Insights
Posted 13 September 2026

Built-in governance is a feature, not your record

You are a credit union or a bank. You bought a product that says governance is built in, for your chatbots or for AI agents that act on your systems.

Here is the gap.

The product can show what the agent did. It cannot show that you oversaw it, and your oversight is what an examiner asks you to show. NCUA's words: board and management "must ensure proper oversight." The banking agencies' words, for banks: using a third party "does not diminish" your responsibility.

The product governs the agent. It does not govern your decision to deploy that agent, or hold the record of who accepted it, on what basis, and when that was last revisited.

It is the vendor's system producing evidence about the vendor's system.

It is a feature. Your examiner is asking a different question, which is how do you know.

And it does not survive change. The model behind that chatbot can be replaced, or handed to a subcontractor, and a feature is not obliged to tell you. Your contract can oblige it.

None of this means your vendor built it badly. I spent this past week asking vendors what record their systems keep. Some answered well. The gap is not about vendor quality. It is that the institution often cannot show the same thing for itself, and the answer lives in a conversation instead of a document it holds.

So your vendor may well have built this properly. Can you show that you know? Would you notice if it changed?

Your responsibility does not transfer. Only the work does.

What narrows it is not a better feature. It is a clause about notice and information rights, and one person who owns a dated record: which systems are deployed, who built them, what you asked, and when you last checked.

Sources:
  • NCUA, Artificial Intelligence page (updated 28 April 2026): "The credit union's board and management must ensure proper oversight to maintain safe and sound operations." ncua.gov
  • NCUA Supervisory Letter SL 07-01, Evaluating Third Party Relationships (October 2007): "outsourcing processes or functions does not eliminate credit union responsibility for the safety and soundness of those processes and functions." ncua.gov
  • Interagency Guidance on Third-Party Relationships, Federal Reserve, FDIC and OCC (9 June 2023): "A banking organization's use of third parties does not diminish its responsibility to meet these requirements..." federalregister.gov

Scope note, because it matters. That 2023 guidance is issued by the Fed, FDIC and OCC and applies to banking organizations. NCUA is not a party to it. For a bank it is supervisory expectation. For a credit union it is best practice, and SL 07-01 is the instrument.

Written for compliance and risk readers in regulated financial firms. Informational, not legal advice; Mike Bidun is not a lawyer.