FFIEC & NCUA IT Compliance
Exam-ready before the exam letter arrives: ASG builds FFIEC-handbook controls into managed IT for Connecticut credit unions and community banks, and keeps the evidence current between exams.
- ✓Examiner-ready controls, documented and tested
- ✓Part 748 written security program, built and maintained
- ✓Risk audited at least quarterly; board reporting prepared for you
Who examines whom (and why the names blur)
The FFIEC (Federal Financial Institutions Examination Council) writes the IT Examination Handbook that every examiner works from. Who shows up with it depends on your charter.
- Examined by
- The NCUA (National Credit Union Administration), directly
- Working from
- The FFIEC IT Examination Handbook
- NCUA Part 748
- Applies
- Examined by
- Your state banking department, with the NCUA backing it up on federally insured charters
- Working from
- The FFIEC IT Examination Handbook
- NCUA Part 748
- Applies if you're federally insured, even under a state charter
- Examined by
- The FDIC, the Federal Reserve, the OCC, or your state regulator
- Working from
- The FFIEC IT Examination Handbook
- NCUA Part 748
- An NCUA rule, so not directly; equivalent expectations arrive through the handbook
Different letterhead, same handbook.
That's why the terms blur together. Whether your exam letter says NCUA, FFIEC, or your state's banking department, the substance being examined is the same set of expectations, and one well-built program answers all of them.
What Part 748 actually requires
NCUA Part 748 requires a written security program that protects member information, plus an appendix of specific safeguards:
- Risk assessment
- Access controls
- Employee training
- Vendor oversight
- Incident response
Miss the written artifacts and the exam finding writes itself, even if the technology underneath is sound.
- 72 hoursfor a federally insured credit union to report a reportable cyber incident to the NCUA, a hard deadline since September 2023
The assessment tools just changed
If your last exam-prep cycle used the FFIEC Cybersecurity Assessment Tool (CAT), that ground has moved.
- Since 2023NCUA credit-union exams run the Information Security Examination (ISE), with its Core and Core+ procedures.
- Aug 31, 2025The FFIEC sunsets the CAT industry-wide.
- NowThe Automated Cybersecurity Evaluation Toolbox (ACET) continues as a voluntary self-assessment (the 'ACET Maturity Assessment'), its statements mapped to NIST CSF 2.0.
The practical takeaway: the NIST Cybersecurity Framework 2.0 is now the common denominator under all of it, and that's the framework ASG already standardizes every client environment against.
If your posture is CSF-aligned, exam prep becomes assembly instead of archaeology.
What examiners actually look at
Beyond the paperwork: evidence that controls operate.
- Documented and tested disaster recovery (a claimed test with no record counts as no test)
- Vendor and third-party oversight, with your core processor at the top of the list
- Access reviews
- Board-level reporting on the information security program
- An incident response plan someone has actually rehearsed
This is where the common gap lives. Your core banking vendor covers the core, and everything around it (email, endpoints, network, backup, the audit trail) belongs to whoever runs your IT. If nobody owns that ring explicitly, the exam finds it.
How ASG carries it
ASG runs the controls inside managed IT and keeps the exam file current as a byproduct: patching, monitoring, access reviews, tested backups, and the documentation trail examiners sample. Your Technology Alignment Manager (TAM) audits your risk posture at least quarterly, so findings shrink between exams instead of accumulating. And your vCIO (your virtual CIO) owns the strategy: writing policy, making recommendations, and preparing the board reporting the program requires, in language your board can act on.
One program, mapped once, defensible everywhere.
About half of ASG's clients carry compliance requirements, and the same program that answers your examiner also answers GLBA, because the substance overlaps almost entirely.
Examiner-ready, kept that way
Exam Readiness Assessment
Your environment measured against FFIEC-handbook expectations and ISE procedures, with a prioritized gap list before the examiner finds one.
Part 748 Written Program
The written security program and appendix safeguards the rule requires, maintained as your environment changes.
ISE / ACET Preparation
Prep aligned to the ISE Core and Core+ procedures, with the voluntary ACET Maturity Assessment as your internal yardstick.
Board & Examiner Reporting
Board-level information security reporting your vCIO prepares, plus the evidence file your examiner samples.
Vendor Oversight
Third-party risk management with your core processor documented first, contracts and controls reviewed on a schedule.
Incident Response & the 72-Hour Rule
A practiced IR plan plus the reporting workflow that meets NCUA's 72-hour cyber incident deadline.
#1 Connecticut MSP · 2026 Channel Futures MSP 501 (#58 nationally) · 5.0 ★ · 104 Google reviews · Serving CT since 1997
Credit unions ASG already keeps exam-ready
Financial-institution clients on what it's like to have ASG running their IT and compliance.
Questions, answered straight
Related: IT for credit unions & banksCompliance & Risk servicesGLBA & FTC Safeguards complianceNIST Cybersecurity Framework alignment
Start with your FFIEC & NCUA gap assessment
Know exactly where you stand within a month: scope, score, and a prioritized roadmap. No deck, no pitch.
