I was talking with a credit union executive once when she said something I’ve heard in different forms many times over the years.
“Rusty, I don’t mind examinations. I just don’t like surprises.”
I understood exactly what she meant.
Nobody expects an examination to be fun.
But there’s a big difference between walking into one knowing where your technology risks are and discovering those risks while someone else is asking questions about them.
That’s why I don’t think examination preparation should begin a few weeks before the examiner arrives.
It should be part of your technology strategy all year long.
For an Ohio credit union, that means bringing together leadership, compliance, operations, and technology to regularly review cybersecurity, business continuity, vendor management, risk assessments, policies, infrastructure, and emerging technologies.
You don’t need a perfect technology environment.
You need to understand your environment, document what you’re doing, recognize your risks, and demonstrate that you’re actively managing them.
Here are nine areas I’d put on the agenda.
1. Start With Your Previous Examination
Before creating another checklist, go back to what you already know.
What questions came up during your previous examination?
Were there findings or recommendations?
Did management commit to specific improvements?
Were those improvements completed?
And most importantly:
Can you demonstrate what changed?
Closing the loop matters.
If an issue was identified previously, leadership should be able to explain what was done, when it was completed, and how the organization is monitoring it going forward.
That’s a much stronger position than scrambling to reconstruct the story when someone asks.
2. Review Your Technology Risk Assessment
A good risk assessment shouldn’t be something you complete, save as a PDF, and forget.
It should help guide your technology priorities.
Review your current risks around areas such as:
- Cybersecurity
- Aging infrastructure
- Microsoft 365
- Remote access
- Cloud services
- Third-party vendors
- Business continuity
- Data protection
- Employee access
Then ask three questions:
What’s our biggest risk?
What are we doing about it?
Can we document our progress?
That’s the kind of conversation leadership should already be having before examination preparation begins.
3. Take a Fresh Look at Cybersecurity
Cybersecurity changes too quickly for last year’s answers to automatically remain good answers.
Review the fundamentals.
Is multi-factor authentication appropriately deployed?
Are privileged accounts protected?
Are endpoints monitored?
Are systems patched?
Are employees receiving security awareness training?
How are suspicious events detected and escalated?
How are Microsoft 365 accounts and data protected?
This is also a good time to review your cyber insurance application.
If you told your insurance carrier that a particular security control was in place, make sure reality still matches the answer.
Documentation should reflect what your technology is actually doing—not what everyone assumes it’s doing.
4. Prove You Can Recover
This is one of my favorite questions:
“When did you last prove that your backups work?”
Notice I didn’t ask whether you have backups.
Most organizations do.
The real question is whether you can recover.
Review:
- Backup success
- Restore testing
- Critical applications
- Recovery priorities
- Recovery time expectations
- Recovery point expectations
- Alternative communications
- Disaster recovery procedures
Then test something.
A tabletop exercise can be especially useful.
Tell your leadership team:
“It’s 8:15 Monday morning and ransomware has affected several systems. What happens next?”
You’ll learn more from that conversation than you will from another green backup dashboard.
5. Review Your Incident Response Plan
If something happens, who makes the first phone call?
Your incident response plan should provide a practical answer.
Review contact information and responsibilities for appropriate internal and external parties, which may include:
- Executive leadership
- IT
- Your managed technology/security partner
- Compliance
- Legal counsel
- Insurance resources
- Critical vendors
- Communications personnel
Don’t wait until an incident to discover that the person listed in the plan left two years ago.
Plans need maintenance.
6. Know Your Vendors
Credit unions don’t operate technology by themselves anymore.
You may depend on a core provider, Microsoft, telecommunications companies, cybersecurity vendors, cloud providers, fintech companies, backup providers, and other third parties.
Make sure you understand your critical technology relationships.
Ask:
- Which vendors have access to sensitive information?
- Which vendors have privileged access?
- How are those relationships reviewed?
- Who owns each vendor relationship?
- What happens if a critical provider becomes unavailable?
- Are responsibilities clearly documented?
Your technology partner should help you see the entire ecosystem—not just the equipment sitting inside your building.
7. Review Your Policies Against Reality
Here’s where organizations sometimes get themselves into trouble.
The policy says one thing.
Technology is doing something else.
Maybe the policy says access is reviewed annually.
Was it?
Maybe it says employees receive regular cybersecurity training.
Can you demonstrate that?
Maybe the incident response policy identifies specific responsibilities.
Are those people still responsible?
Policies shouldn’t describe the organization you hope you have.
They should describe the organization you’re actually operating.
8. Add AI to the Conversation
This is increasingly important.
Your employees may already be using artificial intelligence even if the credit union hasn’t formally adopted an AI platform.
So ask:
- Are employees using ChatGPT, Copilot, or other AI tools?
- Do we have an acceptable-use policy?
- Do employees know what information shouldn’t be entered into unapproved tools?
- Are existing vendors introducing AI capabilities?
- Who evaluates those features?
- How are privacy, security, and governance being considered?
You don’t need to have every answer about AI.
Nobody does.
But leadership should be able to demonstrate that the organization is thinking about emerging technology responsibly.
9. Turn Everything Into a Roadmap
Here’s where all of this comes together.
An examination shouldn’t be the thing driving your technology strategy.
Your strategy should already exist.
After reviewing cybersecurity, infrastructure, business continuity, vendors, policies, Microsoft 365, AI, and other risks, create a prioritized roadmap.
I like organizing it into three buckets:
Now: Issues requiring immediate attention.
Next 12 Months: Projects that should be incorporated into the current budget and operating plan.
Next 3–5 Years: Strategic investments such as cloud modernization, infrastructure replacement, cybersecurity improvements, AI adoption, and major application changes.
Now when leadership or the board asks where technology is headed, you have an answer.
And when an examiner asks how you’re addressing a particular risk, you can show that it’s part of a thoughtful process rather than a last-minute reaction.
Use Your Annual Technology Strategy Meeting
This is exactly why I recommend every credit union hold a formal technology strategy meeting at least annually.
Set aside 90 to 120 minutes.
Bring together the appropriate people from leadership, operations, compliance, and technology.
Review:
- Previous findings and commitments
- Current technology risks
- Cybersecurity posture
- Business continuity and ransomware recovery
- Vendor management
- Policies and documentation
- Infrastructure lifecycle
- Microsoft 365 and cloud security
- AI and emerging technology
- Budget and the 3–5-year roadmap
Then leave the meeting with clearly assigned priorities, owners, and target dates.
That’s far more valuable than waiting for an examination notice and starting a fire drill.
The Question Every Board Should Ask
Your board doesn’t need to understand every cybersecurity tool or every technology standard.
But there is one question worth asking:
“If an examiner asked us to explain our three biggest technology risks today, could we confidently explain what they are and what we’re doing about them?”
If the answer is yes, you’re probably having the right conversations.
If the room gets quiet, you’ve identified where to start.
Final Thoughts
Preparing for an NCUA examination isn’t about making everything look perfect.
It’s about knowing your environment.
Understanding your risks.
Documenting your decisions.
Testing your recovery.
Managing your vendors.
Training your people.
And showing that technology risk is being managed as part of the credit union’s broader business strategy.
After more than 26 years in technology, I’ve found that preparation creates something every leadership team wants:
Confidence.
Confidence when the board asks questions.
Confidence when the cyber insurance renewal arrives.
Confidence when something goes wrong.
And confidence when an examiner walks through the door.
Don’t build your technology program for the examination.
Build a strong technology program for your members.
Then examination readiness becomes a natural result of doing the right things all year long.
Is Your Credit Union Ready for Its Next Technology Review?
At CTG, we help credit unions prepare before technology questions become examination surprises.
We can work with your leadership team to review your technology environment, cybersecurity posture, Microsoft 365 security, business continuity and ransomware recovery, vendor relationships, infrastructure lifecycle, AI readiness, and long-term technology strategy.
Then we help turn those findings into a practical 12-month action plan and 3-to-5-year technology roadmap your leadership team and board can understand.
For more than 26 years, CTG has helped organizations make technology decisions with confidence. Our vendor-agnostic approach means we start with your needs, risks, and goals—not a product we’re trying to sell.
Talk with CTG
Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net
Let’s find the gaps before the examination does—and build a technology strategy that protects your credit union, your employees, and the members who trust you.
Recent Blog Posts...
Preparing Your Credit Union for the Next NCUA Examination: What Should Your Technology Team Review?
Microsoft 365 Security Best Practices for Ohio Credit Unions
How Should an Ohio Credit Union Build an Annual Technology Strategy Meeting Agenda?
What Every Ohio Credit Union Board Should Know About Cybersecurity
How Should an Ohio Credit Union Prepare for a Cyber Insurance Renewal?
- AI6
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud58
- Collaboration18
- Communication20
- Compliance4
- Contact Center1
- Credit Unions14
- Cyber Liability Insurance2
- Cybersecurity37
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure26
- Managed Network Services20
- Managed Services19
- Microsoft Teams2
- Network Performance29
- Network Security34
- News11
- Phishing1
- Press Release2
- Risk Assessment3
- security2
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx7
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

