Leave with the binder, not a badge.
A role-based program for the people who decide which AI a credit union may use, under what conditions, and how it proves it: boards, compliance, risk, security, vendor management, IT and audit.
- lessons across all tiers
- 40lessons across all tiers
- labs
- 11labs
- evidence binder elements
- 8evidence binder elements
- obligations and security controls mapped to lessons
- 63 + 40obligations and security controls mapped to lessons
There is no AI rule for credit unions. That doesn't mean AI is unsupervised.
NCUA says it has not issued AI-specific rules and applies existing, technology-neutral ones. Its AI page also names five things examiners evaluate when a credit union uses AI. Supervisory guidance
- Existing duties still reach AI, such as the written security program (12 CFR 748.0) and the 72-hour cyber incident notice (12 CFR 748.1(c)). Binding rule
- Guidance can't be cited as a violation (12 CFR part 791, subpart D). Binding rule
- An unsafe or unsound practice can be acted on (12 U.S.C. 1786). Statute
- Safety and soundness practices
- Compliance with applicable laws and regulations
- Internal controls around the AI tool
- Ongoing monitoring of risks
- Adequate third-party due diligence when using vendors
Source: NCUA AI page, FAQ updated 28 April 2026. Source-check date 28 September 2026.
Not legal advice. This page describes in general terms how existing rules and guidance apply to AI. Whether a rule reaches your credit union is a question for your counsel. Read the full note.
What could you honestly show today?
Five questions every board should ask about AI. Mark each one evidenced, asserted or unknown, and see where the binder would start.
A snapshot of what you could show, not a prediction of any exam outcome. Most leaders mark more asserted and unknown answers than they expect. That is the starting point.
- What AI do we run, and how do we know?
- Which of it touches member decisions or member data?
- What does each AI vendor do with our data, and how fast would it tell us about an incident?
- What is our 72-hour plan for an AI incident?
- What would make us stop using an AI tool, and who decides?
One academy, organised by role.
AI oversight is cross-functional, so the program is too. The board session frames it, the Core builds the evidence, and specialist and builder tracks add depth.
- CU-AIG-00 · 90 MIN
Boards and executives
What binds your AI, the five questions, and three recorded decisions. Attending is not a vote.
- CU-AIG-01 · 6 WEEKSFLAGSHIP
AI Oversight Core
A team of 6–12. Twelve 20-minute lessons, five 75-minute working sessions, two labs, and your own E1–E8 binder.
- S1–S8 · 3.5 H EACH
Specialist modules
Security, lending, member-facing AI, vendors, HR, marketing, audit, fraud and BSA. Each ends in one artifact.
See the modules → - B1 · BUILDERS
Compliant by Design
For the people who build or configure AI: an acceptance-test pack and a pre-release evidence record.
See the modules →
Staff who use AI day to day take the 30-Day AI Team Pilot.
A week in the Core: week 3, vendors.
- MON
Lesson G05 · 20 min
The vendor manager marks a chatbot vendor’s file “complete: SOC 2 certified.” Predict what’s wrong.
- TUE
Practice case AOP-07
Attempt first, then read the feedback. LAB-G1 is released.
- WED
Lesson G06 · 20 min
Binder drop: the contract gap list for one of your own AI vendors.
- THU
LAB-G1 submitted
Part A unassisted first, then Parts B–D.
- FRI
Session 3 · 75 min
Claim court, LAB-G1 debrief, apply the method to a real vendor, update the evidence meter.
Clearbrook Learning Credit Union, its vendors and its people are fictional. Your real vendor work stays in your own systems.
Every lesson ends in a binder drop.
Eight elements, built in your own systems. The sponsor sees an evidence meter at every session, and the Day-45 report states which elements are delivered, partial or not started, and why.
- E1
What binds us statement and applicability profile
MinimumSix facts recorded, obligations labelled, counsel questions listed
- E2
Evidence-tagged AI inventory with tiers
MinimumEvery row tagged; every tier-1 row has an owner and review date
- E3
Vendor AI files
MinimumFiles for the top three AI vendors, with gap lists
- E4
Security program AI insert and control check
MinimumInsert drafted for the ISO and board; tier-1 control status recorded
- E5
AI incident decision tree and tabletop record
MinimumTabletop held; decision times recorded
- E6
Member-outcome obligation map and fairness plan
MinimumOne member-facing AI mapped; one model’s fairness plan
- E7
Board AI report draft
MinimumDraft delivered to the sponsor
- E8
Maintenance calendar and binder index
MinimumOwners and dates for every item
Drafts are drafts. Adopting any policy, contract term or control is the credit union's own decision, recorded separately.
True, false, or true but mislabelled?
Five claims that sound real. The skill is knowing what kind of authority each one carries.
Every requirement gets one of seven labels
- Binding rule
- Statute
- State law
- Contract
- Supervisory guidance
- Exam procedure
- Benchmark
Confusing these is the program's most consequential error. Claim set 1 comes from the program's session drills. Source-check date 28 September 2026. Not legal advice.
Four simulations. A person reads your work.
No multiple choice. Labs and an unseen exercise are scored by a reviewer on a 20-point rubric. A pass is 16 or more, and five critical failures, such as missing a binding clock, can't be offset by other points.
72-hour incident tabletop
A running clock, timed injects, a vendor that stalls, and a decision log timed to the minute.
Examiner’s chair
Answer from the binder only. “We have that somewhere” counts as not evidenced.
Bot red-team
Thirty member utterances, including disputes phrased a dozen ways and a TTY caller.
Board rehearsal
The sponsor presents the draft board report. Peers play directors and ask the five questions.
| CU-AIG-R1 dimension | Max points |
|---|---|
| Authority classification | 4 |
| Applicability reasoning | 3 |
| Evidence discipline | 4 |
| Clock and escalation | 4 |
| Data handling | 2 |
| Usability | 1 |
| Explanation | 2 |
| Total · pass at 16 or more, no critical failure | 20 |
The five critical failures
- Presenting guidance or a benchmark as a binding rule in a consequential statement
- Accepting a vendor assertion as observed or verified evidence
- Missing or misdating a binding clock
- Stating a legal conclusion on applicability without routing it to counsel
- An unsafe data choice
A human reviewer releases every result. Completion, demonstrated skill and your credit union's own authorization stay separate.
What this program will not do
- Certify compliance, predict exam outcomes, or claim regulator endorsement
- Give legal opinions on applicability. Those go to counsel
- Require or promote a specific product in learner content
- Use real member data, or issue a professional credential
- Teach “NCUA requires” for anything that is guidance or a benchmark
We're working with our first design partners.
The first credit unions to run the Core get founding design-partner terms. Start with a free 30-minute Oversight Snapshot call: we mark each answer evidenced, asserted or unknown and send you one page. No pitch deck.
AI Oversight Program (working name) · Draft v1.0 · Sources checked 28 September 2026 · Not legal advice · Not endorsed by NCUA or any regulator