LIHUE, Kauai—Credit union volunteers have been give a couple of updated checklists of questions to be asking management as part of their responsibility as the “first line of defense of potential losses.”
NCUA Chairman Debbie Matz, who provided those checklists, told the Volunteer Leadership Institute conference here hosted by the Paragon Group that volunteers are critical to monitoring future risks to credit unions, an issue that Matz has stressed since being named chairman.
“Engaged volunteers have led credit unions diligently, from recession through recovery,” Matz told the meeting. “You have turned unprecedented challenges into enduring opportunities. With the financial crisis behind us, we need to discuss the challenges ahead, including interest-rate risk, cyber-security and the need for credit unions to hold adequate capital.”
Matz reviewed issues related to interest rate risk to the audience of board members, noting that IRR for CUs overall is now higher than it was prior to the recent recession. She pointed out that long-term assets have risen from 25% of all assets 10 years ago to 35% today.
Moreover, said Matz, the recent increase in long-term interest rates has meant a $5 billion negative swing for credit unions as unrealized gains became unrealized losses, possibly foreshadowing actual losses if future rate hikes compress interest margins.
IRR Questions To Ask
When it comes to interest rate risk, Matz urged volunteers to ask questions of management, including:
- How is management measuring a credit union’s interest rate risk exposure?
- What has management learned from shock testing?
- Should a credit union change its balance sheet, product pricing or investment strategy to avoid excessive interest rate risk?
- How should the credit union’s interest rate risk policy be updated to reflect the Fed’s new interest rate forecast?
- What internal controls ensure the credit union will follow the board’s interest rate risk policy?
“NCUA examiners encouraging CUs to shock their balance sheets and to plan accordingly for that contingency,” said Matz, who pointed volunteers to the IRR resource page on NCUA’s website.
The second of three issues discussed by Matz was cybersecurity, with Matz conceding many of the related issues get outside her own comfort zone, as well as board members, but she said it requires everyone to get uncomfortable.
With hacker an ever-increasing threat, Matz told the VLI meeting that NCUA examiners will expect credit unions to put mitigation controls into place to better detect, protect against and recover from cyberattacks.
Cyber-Security Questions To Ask
Matz encouraged credit union volunteers to ask management questions such as:
- What are the potential vulnerabilities of hackers using the credit union as an entry point to gain access to larger interconnected systems?
- Has staff done due diligence to evaluate the cybersecurity of every vendor and every payment system with which the credit union has a digital relationship?
- How could the national cybersecurity standards in the NIST framework help further protect a credit union and its members?
- How should the credit union consider changing its cybersecurity protocols, based on guidance from the Federal Financial Institutions Examination Council?
Finally, a week to the day after voting in favor of NCUA’s revised risk-based capital proposal, Matz reviewed for directors the reasons the agency has made the proposal.
Matz said the agency reviewed 2,056 comment letters prior to revising the proposal, and reminded that just 27 CUs will be required to hold more capital based on their higher risks.
“We rely on board members who are dedicated and intelligent and who understand the commitment they make as board members,” Matz told the meeting.
