Merchant Remote Deposit Capture Risk Assessment Checklist: What Banks Should Review

Merchant Remote Deposit Capture on-site risk assessment checklist cover showing a banker reviewing a check scanner and assessment form.

Remote deposit capture gives business customers a convenient way to deposit checks without visiting a branch. However, that convenience changes how a financial institution identifies, monitors, and controls deposit risk.

When employees cannot physically inspect every original check or directly observe where the scanner is being used, risks involving fraud, duplicate presentment, information security, check storage, and unusual account activity may increase.

A merchant remote deposit capture risk assessment helps a bank or credit union determine whether the merchant’s actual practices remain consistent with the institution’s expectations, agreement, and risk appetite.

What Is Merchant Remote Deposit Capture?

Merchant remote deposit capture, commonly called merchant RDC, allows a business to scan checks at an approved location and electronically transmit the check images to its financial institution for deposit.

The business generally retains the original checks for a defined period instead of delivering them to a branch. That makes controls involving check security, storage, destruction, authorized users, equipment, and duplicate prevention particularly important.

The FFIEC BSA/AML Examination Manual identifies several potential RDC risks, including fraud, money laundering, information security concerns, altered items, duplicate presentment, unauthorized equipment movement, and weaknesses involving retained original checks.

Why Conduct an On-Site RDC Risk Assessment?

An on-site assessment helps the financial institution compare the merchant’s documented procedures with what is happening at the approved business location.

The objective is not simply to confirm that a scanner is present. The reviewer should determine whether the merchant’s practices, transaction activity, security controls, and handling of original checks remain consistent with the relationship’s approved risk profile.

FFIEC guidance states that when the level of risk warrants, financial institution personnel should consider visiting the customer’s physical location as part of the suitability review. During the visit, the customer’s operational controls and risk-management processes should be evaluated.

The frequency and scope of a review should be risk-based and consistent with the institution’s policies. A higher-risk merchant, material change in activity, control breakdown, ownership change, new location, fraud event, or significant deviation from expected activity may justify additional review.

Eight Areas to Review During an RDC Assessment

1. Merchant and Service Profile

Begin by confirming the fundamental information about the merchant and the RDC relationship.

Review items such as:

  • Legal business name and physical operating address
  • Industry and type of business
  • Ownership and authorized representatives
  • Approved RDC locations
  • Account and relationship information
  • Length of the banking relationship
  • RDC application or service provider
  • Approved scanner or device information
  • Anticipated check types, volumes, and dollar amounts

This information helps establish whether the merchant’s current operations remain consistent with the facts used during approval.

2. Expected Activity Compared With Actual Activity

The institution should understand the merchant’s expected RDC transaction volume, dollar volume, check types, and normal business activity.

Compare those expectations with actual activity. Material changes may include:

  • Deposit volume increasing significantly
  • Deposits exceeding established limits
  • Check types that were not anticipated
  • Unusual geographic patterns
  • Repeated duplicate items
  • Increased returned items or adjustments
  • Activity inconsistent with the merchant’s stated business
  • Unexplained changes in deposit frequency or average amount

A difference does not automatically mean that fraud is occurring. It does mean the institution should understand and document the reason for the change.

3. Agreement and Merchant Procedures

Confirm that the merchant has access to the current RDC agreement, understands its responsibilities, and follows documented procedures.

The review may include:

  • Authorized locations and equipment
  • Approved users and access responsibilities
  • Deposit preparation requirements
  • Restrictive endorsement requirements
  • Prohibited or ineligible items
  • Daily and per-item limits
  • Original-check retention requirements
  • Secure destruction procedures
  • Duplicate-presentment prevention
  • Procedures for errors, returns, and unusual items
  • The institution’s authority to inspect, restrict, suspend, or terminate the service

The agreement and operational procedures should clearly define the responsibilities of both the merchant and the financial institution.

4. User Access and Authentication

Review how the merchant controls access to the RDC system.

Questions may include:

  • Does every authorized user have unique credentials?
  • Are shared usernames or passwords prohibited?
  • Is multifactor authentication enabled where required by the institution?
  • Are former employees removed promptly?
  • Are user permissions appropriate for assigned responsibilities?
  • Are passwords, tokens, and devices protected?
  • Is administrative access limited?
  • Are access and security incidents reported promptly?

Access should be limited to employees with a legitimate business need. The merchant should not permit shared credentials simply because several employees perform deposits.

5. Equipment and Location Security

Confirm that RDC equipment is used only at approved locations and is protected against unauthorized access or movement.

Consider:

  • Scanner or device location
  • Physical security around the equipment
  • Device make, model, and serial number
  • Approved computer or operating environment
  • Antivirus, security updates, and device maintenance
  • Network protections
  • Restrictions on moving equipment
  • Protection from unauthorized employees or visitors
  • Procedures for lost, stolen, replaced, or damaged equipment

The FFIEC notes that portable RDC equipment can create challenges when institutions cannot determine or control where it is being used.

6. Original-Check Handling

Because the merchant usually retains the original checks, the on-site review should examine the complete check-handling process.

Review whether the merchant:

  • Marks or endorses checks according to institutional requirements
  • Separates processed checks from unprocessed checks
  • Stores original items in a secure location
  • Limits access to retained checks
  • Maintains checks for the required retention period
  • Can retrieve an original item when requested
  • Destroys expired items securely
  • Prevents processed checks from being deposited again
  • Protects confidential information appearing on checks

Weak storage or destruction practices may expose both the merchant and the institution to fraud, privacy, and duplicate-presentment risk.

7. Monitoring, Limits, and Exceptions

The assessment should confirm that approved limits remain appropriate for the merchant’s current activity and financial condition.

Review:

  • Daily deposit limits
  • Per-item limits
  • Deposit cutoff practices
  • Repeated limit exceptions
  • Returned-item activity
  • Duplicate detections
  • Image-quality problems
  • Adjustments and corrections
  • Over-limit approvals
  • Suspicious or unusual activity escalations

The FFIEC recommends establishing RDC transaction limits and conducting additional monitoring when meaningful changes occur in transaction type, volume, customer risk, location, or operating practices.

8. Training and Incident Response

Merchant employees responsible for RDC should understand routine processing, prohibited activity, duplicate prevention, check retention, problem resolution, and security expectations.

Ask how the merchant would respond if:

  • A check were deposited twice
  • RDC credentials were compromised
  • A scanner or authorized device were stolen
  • An employee with RDC access left the company
  • A suspicious or altered check were identified
  • Deposit activity exceeded established limits
  • The merchant could not locate an original check

The merchant should know whom to contact at the financial institution and should report incidents promptly.

What Documentation Should Be Retained?

A completed assessment should create a clear record of what was reviewed, what evidence was examined, and what action is required.

Documentation may include:

  • Assessment date and review type
  • Reviewer and merchant representative
  • Approved locations and equipment
  • Documents and evidence reviewed
  • Responses to assessment questions
  • Exceptions or control weaknesses
  • Risk rating or assessment conclusion
  • Corrective-action owner
  • Target completion date
  • Escalation decision
  • Follow-up verification
  • Final reviewer certification

A checklist should support professional judgment—not replace it. Explanations and supporting evidence are especially important when a control is rated “No,” “Not Applicable,” or requires corrective action.

Common RDC Warning Signs

Potential warning signs may include:

  • Equipment operating from an unapproved location
  • Shared credentials
  • Unsecured original checks
  • Missing restrictive endorsements
  • Processed and unprocessed checks stored together
  • Deposit activity inconsistent with the business
  • Frequent duplicate items
  • Excessive returned checks
  • Repeated limit exceptions
  • Unexplained changes in ownership, location, or activity
  • Employees who cannot explain basic RDC procedures
  • Missing documentation for prior exceptions
  • Corrective actions that remain unresolved

One warning sign may have a reasonable explanation. Multiple unresolved concerns may indicate that the relationship requires further investigation, tighter controls, revised limits, additional monitoring, or escalation under institutional procedures.

Make the Review Consistent and Documented

A structured assessment helps the reviewer move beyond simply observing the scanner. It creates a consistent framework for evaluating the merchant, approved equipment, access security, check handling, transaction activity, documentation, and corrective actions.

The Merchant Remote Deposit Capture (RDC) On-Site Risk Assessment Checklist from Jay Get It™ is an editable four-page Word document designed to help financial institutions organize and document that review.

You can also explore additional banking job aids and professional checklists.

Frequently Asked Questions

Is an on-site visit required for every RDC merchant?

The appropriate review method and frequency should be based on the institution’s risk assessment, policies, customer profile, and circumstances. FFIEC guidance states that an institution should consider visiting the customer’s physical location when the level of risk warrants it.

How often should an RDC merchant be reviewed?

There is no single review frequency that fits every relationship. Institutions should establish risk-based review practices and consider additional review when activity, ownership, locations, equipment, underwriting information, or risk conditions change significantly.

What should an RDC risk assessment evaluate?

The assessment should be appropriate for the relationship and may evaluate customer suitability, expected and actual activity, agreements, authorized users, authentication, equipment, approved locations, original-check security, deposit limits, monitoring, training, incident response, and corrective actions.

What happens when a control weakness is identified?

The reviewer should document the issue, supporting evidence, risk created, responsible owner, required corrective action, target date, escalation decision, and follow-up result according to the institution’s policies.

Does a checklist replace the institution’s policies?

No. A checklist is an organizational and documentation tool. Each financial institution must follow its own policies, agreements, risk appetite, regulatory requirements, and legal or compliance guidance.

Authoritative References

This article is provided for educational purposes and does not constitute legal, regulatory, audit, or compliance advice. Financial institutions should follow their own policies, agreements, risk assessments, and applicable regulatory guidance.