Most compliance-conscious credit union leaders have read NCUA’s AI resource page at least once and walked away with the same reaction: “Okay, but what does this require me to do before I turn on a vendor?” NCUA has been unusually direct on the answer, and that answer is more permissive than most internal compliance debates assume.

So here is the published record, translated into a pre-deployment checklist for any AI vendor engagement that touches member data. Every citation was pulled from ncua.gov. Where a common industry claim is not supported by a specific letter, we say so. Loose citations get repeated into policy documents, and then the policy restricts things the regulator never did.

What NCUA has said

There is one plain-English NCUA source you should read first, and the answer to most of your questions is in it: NCUA’s Artificial Intelligence resource page. Two direct statements from the FAQ on that page frame everything that follows.

First, on whether AI is allowed at all: “Credit unions may use AI tools and technologies. NCUA supports the adoption of technology, including AI, when implemented in a safe, sound, and compliant manner.”

Second, and this is the sentence to underline: “NCUA has not issued AI specific rules or regulation. However, existing regulations are technology-neutral and apply to AI use.”

That framing removes the excuse that “we cannot deploy AI because NCUA has not told us how.” Your obligations are the ones you already have, applied to a new class of tool.

The five supervisory expectations, in NCUA’s own words

The AI resource page’s FAQ explicitly lists what examiners evaluate when a credit union uses AI. Every item on the list is familiar.

  1. Safety and soundness practices.
  2. Compliance with applicable laws and regulations.
  3. Internal controls around the AI tool.
  4. Ongoing monitoring of risks.
  5. Adequate third party due diligence when using vendors.

The FAQ closes that section with a line worth remembering: “AI is not treated differently than any other innovative technology.” The sentence that follows puts the supervisory focus squarely on risk management rather than on the tool itself.

If your compliance conversation is stuck on the tool (“Is this LLM allowed?”), the examiner is going to be somewhere else entirely, asking how you evaluated it and how you are monitoring it.

The pre-deployment checklist

Below is the practical checklist to run before an AI vendor touches member data. Every item traces back either to NCUA’s AI resource page or to an existing NCUA letter or interagency resource that page points to.

1. Third-party due diligence, documented

NCUA’s AI page directs credit unions to two active letters for AI vendor due diligence: Letter 07-CU-13, “Evaluating Third Party Relationships” (December 2007), and Letter 01-CU-20, “Due Diligence Over Third Party Service Providers” (November 2001). Both letters are still active, and both are linked from the AI resource page’s third-party vendor resources section.

01-CU-20 is specific about what a due diligence file should include: planning against the credit union’s strategy, background check on the vendor, legal review of contracts, financial review of the vendor’s statements (audited by a CPA when possible), an ROI projection, and insurance review. 07-CU-13 provides the supervisory framework examiners use, along with an enclosed Supervisory Letter.

For an AI vendor specifically, NCUA’s FAQ lists what “appropriate due diligence” includes: how the product or service functions, risks introduced by the AI technology, how the AI technology fits into the business model, and the vendor’s safeguards, reliability, and controls. That last bullet is the one that gets left out of most vendor files. A decent test: can someone on your team describe the vendor’s controls in their own words, without reaching for the vendor’s marketing deck?

2. Board and management oversight, in writing

The AI resource page states plainly: “The credit union’s board and management must ensure proper oversight to maintain safe and sound operations.” That does not mean the board must approve every tool. Vendor selection can be delegated to management under existing authority. It means the record has to show that the board oversees how AI risk is managed and receives reporting on live systems, even when individual vendor decisions happen at the VP level.

Practically, the record should demonstrate board or senior-management awareness of the credit union’s approach to AI risk, that the approach covers vendor selection, and that reporting on live systems flows up on a defined cadence. An ops-VP approval with no board-visible oversight behind it is the gap examiners will flag.

3. Risk identification, monitoring, and controls

NCUA’s AI FAQ lists three obligations for the operator: identify risks that may be unique to AI or automated tools, monitor and measure those risks regularly, and implement controls to mitigate operational, compliance, and security risks. These are described as “the same as those for any new product or service.”

The “unique to AI” phrase is the one to take seriously. Standard vendor risk assessments do not always cover model drift, prompt injection, hallucinated outputs, or training-data provenance. If your vendor risk template dates from 2020, add an AI-specific supplement. No need to reinvent the whole thing.

4. Information security, unchanged

NCUA’s information security expectations under Part 748 apply whether the data is processed by a human, a legacy core system, or an AI model. The AI resource page reinforces this framing: existing regulations are technology-neutral. If your vendor handles member NPI, all the standard controls apply, including access controls, encryption, incident response, and vendor security due diligence.

For data security posture specifically, the same NCUA resource page links to two joint NSA and CISA information sheets: AI Data Security (May 2025) and Deploying AI Systems Securely (April 2024). Neither is credit-union-specific, but both are worth a CISO or MSSP review before you sign a vendor contract in this space.

5. Fraud posture, including deepfakes

NCUA’s AI page also links to FinCEN’s alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions. First, deepfake fraud is a member-facing risk NCUA specifically points credit unions to, independent of whether you deploy AI internally. Second, your identity verification procedures should be reviewed against the specific red flags in the FinCEN alert. This is not optional reading for anyone owning fraud at a credit union.

6. Model and enterprise-risk framework

For overall governance, the NCUA page points to external frameworks including NIST’s AI resources, Treasury’s equivalent materials, and the COSO paper “Realize the Full Potential of Artificial Intelligence.” None are required. NCUA cites them as available frameworks, nothing more. If you already run an enterprise risk framework, extend it rather than inventing a parallel structure.

What NCUA does not say

Compliance conversations tend to skip this part. Knowing what NCUA has not said saves real time in vendor selection.

  • NCUA does not prohibit generative AI. There is no rule stating that LLMs cannot process member data. The vendor and the use case still have to pass your due diligence and information security review, but the tool class itself is not banned.
  • NCUA does not require an AI-specific policy separate from your existing information security and third-party risk policies. It does require that those existing policies contemplate AI risks. Updating what you have covers it.
  • NCUA’s 2026 supervisory priorities letter does not mention AI at all. The priorities are balance sheet management (lending, market and liquidity risk, earnings and capital), payment systems, fraud, and BSA/AML. AI use gets examined through those existing lenses.
  • NCUA has not published a required AI model risk management standard. The model risk guidance known as SR 11-7 (Federal Reserve and OCC guidance, later adopted by the FDIC) is often cited as a de facto reference by consultants; it applies to banks. Credit unions are not directly bound by it. Adopting elements of it is prudent for larger institutions, but citing it as “required by NCUA” is inaccurate.
  • NCUA’s 2026 Supervisory Priorities letter reaffirms the agency’s “No Regulation by Enforcement” policy. Read it as a posture signal; the rules themselves have not changed. The letter never mentions AI, but the same posture logically extends to novel supervisory issues like AI.

If your compliance team is quoting rules that do not actually exist, that deserves a direct conversation. The usual cost is a pilot that never launches, and nobody tracks those.

Examiner questions to expect

Exam questions are risk-based and set by the examiner in charge, so no list is guaranteed. But based on what NCUA’s AI resource page says examiners evaluate, a credit union operating an AI system on member data should be ready to answer questions along these lines:

  • Who at the credit union owns this AI system, and where is that documented?
  • What third-party due diligence was performed on the vendor, and where is the file?
  • What risks unique to AI (model drift, prompt injection, hallucination, training data provenance, output monitoring) did you identify, and how are you monitoring them?
  • What is the incident response plan if the AI system produces an incorrect or harmful output affecting a member?
  • What board or senior-management-level reporting exists on this system, and when was the last report delivered?

None of these questions require anything not already contemplated by 07-CU-13, 01-CU-20, and Part 748.

What to do this month

If your credit union has an active or planned AI deployment on member data, start with these.

  1. Pull your existing third-party due diligence file for the AI vendor. Compare it to the checklist above. Fill the gaps. The gap analysis itself is about a week of work; closing the gaps depends mostly on how fast the vendor produces documents like SOC 2 reports and audited financials, so start those requests now.
  2. Update the enterprise risk framework to include a short AI section that references NCUA’s AI resource page, 07-CU-13, and 01-CU-20 by name. A short section is enough to start, but it should name the AI-specific risks and the monitoring in place, scaled to what is in production. Pair it with a documented risk assessment for each live system so examiners can see the framework exists and is applied.
  3. Brief the board. Prepare a short pre-read and take a slot at a regular meeting to cover what AI systems are in production or planned, what the risks are, and how the credit union is monitoring them. Put it in the minutes.

If the framework work is more than your team can absorb this quarter, Advisor Labs runs an AI governance review focused on the vendor files, risk framework, and board reporting for credit union AI deployments. Start that conversation here. For the same conversation applied to your specific back-office AI candidates first, see the companion piece on the three-signals test for finding your first AI wins and the NCUA compliance pillar.

For a direct engagement with a working checklist tailored to your institution, book a 45-minute AI readiness audit.

In our experience the credit unions moving fastest on AI in 2026 mostly just read the resource page carefully and updated the files they already had.