By Ray Birch
WASHINGTON—A former NCUA chairman who opposed NCUA oversight of third parties while he was in that role said it’s a viewpoint he continues to hold, saying he believes and NCUA such authority would present new challenges for the agency and turn the agency into the “Federal Trade Commission of the credit union industry.”
Dollar, who joined the NCUA board in 1997 and then served as chairman from 2001-04, is sharing his perspective at the same time four other former NCUA chairs have recently sent a letter to Congress urging it to grant the agency authority to oversee vendors, including CUSOs.
The former chairs who signed the letter are Michael Fryzel, Debbie Matz, Mark McWatters and Rick Metsger.
The former chairs stated in part in their letter, “Given the increasing reliance of credit unions on third-party vendors for critical functions such as data processing, deposit taking, payment services, loan servicing, and mobile and online member services, it is imperative that the NCUA be granted the authority to oversee these vendors effectively,” the letter states in part. “Without proper oversight of these service providers, credit unions may be exposed to greater chances of operational disruptions, financial losses, reputational damage, and, most importantly, threats to the security and privacy of their members' information.”
Current NCUA Chairman Todd Harper has also repeatedly urged Congress to amend the FCU Act to give NCUA oversight.
Beyond ‘Scope’
“I have great respect for my colleagues as former chairmen. They were all effective chairmen and their views are consistent with the positions they took when they were at NCUA,” said Dollar, who today leads the consulting firm Dollar Associates. “Personally, I do not believe having the authority to examine every type of enterprise that does business with a credit union is within the scope or ability of NCUA as a federal agency charged with the safety and soundness of credit unions and credit unions alone. That is the position I took as NCUA chairman and the one I still take today.”
Dollar told CUToday.info his view is formed by what he saw while he was with the agency.
“From my experience as a NCUA chairman, I do not believe NCUA has the expertise to examine every type of business. They should stick to what they do best—examining and making sure credit unions are safe and sound,” Dollar said.
‘Dramatic’ Increase
Dollar said that in order for NCUA to gain sufficient expertise to examine every type of entity that does business with a credit union would require a “dramatic” increase in the agency’s budget and be a major expansion of the agency’s authority.
“Credit unions are very concerned about the potential overreach of utilizing the authority to force credit unions to take actions they might not otherwise need to take through coercion of their vendors,” he said.
Moreover, Dollar said he believes granting additional regulatory and examination authority to a federal agency to go beyond its congressionally mandated safety and soundness responsibilities is not good public policy.
“NCUA has a stellar record in protecting the insurance fund and keeping credit unions a safe and sound contributor to the American economy and impacting positively the financial lives of over 120-million credit union members nationwide,” Dollar said. “In my view, that should remain their focus—not trying to become the Federal Trade Commission of the credit union industry.”
What About Cyber-Threats?
Dollar acknowledges the growing cyber-attacks are one of the primary reasons NCUA has cited in its bid to gain the expanded oversight.
“Cyber security is always a concern even though there are over 40 federal agencies with cyber responsibilities today,” Dollar pointed out. “I just cannot see how having one more agency expanding its authority, budget and staffing to focus on cyber risks is going to make any real difference over what 40 agencies have done and can do. NCUA already has authority over cybersecurity issues at credit unions, and they are correct to focus on cybersecurity at credit unions. There does not seem to be the need, in my view, to have NCUA examiners taking time from examining credit unions to go into data processors, check printers, advertising agencies, copier companies, lawn care companies and garbage disposal contractors.”
Information is Available
Financial Institutions Examination Council (FFIEC), can work with fellow federal financial regulators to access information from their exams of the “most impactful” vendors that work with banks and credit unions, such as core processors and credit card companies.
As NCUA often notes, other regulators, including the FDIC, have third party oversight authority.
“So, NCUA is not at all impotent in the cyber security risk arena, as they can examine credit unions—their primary responsibility—and can access information through their fellow regulators on the largest vendors with direct access to member data,” Dollar said.
Dollar said NCUA has always “coveted” the expanded authority and that Congress, under control of both Democrats and Republicans, has not granted it for over twenty years.
“The reason is simple,” Dollar said. “Congress does not easily, and in a bipartisan manner, expand regulator authorities without a compelling reason that cannot be accomplished within existing authority, particularly if it is to expand federal agency authority over private businesses, and especially small businesses.”
Calls from the Hill
Dollar said that following the recent letter from the former chairs, congressional staffers have reached out to him asking why his signature wasn’t also on the letter.
“I have told them the same thing I did when I opposed vendor authority as NCUA chairman,” Dollar said. “I think it will take the agency away from its primary safety and soundness focus, have a dramatic impact upward on the NCUA budget, have the potential to be abused on individual vendors of all sizes by examiner overreach—and, the most important information is from vendors that serve banks as well as credit unions and, therefore, can be cooperatively gained through partnership with other FFIEC agencies.”
Based on his interactions with Capitol Hill, Dollar said he does not believe Congress has the “appetite” for dramatically expanding the authority of a smaller agency, like NCUA, just because it would like to have it.
“However, that could change,” Dollar said. “But Congress has been very consistent in its failure to even vote on expanded vendor authority for NCUA over the past 25 years. No matter where we stand on the issue, pro or con, I’m not sure that the views of a handful of us former chairmen are going to change the way Congress looks at a federal agency’s authority and the possibility of a significant expansion of that authority.”
A ‘Tough Sell’
Dollar emphasized that everyone is entitled to his or her own opinion on the vendor authority question.
“But the scope of federal agency authority is a major policy issue for Congress that they will take very seriously in such a closely divided environment,” concluded Dollar. “From what I have learned in discussions with congressional officials and staff over recent years about this issue, I personally think it’s going to be a tough sell in Congress. But if it passes or fails, I doubt that us former chairmen will impact that decision very much, regardless of whether we are for it or against it.”
