Guide · AI governance

AI governance for credit unions: a practical guide

A credit union AI governance program has five parts: an inventory of every AI use, a risk tier for each use, controls sized to that tier, due diligence on the vendors behind each use, and a recurring board report. NCUA has no AI-specific rule. Examiners reach AI through duties you already have: information security, third-party oversight, lending compliance, and BSA. This guide shows how to build each part without creating a new bureaucracy.

What is AI governance at a credit union?

AI governance is the set of decisions, roles, and controls that determine which AI uses your credit union allows, who owns each one, and how you check that it works as intended.

It is not a separate program. It extends the enterprise risk management, information security, and vendor management work you already do. The goal is simple: management can explain every AI use to the board, to an examiner, and to a member.

AI governance covers three kinds of AI:

  • Predictive models that score or classify, such as credit decisioning, fraud detection, and member attrition models.
  • Generative AI that writes or summarizes, such as chat assistants, call summaries, and staff copilots.
  • Agentic AI that takes actions across systems, such as an agent that opens a case, updates a record, or starts a workflow.

Each kind carries different risks. Agentic AI needs the tightest limits, because it acts without a person at each step.

Does NCUA have rules for AI?

No. As of October 2026, NCUA has not issued an AI-specific regulation or supervisory letter. That does not put AI outside the exam.

  • Information security. NCUA Part 748 and its Appendix A require a written information security program that protects member information. An AI tool that touches member data is inside that program.
  • Third-party oversight. NCUA expects due diligence and ongoing monitoring of service providers. Letter to Credit Unions 07-CU-13, Evaluating Third Party Relationships, is the core reference. Most credit union AI arrives through vendors.
  • Supervisory priorities. NCUA’s 2026 Supervisory Priorities letter (26-CU-01) does not list AI as its own priority. It does name third-party risk management, payment fraud controls, and BSA program effectiveness. AI shows up inside each of those.
  • Resources. NCUA keeps an AI resource page, updated in December 2025, that collects federal references on AI risk, vendor diligence, and cybersecurity.

One gap matters. NCUA cannot examine technology service providers directly. The Government Accountability Office noted this in a May 2025 report (GAO-25-107197) and recommended that NCUA update its model risk guidance. The practical effect: your own vendor diligence is the main evidence an examiner will see.

What belongs in an AI inventory?

Every AI use, including AI built into products you already own. First inventories often miss many uses, because core, lending, fraud, and contact-center platforms now ship AI features by default.

Look in four places: vendor contracts and release notes, the IT asset list, staff surveys on tool use, and expense reports for software subscriptions.

Record these fields for each use:

  • Name and business purpose
  • Business owner (a named person, not a department)
  • Vendor and any underlying model provider
  • Type: predictive, generative, or agentic
  • Data used, and whether it includes nonpublic member information
  • Decision role: informs, recommends, or decides
  • Whether members see the output or feel its effect
  • Date approved and date of last review

How should a credit union tier AI risk?

Use three tiers. Score each use on five factors: member impact, data sensitivity, decision weight, autonomy, and how easily a mistake can be reversed.

TierTypical usesWhat puts a use here
HighCredit decisioning, account opening, fraud blocks, agents that change records or move moneyAffects a member’s access, price, or funds; shares member data externally; acts without a person in the loop
ModerateCall summaries, collections prioritization, marketing segmentation, member-facing chat that answers but does not decideShapes decisions that a person reviews, or produces member-facing content
LowDrafting internal documents, code assistance, meeting notes with no member dataInternal productivity; no member data; easy to correct
The uses from the table, sorted into tiers.

When a use sits between two tiers, pick the higher one. Re-tier a use when its scope, data, or vendor model changes.

Which controls fit each tier?

Controls should follow the tier. Heavy controls on low-risk tools waste staff time and push people toward unapproved tools.

  • High: a named owner; testing before go-live for accuracy and, for credit, fair lending outcomes; a defined human sign-off point; monitoring against set thresholds; review at least once a year; an incident playbook; a line in the board report.
  • Moderate: a named owner; testing before go-live; periodic review; a clear rule for when staff must check the output.
  • Low: the acceptable use policy, data handling rules, and staff training.

One control applies to every tier: no nonpublic member information goes into an AI tool the credit union has not approved.

Who should own AI governance?

Use the structure you have. Most credit unions do not need a chief AI officer.

  • Board: approves the AI risk appetite and the AI policy, and receives regular reporting.
  • Management committee: an existing ERM, IT steering, or risk committee approves high-tier uses and policy exceptions.
  • Business owners: answer for the results of each AI use they sponsor.
  • Risk and compliance: review high-tier uses, vendor diligence, and fair lending testing.
  • Internal audit: tests whether the program works as written.

Name one executive, often the chief risk officer, as the accountable lead. Shared ownership with no lead is the most common failure I see.

What should a credit union AI policy say?

Keep it short. Five to eight pages is enough for most credit unions. It should cover:

  1. Scope and definitions, including predictive, generative, and agentic AI
  2. Acceptable use rules for staff, including approved tools and banned data
  3. The approval path for each risk tier
  4. Minimum vendor requirements, linked to your vendor management policy
  5. Testing, monitoring, and review cycles by tier
  6. Incident handling, including how AI incidents feed cyber incident reporting to NCUA
  7. Roles, and the committee that owns exceptions
  8. Board reporting and the policy review date

How can a credit union start in 90 days?

  • Days 1–30: Publish an interim acceptable use rule for staff. Build the first inventory.
  • Days 31–60: Tier every use. Run diligence on the vendors behind high-tier uses. Fix the largest gaps first.
  • Days 61–90: Approve the AI policy and risk appetite. Deliver the first board AI report.

After 90 days, the work becomes routine: quarterly reporting, an annual policy review, and diligence when a new use or vendor arrives.

Frequently asked questions

Does NCUA require credit unions to have an AI policy?

No NCUA rule requires a standalone AI policy. Part 748 does require a written information security program that protects member information, and NCUA expects oversight of third-party service providers. An AI policy is the clearest way to show how those duties apply to AI.

Does the new interagency model risk guidance apply to credit unions?

No. SR 26-2, issued in April 2026, came from the Federal Reserve, OCC, and FDIC. NCUA did not join it. It also excludes generative and agentic AI. Credit unions can still use its principles, such as model inventory, validation, and ongoing monitoring, as a reference for predictive models.

How large must a credit union be to need AI governance?

Size changes the depth, not the need. If staff use generative AI tools or vendors embed AI in your systems, you have AI risk. A small credit union may need only a short policy, an inventory, and a quarterly line in the board report.

Who should lead AI governance at a credit union?

One named executive, often the chief risk officer, should be accountable. An existing risk or IT steering committee can approve high-risk uses. The board approves the policy and risk appetite.

How long does it take to set up an AI governance program?

About 90 days for the core: an inventory, risk tiers, an approved policy, diligence on high-risk vendors, and a first board report.

This guide is general information, not legal advice. Regulatory references reflect public guidance as of October 10, 2026. Confirm current requirements with your counsel and examiner.