National Automated Clearing House Association (NACHA) Rules echecks
|
|
|
- Janice Gilmore
- 10 years ago
- Views:
Transcription
1 National Automated Clearing House Association (NACHA) Rules echecks The University of Texas at Austin Office of Internal Audits UTA
2 The University of Texas at Austin Internal Audit Committee Mr. William C. Powers Jr., Chair, President Dr. Steven W. Leslie, Executive Vice President and Provost Mr. Kevin P. Hegarty, Vice President and Chief Financial Officer Dr. Patricia L. Clubb, Vice President for University Operations Ms. Patricia C. Ohlendorf, Vice President for Legal Affairs Dr. Juan M. Sanchez, Vice President for Research Dr. Gage E. Paine, Vice President for Student Affairs Dr. Charles A. Roeckle, Deputy to the President Ms. Mary E. Knight, Associate Vice President and Budget Director Mr. Frank W. Maresh, CPA, External Member Mr. Rudolph H. Green, Director, University Compliance Services Mr. Cameron D. Beasley, University Information Security Officer Mr. Michael W. Vandervort, Director, Office of Internal Audits Director: Assistant Directors: Auditor IV: Auditor III: Auditor I: IT Auditors: Student Interns: The University of Texas at Austin Office of Internal Audits Michael Vandervort, CPA Kathey Mitchell, CIA, CGAP *Chris Taylor, CIA, CISA William Koenig, CIA, CGAP Brenda Guerrero Ashley Foster Cameosha Jones Caroline Poquez *Tod Maxwell, CISA, CISSP Brandon Morales, CISA, CGAP Victoria Hernandez Cameron Fletcher * denotes project members This report has been distributed to Internal Audit Committee members, the Legislative Budget Board, the State Auditor s Office, the Sunset Advisory Commission, the Governor s Office of Budget and Planning, and The University of Texas System Audit Office for distribution to the Audit, Compliance, and Management Review Committee of the Board of Regents. National Automated Clearing House Association (NACHA) Rules - echecks Project Number
3
4 TABLE OF CONTENTS Executive Summary... 1 Background... 2 Scope, Objectives, and Procedures... 2 Audit Results... 3 Conclusion... 3
5 EXECUTIVE SUMMARY The Office of Accounting provides individuals (typically students, faculty, and staff) the option of transferring funds via website using an electronic check (echeck) for payments to The University of Texas at Austin (UT Austin). Payments may include tuition, room and board, taxes, fees, and Bevo Bucks. Monetary transfers to UT Austin by echeck rather than by debit or credit card are processed through the Automated Clearing House (ACH) Network. The National Automated Clearing House Association (NACHA) is a not-for-profit trade association that oversees the ACH Network. 1 NACHA Operating Rules require each Originator of Internet-Initiated/Mobile Entries 2 to conduct annual audits to ensure that the financial information the Originator obtains from Receivers is protected by commercially reasonable security practices. For echeck transactions in this network, the role of the individual making the payment is that of the Receiver and the role of UT Austin is that of the Originator. The scope of this audit included the current controls associated with the Office of Accounting s echeck payment option. The audit objective was to determine compliance with NACHA 2012 Operating Rules for Internet-Initiated/Mobile Entries. Based on interviews with relevant staff, a review of policies and procedures, a review of applicable IT system documentation, and limited testing, Internal Audits concludes that the Office of Accounting s echeck payment option is in compliance with NACHA 2012 Operating Rules for Internet-Initiated/Mobile Entries. This audit was conducted as part of the Fiscal Year 2012 Audit Plan. 1 NACHA Website Internet-Initiated/Mobile Entries are defined by NACHA as debit entries to a consumer s account based on an authorization from the Receiver to the Originator via the Internet or Wireless Network, excluding oral authorization via these channels. Page 1
6 BACKGROUND The Office of Accounting provides individuals (typically students, faculty, and staff) the option of transferring funds via website using an electronic check (echeck) for payments to The University of Texas at Austin (UT Austin). Payments may include tuition, room and board, taxes, fees, and Bevo Bucks. Monetary transfers to UT Austin by echeck rather than by debit or credit card are processed through the Automated Clearing House (ACH) Network. The National Automated Clearing House Association (NACHA) is a not-for-profit trade association that oversees the ACH Network. 3 The NACHA Operating Rules provide the legal foundation for the exchange of ACH payments and ensure that the ACH Network remains efficient, reliable, and secure for the benefit of all participants. 4 For echeck transactions in this network, the role of the individual making the payment is that of the Receiver and the role of UT Austin is that of the Originator. Chapter 48 - Section V of the NACHA Operating Rules require Originators of Internet- Initiated/Mobile Entries 5 to conduct an annual data security audit ensuring the financial information that the Originator obtains from Receivers is protected by commercially reasonable security practices that include: Adequate levels of physical security to protect against theft, tampering or damage, Personnel and access controls to protect against unauthorized access and use, and Network security to ensure capture, transmission, storage, distribution, and destruction. For the fiscal year ending August 31, 2012, there were 83,206 echeck transactions collected through the Office of Accounting s webpages ( What I Owe, My Tuition Bill, and Institution Loans ). These transactions totaled approximately $145.7 million. At the time of the audit, UT Austin did not have a mobile device software application covered under NACHA rules and regulations. SCOPE, OBJECTIVES, AND PROCEDURES The scope of this audit included the current controls associated with the Office of Accounting s echeck payment option. The audit objective was to determine compliance with NACHA 2012 Operating Rules for Internet-Initiated/Mobile Entries. To achieve this objective, the Office of Internal Audits (Internal Audits) staff: Reviewed NACHA 2012 Operating Rules for Internet-Initiated/Mobile Entries; 3 NACHA Website NACHA Website Internet-Initiated/Mobile Entries are defined by NACHA as debit entries to a consumer s account based on an authorization from the Receiver to the Originator via the Internet or Wireless Network, excluding oral authorization via these channels. Page 2
7 Reviewed current UT Austin policies, procedures, and guidelines; Reviewed the current list of users with access to *DEFINE related echeck information; Reviewed supporting documentation; Interviewed staff from Information Technology Services and the Office of Accounting; and Performed limited testing of echeck transactions. This audit was conducted in accordance with the International Standards for the Professional Practice of Internal Auditing and with Government Auditing Standards. AUDIT RESULTS NACHA requires that at a minimum, the audit cover the following sections of the NACHA Operating Rules: Physical security Personnel and Access controls Network security Although not required to be audited by NACHA, the following sections of the NACHA Operating Rules were included in the audit: Originating Depository Financial Institution Agreement Authorizations Authentication Fraudulent Transaction Detection Systems Verification of Routing Numbers Standard Entry Class (SEC) for web site (WEB) transactions Internal Audits determined that echeck access is adequately controlled and other control processes are in place. There were no exceptions. CONCLUSION Based on interviews with relevant staff, a review of policies and procedures, a review of applicable IT system documentation, and limited testing, Internal Audits concludes that the Office of Accounting s echeck payment option is in compliance with NACHA 2012 Operating Rules for Internet-Initiated/Mobile Entries. Page 3
National Automated Clearing House Association Rules echecks
National Automated Clearing House Association Rules echecks The University of Texas at Austin Office of Internal Audits UTA 2.302 (512) 471-7117 The University of Texas at Austin Internal Audit Committee
Information Technology General Controls College of Natural Sciences
Information Technology General Controls College of Natural Sciences The University of Texas at Austin Office of Internal Audits UTA 2.302 (512) 471-7117 The Unive rsity of Te xas at Aust in Inte rnal Audit
May 29, 2008. Members of the Legislative Audit Committee:
John Keel, CPA State Auditor An Audit Report on Student Loan Default Rate Prevention and Management Activities May 29, 2008 Members of the Legislative Audit Committee: Texas Southern University (University)
EQUIPMENT INVENTORY AUDIT MAY 21, 2013. INTERNAL AUDIT DEPARTMENT BOX 19112 ARLINGTON, TX 76019-0112 817-272-0150 www.uta.
EQUIPMENT INVENTORY AUDIT MAY 21, 2013 INTERNAL AUDIT DEPARTMENT BOX 19112 ARLINGTON, TX 76019-0112 817-272-0150 www.uta.edu/internalaudit MEMORANDUM: June 17, 2013 SUBJECT: cc: Dr. Ronald L. Elsenbaumer,
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014
Agenda Item: 7.6 Prepared by: Mark Majek, Kathy Thomas, Deborah Bell, Tamara Cowen and Jaye Stepp Meeting Date: October 2014 Summary of Request: The purpose, authority, and responsibility of the internal
May 2012 Report No. 12-030
John Keel, CPA State Auditor Incentive Compensation at the Teacher Retirement System, the Employees Retirement System, and the Permanent School Fund Report No. 12-030 Incentive Compensation at the Teacher
Health and Human. Services. Commission. InternalAutht Division. Internal Audit Plan. Fiscal Year 2016
x Health and Human Services, Commission InternalAutht Division Internal Audit Plan Fiscal Year 2016 September 22, 2015 NicolE Guerrero, MBA, CIA, CGAP DiredQgof Internal Audit Chris Traylor Executive Commissioner
Citywide Identity Management Follow up Report
Citywide Identity Management Follow up Report July 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver
Texas A&M University - Commerce: Review of Faculty Human Resources Processes PROJECT SUMMARY. Summary of Significant Results
PROJECT SUMMARY Overview Table of Contents Project Summary... 1 Detailed Observations... 3 Basis of Review... 10 Audit Team Information... 11 Distribution List... 11 Processes and controls at Texas A&M
THE UNIVERSITY OF TEXAS AT DALLAS Office of Audit & Compliance 800 West Campbell Rd., ROC 32, RICHARDSON, TX 75080 (972) 883-2233
THE UNIVERSITY OF TEXAS AT DALLAS Office of Audit & Compliance 800 West Campbell Rd., ROC 32, RICHARDSON, TX 75080 (972) 883-2233 February 28, 2014 Dr. Daniel, We have completed a financial audit over
OFFICE OF THE STATE AUDITOR TWO COMMODORE PLAZA 206 EAST NINTH STREET, SUITE 1900 LAWRENCE F. ALWIN, CPA
OFFICE OF THE STATE AUDITOR TWO COMMODORE PLAZA 206 EAST NINTH STREET, SUITE 1900 LAWRENCE F. ALWIN, CPA AUSTIN, TEXAS 78701 State Auditor July 22, 1998 RE: A Review of General Automation Controls at Selected
Accounts Payable Audit
Audit Report# 15-11 November 12, 2015 "Committed to Service, Independence and Quality" THE UNIVERSITY OF TEXAS AT EL PASO Office of Auditing and Consulting Services November 12, 2015 Dr. Diana Natalicio
TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION
TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION The External Leads Program Results in the Recovery of Erroneously Issued Tax Refunds; However, Improvements Are Needed to Ensure That Leads Are Timely
Procure to Pay Process Audit
City of Austin AUDIT REPORT A Report to the Austin City Council Mayor Lee Leffingwell Procure to Pay Process Audit November 2013 Mayor Pro Tem Sheryl Cole Council Members Chris Riley Mike Martinez Kathie
Emerging Strategies for Performance Auditing
IIA R E S E A R C H R E P O R T Emerging Strategies for Performance Auditing Insights from City Auditors in Major Cities in the U.S. and Canada Ronald C. Foster, CIA, CRMA, CISA, CPA, CMA, PMP, CFE Thomas
TEXAS LOTTERY COMMISSION INTERNAL AUDIT DIVISION. An Internal Audit of INSTANT TICKET GAME CLOSING, RETURN & DESTRUCTION
TEXAS LOTTERY COMMISSION INTERNAL AUDIT DIVISION An Internal Audit of INSTANT TICKET GAME CLOSING, RETURN & DESTRUCTION IA #09-013 February 2009 TABLE OF CONTENTS EXECUTIVE SUMMARY... 1 DETAILED REVIEW
911 Data Center Operations Performance Audit
911 Data Center Operations Performance Audit June 2010 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is
DIA Network Security Management Follow up Report
DIA Network Security Management Follow up Report March 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver
Office of Internal Audit. Activity Report. For the period from March 16, 2014 to August 8, 2014. Internal Audit Team
Activity Report For the period from March 16, 2014 to August 8, 2014 Internal Audit Team Stefanie Powell, CPA, CISA Interim Director Kelly Mintern, CPA, CIA Auditor Cynthia Nickerson, CPA Auditor Karen
ERIC M. WRIGHT, cpa, citp
ERIC M. WRIGHT, cpa, citp ERIC M. WRIGHT, CPA, CITP Eric has been involved with Information Technology with Schneider Downs since 1983. He specializes in and oversees the design, setup, installation and
Research Administration at the University of Maryland
Research Administration at the University of Maryland Anne S. Geronimo, M.S. Director, Research Development Division of Research University of Maryland June 2007 Tokyo, Japan University of Maryland Profile
Denver 311 Follow up Report
Denver 311 Follow up Report December 2014 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently
Oklahoma State University Policy and Procedures. Red Flags Rules and Identity Theft Prevention
Oklahoma State University Policy and Procedures Rules and Identity Theft Prevention 3-0540 ADMINISTRATION & FINANCE July 2009 Introduction 1.01 Oklahoma State University developed this Identity Theft Prevention
PeopleSoft IT General Controls
PeopleSoft IT General Controls Performance Audit December 2009 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of
ACH Authorization Requirements
ACH Authorization Requirements Single Entry TEL (Telephone Initiated Entry) The authorization is not required to be provided to the consumer in writing, however as the authorization is received orally,
OFFICE OF AUDITS & ADVISORY SERVICES SUNGARD TREASURY MANAGEMENT SYSTEM CONTRACT COMPLIANCE FINAL AUDIT REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES SUNGARD TREASURY MANAGEMENT SYSTEM CONTRACT COMPLIANCE FINAL AUDIT REPORT Chief of Audits: Juan R. Perez Senior Audit Manager:
DIA Network Device Security Management Performance Audit
DIA Network Device Security Management Performance Audit June 2014 Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City and County of Denver is independently
Oregon Employment Department: Computer Programs for Unemployment Tax Returns and Claims Need Attention
Secretary of State Audit Report Jeanne P. Atkins, Secretary of State Gary Blackmer, Director, Audits Division Oregon Employment Department: Computer Programs for Unemployment Tax Returns and Claims Need
OFFICE OF AUDITS & ADVISORY SERVICES BEHAVIORAL HEALTH SERVICES CONTRACT MONITORING AUDIT FINAL REPORT
County of San Diego Auditor and Controller OFFICE OF AUDITS & ADVISORY SERVICES BEHAVIORAL HEALTH SERVICES CONTRACT MONITORING AUDIT FINAL REPORT Chief of Audits: Juan R. Perez Audit Manager: Laura R.
Assistant Ms. Sophie Miller-Gilliland Manager, Office of the President Saddleback College
Chair Dr. Tod Burnett President Saddleback College A results-oriented leader with a distinguished career in the public sector, Dr. Tod A. Burnett has served as president of Saddleback College since August
O L A. Department of Employee Relations Department of Finance SEMA4 Information Technology Audit OFFICE OF THE LEGISLATIVE AUDITOR STATE OF MINNESOTA
O L A OFFICE OF THE LEGISLATIVE AUDITOR STATE OF MINNESOTA Financial-Related Audit Department of Employee Relations AUGUST 29, 2002 02-57 Financial Audit Division The Office of the Legislative Auditor
John Keel, CPA State Auditor. A Report on State Employee Benefits as a Percentage of Total Compensation. April 2014 Report No.
John Keel, CPA State Auditor A Report on State Employee Benefits as a Percentage of Total Compensation Report No. 14-704 A Report on State Employee Benefits as a Percentage of Total Compensation Overall
Police Records Management System IT General Controls Follow up Report
Police Records Management System IT General Controls Follow up Report March 2015 Office of the Auditor Audit Services Division City and County of Denver Dennis J. Gallagher Auditor The Auditor of the City
CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Customer Service/311. CRM System. Project No. AU12-020. April 15, 2013
CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR Audit of Customer Service/311 CRM System Project No. AU12-020 April 15, 2013 Kevin W. Barthold, CPA, CIA, CISA City Auditor Executive Summary As part of our
5500 Brooktree Road, Suite 104 Wexford, PA 15090 888-436-5101 www.profituity.com AN OVERVIEW OF ACH COPYRIGHT 2013, PROFITUITY, LLC
5500 Brooktree Road, Suite 104 Wexford, PA 15090 888-436-5101 www.profituity.com AN OVERVIEW OF ACH COPYRIGHT 2013, PROFITUITY, LLC Page 2 of 11 Contents Automated Clearing House... 3 The Role of NACHA...
The University of Texas at Austin Campus Master Plan. Cesar Pelli & Associates Balmori Associates, Inc.
The University of Texas at Austin Campus Master Plan Cesar Pelli & Associates Balmori Associates, Inc. as of May 1999 OFFICERS OF ADMINISTRATION The University of Texas at Austin BOARD OF REGENTS The University
HUMAN RESOURCES PAYROLL
HUMAN RESOURCES New Hires, Promotions, PAYROLL and Terminations City of Tulsa Internal Auditing November 2013 HUMA AN RESOURCES PAYROLL New Hires, Promot tions And Terminations City of Tulsa Internal Auditing
echeck.net Operating Procedures and User Guide
echeck.net Operating Procedures and User Guide Table of Contents Introduction... 4 What is echeck.net?... 4 Who can use echeck.net?... 4 Applying for echeck.net... 5 echeck.net Fees and Settings... 5 echeck.net
The University of Texas at Austin BYLAWS OF THE GRADUATE STUDENT ASSEMBLY. ARTICLE I Objectives
The University of Texas at Austin BYLAWS OF THE GRADUATE STUDENT ASSEMBLY ARTICLE I Objectives Section 1. General Objectives 1.1. To represent the views of graduate students to the university community
Identity Theft Prevention Policy
Eastern Kentucky University Policy and Regulation Library 6.#.#P Volume 6, Volume Title: Financial Affairs Chapter #, Chapter Title Section #, Name: Identity Theft Prevention Policy Approval Authority:
ASSESSMENT REPORT 13 19. Federal PKI Compliance Report September 6, 2013
ASSESSMENT REPORT 13 19 Federal PKI Compliance Report September 6, 2013 Date September 6, 2013 To Chief Information Officer From Inspector General Subject Assessment Report Federal PKI Compliance Report
March 2007 Report No. 07-709
John Keel, CPA State Auditor the State s Attorney, Assistant Attorney General, and General Counsel Positions Report No. 07-709 the State s Attorney, Assistant Attorney General, and Positions Overall Conclusion
