NCUA AI readiness: what examiners will ask, and how to answer
There is no separate "AI exam." In 2026, NCUA evaluates AI through the frameworks you already know — BSA/AML, fair lending, vendor management, and third-party oversight. This guide translates that posture into the questions examiners ask, a vendor-evaluation checklist your team can use tomorrow, and the documentation to have ready.
NCUA's 2026 supervisory posture, in plain terms
NCUA's 2026 supervisory priorities put third-party and AI risk squarely inside existing examination frameworks rather than inventing a new one. Practically, that means:
- AI in origination is a BSA/AML and fair-lending question first. If AI touches who gets an account or a loan, examiners want to see that CIP, OFAC screening, and Reg B adverse-action obligations work exactly as they would without AI — and that decisions are explainable.
- An AI vendor is a third-party vendor. Your TPRM program — due diligence, contracts, ongoing monitoring — is expected to cover AI vendors with the same rigor as your core processor, plus AI-specific items like model governance and data-use commitments.
- The credit union owns the risk. "The vendor's model did it" is not an accepted answer. You need documentation showing you understood what the AI does, set its boundaries, and can oversee it.
The good news: if your vendor management program is sound, AI readiness is an extension of it — not a new discipline.
What examiners ask about AI vendors
Questions credit unions are hearing in exams and pre-exam requests, in roughly the order they come up:
- Which of your vendors use AI, and in which member-facing or decisioning processes?
- What decisions can the AI make or influence without a human? Who approves the rules it operates under?
- How are AI-assisted decisions documented? Can you produce the audit trail for a specific application?
- Is member data used to train the vendor's models, or sent to public AI models? Where is that commitment in writing?
- How do you monitor for fair-lending impact from automated decisioning?
- What happens when the AI is wrong — what's the override and escalation path?
- What did your due diligence on this vendor's AI capabilities include, and when was it last refreshed?
The AI vendor-evaluation checklist
Put these seven items in your due-diligence questionnaire for any AI vendor. The right column shows how Cotribute answers each one — hold every vendor to the same standard.
| Checklist item | What to require | How Cotribute maps |
|---|---|---|
| Model governance | Documented description of what the AI does, its inputs, and who at the vendor owns model changes. | AI Growth Agents operate under documented governance; decisioning runs on 70+ configurable rules your institution approves, so every decision is explainable rule by rule. |
| Human-in-the-loop | Named checkpoints where a human approves or can intervene — structural, not a settings toggle. | All 3 AI Growth Agents (in production since June 2025) are human-in-the-loop by design; your staff and configured rules make the decisions. |
| No autonomous actions | Written confirmation the AI cannot act outside institution-approved rules. | No autonomous actions — agents recommend and prepare; nothing executes outside the rules your institution configured. |
| Audit trails | Per-decision logs, exportable in examiner-ready form, with defined retention. | Every application decision is logged; MCP Connect queries are individually audited with 7-year retention. |
| Data boundaries | Explicit statement of where member data goes, with PII controls. | No member data in public AI models; MCP Connect is read-only with PII masked by default. |
| No-train commitments | Contractual commitment that your data never trains shared or third-party models. | Member data is never used to train shared models — committed contractually, not just in marketing. |
| SOC 2 & right-to-audit | Current SOC 2 Type 2 report and audit rights in the contract. | SOC 2 Type 2 certified; report, architecture overview, and pre-filled questionnaire delivered in the due-diligence package. |
FAQ
ComplianceDoes NCUA have a dedicated AI regulation we need to comply with?
No. As of 2026, NCUA evaluates AI through existing frameworks — BSA/AML, fair lending, vendor management, and third-party oversight — rather than a standalone AI rule. That's why AI readiness is mostly vendor-management readiness: if you can evidence due diligence, boundaries, and oversight, you're answering the questions examiners actually ask.
ComplianceDo we need board approval to use AI in origination?
Treat it like any material third-party relationship: board or committee visibility into the risk assessment, and policy coverage for automated decisioning. Many credit unions add a short AI addendum to their vendor management policy covering model governance, data use, and human oversight — the checklist on this page maps to that addendum.
ComplianceHow do we evidence fair-lending compliance with automated decisioning?
Explainability is the foundation: every automated decision should trace to specific, institution-approved rules, with adverse action notices carrying accurate reason codes under Reg B. Rules-based decisioning your credit team configures — rather than an opaque model score — makes that evidence straightforward to produce, and your existing fair-lending monitoring applies unchanged.
ComplianceWhat should we ask an AI vendor before signing?
Use the seven-item checklist above: model governance, human-in-the-loop design, no autonomous actions, audit trails, data boundaries, no-train commitments, and SOC 2 with right-to-audit. Require the answers in writing — in the contract or the diligence file — because "in writing" is what counts at exam time.
CEOIs examiner scrutiny a reason to wait on AI?
Waiting doesn't reduce the scrutiny — examiners increasingly ask about AI whether or not you've adopted it, because your vendors already use it. The differentiator is governance: institutions that adopt AI with documented oversight tend to have easier exam conversations than those discovering mid-exam that a vendor quietly added AI features.
Disclaimer: This guide is educational and reflects general supervisory trends as of 2026. It is not legal advice, and it doesn't substitute for guidance from your compliance counsel or your NCUA examiner.
Put the checklist to work
Request Cotribute's due-diligence package and score us against every item — or bring your compliance team to the conversation.
