Accredited ACH Professional (AAP) — Questions and Answers
Question 1: Which one of the following risk control techniques will reduce loss severity and make losses more predictable, without increasing loss frequency? Choose one answer.
- Loss prevention
- Duplication (Correct answer)
- Diversification
- Separation
Correct answer: Duplication
Duplication is a risk control technique that involves creating backup copies of critical assets, data, or operations and storing them in a separate location. This strategy primarily reduces loss severity because if the primary asset is damaged or destroyed, the duplicate can be quickly utilized to restore functionality. It also makes losses more predictable by ensuring continuity, without necessarily influencing the frequency of the initial loss event.
Question 2: For ARC entries, the notice posted by the Originator at the point of check collection must be:
- Clear and conspicuous, informing consumers that their check will be converted to an ACH debit (Correct answer)
- Sent via email to the consumer prior to the collection date
- Printed directly on the back of every check accepted
- Posted only on the Originator's public website
Correct answer: Clear and conspicuous, informing consumers that their check will be converted to an ACH debit
For ARC, NACHA requires a clear and conspicuous notice at the collection point (e.g., billing statement or return envelope) that checks may be converted to ACH debits.
Question 3: After identifying and analyzing loss exposures and evaluating and selecting the appropriate risk management techniques, the next step in the risk management process is to Choose one answer.
- Implement the selected techniques. (Correct answer)
- Decide on risk financing techniques.
- Monitor the results.
- Revise the risk management program.
Correct answer: Implement the selected techniques.
The risk management process follows a logical sequence to effectively address potential losses. After identifying and analyzing loss exposures, and subsequently evaluating and selecting the most appropriate risk management techniques (both control and financing), the next crucial step is to put these chosen strategies into action. This implementation phase involves executing the selected techniques, such as purchasing insurance, installing safety measures, or establishing contingency plans, before their effectiveness can be monitored.
Question 4: For POP entries, what must an Originator provide to the consumer at the point of purchase?
- The merchant's ODFI name and ACH company ID
- A copy of the NACHA Operating Rules for consumer reference
- A written authorization for all future debit entries
- A receipt and clear notice that the check will be converted to an ACH debit entry (Correct answer)
Correct answer: A receipt and clear notice that the check will be converted to an ACH debit entry
For POP entries, the Originator must provide the consumer with a receipt and prominent notice that their check will be converted to an ACH debit and is not their original check.
Question 5: Which record type code identifies an ACH Addenda Record?
- 5
- 6
- 7 (Correct answer)
- 8
Correct answer: 7
Record type code '7' identifies Addenda Records, which provide supplemental payment-related information attached to an Entry Detail Record.
Question 6: Under Regulation E, a consumer must report an unauthorized transaction within what timeframe to receive maximum protection?
- 60 days from the date of the account statement
- Same day the unauthorized transaction is discovered
- 2 business days of learning of the loss or theft of an access device (Correct answer)
- 30 calendar days of the transaction date
Correct answer: 2 business days of learning of the loss or theft of an access device
Reporting within 2 business days of learning of a lost or stolen access device limits consumer liability to $50; waiting longer increases potential liability.
Question 7: Under NACHA rules, a Third-Party Sender's compliance obligation includes:
- Obtaining direct NACHA membership as a condition of operation
- Registering directly with the Federal Reserve before transmitting entries
- Entering into a written agreement with the ODFI acknowledging its responsibilities under NACHA Operating Rules (Correct answer)
- Annual CPA certification of its ACH transaction volumes
Correct answer: Entering into a written agreement with the ODFI acknowledging its responsibilities under NACHA Operating Rules
NACHA requires each Third-Party Sender to have a written agreement with its sponsoring ODFI that explicitly acknowledges the TPS's obligations to comply with NACHA Operating Rules.
Question 8: Return code R29 indicates:
- Corporate account has been closed
- Invalid company identification number
- Insufficient funds in a corporate account
- Corporate customer advises the entry is not authorized (for CCD, CTX, or other corporate entries) (Correct answer)
Correct answer: Corporate customer advises the entry is not authorized (for CCD, CTX, or other corporate entries)
R29 (Corporate Customer Advises Not Authorized) is the business equivalent of R10, used when a corporate Receiver states a debit entry was not authorized.
Question 9: When a consumer's check is received via a lockbox for conversion to an ACH debit, which SEC code applies?
- TEL (Telephone-Initiated Entry)
- ARC (Accounts Receivable Conversion) (Correct answer)
- POP (Point-of-Purchase)
- BOC (Back Office Conversion)
Correct answer: ARC (Accounts Receivable Conversion)
ARC is the correct SEC code for checks received via mail or lockbox (not at a physical point of purchase) that are converted to ACH debit entries.
Question 10: Which SEC code is used for point-of-purchase check conversion transactions at a merchant location?
- ARC (Accounts Receivable Conversion)
- RCK (Re-presented Check)
- POP (Point-of-Purchase) (Correct answer)
- BOC (Back Office Conversion)
Correct answer: POP (Point-of-Purchase)
POP is used when a consumer's check is converted to an ACH debit entry at the point of purchase with the consumer present.
Question 11: A consumer may revoke ACH debit authorization by:
- Filing a formal complaint with NACHA's consumer protection division
- Notifying the Originator in the manner specified in the authorization agreement (Correct answer)
- Calling their RDFI only—the RDFI then notifies the Originator
- Disputing the charge through their credit card issuer
Correct answer: Notifying the Originator in the manner specified in the authorization agreement
To revoke an ACH debit authorization, the consumer must notify the Originator in the method described in the authorization agreement itself.
Question 12: NOC change code C05 indicates:
- Incorrect company name
- Incorrect transaction code (Correct answer)
- Incorrect DFI account number
- Incorrect routing/transit number
Correct answer: Incorrect transaction code
C05 is used in a Notification of Change when the transaction code (indicating account type and credit/debit) in the entry is incorrect.
Question 13: Which two entities serve as ACH Operators in the United States?
- OCC and FDIC
- JPMorgan Chase and Wells Fargo
- NACHA and FinCEN
- FedACH and EPN (operated by The Clearing House) (Correct answer)
Correct answer: FedACH and EPN (operated by The Clearing House)
The two ACH Operators are FedACH (operated by the Federal Reserve Banks) and EPN (Electronic Payments Network, operated by The Clearing House).
Question 14: Which party initiates a reversing entry in the ACH network?
- The RDFI on behalf of the Receiver
- The ACH Operator upon error detection
- The Originator through its ODFI (Correct answer)
- NACHA as the network administrator
Correct answer: The Originator through its ODFI
Only the Originator, through its ODFI, may initiate a reversing entry to correct an erroneous entry that was already transmitted.
Question 15: The unauthorized entry return rate threshold (using codes R05, R07, R10, R29, R51) that triggers NACHA scrutiny is:
- 15.0% of debit entries originated
- 3.0% of debit entries originated
- 1.0% of debit entries originated
- 0.5% of debit entries originated (Correct answer)
Correct answer: 0.5% of debit entries originated
The unauthorized return rate threshold is 0.5%—much stricter than the 15% overall threshold—because unauthorized entries indicate serious authorization failures.
Question 16: What is the main responsibility of the Originating Depository Financial Institution (ODFI) in ACH transactions?
- To determine the settlement date for the transaction
- To ensure compliance with ACH rules and properly transmit entries to the ACH Operator (Correct answer)
- To verify the authenticity of the Receiver's account
- To ensure all transactions are settled by the Federal Reserve
Correct answer: To ensure compliance with ACH rules and properly transmit entries to the ACH Operator
The Originating Depository Financial Institution (ODFI) plays a critical role in ACH transactions, bearing significant responsibilities. Its main responsibility is to ensure that all ACH entries it originates fully comply with the Nacha Operating Rules and any applicable laws. The ODFI must also properly transmit these compliant entries to the ACH Operator for processing, acting as the gateway for Originators into the ACH Network.
Question 17: How is a Third-Party Sender (TPS) defined under NACHA Operating Rules?
- A direct customer of an ODFI with its own origination agreement
- A company that transmits ACH entries on behalf of Originators through an ODFI (Correct answer)
- A federal reserve bank that clears ACH entries
- An ACH network operator that settles transactions
Correct answer: A company that transmits ACH entries on behalf of Originators through an ODFI
A Third-Party Sender is an intermediary that transmits ACH entries to an ODFI on behalf of Originators, often providing processing services for multiple clients.
Question 18: An ODFI's warranty to the ACH network when transmitting entries includes:
- That the RDFI will post entries within one hour of receipt
- That entries are guaranteed to be fraud-free
- That entries comply with NACHA Operating Rules and that the Originator has obtained proper authorization (Correct answer)
- That all entries will settle on the same day
Correct answer: That entries comply with NACHA Operating Rules and that the Originator has obtained proper authorization
By transmitting entries, the ODFI warrants that they comply with NACHA Operating Rules and that proper Receiver authorizations have been obtained.
Question 19: The second step in the risk management process is analyzing loss exposures. Which one of the following is true regarding this step? Choose one answer.
- Loss exposures that could interfere with the achievement of the organization's goals are identified in this step.
- A weakness of loss exposure analysis is that it is useful only for those types of losses that an organization has suffered in the past.
- Loss exposures are analyzed based on loss frequency, loss severity, total dollar losses, and timing in this step. (Correct answer)
- A major strength of loss exposure analysis is that the process is generally inexpensive.
Correct answer: Loss exposures are analyzed based on loss frequency, loss severity, total dollar losses, and timing in this step.
The second step in the risk management process, analyzing loss exposures, involves a detailed quantitative and qualitative assessment of identified risks. This analysis specifically focuses on four critical dimensions: loss frequency (how often a loss is expected), loss severity (the potential financial impact of each loss), total dollar losses (the aggregate financial burden), and timing (when losses are likely to occur). This comprehensive evaluation helps in understanding the true impact of potential risks.
Question 20: For WEB debit entries, what additional security requirement is imposed on Originators?
- Real-time fraud monitoring certification by a third party
- Monthly reporting of WEB volume to NACHA
- An annual audit to validate the security of transmission and storage of Receiver banking information (Correct answer)
- Mandatory two-factor authentication for all WEB transactions
Correct answer: An annual audit to validate the security of transmission and storage of Receiver banking information
NACHA rules require Originators of WEB entries to conduct an annual audit of their data security practices for transmitting and storing Receiver banking information.
Question 21: What are the two primary types of transactions processed through the ACH Network?
- Credit and debit transactions (Correct answer)
- Direct deposits and cash withdrawals
- Wire transfers and credit card payments
- Check and electronic transfers
Correct answer: Credit and debit transactions
The two primary types of transactions processed through the ACH Network are credit and debit transactions. Credit transactions involve pushing funds from one account to another, such as direct deposits of payroll. Debit transactions involve pulling funds from an account, like automatic bill payments. These two categories encompass the vast majority of ACH activity.
Question 22: Which of the following is NOT a required element of a valid PPD debit authorization?
- The payment schedule or frequency of debits
- The Originator's name
- The Originator's profit margin or fee disclosure (Correct answer)
- The Receiver's name
Correct answer: The Originator's profit margin or fee disclosure
While profit margin disclosures may be required by other laws, they are not a required element of a NACHA-compliant PPD debit authorization.
Question 23: NACHA Operating Rules require ODFIs to monitor their Originators primarily for which key compliance metric?
- Return rates—specifically the unauthorized debit return rate and the overall debit return rate (Correct answer)
- Average transaction dollar amount relative to industry benchmarks
- Consumer complaint ratio reported to the CFPB
- Daily entry count compared to the Originator's origination limit
Correct answer: Return rates—specifically the unauthorized debit return rate and the overall debit return rate
ODFIs must monitor Originator return rates, because excessive overall or unauthorized return rates indicate compliance problems that require ODFI intervention.
Question 24: Regulation E primarily protects:
- ACH Operators from network disruptions caused by fraud
- Consumers from unauthorized electronic fund transfers (Correct answer)
- ODFIs from Originator liability for unauthorized entries
- Businesses from ACH fraud and unauthorized debits
Correct answer: Consumers from unauthorized electronic fund transfers
Regulation E (Electronic Fund Transfer Act) establishes the rights of consumers and the responsibilities of financial institutions regarding unauthorized electronic fund transfers.
Question 25: Return code R01 indicates:
- Payment stopped by the Receiver
- Account has been closed
- No account or unable to locate the account
- Insufficient funds in the Receiver's account (Correct answer)
Correct answer: Insufficient funds in the Receiver's account
R01 (Insufficient Funds) means the Receiver's account did not have enough available funds to cover the debit entry at the time of posting.
Question 26: Risk is a term that is regularly used and that is generally understood in context. As used in this discussion, which one of the following is one of the two elements within the definition of risk?
- Likelihood of injury or damage to property
- Uncertainty of outcome (Correct answer)
- Opportunity for profit
- Probability of financial loss
Correct answer: Uncertainty of outcome
In the context of risk management, risk is fundamentally defined by two key elements: uncertainty of outcome and the possibility of a negative deviation from what is expected. Uncertainty refers to the unpredictability of whether a particular event will occur and what its consequences might be. This inherent unpredictability is what makes risk a central concern for organizations, necessitating management strategies.
Question 27: OFAC compliance in ACH processing requires financial institutions to:
- Screen transactions against the SDN list and block or reject prohibited transactions (Correct answer)
- File a SAR with FinCEN for every IAT entry received
- Report all international ACH transactions to OFAC before processing
- Obtain OFAC pre-approval for every IAT entry originated
Correct answer: Screen transactions against the SDN list and block or reject prohibited transactions
Financial institutions must screen ACH transaction parties against OFAC's Specially Designated Nationals (SDN) list and block or reject any transactions involving prohibited parties.
Question 28: A Nested Third-Party Sender is defined as:
- An ODFI that sponsors multiple originators simultaneously
- A direct ACH network member with nested accounts
- A TPS that itself uses another TPS to transmit entries to an ODFI (Correct answer)
- A Federal Reserve branch providing sub-processing services
Correct answer: A TPS that itself uses another TPS to transmit entries to an ODFI
A Nested Third-Party Sender is a TPS that contracts with another TPS (rather than directly with an ODFI) to transmit ACH entries, creating a layered origination structure.
Question 29: Risk management program goals are typically divided into two categories: pre-loss goals and post-loss goals. Which one of the following describes one of these categories of goals? Choose one answer.
- Post-loss goals include immediate restoration of operations, tolerable uncertainty, and loss mitigation.
- Pre-loss goals include profitability, earnings stability, and loss prevention.
- Post-loss goals broadly describe the degree of recovery that an organization will strive to reach following a loss. (Correct answer)
- Pre-loss goals are risk management goals that allow the organization to prepare for future losses.
Correct answer: Post-loss goals broadly describe the degree of recovery that an organization will strive to reach following a loss.
Risk management goals are typically categorized into pre-loss and post-loss objectives. Post-loss goals specifically define the desired state of an organization after a loss event has occurred. These goals aim to guide the recovery process, ensuring the organization can survive, maintain operations, and achieve a certain level of stability and normalcy following an adverse incident.
Question 30: For most standard return reasons, an RDFI must return an ACH entry within how many banking days of the settlement date?
- 5 banking days
- 60 calendar days
- 2 banking days (Correct answer)
- Same business day
Correct answer: 2 banking days
The standard return timeframe under NACHA rules is 2 banking days from the settlement date of the original entry.
Accredited ACH Professional (AAP)
The AAP certification validates expertise in ACH network operations, rules and regulations, risk management, file formatting, and other payment systems. It is administered by Nacha and recognized as the premier credential for ACH payments professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds