Guide · Agentic AI

Agentic AI for credit unions: use cases, controls, and ROI

An AI agent does not just answer. It plans a task, calls other systems, and completes steps on its own. For a credit union, that means real work can move faster: call report preparation, loan conditions, document checks, and member service queues. It also means software can now change records. This guide covers where agents fit first, how to choose between building, buying, or working through a CUSO, the controls an examiner will expect, and how to measure the return.

What makes AI agentic?

Three things separate an agent from a chatbot or a scoring model.

  • It works toward a goal. It breaks a task into steps and decides the next one.
  • It uses tools. It reads from and writes to other systems: the core, the loan origination system, the document store, email.
  • It acts without a prompt for each step. A person sets the task. The agent carries it forward.

The third point is where the risk sits. A chatbot that gives a wrong answer is a quality problem. An agent that takes a wrong action is an operational event.

Where do agents fit first at a credit union?

Start where the work is high-volume, rule-bound, and already checked by a person. Good first candidates:

  • Regulatory reporting. 5300 call report preparation, variance explanations, and the supporting schedules finance builds each quarter.
  • Lending operations. Collecting stipulations, checking documents against conditions, and drafting status updates for members and loan officers.
  • Document intelligence. Reading pay stubs, tax returns, and statements, then routing exceptions. Test the extracted data before anyone relies on it.
  • Records and document storage. Classifying documents, applying retention schedules, and flagging files that hold member information under Part 748.
  • Member service queues. Card disputes, address changes, and back-office tickets where the agent drafts and staff decide.
  • Data warehouse upkeep. Reconciling feeds from the core, cards, and lending into the credit union data warehouse, and flagging breaks before reports run.

Leave member-facing credit decisions and account changes without review for later. They need the strongest controls and the clearest audit trail.

Can an agent prepare the 5300 call report?

It can prepare the work. It should not certify or file it. A practical design has four steps:

  1. The agent pulls balances from the core and general ledger.
  2. It maps each balance to the 5300 account codes, using a mapping your finance team owns and approves.
  3. It runs the variance and edit checks the team already uses, and drafts plain-language explanations for large quarter-over-quarter changes.
  4. A person reviews, corrects, certifies, and files.

Log every mapping and every check the agent ran. An examiner should be able to trace any reported figure back to its source.

There is a second reason to care about call report data. AI assistants now search for credit union financials on behalf of members, partners, and analysts. They pull total assets and peer comparisons straight from public 5300 data. Accurate, timely filings now shape what those assistants say about your credit union.

Build, buy, or work through a CUSO?

Most credit unions will not build agents from scratch. There are three routes:

  • Buy from your core or a fintech. Fastest to start. You inherit the vendor’s design choices, so diligence carries most of the risk work.
  • Work through a CUSO. A technology CUSO can spread the cost of building, testing, and monitoring agents across many credit unions. Confirm who owns the controls, who holds the logs, and how each owner credit union gets audit access.
  • Build in-house. Makes sense only for larger credit unions with engineering staff and a process no vendor serves well.

Whichever route you take, NCUA lacks authority to examine technology service providers. Your own diligence file is the main evidence of oversight. The AI vendor due diligence guide covers what belongs in it.

How should you judge an agent framework?

Technical teams compare open-source frameworks such as LangGraph, CrewAI, and AutoGen. Each takes a different approach. LangGraph models a task as a graph of steps with saved state. CrewAI organizes agents into teams with defined roles. AutoGen coordinates agents through conversation. It is now in maintenance mode, and Microsoft points new users to its Agent Framework instead. For a credit union, popularity is the wrong test. Ask four questions instead:

  1. Can it pause for a person? Consequential actions need a built-in approval step, not a workaround.
  2. Does it keep durable state? If a run fails halfway, you need to know what already happened.
  3. Can you log every step? Every tool call, input, and output, kept for your retention period.
  4. Can you limit its tools? Each agent should reach only the systems and actions its task needs.

If you buy, ask the vendor which framework and which foundation model sit under its agents. Both affect what you can verify, and either can change without a release.

Which controls will an examiner expect?

The April 2026 interagency model risk guidance (SR 26-2) excludes generative and agentic AI from its scope. That leaves the work to you, not out of scope. Six controls cover most of it:

  • An agent inventory. Each agent, its owner, its task, its data, and the systems it can touch.
  • Autonomy tiers. A written line between actions the agent may take alone, actions that need approval, and actions it may never take.
  • Least-privilege access. Service accounts scoped to the task, never a staff member’s credentials.
  • Complete logs. Enough to rebuild what the agent did and why.
  • A stop switch. A tested way to halt an agent within minutes.
  • Incident handling. A path into your existing process, including NCUA’s 72-hour cyber incident reporting where it applies.
Autonomy tiers in motion. Press the stop switch to halt the agent.

Illustration. Your credit union writes the line between the lanes for each agent.

Report agent activity to the board with the rest of your AI program. The board AI reporting guide shows a format.

How do you measure agentic AI ROI?

Measure cost per completed task, before and after. Most agentic AI ROI calculators leave out costs that matter at a credit union. Count all of them:

  • Model and platform fees, which grow with volume.
  • Staff time spent reviewing and approving agent work.
  • Rework when the agent is wrong.
  • One-time cost of process redesign, controls, and testing.

Count only benefits you can see: backlog cleared, hires not needed, faster loan cycle times, or fewer exceptions. Time saved that is not redeployed is not a return. Report the result next to error rates and member complaints, so the board sees speed and quality together.

What should an agentic AI RFP ask?

Add these to your credit union software RFP when the product includes agents:

  • Which actions can the agent take without human approval? Can we change that line?
  • Which framework and foundation model do you use? Will you notify us before either changes?
  • What does the agent log, where is it stored, and how long do we keep access?
  • How do we stop the agent, and how fast?
  • Does member data train any model? Under what terms?
  • What error and override rates do current credit union clients see?

To shorten the research step, Depository360 profiles more than 250 AI vendors and the CUSOs that serve credit unions.

Frequently asked questions

What is agentic AI at a credit union?

Agentic AI is software that plans and completes a multi-step task by calling other systems, not only answering a question. At a credit union, an agent might gather loan documents, check them against conditions, draft a status update, and queue the file for an underwriter. The credit union decides which actions it may take alone and which need a person to approve.

Can agentic AI prepare the NCUA 5300 call report?

It can prepare the work, not sign it. An agent can pull balances from the core and general ledger, map them to 5300 accounts, run the variance checks your finance team already uses, and draft explanations for large quarter-over-quarter changes. A person reviews, certifies, and files. The agent’s mapping and checks should be logged so an examiner can trace each figure.

Does SR 26-2 cover agentic AI?

No. The April 2026 interagency model risk guidance excludes generative and agentic AI from its scope. That does not remove the risk. Credit unions still need their own controls for agents: an inventory, limits on what each agent can do, human approval for consequential actions, logging, and a way to stop an agent quickly.

Should a credit union choose LangGraph, CrewAI, or AutoGen?

Most credit unions should not choose a framework directly. They will buy agents from a core provider, fintech, or CUSO. If you build, choose on audit needs, not popularity: durable state, a full log of every step, and a built-in pause for human approval. Ask any vendor which framework and which foundation model sit under its agents, because both affect what you can verify.

How should a credit union measure agentic AI ROI?

Measure cost per completed task before and after. Include model and platform fees, staff review time, rework when the agent is wrong, and the one-time cost of process redesign and controls. Count only time that is redeployed or avoided, such as backlog cleared or hires not needed. Report the result to the board next to error and complaint rates.

This guide is general information, not legal advice. Regulatory references reflect public guidance as of October 10, 2026. Confirm current requirements with your counsel and examiner.