Letter to Credit Unions 07-CU-13, issued in December 2007, is the NCUA's foundational third-party risk guidance and the framework examiners apply to AI vendors today. It requires risk assessment and planning, due diligence (financial condition, controls, contract review), and ongoing monitoring of third-party relationships, with the credit union's board retaining responsibility for outsourced activities.
| Document | NCUA Letter 07-CU-13 — Evaluating Third Party Relationships |
| Issued by | National Credit Union Administration |
| Type | Letter |
| Status | In force |
| Published | Dec 1, 2007 |
| Effective | Dec 1, 2007 |
| Applies to | All federally insured credit unions |
| Official source | ncua.gov ↗ |
| Use cases | Third-party & vendor AI · AI governance (general) |
What are the key points of NCUA Letter 07-CU-13?
- Three-stage framework: risk assessment and planning, due diligence, and risk measurement, monitoring, and control
- Due diligence covers the vendor's background, business model, financial condition, legal review, accounting, and internal controls
- Contracts should address performance standards, data security, confidentiality, audit rights, and termination
- Board and management remain responsible for outsourced activities; outsourcing does not outsource accountability
- The NCUA's 2025 AI resource page points credit unions back to this due-diligence standard for AI service providers
- Because the NCUA cannot examine technology vendors directly, this letter is the primary lever over AI supplied by third parties
What did NCUA Letter 07-CU-13 change for banks?
Nothing about AI specifically, but in 2025-2026 this 2007 letter is what NCUA examiners cite when asking how a credit union vetted an AI underwriting model, chatbot, or fraud tool bought from a vendor. Its due-diligence checklist (understand how the product works, what the risks are, what safeguards the vendor has) has become the de facto AI vendor standard for credit unions.
Is 07-CU-13 still the NCUA's third-party guidance?
Yes. It remains posted as current guidance, supplemented by the 2023 Financial Innovation rule that codified due-diligence expectations for indirect lending and loan participations. The NCUA did not join the June 2023 interagency third-party guidance issued by the OCC, Fed, and FDIC.
What does the NCUA expect before a credit union deploys a vendor AI tool?
The 07-CU-13 process: a risk assessment, due diligence on the vendor and the tool (how it works, its risks, the vendor's safeguards), a contract with data-security and audit terms, and ongoing monitoring reported to the board.
| Date | Document | Status |
|---|---|---|
| Feb 12, 2026 | Hauptman Senate testimony (Feb 2026) — Written Testimony of NCUA Chairman Kyle S. Hauptman before the U.S. Senate Committee on Banking, Housing, and Urban Affairs | Final |
| Jan 14, 2026 | NCUA Letter 26-CU-01 — NCUA's 2026 Supervisory Priorities | In force |
| Sep 1, 2025 | NCUA AI Compliance Plan (2025) — NCUA Artificial Intelligence Compliance Plan | Final |
| Aug 1, 2025 | NCUA Credit Union AI Resource Center — Artificial Intelligence (AI) — Credit Union AI Resource Center and AI Resources page | In force |
| Jul 24, 2025 | NCUA Board AI briefing (Jul 2025) — Board Briefing: Artificial Intelligence and Its Use Within the Credit Union Industry and the NCUA | Final |
| Sep 21, 2023 | NCUA Financial Innovation Rule (2023) — Financial Innovation: Loan Participations, Eligible Obligations, and Notes of Liquidating Credit Unions (final rule) | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →