The operational-resilience, BCDR, and crisis-handling obligations that most likely apply to credit unions — by regulator, domain, and compliance status. Filter and search the full set below.
credit_union · 68 likely-applicable · 0 excluded by asset sizeHow this persona’s 68 applicable obligations distribute across cross-cutting themes. For the full lens (what each requires), run python3 -m regwatch.theme <theme> --persona credit_union.
| Theme | Obligations | of which proposed |
|---|---|---|
| Third-Party / Vendor Risk Management | 10 | |
| Cybersecurity × Resilience | 19 | |
| Incident Reporting & Notification | 19 | |
| Resilience Testing & Exercises | 5 |
| ID | Country | Regulator | Domain | Size trigger | Obligation (with source quote) | Citation | Status | Suggested evidence to comply |
|---|---|---|---|---|---|---|---|---|
OBL-01076 | United States | NCUA | business continuity | Establish a written vital records preservation program within six months of insurance certificate issuance to identify, store, and reconstruct vital records in the event such records are destroyed. “The board of directors of a credit union is responsible for establishing a vital records preservation program within six months of its insurance certificate being issued. The program must be in writing and contain procedures for maintaining duplicate vital records at a vital records center.” | 12 CFR 749.2(a) | final | Board-approved written vital records preservation program; date-stamped adoption records showing compliance with six-month deadline. | |
OBL-01077 | United States | NCUA | business continuity | Include in the written program designated staff responsible for vital records preservation. “The procedures must include: (1) Designated staff responsible for vital records preservation” | 12 CFR 749.2(a)(1) | final | Written program identifying named roles or positions responsible for vital records preservation; current assignment documentation. | |
OBL-01078 | United States | NCUA | business continuity | Include in the written program a schedule for the storage and destruction of vital records. “The procedures must include: (2) A schedule for the storage and destruction of vital records” | 12 CFR 749.2(a)(2) | final | Written schedule within the program specifying frequency of storage updates and criteria/timeline for destruction of superseded vital records. | |
OBL-01079 | United States | NCUA | business continuity | Maintain a records preservation log that will aid in locating and easily accessing vital records, in electronic or any other format as determined by the credit union. “A records preservation log as determined by the credit union that will aid in locating and easily accessing the vital records. The log may be in electronic or any other format as determined by the credit union.” | 12 CFR 749.2(a)(3) | final | Maintained records preservation log (electronic or otherwise) demonstrating location and access information for all stored vital records. | |
OBL-01080 | United States | NCUA | business continuity | Store duplicate vital records at a vital records center located far enough from the credit union's offices to avoid simultaneous loss of both sets of records in a catastrophic event. “contain procedures for maintaining duplicate vital records at a vital records center... a storage facility...at any location far enough from the credit union's offices to avoid the simultaneous loss of both sets of records in the event of a catastrophic act.” | 12 CFR 749.2(a); 12 CFR 749.1 (definition of 'Vital records center') | final | Documentation of offsite vital records center location; geographic separation analysis; copies of storage or hosting agreements. | |
OBL-01081 | United States | NCUA | business continuity | Ensure the vital records preservation program covers the six specified categories of vital records, including member account balances, financial reports, bank reconcilements, account/investment lists, and emergency contact information. “Vital records are the most recent and current versions of the records a credit union needs to restore vital member services. These records are: (1) A list of share, deposit, and loan balances... (2) A financial report... (3) Bank reconcilements... (4) A list of the credit union's accounts... (5) Eme” | 12 CFR 749.1 (definition of 'Vital records', subsections (1)-(5)) | final | Inventory of vital records preserved; confirmation each required category is current; storage logs showing most-recent business day or month-end versions. | |
OBL-01082 | United States | NCUA | business continuity | Where vital records are maintained by an off-site data processor, ensure the service agreement specifies that the data processor safeguards against simultaneous destruction of production and back-up information. “A credit union that has some or all of its vital records maintained by an off-site data processor is considered to be in compliance for the storage of those records if the service agreement specifies the data processor safeguards against the simultaneous destruction of production and back-up informa” | 12 CFR 749.2(b) | final | Executed service agreement with off-site data processor containing explicit contractual provision against simultaneous destruction of production and backup data. | |
OBL-01083 | United States | NCUA | business continuity | Maintain, or contract with a third-party service provider to maintain, any equipment or software necessary for the vital records center so the credit union can access its records. “A credit union must maintain, or contract with a third-party service provider to maintain, any equipment or software for its vital records center necessary for the credit union to access its records.” | 12 CFR 749.3 | final | Inventory of equipment/software at vital records center; contracts with third-party providers; tested access procedures demonstrating records are retrievable. | |
OBL-01084 | United States | NCUA | business continuity | Maintain effective oversight of any third-party service provider contracted to maintain vital records to ensure the records meet the requirements of 12 CFR 749.3. “If a credit union contracts with a third-party service provider to maintain its records, the credit union must maintain effective oversight of the third-party service provider to ensure the records meet the requirements of this section.” | 12 CFR 749.3 | final | Third-party oversight program documentation; periodic audits or assessments of service provider; written oversight reports; corrective action records. | |
OBL-01085 | United States | NCUA | business continuity | Preserve vital records in a format that accurately reflects the information, remains accessible to all entitled persons, and is capable of reproduction by transmission, printing, or otherwise. “Preserved vital records may be in any format that can be used to reconstruct the credit union's vital records. The format used must accurately reflect the information in the record, remain accessible to all persons entitled to access by statute, regulation, or rule of law, and be capable of reproduc” | 12 CFR 749.4 | final | Documentation of format(s) used; periodic access and reproduction tests; evidence of successful reconstruction of records in chosen format. | |
OBL-01312 | United States | NCUA | cybersecurity | Report a reportable cyber incident to the NCUA-designated point of contact as soon as possible and no later than 72 hours after the FICU reasonably believes a reportable cyber incident has occurred. “The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident” | 12 CFR 748.1(c) | final | Incident log showing date/time FICU formed reasonable belief; notification record (email/phone/portal) to NCUA within 72h; incident tracking policy. | |
OBL-01313 | United States | NCUA | cybersecurity | Report via email, telephone, or other NCUA-prescribed method to the NCUA-designated point of contact upon occurrence of a reportable cyber incident. “Each federally insured credit union must notify the appropriate NCUA-designated point of contact of the occurrence of a reportable cyber incident via email, telephone, or other similar methods that the NCUA may prescribe.” | 12 CFR 748.1(c) | final | Written notification procedures identifying approved channels; records of each notification transmitted to NCUA. | |
OBL-01314 | United States | NCUA | cybersecurity | Report a cyber incident causing a substantial loss of confidentiality, integrity, or availability of a network or member information system resulting from unauthorized access to sensitive data, disruption of vital member services, or serious impact on safety and resiliency of operational systems. “A substantial loss of confidentiality, integrity, or availability of a network or member information system...that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services...or has a serious impact on the safety and resiliency of operational systems and p” | 12 CFR 748.1(c)(1)(i)(A) | final | Incident classification criteria in IR policy; incident reports filed with NCUA; documentation of impact assessment at time of notification. | |
OBL-01315 | United States | NCUA | cybersecurity | Report a cyber incident where a cyberattack or exploitation of vulnerabilities causes disruption of business operations, vital member services, or a member information system. “A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities.” | 12 CFR 748.1(c)(1)(i)(B) | final | Incident log entries; NCUA notification records; evidence of cyberattack/vulnerability exploitation (e.g., SIEM alerts, forensic summary). | |
OBL-01316 | United States | NCUA | cybersecurity | Report within 72 hours a cyber incident where a compromise of a credit union service organization, cloud service provider, third-party data hosting provider, or supply chain causes disruption of business operations or unauthorized access to sensitive data. “A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise.” | 12 CFR 748.1(c)(1)(i)(C) | final | Third-party incident notifications received; NCUA notification filed within 72h of receipt or reasonable belief; vendor management records. | |
OBL-01317 | United States | NCUA | cybersecurity | When notified by a third-party of a compromise affecting the FICU, report to NCUA within 72 hours of that third-party notification, whichever is sooner than the FICU's own reasonable belief. “within 72 hours of being notified by a third-party, whichever is sooner.” | 12 CFR 748.1(c) | final | Timestamped third-party notification records; NCUA notification log showing submission within 72h of third-party notice. | |
OBL-01489 | United States | NCUA | business continuity | Establish and maintain a written vital records preservation program to identify, store, and reconstruct vital records in the event records are destroyed. “All credit unions must have a written program that includes plans for safeguarding records and reconstructing vital records.” | 12 CFR 749.0(a); 12 CFR 749.2 | final | Board-approved written vital records preservation program; program inception date within 6 months of insurance certificate issuance. | |
OBL-01490 | United States | NCUA | business continuity | Board of directors must establish the vital records preservation program within 6 months after the credit union's insurance certificate is issued. “The board of directors of a credit union is responsible for establishing a vital records preservation program within 6 months after its insurance certificate is issued.” | 12 CFR 749.2 | final | Board meeting minutes authorizing/approving the program; dated program document showing compliance with 6-month requirement. | |
OBL-01491 | United States | NCUA | business continuity | Written vital records preservation program must contain procedures for maintaining duplicate vital records at a vital records center. “The program must be in writing and contain procedures for maintaining duplicate vital records at a vital records center.” | 12 CFR 749.2 | final | Written program document specifying duplicate vital records procedures; records center agreement or designation documentation. | |
OBL-01492 | United States | NCUA | business continuity | Written vital records preservation program must designate staff responsible for vital records preservation. “The procedures must include: designated staff responsible for vital records preservation, a schedule for the storage and destruction of records, and a records preservation log...” | 12 CFR 749.2 | final | Program document naming designated staff roles; job descriptions or assignment documentation for records preservation responsibilities. | |
OBL-01493 | United States | NCUA | business continuity | Written vital records preservation program must include a schedule for the storage and destruction of records. “The procedures must include: designated staff responsible for vital records preservation, a schedule for the storage and destruction of records, and a records preservation log...” | 12 CFR 749.2 | final | Documented records storage and destruction schedule within the written program; retention schedule approved by the board. | |
OBL-01494 | United States | NCUA | business continuity | Written vital records preservation program must include a records preservation log detailing each record stored, its name, storage location, storage date, and name of the person sending the record. “a records preservation log detailing for each record stored, its name, storage location, storage date, and name of the person sending the record for storage.” | 12 CFR 749.2 | final | Active records preservation log with required fields (name, storage location, storage date, sender name) maintained and updated. | |
OBL-01495 | United States | NCUA | business continuity | Credit unions using an off-site data processor must ensure the service agreement specifies the data processor safeguards against simultaneous destruction of production and back-up information. “Credit unions which have some or all of their records maintained by an off-site data processor are considered to be in compliance...if the service agreement specifies the data processor safeguards against the simultaneous destruction of production and back-up information.” | 12 CFR 749.2 | final | Executed service agreement with off-site data processor containing explicit safeguard language against simultaneous production and backup destruction. | |
OBL-01496 | United States | NCUA | business continuity | Maintain or contract with a third party to maintain equipment or software at the vital records center necessary to access vital records. “A credit union must maintain or contract with a third party to maintain any equipment or software for its vital records center necessary to access records.” | 12 CFR 749.3 | final | Documentation of owned or contracted equipment/software at vital records center; third-party contract if applicable; periodic access testing records. | |
OBL-01497 | United States | NCUA | business continuity | The vital records center must be located far enough from the credit union's offices to avoid simultaneous loss of both sets of records in the event of a catastrophic act. “A vital records center is defined as a storage facility...at any location far enough from the credit union's offices to avoid the simultaneous loss of both sets of records in the event of a catastrophic act.” | 12 CFR 749.3 | final | Documented geographic separation analysis or policy justifying vital records center location; site address relative to primary office. | |
OBL-01498 | United States | NCUA | business continuity | Preserved vital records must be maintained in a format that accurately reflects information in the record, remains accessible to entitled persons, and is capable of reproduction. “The format used must accurately reflect the information in the record, remain accessible to all persons entitled to access by statute, regulation or rule of law, and be capable of reproduction by transmission, printing, or otherwise.” | 12 CFR 749.4 | final | Format specification documentation; sample reproduction test results; NCUA examiner access confirmation procedures. | |
OBL-01499 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Develop a catastrophic act preparedness program that includes a business impact analysis to evaluate potential threats. “(1) A business impact analysis to evaluate potential threats;” | 12 CFR Part 749 Appendix B, Element (1) | final | Written business impact analysis document identifying and evaluating potential threats to credit union operations; board oversight records. | |
OBL-01500 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Develop a catastrophic act preparedness program that includes a risk assessment to determine critical systems and necessary resources. “(2) A risk assessment to determine critical systems and necessary resources;” | 12 CFR Part 749 Appendix B, Element (2) | final | Written risk assessment identifying critical systems and required resources; documentation of methodology and board oversight. | |
OBL-01501 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Develop a written catastrophic act preparedness plan identifying persons with authority to enact the plan. “A written plan addressing: i. Persons with authority to enact the plan;” | 12 CFR Part 749 Appendix B, Element (3)(i) | final | Written plan document with named/titled individuals authorized to activate the plan; delegation of authority documentation. | |
OBL-01502 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must address preservation and ability to restore vital records. “A written plan addressing:...ii. Preservation and ability to restore vital records;” | 12 CFR Part 749 Appendix B, Element (3)(ii) | final | Written plan section detailing vital records preservation procedures and recovery/restoration steps; test results demonstrating restoration capability. | |
OBL-01503 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include a method for restoring vital member services through alternate operating locations or service mediums. “iii. A method for restoring vital member services through identification of alternate operating location(s) or mediums to provide services, such as telephone centers, shared service centers, agreements with other credit unions, or other appropriate methods;” | 12 CFR Part 749 Appendix B, Element (3)(iii) | final | Written plan with identified alternate operating locations or service mediums; executed agreements with service providers or other credit unions. | |
OBL-01504 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include communication methods for employees and members during a catastrophic act. “iv. Communication methods for employees and members;” | 12 CFR Part 749 Appendix B, Element (3)(iv) | final | Written plan section detailing employee and member communication protocols; contact trees; communication channel documentation. | |
OBL-01505 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must address notification of regulators as required under 12 CFR 748.1(b). “v. Notification of regulators as addressed in 12 CFR 748.1(b);” | 12 CFR Part 749 Appendix B, Element (3)(v) | final | Written plan section referencing and detailing regulatory notification procedures; contact information for regional director; prior notification records. | |
OBL-01506 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include training and documentation of training for all employees and volunteer officials on catastrophic act procedures. “vi. Training and documentation of training to ensure all employees and volunteer officials are aware of procedures to follow in the event of destruction of vital records or loss of vital member services;” | 12 CFR Part 749 Appendix B, Element (3)(vi) | final | Training program documentation; training completion records for all employees and volunteer officials; training content covering catastrophic act procedures. | |
OBL-01507 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Written catastrophic act preparedness plan must include testing procedures with a means for documenting testing results. “vii. Testing procedures, including a means for documenting the testing results.” | 12 CFR Part 749 Appendix B, Element (3)(vii) | final | Written testing procedures within the plan; documented test results from each exercise; remediation actions recorded. | |
OBL-01508 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Establish internal controls for reviewing the catastrophic act preparedness plan at least annually and revising it as circumstances warrant. “(4) Internal controls for reviewing the plan at least annually and for revising the plan as circumstances warrant, for example, to address changes in the credit union's operations;” | 12 CFR Part 749 Appendix B, Element (4) | final | Annual plan review schedule; documented review records with dates and any revisions made; change log tracking updates to the plan. | |
OBL-01509 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Conduct annual testing of the catastrophic act preparedness program. “(5) Annual testing.” | 12 CFR Part 749 Appendix B, Element (5) | final | Annual test completion records; test scenario documentation; after-action reports; evidence of board or management review of test outcomes. | |
OBL-01510 | United States | NCUA | business continuity | NOT YET IN FORCE (effective 2026-07-16): Catastrophic act preparedness program must be developed with oversight and approval of the board of directors. “The program should be developed with oversight and approval of the board of directors.” | 12 CFR Part 749 Appendix B (introductory paragraph) | final | Board meeting minutes reflecting approval of the catastrophic act preparedness program; evidence of ongoing board oversight. | |
OBL-01511 | United States | NCUA | business continuity | A FICU board of directors must establish a written succession plan that addresses specified positions and contains required information to ensure continuity of critical leadership. [adjacent] “a FICU board of directors establish a written succession plan that addresses specified positions and contains certain information” | 12 CFR 701.4(e) | final | Board-approved written succession plan covering required positions; documentation of plan contents meeting regulatory elements; examiner-reviewable plan on file. | |
OBL-01512 | United States | NCUA | business continuity | The FICU board of directors must review the succession plan no less than every 24 months to ensure it remains current and adequate. [adjacent] “a credit union board must review its succession plan no less than every 24 months, as opposed to the annual review that would have been required under the proposed rule” | 12 CFR 701.4(e) | final | Board meeting minutes documenting succession plan review at least every 24 months; updated plan reflecting review outcomes. | |
OBL-01513 | United States | NCUA | business continuity | Newly appointed FICU board members must obtain working familiarity with the succession plan no later than six months after appointment. [adjacent] “newly appointed members of the board of directors have a working familiarity with the succession plan no later than six months after appointment” | 12 CFR 701.4(e) | final | Onboarding records showing date of appointment and date of succession plan familiarization; attestation or training log for each new board member. | |
OBL-01515 | United States | NCUA | business continuity | The succession plan must identify the anticipated vacancy date for each covered position, such as the incumbent's retirement eligibility date or announced departure date. [adjacent] “The final rule does not require the FICU use a specific date, but suggests some possible proxies, including the individual's anticipated retirement date or announced departure date. A credit union can also note that a retirement or departure date is unknown.” | 12 CFR 701.4(e) | final | Succession plan listing anticipated vacancy dates or proxies for each covered position; updated dates reflecting changes in incumbents' circumstances. | |
OBL-01516 | United States | NCUA | business continuity | The succession plan must cover specified senior leadership positions responsible for oversight or day-to-day management of the FICU, including management officials and senior executive officers per 12 CFR 701.14(b)(2). [adjacent] “succession plans are intended to cover senior leadership positions responsible for the oversight of the FICU or its day-to-day management” | 12 CFR 701.4(e)(2) | final | Succession plan listing all required covered positions; mapping of plan positions to regulatory definitions in 12 CFR 701.14(b)(2) and model FCU bylaws. | |
OBL-01517 | United States | NCUA | business continuity | The succession plan may include other personnel the board deems critical given the FICU's size, complexity, or risk of operations, including positions required due to planned operational changes. [adjacent] “other personnel the board of directors deems critical given the [FICU's] size, complexity, or risk of operations. This includes new positions that may be required due to planned changes in operations, supervisory landscape, or corporate structure.” | 12 CFR 701.4(e)(2)(iii) | final | Board resolution or plan documentation identifying additional critical positions and rationale; succession plan sections addressing those positions. | |
OBL-01518 | United States | NCUA | business continuity | FISCUs must adhere to the NCUA succession planning requirements to the extent they do not conflict with an applicable state requirement; NCUA defers to enforceable state requirements where no conflict exists. [adjacent] “a FISCU must adhere to the succession planning requirements 'to the extent these regulatory provisions do not conflict with an applicable state requirement.'” | 12 CFR 741.228 | final | Analysis of applicable state statutory or regulatory succession planning requirements; documented compliance mapping showing areas of deference or NCUA rule application. | |
OBL-01833 | United States | NCUA | business continuity | Develop and maintain a written security program within 90 days of insurance effective date that prevents destruction of vital records and responds to unauthorized access incidents. “Each federally insured credit union will develop a written security program within 90 days of the effective date of insurance.” | 12 CFR 748.0(a), 748.0(b)(3), 748.0(b)(5) | final | Written security program document; board approval records; procedures for incident response and vital records protection. | |
OBL-01834 | United States | NCUA | business continuity | Notify the NCUA regional director within 5 business days of any catastrophic act causing physical destruction or interruption of vital member services projected to last more than two consecutive business days. “Each federally insured credit union will notify the regional director within 5 business days of any catastrophic act that occurs at its office(s).” | 12 CFR 748.1(b) | final | Incident notification log; dated communications to regional director; post-incident records filed at main office. | |
OBL-01835 | United States | NCUA | business continuity | Prepare and file a record of each catastrophic act at the credit union's main office, documenting location, timing, losses, operational deficiencies, and corrective actions. “Within a reasonable time after a catastrophic act occurs, the credit union shall ensure that a record of the incident is prepared and filed at its main office.” | 12 CFR 748.1(b) | final | Post-incident written record filed at main office covering: office affected, date, loss amount, deficiencies identified, corrective actions taken or planned. | |
OBL-01836 | United States | NCUA | business continuity | Notify NCUA's designated point of contact of a reportable cyber incident as soon as possible but no later than 72 hours after the credit union reasonably believes it has experienced such an incident. “The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident.” | 12 CFR 748.1(c) | final | Cyber incident log with timestamps; 72-hour notification records to NCUA; escalation procedures documented in incident response plan. | |
OBL-01837 | United States | NCUA | business continuity | Report a cyber incident within 72 hours when a disruption of business operations or vital member services results from a cyberattack or exploitation of vulnerabilities. “A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities.” | 12 CFR 748.1(c)(1)(i)(B) | final | Incident classification records showing determination of reportability; 72-hour notification to NCUA; incident response documentation. | |
OBL-01838 | United States | NCUA | business continuity | Report within 72 hours when a third-party (CUSO, cloud provider, or other data hosting provider) compromise causes a disruption of business operations or unauthorized access to sensitive data. “A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a credit union service organization, cloud service provider, or other third-party data hosting provider or by a supply chain compromise.” | 12 CFR 748.1(c)(1)(i)(C) | final | Third-party incident notifications received; 72-hour NCUA notifications; third-party monitoring logs; supply chain incident records. | |
OBL-01839 | United States | NCUA | business continuity | Develop and implement a comprehensive written information security program with administrative, technical, and physical safeguards appropriate to the credit union's size and complexity. [adjacent] “A comprehensive written information security program includes administrative, technical, and physical safeguards appropriate to the size and complexity of the credit union and the nature and scope of its activities.” | 12 CFR Part 748, Appendix A, Section II.A | final | Written information security program document; board approval; evidence of coordination across all credit union elements. | |
OBL-01840 | United States | NCUA | business continuity | Have the board of directors approve the written information security policy and program, and oversee its development, implementation, and maintenance including reviewing management reports. [adjacent] “Approve the credit union's written information security policy and program; and oversee the development, implementation, and maintenance of the credit union's information security program.” | 12 CFR Part 748, Appendix A, Section III.A | final | Board meeting minutes reflecting program approval; board committee oversight records; management reports submitted to board. | |
OBL-01841 | United States | NCUA | business continuity | Assess reasonably foreseeable internal and external threats to member information systems, evaluate likelihood and potential damage of threats, and assess sufficiency of existing controls. “Identify reasonably foreseeable internal and external threats that could result in unauthorized disclosure, misuse, alteration, or destruction of member information or member information systems.” | 12 CFR Part 748, Appendix A, Section III.B | final | Documented risk assessment; threat inventory; likelihood and impact ratings; gap analysis of current controls. | |
OBL-01842 | United States | NCUA | business continuity | Implement response programs specifying actions when unauthorized access to member information systems is suspected or detected, including reports to regulatory and law enforcement agencies. “Response programs that specify actions to be taken when the credit union suspects or detects that unauthorized individuals have gained access to member information systems, including appropriate reports to regulatory and law enforcement agencies.” | 12 CFR Part 748, Appendix A, Section III.C.1.g | final | Written incident response plan; escalation procedures; evidence of regulatory/law enforcement notification workflows. | |
OBL-01843 | United States | NCUA | business continuity | Implement measures to protect member information against destruction, loss, or damage due to environmental hazards such as fire, water damage, or technical failures. “Measures to protect against destruction, loss, or damage of member information due to potential environmental hazards, such as fire and water damage or technical failures.” | 12 CFR Part 748, Appendix A, Section III.C.1.h | final | Environmental hazard controls documentation; backup and recovery procedures; physical security and disaster recovery controls. | |
OBL-01844 | United States | NCUA | business continuity | Implement monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems. [adjacent] “Monitoring systems and procedures to detect actual and attempted attacks on or intrusions into member information systems.” | 12 CFR Part 748, Appendix A, Section III.C.1.f | final | Intrusion detection/prevention system records; security monitoring logs; alert and escalation procedures documentation. | |
OBL-01845 | United States | NCUA | business continuity | Regularly test key controls, systems, and procedures of the information security program, with tests conducted or reviewed by independent parties, at a frequency determined by risk assessment. [adjacent] “Regularly test the key controls, systems and procedures of the information security program. The frequency and nature of such tests should be determined by the credit union's risk assessment.” | 12 CFR Part 748, Appendix A, Section III.C.3 | final | Test schedules; test results reports; documentation of independent reviewer or third-party involvement; risk-based frequency rationale. | |
OBL-01846 | United States | NCUA | business continuity | Exercise due diligence in selecting service providers, require them by contract to implement appropriate information security measures, and monitor their compliance where indicated by risk assessment. ⚠ audit “Exercise appropriate due diligence in selecting its service providers; Require its service providers by contract to implement appropriate measures designed to meet the objectives of these guidelines.” | 12 CFR Part 748, Appendix A, Section III.D | final | Vendor due diligence records; service provider contracts with security requirements; audit reviews or monitoring reports for key service providers. | |
OBL-01847 | United States | NCUA | business continuity | Monitor, evaluate, and adjust the information security program in response to relevant changes in technology, threat environment, member information sensitivity, and business arrangements including outsourcing. [adjacent] “Monitor, evaluate, and adjust, as appropriate, the information security program in light of any relevant changes in technology, the sensitivity of its member information, internal or external threats to information, and the credit union's own changing business arrangements.” | 12 CFR Part 748, Appendix A, Section III.E | final | Program review records tied to trigger events (technology changes, new outsourcing arrangements, threat landscape changes); documented program update history. | |
OBL-01848 | United States | NCUA | business continuity | Report to the board or board committee at least annually on the overall status of the information security program, including risk assessment, risk management decisions, service provider arrangements, test results, and security breaches. [adjacent] “Each credit union should report to its board or an appropriate committee of the board at least annually. This report should describe the overall status of the information security program and the credit union's compliance with these guidelines.” | 12 CFR Part 748, Appendix A, Section III.F | final | Annual board/committee report; board minutes recording receipt of report; report covering risk assessment, control decisions, testing, breaches, and service provider status. | |
OBL-01849 | United States | NCUA | business continuity | Develop and implement a risk-based response program to address incidents of unauthorized access to member information, as a key component of the information security program. [adjacent] “Every credit union should also develop and implement a risk-based response program to address incidents of unauthorized access to member information in member information systems that occur nonetheless.” | 12 CFR Part 748, Appendix B, Section II | final | Written incident response program document; evidence of integration into information security program; program scaled to credit union size and complexity. | |
OBL-01850 | United States | NCUA | business continuity | Include in the response program procedures to assess the nature and scope of an incident and identify which member information systems and information types were accessed or misused. “Assessing the nature and scope of an incident, and identifying what member information systems and types of member information have been accessed or misused.” | 12 CFR Part 748, Appendix B, Section II.A.1.a | final | Incident response procedures with scope-assessment steps; incident records documenting system and data type identification during incidents. | |
OBL-01851 | United States | NCUA | business continuity | Notify the appropriate NCUA Regional Director (and state supervisory authority for state-chartered CUs) as soon as possible upon discovering an incident involving unauthorized access to sensitive member information. [adjacent] ⚠ audit “Notifying the appropriate NCUA Regional Director, and, in the case of state-chartered credit unions, its applicable state supervisory authority, as soon as possible when the credit union becomes aware of an incident involving unauthorized access to or use of sensitive member information.” | 12 CFR Part 748, Appendix B, Section II.A.1.b | final | Notification log with timestamps; contact list for NCUA Regional Director; evidence of state authority notification for state-chartered CUs. | |
OBL-01852 | United States | NCUA | business continuity | Take appropriate steps to contain and control incidents of unauthorized access to prevent further unauthorized access, including monitoring, freezing, or closing affected accounts while preserving records and evidence. “Taking appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information, for example, by monitoring, freezing, or closing affected accounts, while preserving records and other evidence.” | 12 CFR Part 748, Appendix B, Section II.A.1.d | final | Incident response playbooks with containment steps; evidence preservation procedures; post-incident containment action records. | |
OBL-01853 | United States | NCUA | business continuity | Require service providers by contract to promptly notify the credit union of unauthorized access incidents to member information to enable timely implementation of the credit union's response program. [adjacent] “A credit union's contract with its service provider should require the service provider to take appropriate actions to address incidents of unauthorized access to or use of the credit union's member information, including notification of the credit union as soon as possible of any such incident.” | 12 CFR Part 748, Appendix B, Section II.ii | final | Service provider contracts containing incident notification clauses; records of notifications received from service providers. | |
OBL-01856 | United States | NCUA | business continuity | Annually certify compliance with all requirements of 12 CFR Part 748 via the Credit Union Profile through NCUA's online information management system. [adjacent] “The president or managing official of each federally insured credit union must certify compliance with the requirements of this part in its Credit Union Profile annually through NCUA's online information management system.” | 12 CFR 748.1(a) | final | Annual compliance certification submitted via NCUA online system; records of certification filings by year. | |
OBL-01857 | United States | NCUA | business continuity | Design the information security program to control risks commensurate with information sensitivity and business complexity, considering and adopting appropriate controls including encryption, access controls, and modification procedures. [adjacent] “Design its information security program to control the identified risks, commensurate with the sensitivity of the information as well as the complexity and scope of the credit union's activities.” | 12 CFR Part 748, Appendix A, Section III.C.1 | final | Risk-based security program with documented rationale for controls selected; encryption policy; access control documentation; system modification procedures. |
Knowing which rules bind you is step one. WSquare Advisory builds the operating capability behind compliance — the continuity, third-party, and recovery disciplines these regimes expect. If that's your challenge, let's talk.
Start with an Operating Survey · $5,000 →