AI Regulation Tracker · NCUA · Letter

What does NCUA Letter 07-CU-13 say about AI in banking?

Published Dec 1, 2007 · Last reviewed Aug 26, 2026

Letter to Credit Unions 07-CU-13, issued in December 2007, is the NCUA's foundational third-party risk guidance and the framework examiners apply to AI vendors today. It requires risk assessment and planning, due diligence (financial condition, controls, contract review), and ongoing monitoring of third-party relationships, with the credit union's board retaining responsibility for outsourced activities.

DocumentNCUA Letter 07-CU-13Evaluating Third Party Relationships
Issued byNational Credit Union Administration
TypeLetter
StatusIn force
PublishedDec 1, 2007
EffectiveDec 1, 2007
Applies toAll federally insured credit unions
Official sourcencua.gov
Use casesThird-party & vendor AI · AI governance (general)

What are the key points of NCUA Letter 07-CU-13?

  • Three-stage framework: risk assessment and planning, due diligence, and risk measurement, monitoring, and control
  • Due diligence covers the vendor's background, business model, financial condition, legal review, accounting, and internal controls
  • Contracts should address performance standards, data security, confidentiality, audit rights, and termination
  • Board and management remain responsible for outsourced activities; outsourcing does not outsource accountability
  • The NCUA's 2025 AI resource page points credit unions back to this due-diligence standard for AI service providers
  • Because the NCUA cannot examine technology vendors directly, this letter is the primary lever over AI supplied by third parties

What did NCUA Letter 07-CU-13 change for banks?

Nothing about AI specifically, but in 2025-2026 this 2007 letter is what NCUA examiners cite when asking how a credit union vetted an AI underwriting model, chatbot, or fraud tool bought from a vendor. Its due-diligence checklist (understand how the product works, what the risks are, what safeguards the vendor has) has become the de facto AI vendor standard for credit unions.

Is 07-CU-13 still the NCUA's third-party guidance?

Yes. It remains posted as current guidance, supplemented by the 2023 Financial Innovation rule that codified due-diligence expectations for indirect lending and loan participations. The NCUA did not join the June 2023 interagency third-party guidance issued by the OCC, Fed, and FDIC.

What does the NCUA expect before a credit union deploys a vendor AI tool?

The 07-CU-13 process: a risk assessment, due diligence on the vendor and the tool (how it works, its risks, the vendor's safeguards), a contract with data-security and audit terms, and ongoing monitoring reported to the board.

DateDocumentStatus
Feb 12, 2026Hauptman Senate testimony (Feb 2026)Written Testimony of NCUA Chairman Kyle S. Hauptman before the U.S. Senate Committee on Banking, Housing, and Urban AffairsFinal
Jan 14, 2026NCUA Letter 26-CU-01NCUA's 2026 Supervisory PrioritiesIn force
Sep 1, 2025NCUA AI Compliance Plan (2025)NCUA Artificial Intelligence Compliance PlanFinal
Aug 1, 2025NCUA Credit Union AI Resource CenterArtificial Intelligence (AI) — Credit Union AI Resource Center and AI Resources pageIn force
Jul 24, 2025NCUA Board AI briefing (Jul 2025)Board Briefing: Artificial Intelligence and Its Use Within the Credit Union Industry and the NCUAFinal
Sep 21, 2023NCUA Financial Innovation Rule (2023)Financial Innovation: Loan Participations, Eligible Obligations, and Notes of Liquidating Credit Unions (final rule)In force

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →