From Compliance Guidance to Risk-Based Governance: What NCUA Part 748 Means for Credit Unions with Paul Kissel
Trustero's Information Security Leaders series
Show Notes
Podcast Overview
The NCUA’s proposed changes to Part 748 may remove Appendix A from the regulation, but they do not remove a credit union’s responsibility to protect member information or comply with the Gramm-Leach-Bliley Act.
In this discussion, former NCUA examiner Paul Kissel explains why credit unions should prepare for a shift from prescriptive, checklist-based compliance toward risk-based governance. He also discusses how quantitative risk analysis, continuous control monitoring, reliable evidence, and AI-powered GRC can help management make defensible decisions and clearly communicate risk to boards and regulators.
Key Discussion Highlights
What changes under the Part 748 proposal
The proposed change would remove Appendix A, which many credit unions have treated as a compliance checklist. However, Part 748 and the underlying requirements of the Gramm-Leach-Bliley Act remain in place.
Credit unions must still protect the confidentiality and security of member information, explain their information-sharing practices, and maintain an appropriate information security program.
From checklist compliance to defensible decisions
Risk-focused governance requires management to explain why safeguards were selected, how they match the institution’s size and complexity, and what evidence supports those decisions.
The focus is no longer simply whether a task was completed. Credit unions must demonstrate that their decisions are appropriate for their unique risk profile.
Every credit union has a different risk profile
A smaller credit union and a multibillion-dollar institution have very different technology environments, services, third-party relationships, and operational complexity.
The correct question is not whether a credit union uses the same controls as its peers. The question is whether its safeguards are appropriate for its own exposure.
Translating cyber risk into business terms
Paul recommends using quantitative risk analysis to translate vulnerabilities and control gaps into business measures such as:
- Expected annual loss
- Severe-loss scenarios
- Net-worth impact
- Earnings impact
- Residual risk
- Control effectiveness
These figures help boards understand cybersecurity as a business and financial issue rather than a collection of technical metrics.
Continuous control monitoring and reliable evidence
Annual assessments and last-minute evidence collection do not provide an accurate picture of current risk.
Credit unions need a continuous process for collecting evidence, testing controls, tracking findings, monitoring remediation, and identifying changes in exposure.
How AI supports credit union governance
AI agents can continuously collect evidence, test controls, review policies, identify design and operational deficiencies, and produce reports with reasoning and citations.
This can reduce the manual work involved in governance and allow GRC teams to focus on judgment, prioritization, and risk decisions.
Five Major Takeaways
1. Reassess the information security governance program
Credit unions should use the proposed Part 748 changes as an opportunity to review how risks are identified, evaluated, controlled, documented, and reported.
The objective is not necessarily to rebuild the entire program. It is to rationalize the existing process and ensure it reflects the institution’s current risk profile.
2. Quantify the institution’s business exposure
Translate cyber events into financial and operational impact.
Management should understand how potential losses could affect earnings, capital, net worth, critical services, and strategic objectives.
3. Connect safeguards directly to identified risks
For every material risk, determine which controls reduce that risk and how much mitigation those controls are expected to provide.
Management must be able to explain why each safeguard is appropriate for the credit union’s size, complexity, services, and exposure.
4. Continuously test controls and maintain evidence
Do not wait until an audit or examination to gather documentation.
Continuously collect reliable evidence, test whether controls are operating effectively, track findings, and verify that remediation has occurred.
5. Give boards and regulators clear, current information
Replace large packets of technical metrics with timely information about exposure, financial impact, control effectiveness, residual risk, and remediation priorities.
The board should be able to understand what the risk is, why management made a particular decision, and whether the chosen controls are working.
Chapter Markers
00:00 – Introduction and Paul Kissel’s NCUA background
01:25 – What the NCUA Part 748 proposal means
02:35 – The four major topics covered in the discussion
03:05 – What changes and what remains unchanged
04:55 – Moving from checklist compliance to risk-based governance
06:45 – Why risk is contextual for every credit union
08:30 – Translating technical risk for executives and boards
10:00 – Why credit unions need quantitative risk analysis
11:05 – Risk assessment as a continuous management cycle
12:45 – How institutional size and services affect exposure
14:00 – Estimating annual and severe cyber losses
15:45 – Measuring impact on net worth and earnings
17:10 – The cybersecurity ratio and control effectiveness
18:05 – Combining quantitative risk analysis with Trustero
19:20 – Continuous evidence collection and examination readiness
21:00 – AI agents for control testing and gap identification
22:25 – Reliable evidence from an examiner’s perspective
23:40 – Asset inventory, unsupported systems, and exposure
25:35 – Why last-minute audit preparation fails
26:40 – Tracking findings, remediation, and residual risk
28:10 – Turning vulnerabilities into financial exposure
29:00 – Fraud, insider risk, and business email compromise
31:00 – Using AI to continuously test operational controls
32:30 – Expanding AI governance beyond cybersecurity
33:35 – Copilot risks, context, and secure AI use
35:00 – How Trustero differs from traditional GRC tools
36:30 – Recommended actions for credit unions
38:00 – Questions management should be able to answer
39:10 – Cyber insurance and proving control effectiveness
40:00 – Current evidence, board oversight, and regulatory defensibility
41:35 – Audience Q&A begins
42:00 – Do credit unions need to replace existing processes?
43:30 – How often should risk profiles be reassessed?
44:20 – Vendor risk and shared responsibility
47:05 – Why annual risk assessments are insufficient
48:10 – Why traditional GRC tools often add complexity
49:00 – Trustero Playbooks and business impact assessments
50:25 – AI accuracy, consistency, reasoning, and citations
52:00 – Closing remarks
Concise Podcast Summary
Paul Kissel explains that the proposed removal of Appendix A from NCUA Part 748 does not reduce credit unions’ information security responsibilities. Instead, it increases the importance of risk-based decision-making.
Credit unions will need to demonstrate that their safeguards are appropriate for their unique exposure, explain those decisions to boards and regulators, and support them with current, reliable evidence.
Paul recommends quantitative risk analysis to express cybersecurity exposure in financial terms. He also explains how continuous control monitoring and AI-powered platforms such as Trustero can automate evidence collection, control testing, gap identification, and reporting.
The central message is that credit unions should move away from periodic, checklist-driven compliance and build a continuous governance process based on measurable risk, effective controls, and defensible evidence.
Join Trustero for a conversation with Paul Kissel, a former NCUA information systems examiner and founder of Akudaikon, as they explore the proposed changes to NCUA Part 748 and what the shift away from Appendix A could mean for credit union information security programs.
The discussion examines why removing prescriptive guidance does not reduce a credit union’s responsibility to protect member information. Instead, it places greater emphasis on management’s ability to understand its unique risk profile, select appropriate safeguards, and support its decisions with current, reliable evidence.
Paul explains why risk-focused governance requires more than policies, frameworks, and completed checklists. Credit unions must be able to translate technical findings, vulnerabilities, vendor assessments, and control gaps into clear business impacts that executives and board members can understand. The conversation also explores how quantitative risk analysis can connect cybersecurity exposure to potential financial loss, earnings, capital, and strategic objectives.
The webinar also looks at how Trustero can help credit unions move from periodic audit preparation to continuous governance. By connecting to organizational systems, collecting control evidence, and using AI agents to test whether controls are properly designed and operating effectively, Trustero helps organizations maintain a structured and repeatable view of their risk and compliance posture.
Paul and the Trustero team also discuss the practical challenges credit unions face, including incomplete asset inventories, outdated documentation, unresolved audit findings, vendor risk, shared responsibility gaps, fraud controls, and the difficulty of proving that safeguards are working as intended. They explain why waiting until an examination or audit to collect evidence often leaves organizations without enough time to identify and remediate problems.
The conversation also covers how AI can make continuous control monitoring more accessible to smaller credit unions with limited risk and compliance resources. Trustero’s specialized agents can analyze evidence, test controls, identify deficiencies, and provide answers with supporting reasoning and source citations, allowing human reviewers to verify the results.
Tune in for a practical discussion on how credit unions can respond to the proposed Part 748 changes, strengthen risk-based governance, improve examiner confidence, and use AI to maintain a more continuous, evidence-based information security program.



