Compliance frameworks, security audits, and quality certifications this company maintains.
Jack Henry & Associates maintains SOC 2 Type II certification across its SilverLake, Symitar, and Banno platforms, providing community bank and credit union clients with independent third-party assurance that Jack Henry's controls protecting customer financial data meet AICPA Trust Service Criteria for security, availability, and confidentiality.
Jack Henry holds PCI DSS Level 1 certification for its JHA PayCenter payments hub and card processing services, satisfying the most rigorous payment card industry security standard and enabling community financial institutions to process debit and credit card transactions without maintaining their own PCI Level 1 compliance program.
Regulatory
FFIEC IT Examination Handbook
CompliantJack Henry's core banking platforms and hosting operations are designed to align with the FFIEC IT Examination Handbook, which governs how federal examiners assess the technology risk management of U.S. banks and credit unions — ensuring that Jack Henry's clients can demonstrate technology governance compliance during FDIC, OCC, and NCUA examinations.
Privacy
GLBA Safeguards Rule
CompliantJack Henry's products and data handling practices comply with the Gramm-Leach-Bliley Act Safeguards Rule, which requires financial institutions and their service providers to implement comprehensive information security programs protecting nonpublic personal financial information of bank and credit union customers.
Regulatory
FedNow Service Certification
CertifiedJack Henry is a certified Federal Reserve FedNow Service provider, having completed the Fed's technical certification program at the July 2023 launch. This certification enables Jack Henry to connect over 1,500 community financial institution clients to the FedNow instant payment rail through JHA PayCenter without each institution undergoing independent Fed certification.
Regulatory
NACHA Operating Rules
CompliantJack Henry's JHA PayCenter ACH processing platform complies with NACHA Operating Rules governing ACH Network transactions, enabling community banks and credit unions to originate and receive ACH credits and debits — including payroll, consumer bill pay, and B2B payments — through a NACHA-compliant infrastructure.
Jack Henry maintains ISO 27001 certification for its information security management system across core banking and payments hosting environments, providing international clients and enterprise bank partners with globally recognized assurance that Jack Henry's security controls meet rigorous third-party standards.
Regulatory
FinCEN BSA/AML Guidelines
CompliantJack Henry's ProfitStars AML and transaction monitoring products are designed to support financial institution compliance with FinCEN's Bank Secrecy Act and Anti-Money Laundering regulations, including automated SAR filing, CTR generation, and customer due diligence workflows aligned to the 2016 FinCEN CDD Rule.
Jack Henry's Banno Digital Platform meets WCAG 2.1 AA accessibility standards, ensuring that the digital banking apps and online banking portals delivered to community bank and credit union customers are accessible to users with visual, motor, and cognitive disabilities — supporting client compliance with ADA digital accessibility requirements.
Security
NIST Cybersecurity Framework
CompliantJack Henry aligns its cybersecurity program to the NIST Cybersecurity Framework (CSF), covering Identify, Protect, Detect, Respond, and Recover functions across its SilverLake, Symitar, and Banno platform environments — enabling community financial institution clients to point to Jack Henry's NIST alignment in their own examiner-facing technology risk disclosures.