Credit unions have an AI risk gap: American Banker research

  • Key insight: Credit unions are expressing less concern about AI model risk, according to American Banker research.  
  • What's at stake: As more financial institutions use AI, the risk of models performing outside of their training will become a broader threat. 
  • Expert quote: "AI is no longer a future issue. The decisions credit unions make today about AI, governance, and risk will shape their competitiveness and their members' trust for years to come." —Teachers Federal Credit Union CEO Brad Calhoun

As financial institutions increase their use of artificial intelligence, the risk that results when AI models go astray will also increase. New American Banker research suggests credit unions do not give this risk the same weight as other financial firms. 

Processing Content

Only 18% of credit union respondents say AI model risk is a critical or high threat, compared to 62% at national banks, 54% of midsized banks and 50% of community banks. Seventy-one percent of credit unions say they aren't prepared for the threat, compared to 73% of national banks, 62% of midsized banks and 61% of community banks.  

"The biggest AI risk for credit unions isn't moving too fast. It's failing to prepare," Brad Calhoun, president and CEO of Teachers Federal Credit Union, told American Banker in an email.  

Not following orders

AI model risk refers to a machine learning or AI model performing poorly or outside of its programming or training, leading to bad decisions or financial risk.

Credit unions often work with third party vendors, and assume the third party will manage AI risk, and that's a dangerous assumption, according to Tracy Goldberg, director of cybersecurity at Javelin Strategy & Research.

"There are so many variables with AI and if you don't have protections in place, there is real risk there," Goldberg told American Banker. 

The entire financial services industry is struggling with AI model risk. More than a third of U.S. bankers, for example, are not sure if they have kill switches for their AI models, according to Wolters Kluwer. And writing for American Banker, risk management executive Lisa Matthews said regulatory guidance on AI is unclear, leaving it up to financial institutions to sort out the risk for themselves. 

American Banker's research found that AI model risk is also the single biggest destination for new risk spending: 63% across all financial services size categories say their institution is increasing the budget, staff or tools devoted to it over the next 12 months, ahead of external fraud at 58% and well ahead of the traditional credit and liquidity risks. 

"For us, the question isn't whether the risk is there;  the question is how we build in the governance and expertise to manage those risks at the front end as we continue to innovate on behalf of our members and the industry," Kal Majmundar, chief technology and transformation officer for Patelco Credit Union, told American Banker.  As Patelco explores new ways to make financial services faster, easier and more accessible, it also has a responsibility to make sure the appropriate safeguards, governance and oversight are in place, according to Majmundar, adding the credit union's technology stack combines in-house custom platforms and relationships with external partners. 

Responsibility

AI is rapidly changing how financial institutions operate, make decisions and serve their members, Calhoun said. "Responsible AI adoption requires clear accountability, strong oversight and a disciplined understanding of where AI creates value and where it introduces risk. Credit unions may not have the resources of the nation's largest banks, but collaboration has always been one of our greatest strengths."

Credit unions should use that advantage to raise AI readiness across the industry, according to Calhoun. "AI is no longer a future issue. The decisions credit unions make today about AI, governance and risk will shape their competitiveness and their members' trust for years to come." 

Read more:

John Meyer, a managing director at Cornerstone Advisors, said credit union clients are asking Cornerstone about AI models, particularly if alternative credit decisioning has a bias that causes issues with air lending or UDAAP compliance. Other model concerns, especially when bankers use large language models, center around data privacy, or where is the data stored and how is the data used, Meyer said.
"For example, even simple AI tools like meeting notetakers need to be vetted to ensure the data is not stored in Europe or is used to train other call data, since many of the topics for internal credit union meetings involve member services or ways that the credit union might consider differentiating," Meyer told American Banker. 

Meyer predicts AI models will eventually go through a third-party model validation audit much like BSA/AML systems today. "However, we are not encountering any vendors who have used an external audit firm to conduct such a validation, so we are encouraging our clients to update their third-party risk management to ask for vendors to sign an attestation that their models are not impacted by bias and do not violate any regulations," Meyer said.


For reprint and licensing requests for this article, click here.
Artificial Intelligence Risk management Security risk Payments Credit unions
MORE FROM AMERICAN BANKER
Load More