Cyberuptive

Credit Union & Financial Services Checklist

A 40-point exam-readiness checklist for credit unions and community financial institutions.

What an NCUA or state examiner actually asks to see, organized so you can walk in with the documentation ready instead of assembling it during the exam.

Free download

Get the checklist as a PDF

We’ll email a formatted PDF you can print, share with your compliance team, or drop into your exam prep binder. The full checklist is also below on this page.

How to use this

For each item, mark Documented & Current / Exists but Outdated / Missing. Anything not “Documented & Current” is what an examiner will flag first, so prioritize those before your next exam cycle, not during it. Want a scored maturity view first? Start with our Financial Services Security Assessment.

Governance & Board Reporting

  • Board-approved information security program on file, reviewed in the last 12 months
  • Board or a designated committee receives a cybersecurity update at least quarterly
  • Named information security officer with documented authority, not an informal assignment
  • Risk assessment results presented to the board in language they can act on, not just a technical report
  • Prior exam findings tracked to closure with dates and owners

Identity & Access Controls

  • Multi-factor authentication enforced for all remote and administrative access
  • Privileged account access reviewed at least quarterly
  • Access reviews documented with sign-off, not just performed informally
  • Terminated-employee access removal is same-day and logged
  • Shared or generic accounts eliminated or individually accountable

Vendor & Third-Party Risk Management

  • Inventory of all vendors with access to member data or core systems
  • Vendor risk tier assigned based on data access and criticality
  • Annual vendor security review completed for critical/material vendors, with evidence on file
  • Vendor contracts include security and breach-notification obligations
  • Fourth-party (your vendor’s vendors) exposure identified for critical service providers

Vulnerability & Patch Management

  • Vulnerability scanning performed at least quarterly, with results tracked to remediation
  • Patch management SLA defined by severity (e.g., critical patched within a set number of days)
  • External penetration test completed at least annually
  • Internal penetration test and social-engineering/phishing test completed at least annually
  • Known Exploited Vulnerabilities (CISA KEV) cross-checked against your environment, not just general CVE scoring

Incident Response & Regulatory Notification

  • Written incident response plan tested via tabletop in the last 12 months
  • 72-hour NCUA cyber incident notification workflow documented and assigned to a named owner
  • Member notification procedure meets state breach-notification law timelines
  • IR plan includes law enforcement and cyber-insurance carrier contact procedures
  • Post-incident review process documented, with findings tracked to remediation

Business Continuity & Backup

  • Immutable, tested backups for core banking and member-data systems
  • Business continuity plan tested at least annually, including a branch-outage scenario
  • Recovery time objectives defined and validated against actual restore tests
  • Alternate processing site or cloud failover documented and tested
  • Backup and continuity plans reviewed after any material system change

Employee Training & Awareness

  • Security awareness training completed by all staff at least annually, tracked by name
  • Phishing simulation program in place with results tracked over time
  • Role-based training for staff with elevated access (IT, finance, wire desk)
  • New-hire security training completed before system access is granted
  • Board and senior management receive their own cybersecurity briefing, separate from general staff training

Audit Trail & Examiner Documentation

  • Most recent ACET (or equivalent) self-assessment completed and on file
  • Evidence library organized so documentation can be produced within the exam’s timeframe, not assembled from scratch
  • Prior exam report and management response on file with tracked remediation status
  • Internal or external IT audit completed in the last 12–18 months
  • Change management and configuration records available for core system changes

Sources & further reading

This checklist is built around the NCUA’s Automated Cybersecurity Examination Tool (ACET), the framework NCUA examiners use to assess credit union cybersecurity maturity, and references the CISA Known Exploited Vulnerabilities (KEV) Catalog for patch prioritization. ACET itself is built on the FFIEC Cybersecurity Assessment Tool, so much of this checklist maps cleanly to bank and thrift examinations as well.

Frequently asked questions

What is ACET and do all credit unions have to use it?

The Automated Cybersecurity Examination Tool (ACET) is NCUA's standardized framework for assessing a credit union's cybersecurity maturity during examinations. NCUA examiners use it as part of the exam process for federally insured credit unions; the maturity levels in this checklist (Baseline through Innovative) mirror ACET's own scale.

How often does NCUA expect a cybersecurity self-assessment?

NCUA guidance encourages credit unions to complete an ACET self-assessment periodically, commonly annually, and to update it after material changes to IT systems, core processor relationships, or after a security incident. Your examiner can confirm the expected cadence for your specific charter size and risk profile.

What's the difference between ACET and the FFIEC Cybersecurity Assessment Tool?

ACET is NCUA's adaptation of the FFIEC Cybersecurity Assessment Tool, built specifically for credit unions. The underlying maturity model and most control domains are consistent between the two, which is why credit unions working with core processors or vendors that also serve banks often see very similar assessment language.

Do third-party vendors and core processors need to be included in this checklist?

Yes. NCUA examiners routinely review third-party risk management, including due diligence on core processors, digital banking vendors, and payment processors, as part of an ACET-aligned exam. A checklist that only covers internal systems misses a significant share of what examiners actually ask about.

What happens if my ACET self-assessment shows gaps right before an exam?

Document them. Examiners generally respond better to a credit union that has identified its own gaps with a documented remediation plan than to one that appears unaware of them. A dated action plan with owners and target dates is far stronger than no assessment at all.

Aloha, let’s talk

Want your next exam prep run for you?

We build the documentation trail examiners actually ask for, before the exam letter arrives.