Broad Vendor Exam Authority Would Burden Small Credit Unions

By Jason Stverak


Congress should reject broad third-party vendor examination authority for the National Credit Union Administration (NCUA). Expanding federal jurisdiction across credit union service relationships could impose substantial costs, weaken competition, and make it harder for smaller institutions to serve their members. Cybersecurity deserves a separate, focused discussion. It should not become a justification for regulatory authority that reaches far beyond demonstrated cyber risks.

Start with why credit unions use outside providers. NCUA’s own guidance recognizes that these relationships can provide expertise, economies of scale, and improved member services. For a smaller institution, hiring a specialist can make a service possible that would be impractical to build internally. Policy should preserve that opportunity while holding credit unions accountable for managing the risks.

Undermining the Balance

Broad vendor oversight could undermine that balance. A company facing additional examinations may need more compliance personnel, legal support, and documentation. Those expenses can enter the prices charged to its credit union clients. Directing an examination at a vendor does not insulate the credit union from its cost. Smaller institutions could face higher bills without receiving any additional service.

The same expense can have very different consequences depending on an institution’s scale. A large credit union can spread a fixed increase across more accounts. A smaller institution has less room to absorb it. An added compliance expense competes with investments in lending, technology, and personal service. Policymakers should recognize those choices before describing a new examination regime as a straightforward improvement.

Consider This Example

Consider a small credit union planning to introduce a better fraud detection tool. If its provider raises prices to cover overlapping regulatory demands, that institution may have to postpone another investment or reconsider the purchase. This is a foreseeable tradeoff, not a prediction about any particular provider. Congress should investigate how proposed requirements could affect the institutions with the least capacity to absorb them.

There is also a competition problem. DCUC has warned that expansive vendor authority could discourage smaller providers, slow innovation, and raise costs. If serving credit unions becomes less attractive, emerging companies may look elsewhere. Fewer choices would leave small credit unions with less bargaining power. A policy intended to reduce risk could instead deepen dependence on a narrower group of suppliers.

Small institutions also need predictable rules. Broad authority leaves them exposed to changing examination priorities and vendor responses they cannot control. Congress should put meaningful boundaries in statute, including limits on covered activities and protections against repetitive reviews. Smaller credit unions should not have to rely on regulatory restraint.

The Broader Concern

Representative Bill Foster’s H.R. 10230, the Strengthening Oversight for the Financial Sector Act of 2026, illustrates the broader concern. Section 2 would remove the expiration provision governing NCUA’s authority under Section 206A of the Federal Credit Union Act, without replacing it with another sunset. That authority originated in 1998 examination parity and Y2K legislation and expired on December 31, 2001.

The underlying statutory language reaches outsourced services authorized under federal credit union law or applicable state law. Covered activities would be examined and regulated as though performed by the credit union itself. It is not confined to cybersecurity or critical technology providers. Our September 3 letter opposing the Foster bill reflects a principle that should govern any such proposal: regulatory reach must be justified by a clearly defined need.

Cybersecurity requires its own substantive examination. Congress should identify vulnerable functions, understand how incidents occur, and evaluate which interventions would improve prevention and recovery. Credit union executives and security professionals should help shape that discussion. The seriousness of a threat strengthens the obligation to design an effective response. It does not establish that broad supervisory authority is the appropriate answer.

CUs Already Have Responsibilities

Credit unions already have responsibilities. NCUA’s supervisory framework calls for risk assessment, due diligence, monitoring, and controls over third-party relationships. Outsourcing does not remove responsibility for safeguarding member assets. The guidance also recognizes that smaller or less complex institutions may need alternative approaches and that the depth of review should reflect risk and complexity.

Those expectations are different from direct federal examination authority over vendors. Congress should examine whether existing supervision is effective and where it leaves a specific material gap. It should assess whether contractual protections, independent audits, or access to another regulator’s findings could address that gap. Any new authority should follow that analysis, with safeguards against unnecessary duplication.

For defense credit unions, these questions concern dependable service during deployments, relocations, and overseas assignments. Our letter describes the importance of specialized partners to that mission. A military family trying to resolve a payment problem needs its credit union to have reliable, affordable tools. Regulation should strengthen that capacity. Costs that crowd out useful services deserve scrutiny alongside the risks policymakers hope to address.

What Congress Should Do First

Before advancing any vendor authority proposal, Congress should publish an assessment of its effects on smaller credit unions. Examine likely contract costs, staff demands, and changes in provider choice. Explain how overlapping examinations would be avoided and how sensitive information would be protected. Require meaningful measures of security improvements, alongside transparent accounting of the resources consumed.

DCUC remains willing to discuss a narrowly designed response to a demonstrated cybersecurity gap. That willingness does not soften our opposition to sweeping vendor examination powers. Congress should reject excessive regulatory burdens, protect smaller credit unions’ ability to compete, and insist that any additional authority delivers benefits proportionate to its costs. Members deserve both secure services and credit unions capable of continuing to provide them.

Jason Stverak is chief advocacy officer with the Defense Credit Union Council

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.