Guide · Board oversight

Board AI reporting for credit unions and banks

A board AI report should answer three questions every quarter: what AI is in use, what changed, and what is outside tolerance. It fits on two pages. Directors need enough to oversee risk and challenge management. They do not need model details.

What is the board responsible for with AI?

The board sets direction and oversees management. It does not run the AI program. For AI, that means four duties:

  1. Approve the AI risk appetite.
  2. Approve the AI policy, or the sections of existing policies that cover AI.
  3. Receive regular reporting and challenge management on it.
  4. Make sure directors know enough about AI to do the first three.

These duties sit on top of existing ones. Under NCUA Part 748 Appendix A, a credit union’s board or a board committee approves the written information security program and oversees it. Bank boards have the same duty under the Interagency Guidelines Establishing Information Security Standards. AI that touches member or customer data falls inside those programs.

How should a board set AI risk appetite?

Write plain statements that management can test. Examples:

  • We do not let AI make a final credit denial without human review.
  • No nonpublic member information enters an AI tool we have not approved.
  • AI agents may not move funds or change account ownership without human approval.
  • Every AI use that affects members has a named owner and a review date.

Pair each statement with a tolerance and a metric. For example: zero high-risk uses more than 30 days past their review date.

What should a quarterly AI report include?

Two pages. The first page is a dashboard. The second is a short narrative.

Page one: the dashboard

  • AI uses in the inventory, by risk tier, with new and retired uses this quarter
  • Key risk indicators against tolerance, each with a red, amber, or green status
  • AI-related incidents, near misses, and member complaints
  • Material vendor changes, such as a new model provider
  • Policy exceptions granted and open remediation items
  • Value delivered against the business case

Page two: the narrative

  • What changed and why it matters
  • Decisions the board needs to make
  • One topic in more depth, such as a new high-risk use or an exam finding

Which metrics belong in a board AI report?

Pick eight to ten. Track the same ones every quarter so the trend is visible.

MetricWhat it shows
Share of AI uses with a named owner and a current reviewControl coverage
High-risk uses past their review dateControl slippage
Model performance against thresholdAccuracy and drift
Fair lending test results for credit modelsDiscrimination risk
AI-related incidents and near missesOperational risk
Member complaints tied to automated decisions or chatMember impact
Material vendor model changes receivedThird-party risk
Staff completion of AI acceptable use trainingUnapproved tool risk
Hours saved, losses avoided, or service gainsBusiness value

Include value metrics. A board that sees only risk will either block AI or stop asking questions. Neither is good governance.

What questions should directors ask management?

  1. What AI do we use today, including AI inside vendor products?
  2. Which uses affect members or customers directly?
  3. Who owns each high-risk use?
  4. How do we know each high-risk use works as intended?
  5. What member data do our AI vendors receive, and can they train on it?
  6. What would we tell an examiner about our AI oversight today?
  7. Where are staff using AI tools we have not approved?
  8. What value has AI delivered against its cost?

How often should the board receive AI reporting, and from whom?

Quarterly to the risk or audit committee. At least once a year to the full board, alongside the policy and risk appetite review.

The accountable executive presents, often the chief risk officer. Internal audit covers AI governance in its own plan, so the board also hears an independent view.

Report off cycle when a high-risk AI incident occurs or an exam produces an AI-related finding.

One year of board AI reporting.

The accountable executive presents. Internal audit adds an independent view.

How do directors build enough AI knowledge?

Hold a focused AI briefing at least once a year. Cover the institution’s own AI uses, not general trends. Record the session in the minutes. That record shows examiners that directors are prepared to oversee the topic.

I run these as single-session board and leadership AI briefings.

Frequently asked questions

How often should a credit union board receive AI reporting?

Quarterly to the risk or audit committee, and at least once a year to the full board. Report off cycle after a high-risk AI incident or an AI-related exam finding.

What is an AI risk appetite statement?

It is a short, board-approved statement of how much AI risk the institution will accept. For example: no AI makes a final credit denial without human review. Each statement should have a tolerance and a metric.

Should the board approve every AI tool?

No. The board approves the policy and risk appetite. Management approves individual uses inside those limits. The board sees new high-risk uses in its regular report.

How long should a board AI report be?

Two pages: a one-page dashboard with the inventory, risk indicators, incidents, and value, and a one-page narrative on changes and decisions needed.

What metrics should a board AI report include?

Eight to ten, tracked every quarter: control coverage, overdue reviews, model performance, fair lending results, incidents, member complaints, vendor model changes, training completion, and business value.

This guide is general information, not legal advice. Regulatory references reflect public guidance as of October 10, 2026. Confirm current requirements with your counsel and examiner.