We have written about the AI questions examiners are asking in 2026 and what NCUA expects before you deploy AI on member data. Readers of both pieces keep asking for the same follow-up: a checklist a compliance officer can print, walk through with each business owner, and mark up six weeks before the exam starts.

Here it is, organized by exam area rather than by technology topic, because exams follow exam areas. NCUA’s 2026 Supervisory Priorities letter contains no standalone AI section, and the agency’s own AI supervision FAQ confirms there is no AI-specific regulation. Existing rules are technology-neutral, and examiners weigh how you manage the attendant dangers rather than the tool itself. So the questions arrive inside the reviews you already prepare for: third-party oversight, information security, fraud, BSA, and lending.

Work through each section below. An item you can check gets a document reference next to it; anything you cannot check becomes a task with an owner and a date. The marked-up page is your readiness plan.

Area 1: Governance and board oversight

NCUA’s supervision FAQ puts board and management oversight explicitly inside its vendor due diligence expectation for AI. The bar sits well below a bank holding company’s model risk apparatus: evidence that leadership knows what is deployed and reviews it on a schedule clears it.

  • A written AI use policy exists, approved by management, covering sanctioned tools, prohibited uses, and who may approve new ones
  • The board packet includes AI at a defined cadence, even if the agenda item is ten minutes
  • Board minutes show the AI inventory and monitoring results were presented at least twice in the past year
  • One named individual owns the AI program, and that person’s name appears in the policy
  • Employee-facing guidance exists for general-purpose AI tools, so unsanctioned use has a documented answer

The last item deserves extra attention. Examiners understand that staff experiment with public AI tools. What they want to see is a written answer to that reality, ideally one dated well before the exam.

Area 2: The AI inventory

Institutions stumble on the inventory question more than any other, and everything else on this page depends on it. The inventory must include AI features embedded inside vendor products you already run, because your core provider, loan origination system, and fraud platform have all shipped AI capabilities that arrived without a new contract. Our 2026 vendor map walks through how much AI the incumbent tier has switched on this year.

  • A single document lists every AI tool and every AI feature inside existing vendor systems, one line each
  • Each line names the business owner, the workflow, and whether member data is involved
  • Each line notes whether the tool influences a member outcome (a loan decision, a fraud hold, an account restriction)
  • The inventory has a review date within the last quarter and a named maintainer
  • Shadow entries are included: tools staff use informally, captured rather than ignored

If the inventory does not exist yet, build it before touching any other section. It takes one afternoon of interviews and it reorders every other priority on this list.

Area 3: Third-party due diligence

Most AI reaches a credit union through a vendor, so most exam scrutiny arrives through the third-party lens. The governing guidance is not new. Letter to Credit Unions 07-CU-13, Evaluating Third Party Relationships, has told examiners since 2007 to weigh risk assessment, due diligence, and ongoing monitoring against the criticality of the outsourced function. A system that touches member data and influences member outcomes sits at the top of that scale. The AI FAQ adds the specifics: understand how the product functions, what risks it introduces, how it fits your business model, and the vendor’s safeguards and controls.

For each AI vendor on the inventory, the due diligence file should contain:

  • A plain-language description of how the product works and what data it consumes
  • The vendor’s answer, in writing, to whether member data trains models that serve other customers
  • The subprocessor list, including the underlying model provider if the product wraps a frontier model
  • Current SOC 2 Type II or equivalent, reviewed and dated, not just filed
  • Financial condition review appropriate to the vendor’s size and the function’s criticality
  • Contract terms covering data return, deletion with certification, and incident notification within defined hours
  • What happens to your data and any models tuned on it if the vendor is acquired or shuts down

The training question deserves its own emphasis. Some vendors will not put the answer in writing, and that refusal belongs in the diligence file too. If your contracts predate your AI deployments, the renewal cycle is where these terms get fixed, and the exam file should show you know which agreements fall short.

Area 4: Information security and data flows

Technology-neutral regulation means your obligations under Part 748 and its appendices followed the member data into the vendor’s model. The examiner’s question is simple: what leaves your environment, where does it go, and under what protections?

  • A one-page data map exists per AI tool: data elements, destination, retention period, deletion terms
  • Data sent to AI tools is covered by the same classification and handling rules as the rest of the institution
  • Access to AI tools is provisioned and deprovisioned through the standard identity process
  • The incident response plan names AI vendors among the third parties that trigger notification duties
  • Any tool with member PII has encryption in transit and at rest confirmed in the vendor file, not assumed

One page per tool is enough. Long documents in this category tend to go unmaintained, and examiners can tell.

Area 5: Fraud, BSA, and payment systems

The 2026 priorities letter commits NCUA to keeping internal control reviews current with what it calls the ever-changing fraud landscape, and it directs examiners to assess governance, risk assessments, vendor management, and security frameworks supporting payment operations. AI sits on both sides: your detection stack increasingly runs on it, and attackers already use it. NCUA’s AI resource page points institutions to FinCEN’s alert on deepfake media schemes targeting financial institutions.

  • The fraud risk assessment mentions AI-enabled attack methods by name, including deepfake identity media and synthetic voice
  • Identity verification procedures state what happens when staff suspect generated media
  • If AI scores transactions or triages AML alerts, the model’s thresholds and tuning history are documented
  • Alert dispositions influenced by AI are traceable: who reviewed, what the system recommended, what the human decided
  • BSA officer sign-off exists for any AI touching AML workflows, consistent with the risk-based program emphasis in the 2026 letter

Expect the deepfake question even if you have zero AI deployed. Attackers adopted these tools years ahead of most institutions, and examiners know it.

Area 6: Lending and fair lending

If AI touches credit decisions anywhere in the pipeline, this section carries the most regulatory weight per line item.

  • The fair lending analysis covers every model influencing credit decisions, with a refresh date
  • Adverse action notices state specific, accurate reasons that reflect what the model actually used
  • Override authority is defined: who can reverse the system, and every override is logged with a timestamp
  • Model performance is monitored across protected-class proxies where the analysis supports it
  • Second-look procedures exist for declined applications near the threshold

The override log is worth singling out. It is the single most persuasive control artifact an institution can produce, because it shows human review actually happening.

Area 7: Internal controls and ongoing monitoring

The supervision FAQ lists internal controls and ongoing monitoring as core evaluation points. A pilot-era accuracy figure with no refresh date is a finding waiting to be written.

  • Each production tool has a monitoring plan: what is measured, how often, who sees it
  • The last three monitoring readings are on file, with evidence someone reviewed them
  • Escalation triggers are defined in writing: what performance drop or error pattern forces a human decision
  • A model change log exists for vendor-driven updates, so a silent model swap cannot go unexamined
  • Decommissioning is documented for any tool retired this year, including data return

If you ran a structured pilot, most of this exists already. The 90-day pilot plan has institutions open an examiner file on day 15 precisely so production monitoring inherits pilot discipline instead of replacing it.

What this checklist deliberately leaves out

There is no line item for filing anything with NCUA before deployment, because no such filing exists. There is no line item for adopting NIST’s AI framework wholesale, because NCUA’s resource page offers the NIST AI Risk Management Framework as a helpful vocabulary, not an adopted requirement. Proportionality is the standard. A document-routing tool with human review needs about a page of documentation. It does not need a validation team.

Over-preparation is a real failure mode. It stalls useful projects, burns compliance hours on low-risk tools, and produces binders that go stale. The institutions that do well on exams answer “what AI is in use here” with a current inventory, a set of one-page data maps, and monitoring numbers somebody reads every quarter.

Six weeks out: the run order

If the exam date is on the calendar, work the sections in this order: inventory first, then vendor files, then data maps, then monitoring records, then board documentation. Governance paperwork is fastest to fix and lending analysis is slowest, so start any fair lending refresh immediately even though it appears late in the checklist.

The full archive on exam preparation lives in the NCUA and compliance pillar. If you want a second set of eyes before exam week, Advisor Labs runs a 45-minute readiness review against this exact checklist: book a conversation.

Get one substantive analysis like this every week: subscribe to the AiForCU newsletter.