Filed under: Foundations, Not-for-Profits, Software Solutions & Training
December 17, 2024
While the Automated Clearing House (ACH) option is ideal for quick and simplified payments, it is imperative to keep security at the forefront of your process. If your grantmaking organization is considering utilizing ACH to transfer funds electronically to your grantees, or if you have already implemented this functionality, there are some key considerations to consider.
First, think through the segregation of duties when managing ACH information. We recommend limiting the number of grantee contacts within each organization with access to enter or change the ACH number. When a grantee contacts your organization with a bank routing number change, verify the change by contacting them using an already-established phone number; do not rely on any information in an email requesting the change.
A good practice would be to have two separate people from the grantee organization involved in any given banking update. For verification purposes, consider having a grantee security code (used for authentication purposes when authorizing a change) that is only known by your organization and the grantee. Be sure to re-verify the number on a regular cadence.
When ACH information changes occur, make sure there is a good audit trail of who initiated and approved the change, while being intentional to not make the process too cumbersome for grantees. Also, consider periodically reviewing the audit trail for changes.
Another good practice is to add multi-factor authentication (MFA) to all banking and email systems. Keep in mind that MFA using an app or token is stronger than text authentication. We recommend requiring systems to be reauthenticated each time you log into the system, no less than daily.
If your organization sends grant payment letters or emails, make sure to mention the date and bank the ACH payment went to. This could help grantees spot fraud on their side. Consider adding an email alias in grant payment letters for grantees to report issues (i.e., question@DOMAIN.org or info@DOMAIN.org) or a link to a whistleblower hotline if your organization has one. Do be extra cautious of urgent or last-minute requests as they can often be related to fraudulent activity.
To minimize risk, some additional considerations for the organization’s internal controls include:
- Automating the ACH process from origination to payment to help limit the opportunity for malicious individuals to act.
- Using positive pay for ACH payments.
- Periodically reviewing the vendor master file for old or duplicate vendors and deleting them. Take cautious note of vendors set up with initials.
For your existing software applications, there are opportunities to take advantage of how the systems are set up and workflows are utilized. Here are some good practices for those using Sage Intacct© and CRM tools.
Sage Intacct Features
- Grantee account numbers can be stored in Sage Intacct, allowing for the generation of the ACH file that can be uploaded to your bank. Sage Intacct provides role permissions for the ACH file generator, ACH bank configurations, and ACH payment files.
- Be diligent about who within an organization has what permissions and audit them regularly. Also, make it known to these users that they have permissions and associated activity will easily be tracked back to them.
- When a grantee record, also known as a vendor in the system, is updated (such as a change in the ACH number), a notification can be sent for approval. This can be accomplished via a Trigger.
Salesforce or other CRM Tools
- Determine if you really need to store the ACH numbers in the CRM system. Sometimes, a reference to the bank and the date it was last updated is all that is needed.
- If you are storing ACH numbers in a CRM system, make sure the field is encrypted and you limit who can view or edit the field.
For additional tips, see this government resource that includes some suggested practices. If you are interested in learning more about implementing ACH payments within your organization, reach out and we would be happy to start the conversation.
© Clark Nuber PS, 2024. All Rights Reserved.


