A member asks about the early-withdrawal penalty on a share certificate. A customer asks why a deposit is on hold. A loan officer needs to know how an investor overlay treats a borrower with gig income. The right answer exists in a product guide, a rate sheet, a policy manual, a procedure, or the memory of someone who has been there fifteen years.
Credit unions and community banks compete on service, and the front line gives the answers. When the same question gets different answers depending on who picks up, members and customers notice, and so do examiners.
Where do policy and procedure answers break down?
At the desk, on a busy day. Front-line staff carry dozens of products, rates that change, eligibility rules, fee schedules, and procedures that update. A new hire can take months to learn it all, and the veterans who know the edge cases aren't at every desk. The same question can get different answers depending on who picks up.
Veterans also retire, and what they know leaves with them unless it is written into the documents everyone else works from.
Why can't a general chatbot answer these questions?
It doesn't know your bank or credit union. A general chatbot answers from a generic training set. It has no idea what your certificate rates are, how your field of membership is defined, what your fee schedule says, or which overlays your lenders follow. It will still give a confident answer, and a member or borrower may act on it.
What should the AI answer from?
Your own approved documents. That means product guides, rate sheets, policy manuals, procedures, fee schedules, loan policies, investor guidelines and overlays, and member service FAQs. With Lumen, the private AI platform from Cognetryx, each answer cites its source, and clicking the citation opens the document with the passage highlighted, so staff can confirm it before they tell the member.
Answers follow each person's existing permissions through SSO over SAML or OIDC. A teller gets answers from what a teller can open, and a loan officer from the lending files they can already reach. We explain how in permission-aware AI.
Picture three ordinary moments. A new representative gets a question about the early-withdrawal penalty on a 36-month share certificate, and the answer comes back with a link to the certificate disclosure it came from. A call-center rep fields a membership question about a member's relative, where the field-of-membership rules are easy to get wrong, and the system brings up your actual eligibility policy. A loan officer needs to confirm how policy treats a case that rarely comes up and gets the current approved language.
The same cited answers help when an examiner asks for the procedure your staff follow today.
Which lending tasks is AI good for?
The ones that take the most time per loan and depend on finding the right version of the right policy at the right moment. In each task below, the AI drafts or checks the work, and a person makes the final call.
- Loan file review. Find missing documents before underwriting starts.
- Disclosure checks. Confirm the Loan Estimate and Closing Disclosure match current loan terms before they go out.
- Adverse action drafts. Draft notices tied to the specific reasons recorded in the loan file.
- Policy and guideline lookup. Pull up the current investor guidelines, overlays, and exception policies without a hunt through the document system.
- HMDA checks before submission. Check loan files against your Regulation C data definitions before you file, so errors turn up before an exam.
All five work better when the AI knows your own overlays and product mix. Generic output gets checked against your documents anyway, which cancels the time saved.
Do fair lending rules change when AI helps with a credit decision?
The rules stay the same. ECOA, Regulation B, and HMDA apply the same way whether a person or an AI tool helps with the work. When a lender takes adverse action, such as denying credit, Regulation B requires a statement of reasons that is specific and gives the principal reasons for the action.[1]
Reg B calls it insufficient to say the applicant failed the lender's internal standards or missed a qualifying score on its scoring system.[1] That holds when a model shaped the decision. The CFPB said so in a 2022 circular, which it withdrew on May 12, 2025.[2] The regulation still applies, so an AI-drafted notice has to name the real reasons, and a person should check it against the file.
ECOA and the Fair Housing Act together bar discrimination based on race, color, religion, national origin, sex, marital status, age, receipt of public assistance, familial status, and disability. Those protections cover AI-assisted work the same as any other part of the lending process.
HMDA errors bring penalties too. In 2023 the CFPB fined Bank of America $12 million for reporting false HMDA data.[3] A check before submission gives your team one more chance to catch errors while they are cheap to fix.
When an examiner asks how AI was used on a loan file, you need a record. The Compliance Portal logs chats, tool calls, agent runs, approvals, exports, and permission and config changes, and your compliance team can search it.
Who holds member and customer data when staff use AI?
Whoever runs the AI. Credit unions protect member data under NCUA Part 748, whose Appendix A sets the GLBA safeguards. It tells each credit union to vet its service providers, require safeguards by contract, and monitor them where its risk review calls for it.[4] Banks follow the same steps under the Interagency Guidelines Establishing Information Security Standards.[5]
Appendix A defines a service provider broadly. It is any person or entity that maintains, processes, or is otherwise permitted access to member information through services it provides to the credit union.[4] A contracted AI service that reads member files fits that description.
Those duties apply either way. What changes is the number of outside parties that hold your data. An outside AI service that receives member data becomes one more provider to vet, bind by contract, and monitor. Running the AI on your own servers avoids adding that vendor. Lumen is still software you review like any other, and the member data it reads stays in your environment.
Unapproved tools add risk of their own. Say a loan officer pastes a borrower's income, assets, debts, and address into a public chatbot to draft a preapproval letter. That officer has sent member information to an outside service no one vetted. An approved tool that runs in-house gives staff a safe place to do that work. We cover this in where your data goes when staff use AI.
Each outside party that holds member data is also one more place an incident can start. A federally insured credit union must notify the NCUA within 72 hours of a reportable cyber incident. That includes an incident caused by a compromise at a CUSO, a cloud provider, or another third-party data host.[6] A bank must notify its federal regulator within 36 hours after it determines a notification incident has occurred.[7] We cover third-party risk in exams in bank and credit union exams in 2026.
If you run a mortgage unit or work with nonbank lenders, check which safeguards rule applies. Banks and credit unions follow their own agencies' guidelines. Nonbank mortgage lenders and brokers fall under the FTC Safeguards Rule.[8] Reg S-P is the SEC's rule for brokers, funds, advisers, and transfer agents.[9]
What should the AI leave to people?
Every decision. Set it up to support staff and leave member decisions, credit decisions, and exceptions to a person. The AI finds the approved answer and shows where it came from. Your people keep the relationship and make the call.
Used that way, a new hire can answer like your most experienced people, because both are reading from the same approved documents.
See a cited answer from your own policy manual
Ask a question of your own documents and click through to the highlighted passage.
See it in actionSources
- 12 CFR 1002.9(b)(2), Regulation B, statement of specific reasons. law.cornell.edu
- Consumer Financial Protection Bureau, Withdrawn Guidance. Circular 2022-03, Adverse Action Notification Requirements in Connection With Credit Decisions Based on Complex Algorithms, was withdrawn on May 12, 2025. consumerfinance.gov
- Consumer Financial Protection Bureau, enforcement action against Bank of America, N.A., November 28, 2023, with a $12 million civil money penalty for HMDA reporting. The CFPB ended the order on June 5, 2025, after the bank met its terms. consumerfinance.gov
- 12 CFR Part 748, Appendix A, Guidelines for Safeguarding Member Information, section III.D, Oversee Service Provider Arrangements. law.cornell.edu
- 12 CFR Part 364, Appendix B, Interagency Guidelines Establishing Information Security Standards (FDIC version), section III.D. law.cornell.edu
- 12 CFR 748.1(c), NCUA cyber incident report. law.cornell.edu
- Computer-security incident notification rules for banks: 12 CFR 53.3 (OCC), 12 CFR 225.302 (Federal Reserve), and 12 CFR 304.23 (FDIC). law.cornell.edu
- Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know. Section 314.2(h) of the rule lists mortgage lenders and mortgage brokers among covered financial institutions. ftc.gov
- 17 CFR 248.30(d)(3), Regulation S-P, definition of covered institution. law.cornell.edu
This article is informational and not legal or compliance advice. Have counsel confirm how Regulation B and the safeguards rules apply to your institution.