September Compliance Update: Practical Priorities for Credit Unions
As the long, hot days of summer begin to give way to the welcome rhythm of fall, September offers a natural moment to pause, reset, and prepare for the season ahead. For credit unions, that preparation includes a few timely compliance priorities—from confirming recent ACH updates to refreshing fraud-response practices and keeping an eye on emerging vendor-management guidance. The good news is that these developments largely call for focused review and thoughtful fine-tuning, not a wholesale overhaul.
Start with ACH readiness
Two Nacha Rules became effective September 18, and each depends on the credit union’s ACH activity—not its asset size. Smaller institutions should not assume the rules do not apply. Nacha’s current Rules update addresses both changes
Earlier availability for ACH credits
Non-Same Day ACH credits generally must now be available for withdrawal by 9:00 a.m. local time on the settlement date. The change eliminates the former 5:00 p.m. local-time receipt condition, meaning the availability requirement applies even when an affected credit is received after that prior-day cutoff. Nacha includes a limited exception for certain institutions affected by time-zone differences east of the Atlantic Time Zone and west of the International Date Line. Nacha: Funds Availability Requirements for Non-Same Day Credit Entries.
For some credit unions, this may simply confirm that existing processes already meet the requirement. For others, it may be worth taking a closer look at:
How and when ACH files are received and posted
Whether late-arriving files are included in the morning posting cycle
The operational treatment of early-morning ACH Operator files
Whether core processing or vendor arrangements support availability by the required deadline
A short operational validation now can help avoid member-service issues, exceptions, and unnecessary examination questions later.
A clearer international ACH definition
Nacha also revised its definition of an International ACH Transaction, commonly called an IAT. The Rule clarifies when an ACH entry is the U.S. ACH-network component of an international payment transaction, including transactions that originate with, transit through, or are delivered to an account at a financial agency outside the United States. Nacha: Definition of IAT Entries.
This distinction matters because it can affect payment classification, originator onboarding, agreements, required information, sanctions and compliance screening, and overall ACH risk management.
Credit unions that originate ACH payments should consider whether originators, third-party providers, or payment arrangements may need updated classification practices. Receiving institutions may also experience changes in IAT volume or screening workload—even if they do not originate ACH entries themselves.
The appropriate response will vary by payment activity and provider arrangement. In many cases, a targeted review is more appropriate than a broad rewrite of the ACH program.
Keep scam-response practices current
FinCEN’s September 3 alert is a timely reminder that fraud trends continue to evolve and that scam-center activity can present through familiar transaction channels, not only through digital-asset activity. FinCEN Alert FIN-2026-Alert005.
The alert identifies several potential scam-center indicators, including:
Government impersonation scams
Fraudulent “recovery” services that claim to help victims recover prior losses
Instructions for a victim to purchase gold or other precious metals and deliver it to a courier
Payment activity involving conventional cash withdrawals, wires, and other familiar transaction channels
This is important because a credit union does not need to offer cryptocurrency services to encounter these fact patterns. Members may be directed to withdraw cash, initiate wires, purchase precious metals, or make other payments that can appear routine unless the surrounding circumstances are understood.
For suspicious activity reports involving conduct described in the alert, FinCEN requests that institutions include the key term FIN-2026-SCAMCENTERS in SAR Field 2 and in the narrative. FinCEN also identifies “Scam Centers” as the requested description under the applicable Fraud—Other selection. FinCEN: SAR Advisory Key Terms.
A focused review may be helpful in three areas:
Frontline escalation guidance, including what employees should notice and when they should elevate concerns
Member-facing scripts for discussing suspicious transactions or fraud-related account restrictions
SAR procedures and reference materials used by BSA staff
A separate interagency statement issued September 2 provides useful clarity for member communications. The Bank Secrecy Act and its implementing regulations do not prohibit banks and credit unions from discussing potentially fraudulent or suspicious transactions—or from notifying a member that an account may be restricted or closed because of such activity—provided the communication does not reveal the existence of a Suspicious Activity Report. NCUA: Joint Statement on SAR Confidentiality Considerations Regarding Communications with Customers.
The statement does not establish new legal requirements or supervisory expectations. Rather, it clarifies the distinction between prohibited disclosure of a SAR and permissible communication about the underlying facts, transactions, and account decisions.
Corporate transparency relief does not replace CDD
FinCEN has permanently removed the Corporate Transparency Act beneficial ownership information reporting requirement for U.S. companies and U.S. persons, effective August 14, 2026. FinCEN: Final Rule Questions and Answers.
For most credit unions, the immediate operational effect may be limited. Importantly, this reporting relief does not eliminate a credit union’s separate beneficial ownership and customer due diligence responsibilities under applicable CDD requirements.
In other words, a business may no longer have a reporting obligation to FinCEN under the Corporate Transparency Act, while the credit union may still need beneficial ownership information as part of account opening, ongoing monitoring, or risk-based due diligence.
This distinction is worth reinforcing with staff and in account-opening procedures so that the change is not misunderstood as a broader relaxation of customer due diligence expectations.
Watch: Vendor-management proposal
On September 11, the NCUA, FDIC, Federal Reserve Board, and OCC requested comment on proposed interagency third-party risk-management guidance. The proposal is intended to help financial institutions tailor their risk-management practices to the risks associated with each individual third-party relationship. NCUA: Proposed Third-Party Risk Management Guidance.
That focus is especially relevant for smaller credit unions, which may rely heavily on core providers, digital-banking platforms, fintech relationships, payment vendors, cloud services, and other critical third parties.
At this stage, the guidance is proposed and nonbinding. It does not require immediate policy changes. The agencies have indicated that, when finalized, the guidance is intended to replace existing third-party risk-management guidance; comments are due 60 days after publication in the Federal Register.
Still, the proposal is a useful opportunity to consider whether your vendor-management program clearly reflects the level of risk presented by each relationship. A critical core-system provider should not necessarily receive the same level of oversight as a low-risk service provider, but both relationships should be evaluated through a documented, thoughtful process.
A practical September checklist
This month, consider taking the following steps:
Confirm that all affected ACH credits are available by 9:00 a.m. local time on the settlement date.
Review ACH processing schedules, vendor timing, and treatment of late-arriving files.
Assess whether the revised IAT definition affects your ACH origination, receiving, screening, or onboarding practices.
Refresh frontline fraud-escalation guidance for scam-center indicators, including precious-metals and courier scenarios.
Update SAR reference materials to include FIN-2026-SCAMCENTERS where applicable.
Reinforce the distinction between CTA reporting relief and ongoing beneficial ownership and CDD responsibilities.
Monitor the proposed interagency vendor-management guidance and consider whether comments or future program refinements may be appropriate.
As fall begins, a few timely check-ins can help your credit union enter the next season well prepared—supporting sound operations, clear member communication, and a compliance program that remains both practical and responsive.
Crimson Oak can help you determine which developments require action for your particular payment activities, vendor arrangements, and risk profile—so your credit union can respond thoughtfully, efficiently, and with confidence.