NCUA can't examine your AI vendors
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
What happened
In May 2025, the Government Accountability Office published GAO-25-107197, Artificial Intelligence: Use and Oversight in Financial Services. Buried in a report about how regulators supervise AI is a structural fact every credit-union compliance officer should have taped to their monitor: the NCUA does not have authority to examine third-party technology service providers.
The reason is statutory. The Federal Credit Union Act never granted the NCUA the same power the banking regulators have — the ability to examine services performed by third parties on behalf of the institutions they supervise. GAO didn't discover this in 2025; it first recommended that Congress fix it back in 2015 (in GAO-15-509), and it reiterated that recommendation in the 2025 report. As of the report's writing, Congress still had not acted. So the gap that existed a decade ago is the gap that exists today.
GAO is blunt about why it matters now: credit unions already rely on third-party AI models for core functions — data processing, risk management, loan decisions, customer support — and the agency that supervises those credit unions has no line of sight into the vendors delivering that AI.
Why it matters
It's easy to misread a regulator's lack of authority as a break for the regulated. It is the exact opposite. When a banking regulator can examine a technology vendor, the bank gets to lean on that: the examiner has looked at the core processor, the AI provider, the cloud platform, and the bank inherits some assurance from that supervisory reach. Credit unions get none of that. No one with a badge is examining your AI vendors on your behalf — not because the vendors are trusted, but because the NCUA is legally unable to.
So the risk doesn't vanish. It relocates — onto you. Every question a vendor examiner would have asked, every control a supervisor would have verified, is now a question the credit union has to ask and a control the credit union has to verify, or it simply goes unasked and unverified. GAO's finding, read as a compliance officer must read it, says: the diligence gap is real, it is structural, and it is yours to close.
This is the through-line connecting the whole 2026 landscape. The Fed carved generative AI out of its model-risk guidance. Reg S-P gives RIAs a duty but no AI-specific structure. And now GAO confirms the NCUA can't reach your vendors at all. Different corners, same shape: regulators are describing the gap, and the institution is the one standing in it. The AI showing up inside your credit union — much of it arriving through vendors — sits in the least-supervised space on the map, and you own it outright.
What it means for you
If you're a credit union: this is your rule of the road, and the do-this-Monday version is unusually concrete because there's no one else to defer to.
- Stop assuming your examiner has vetted your vendors. They haven't, and they legally can't. Any risk posture that quietly relied on "surely the NCUA would have flagged it" needs to be rebuilt on the assumption that you are the only one looking.
- Inventory the AI reaching you through vendors. Your core processor, your loan-decisioning tools, your member-service chatbots, your fraud and BSA/AML systems — many have added AI you didn't separately approve. Start with an AI data call to find them; you can't diligence what you haven't inventoried.
- Do the diligence proportionally. The NCUA's operative framework here is still 07-CU-13 / Supervisory Letter 07-01 — the agency never adopted the 2023 interagency third-party guidance — and it explicitly lets you scale effort to risk: "reasonable alternative procedures," less analysis for non-complex, non-core vendors. So you don't diligence a scheduling tool the way you diligence your core. You do have to be able to show the judgment. Proportional is not the same as optional.
- Document what you couldn't get. A vendor that won't answer your AI questionnaire is a documented finding you manage, not a hole you hide. Since no examiner will independently verify the vendor, your written record of asking is the evidence.
If you're an RIA, broker-dealer, or bank: the specific statutory gap is a credit-union problem — your regulators have vendor-examination reach the NCUA lacks. But don't get comfortable. The principle GAO is naming — that supervisory reach into AI vendors is thin and the institution carries the diligence — applies to you by degrees. And if you rely on credit-union partners or serve them, their vendor gap can become your counterparty risk.
How to get ahead of it
The prepared credit union turns "no one else can examine our vendors" into "we examine them, and we can prove it." The artifact is a vendor-oversight file built proportionally: for each AI-touching vendor, what it does, what AI it uses, what your diligence found, what you couldn't verify, and how you monitor it. Anchor the depth of each file to 07-CU-13's proportionality — thin for the low-risk, thorough for the core — and anchor the shape to a framework your examiner recognizes, like the NIST AI Risk Management Framework. That combination — proportional depth, recognizable structure — is what turns a pile of vendor emails into an examiner-ready binder.
The leverage is that this file does double duty. It's your NCUA vendor-diligence evidence and the same artifact that would satisfy Reg S-P service-provider oversight if you ever needed it. Build it once, keep it current, and it answers every version of the question.
What to watch out for
The first trap is reading proportionality as permission to do nothing. 07-CU-13 lets you scale down effort for non-core vendors; it does not let you scale it to zero, and "the NCUA can't examine them anyway" is not a documented diligence procedure. An examiner reviewing you — which the NCUA absolutely can do — will look for evidence that you exercised judgment, not evidence that you skipped the work because no one was watching the vendor.
The second trap is the inverse: overbuilding. A credit union with a one- or two-person compliance program cannot run enterprise-grade validation on every vendor, and 07-CU-13 never asked it to. Burning your whole compliance capacity on process theater for a low-risk tool is its own kind of finding — it means the high-risk vendor didn't get the attention.
The honest boundary we'll always name: no assessment, ours included, can examine a vendor the way a supervisor with subpoena power could. We can ask the right questions, verify what's verifiable, and document what a vendor won't disclose — and that closes most of the gap most of the time. But "the vendor declined to answer" is sometimes the truest finding available, and a trust company should say so out loud rather than pretend it saw inside a black box.
The bottom line
The NCUA can't examine your AI vendors — GAO has said so since 2015 and said it again in 2025 — and Congress hasn't fixed it. That's not relief; it's the transfer of the entire vendor-diligence burden onto the credit union, exactly as more AI arrives through those vendors. Getting ahead means doing proportional, documented diligence yourself, on the AI you can't see into — which is precisely the exposure a Discover scan is built to inventory.
Request your Discover scan. We run it with you.