By Ray Birch
ALEXANDRIA, Va.—Will NCUA, under a new chairman, continue to press for third-party vendor oversight authority? Will the agency raise the normal operating level of the NCUSIF if that power is not granted?
NCUA Chairman Todd Harper answered those questions and more during an interview with CUToday.info that focused on the agency’s efforts to obtain the ability to oversee credit union vendors and CUSOs, and how growing cyber-security threats and new CFPB rules make that power even more critical for the industry.
Harper, first, restated a point he has made in previous NCUA board meetings and in front of Congress—NCUA not having third-party vendor oversight authority is a growing regulatory “blind spot.”
“Our financial system is only getting more reliant on third-party vendors to conduct basic functions for credit unions themselves. Ninety percent of the industry's assets are affected by key service functions provided by third parties,” Harper told CUToday.info.
Harper pointed to the ransomware attack that affected Ongoing Operations, and impacted the data systems of a large number of credit unions in late 2023.
Big Data Breach
“I believe more than 100 credit unions were affected and 60 of those went down with their core processing because of this vendor’s data breach,” Harper said. “We don't have the ability to go into vendors when problems like that occur. In fact, it took us multiple attempts to even get the company to return our calls.”
Harper insisted if NCUA had vendor examination authority, the way banking regulators do, vendors would be more responsive to the agency.
“Especially during times when problems arise, and we could work together to fix those problems,” Harper said. “Within the banking world, the banking regulators come in and examine third parties. If a bank is looking to use a third-party vendor, they can get a summary examination report that can help with their due diligence. Credit unions don't have that opportunity.”
Harper said that places credit unions at a competitive disadvantage, when it comes to conducting due diligence.
“The increasing risks caused by vendors bring potential risks to the Share Insurance Fund—whether that's due to safety and soundness risks, underwriting risks, legal risks due to data breaches, violations of Consumer Financial Protection laws...That’s all going to fall back onto the credit union that's using the vendor. And it's also a national security issue.”
The entire financial services infrastructure is under continuous attack by multi-national bad actors, Harper reminded.
“They are out to undermine the strength of our system. We need to protect the financial system and third-party vendor authority is a key part of that,” he said.
During NCUA’s October open board meeting, Harper stated that if the agency does not get third-party vendor authority, it may be forced to consider adjusting the normal operating level (NOL) of the NCUSIF.
“I'm not alone in my views here,” Harper said, adding that many government agencies have the same perspective. “The Financial Stability Oversight Council (FSOC), in every single annual report since 2015, has cited the need for the NCUA to have third-party vendor authority.
GAO Perspective
“We have the experts coming together across the administrations of both political parties saying we need to have this authority and that it is a growing regulatory blind spot,” Harper said, noting FSOC this year stressed the urgency of NCUA receiving this power.
Harper noted the Government Accountability Office has stated that Congress needs to pass legislation to grant NCUA third-party vendor authority because, otherwise, there are mounting risks to the financial system.
“Our own Inspector General, which is independent from the NCUA, did an examination and said that it's their position that we need to have vendor authority,” Harper said.
Harper emphasized his opinion is one held by the NCUA board. Harper, a Democrat, is expected to be replaced as chairman next year by Vice Chairman Kyle Hauptman, a Republican, when Donald Trump takes office.
“It is the board's position that we have vendor authority, and that continues to be the position of the agency. Now, a different chairman may have different perspectives on it, but the fact is that is what the board’s announced public position is, going back years,” Harper explained. “If we were to get vendor authority, we would work very carefully to focus on what are the areas causing greatest risk—just like we do during an exam at the credit union. And we would have narrow places where we would then be looking when it comes to vendors.
“And if we don't get that vendor authority, this year's Financial Stability Oversight Council report says we should work to increase the reserves of the credit union system to account for those risks,” continued Harper. “And I'm certainly supportive of that.”
At what percentage might the NOL be set?
“I don't want to get out in front of that because that's something that staff needs to study—how many points we are talking about. That's something that I'm not ready to answer,” Harper said. “I've said publicly that next year we're going out with a public notice and comment period on making adjustments to how we manage the normal operating level. And at that point in time we will have a clearer understanding of what those risks are and how we might account for them.”
Feedback Invited
Public feedback will be invited, Harper stressed.
“We will take in all the feedback and use it in our analysis as to whether (the NOL) should be modified before the board would adopt any changes to the operating model structure,” Harper said.
Harper recognized that VyStar’s well-publicized problems with its online and mobile banking rollout support the need for NCUA to have third-party vendor oversight authority. He also addressed the CFPB’s new rule on open banking.
“The open banking rule is about giving customers ownership of their own information. So, if they want to switch providers it would be easier for them,” Harper explained. “You don’t have to go through the trouble of cancelling credit cards and re-setting up all of the different payments that were on the under the old card.”
There are added security risks and dangers that come with the growth of open banking, Harper acknowledged.
“But there are also opportunities for credit unions. Credit unions consistently talk about how they are the best option for consumers,” he said. “Well, if they are indeed the best option for consumers the open banking rule could be a tremendous opportunity for them to attract members and bring more people into the credit union system.”
Harper emphasized that risks to the CU system are magnified today, and that lack of third-party vendor oversight is a growing problem.
“The risks are greater to the system,” he said. “The need to protect the system is greater today. We would be wise to get ahead of this matter before there's a problem and we have to deal with cleaning up a mess that’s much larger than it should have been.”
