Agreements
For IAT Entries, do the Origination Agreements specify allocation of gains/losses and rights/responsibilities in the event of an Erroneous Entry?
N/A.
N/A — Bradley Company does not originate IAT Entries.
Not Applicable
A2R-01
Article Two · Risk ManagementUpdated
Describe the TPS's Know Your Customer (KYC) procedures and how it assesses the risks of each Originator's ACH activity (Customer Due Diligence).
'Gather normal information from client's application for service.'
Formal KYC/CDD documented in the Originator Due Diligence Policy: legal-name / TIN / address verification, secretary-of-state confirmation, OFAC screen, beneficial-ownership review, expected-activity profile, and risk rating. Refreshed at annual periodic review.
Compliant – Enhanced
A2R-02
Article Two · Risk ManagementUpdated
What due diligence procedures ensure Nested Third-Party Senders are appropriately identified?
Left blank.
N/A — no Nested Third-Party Senders. If a Nested TPS relationship is added, the Nested TPS identification and warranty procedures in the Originator Due Diligence Policy will apply.
Not Applicable
A2R-03
Article Two · Risk ManagementLCB RU-5 · Discovery 5Updated
Does the TPS have written policies and procedures for underwriting Originators'/Nested TPSs' exposure limits?
No.
Yes — the Exposure Limit Methodology documents underwriting inputs, formula, tiering, approval authority, and monitoring frequency.
Compliant – Enhanced
Addresses LCB Discovery 5 / RU-5 (Art. 2 §2.2.3 — exposure limits per Originator with periodic review).
A2R-04
Article Two · Risk ManagementLCB RU-5 · Discovery 5Updated
How are exposure limits established and implemented for each Originator / Nested TPS, and has an exposure limit been established for each?
Not described / No.
Established per the Exposure Limit Methodology (volume × ticket × risk multiplier); an exposure limit is set for every active Originator prior to first origination and enforced daily.
Compliant – Enhanced
Addresses LCB Discovery 5 / RU-5.
A2R-05
Article Two · Risk ManagementLCB RU-5 · Discovery 5Updated
How often are exposure limits reviewed? Has the TPS conducted a recent periodic review for each Originator?
'Not part of procedures' / No.
Annually and upon material change in Originator profile. 2025 periodic review completed for all active Originators; evidence retained in the Originator file.
Compliant – Enhanced
Addresses LCB Discovery 5 / RU-5.
A2R-06
Article Two · Risk ManagementUpdated
Has the TPS established procedures to monitor Originator origination and Return activity across multiple Settlement Dates?
No / No.
Yes — daily origination and Return activity are logged by Originator across Settlement Dates in the ACH Operations log; deviations trigger review.
Compliant – Enhanced
A2R-07
Article Two · Risk ManagementLCB R-10 · Discovery 10Updated
How does the TPS enforce restrictions on the types of Entries that may be originated? Does the TPS review actual outgoing ACH data for use of appropriate SEC Codes?
NA / No.
Yes — Origination Agreement lists approved SEC codes per Originator; outbound files sampled monthly against the approved list per the Outbound SEC Code Monitoring Procedure (§21).
Compliant – Enhanced
Addresses LCB Discovery 10 / R-10 (monitor outgoing data for proper SEC codes).
A2R-08
Article Two · Risk ManagementLCB RU-5 · Discovery 5Updated
How does the TPS enforce the exposure limits, and does the Originator know its exposure limit and what to do when exceeded?
'Based on available balance' / No / No.
Enforced at file release against the per-Originator limit from the Exposure Limit Methodology. Each Originator is notified in writing of its assigned limit and of the exception process (advance request + management approval).
Compliant – Enhanced
Addresses LCB Discovery 5 / RU-5 (informing Originators of limits and exceedance procedures).
A2R-09
Article Two · Risk ManagementUpdated
What department or individual is responsible for the Originator/Nested TPS creditworthiness review?
'Based on available balance.'
Credit review is owned by the ACH Compliance Officer with sign-off by the Finance Controller; scope and documentation defined in the Originator Due Diligence Policy.
Compliant – Enhanced
A2R-10
Article Two · Risk ManagementLCB RU-1 · Discovery 1Updated
How does the TPS receive notice of Return Entries from the ODFI, and how are Originators/Nested TPSs informed?
Email / email.
Return notices from Lake City Bank are received via the ODFI's secure portal. Originators are notified via the secure portal or TLS-enforced encrypted email per the Secure Transmission of NOCs & Return Notifications policy (§19). Unsecured email is prohibited.
Compliant – Enhanced
Addresses LCB Discovery 1 / RU-1 (Art. 1 §1.7 — secure transmission of NOC/Return notifications).
A2R-11
Article Two · Risk Management
Are incoming Return Entries communicated to the Originator/Nested TPS in a timely fashion?
Yes.
Yes — retained. Returns communicated within one Banking Day of receipt.
Compliant
A2R-12
Article Two · Risk ManagementUpdated
How are Return Rates calculated (Unauthorized 0.5%, Administrative 3.0%, Overall 15.0%) — ACH software, manual, ODFI monitoring?
Thresholds recorded (0.5% / 3.0% / 15.0%); calculation source columns left unchecked.
Rates calculated monthly by ACH Compliance Officer using the ACH Operations log, with cross-verification against Lake City Bank return monitoring reports. Rates reviewed against NACHA thresholds and reported to management quarterly.
Compliant – Enhanced
PRE-01
Article Two · PrenotificationsUpdated
Do the TPS Origination Agreements with Originators / Nested TPSs address the use of Prenotification Entries?
No.
Yes — the updated Origination Agreement addresses optional Prenotification use and requires the Originator to follow Rules if Prenotes are used.
Compliant – Enhanced
PRE-02
Article Two · PrenotificationsUpdated
Procedures to alert Originators of Returned Prenotifications; to hold subsequent Entries until the third Banking Day; to monitor subsequent Entries that have been Returned as invalid; and to ensure the Receiver's account is not debited/credited before remediation of a Return or NOC in response to a Prenotification.
'Send email if it occurs' / NA / NA / 'Email and phone call.'
Documented Prenotification SOP: (a) Returned Prenotes notified to the Originator through the secure channel within one Banking Day; (b) subsequent Entries held until the third Banking Day following Settlement; (c) any Return/NOC in response to a Prenote must be remedied and re-documented before the next Entry is released.
Compliant – Enhanced
MIC-01
Article Two · Micro-Entries
Does the TPS or its Originators transmit Micro-Entries in accordance with the Rules (credit < $1.00; separate batch with 'ACCTVERIFY'; Company Name identifies Originator of future Entries; commercially reasonable fraud detection)?
N/A across all Micro-Entry questions.
N/A — Micro-Entries not originated by Bradley Company or any Originator. Controls will be implemented if Micro-Entry use is ever adopted.
Not Applicable
RET-01
Article Two · Return Fees & Reinitiated Entries
Does the TPS transmit ACH debit Entries for its Originators / Nested TPSs, and are Returned Entries reinitiated on their behalf?
Yes / Yes / Yes.
Yes / Yes / Yes — retained, under the formal Reinitiation SOP.
Compliant
RET-02
Article Two · Return Fees & Reinitiated EntriesUpdated
Does the TPS ensure reinitiated Return Entries are transmitted only if allowed (NSF/Uncollected, separately authorized stopped payment, or corrective action)?
N/A.
Yes — Reinitiation SOP restricts reinitiation to the three permitted scenarios; compliance verified during batch review.
Compliant – Enhanced
Documents reinitiation scenarios under NACHA Art. 2 §2.13.4.1 — internal remediation, not an LCB Discovery / RU.
RET-03
Article Two · Return Fees & Reinitiated EntriesUpdated
Are reinitiated Returns transmitted within 180 days of the Settlement Date of the original Entry, and not initiated more than two times following the Return?
N/A / N/A.
Yes to both — enforced by the Reinitiation SOP with a control on the batch-review checklist.
Compliant – Enhanced
Documents reinitiation control under NACHA Art. 2 §2.13.4 — internal remediation, not an LCB Discovery / RU.
RET-04
Article Two · Return Fees & Reinitiated EntriesUpdated
Are reinitiated Entries submitted as a separate batch containing 'RETRY PYMT' in the Company Entry Description field?
N/A.
Yes — mandatory formatting is enforced by the Reinitiation SOP and verified during batch review.
Compliant – Enhanced
Documents 'RETRY PYMT' formatting under NACHA Art. 2 §2.13.4.2 — internal remediation, not an LCB Discovery / RU.
RET-05
Article Two · Return Fees & Reinitiated EntriesUpdated
Do Originators / Nested TPSs originate Return Fee Entries in accordance with the Rules (PPD SEC, 'RETURN FEE' description, Company Name matches original NSF/Uncollected, Individual Name/Receiving Company Name identifies the Receiver, and Receiver notice given)?
N/A across the sub-items.
N/A — no Originator currently originates Return Fee Entries. Origination Agreement forbids Return Fee origination unless the Originator provides the required Receiver notice and follows §2.15 formatting; any request triggers ACH Compliance Officer review.
Not Applicable
Documents Return-Fee-Entries posture under NACHA §2.15 — currently N/A, internal completeness, not an LCB Discovery / RU.
NOC-01
Article Two · NOC Provision to OriginatorsLCB RU-1 · Discovery 1Updated
How does the TPS receive NOCs from the ODFI, and how is NOC information provided to Originators / Nested TPSs within two Banking Days of Settlement?
Left blank / left blank.
NOCs received from Lake City Bank via secure portal; NOC data pushed to the Originator via the secure portal or TLS-enforced encrypted email within two Banking Days of Settlement. Unsecured email is prohibited (§19 policy).
Compliant – Enhanced
Addresses LCB Discovery 1 / RU-1 (secure NOC transmission).
NOC-02
Article Two · NOC Provision to OriginatorsUpdated
Does the notification to the Originator / Nested TPS include all information required by the Rules (Company Name, Company ID, Company Entry Description, Effective Entry Date, DFI Account Number, Individual Name/Receiving Company Name, Individual Identification Number, Change Code, Original Entry Trace Number, Original RDFI Identification, Corrected Data)?
Yes — but NACHA §2.12.1 minimum-field completeness is being tightened internally (not an LCB Discovery).
Yes — the standardized NOC notification template includes every required field per §2.12.1 and Appendix Five; template retained in the Executive Binder.
Compliant – Enhanced
Documents minimum required NOC fields under NACHA Art. 2 §2.12.1 — internal remediation, not an LCB Discovery / RU.
NOC-03
Article Two · NOC Provision to Originators
Who is responsible for updating the Receiver's banking information — the TPS or the Originator / Nested TPS?
Originator.
Originator — retained. The updated Origination Agreement makes this responsibility explicit.
Compliant
NOC-04
Article Two · NOC Provision to OriginatorsUpdated
What process ensures the requested change has been made within six Banking Days of NOC receipt or prior to the next Entry, whichever is later?
'Notified within 48 hrs.'
Formal NOC follow-up SOP: the ACH Compliance Officer tracks each NOC in the Operations log with a due date; the next Entry is blocked at file release until the Originator confirms in writing that the change is made or six Banking Days have elapsed with a documented confirmation.
Compliant – Enhanced
Documents six-Banking-Day change window under NACHA Art. 2 §2.12.1 — internal remediation, not an LCB Discovery / RU.
AUTH-01
Article Two · Record of AuthorizationLCB RU-6 · Discovery 6Updated
Is authorization retention addressed in the TPS/Originator Agreement, and have Originators been made aware of the requirement to provide a copy of the Receiver's authorization for all debit Entries to a Consumer Account?
No / Yes.
Yes — authorization-retention verbiage added to the updated Origination Agreement per Art. 2 §2.16.6, and the requirement to provide the Receiver's authorization on request is called out in the Originator onboarding acknowledgement.
Compliant – Enhanced
Addresses LCB Discovery 6 / RU-6 (Art. 2 §2.16.6 — authorization-retention verbiage in the Origination Agreement).
AUTH-02
Article Two · Record of AuthorizationUpdated
Does the TPS have procedures to obtain a copy of the Receiver's authorization from the Originator and provide it to the ODFI within the required time frame? Has testing been performed with Originators on their ability to produce within the required time frame?
No / No.
Yes — the Authorization Production SOP requires the Originator to provide the authorization within three Banking Days of request; the TPS then delivers to Lake City Bank within the 10-Banking-Day Rules window. Annual test performed with each Originator; results retained.
Compliant – Enhanced
AUTH-03
Article Two · Record of AuthorizationUpdated
Does the TPS have procedures to obtain a copy of the front of a source document for ARC or BOC Entries within 10 Banking Days of an RDFI written request, and does the TPS ensure ARC/BOC Entry information, non-representment, retention (two years), and secure storage requirements?
No / no boxes checked.
N/A — ARC and BOC Entries are not originated by Bradley Company or its Originators. Controls will be implemented if ever adopted.
Not Applicable
AUTH-04
Article Two · Record of AuthorizationUpdated
Does the TPS verify that proper authorizations are being obtained based on the specific SEC code used by an Originator / Nested TPS?
No.
Yes — as part of onboarding and annual periodic review, the ACH Compliance Officer samples authorizations against the SEC code in use and documents the review.
Compliant – Enhanced
ID-01
Article Two · Identification of Originators / Provision to ODFIUpdated
What commercially reasonable procedures are used to verify Originator, Nested TPS, and Nested-TPS-Originator identity (where no direct relationship exists)?
'Complli' (incomplete).
CIP procedures per the Originator Due Diligence Policy: legal-name / TIN / address verification, OFAC screen, secretary-of-state confirmation, and identity verification of authorized signers.
Compliant – Enhanced
ID-02
Article Two · Identification of Originators / Provision to ODFIUpdated
What documentation does the TPS require from the Nested TPS to verify Originator identification, and is due-diligence documentation included in the Originator's file?
Blank / No.
N/A on the Nested TPS component. For direct Originators, due-diligence documentation is retained in the Originator file per the Originator Due Diligence Policy.
Compliant – Enhanced
ID-03
Article Two · Identification of Originators / Provision to ODFI
Upon request from the ODFI, can information verifying the Originator / Nested TPS identity be provided to the ODFI within two Banking Days of the request?
Yes.
Yes — retained. Originator files are indexed for rapid production to Lake City Bank within two Banking Days.
Compliant
REV-01
Article Two · ReversalsUpdated
Are TPS personnel aware of the specific scenarios under which a Reversal Entry can be transmitted?
Not answered.
Yes — the Reversals SOP defines the permitted scenarios (Erroneous or duplicate Entry/File) and staff are trained annually on the SOP. Owner-distribution Reversals are routed through formal approval channels rather than initiated by the Property Accountant.
Compliant – Enhanced
REV-02
Article Two · ReversalsLCB RU-7 · Discovery 7Updated
Does the TPS/Originator (or Nested TPS) Agreement identify which party is responsible for the creation of Reversal Files or Entries?
No.
Yes — the updated Origination Agreement assigns Reversal creation responsibility (typically Bradley Company as TPS with Originator authorization); verbiage added per Art. 2 §2.9.
Compliant – Enhanced
Addresses LCB Discovery 7 / RU-7 (Art. 2 §2.9 — Origination Agreement identifies responsible party for Reversal File / Entry creation).
REV-03
Article Two · Reversals
Are Reversal Files or Entries transmitted within five Banking Days of the Settlement Date of the erroneous/duplicate File or Entry, and is a Correcting File/Entry transmitted within 24 hours of discovery?
Yes / Yes.
Yes / Yes — retained; controls documented in the Reversals SOP.
Compliant
REV-04
Article Two · Reversals
Does the Reversal File / Entry contain the word 'REVERSAL' in the Company Entry Description field per §2.10.2?
Yes.
Yes — retained and enforced by the batch-review checklist.
Compliant
REV-05
Article Two · ReversalsUpdated
In the sample tested, were the Company ID / Originator ID, SEC Code, and amount fields identical to the original Entry?
N/A.
Yes — validated during 2025 sample testing; results retained in the Executive Binder.
Compliant – Enhanced
REV-06
Article Two · ReversalsUpdated
Are Originators / Nested TPSs aware of their responsibility to notify Receivers of the Reversal Entry and reason no later than the Settlement Date of the Reversing Entry?
No.
Yes — the updated Origination Agreement obligates the Originator to notify the Receiver no later than the Settlement Date of the Reversing Entry, with a template notice provided.
Compliant – Enhanced
TEL-01
Article Two · TEL Entries
Do Originators / Nested TPSs transmit ACH Entries utilizing the TEL SEC Code?
Yes.
Yes — limited legacy use by one Originator. All controls below now apply.
Compliant
TEL-02
Article Two · TEL EntriesUpdated
Does the TPS ensure that Originators / Nested TPSs initiating TEL Entries record the Oral Authorization or provide the Receiver with written notice confirming the oral authorization prior to Settlement?
N/A across both sub-items.
Yes — the updated Origination Agreement requires the TEL Originator to either audio-record the Oral Authorization or send written confirmation to the Receiver prior to Settlement. Retention and production timelines are specified.
Compliant – Enhanced
TEL-03
Article Two · TEL EntriesUpdated
Has the TPS reviewed the Oral Authorization script in use for each TEL Originator / Nested TPS?
N/A.
Yes — the Oral Authorization script is reviewed at onboarding and annually; the reviewed script is retained in the Originator file.
Compliant – Enhanced
TEL-04
Article Two · TEL EntriesUpdated
Has training/education been provided to each TEL Originator/Nested TPS regarding the length of time authorizations must be retained? When the Oral Authorization is communicated over an unsecured electronic network, is §1.7 satisfied?
No / No.
Yes / Yes — training delivered at onboarding and annually. Non-telephone Oral Authorization channels are prohibited unless they meet the Secure ACH Communications Policy requirements (TLS 1.2+ or portal MFA).
Compliant – Enhanced
TEL-05
Article Two · TEL EntriesUpdated
How does the TPS monitor TEL Originators to ensure risks remain within the approved parameters?
'Not monitored.'
TEL Originators are monitored under the standard return-rate and exposure-limit framework, plus a TEL-specific quarterly sample review of authorizations and returns.
Compliant – Enhanced
'Not monitored' was a material 2024 finding for the one live TEL Originator.
WEB-01
Article Two · Debit WEB Entries
Do Originators / Nested TPSs transmit ACH Entries utilizing the debit WEB SEC code? If yes, has an annual data-security audit been conducted for the site, testing physical security, access controls, and network security?
No / N/A / no boxes checked.
No — debit WEB Entries are not originated by Bradley Company or its Originators. Controls will be implemented if debit WEB use is ever adopted.
Not Applicable
WEB-02
Article Two · Debit WEB Entries
Does each debit WEB Originator/Nested TPS utilize a commercially reasonable fraudulent transaction detection system that validates the account number on first use and any change, and use commercially reasonable methods to verify Receiver identity and the routing number? What controls monitor and mitigate the risks?
N/A across sub-items.
N/A — no debit WEB origination.
Not Applicable
OFAC-01
Article Two · OFAC RequirementsUpdated
How does the TPS verify Originator / Nested TPS is not a blocked person subject to OFAC sanctions when conducting due diligence?
Not documented.
OFAC screening against the SDN and consolidated sanctions list performed at Originator onboarding and refreshed at least annually and on Origination Agreement renewal. Screening evidence retained in the Originator file.
Compliant – Enhanced
OFAC-02
Article Two · OFAC RequirementsUpdated
Does the TPS ensure that both the Originator / Nested TPS and Receiver of any ACH Entries are not subject to OFAC sanctions?
No.
Yes — the TPS screens Originators directly. The updated Origination Agreement obligates each Originator to screen its Receivers against OFAC and to warrant that no Receiver is a blocked party.
Compliant – Enhanced
OD-01
Owner Distributions SOPUpdated
Is there a documented SOP governing owner distributions processed via ACH, including verification, dual approval, and secure transmission?
Not addressed — owner distribution process was not formalized in the prior-year audit package.
Yes — Owner Distribution SOP (v. 02/13/2026) adopted. Requires encrypted-email intake of the signed Owner Distribution Form, verbal verification of routing/account numbers with the owner prior to processing, mandatory CCD SEC code for owner distributions, dual approval documented in Microsoft Teams (retained one year), and daily reconciliation. Bradley Company enters instructions only; Lake City Bank generates the NACHA file.
Compliant – Enhanced
New in 2025 package. Directly captures the owner-distribution workflow that was previously informal.
OD-02
Owner Distributions SOPUpdated
Are recipient banking details verbally verified with the owner or authorized representative before any distribution is entered or updated?
Not documented — verification practice existed informally but was not required by written policy.
Yes — Section 4.3 of the Owner Distribution SOP requires Accounting to verbally verify routing and account numbers with the owner or authorized representative before entry or update, with the verification documented per internal recordkeeping.
Compliant – Enhanced
Primary control against Business Email Compromise on owner payment changes.
OD-03
Owner Distributions SOPUpdated
Are owner distributions originated using the correct SEC code and subject to dual approval with retained evidence?
Not formalized.
Yes — CCD SEC code is mandatory for owner distributions unless management-approved exception. Every ACH transaction receives two separate approvals documented in Microsoft Teams and retained one year. Errors or exceptions are corrected with the bank within 48 hours; reversals are routed through formal approval channels rather than initiated by the Property Accountant.
Compliant – Enhanced