AI Governance Framework and What CUs are Doing Focus of Third Installment of AI Imperative Series

Editor’s Note: This story has been updated from its original reporting to clarify that George Estrada is with Rize Credit Union

BOULDER CITY, Nev. — As credit unions move artificial intelligence from experimentation into everyday operations, two technology-focused credit union leaders said institutions need governance frameworks that protect member data and establish accountability without becoming so restrictive they stifle innovation.

Linda Bodie, CEO of Element Federal Credit Union in West Virginia, and George Estrada, CTIO with Rize Credit Union in California and Nevada, discussed AI oversight during “The AI Imperative: AI Oversight, Authority and Kill Switches,” the third installment of a seven-part webinar series hosted by The CU Daily and Mitchell Stankovic and Associates.

Bodie said AI governance should establish how the technology can be used, what information it can access, who remains accountable and how its output is verified.

“It’s not a manual that sits on a shelf,” Bodie said. “It is actually knowing where the AI is working, what it’s touching and who’s checking it.”

Governance Must Evolve With AI

Estrada said Rize has adopted what he described as a “minimum viable governance” framework because AI technology and use cases are changing too rapidly for static policies.

Using AI internally to prepare board reports, for example, presents substantially different risks than applications involving member data or personally identifiable information.

Rize reviews its AI governance monthly and has created an AI business analyst position responsible in part for monitoring and calibrating those policies, Estrada said.

The most important line credit unions must draw involves member information.

“You gotta be very steadfast and hold the line on member data and PII,” Estrada said.

He cautioned that nearly every technology vendor is adding AI capabilities, potentially reversing years of work by credit unions to eliminate data silos. Institutions need to know where information resides, who can access it and how many outside services touch it, he said.

AI Already Producing Results

Both credit unions are already using AI extensively.

Bodie said Element initially used the technology for research, regulatory analysis and improving policies and procedures. Its applications have expanded to training, marketing and product development.

Element’s Pink Tax Payback Rewards card was developed with AI, Bodie said, adding that she was able to take an idea to a nearly finished product in about 10 hours.

But AI-generated work can’t simply be accepted as accurate or compliant.

“It does not consider compliance,” Bodie said. “It goes off the rails.”

Element uses different AI tools to cross-check work and brings in attorneys when issues warrant additional review.

Rize is using AI for board reports, financial analysis and predictive models while building AI agents and internal knowledge bases. Estrada said those applications remain internally focused for now.

The credit union also used an AI-powered knowledge base to prepare for its recent NCUA examination, helping employees respond to information requests without working additional hours.

Estrada said examiners focused on governance, making it important that Rize could explain not only its policies but the reasoning and documentation supporting them.

Employees Need Guardrails, Not Prohibitions

Bodie said Element, which has 18 employees, has some workers eager to experiment with AI and others who want little to do with it.

The challenge is allowing experimentation while ensuring employees don’t inadvertently expose member or credit union information.

Estrada said Rize, with approximately 200 employees, similarly has sought to avoid becoming an organization that “always says no.”

The credit union has implemented security tools intended to prevent confidential information from being uploaded while developing internal AI tools employees can use safely.

“We’re deploying these tools to amplify you,” Estrada said of the message to employees, rather than replace them.

Rize also plans to give directors AI tools allowing them to query current and historical board packages, Estrada said.

Bodie said board oversight at Element is approached similarly to cybersecurity: Directors need education about their responsibilities, the tools being used and how those applications affect the institution.

Privacy, Bias Remain Concerns

Asked about AI risks, Bodie identified data privacy as the most immediate operational concern, followed by inaccurate answers, or hallucinations, and bias embedded in AI models.

She said users must actively review and challenge AI-generated results rather than assume the technology is neutral or accurate.

Estrada said another concern is the concentration of increasingly powerful AI models among a handful of large technology companies, creating potential blind spots around how information and safeguards are controlled.

For credit unions, both said the response isn’t to stop using AI, but to ensure governance evolves alongside it.

That means knowing what AI is doing, protecting member information, documenting decisions and keeping humans accountable for the results — while leaving employees enough room to discover what the technology can do.

For more info on the webinar series, go here.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.