Foster Again Introduces Bill to Give NCUA Supervisory Authority Over Third-Party Vendors

WASHINGTON — Rep. Bill Foster (D-IL) is renewing an effort to give the National Credit Union Administration direct supervisory authority over third-party vendors serving credit unions, reviving a proposal that in the past has drawn opposition from credit union trade groups concerned about additional regulatory costs and expansion of the agency’s authority.

The Defense Credit Union Council has already announced opposition to the measure, as reported here.

Foster announced he has introduced the Strengthening Oversight for the Financial Sector Act, which would give both the NCUA and Federal Housing Finance Agency authority to oversee third-party vendors used by institutions they regulate. Foster said the legislation is increasingly important as financial institutions rely on outside technology providers and artificial intelligence creates new cybersecurity risks.

The fate of the legislation, however, is iffy at best given the current state of Congress, the midterm elections and a short session calendar.

Rep. Bill Foster

“As AI makes cyberattacks more sophisticated, it is even more important to ensure that third-party vendors don’t become a weak link in our financial system,” Foster said in announcing the legislation. “We have learned the hard way how much damage supply chain vulnerabilities can cause, and third-party vendors are attractive targets.”

Foster said the legislation would give regulators additional tools to protect consumers’ money and sensitive information from AI-assisted cyber threats.

NCUA Authority Expired in 2002

The proposal would restore authority the NCUA temporarily held from 1998 until 2002, when Congress allowed the agency to examine third-party service providers as financial institutions prepared for potential technology problems associated with the Y2K transition.

Unlike federal banking regulators, the NCUA currently does not have general statutory authority to directly supervise and enforce requirements against third-party service providers used by credit unions. Some members of the NCUA board have previously repeatedly asked Congress to restore that authority, arguing that its inability to directly examine vendors creates a regulatory blind spot as credit unions increasingly outsource technology and other critical functions.

The agency has said third-party vendor authority would allow it to better evaluate cybersecurity, anti-money laundering, consumer protection and safety-and-soundness risks affecting credit unions and the National Credit Union Share Insurance Fund.

In his statement, Foster said NCUA and FHFA leaders from both political parties have sought the authority. The Government Accountability Office and Financial Stability Oversight Council also have recommended expanded oversight of third-party vendors, according to Foster’s office.

Credit Union Groups Have Opposed Expansion

Credit union trade groups, however, have previously opposed legislation giving the NCUA direct third-party vendor authority.

America’s Credit Unions argued in 2024 that the NCUA should remain focused on regulating credit unions and warned that establishing a new vendor examination program could increase the agency’s budget and ultimately increase costs for credit unions.

Then-President and CEO Jim Nussle argued that the NCUA could instead obtain information about vendors through its participation in the Federal Financial Institutions Examination Council, or FFIEC, including examination information developed by other federal banking regulators. If other regulators are unwilling to provide that information, Nussle said Congress could require them to share it with the NCUA.

The Defense CU Council’s newly stated opposition to the bill can be found here.

Previous Version Advanced in House Committee

Foster has pursued the issue previously.

His Strengthening Cybersecurity for the Financial Sector Act of 2022 would have permanently restored NCUA authority over third-party vendors and provided similar authority to the FHFA. The House Financial Services Committee approved that legislation 24-22, but it did not receive a vote on the House floor.

Foster’s office said the new legislation is intended to close what it describes as an increasingly significant regulatory gap as financial institutions become more dependent on outside technology companies.

The congressman said AI adds urgency to the issue because the technology can make it easier for attackers to identify and exploit vulnerabilities in financial institutions and their vendors.

The NCUA currently holds credit unions responsible for conducting due diligence, monitoring vendors, overseeing contracts and managing cybersecurity and compliance risks associated with outsourced services, even though the agency does not directly regulate or supervise those vendors.

Facebook
Twitter
LinkedIn

One Response

  1. The Endangered Small Credit Union Defense (www.endangeredsmallCUdefense) is aligned with other credit union associations in opposition to this bill.
    -Doug Wadsworth

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.