The following is an article written by Optiri's Director, Security and Resilience, Tim Daugherty. It originally appeared on CUInsight.com.
Artificial intelligence (AI) is no longer a future consideration for credit unions; it is already influencing how they detect fraud, serve members, monitor cyber threats, evaluate vendors and make operational decisions. For business continuity and operational resiliency leaders, this creates an important shift. AI is not just another technology to support efficiency: it is becoming part of the resilience ecosystem itself while also introducing new risks that must be governed, tested and controlled.
For credit unions, the issue is especially important because member trust depends on consistent access to financial services. A disruption to digital banking, payments, lending, debit card processing, call center operations or third-party platforms can quickly become more than a technology issue. It can affect member confidence, regulatory scrutiny, reputation and the credit union’s ability to fulfill its mission. AI can help strengthen readiness, but only if it is incorporated into business continuity, incident response, vendor risk management, cybersecurity, and governance programs in a disciplined way.
One practical example is fraud detection. Many credit unions already depend on systems that analyze member transaction activity and identify behavior that appears unusual. AI can help these tools recognize patterns more quickly than traditional rules-based monitoring. For example, if a member’s debit card is suddenly used in multiple locations or for activity inconsistent with normal behavior, AI-assisted monitoring may help identify the concern earlier and support faster intervention. This can reduce losses, protect members and limit operational disruption during fraud events. The NCUA has identified fraud detection, member service, cybersecurity and other operational uses as areas where credit unions are exploring AI-enabled solutions.
AI can also support cybersecurity resilience. During a ransomware event, phishing campaign, credential compromise or unusual network activity, security teams may receive a large volume of alerts. AI-enabled tools can help organize those signals, highlight unusual behavior and support faster triage by security personnel. The value is not that AI replaces judgment, but that it can help teams recognize potential threats sooner and focus attention where it matters most. This is increasingly important as cyber threats evolve and attackers use automation and AI-assisted techniques to increase speed and sophistication.
Member service is another area where AI can improve continuity. A credit union experiencing severe weather, a branch closure, a digital banking outage or a call center surge may use AI-supported chatbots or virtual assistants to answer routine questions, provide status updates and route members to the right support channels. When properly governed, these tools can reduce pressure on staff and help members receive timely information during disruptions. However, they must be tested to ensure they provide accurate, approved and member-appropriate responses during high-stress events. (For more information on how severe weather is impacting credit unions, register for my upcoming webinar, “Business Continuity Planning vs. Resiliency Planning During El Nino and Weather-Driven Natural Disasters: A Credit Union Perspective.”)
AI can also improve operational awareness. For example, a credit union could use AI-enabled analytics to review outage history, vendor performance, incident logs, recovery times, member complaint themes or help desk trends. These insights can help leaders identify recurring weaknesses before they create a larger disruption. If a critical third-party provider repeatedly experiences service degradation, AI-supported reporting may help management identify that pattern earlier and escalate the concern through vendor management, business continuity or enterprise risk channels. Internal resiliency planning materials also recognize predictive analytics, dependency analysis, member communication and AI-supported response guidance as potential future capabilities for strengthening operational resilience.
While AI can strengthen resilience, it also expands the risk landscape. Credit unions should not assume that AI-enabled systems are always accurate, available, explainable, or appropriate for every operational decision. A chatbot may provide incomplete information during an outage. A fraud model may generate false positives that frustrate members. A vendor-provided AI tool may become unavailable during a cyber event. An automated workflow may fail if it depends on incomplete or poor-quality data.
That is why AI must be included in the credit union’s operational resilience framework. AI-enabled systems should be documented in the business impact analysis, mapped to critical services, evaluated for recovery requirements and included in tabletop exercises where appropriate. If an AI supported tool is used in fraud, lending, cybersecurity, member service or operational decision making, management should understand the impact if the tool fails, produces inaccurate results or becomes unavailable.
Vendor risk is especially important. Many AI capabilities are provided by fintechs, core processors, cloud providers, cybersecurity firms, lending platforms, and member service vendors. The NCUA has noted that AI can create added considerations involving third-party relationships, data protection, model risk, operational resilience, and oversight. Credit unions should ensure vendor due diligence addresses how AI is used, what member or operational data is involved, how availability is maintained, what incident notification commitments exist, and how the vendor validates performance and security.
AI governance does not need to exist in isolation. For most credit unions, the better approach is to embed AI oversight into existing governance structures: enterprise risk management, information security, vendor management, compliance, internal audit, business continuity, and board reporting.
Relevant regulatory and supervisory expectations already point in this direction. The NCUA’s AI resources emphasize the importance of risk management, third-party due diligence, data security, operational resilience, and governance when credit unions evaluate or implement AI. Existing information security expectations under NCUA Part 748 and FFIEC guidance continue to apply when AI systems process sensitive data, support cybersecurity functions, or affect critical operations. The FFIEC Business Continuity Management Handbook also reinforces the broader expectation that financial institutions manage continuity as an ongoing governance and resilience discipline, not merely as a recovery document.
Credit union leaders should consider the following actions:
AI can help credit unions become more resilient by improving detection, accelerating analysis, supporting member communication, and identifying risks earlier. But AI also creates new dependencies that must be governed with the same discipline applied to cybersecurity, third-party providers, disaster recovery, and critical operations.
The credit unions that benefit most from AI will not be those that simply adopt new tools; they will be the ones that understand where AI is used, how it affects member service, what could go wrong, and how the organization will continue operating if those tools fail. AI should be treated as part of the credit union’s operational resiliency strategy and be governed, tested, monitored, and aligned with the obligation to protect members and maintain trust under all conditions.