NCUA has not published a list of questions examiners will ask about AI. Its supervisory priorities letters for 2025 and 2026 do not mention AI at all. What NCUA has said, on its own AI resource page, is that it supervises AI within the existing supervisory framework and that examiners evaluate the same things they evaluate for any technology: safety and soundness practices, compliance with law, internal controls around the tool, ongoing monitoring of risks, and third-party due diligence. So the practical answer is that you should expect the ordinary questions, applied to staff use of AI, and keep the records that answer them.
What has NCUA actually said about AI and examinations?
Two things are worth separating. The first is silence. NCUA’s 2026 supervisory priorities letter (26-CU-01) and its 2025 letter (25-CU-01) both name cybersecurity and third-party risk management as priorities, and neither uses the words “AI” or “artificial intelligence.” If a vendor tells you NCUA named AI as an examination focus in those letters, the letters do not say so.
The second is a direct statement. NCUA’s AI resource page, last modified April 28, 2026, includes frequently asked questions about how NCUA supervises AI. It says NCUA has not issued AI-specific rules, that existing regulations are technology-neutral and apply to AI use, and that “NCUA supervises AI within the existing supervisory framework.” Examiners evaluate:
- safety and soundness practices,
- compliance with applicable laws and regulations,
- internal controls around the AI tool,
- ongoing monitoring of risks, and
- adequate third-party due diligence when using vendors.
The page adds that credit unions are expected to identify risks that may be unique to AI or automated tools, monitor and measure those risks regularly, and implement controls to mitigate operational, compliance, and security risks, the same expectations as for any new product or service. For an AI vendor, it says a credit union must conduct appropriate due diligence, including understanding how the product functions, the risks the AI introduces, how it fits the business model, and the vendor’s safeguards, reliability, and controls, and that the board and management must ensure proper oversight.
What did GAO find?
In GAO-25-107197, published May 19, 2025, the Government Accountability Office reviewed how financial regulators oversee AI. On NCUA it found that the model risk management guidance in NCUA’s examiner guide “addresses only interest rate risk modeling” and “does not have sufficient detail to ensure examiners and credit unions follow key risk management practices, including those related to managing risks from AI models.” It also reported that NCUA lacks the authority to examine technology service providers, despite credit unions’ increasing reliance on them for AI-driven services. GAO recommended that NCUA update its model risk management guidance to cover a broader variety of models, and NCUA generally agreed.
Read that carefully. It concerns NCUA’s guidance on models, and it is a 2025 report. It does not describe what an examiner will ask about staff using a chat assistant or a coding tool today. What it does tell you is that NCUA’s AI-specific guidance is still developing, which is one more reason to prepare for the standing questions rather than a published checklist.
Which existing rules would those questions rest on?
The rule most likely to carry them is Appendix A to 12 CFR Part 748, the guidelines for safeguarding member information. It does not mention AI. But it asks for a board-approved written information security program, a risk assessment that identifies reasonably foreseeable internal and external threats, controls the credit union concludes are appropriate (its examples include access controls and monitoring systems), staff training, regular testing of key controls, due diligence and contract terms for service providers, and an annual report to the board covering, among other things, risk management and control decisions, service provider arrangements, and results of testing.
Which of those an examiner applies to staff AI use, and how, is our inference from NCUA’s statement that its rules are technology-neutral. It is not a quotation from any examination procedure, and it is not a prediction of any one examiner’s questions.
What records should a credit union keep of staff AI use?
Start from the questions above and ask what would answer each one. The table is a working list, not a rule. No NCUA regulation we read sets a retention period for AI records: Part 749, the vital records preservation program, is about identifying, storing, and reconstructing vital records if they are destroyed, and it says it does not supersede records preservation requirements under other law. Your counsel sets how long you keep any of this.
| A question an examiner could ask | A record that helps answer it |
|---|---|
| Which AI tools do staff use? | An inventory, plus a record of actual use, since a list of approved tools does not show what people did |
| Who approved a tool, and on what terms? | The approval decision, the vendor due diligence file, and the contract |
| What may staff put into it? | The written policy, its approval by the board or a committee, and training records |
| Do the controls work? | Test results and a record of what the controls flagged or refused |
| What did the board see? | The annual report to the board, including AI use and any service provider arrangements |
The middle rows are documents you write once and update. The first and fourth rows are different, because they describe what happened on ordinary days, and they only exist if something recorded it when it happened. That is the gap most credit unions will find first: a policy on paper, and no record of what staff did under it.
Where Verillian fits
Verillian governs AI use on the devices you enroll. A checkpoint on each device sits between your people’s AI tools and agents and the AI providers it supports. For Claude and Claude Code traffic (the Anthropic API format), a tool call your policy bans is removed before your machine can run it; for the other supported providers, it screens and records the usage, and the Claude desktop app and Cursor are recorded only, with no redaction. Each record is signed on the device it came from and hash-chained to the one before it, so a change to its signed fields is detectable, and it stays on your own infrastructure. It cannot show that nothing was omitted. Redaction is best-effort, not a guarantee that every value is caught. The admin server runs where you choose: on-prem or in a private cloud you run. macOS is the supported install today; Windows has an interim scripted installer and Linux builds from source. For a credit union, that record can help show which AI services were used on enrolled devices, attributed to the user and device the checkpoint reports, and when, which supports the first and fourth rows above. On a fresh install the checkpoint detects and flags values such as a Social Security number or a credit card number without changing traffic; an administrator has to set redaction on, and a redacted Social Security number leaves the device as [US_SSN_REDACTED]. Every captured interaction is signed into the record, and anything the checkpoint never saw is not in it. The architecture is aligned with the safeguards Appendix A expects, not certified, because Appendix A sets standards for the credit union’s own program and no certification of a product exists under it.
Verillian does not see inside a vendor’s own cloud. When a vendor’s service calls a model on the vendor’s servers, as an AI feature inside member-service software does, the record of what that model received is created on the vendor’s side, and the contract is your lever for it. What Verillian gives you is the record of AI use that starts on your own devices.
For what a record has to contain to be worth keeping, see what an AI audit trail is. The related question of what staff may paste into a public chat tool is covered in can credit union staff put member data into ChatGPT, and the platform page covers how policy is applied.
Sources
- NCUA Letter to Credit Unions 26-CU-01, NCUA’s 2026 Supervisory Priorities, January 2026, and 25-CU-01, NCUA’s 2025 Supervisory Priorities, January 2025.
- NCUA, Artificial Intelligence (AI) resources, including Frequently Asked Questions About NCUA’s Supervision of AI, last modified April 28, 2026.
- GAO, GAO-25-107197, Artificial Intelligence: Use and Oversight in Financial Services, May 19, 2025.
- 12 CFR Part 748, Appendix A, Guidelines for Safeguarding Member Information, and 12 CFR Part 749, Vital Records Preservation Program.
