How to evaluate a consultant's NCUA and examiner depth

Every AI consultant who wants your business will tell you they understand regulated financial institutions. Most of them mean they once did a project for a bank. That is not the same thing as knowing what an NCUA examiner will ask about the system they are proposing to build for you, and the gap between those two positions is where credit unions get hurt.

This deep-dive gives you a concrete way to test regulatory depth before you sign: the documents to request, the questions that separate real experience from a slide about "responsible AI," and a worked example scored against the rubric on the scorecard page. Regulatory working knowledge carries a suggested weight of 20% in that rubric, tied with credit union depth for the heaviest criterion, and for good reason. A consultant's regulatory blind spot becomes your examination finding roughly twelve to eighteen months after they cash the final invoice.

Why banking compliance experience does not transfer cleanly

NCUA supervision differs from OCC and Federal Reserve supervision in ways that matter for AI projects. Examiners arrive with different priorities, credit unions carry a cooperative governance structure that changes how model decisions get approved, and NCUA's guidance on third-party relationships puts specific documentation burdens on you, not the vendor. A firm that learned compliance at a national bank will often over-engineer in some places (building model risk apparatus sized for a $50 billion institution) and under-deliver in others (missing the third-party due diligence file your examiner actually requests).

Test vocabulary under pressure. A firm with real NCUA exposure talks naturally about supervisory priorities, the third-party risk expectations in NCUA guidance, fair lending review under Regulation B for anything touching credit decisions, and the difference between a model your team can explain and one nobody in the building understands. A firm without that exposure retreats to generalities within two follow-up questions.

Documents to request before you sign

Ask every finalist for these four items. Redacted versions are fine; refusal to produce any of them is an answer in itself.

A redacted examiner-readiness or governance deliverable from a prior credit union engagement. You want to see the actual work product: a model inventory entry, a documented risk assessment, a policy the client's board adopted. Judge whether the document would survive your own examiner's review. Thin deliverables look like reformatted vendor whitepapers. Strong ones reference the client's specific systems, data flows, and approval chain.

A sample third-party risk documentation package. If the firm recommends or implements any vendor tool, you carry the third-party risk obligation. Ask what documentation package they hand you for it: due diligence summary, data flow description, contract terms review, ongoing monitoring plan. A firm that says "your compliance team handles that" is planning to leave you with a liability and no file.

Their fair lending position for any decisioning use case. If the proposal touches lending, collections, or membership decisions in any way, ask for a written description of how they test for disparate impact and what they document. Accept no hand-waving here. "The model doesn't use protected attributes" is not a fair lending analysis; proxy variables are the entire problem.

References from credit unions that have been examined since the engagement ended. This is the single most valuable request on the list. A reference who can say "the examiner reviewed the AI system and the documentation held up" is worth more than any credential. Ask the reference what the examiner requested and whether anything was missing.

Red flags

Green flags

A worked example

A $600 million credit union in the Midwest evaluated two firms for a lending back-office automation project. Firm A, a national technology consultancy, presented a polished AI governance framework and a compliance workstream priced at $40,000 inside a larger proposal. Firm B, a smaller specialist, presented a plainer deck but opened the second meeting by asking about the credit union's 2024 exam and the documented findings on vendor management.

The evaluation team ran the document test. Firm A produced a governance whitepaper with the client name removed; it contained no reference to any specific system and could have applied to a hospital. Firm B produced a redacted model inventory entry and a third-party due diligence file, then connected the team with a reference client examined eight months after go-live. The reference reported the examiner requested the model documentation, reviewed it in an afternoon, and moved on.

On the rubric, Firm A scored 2 on regulatory working knowledge (generic framework, no examiner-tested artifacts) and Firm B scored 5 (NCUA-specific deliverables, referenceable exam outcome). At a 20% weight, that three-point spread moved the weighted total by more than half a point on a five-point scale, enough to flip the decision despite Firm A's stronger brand. The credit union hired Firm B, and the board minutes recorded the document comparison as the deciding evidence. That paper trail matters when someone later asks why you passed on the bigger name.

Where this fits in the full evaluation

Regulatory depth is one criterion of seven. A firm can know NCUA guidance cold and still fail you on capability transfer or vendor independence, so run the full rubric and the twelve questions on the interview questions page, especially question three, which asks the firm to predict what an examiner would request about their proposed system. Strong firms answer it in under two minutes with specifics.

If you want to see what examiner-ready scoping looks like in a bounded first engagement, review the structure of an AI readiness assessment and hold every firm you evaluate, including its publisher, to the same documentary standard. The test is always the same: ask for the artifact, not the assurance.