Bank and credit union exams in 2026: model risk, third-party risk, and fair lending

Examiners ask about AI under rules you already follow. This guide covers what changed in the past year, what examiners ask for, and how to build an AI program a lean team can run.

Line drawing of a small bank beside an AI chip under a magnifying glass, linked to an examiner's checklist
AI questions come up in model risk, vendor risk, and fair lending reviews.

Examiners look at AI through the reviews they already run. NCUA's AI page says it has no AI-specific rules and supervises AI inside its existing framework. Its examiners look at safety and soundness, legal compliance, internal controls, ongoing monitoring, and vendor due diligence.[1] The new state exam framework from CSBS works the same way. It routes AI questions into existing model risk, vendor, and consumer protection reviews.[2]

What changed for banks and credit unions in the past year?

The rules around AI moved a lot between May 2025 and September 2026. The CFPB pulled its AI guidance and rewrote part of Reg B. The banking agencies replaced their model risk guidance and proposed new vendor guidance. NCUA and the state regulators spelled out how their examiners approach AI. The table puts the changes in order.

Date What happened What it means for you
May 12, 2025 The CFPB withdrew its circulars on AI and adverse action notices.[3] Reg B's duty to give specific reasons for a denial still applies.
December 11, 2025 Executive Order 14365 told the Attorney General to set up a task force to challenge state AI laws in court.[4] The order targets state laws. It names no bank or credit union regulator.
April 17, 2026 The Fed, OCC, and FDIC replaced SR 11-7 with new model risk guidance, SR 26-2. Generative and agentic AI are outside its scope.[5] Your own risk program sets the controls for generative AI tools. The agencies plan a request for information on AI.[6]
April 28, 2026 NCUA updated its AI page, with answers on how its examiners supervise AI.[1] Credit union exams reach AI through existing areas, with vendor due diligence up front.
July 21, 2026 A CFPB rule took effect that drops disparate-impact liability from Reg B and narrows what counts as discouragement.[7] Denial reasons and the ban on disparate treatment still apply.
September 11, 2026 Four agencies, NCUA included, proposed new third-party risk guidance. Comments close November 16, 2026.[8] The 2023 guidance stays in force until the new version is final.
September 16, 2026 CSBS released an AI supervisory framework for state examiners, with scoping questions and a document request list.[2] State-chartered banks can use it as a checklist before the next exam.

Does SR 26-2 apply to a community bank or credit union?

SR 26-2 says it is most relevant to banks with more than $30 billion in assets. Smaller banks are generally outside it, though it may still matter for one with heavy model risk from many complex models or from work beyond traditional community banking. NCUA didn't sign it, so credit unions follow NCUA's own approach.[5]

A footnote puts generative and agentic AI outside the guidance, because those models are new and changing fast. The same footnote says a bank's own risk management and governance practices should set the controls for any tool the guidance leaves out. Traditional models and other AI, such as a machine learning fraud score, stay inside.[5]

SR 26-2 also says falling short of it won't bring supervisory criticism on its own. Its first footnote adds that supervisory action can still follow from unsafe or unsound practices rooted in weak model risk management. So the program that governs your chatbot, your policy search, or an AI agent is the one you write. CSBS says state examiners may use its AI framework where existing model risk tools fall short on generative or agentic AI.[2]

Why does it matter where the model runs?

Validation needs a fixed model you can test, retest, and describe. For the models it covers, SR 26-2 calls it sound practice to understand a vendor model's design, development data, and performance, then keep checking that it stays fit for purpose.[5] A hosted large language model makes each step harder, since the provider holds the weights and data and picks when versions change.

Say you tested a loan policy assistant in March. In June the provider retires that model version and moves your account to a new one. Nothing changed on your side, and your test results now describe a model you no longer run. To show an examiner the tool still gives the answers you approved, you need the version you approved.

Running an open-weight model on your own servers changes those mechanics. You choose the version and when it changes. You keep the weights and settings, so you can write down what you tested. You can rerun last quarter's test set against the same version and compare the answers. A large language model stays hard to explain wherever it runs, and anyone promising full explainability is overselling. Running it yourself gives you a fixed version to test.

Lumen, the private AI platform from Cognetryx, is built this way. Updates ship as signed packages your IT team installs on its own schedule, so the model changes when you decide. It runs the AI model your bank chooses, on your own servers.

Keep security answers and validation answers apart. A vendor can truthfully say your data is encrypted, walled off, and kept out of training. An examiner asking how you validated the model wants test results, version history, and monitoring reports.

What should your AI program include?

Start from the use case, because the risk comes from the work an answer feeds. Then build controls into the system, test on real files, name who reviews what, and keep a record that matches the running system. The steps below follow that order and are sized for a lean team.

  1. Write a one-line use case. Name the user, the workflow, the source data, the output, and the cost of a wrong answer. "Help compliance" is too vague to judge. "Compare a draft loan policy change against the board-approved credit policy and cite the sections" gives risk, IT, and the business owner something to test.
  2. Sort helper work from decision work. Drafting, search, and summaries, with a person on the hook for the result, are helper work. Anything that moves who gets a loan, which BSA alert closes, or what goes into a call report is decision work. Put the heavy testing and review on decision work, and name who re-sorts a tool when someone wires it into a new workflow.
  3. Build identity and logging into the tool. Single sign-on says who is asking. Document permissions have to hold through the search step, so a reworded question still reaches only what that person can open. Log the user, the time, the model and version, the sources pulled, the answer, and any action taken. Permission-aware AI covers the search step in detail.
  4. Test on real work before launch. Use real files and the questions people ask. Include restricted documents, vague requests, and cases where the right answer is that the evidence falls short. For decision work, someone outside the build team signs off.
  5. Name the reviewer and what they can stop. Say who checks the output, when, and what they can override. Give reviewers the sources behind each answer, or the review turns into a signature. Human review holds up best on a single file, with time to think.
  6. Set change tiers. A wording fix needs a light look. A new data source, a model upgrade, or a move into decision work needs a retest, an approval, and a way to roll back.
  7. Keep the record current. Hold the use-case list, risk ratings, a data-flow write-up, test results, approvals, monitoring reports, and a change log. A record that describes a retired model version misleads whoever reads it.

That list tracks the CSBS document request closely. State examiners may ask for AI policies, board reporting, an inventory of AI tools and use cases with risk tiers, change records, a list of approved generative AI tools, and samples of AI output that customers saw, such as chatbot transcripts. For generative AI they also ask whether each tool is public, private, run in-house, or supplied by a vendor, what data goes in, and who reviews the output. For agents, they ask what actions the agent may take and how to halt it.[2] Each state agency decides how much of the framework to use.

What will examiners ask about an AI vendor?

Bank examiners review an AI vendor like any other third party. The 2023 interagency guidance covers every third-party relationship through planning, due diligence, contract talks, ongoing monitoring, and termination. It doesn't mention AI. It says a bank that uses a vendor stays responsible for safe and sound operation and for following the law, including consumer protection and customer data security.[9]

On September 11, 2026, the Fed, FDIC, OCC, and NCUA proposed guidance to help banks and credit unions match third-party work to the risk of each relationship. Once final, it would replace the 2023 version.[8]

For credit unions today, NCUA's AI page points to its vendor letters, 07-CU-13 and 01-CU-20. It lists four things to understand about any AI vendor: how the product works, the risks the AI adds, how it fits your business model, and the vendor's safeguards and controls.[1]

Whatever your charter, ask each AI vendor where your prompts, files, search indexes, and logs are processed and stored, and what you can read afterward. The answer decides which controls you can enforce and which you can only request. Get the contract terms on whether the vendor keeps, shares, or trains on your data. CSBS lists those terms in its document request, and its scoping questions ask about AI built into products you already use, so check your current vendors for new AI features too.[2]

What does fair lending require when a model shapes a credit decision?

Reg B gives a lender 30 days after a completed application to notify the applicant of the decision. Any reasons given for a denial must meet the standard quoted below, and the rule says a missed qualifying score on the lender's scoring system falls short.[10] The duty holds whether a loan officer, a scorecard, or a machine learning model drove the decision.

Regulation B, 12 CFR 1002.9(b)(2)

“The statement of reasons for adverse action required by paragraph (a)(2)(i) of this section must be specific and indicate the principal reason(s) for the adverse action.”

The CFPB used to spell this out for complex models. Circular 2022-03 said a lender can't skip specific reasons because its model is too complex to explain. Circular 2023-03 said checklist reasons from the sample forms fall short when they don't match the real reasons. The CFPB withdrew both on May 12, 2025, in a notice that pulled many guidance documents at once.[3] The rule they explained stayed the same. Section 1002.9 was last amended in 2023.[10]

Reg B itself changed in 2026. A CFPB rule effective July 21, 2026 states that ECOA does not provide for the effects test, the legal term for disparate impact. It also limits discouragement to statements a lender knows or should know would lead a reasonable person to expect a denial or worse terms on a prohibited basis.[7] Treating applicants differently on a prohibited basis is still barred.[10]

The Fair Housing Act is a separate law, and the Supreme Court held in 2015 that it allows disparate-impact claims, so a mortgage model can still face one.[11] If a model picks who sees a loan offer or writes the ad, review what it sends and to whom before it goes out. Ask counsel how your state's laws apply.

Record the reasons at decision time: what the model returned, which factors drove it, what the loan officer decided, and when. A year later, after the model has been updated, those reasons are much harder to rebuild.

What should you do this quarter?

  1. Find every AI tool in use. Include vendor products that added AI features and tools staff signed up for on their own. Write the one-line use case for each, and mark it helper work or decision work.
  2. Rebuild one real answer from 30 days ago. Pick a decision-work case. Find what the tool pulled, which model version answered, and who checked it. Anything you have to guess at is a gap.
  3. Run the CSBS request list as a self-check. It's public, it's short, and it shows what a state examiner may ask for. For structure, map the program to the NIST AI Risk Management Framework, part of the NIST AI resources NCUA's page points to.[1]

Sources

  1. National Credit Union Administration, "Artificial Intelligence (AI)," regulatory compliance resources page, last updated April 28, 2026. ncua.gov
  2. Conference of State Bank Supervisors, Artificial Intelligence Supervisory Framework: Core Examiner Guide, version 1.0, approved August 13, 2026, released September 16, 2026. csbs.org
  3. Consumer Financial Protection Bureau, "Interpretive Rules, Policy Statements, and Advisory Opinions; Withdrawal," 90 FR 20084, May 12, 2025, withdrawing Circulars 2022-03 and 2023-03. federalregister.gov; consumerfinance.gov
  4. Executive Order 14365, "Ensuring a National Policy Framework for Artificial Intelligence," December 11, 2025. govinfo.gov
  5. Federal Reserve SR 26-2, "Revised Guidance on Model Risk Management," April 17, 2026, issued with the OCC and FDIC and replacing SR 11-7 and SR 21-8. See the attachment's footnotes 1 and 3 and its section on vendor products. federalreserve.gov
  6. OCC Bulletin 2026-13, "Model Risk Management: Revised Guidance," April 17, 2026, on the planned request for information about banks' use of AI. occ.gov
  7. Consumer Financial Protection Bureau, "Equal Credit Opportunity Act (Regulation B)," final rule, 91 FR 21620, April 22, 2026, effective July 21, 2026. federalregister.gov
  8. Federal Reserve, FDIC, NCUA, and OCC, "Proposed Third-Party Risk Management Guidance," announced September 11, 2026 in FDIC FIL-58-2026 and OCC Bulletin 2026-46. Published in the Federal Register September 15, 2026, with comments due November 16, 2026. fdic.gov; occ.gov; federalregister.gov
  9. FDIC FIL-29-2023, "Interagency Guidance on Third-Party Relationships: Risk Management," June 2023, from the Federal Reserve, FDIC, and OCC. fdic.gov
  10. Regulation B, 12 CFR 1002.4(a) and (b), 1002.6(a), and 1002.9(a)(1)(i) and (b)(2), current text. ecfr.gov
  11. Texas Department of Housing and Community Affairs v. Inclusive Communities Project, Inc., No. 13-1371, decided June 25, 2015. law.cornell.edu

This guide is informational and not legal or compliance advice. Confirm how these rules apply to your institution with your counsel and your examiners.

Show your examiner the trail behind each answer

See Lumen answer from a bank's own documents, with a citation on every answer and a log your compliance team can search.

See it in action
Keith Kennedy

Keith Kennedy, CISSP

Founder, Cognetryx

Keith is an IT thought leader with nearly 20 years of experience architecting secure technology solutions for regulated industries. He holds a CISSP certification and has advised enterprise companies on HIPAA, SEC/FINRA, and GDPR compliance.

See how Lumen delivers examiner-ready AI for banks and credit unions. Private AI for Banking →