July 24, 2026

From Compliance Guidance to Risk-Based Governance: What NCUA Part 748 Means for Credit Unions with Paul Kissel

Trustero's Information Security Leaders series
July 24, 2026

Join Trustero for a conversation with Paul Kissel, a former NCUA information systems examiner and founder of Akudaikon, as they explore the proposed changes to NCUA Part 748 and what the shift away from Appendix A could mean for credit union information security programs.

The discussion examines why removing prescriptive guidance does not reduce a credit union’s responsibility to protect member information. Instead, it places greater emphasis on management’s ability to understand its unique risk profile, select appropriate safeguards, and support its decisions with current, reliable evidence.

Paul explains why risk-focused governance requires more than policies, frameworks, and completed checklists. Credit unions must be able to translate technical findings, vulnerabilities, vendor assessments, and control gaps into clear business impacts that executives and board members can understand. The conversation also explores how quantitative risk analysis can connect cybersecurity exposure to potential financial loss, earnings, capital, and strategic objectives.

The webinar also looks at how Trustero can help credit unions move from periodic audit preparation to continuous governance. By connecting to organizational systems, collecting control evidence, and using AI agents to test whether controls are properly designed and operating effectively, Trustero helps organizations maintain a structured and repeatable view of their risk and compliance posture.

Paul and the Trustero team also discuss the practical challenges credit unions face, including incomplete asset inventories, outdated documentation, unresolved audit findings, vendor risk, shared responsibility gaps, fraud controls, and the difficulty of proving that safeguards are working as intended. They explain why waiting until an examination or audit to collect evidence often leaves organizations without enough time to identify and remediate problems.

The conversation also covers how AI can make continuous control monitoring more accessible to smaller credit unions with limited risk and compliance resources. Trustero’s specialized agents can analyze evidence, test controls, identify deficiencies, and provide answers with supporting reasoning and source citations, allowing human reviewers to verify the results.

Tune in for a practical discussion on how credit unions can respond to the proposed Part 748 changes, strengthen risk-based governance, improve examiner confidence, and use AI to maintain a more continuous, evidence-based information security program.