Skip to main content
Top Rated IT Provider · 5.0★ on Google · support answers in ~4 rings
ASG Information Technologies
Contact Us
FFIEC · NCUA Part 748

FFIEC & NCUA IT Compliance

Exam-ready before the exam letter arrives: ASG builds FFIEC-handbook controls into managed IT for Connecticut credit unions and community banks, and keeps the evidence current between exams.

203-440-4413
Where you'll stand with ASG
  • Examiner-ready controls, documented and tested
  • Part 748 written security program, built and maintained
  • Risk audited at least quarterly; board reporting prepared for you

Who examines whom (and why the names blur)

The FFIEC (Federal Financial Institutions Examination Council) writes the IT Examination Handbook that every examiner works from. Who shows up with it depends on your charter.

Federal credit unions
Examined by
The NCUA (National Credit Union Administration), directly
Working from
The FFIEC IT Examination Handbook
NCUA Part 748
Applies
State-chartered credit unions
Examined by
Your state banking department, with the NCUA backing it up on federally insured charters
Working from
The FFIEC IT Examination Handbook
NCUA Part 748
Applies if you're federally insured, even under a state charter
Community banks
Examined by
The FDIC, the Federal Reserve, the OCC, or your state regulator
Working from
The FFIEC IT Examination Handbook
NCUA Part 748
An NCUA rule, so not directly; equivalent expectations arrive through the handbook
Different letterhead, same handbook.

That's why the terms blur together. Whether your exam letter says NCUA, FFIEC, or your state's banking department, the substance being examined is the same set of expectations, and one well-built program answers all of them.

What Part 748 actually requires

NCUA Part 748 requires a written security program that protects member information, plus an appendix of specific safeguards:

  • Risk assessment
  • Access controls
  • Employee training
  • Vendor oversight
  • Incident response

Miss the written artifacts and the exam finding writes itself, even if the technology underneath is sound.

  • 72 hoursfor a federally insured credit union to report a reportable cyber incident to the NCUA, a hard deadline since September 2023

The assessment tools just changed

If your last exam-prep cycle used the FFIEC Cybersecurity Assessment Tool (CAT), that ground has moved.

  1. Since 2023
    NCUA credit-union exams run the Information Security Examination (ISE), with its Core and Core+ procedures.
  2. Aug 31, 2025
    The FFIEC sunsets the CAT industry-wide.
  3. Now
    The Automated Cybersecurity Evaluation Toolbox (ACET) continues as a voluntary self-assessment (the 'ACET Maturity Assessment'), its statements mapped to NIST CSF 2.0.

The practical takeaway: the NIST Cybersecurity Framework 2.0 is now the common denominator under all of it, and that's the framework ASG already standardizes every client environment against.

If your posture is CSF-aligned, exam prep becomes assembly instead of archaeology.

What examiners actually look at

Beyond the paperwork: evidence that controls operate.

  • Documented and tested disaster recovery (a claimed test with no record counts as no test)
  • Vendor and third-party oversight, with your core processor at the top of the list
  • Access reviews
  • Board-level reporting on the information security program
  • An incident response plan someone has actually rehearsed

This is where the common gap lives. Your core banking vendor covers the core, and everything around it (email, endpoints, network, backup, the audit trail) belongs to whoever runs your IT. If nobody owns that ring explicitly, the exam finds it.

How ASG carries it

ASG runs the controls inside managed IT and keeps the exam file current as a byproduct: patching, monitoring, access reviews, tested backups, and the documentation trail examiners sample. Your Technology Alignment Manager (TAM) audits your risk posture at least quarterly, so findings shrink between exams instead of accumulating. And your vCIO (your virtual CIO) owns the strategy: writing policy, making recommendations, and preparing the board reporting the program requires, in language your board can act on.

One program, mapped once, defensible everywhere.

About half of ASG's clients carry compliance requirements, and the same program that answers your examiner also answers GLBA, because the substance overlaps almost entirely.

What we do

Examiner-ready, kept that way

Exam Readiness Assessment

Your environment measured against FFIEC-handbook expectations and ISE procedures, with a prioritized gap list before the examiner finds one.

Part 748 Written Program

The written security program and appendix safeguards the rule requires, maintained as your environment changes.

ISE / ACET Preparation

Prep aligned to the ISE Core and Core+ procedures, with the voluntary ACET Maturity Assessment as your internal yardstick.

Board & Examiner Reporting

Board-level information security reporting your vCIO prepares, plus the evidence file your examiner samples.

Vendor Oversight

Third-party risk management with your core processor documented first, contracts and controls reviewed on a schedule.

Incident Response & the 72-Hour Rule

A practiced IR plan plus the reporting workflow that meets NCUA's 72-hour cyber incident deadline.

#1 Connecticut MSP · 2026 Channel Futures MSP 501 (#58 nationally) · 5.0 ★ · 104 Google reviews · Serving CT since 1997

Our clients

Credit unions ASG already keeps exam-ready

Financial-institution clients on what it's like to have ASG running their IT and compliance.

Police Credit Union of CTCredit union
State Police Credit UnionCredit union

Questions, answered straight

Related: IT for credit unions & banksCompliance & Risk servicesGLBA & FTC Safeguards complianceNIST Cybersecurity Framework alignment

Start with your FFIEC & NCUA gap assessment

Know exactly where you stand within a month: scope, score, and a prioritized roadmap. No deck, no pitch.

Call · engineer in ~4 rings