From Compliance Guidance to Risk-Based Governance: What NCUA Part 748 Means for Credit Unions with Paul Kissel

Trustero's Information Security Leaders series

Show Notes

Podcast Overview

The NCUA’s proposed changes to Part 748 may remove Appendix A from the regulation, but they do not remove a credit union’s responsibility to protect member information or comply with the Gramm-Leach-Bliley Act.

In this discussion, former NCUA examiner Paul Kissel explains why credit unions should prepare for a shift from prescriptive, checklist-based compliance toward risk-based governance. He also discusses how quantitative risk analysis, continuous control monitoring, reliable evidence, and AI-powered GRC can help management make defensible decisions and clearly communicate risk to boards and regulators.

Key Discussion Highlights

What changes under the Part 748 proposal

The proposed change would remove Appendix A, which many credit unions have treated as a compliance checklist. However, Part 748 and the underlying requirements of the Gramm-Leach-Bliley Act remain in place.

Credit unions must still protect the confidentiality and security of member information, explain their information-sharing practices, and maintain an appropriate information security program.

From checklist compliance to defensible decisions

Risk-focused governance requires management to explain why safeguards were selected, how they match the institution’s size and complexity, and what evidence supports those decisions.

The focus is no longer simply whether a task was completed. Credit unions must demonstrate that their decisions are appropriate for their unique risk profile.

Every credit union has a different risk profile

A smaller credit union and a multibillion-dollar institution have very different technology environments, services, third-party relationships, and operational complexity.

The correct question is not whether a credit union uses the same controls as its peers. The question is whether its safeguards are appropriate for its own exposure.

Translating cyber risk into business terms

Paul recommends using quantitative risk analysis to translate vulnerabilities and control gaps into business measures such as:

  • Expected annual loss
  • Severe-loss scenarios
  • Net-worth impact
  • Earnings impact
  • Residual risk
  • Control effectiveness

These figures help boards understand cybersecurity as a business and financial issue rather than a collection of technical metrics.

Continuous control monitoring and reliable evidence

Annual assessments and last-minute evidence collection do not provide an accurate picture of current risk.

Credit unions need a continuous process for collecting evidence, testing controls, tracking findings, monitoring remediation, and identifying changes in exposure.

How AI supports credit union governance

AI agents can continuously collect evidence, test controls, review policies, identify design and operational deficiencies, and produce reports with reasoning and citations.

This can reduce the manual work involved in governance and allow GRC teams to focus on judgment, prioritization, and risk decisions.

Five Major Takeaways

1. Reassess the information security governance program

Credit unions should use the proposed Part 748 changes as an opportunity to review how risks are identified, evaluated, controlled, documented, and reported.

The objective is not necessarily to rebuild the entire program. It is to rationalize the existing process and ensure it reflects the institution’s current risk profile.

2. Quantify the institution’s business exposure

Translate cyber events into financial and operational impact.

Management should understand how potential losses could affect earnings, capital, net worth, critical services, and strategic objectives.

3. Connect safeguards directly to identified risks

For every material risk, determine which controls reduce that risk and how much mitigation those controls are expected to provide.

Management must be able to explain why each safeguard is appropriate for the credit union’s size, complexity, services, and exposure.

4. Continuously test controls and maintain evidence

Do not wait until an audit or examination to gather documentation.

Continuously collect reliable evidence, test whether controls are operating effectively, track findings, and verify that remediation has occurred.

5. Give boards and regulators clear, current information

Replace large packets of technical metrics with timely information about exposure, financial impact, control effectiveness, residual risk, and remediation priorities.

The board should be able to understand what the risk is, why management made a particular decision, and whether the chosen controls are working.

Chapter Markers

00:00 – Introduction and Paul Kissel’s NCUA background

01:25 – What the NCUA Part 748 proposal means

02:35 – The four major topics covered in the discussion

03:05 – What changes and what remains unchanged

04:55 – Moving from checklist compliance to risk-based governance

06:45 – Why risk is contextual for every credit union

08:30 – Translating technical risk for executives and boards

10:00 – Why credit unions need quantitative risk analysis

11:05 – Risk assessment as a continuous management cycle

12:45 – How institutional size and services affect exposure

14:00 – Estimating annual and severe cyber losses

15:45 – Measuring impact on net worth and earnings

17:10 – The cybersecurity ratio and control effectiveness

18:05 – Combining quantitative risk analysis with Trustero

19:20 – Continuous evidence collection and examination readiness

21:00 – AI agents for control testing and gap identification

22:25 – Reliable evidence from an examiner’s perspective

23:40 – Asset inventory, unsupported systems, and exposure

25:35 – Why last-minute audit preparation fails

26:40 – Tracking findings, remediation, and residual risk

28:10 – Turning vulnerabilities into financial exposure

29:00 – Fraud, insider risk, and business email compromise

31:00 – Using AI to continuously test operational controls

32:30 – Expanding AI governance beyond cybersecurity

33:35 – Copilot risks, context, and secure AI use

35:00 – How Trustero differs from traditional GRC tools

36:30 – Recommended actions for credit unions

38:00 – Questions management should be able to answer

39:10 – Cyber insurance and proving control effectiveness

40:00 – Current evidence, board oversight, and regulatory defensibility

41:35 – Audience Q&A begins

42:00 – Do credit unions need to replace existing processes?

43:30 – How often should risk profiles be reassessed?

44:20 – Vendor risk and shared responsibility

47:05 – Why annual risk assessments are insufficient

48:10 – Why traditional GRC tools often add complexity

49:00 – Trustero Playbooks and business impact assessments

50:25 – AI accuracy, consistency, reasoning, and citations

52:00 – Closing remarks

Concise Podcast Summary

Paul Kissel explains that the proposed removal of Appendix A from NCUA Part 748 does not reduce credit unions’ information security responsibilities. Instead, it increases the importance of risk-based decision-making.

Credit unions will need to demonstrate that their safeguards are appropriate for their unique exposure, explain those decisions to boards and regulators, and support them with current, reliable evidence.

Paul recommends quantitative risk analysis to express cybersecurity exposure in financial terms. He also explains how continuous control monitoring and AI-powered platforms such as Trustero can automate evidence collection, control testing, gap identification, and reporting.

The central message is that credit unions should move away from periodic, checklist-driven compliance and build a continuous governance process based on measurable risk, effective controls, and defensible evidence.

Join Trustero for a conversation with Paul Kissel, a former NCUA information systems examiner and founder of Akudaikon, as they explore the proposed changes to NCUA Part 748 and what the shift away from Appendix A could mean for credit union information security programs.

The discussion examines why removing prescriptive guidance does not reduce a credit union’s responsibility to protect member information. Instead, it places greater emphasis on management’s ability to understand its unique risk profile, select appropriate safeguards, and support its decisions with current, reliable evidence.

Paul explains why risk-focused governance requires more than policies, frameworks, and completed checklists. Credit unions must be able to translate technical findings, vulnerabilities, vendor assessments, and control gaps into clear business impacts that executives and board members can understand. The conversation also explores how quantitative risk analysis can connect cybersecurity exposure to potential financial loss, earnings, capital, and strategic objectives.

The webinar also looks at how Trustero can help credit unions move from periodic audit preparation to continuous governance. By connecting to organizational systems, collecting control evidence, and using AI agents to test whether controls are properly designed and operating effectively, Trustero helps organizations maintain a structured and repeatable view of their risk and compliance posture.

Paul and the Trustero team also discuss the practical challenges credit unions face, including incomplete asset inventories, outdated documentation, unresolved audit findings, vendor risk, shared responsibility gaps, fraud controls, and the difficulty of proving that safeguards are working as intended. They explain why waiting until an examination or audit to collect evidence often leaves organizations without enough time to identify and remediate problems.

The conversation also covers how AI can make continuous control monitoring more accessible to smaller credit unions with limited risk and compliance resources. Trustero’s specialized agents can analyze evidence, test controls, identify deficiencies, and provide answers with supporting reasoning and source citations, allowing human reviewers to verify the results.

Tune in for a practical discussion on how credit unions can respond to the proposed Part 748 changes, strengthen risk-based governance, improve examiner confidence, and use AI to maintain a more continuous, evidence-based information security program.

One system. Any framework.

Each control is mapped to multiple applicable security frameworks, giving your team true scalability and efficiency. Trustero supports every major framework.

And more