Bill That Would Give NCUA Third-Party Vendor Oversight Authority is Opposed by DCUC

WASHINGTON — The Defense Credit Union Council is opposing legislation that would give the National Credit Union Administration broader authority to examine third-party vendors, arguing the proposal goes well beyond the cybersecurity and artificial intelligence risks cited by its sponsor.

DCUC said Thursday it has sent a letter to Rep. Bill Foster (D-IL) opposing H.R. 10230, the Strengthening Oversight for the Financial Sector Act of 2026. The legislation would grant the NCUA authority to regulate and examine companies that provide services to federally insured credit unions.

As the CU Daily reports here, Foster has argued the authority is needed in part because financial institutions increasingly rely on third-party technology providers and because AI is making cyberattacks more sophisticated.

DCUC said it agrees cybersecurity risks warrant attention but contends the legislation would give the NCUA authority extending well beyond technology and cybersecurity providers.

“Our objection is not to cybersecurity as an objective,” Jason Stverak, DCUC’s chief advocacy officer, wrote in the letter. “Our concern is that the legislation is far more sweeping than the cybersecurity problem it is purportedly designed to address.”

Anthonyt Hernandez

DCUC Calls Proposal Too Broad

DCUC President and CEO Anthony Hernandez, a retired U.S. Air Force colonel, said Congress should first determine what regulatory gaps exist before expanding the NCUA’s authority.

“Cybersecurity is a serious national-security, consumer-protection, and operational priority,” Hernandez said in a statement. “However, granting NCUA sweeping authority over the full range of credit union service providers is not a narrowly tailored cybersecurity solution.”

Hernandez said lawmakers should determine why existing regulatory authorities and interagency processes are insufficient and consult credit unions that would bear the costs and operational consequences of any expanded oversight.

DCUC said it has consistently opposed giving the NCUA unrestricted third-party vendor authority because of concerns about duplicative examinations, increased regulatory expenses, reduced vendor competition and potentially slower technological innovation.

Those additional costs ultimately could be passed along to credit union members, the trade group said.

Group Seeks Limits on Vendor Authority

DCUC also argued the legislation does not establish adequate thresholds for determining which vendors should be subject to direct NCUA oversight.

The organization said the proposal does not sufficiently distinguish between critical technology providers with access to sensitive financial information and ordinary vendors presenting significantly less risk.

DCUC also said the legislation does not expressly require the NCUA to rely on examinations performed by other federal or state regulators before conducting its own review, potentially resulting in duplicative regulatory oversight.

“It remains unclear how expanding NCUA’s jurisdiction over thousands of private companies would have prevented past cyber breaches, especially when federal agencies and federal contractors with extensive oversight and cybersecurity resources continue to experience similar incidents,” Stverak said. “Regulatory authority is not, by itself, a cybersecurity control.”

If Congress determines additional authority is necessary, DCUC said it should be limited to material cybersecurity, data protection and operational resilience risks involving critical service providers.

Existing CU Oversight Cited

DCUC noted that NCUA examiners already assess how credit unions manage third-party relationships, including whether institutions conduct appropriate due diligence, protect member information, negotiate contractual safeguards, monitor vendor performance and maintain cybersecurity and incident-response programs.

The group said Congress should consider whether greater information sharing among financial regulators, increased reliance on existing examination findings, stronger cybersecurity threat-information sharing or joint examinations of critical service providers could address regulatory gaps without creating another examination structure.

“Congress should first determine whether greater information sharing among federal financial regulators, reliance on existing examination findings, stronger threat-information sharing, or joint examinations of genuinely critical providers could address identified vulnerabilities without creating a new and duplicative regulatory structure,” Stverak said.

DCUC said it has offered to meet with Foster and his staff to discuss the legislation and provide input from credit union executives and cybersecurity professionals.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.