Examiner-Ready Private AI, Deployed Inside Your Network

FDIC, OCC, NCUA, and state examiners are already asking how your institution governs AI. Your staff is already using it with customer data. Lumen, the private AI platform from Cognetryx, gives you a governed alternative that runs entirely inside your bank or credit union, so NPI never leaves and your next exam has the simplest possible answer.

FIL-29

FDIC third-party risk guidance covers outside AI vendors

FDIC, 2023

0

BAAs, data-sharing agreements, or Reg P disclosures needed when data stays inside

Architectural outcome

90 days

Typical time from kickoff to production deployment

Implementation roadmap

See it in action

Every answer traces back to the exact line in your own files

Ask in plain language. Get an answer drawn only from your documents, with the source passage shown and highlighted, so anyone can check the work.

Lumen · grounded in your documents

What are the collateral protection requirements on a direct vehicle loan?

Answer

Two requirements. The borrower must carry physical damage insurance, both comprehensive and collision, for the life of the loan, with the bank named as the lienholder. And the bank must hold a first and exclusive lien on the vehicle, or the loan will not be originated.

↳ Section 2, ¶2 · p.14 ↳ Section 2, ¶5 · p.14

Answered from 2 passages in your Lending Operations Manual

Generic Bank of MichiganMember FDIC
Lending Operations Manual
Lending Policy Section
Section 2: Direct Vehicle Loans
Maximum TermUp to 85 months.
Maximum AmountUp to 120% LTV. Exceptions to maximum LTV may be approved by the underwriter.
New vs. UsedNew vehicles include any untitled vehicle, a vehicle purchased new within the past 90 days, or a current model-year vehicle. All others are considered used.
General Guidelines
1. Financing on new automobiles, SUVs, vans, and light trucks may extend to 120% of the vehicle's MSRP, inclusive of allowable add-ons such as documentation fees, taxes, title, GAP, and credit life coverage.
2. Physical damage insurance covering both comprehensive and collision must be carried for the life of the loan. The bank must be named as the lienholder on the borrower's policy.
3. Vendor's Single Interest (VSI) coverage is mandatory on all vehicle loans in this category. The VSI premium is included in the loan proceeds at closing.
4. A security interest in the vehicle will be perfected by recording the bank's lien on the certificate of title. Title filing costs are the borrower's responsibility.
5. Loans will not be originated in this program where the bank cannot hold a first and exclusive lien on the collateral.
6. Valuation of new vehicles uses the manufacturer's MSRP. Used vehicles are assessed at NADA Retail, with mileage adjustments factored in.
LP-AUTO-02 · Rev 6 · Effective 2026-01-02 · Owner: VP, Consumer LendingUncontrolled when printed · p.14

Where Institutions Start

High-Leverage Use Cases in Banking and Credit Unions

Most institutions see fastest ROI when AI handles the work that is already documented, already governed, and already repetitive. Lumen puts your documented institutional knowledge to work and leaves expert judgment with your team.

Policy & Procedure Lookup

Frontline staff get immediate, cited answers from your loan policy, deposit operations manual, or compliance procedures without escalating to a supervisor or pulling a department head into a routine question.

Loan File Summarization

Credit analysts summarize borrower documentation and commentary histories grounded in your own file structure and underwriting standards. Output stays in your network, logged, and tied to source documents.

Complaint Response Drafting

Compliance staff generate first-draft responses to member or customer complaints anchored in your institution's actual handling precedents and regulatory obligations, not generic legal language.

Exam & Audit Preparation

When examiners arrive, compliance teams can query institutional memory directly: how a specific policy was applied, which board minutes reference a control, or where a particular procedure was last updated.

Staff Onboarding & Training

New hires get consistent, institution-specific answers to routine questions that normally consume supervisor time. Onboarding accelerates and interpretive variance across staff falls.

Board & Regulatory Reporting

Assemble first-draft board materials, exam responses, and regulatory filings from source documents already governed inside your institution. Humans review and approve. The AI shortens the drafting cycle.

Compliance Mapping

How the Architecture Addresses What Examiners Ask

Federal, state, and prudential examiners are converging on the same questions about AI governance. Here is how Lumen directly addresses each framework without bolt-on tooling.

FrameworkThe RequirementHow Lumen Addresses It
FDIC FIL-29-2023Third-party risk management expectations covering any vendor that handles institution data, AI vendors included.No third-party data processing occurs. Deployment is internal infrastructure governed by existing vendor management frameworks rather than cloud processor reviews.
OCC Third-Party Risk GuidanceDue diligence, contract terms, ongoing monitoring, and exit planning for third parties with access to bank data.Because data never reaches a third party, lifecycle obligations collapse to a professional services and support relationship.
NCUA Supervisory ExpectationsLetters to Credit Unions on IT risk, information security, and AI governance under member data protection obligations.Member data remains inside the credit union's network. Existing information security program applies. CUSO and league deployment models supported.
GLBA Safeguards RuleAdministrative, technical, and physical safeguards for nonpublic personal information.Existing Safeguards Rule controls extend natively to the AI deployment. NPI never leaves the protected environment.
FFIEC IT HandbookIT governance, risk assessment, and information security expectations examined by federal and state regulators.Architecture aligns with FFIEC principles for data governance, access control, audit trail, and change management.
NIST AI RMFVoluntary but increasingly referenced framework for AI governance, mapping functions across govern, map, measure, and manage.Traceable reasoning, source citation, audit logging, and human-in-the-loop controls support the full RMF profile.

What examiners are looking at in 2026

Oversight of bank and adviser AI moved from guidance to examination in 2026. The SEC's FY2026 examination priorities name AI directly and say examiners will check whether firms actually supervise AI use and whether their public AI claims are accurate. In its May 2026 Semiannual Risk Perspective, the OCC warned that AI is reshaping the cybersecurity threat landscape for banks, lowering the barrier for fraud and raising the speed and scale of attacks. Both point the same way: institutions need AI they can govern, log, and explain to an examiner. An environment that runs inside the bank's own network, with every query and response recorded, is built for that.

Source: SEC FY2026 Examination Priorities; OCC Semiannual Risk Perspective, May 2026. See how AI agent governance works in financial services.

Common Questions

What Banking and Credit Union Leaders Ask

Does Cognetryx meet FDIC and OCC examiner expectations for third-party risk?

Because Lumen runs inside your institution's network, we occupy a different regulatory position than a cloud AI vendor. Your data never reaches a third-party processor. For third-party risk management under FDIC FIL-29-2023 and OCC guidance, Cognetryx is treated as an infrastructure and professional services relationship rather than a cloud data processor. Your existing vendor management framework governs the engagement, and every AI interaction is auditable inside your environment.

How does this work for credit unions under NCUA oversight?

Credit unions operate under NCUA examination with specific expectations around member data, IT governance, and third-party risk. Lumen runs entirely inside the credit union's network, meaning member data never leaves the institution. NCUA Letters to Credit Unions on IT risk, information security, and AI governance are addressed architecturally rather than through bolt-on controls. CUSOs and leagues can also operate Lumen on behalf of member institutions.

What about GLBA, Reg P, and Safeguards Rule obligations?

The GLBA Safeguards Rule requires administrative, technical, and physical safeguards for nonpublic personal information. Lumen inherits your existing Safeguards Rule controls because the system runs inside your network. Nonpublic personal information never leaves your environment, so Reg P sharing considerations with third-party AI vendors do not apply. Your existing written information security program covers the deployment.

How does Lumen handle shadow AI already happening at our institution?

Shadow AI in banks and credit unions usually means staff pasting customer information into ChatGPT to draft denial letters, summarize loan files, or write policy language. It is a symptom of documentation burden, not a discipline problem. When your staff has a governed tool that is genuinely faster than the unsanctioned one and grounded in your institution's own policies, shadow AI drops sharply. Lumen is built to be that better tool.

What happens during an FDIC, OCC, NCUA, or state examination?

Every AI interaction is logged with user identity, timestamp, source document referenced, and output generated. Your compliance and audit teams own this trail and can produce it on demand. Because data never left your network, the examiner's hardest question has the simplest answer. We have built the system specifically to support exam preparation workflows, so compliance teams spend less time scrambling and more time responding with confidence.

How long does deployment take for a community bank or credit union?

Most mid-market institution deployments go live in four weeks, with full production rollout in 90 days. Cognetryx includes white-glove onboarding, staff training, board presentations, and 30 days of on-site support at go-live. Timeline depends on infrastructure readiness and the scope of institutional documentation to be integrated. Smaller institutions can often deploy faster because their documentation footprint is more contained.

See What Examiner-Ready AI Looks Like

Book a 30-minute demo. We will walk your compliance and IT teams through exactly what an examiner would see, and map where private AI fits inside your existing architecture. Read what examiners ask about AI →

See it in action