Credit Union Compliance: The Complete 2026 Guide

Credit Union Compliance: The Complete 2026 Guide — Sedric pillar covering NCUA, CFPB, BSA/AML, fair lending, cybersecurity, and the CMS framework.
Sedric Team
Communications
Share article on
Linkedin logoX logo

Quick answer: Credit union compliance is the discipline of running a federally insured credit union within the full body of federal and state law that governs how it takes deposits, makes loans, markets to members, protects data, prevents financial crime, treats consumers fairly, and reports to regulators. In 2026 that surface is broad. The credit union compliance officer manages NCUA-specific rules (12 CFR Parts 700–799), consumer protection rules that flow from the CFPB (Regulations B, E, P, X, Z, F, V, and CC), the Bank Secrecy Act and OFAC sanctions, fair-lending statutes (ECOA and the Fair Housing Act), the Servicemembers Civil Relief Act and Military Lending Act, cybersecurity obligations under NCUA Part 748 and GLBA, third-party oversight, and the annual examination process itself. This is the operator's guide to that surface.

TL;DR: This is a hub, not a one-stop shop. It maps every major compliance area, points you at the primary source for each, and links out to deeper guides where a topic has enough surface area to warrant its own pillar. Sedric operationalises the marketing, advertising, and communications slice of the stack. For every other area, this guide names the rule, the regulator, and the citation so you can go straight to the primary source.

The scale of the sector puts the stakes in context. There are 4,250 federally insured credit unions in the United States, serving 145.8 million members and holding $2.48 trillion in assets, per the NCUA Quarterly Data Summary for Q1 2026. Every one of those institutions runs under the same core regulatory framework this pillar describes.

What makes credit union compliance different from bank compliance?

Credit union vs. commercial bank compliance at a glance — regulator, deposit-disclosure rule, advertising rule, tax status, insurance fund, and ownership structure.

Credit unions and commercial banks share most of the consumer-protection rulebook, but four structural differences make credit union compliance its own discipline.

Different regulator, different rulebook prefix. The National Credit Union Administration (NCUA) is the prudential regulator for all federally chartered credit unions and the deposit insurer for federally insured state-chartered credit unions, under 12 U.S.C. Chapter 14. Federal credit union rules live in 12 CFR Chapter VII. Commercial banks look to the OCC (national banks), the FDIC (state-chartered non-member banks), or the Federal Reserve (state-chartered member banks and holding companies). This changes which examiner walks in the door and which rulebook the exam is graded against.

Different deposit rule. Banks and thrifts follow the CFPB's Regulation DD to implement the Truth in Savings Act. Credit unions do not. Credit unions follow the NCUA's parallel rule at 12 CFR Part 707, which excludes credit unions from Reg DD by its own terms and applies NCUA-specific interpretations. If your team is copying disclosure templates from a bank's playbook, check the citation, because the section numbers and staff commentary differ. Our Truth in Savings advertising guide works through the details.

Different advertising rule. Banks work under Regulation DD's advertising sections and FDIC signage rules. Credit unions work under 12 CFR Part 740, which requires that advertising be accurate and not deceptive (§740.2), that the official NCUA sign be displayed at deposit-taking locations (§740.4), and that most advertising carry an official advertising statement of NCUA insurance (§740.5). NCUA proposed removing §740.5 in December 2025 (Federal Register, 29 Dec 2025), but until that is finalised, the statement is still required. See our NCUA advertising rules guide for the operational detail.

Different tax and structure. Federal credit unions are exempt from federal income tax under 12 U.S.C. 1768, and state-chartered credit unions are typically exempt from state income tax under enabling state statutes. That tax status is tied to the mutual, member-owned structure, and the field-of-membership rules that limit who can join a particular credit union. Field of membership is itself an examinable area: unqualified "anyone can join" advertising is treated as inaccurate or deceptive under §740.2, per NCUA Letter 13-FCU-03.

Who supervises whom?

The four regulators that supervise a US credit union: NCUA, state regulator, CFPB, and FinCEN/OFAC.

Four regulators do most of the work on a US credit union's compliance surface. The examiner who visits depends on charter, insurance status, and asset size.

NCUA supervises every federally chartered credit union and every federally insured state-chartered credit union for safety and soundness and for federal consumer financial law, other than for state-chartered institutions above the $10 billion CFPB threshold. NCUA also administers the National Credit Union Share Insurance Fund (NCUSIF), which insures member deposits up to $250,000 per share owner per insured credit union, per ownership category.

The state regulator supervises state-chartered credit unions for the state charter, state-law consumer protections, and (when the credit union is not federally insured) deposit insurance. Some states run their own privately administered deposit insurance or require federal insurance. State law adds its own overlay for collections, licensing, and complaints.

The Consumer Financial Protection Bureau (CFPB) supervises credit unions with more than $10 billion in assets for federal consumer financial law, including UDAAP, RESPA, TILA, ECOA, EFTA, FCRA, and HMDA, per CFPB, institutions subject to supervision. At or below $10 billion, the NCUA (or the state regulator, for state-chartered) supervises for the same rules. The UDAAP prohibition and the underlying consumer-protection statutes apply at every asset size; only the examiner changes.

FinCEN and OFAC sit outside prudential supervision but reach every credit union. FinCEN administers the Bank Secrecy Act under 31 U.S.C. Chapter 53, requires currency transaction reports and suspicious activity reports, and enforces the Customer Due Diligence rule. OFAC administers economic sanctions under authorities including the International Emergency Economic Powers Act. Cross-border activity, wire transfers, and prepaid programs all sit in this surface. Additional agencies matter for narrower slices: HUD for Fair Housing Act enforcement, the FTC for advertising and the Endorsement Guides, and the CFPB (again) for open-banking rights under Section 1033.

The compliance surface — ten functional areas

The ten functional areas of credit union compliance: governance, consumer protection (UDAAP), deposit operations, lending, marketing and communications, collections, BSA/AML/OFAC, privacy and cybersecurity, third-party and CUSO oversight, and complaints management.

Once you get past who the regulator is, the compliance surface itself has a fairly stable shape. It shows up on the compliance officer's desk in roughly ten functional areas, each with its own primary rules. What follows is the map. Each section names the anchor rules, the primary regulator, and (where relevant) the internal link to a deeper guide.

1. Governance and board oversight

The starting point for any credit union compliance program is board and management oversight. NCUA's Federal Consumer Financial Protection Guide sets the expectation that the board approve the compliance program, receive periodic reports, and act on identified deficiencies. The Supervisory Committee, required under 12 U.S.C. 1761d for federal credit unions and by state law for most state charters, provides the independent audit function. This layer is where enterprise risk management, compliance culture, and management change controls live. Examiners routinely open with governance and consumer-compliance ratings before they look at any specific line-of-business rule.

2. Consumer financial protection (the UDAAP layer)

Unfair, deceptive, or abusive acts or practices — UDAAP — is the broadest consumer-protection standard credit unions operate under. Its statutory basis is Sections 1031 and 1036 of the Dodd-Frank Act (12 U.S.C. 5531 and 5536); the "unfair" and "deceptive" prongs also trace back to Section 5 of the FTC Act (15 U.S.C. 45). UDAAP applies across every consumer-facing surface, from origination and account opening through servicing and collections. The CFPB's UDAAPs Examination Procedures are the operator's benchmark for how examiners apply the three standards.

UDAAP touches marketing (see credit union marketing and communications compliance), collections (see UDAAP and collections call monitoring), fee practices, disclosures, and member service scripts. Because it is principle-based, the substantive tests — substantial injury, misleading a reasonable member, taking unreasonable advantage — apply even when a specific rule does not.

3. Deposit operations

Deposit compliance for credit unions runs on three anchors. Regulation CC (12 CFR Part 229) implements the Expedited Funds Availability Act and governs check hold policies, disclosure of funds-availability terms, and the substitute-check regime under Check 21. Regulation D (12 CFR Part 204) covers reserve requirements — historically the transaction/savings distinction, now much reduced after the Federal Reserve dropped reserve ratios to zero in March 2020. And NCUA Part 707 covers Truth in Savings account disclosures, periodic statements, and advertising. Together they set what you must disclose at account opening, what you must show on periodic statements, and how quickly a member can access deposited funds.

4. Lending and mortgage compliance

Consumer lending is where the largest volume of compliance obligations lands. The anchors are Regulation Z (Truth in Lending, 12 CFR Part 1026), Regulation X (RESPA, Part 1024) for mortgage loans, Regulation B (ECOA, Part 1002) for fair credit access, and Regulation V (FCRA, Part 1022) for credit reporting and adverse action.

Layered on top are product-specific rules: the ability-to-repay and Qualified Mortgage rules under Regulation Z §1026.43, the Loan Originator Compensation rule, the mortgage servicing rules in Regulation X Subpart D, the Home Ownership and Equity Protection Act (HOEPA) high-cost mortgage rules, the CARD Act rules for credit cards under Regulation Z Subpart G, the Military Lending Act (10 U.S.C. 987 and 32 CFR Part 232), and the Servicemembers Civil Relief Act (50 U.S.C. Chapter 50). Flood-insurance requirements under the Flood Disaster Protection Act sit alongside. Mortgage loan originators must register annually with the NMLS under the SAFE Act (12 U.S.C. 5101 et seq.). HMDA data collection and reporting flow from Regulation C (Part 1003) for credit unions above the reporting threshold.

5. Marketing, advertising, and communications

Marketing and communications is where a credit union's compliance obligations meet its growth engine. This is Sedric's operating surface, and it is anchored in three rules: NCUA Part 740 for advertising accuracy and insured-status disclosures, NCUA Part 707 for how you advertise deposit rates, and UDAAP for the fairness of every member-facing message. For a deep operational treatment, start with the credit union marketing and communications compliance pillar, then work through NCUA advertising rules and Truth in Savings advertising.

The examinable surface here is broader than the ads themselves. It includes disclosures on the website, in mobile banking, in email templates, and on periodic-statement inserts, and the internal review workflow that vets each of those before publication. It also includes third-party marketing on the credit union's behalf — anything a partner, referral network, or influencer says in the credit union's name is within scope.

6. Collections and account servicing

A credit union collecting its own member loans is typically a first-party creditor, and most first-party collectors are outside the technical FDCPA definition of "debt collector." Regulation F (12 CFR Part 1006) implements the FDCPA and binds those covered "debt collectors." UDAAP is the standard that reaches first-party creditors, and the CFPB has been explicit that conduct which would violate the FDCPA can also be a UDAAP even where the FDCPA does not technically apply, per CFPB Bulletin 2013-07. In practice, Reg F is the sensible operational benchmark for what your collections agents can and cannot say on a call, even if it does not formally apply to you. Our UDAAP and collections call monitoring guide maps the specific behaviours to the specific rule.

7. Bank Secrecy Act, AML, and OFAC sanctions

BSA/AML is the standalone compliance program every credit union must run, regardless of size. The statutory foundation is the Bank Secrecy Act (31 U.S.C. Chapter 53), implemented by FinCEN regulations at 31 CFR Chapter X. The NCUA's implementing rule for credit unions is 12 CFR Part 748, which requires each federally insured credit union to develop a written BSA compliance program approved by the board, with specified minimum elements: internal controls, independent testing, a designated BSA officer, training, and — since May 2018 — customer due diligence including beneficial-ownership identification for legal-entity members.

The program feeds specific reporting obligations: Currency Transaction Reports (CTRs) for cash transactions over $10,000; Suspicious Activity Reports (SARs) for transactions or patterns that appear to involve funds derived from illegal activity, evade the BSA, have no apparent lawful purpose, or facilitate criminal activity; and Section 314(a) responses to law-enforcement requests. Wire-transfer travel-rule obligations, prepaid access rules, and cross-border currency movement reporting all live in this stack.

OFAC sanctions run in parallel. Every credit union must screen transactions and members against the Specially Designated Nationals (SDN) list and other sanctions lists, block or reject prohibited transactions, and report as required under 31 CFR Chapter V. OFAC does not publish an implementing rule the way NCUA does; the obligation flows from the underlying sanctions authorities (IEEPA, TWEA, and specific country programmes).

8. Privacy, data protection, and Section 1033 open banking

Consumer privacy for credit unions is anchored in the Gramm-Leach-Bliley Act (GLBA), implemented for credit unions by Regulation P (12 CFR Part 1016) for the privacy notice and opt-out obligations, and by NCUA Part 748 Appendix A for the Safeguards Rule requirements: written information-security programme, designated coordinator, risk assessment, and vendor oversight. The Fair Credit Reporting Act (FCRA) adds obligations around adverse-action notices, permissible-purpose limits on pulling credit, dispute handling under FCRA §611, and identity-theft red flag rules under §615.

Data breach notification is a state-law patchwork: all 50 states plus DC and several US territories have breach-notification statutes with different definitions of personal information, notification triggers, timelines, and regulator-notification rules. GLBA imposes a separate federal expectation of prompt notification of the primary regulator on material breach events.

The CFPB's Section 1033 rule — the "Consumer Financial Data Rights" or personal-financial-data-rights rule, finalised in October 2024 under 12 CFR Part 1033 — extends open-banking obligations to depository institutions above certain asset thresholds. Credit unions above the applicable size threshold must be prepared to provide covered data to consumers and to authorised third parties through secure, standardised interfaces on the compliance timelines set by the rule. This is an emerging obligation and the operating detail is still developing through implementation.

9. Third-party risk and CUSO oversight

Vendor risk management is not an option. NCUA's Letter to Credit Unions 07-CU-13 and follow-on guidance set the expectations for due diligence, contracts, and ongoing monitoring on any third-party relationship. Credit Union Service Organisations (CUSOs), regulated under 12 CFR Part 712, have their own investment and lending limits and their own recordkeeping requirements. And for credit unions with BaaS or partner-brand programmes, everything a partner says or does in the credit union's name flows back to the credit union's regulatory posture. That is the same principle you see in bank sponsorship arrangements: the depository institution owns the compliance outcome.

10. Complaints management and consumer response

Consumer-complaint management is a supervisory expectation in its own right. NCUA's consumer complaint process takes complaints against federal credit unions directly; the CFPB's public complaint database (consumerfinance.gov/complaint) publishes complaints against institutions the CFPB supervises. A written policy, a defined intake channel, a routing procedure, and root-cause analysis are all pieces the examiner will ask about. Complaint trends are also one of the CFPB's most-used UDAAP evidence sources, so a well-run intake process both discharges the specific obligation and reduces the UDAAP exposure that comes from unresolved patterns.

The NCUA rulebook — the parts you actually cite

The NCUA parts most cited by credit union compliance officers: Part 707 Truth in Savings, Part 712 CUSOs, Part 723 member business loans, Part 740 advertising, Part 741 share insurance, Part 748 security and BSA/AML, Part 749 records preservation.

Most credit union compliance officers spend the majority of their week inside a handful of NCUA parts. This is the operational reference table.

Notes on a few of these worth reading closely. Part 741 governs the requirements a state-chartered credit union must meet to obtain and keep federal share insurance. Part 748 is the security and cybersecurity part — its Appendix A is the Safeguards Rule for credit unions and its Appendix B is the incident-response guidance. Part 749 covers records preservation and retention, including the disaster-recovery plan. Part 723 governs member business loans and their concentration limits. Part 712 governs CUSOs. Part 704 governs corporate credit unions.

CFPB rules that apply to credit unions

Since Dodd-Frank moved rulemaking authority for most consumer financial protection rules to the CFPB, credit unions look to the CFPB's Chapter X regulations even though supervision below $10 billion stays with the NCUA. The relevant regulations for a typical credit union are:

Regulation B (ECOA, 12 CFR 1002) for fair credit and adverse-action notices. Regulation C (HMDA, 12 CFR 1003) for mortgage data collection, above the reporting threshold. Regulation E (EFTA, 12 CFR 1005) for electronic fund transfers, error resolution, and Regulation E overdraft opt-in. Regulation F (12 CFR 1006) for FDCPA-covered debt collection. Regulation P (GLBA privacy, 12 CFR 1016) for annual privacy notices and opt-out. Regulation V (FCRA, 12 CFR 1022) for credit reporting and identity-theft red flags. Regulation X (RESPA, 12 CFR 1024) for mortgage settlement, escrow, and servicing. Regulation Z (TILA, 12 CFR 1026) for credit disclosures, ability-to-repay, credit cards, and mortgages. Regulation 1033 (12 CFR 1033) for personal financial data rights.

A useful mental model: credit unions comply with these regulations because Congress placed the substantive obligations on covered institutions, and the CFPB is the rulewriter under Dodd-Frank Title X. Below $10 billion, the NCUA examines credit unions for these rules using the CFPB's regulatory text and its own consumer-financial-protection guide.

The Compliance Management System (CMS) framework

The four pillars of a Compliance Management System: board and management oversight, compliance program, consumer complaint response, and compliance audit.

Every credit union runs, whether it uses the acronym or not, a Compliance Management System — the collection of policies, procedures, controls, and oversight that translates the rules above into day-to-day operations. NCUA's Federal Consumer Financial Protection Guide and the CFPB's Supervision and Examination Manual both organise the CMS into four pillars: board and management oversight, the compliance program (policies, procedures, and training), the consumer-complaint response function, and the compliance-audit function that provides independent assurance.

Examiners assess these pillars during consumer-compliance supervision and assign a rating on the CFPB's five-point scale (from "1 — Strong" to "5 — Substantial noncompliance"). A weak CMS is often the finding under which specific violations get aggregated. Investing in the CMS pays down risk on every specific rule at once.

How credit union exams actually work

The NCUA credit union examination cycle: pre-exam planning, onsite fieldwork, CAMELS ratings, findings and Document of Resolution, follow-up and remediation.

NCUA runs a risk-focused examination programme. Every federally insured credit union is on an exam cycle, with cycle length depending on asset size, complexity, and prior-exam findings. The examination workflow is broadly consistent.

Pre-exam planning uses the NCUA's AIRES (Automated Integrated Regulatory Examination System) data collection to review Call Report data, complaint history, and prior-exam findings. Onsite work is structured around the CAMELS composite rating (Capital, Asset quality, Management, Earnings, Liquidity, and Sensitivity to market risk) for safety and soundness, plus a consumer-compliance rating for the CMS. The credit union receives a Document of Resolution when there are matters requiring attention, and the follow-up cycle can include supervisory letters, cease-and-desist authority, or in extreme cases conservatorship. State-chartered credit unions run under the state regulator's examination framework, which coordinates with the NCUA for federally insured institutions.

The NCUA's 2026 supervisory priorities

Each year, the NCUA publishes its supervisory priorities in a Letter to Credit Unions. The 2025 letter, 25-CU-01, laid out the agency's focus for the year: credit risk (including modified loans), balance-sheet management and liquidity, cybersecurity, consumer financial protection, and BSA/AML. The 2026 letter, when published, sets similar categories with year-specific emphasis on the areas the agency believes are trending. Watch for it early in the calendar year and align your exam-preparation cycle to whatever is emphasised.

Emerging areas that examiners are asking about across many institutions include: use of artificial intelligence in decisioning (particularly for fair-lending exposure), open-banking readiness under Section 1033, elder financial exploitation and its intersection with BSA/SAR obligations, and third-party BaaS or fintech-partnership arrangements. None of these are new rules, in most cases, but they are the areas where examiners are asking harder questions.

Where technology (and Sedric) fit

Compliance technology in a credit union should be layered on top of the CMS, not a substitute for it. A useful working split:

Where automation genuinely lifts the operating model: pre-publication review of marketing content against the credit union's claims library and against Part 740 and Part 707 disclosures; communications surveillance across calls, chat, and email for UDAAP-relevant conduct; complaint mining for pattern detection ahead of a CFPB inquiry; fair-lending analytics on origination and pricing outcomes; and BSA/AML transaction monitoring, where model risk management under NCUA's expectations and OCC 2011-12 (which the NCUA cross-references for model governance) applies.

Where automation should stay in a supporting role: board-level judgment on risk appetite, examination-response strategy, SAR narrative writing where nuance matters, and any decision that touches denial-of-service or account-closure for a member. These involve either regulatory judgment calls, litigation exposure, or reputational risk that the compliance officer needs to own personally.

Sedric operates in the first bucket, at the intersection of marketing content review and communications surveillance. The platform reviews marketing assets and member communications before they publish or after they are sent, links each flag to the specific rule (Part 740, Part 707, or a UDAAP standard), and logs each decision with the underlying evidence, so the credit union has an exam-ready record of what was reviewed and why. Sedric does not do BSA/AML transaction monitoring, fair-lending model validation, or Call Report generation — those are separate specialist stacks.

Frequently asked questions

Do credit unions follow the same rules as banks?

Mostly yes, with the four structural differences above. Credit unions and banks share the CFPB Chapter X consumer-protection rulebook (Regulations B, E, P, X, Z, F, and V), the Bank Secrecy Act, OFAC, and fair-lending statutes. The differences are the regulator (NCUA vs. OCC / FDIC / Federal Reserve), the deposit-disclosure rule (NCUA Part 707 vs. Regulation DD), the advertising rule (NCUA Part 740), and the mutual, tax-exempt structure.

Who supervises a credit union with $12 billion in assets?

Both. The NCUA continues as the prudential and safety-and-soundness supervisor. The CFPB supervises for federal consumer financial law under Dodd-Frank once the credit union crosses $10 billion in assets. State-chartered credit unions above the threshold are also supervised by the state regulator for the state charter.

Which NCUA regulations should every compliance officer know cold?

At minimum: Part 740 (advertising), Part 707 (Truth in Savings), Part 741 (federal insurance requirements), Part 748 (security and cybersecurity, plus the Safeguards Rule in Appendix A), Part 749 (records preservation), and Part 712 (CUSOs) if the credit union has any partner-organisation exposure. Above those, the CFPB Chapter X regulations that apply to credit unions.

Is the NCUA about to remove the insured-statement requirement?

The NCUA Board proposed removing 12 CFR 740.5 (the official advertising statement) in December 2025, describing it as poorly suited to digital and social media (Federal Register, 29 Dec 2025). The comment period closed 27 February 2026. Until the rule is finalised, §740.5 stays in force, and ads should still carry the statement. The proposal would not change the §740.4 sign requirement or the §740.2 accuracy standard.

Does UDAAP apply to a credit union collecting its own loans?

Yes. A first-party creditor is usually outside the FDCPA definition of "debt collector," but the UDAAP prohibition in Dodd-Frank Sections 1031 and 1036 applies to the collection of a consumer's own debts. CFPB Bulletin 2013-07 confirms this and treats FDCPA-type conduct as potential UDAAP even where the FDCPA does not technically apply.

What triggers a Suspicious Activity Report at a credit union?

At a federally insured credit union, the SAR filing obligation is codified in NCUA Part 748 and the FinCEN rules. A SAR is required for any transaction the credit union knows, suspects, or has reason to suspect involves funds derived from illegal activity, is intended to evade the BSA, has no apparent lawful purpose, or facilitates criminal activity — where the transaction, or aggregated transactions, meets the applicable dollar threshold. Structuring, unusual cash activity, wire transfers with high-risk jurisdictions, and elder-exploitation indicators are common triggers.

What is the CFPB's 1033 rule and does it apply to us?

Section 1033 of Dodd-Frank required the CFPB to write a rule giving consumers access to their financial data. The CFPB finalised the Personal Financial Data Rights rule in October 2024 (12 CFR Part 1033). Depository institutions above the applicable asset threshold must, on the timelines the rule sets, make covered data available to consumers and to authorised third parties via standardised interfaces. Below the threshold, the rule imposes a lighter set of obligations. Credit unions should confirm their applicable tier and begin implementation planning if not already underway.

How do we handle a state data-breach notification when we operate in multiple states?

Every US state has its own breach-notification statute, with different definitions of personal information, notification triggers, timelines, and regulator-notification requirements. GLBA and NCUA Part 748 add federal expectations of prompt regulator notification on material breach events. A written incident-response plan under Part 748 Appendix B should map, in advance, which state statute governs each member's residence and which regulator notifications need to fire.

Do credit unions have to comply with the Military Lending Act?

Yes. The Military Lending Act (10 U.S.C. 987 and 32 CFR Part 232) caps the Military Annual Percentage Rate at 36% for covered borrowers on most consumer credit products and imposes specific disclosures, prohibited terms, and mandatory checks against the DoD MLA database or a covered credit reporting agency. NCUA examines federally insured credit unions for MLA compliance during consumer-compliance exams.

What does 'field of membership' have to do with compliance?

Field of membership is not just a chartering question. It is a compliance surface because advertising or member-facing communications that overstate eligibility — for example, unqualified "anyone can join" claims — are treated as inaccurate or deceptive under NCUA §740.2. NCUA Letter 13-FCU-03 walks through the specific patterns. Marketing teams and compliance teams both need to work from the same current field-of-membership statement.

Is UDAAP really a bigger risk than the specific rules?

Often, yes. Specific rules like Regulation Z or Regulation E give you a checklist you can operationalise. UDAAP is a principle-based standard that catches conduct even when the checklists have been followed. The CFPB's largest consumer-protection enforcement outcomes are frequently framed as UDAAP even where a specific-rule violation could also be pleaded, because UDAAP reaches consumer-injury outcomes rather than technical rule-book violations. Building UDAAP into the CMS explicitly — not just as a residual — is a mature-program move.

How do we prepare for an NCUA exam?

Keep the CMS documented and current: board-approved policies with dates, training records, complaint logs with root-cause analysis, audit reports, and a current risk assessment. Pre-exam questionnaires from NCUA will ask for specific artefacts — a well-run programme has these on hand rather than assembled in the two weeks before onsite work begins. Watch the annual supervisory priorities letter each January for what the examiner will lean into that year.

Sources

NCUA Quarterly Data Summary, 2026 Q1

12 CFR Chapter VII (NCUA)

12 CFR Part 707 — Truth in Savings (NCUA)

12 CFR Part 740 — Accuracy of Advertising and Notice of Insured Status

12 CFR Part 748 — Security Program (NCUA)

Federal Register — NCUA proposed rule on Part 740 (29 Dec 2025)

12 CFR Part 1002 — Regulation B (ECOA, CFPB)

12 CFR Part 1005 — Regulation E (EFTA)

12 CFR Part 1006 — Regulation F (FDCPA)

12 CFR Part 1016 — Regulation P (GLBA privacy)

12 CFR Part 1022 — Regulation V (FCRA)

12 CFR Part 1024 — Regulation X (RESPA)

12 CFR Part 1026 — Regulation Z (TILA)

12 CFR Part 229 — Regulation CC (Availability of Funds)

CFPB — Institutions subject to supervision

CFPB — UDAAPs Examination Procedures

CFPB Bulletin 2013-07 — UDAAP in debt collection

CFPB Supervision and Examination Manual

NCUA Federal Consumer Financial Protection Guide

NCUA 2025 Supervisory Priorities (Letter 25-CU-01)

NCUA Letter 13-FCU-03 — Common-bond advertising

NCUA Letter 07-CU-13 — Evaluating third-party relationships

Run compliance on autopilot

Convert your static procedures into active AI controllers that protect your brand 24/7.