Insights

Compliance Strategy for
Credit Union Leaders

Perspectives on regulatory risk, competitive positioning, and the technology decisions that determine whether your compliance function is a liability or an asset.

Agents Propose, People Decide: How We’re Redesigning Credit Union Compliance

Compliance teams at credit unions are small, and the work keeps growing: more data, more often, with the same examiner expectations. We are rebuilding PinotPulse around one idea. AI agents do the heavy lifting. A person in the matching role makes every decision that counts.

Four agents, four owners

Each agent will be paired with the officer whose job it is to decide. The Risk Analyst agent works for your Risk Manager. The Officer agent works for your Compliance Officer. The BSA agent works for your BSA Officer. The Loan agent works for your lending and compliance team. The goal is that an agent hands its officer a finished proposal, not a blank form.

The line that never moves

Four things are reserved for a person, always: approving, verifying or submitting a filing; the SAR file or no-file decision; dismissing an alert or clearing an OFAC hit; and attesting to figures. We are designing the software to enforce this: an agent that asks for any of those four actions will be refused by the platform itself, not stopped by a policy document.

Every action has a name on it

In the design, an agent acts under a named person’s authority, and the record will show the agent, the person it acted for, and the run that produced the work, so an agent’s work can never be passed off as a person’s. An agent will never be both maker and checker. Everything an agent prepares is checked by a distinct, named person, including at a one-officer credit union. Agents will work through the same interfaces your staff use, with no side door. Rate and cost limits and a kill switch are part of the design.

Where this stands

We are building this now and are inviting a small group of credit unions to shape it as design partners. A person will always submit through the agency’s own channel; the agent never sends anything to a regulator. The next four posts take each agent in turn: what it prepares, and what it leaves to the officer.

The Risk Analyst Agent: Your Risk Manager Reviews a Finished Read, Not Raw Data

A risk manager at a credit union spends too much of the quarter assembling numbers and too little of it judging them. The Risk Analyst agent is built to flip that ratio.

What the agent prepares

It is designed to watch credit, interest-rate, liquidity and concentration risk on the institution’s own data as that data loads. It will draft the CAMEL self-assessment and the board read, and assemble the figures an examiner typically asks for, each one traceable to the source rows behind it. When an exposure moves, it will flag the movement and explain it in plain language rather than leave a red cell for someone to decode.

What stays with the Risk Manager

The agent proposes. Your Risk Manager verifies, approves and owns the result. The agent will not attest to figures or sign off a board package. If a number is wrong, the review is designed to show exactly where it came from, so the correction happens at the source and not in a spreadsheet copy.

Why absent is not zero

We hold this agent to one rule: a figure it cannot compute is shown as unavailable, never as zero. A dashboard that quietly fills gaps with zeros looks healthy at precisely the moment it should not. An honest “data unavailable” is something a risk manager can act on.

Where this stands

The Risk Analyst agent is part of the agentic platform we are building now, and we are inviting a small group of credit unions to shape it as design partners. If your risk function wants a say in how it works, we would like to hear from you.

The Officer Agent: A 5300 Draft That Explains Itself Before the Deadline

Every quarter, the NCUA 5300 Call Report turns into a sprint: exports, mapping, reconciliation, and a race to clear edit-check errors before they become rejections. The Officer agent is designed to take the sprint out of it.

What the agent prepares

It is designed to pre-fill the 5300 from the institution’s own data and record where every figure came from. It will run the agency’s published edit checks as the data loads, not the night before the deadline. Each warning is meant to come with a plain-language explanation of what triggered it and what would clear it. It will also prepare the workpapers behind the filing, so your compliance officer opens a finished draft, not a blank form.

What stays with the Compliance Officer

The officer reviews what the agent did and why, with the source behind each number. Only a person can approve the report, confirm the figures, or submit it. By design, an unexplained warning keeps the report from being marked ready until a person has looked at it, because a warning nobody read is the one an examiner asks about.

The agency’s rules, not ours

The agent checks against the edits the agency publishes. It does not invent a stricter or looser private version. When the agency changes an edit, our check is updated to match. That is the only kind of validation a compliance officer can defend.

Where this stands

A person submits the 5300 through the agency’s own channel, and that stays true as we build the Officer agent. We are inviting a small group of credit unions to shape it as design partners.

The BSA Agent: It Builds the Case File. Your BSA Officer Makes the Call.

BSA work at a credit union is mostly volume. Alerts arrive faster than one officer can read them, and the judgement that matters gets squeezed into whatever time is left. The BSA agent is designed to handle the volume so the officer has time for the judgement.

What the agent prepares

It is designed to triage alerts and group the activity behind each one. It will screen names against the OFAC SDN list, assemble draft FinCEN SAR and CTR filings, and put together the complete case file: the transactions, the member history, and a narrative draft that says what happened and why it was flagged. The officer walks into a decision, not a pile of raw alerts.

What the agent will never do

The SAR file or no-file decision belongs to your BSA Officer. The agent cannot dismiss an alert, cannot clear an OFAC hit, and cannot submit a filing. The platform is being designed so those actions refuse an agent outright, rather than relying on good intentions.

Confidentiality by design

SAR information is among the most sensitive data a credit union holds. The design limits who and what can see SAR information, and treats anything an agent reads, such as a transaction memo, as data and never as instructions, so a crafted note cannot redirect the agent. Every step the agent takes will be logged with the person it acted for.

Where this stands

The BSA agent is part of the platform we are building now, and we are inviting a small group of credit unions to shape it as design partners. A person submits every filing through FinCEN’s own channel; the agent never sends anything.

The Loan Agent: HMDA Problems Found at Origination, Not the Night Before the Deadline

Many HMDA errors are made months before anyone notices them. A field gets keyed wrong at origination, sits in the system all year, and turns up during the scramble to file. The Loan agent is designed to catch it when it happens.

What the agent prepares

It is designed to validate HMDA LAR data as loans are entered, against the edits the agency publishes, and explain each problem while the loan file is still open and the person who knows the answer is still at their desk. It will prepare the Reg B and Reg Z artifacts that sit alongside lending, and check the fair-lending fields early, so a gap is a quick correction rather than a year-end reconstruction.

What stays with your team

Your lending and compliance team verifies and owns every result. The agent proposes corrections; a person accepts them. The agent submits nothing, and by design no correction is applied without a named person approving it.

Why early matters

A HMDA edit caught at origination is a quick fix. The same edit caught at filing time means finding the file, finding the person, and reconstructing what they meant. Moving the check to the moment of entry saves that reconstruction, and it takes no judgement away from the people who own it.

Where this stands

The Loan agent is part of the agentic platform we are building now, and we are inviting a small group of credit unions to shape it as design partners. If you run lending compliance, we would welcome your view on how it should work.

Watch: We Filmed the Red Screens Too — 28 Compliance Screens on a Credit Union That Is Not Ready to File

Every compliance product demo you have ever sat through was filmed on a green dashboard. This one is not. It is the complete risk-officer seat — twenty-eight screens, one login, under four minutes — and the readiness panel in the middle of it says 54%, Not Ready, submission blocked. We left it in, because a readiness score that cannot come back red is not a control. It is a logo.

Three numbers in this video that no vendor publishes

54%, Not Ready, one blocking error. The NCUA 5300 readiness simulator scoring the seeded institution before anything leaves the building, and refusing to unlock submission. The useful output of a pre-submission check is the one that stops you.

8.8% of 1,097 edit codes backed by real checks. That is our own coverage denominator, rendered on the screen, in the video, on the marketing page. The 5300 Call Report carries over a thousand validation edits; we have wired a known fraction of them and we show the fraction rather than the ratio of the ones we happen to pass. A competitor who cannot tell you their number is not telling you it is high.

0 of 110 HMDA fields, XML schema invalid. There is no HMDA data loaded for this org, and every panel reports zero instead of interpolating a friendly-looking partial. A reporting tool that renders something when it was given nothing will render something when it was given the wrong thing.

The CAMEL screen is labelled a heuristic on camera

The tour opens on a CAMEL dashboard — capital, asset quality, earnings, liquidity, each scored against peers — and the narration's second sentence is that it is flagged in-product as an internal heuristic, because examiners do not use this formula. NCUA does not publish the CAMELS arithmetic and a vendor who implies otherwise is selling you a number you cannot defend in an exam. Ours is useful for direction and it says what it is.

The rest of the seat

Risk & Compliance. A red-flag scan reading transactions against the FFIEC BSA/AML manual and drafting SAR recommendations with a confidence score on each. Reg E §1005.11 disputes — seven open, one already past its investigation window, 9.4 days average, provisional credit tracked against the ten-business-day rule. ALLL/CECL reserving on the NCUA simplified tool: $210K held against $193K required, with commercial showing under-reserved rather than quietly rounded up. Fraud alerts across card, ACH and account takeover; twenty-five cases, each with a type, a severity and a clock; and the audit-log tab that carries the SOC 2 application trail.

Regulatory — twenty tabs. Reg B disparate impact with the four-fifths test and p-values per protected class. CECL qualitative factors, nine per segment, with direction, basis points and a written justification. Declared segment methodology. GL-to-subledger reconciliation that blocks a filing on a hard break. PCD assets under ASC 326. A Federal Register / NCUA / OFAC rule-change feed. Examiner workpapers with seven-year retention enforced in the database, and scoped, expiring examiner-access tokens with an activity trail. A filing calendar — eleven due, three overdue. Fifteen reports in submission history with per-report confidence. OFAC screening evidence and the BSA program annual review, both view-only from this seat because the BSA officer is the filer of record. CIP and EDD program evidence quarter by quarter. USA PATRIOT Act §314(a) information sharing with the twelve-month lookback enforced. FinCEN DOEP Form 110 and IRS Form 8300. And an ingestion audit of nine validators that reports real results only, with an empty state when nothing has been run.

Why publish the unflattering cut

Credit unions buy regulatory software the way they buy an audit: the thing being purchased is defensibility. You cannot get defensibility from a vendor who has never shown you their product failing. Four thousand credit unions are currently choosing between reporting suites owned by the same consolidator, and the differentiator we are betting on is not a feature — it is that we will tell you our coverage number before you ask for it.

Recorded 17 September 2026 against a local build. The institution shown is Pinot Valley FCU, our seeded demonstration credit union — not a customer, and not real member data. Several panels in the footage are empty or carry seeded placeholder values, and are labelled as such on screen. Informational only — not legal advice, and no substitute for your own counsel or your examiner’s guidance.

Watch: The Whole Lending Seat, Unedited — Where the Loan Book and the Filing Are One System

Vendor demos show you three screens. This is twenty-five, in one login, in under four minutes: everything a lending officer at a credit union can reach in PinotPulse, in the order the left rail presents it, with nothing skipped because it was inconvenient.

The point of a full-seat tour

Lending systems and compliance systems are almost always two purchases. The loan origination system holds the book; a reporting product re-reads an extract of it once a quarter and builds the filing. Everything painful about regulatory reporting at a credit union lives in the seam between those two: the extract that was taken on the wrong date, the field the mapping dropped, the reconciliation nobody can reproduce twelve months later when an examiner asks.

What this footage is meant to show is the absence of that seam. The HMDA loan application register, the Reg Z disclosure clock and the Reg B fair-lending test are tabs in the same left rail as the loan book, reading the same rows, under one login. Not integrated — the same system.

What is on screen, in order

The book. A lending dashboard at $86M in assets and $28M in loans across 363 members; Member 360 and its lifecycle split (212 engaged, 126 at risk, 24 dormant); 598 share accounts holding $58M; and the loan portfolio — 309 current, 3 delinquent, six loan types, with auto flagged at 79% concentration. Then each book on its own tab: commercial ($5.3M / 33 loans), consumer ($21.7M / 270), mortgage (9 loans / $1M), and a delinquency view of three loans across three aging buckets.

The filing. The HMDA loan application register as a six-step workflow where submission stays locked until validation clears 99.5% confidence — the point being that the button is disabled by evidence, not by a checkbox. Reg Z §1026.19 disclosures with the three-business-day delivery clock computed per record, and the loan estimate and closing disclosure queues behind it. Reg B fair lending running the four-fifths test on every protected class — ten comparisons this quarter, all passing. CECL qualitative factors, nine per loan segment, read-only from this seat because the risk officer owns them. Purchased credit-deteriorated assets under ASC 326. An examiner workpaper packet, a scoped examiner-access panel, and a submission history of fifteen reports with a due date and a confidence score on each.

What the tour does not hide

Several panels are empty, and they say so on screen rather than rendering a zero that looks like a measurement: no loan estimates issued, no closing disclosures issued, no PCD assets on the books, no examiner tokens outstanding, no rule changes matching today's filters. An empty state that admits it is empty is the difference between a product you can audit and a dashboard you have to trust.

Recorded 17 September 2026. The institution shown is Pinot Valley FCU, our seeded demonstration credit union — not a customer, and not real member data. Informational only — not legal advice, and no substitute for your own counsel or your examiner’s guidance.

The $500M Line: What Crossing It Changes About Your Audit

Most asset thresholds in credit union regulation arrive gradually. You watch them coming for years, and the quarter you cross one looks much like the quarter before. The $500 million line is different, because it swaps out the kind of audit you are required to obtain — and it does so for the fiscal year you are already in.

What actually changes

Under 12 CFR 715.4(c), a federally insured credit union with total assets of $500 million or greater must obtain an annual audit of its financial statements, performed in accordance with Generally Accepted Auditing Standards, by an independent person licensed to do so by the state or jurisdiction where the credit union is principally located.

Below that line, a supervisory committee audit satisfies the requirement. Above it, it does not. That is the whole change, and it is a larger one than the sentence suggests: a supervisory committee audit and a GAAS financial statement audit are different engagements, with different evidence expectations, different workpaper standards, and a different relationship to your general ledger.

This applies to both charter types. Part 715 reaches federally insured credit unions whether federally or state chartered. State-chartered credit unions should also check their state supervisor’s requirements, which in some states are more rigorous than the federal floor rather than equivalent to it.

Why the timing catches people

The threshold is measured on total assets, and assets move for reasons that have nothing to do with audit readiness — a strong share-growth quarter, a merger completing, a large deposit inflow. A credit union can cross $500 million in a quarter where nobody on the finance team was thinking about Part 715 at all, and discover the new obligation when the supervisory committee starts scoping the annual audit.

This is not a rare event. Analysing NCUA’s Q1 2026 Call Report data against the same quarter a year earlier, 20 credit unions crossed $500 million in the preceding four quarters, and a further 17 crossed $1 billion. Every one of the 20 picked up this requirement in the process.

What to have ready

An independent auditor performing a GAAS engagement will ask for evidence in a form that supervisory committee audits often do not require. The gaps we see most often are not accounting problems — they are documentation problems:

Reconciliation trails that survive being asked twice. Not just the reconciliation, but who performed it, who reviewed it, and when. A reconciliation that is correct but undocumented is a finding.

A general ledger mapping you can explain. When a Call Report line is questioned, the answer needs to be a traceable path from GL account to reported figure, not institutional memory.

Evidence of controls operating, not just existing. A written policy is the beginning of the answer. The evidence that the control ran — every period, with an identifiable reviewer — is the rest of it.

Prior-period consistency. Restatements are survivable. Unexplained restatements are not.

The honest version

Crossing $500 million is good news. It means the credit union grew. The requirement that comes with it is manageable, and credit unions handle it every year without drama — but it is meaningfully easier when the evidence has been accumulating all along than when it is assembled in the eight weeks before fieldwork.

If you crossed the line in the last year, the useful question is not whether you will comply. It is whether your evidence is currently in a form somebody outside your institution can follow without you in the room.

Sources: 12 CFR 715.4 and 715.5; NCUA Q1 2026 Call Report data. Informational only — not legal or accounting advice, and no substitute for your own counsel, your auditor, or your examiner’s guidance.

One Owner Now: What the Regnology Roll-Up Means for Credit Union Reporting

Over roughly thirteen months, most of the United States regulatory reporting market has consolidated under a single European owner. If your credit union files through Fed Reporter, or evaluated Wolters Kluwer at any point, this changes who you are actually buying from — and it is worth understanding before your next renewal rather than during it.

What happened, in order

July 2025. Wolters Kluwer agreed to divest its Finance, Risk and Regulatory Reporting unit — the OneSumX product line — to Regnology, a Frankfurt-based regulatory technology company backed by Nordic Capital. Enterprise value was approximately €450 million. The transaction closed on 1 December 2025.

December 2025. Regnology agreed to acquire Moody’s regulatory reporting and ALM business, adding Basel III, IFRS 9, ALM and Solvency II coverage across more than fifty jurisdictions.

July 2026. Regnology signed a definitive agreement to acquire Fed Reporter, subject to customary regulatory approvals. Regnology described the deal as extending its reach to more than 4,000 institutions, “from global banks to community lenders.”

Fed Reporter was itself already a consolidator. It absorbed Jack Henry’s Regulatory Filing Group in 2017 and FIS’s Regulatory Reporting Group in 2023. For a large share of credit unions filing the 5300 through software, the vendor lineage now runs through one owner.

One correction worth making

Wolters Kluwer did not exit compliance. What it sold was the finance, risk and regulatory reporting unit. Its Financial & Corporate Compliance division retained — and said it would reinvest in — its U.S. banking compliance business. If you use a Wolters Kluwer product for lending or deposit compliance, that is a different business unit and is not part of this transaction.

What it means for a credit union

Consolidation is not automatically bad. Regnology is a serious regulatory technology company, and scale can fund exactly the kind of schema-tracking and agency-relationship work that filing software depends on. That is a real argument in its favour.

What consolidation reliably produces, though, is a period of change for customers. Three things are worth watching over the next several renewal cycles:

Product rationalisation. When one owner holds overlapping products, some get invested in and some get maintained. Ask directly which category your product is in, and ask for it in writing.

Pricing normalisation. Acquired product lines tend to migrate toward the acquirer’s pricing structure over time. If your renewal is more than a year out, that is worth modelling now rather than discovering later.

Support continuity. Fed Reporter’s appeal for community institutions has always been that you can reach a person who knows the 5300. That is a property of a team, not a platform, and it is the thing most worth asking about specifically.

The context underneath all of this

The number of federally insured credit unions fell from 4,411 in Q1 2025 to 4,250 in Q1 2026. Roughly 160 institutions disappeared in a year, and the decline is concentrated among smaller credit unions. Vendors are consolidating in part because their customer base is.

None of that is an argument for or against any particular vendor. It is an argument for knowing who owns your filing software, what their roadmap for it is, and what your exit would look like if the answer stops working for you. Those are reasonable questions to ask any vendor, including us.

Sources: Wolters Kluwer investor communications on the FRR divestiture and its completion; Regnology press releases on the Moody’s and Fed Reporter transactions; FedReporter.net company history; NCUA quarterly credit union system performance data for Q1 2025 and Q1 2026. The Fed Reporter transaction was pending regulatory approval at the time of writing.

Watch: Conversation Assurance, End to End in Under Five Minutes

A walkthrough of Conversation Assurance running in production — every member conversation in the archive scored against the rule it implicates, not a two-percent sample. Filmed against the live product, with real data and three different seats: the compliance officer reviewing findings, the administrator who owns the run, and the risk officer. No slides, no mockups.

What the footage shows, in order: a completed run over 292 conversations with 6 flagged and 7 findings, the clean population listed alongside the exceptions; a finding opened to its citation and the passage of dialogue that triggered it; the administrator’s run console, where the archive is registered and the batch re-run; and the retention panel, where disposal runs on the clock each rule sets.

The seven rules carry citations to 12 CFR §1005.11 (Reg E error resolution), §1002.9 (Reg B adverse action), 12 USC §5531/§5536 with CFPB Bulletin 2013-07 (UDAAP), and NCUA Letter 15-CU-04 (consumer complaints) — each linked in the product to the regulator’s own text, so a finding can be traced rather than taken on trust.

The written version, including what the product deliberately does not do, is in Conversation Assurance Is Live.

Recorded 11 September 2026 against the production build. Figures shown are the seeded demonstration institution, not a customer. Informational only — not legal advice, and no substitute for your own counsel or your examiner’s guidance.

Conversation Assurance Is Live: We Stopped Sampling Member Conversations

Five days ago we described a compliance layer that would review every member conversation a credit union already records, score each one against the specific rule it implicates, and leave an evidence trail an examiner can walk. It is now running in production. This post is the part vendors usually skip: what actually shipped, what it does not do, and where you can check every claim in it yourself.

What a reviewer sees

A run reads the whole archive for a period and returns the population, not a shortlist. On the demo institution the most recent run shows 292 conversations scanned, 6 flagged, 7 findings — and the members whose conversations produced nothing are listed alongside the ones that did, scored and clean, which is the half that makes it a control. A sample tells you what a supervisor happened to listen to. A population tells you what is there.

Each finding carries the member, the conversation, the severity, when it occurred, and the passage of dialogue that triggered it — a capped excerpt, not the transcript. Per member, the roster also shows the dates the flags first and last occurred. Not a sentiment score. Not a quality rating out of five. The quote, and the obligation it engages.

Seven rules, each one citable

The scoring engine ships with seven rules. Every one of them carries a citation to the regulator’s own text and a link to it, because a finding a compliance officer cannot trace to a source is a finding they cannot defend:

Reg E error resolution — 12 CFR §1005.11(b). An oral assertion of error starts the clock. The engine flags where an agent appeared to condition the investigation on written confirmation, because §1005.11(b)(2) permits requiring writing but not delaying the investigation pending it. A second, informational rule marks the oral notice itself, so the 10- and 45-day clocks have a date to run from.

Reg B adverse action — 12 CFR §1002.9(a) and §1002.9(d). The engine flags adverse action communicated orally with no reference anywhere in the call to a written notice. Oral-only notification is available under §1002.9(d) solely to a creditor that did not receive more than 150 applications in the preceding calendar year, so for most credit unions the finding is a prompt to confirm the written notice went out within 30 days. Mention the letter on the call and the rule does not fire.

UDAAP — 12 USC §5531 and §5536, against CFPB Bulletin 2013-07 and the NCUA Federal Consumer Financial Protection Guide. Three rules, aimed at the patterns that draw examiner attention in collections and servicing contact.

Consumer complaints — NCUA Letter to Credit Unions 15-CU-04, which expects complaints to be documented with the actions taken and the trends evaluated. The engine flags member dissatisfaction consistent with a complaint so you can confirm a record exists for that contact.

The word on the screen is “candidate”

The live product says this in plain sight, above the results table: findings are candidates for disposition, not adjudicated violations — a transcript shows an obligation was triggered, not whether it was met. We put that sentence in the UI rather than a footnote on purpose.

An engine that told a credit union it had committed 6 violations would be wrong and would deserve to be disbelieved. The honest output is narrower and more useful: here are six conversations where a rule was engaged; a human decides what happened. That framing is also the one that survives an examiner asking how the tool reaches its conclusions.

A review cannot change the population it is reviewing

This is a control-design point and it is worth being explicit about. A reviewer records a disposition on a finding — that is their job. What a reviewer cannot do is re-run the batch and change which conversations are under review. Dispositioning a finding is a review act; regenerating the evidence underneath it is an administrative one, and they sit in different seats. The person reviewing findings cannot quietly re-run the population until the numbers look better.

Separation of duties is not a feature anyone asks for in a demo. It is the first thing that matters when the work is examined.

The transcripts you keep are the ones a rule told you to keep

Conversations are streamed from the credit union’s own storage and scored in place. Only conversations that produce a finding are retained — each one under the CFR section that flagged it — and the unflagged population is purged after processing. Retention runs on the clock the rule sets wherever the regulation sets one — two years for Reg E, twenty-five months for Reg B, three years for Reg F where a third-party collector is involved — and a three-year examination-cycle default for the UDAAP and complaint findings, where no federal period attaches to the recording itself. When a clock expires the transcript is destroyed and the finding is kept.

Disposal runs nightly, and there is a button to run it on demand, which exists for exactly one reason: so a credit union can demonstrate disposal to an examiner who asks rather than describe it.

Third-party contact, which is the harder half

The capability we cared most about is live: an archive owned by a third party — an outsourced collections agency, an overflow contact centre — registered as its own source, streamed from the location the vendor delivers to, and scored on the same seven rules as your own contact. You cannot pull a quality report out of a system you do not own, and a vendor’s internal QA programme is the vendor grading the vendor. Reading the transcripts they are already contractually obliged to produce is a different kind of evidence.

What is deliberately not here

No telephony. We are not replacing your contact platform and have no interest in being in that business. Your provider handles the conversation; we handle the evidence about it.

No vendor API dependency. The product reads an export from storage you control. It does not need Eltropy, Glia, Five9 or Talkdesk to build anything, approve anything or sign a partnership. That is a deliberate architectural choice, and it is why nothing here is blocked waiting on somebody else’s roadmap.

No agent scoring. Handle time, after-call work and coaching are real problems that belong to somebody else. The question here is narrower: would these conversations survive examination.

For compliance teams in California and Texas

Two states carry a particular version of this problem. State-chartered California credit unions operate under the DFPI’s consumer-complaint expectations alongside the federal baseline, and state-chartered Texas credit unions under the Texas Credit Union Department — while federally-chartered credit unions in both states answer to the NCUA directly — in both cases on top of the same CFPB and NCUA guidance every other credit union answers to. Neither adds a rule that changes the engineering. Both add an examiner who will ask how you know what is in your member conversations, and “a supervisor listens to a few a month” is a harder answer to give every year.

If you run compliance, risk or BSA at a credit union in either state, the useful first step is not a product decision. It is finding out what is sitting in ninety days of your own archive.

What we will not claim yet

One piece is built and under review but not yet in production, so it gets future tense: closing a finding will require two people in two seats — one to review and propose the closure, a second to approve it — enforced in the database rather than the interface. We are mentioning it because the discipline of this blog is that the shipped list and the roadmap list stay visibly different, and because the reason it is not live yet is that four rounds of review found eleven defects in the first three attempts at it. We would rather ship it late than describe it as done.

Sources: 12 CFR §1005.11 (Reg E error resolution); 12 CFR §1002.9 (Reg B notifications); 12 USC §5531, §5536 and CFPB Bulletin 2013-07 (UDAAP); NCUA Federal Consumer Financial Protection Guide; NCUA Letter to Credit Unions 15-CU-04 (consumer complaints); 12 CFR Part 1006 (Reg F). Capability statements describe functionality live in production as of 11 September 2026, except where explicitly marked as not yet shipped. Informational only — not legal advice, and no substitute for your own counsel or your examiner’s guidance.

Announcing Conversation Assurance: Examination-Grade Oversight for Every Member Contact

PinotPulse is building Conversation Assurance — a compliance oversight layer that reviews every member conversation your contact platform already records, scores it against the regulatory expectations that apply, and produces an evidence trail an examiner can walk. It rides on top of Eltropy, Glia, Five9, Talkdesk or your own archive, replaces nothing, and requires no migration.

The control that samples 2% and calls it coverage

Almost every piece of regulatory evidence a credit union produces is written down. Loan files, disclosures, board minutes, Call Report figures — all of it exists as a document somebody can hand an examiner. Member conversations are the exception. They are the highest-volume, highest-risk interactions in the institution, and they are the ones almost nobody can produce evidence about.

The standard control is sampling. A supervisor listens to a handful of calls a month, fills in a scorecard, and files it. At a credit union handling tens of thousands of member contacts a quarter, that is a low single-digit percentage reviewed by hand — and the sample is usually chosen by whoever had time that week, which is precisely the opposite of how a control is supposed to select its population.

Nobody thinks this is adequate. It persists because the alternative has been unavailable at credit union scale: the platforms built for this were designed for enterprise contact centres with hundreds of agents, and a credit union running twenty-five is not the customer they were built to serve.

What Conversation Assurance does

Reviews the whole population, not a sample. Every conversation, every period. The control’s coverage stops being a function of who had time.

Ties findings to the rule they implicate. Not a quality score out of five — a finding, attached to the specific expectation it engages, in language that survives being read by somebody outside your institution.

Surfaces patterns across members, not one call at a time. The complaint that matters is rarely a single call. It is the same issue recurring across twelve members in a quarter, which is invisible when the unit of review is one conversation.

Leaves a trail. What was reviewed, against what standard, on what date, with what disposition, and who dispositioned it. This is the part that turns an analysis into a control.

What it deliberately is not

Not a phone system. We are not replacing your contact centre and we do not want to be in the telephony business. Your provider handles the conversation; we handle the evidence about it. That boundary is why we can sit on top of whichever platform you already bought, rather than asking you to reconsider it.

Not an agent-productivity tool. Handle time, after-call work and QA coaching are real problems and they belong to somebody else. We are interested in the narrower question of whether your member conversations would survive examination.

Not conditional on vendor cooperation. This matters more than it sounds. Your recordings and transcripts already exist under your own retention practice. A layer that reads your archive does not need your telephony vendor to build anything, approve anything, or sign a partnership. Integrations are upside; nothing is blocked waiting for them.

Third-party contact is the harder half — and the one we are building for

Credit unions are expected to oversee the third parties acting on their behalf. Outsourced collections and overflow contact centres are among the hardest to oversee, for a structural reason rather than a diligence one: the credit union does not own the contact platform. You cannot pull a report from a system that is not yours, and the vendor’s own quality programme is the vendor grading the vendor.

A vendor-neutral layer reading the transcripts a third party is contractually obliged to produce changes that. Same control, applied to the population you have the least visibility into and the most exposure from. We are treating it as a first-class capability rather than a footnote, because we think it is the sharper half of the problem.

Why we are layering rather than replacing

The honest reason is that it is the better product, not merely the faster one to build. A credit union that has already chosen a contact platform is not shopping for a replacement, and a compliance vendor insisting on owning the telephony is asking for a rip-and-replace decision in order to solve an evidence problem. Layering means no migration, no new reliability exposure, and no argument with a system your team already knows.

It also means the contact platforms are a channel rather than an adversary. A provider whose credit union customers need an assurance story has a reason to point at us rather than to block us.

Where the depth has to come from

Detecting that a conversation implicates a rule is the easy half, and it will not remain a differentiator for long. The half that compounds is maintaining the rule — knowing when an interpretation moves, and being able to tell a credit union which of last quarter’s conversations would land differently under it, and which policy has not caught up.

That is a sustained regulatory-content operation, not a model feature. It is the part of this we are least willing to shortcut, it is genuinely hard, and we would rather say so plainly than imply the technology handles it unaided.

What happens next

Conversation Assurance is in active development and is not shipping today. We are starting where the evidence already sits: scoring archived conversations for a small number of credit unions under an evaluation agreement, and handing back what we find in their existing back catalogue. No integration, no migration, no pilot programme — the files, and an honest read of what is in them.

If you run compliance, risk or BSA at a credit union and want to know what is sitting in ninety days of your own archive, that is worth a conversation before it is ever a product decision.

Sources: 12 CFR Part 749 (records preservation); NCUA supervisory guidance on third-party relationships and consumer compliance. Statements about PinotPulse capability in this post are forward-looking and describe development in progress, not shipped functionality. Informational only — not legal advice, and no substitute for your own counsel or your examiner’s guidance.

Side-by-Side: PinotPulse vs. Wolters Kluwer ARC

Wolters Kluwer ARC is the most established regulatory filing platform in the U.S. credit union market. Most $1B+ credit unions run on it. The decision to evaluate a different platform is significant, and credit unions evaluating PinotPulse against ARC deserve a clear, honest side-by-side.

Where Wolters Kluwer ARC has the edge

Examiner familiarity at depth. ARC has been in the NCUA examiner toolkit for two decades. The output formats are recognized on sight. Examiners trained in the 2010s grew up with ARC's reports. That trust is real and it is earned.

The agency-relationship advantage. WK's product team has direct working relationships with NCUA, CFPB, and FinCEN that go back years. When a schema change is coming, WK often knows before the rest of the market does. For a $1.5B credit union that wants the earliest possible warning on regulatory change, that's worth paying for.

Depth on every individual surface. ARC plus Lumio plus TeamMate plus the OneSumX modules represents thousands of person-years of regulatory engineering. On any single filing — HMDA LAR cross-tie diagnostics, NCUA 5300 schedule-by-schedule edit checks, CECL pool-level loss-rate modeling — the WK depth is hard to match.

Where PinotPulse exceeds

Unified data layer. ARC, Lumio, TeamMate, and the OneSumX modules are separate products with separate data stores. A change in your member ledger appears in ARC immediately, in Lumio on a different cadence, in TeamMate when the audit team imports it. PinotPulse runs every module on one shared data layer. The number a BSA Officer sees on the BSA dashboard is the same number on the CTR detail screen and the same number in the audit log, because they read from the same source of truth.

One workflow shape across the whole portfolio. The PinotPulse workflow — data ingest, validation, preview, prepare, audit-evidence retention — runs identically across the compliance portfolio: 6 agency forms, 8 internal workpapers and a screening feed. A BSA Officer works a SAR through the same shape as the NCUA 5300 the Compliance Officer prepares. One pattern. One audit-trail format. Across ARC + Lumio + TeamMate + OneSumX, you learn four separate workflow patterns and four separate audit-trail formats.

Cost structure shaped for the mid-market. The full WK stack at a $750M credit union typically spans four to seven separate products. PinotPulse covers the same federal-filing surface area in a single platform, on one data layer and one audit trail. For a sub-$2B credit union, the consolidation math — in dollars and in staff hours — is straightforward.

Modern interaction design. Every PinotPulse screen is designed for the credit-union compliance officer using it — role-based dashboards, zero-click KPI views, field labels that match the agency-published forms. The look-and-feel and interaction patterns are 2026, not 2008.

The honest call

If your credit union has the budget for the full WK stack, the integration team to operate it, the audit committee mandate that locks TeamMate in place, and an examiner relationship deeply built around WK outputs — ARC is a sensible choice. WK has earned that position.

If your credit union is sub-$2B in assets, fighting the cost or the fragmentation of a four-to-seven-product stack, or evaluating at vendor-renewal time when the auto-renew clause gives you the window to make a change — PinotPulse covers the same federal-filing surface area in a unified platform at a fraction of the bundled cost. The trade is depth on individual specialist surfaces (TeamMate-grade workpapers, Tandem-grade GLBA templates) versus unified breadth on the surfaces that matter most to mid-market credit unions.

The right answer is institution-specific. We'll walk through the comparison with your team honestly — including the surfaces where WK is the better choice for your situation.

Beyond Verafin and Abrigo: Integrated BSA/AML for the Mid-Market

Verafin (now part of Nasdaq) and Abrigo are the two dominant specialist platforms for BSA/AML transaction monitoring in the credit-union and community-bank market. Both are excellent products. For credit unions evaluating where to invest in BSA/AML capability, the question is whether the additional depth of a specialist tool justifies a separate vendor relationship.

What the specialists do that we don't try to match at depth

Verafin's behavioral analytics. Twenty-plus years of behavioral-model refinement, a consortium-based threat-intelligence network that no smaller vendor can replicate, and a case-management workflow shaped by working with hundreds of institutions in remediation. For a credit union under active enforcement or with a material BSA finding to remediate, Verafin's depth pays for itself.

Abrigo's BSA platform. A direct Verafin competitor with strong product integration into the Abrigo Sageworks CECL platform. For an institution already standardized on the Abrigo footprint, the unified Abrigo experience matters.

What PinotPulse delivers in BSA/AML

Multi-day sliding-window structuring detection. OFAC SDN screening with daily list refresh and publisher-certificate validation against supply-chain tampering. SAR and CTR XML drafting in full FinCEN BSA E-Filing format. CIP and EDD evidence packages tied to the §314(a) information-request workflow. DOEP (Form 110) and IRS Form 8300 generation. Four-pillar annual BSA Compliance Program review artifact. Every action writes to a tamper-evident audit log with the regulatory citation attached.

For a $500M–$2B credit union without active enforcement issues, this depth is operationally sufficient. It is not the deepest behavioral-analytics platform on the market. It is, however, integrated with the rest of the compliance workflow — the SAR a BSA Officer drafts pulls member-data context from the same data layer that the Compliance Officer uses for the NCUA 5300, the OFAC alert that fires this morning shows up on the same audit log that the examiner will request next quarter.

Where the integrated approach exceeds specialist depth

Member-360 context at the SAR-drafting moment. The PinotPulse BSA workflow shows the BSA Officer everything the platform knows about a member — recent lending activity, deposit patterns, CIP documentation status, prior alerts — on the same screen as the SAR narrative. In a specialist platform, that context lives in the core or in another vendor's tool. The BSA Officer either tabs between systems or works without the context.

Cross-filing audit-trail integrity. When an examiner asks "show me the trail from this SAR back to the underlying transactions, the CIP documentation, and the prior OFAC screening events" — in PinotPulse, that's a single audit-log query. Across a specialist BSA monitor and a separate core integration, that's a multi-system reconciliation exercise.

Cost integration. Verafin and Abrigo at the credit-union scale are a meaningful standalone line item for a sub-$2B CU. PinotPulse covers BSA/AML alongside the other major federal filings in one unified platform. For a credit union doing the math at vendor-renewal time, the bundled value — fewer contracts, one integrated data layer — is real.

The honest call

If your credit union is in active BSA remediation, has a recent enforcement action, or operates with the kind of risk profile that requires the deepest possible behavioral analytics — keep Verafin or Abrigo. Their depth is hard to replicate and the cost is defensible in your context.

If your credit union is at a quieter risk profile and considering whether to maintain a separate specialist BSA platform or consolidate into a unified compliance platform — the integrated PinotPulse approach often wins on the bundled cost, the workflow integration, and the cross-filing audit-trail integrity. We'll work through the trade-offs with your BSA Officer specifically.

The Examiner-Defendability Test: How Modern Platforms Compare

Every compliance platform claims to be "audit-ready." Few are tested against the actual examiner workflow — the moment when an NCUA examiner sits down next to the compliance officer and asks "walk me through this filing." Here is how the major platforms compare on the dimensions that actually matter when the examiner is in the room.

The five tests

1. Can the examiner follow the data lineage end-to-end? From the member transaction in the core through the GL mapping into the filing into the regulator-submitted artifact. PinotPulse runs one unified data layer; the lineage is a single audit-log trace. Across a specialist stack — WK ARC plus Lumio plus TeamMate plus a separate BSA monitor — the lineage crosses four products and four data stores. The compliance officer becomes the integration layer in the examiner's room.

2. Do the field labels match the agency-published forms? NCUA AIRES specification, CFPB HMDA Filing Instructions Guide, FinCEN BSA-XML schema. PinotPulse uses the agency-canonical field labels throughout the platform — the examiner sees familiar terminology on the screen. Older legacy platforms occasionally translate field names into vendor-internal labels that don't match what the examiner expects to see. Small thing, but it costs trust at the desk.

3. Is the audit trail tamper-evident? PinotPulse writes every regulatory action to a tamper-evident audit log aligned with SOC 2 Trust Services criteria. The same is true of mature specialist platforms. Newer entrants in the market sometimes ship audit logs that are application-database rows — in theory mutable, in practice indistinguishable from the operational data. Examiners notice the difference.

4. Does the regulator confirmation number sit in the audit log? A filing isn't done when the submit button is pressed; it's done when the regulator returns a confirmation number. A complete workflow should capture the agency-issued confirmation number in the audit log next to the submission record, so an examiner can verify acceptance rather than just transmission. PinotPulse builds that audit trail today and is designed to record the agency confirmation as direct submission comes online. Older portal-upload workflows often record only "PDF generated" and rely on the compliance officer to manually paste the regulator's confirmation back into a tracker. The latter is a documented evidence gap under CFR §1020.320.

5. Can a complete workpaper packet be exported in one click? When the examiner asks "send me everything you have on this SAR," the compliance officer should be able to export a single, complete workpaper packet — the source data, the validation results and the audit timeline in one place. PinotPulse assembles that packet for you. Across a multi-vendor stack, the compliance officer assembles the packet from three or four products manually — and assembly mistakes become examiner findings.

Where the established players still have an edge

Examiner familiarity built over twenty years is real. Wolters Kluwer ARC outputs are recognized on sight by every NCUA examiner trained in the last two decades. FedReporter SmartCall has seventeen years of similar history at the sub-$500M tier. A new platform cannot claim that familiarity. What a new platform can do is build the artifacts that let an examiner inspect the methodology directly — reconciliation reports against agency canonical edit codes, methodology documentation tied to specific CFR sections, examiner-handoff workpaper packets that show every input, every validation, every output.

PinotPulse ships these artifacts. We don't ask examiners to trust the platform; we give them the tools to verify it.

The bottom line

On the dimensions that matter when the examiner is actually in the room — data lineage, field-label fidelity, tamper-evidence, audit-trail completeness, and workpaper packaging — a modern unified platform like PinotPulse is built for that moment. Specialist platforms cover their lane well, but the multi-vendor stack pushes the integration burden onto the compliance officer in the worst possible moment: when the examiner is sitting next to them asking questions.

If you'd like to walk through a sample examiner-handoff packet from PinotPulse, we're happy to share one with your team.

The Modern State of Credit Union Compliance in 2026

The credit union compliance vendor ecosystem in 2026 is mature, fragmented, and more capable than it has ever been. Each major regulatory surface has at least one, often three or four, specialist platforms that have spent decades getting very good at their slice. The landscape looks roughly like this.

Filings. Wolters Kluwer ARC and Acuity dominate at the top of the market. FedReporter SmartCall has held the sub-$500M NCUA 5300 niche for nearly two decades and was acquired into Jack Henry’s Regulatory Filing Group in 2017, then re-stitched into FIS’s portfolio in 2023. Both are excellent at what they do.

CECL. Wolters Kluwer Lumio competes with Abrigo Sageworks for the credit-loss-modeling buyer. Both have deep loss-rate methodology, integrate with the major core systems, and have years of examiner sign-off behind them. For credit unions over $500M with material loan portfolios, either is a defensible choice.

Audit and workpapers. Wolters Kluwer TeamMate is the de facto standard for internal-audit functions at $1B+ credit unions, with an installed base that goes back through PricewaterhouseCoopers and Cintas. Workiva competes for the SOX-influenced buyer. Neither is a fit for a $200M CU’s budget; both are excellent for their intended buyer.

Information Security Plans. Tandem and SafeSystems have built deep, examiner-recognized GLBA programs over the past decade. If a CU is in remediation following a §748 finding, the depth of either of those products is hard to match.

BSA / AML monitoring. Verafin (now part of Nasdaq) and Abrigo are the dominant transaction-surveillance platforms in the credit-union and community-bank market. Both are deeply capable; Verafin in particular has set the standard for behavioral analytics in BSA monitoring.

Reg-change tracking. Continuity (Mitratech) competes with Wolters Kluwer’s OneSumX Reg Manager and CCH ASAP. All three serve the “something just changed in the CFR — what does it mean for us?” question well.

Peer benchmarking. Callahan & Associates owns the credit-union peer-data niche. The free FedReporter Performance Reports give every CU access to NCUA peer-universe ratios.

Each of these platforms is the right answer for some segment of the market. None of them, individually, is the right answer for the question “how does a $500M–$2B credit union cover its full regulatory obligation in one place at a price its budget can absorb?” That’s the gap PinotPulse exists to fill — not by competing with the specialists at their depth, but by offering a unified platform shaped around the mid-market institution that wants one partner instead of seven.

Why We're Looking for Design Partners (Not Just Customers)

PinotPulse is in the design-partner phase of company building. We are looking for ten to fifteen credit unions to work with us in a structured, time-boxed way before we open up general availability. This is a deliberate choice and a slower path than running a paid pilot. Here’s what design partnership means at PinotPulse and why we think it matters for your institution as well as ours.

What we commit to a design partner

You get the platform at a heavily reduced price, or no charge during the partnership window. You get the founder on a regular cadence — weekly or bi-weekly — not a customer-success tier. You get to influence the roadmap directly. The next module we build, the next regulatory area we deepen, the next core-system connector we ship — if it matters to your institution, it goes to the top of the queue. You get our reconciliation reports against the canonical NCUA edit codes so your examiner has a defensible artifact to inspect.

What we ask of a design partner

Honest feedback, even when it stings. Willingness to walk through your real data with us, not synthetic test data. A path to becoming a reference customer once the platform meets your bar. And a commitment to participate in the trust-building artifacts — case studies, examiner letters, reference calls — that other credit unions need before they switch.

Why the structured commitment matters

Compliance software earns trust the slow way: a quarter of validation against a real filing, an examiner cycle that goes well, a board meeting where the CAMEL trends are clear because the data was current. Twelve months of design partnership compresses that timeline into a structured engagement. We want partners who treat this as a co-build, not a free trial.

If your credit union is between $100M and $2B in assets, evaluating its compliance stack at vendor-renewal time, and willing to be the institution that helps shape the platform you wish existed — we should talk.

The design-partner cohort is where the next decade of credit union compliance software gets built. We’d like you in it.

The True Cost of the Stitched Compliance Stack

Most credit unions know they have a multi-vendor problem. Few have stopped to add up what it actually costs them in dollars. Here is the math for a typical $750M credit union.

Wolters Kluwer ARC for NCUA 5300 + HMDA + BSA SAR/CTR submissions: $80,000 to $100,000 per year, depending on modules and seat count.

Wolters Kluwer Lumio or Abrigo Sageworks for CECL/ALLL: $40,000 to $60,000 per year.

Wolters Kluwer TeamMate or Workiva for internal audit and workpapers: $40,000 to $70,000 per year.

Tandem or SafeSystems for the GLBA Information Security Plan, Business Continuity Plan, and vendor-management workflows: $25,000 to $40,000 per year.

Continuity (Mitratech) for reg-change tracking: $12,000 to $20,000 per year.

Verafin or Abrigo for BSA/AML transaction monitoring: $50,000 to $80,000 per year.

Callahan & Associates + free FedReporter for peer benchmarks and CAMEL self-assessment: $5,000 to $15,000 per year.

Total annual software cost: $252,000 to $385,000.

The cost that doesn’t show up in the budget

That number is real, but it’s only the line-item cost. The hidden cost is integration overhead. The compliance officer at this $750M CU spends roughly 80 hours per quarter copying data between systems, reconciling exports, and rebuilding board packages from seven different sources. At a fully-loaded compensation rate, that’s another $60,000 of annual expense. Total real cost: about $312,000 to $445,000 per year.

What a unified platform changes

PinotPulse Complete, at $66,000 per year, covers most of the surfaces above — filings, CECL, BSA/AML monitoring, reg-change tracking, and peer benchmarks — in one platform sharing a single data layer. It does not replace TeamMate at workpaper depth or Tandem at full GLBA template depth. For most $500M–$2B credit unions, what gets replaced is the seven-vendor sprawl plus the spreadsheet integration tax. The math, for those institutions, is straightforward.

The specialists are excellent. They are also priced for credit unions whose budgets can absorb a quarter-million-dollar compliance line. PinotPulse is for everyone else.

Where Wolters Kluwer Excels — and Where Mid-Market CUs Should Think About It

Wolters Kluwer is the most successful regulatory technology company in the financial-services market, and the breadth and depth of their compliance portfolio is genuinely impressive. Before any conversation about alternatives, it is worth being precise about what WK actually does well.

Where WK is excellent

WK ARC and Acuity have a 20-year history with the NCUA examiner community. The edit-check library is deep, the audit trail is regulator-grade, and the relationships between WK’s product team and the agencies are close enough that early access to schema changes is real. For credit unions over $1 billion in assets, with five or more compliance staff and an integration team that can connect ARC to the core, ARC is a sensible choice.

WK Lumio is one of two serious products for CECL/ALLL modeling at the credit-union scale. The methodology is examiner-defended, the methodology documentation is comprehensive, and the segment-level loss-rate models stand up to scrutiny.

WK TeamMate is the de facto standard for internal audit workpaper management. Audit committees frequently mandate it. If your CU’s audit committee has standardized on TeamMate, you should keep it — it is excellent at what it does, and replacing it is rarely worth the disruption.

WK OneSumX covers vendor management, business continuity, and regulatory-change tracking with separate modules. Each one is competent. Together, they form the backbone of the integrated WK compliance vision.

WK CCH ASAP is a research subscription, not a compliance system. It answers “what does this rule mean?” well. Plenty of CUs license it for the legal team alongside the operational compliance stack.

Where mid-market CUs should think hard

The challenge with WK at a $500M–$2B credit union is not quality. It’s shape. To get full regulatory coverage from WK, a CU licenses six to seven separate products that don’t share a data layer. Each one has its own login, its own renewal cycle, its own implementation engagement, and its own integration tax. The all-in annual cost lands between $210,000 and $670,000, depending on the bundle. That’s defensible at $1B+. It’s painful at $200M–$500M.

The other consideration is renewal pricing. WK is a public, growth-oriented company; renewal increases of 15–30 percent year-over-year are not unusual at the credit-union tier, and the contract structure is generally a five-year auto-renew. The CFO has a sixty-day window each five years to evaluate alternatives.

Our position

If your CU has the budget, the integration team, and the audit-committee mandate to run the WK stack, WK is the right answer. We are not trying to displace it at $1B+ institutions where the integration overhead is already absorbed. PinotPulse exists for the credit unions where the math doesn’t work — where the WK bundle is too expensive, too fragmented, and too shaped for someone larger than they are. For those institutions, a unified mid-market platform is the better fit.

Tandem and the GLBA Information Security Plan: A Specialist's Strength

Tandem is the credit-union industry’s answer to the GLBA Information Security Plan question, and it has been for over a decade. Built by the team behind CoNetrix Technology, Tandem grew up alongside the FFIEC Information Security Booklet and the §748 amendments. The depth of the product reflects that lineage.

What Tandem does very well

Tandem ships full GLBA Information Security Plan templates, not just frameworks. It walks an information security officer through risk assessment, control documentation, third-party due diligence, and incident response with structure that examiners recognize on sight. The vendor-management workflow, the BCP plan tooling, and the cybersecurity-incident response templates all benefit from being designed by people who have spent careers in this domain.

For a credit union under regulatory scrutiny — a §748 cybersecurity incident notification finding, a GLBA gap surfaced in the last exam, a BCP test that didn’t go well — Tandem is the right tool to remediate quickly. The depth is real and the examiner familiarity is established.

Where PinotPulse fits alongside

Most $500M–$2B credit unions don’t need the deepest possible GLBA template tooling. They need a compliance program, an incident-response playbook, a vendor-risk register, and a documentation trail that ties to the regulatory citations. PinotPulse covers that framework foundation: GLBA program documentation, vendor-risk register, incident-response logging tied to §748, and the audit trail that an examiner will want to see.

If your CU has been in remediation after a finding, or your auditor wants the maximum-depth ISP toolkit available, keep Tandem. We don’t replace it. PinotPulse covers the foundation; Tandem covers the depth. The two work in different layers and a credit union that values both can run them in parallel.

The honest call

Tandem is excellent at what it does. The question for a mid-market CU is whether the marginal value of full template depth justifies the additional vendor relationship, integration, and annual cost. For some CUs, the answer is yes. For others — particularly newly-chartered institutions or CUs without active findings — the framework foundation that comes with the unified PinotPulse platform is sufficient and saves the additional $25,000 to $40,000 per year.

The choice is yours and the answer is institution-specific. We’ll tell you honestly which way the math goes for your situation.

Verafin, Abrigo, and the BSA/AML Decision for Mid-Market CUs

Verafin (now part of Nasdaq following the 2021 acquisition) and Abrigo are the two heavyweight specialist platforms for BSA/AML transaction monitoring in the credit union and community bank market. Both are excellent. The decision a $500M–$2B credit union has to make is whether the depth of either justifies the specialist relationship versus integrated BSA monitoring inside a unified compliance platform.

What Verafin does very well

Verafin’s behavioral analytics models for transaction surveillance are widely recognized as the most sophisticated in the credit-union market. The case-management workflow is deep, the SAR narrative drafting tools have been refined over twenty years, and the consortium-based threat intelligence (the network effect of every Verafin customer feeding the same threat database) is a real differentiator that smaller platforms genuinely can’t replicate.

For credit unions in remediation after BSA findings, with material risk exposures, or with regulator scrutiny following an enforcement action — Verafin is the right tool. The depth pays for itself in those situations.

What Abrigo does very well

Abrigo’s BSA/AML platform is the closest direct competitor to Verafin and a very capable system in its own right. Particularly strong for institutions that already use Abrigo Sageworks for CECL and want a unified Abrigo footprint.

Where PinotPulse fits

Most mid-market credit unions don’t have the risk profile that requires the deepest possible behavioral analytics. They need solid structuring detection, OFAC screening tied to the SDN list, currency-transaction-report drafting and filing, and SAR narrative scaffolding with the right field validations. They need it to integrate with the rest of their compliance work — not sit in its own silo with its own data layer and its own renewal cycle.

PinotPulse covers BSA/AML at this level. Structuring detection with multi-day sliding windows, OFAC screening with daily SDN refresh, SAR/CTR XML drafting, and a complete audit trail tied to the same data layer as your filings and CAMEL. For a CU under $2B in assets without active enforcement issues, this depth is operationally sufficient.

If you have a Verafin or Abrigo deployment that’s working and the budget supports it, keep it. If you’re building a compliance stack from a clean sheet or evaluating at vendor-renewal time, PinotPulse’s integrated BSA monitoring covers the surface area at a fraction of the all-in specialist cost.

Your Core System Stays Where It Is: Symitar, Episys, DNA, and Q2

One of the most important things a compliance software vendor can be honest about is what stays with the core banking system. Symitar (Jack Henry), Episys (Jack Henry), DNA (Fiserv), Corelation KeyStone, and Q2 are the systems where member-facing operational regulations actually run. PinotPulse does not try to replace any of them, and we are explicit about which surfaces stay with the core.

What the core does and PinotPulse does not

Reg DD APY calculations at deposit opening. When a member opens a savings or certificate account, the APY disclosure is calculated by the core in real time using the deposit terms, the rate table, and the compounding method. That’s a deposit-system feature, not a compliance-software feature. PinotPulse never sees that interaction.

Reg CC funds availability decisioning at the teller line. When a member deposits a check, the funds-availability hold is decided by the core based on the deposit type, the account history, the check size, and the institution’s policy. The teller sees the answer at the window. PinotPulse doesn’t compete in that workflow.

Real-time OFAC screening at account opening. When a new member fills out a CIP form, the core or its integrated KYC vendor screens the name against the SDN list before the account number is generated. PinotPulse screens transactions, not signups; the core handles the live signup screen.

Reg E daily-operations decisioning. Card-present authorizations, ACH return windows, and the per-transaction error-resolution mechanics all run inside the core or its integrated payments platform. PinotPulse handles the regulatory documentation, dispute case management, and reporting layer that sits on top — not the live transaction decision.

Where the line is

The clean rule of thumb: if the regulatory action happens in real time at the moment of a member transaction, that’s core territory. If the regulatory action happens on a batch basis, with documentation, audit trail, and submission to a regulator, that’s compliance-platform territory.

This line matters because credit unions sometimes get pitched a compliance platform that promises to displace pieces of the core. Be skeptical of that pitch. The core systems do their job extraordinarily well. The right relationship between a compliance platform and a core is partnership, not displacement. PinotPulse ships with pre-built connectors for the major cores precisely because we expect the core to keep doing what it does best.

Examiner Familiarity Across the Compliance Vendor Landscape

One of the most underrated dimensions in compliance software selection is examiner familiarity. NCUA examiners walk into a credit union exam with a mental model shaped by twenty years of looking at the same product outputs. When the AIRES extract comes from Wolters Kluwer ARC, the examiner recognizes the format, knows where the cross-tie diagnostics live, and trusts the tooling because it has been in the market longer than most of their careers.

This is real. It’s not a marketing artifact, and it’s not something a new platform can claim by asserting it. Familiarity has to be built, and it has to be built deliberately.

How the established vendors got there

Wolters Kluwer ARC has 20+ years with the NCUA. Successive versions have been reviewed by the agency, the AIRES output format is co-evolved with the regulator’s import tooling, and successive examiners have been trained on its quirks. FedReporter SmartCall has 17+ years of similar history, particularly in the sub-$500M segment. CCH ASAP carries the WK halo. TeamMate has been in audit committees since the late 1990s. The familiarity is real and it is earned.

How a new platform earns it

A platform that ships in 2026 cannot pretend to twenty years of examiner relationships. What it can do is build an artifact that lets the examiner inspect the platform’s validation library against the regulator’s canonical edit codes, line by line. That’s the reconciliation report. We publish ours. An examiner can request the report, walk through the rules our platform implements versus the rules NCUA publishes in its quarterly edit-code release, and form their own judgment.

The other artifact is examiner-defendable methodology documentation. For each schedule, each cross-field rule, each calculation, where does it come from? Which CFR section, which AIRES specification, which NCUA technical advisory? That documentation lives in the platform and is exportable. It’s how an examiner builds a mental model of a new tool in real time.

The practical advice

If your CU is mid-cycle on an exam relationship with a deep history in WK or FedReporter outputs, switching mid-cycle is a cost you should weigh carefully. There’s nothing wrong with running the existing tool through the next exam and switching at vendor renewal, when the calendar gives you space. If you’re between exam cycles, or your last exam exposed integration friction the existing tools created, the transition is easier.

Either way, the right move is to engage early with your examiner about the platform change. NCUA examiners have, in our experience, been receptive to platforms that show up with the reconciliation artifacts and the methodology documentation in hand. They want to do their job well. A platform that helps them do that is not a problem.

Focus on Your Members: What Quarterly Compliance Confidence Frees Up

Talk to a credit union compliance officer about how they spend their week and the answer comes back in chunks of fire-fighting. Two weeks every quarter on the NCUA 5300. A month every fall on the HMDA LAR. Continuous interruption from BSA case work. Spreadsheet reconciliation between the core, the filing platform, the CECL model, and the audit-trail system. The board package on the third Tuesday of every month, rebuilt from seven sources.

What gets squeezed out: member experience. Risk-strategy work. Fraud-pattern review. The cross-functional time with lending, retail, and IT that builds an institution’s safety culture. The conversations with branch managers about what members are actually struggling with. The mission work that drew most credit-union compliance officers into this profession in the first place.

The reframe

Compliance is necessary. It is also not the credit union’s mission. The mission is members. Compliance exists because members’ deposits need to be safe, members’ lending decisions need to be fair, and members’ data needs to be protected. Done well, the compliance function is a quiet partner to the institution’s ability to serve members well. Done badly, it consumes the time and energy that should be flowing to members.

A modern compliance platform’s job is to free up that time. Not by removing the obligation — the obligation is regulatory and absolute — but by making the obligation cost less of the team’s attention. Continuous CAMEL visibility instead of a quarterly fire drill. Pre-submission validation that surfaces issues at the desk instead of three days after filing. A unified data layer that means the board package builds itself from the same data the regulator sees. An audit trail that’s a byproduct of normal work, not a deliverable assembled the week before the exam.

What confidence enables

The credit unions that get this right report something that surprises their boards: their compliance officers spend their afternoons on member-experience meetings, fraud-trend reviews, and lending-strategy partnerships. The morning was the regulatory work, and it took an hour because the platform did most of it. The rest of the day was the work that actually moves the institution forward.

That’s the partnership we’re building. Not a tool that does compliance for you; a partner that handles enough of the regulatory weight that your team can spend the rest of their day on the institution’s actual mission.

From Quarterly Scramble to Quarterly Confidence: A Practical 90-Day Roadmap

Most credit unions assume migrating to a new compliance platform is a six-to-twelve month project. For PinotPulse, the practical timeline is closer to ninety days from the day a contract signs to the day the team is filing the next NCUA 5300 with confidence on the new platform. Here’s how we structure it.

Days 1–14: Connect the core

The first deliverable is a working data connection. Pre-built connectors for Symitar, Episys, DNA, KeyStone, and Q2 mean the integration is configuration, not custom development. By day 14, your data is flowing into PinotPulse on the live cadence and the audit trail of the import is auditable end-to-end.

Days 15–30: Validate one full filing

The team picks the next NCUA 5300 cycle and runs it through PinotPulse in parallel with whatever they’re using today. Same source data, same filing window, two outputs. The reconciliation between the two is the trust-building exercise. The differences either tie out (good) or surface issues that get explained (also good). By the end of this window, the team has a baseline confidence in the platform’s output.

Days 31–60: Bring the next module live

Once the filing module is trusted, the next surface comes online. For most CUs that’s HMDA. For some it’s BSA monitoring, or CECL, or CAMEL. The pattern repeats: parallel run, reconciliation, sign-off. Each module added compounds the platform’s value because it shares a data layer with the modules already trusted.

Days 61–90: Train the team and retire the old workflows

By day 60 the platform is doing real work. The remaining month is about retiring spreadsheets, documenting the new workflows, training the people who haven’t been hands-on in the parallel runs, and getting the board comfortable with the new dashboards. By day 90 the team has filed at least one cycle on PinotPulse with no parallel safety net — and the next cycle starts with a platform that already has a quarter of trusted output behind it.

What the design partnership adds

Through the design-partner phase, the founder is on a weekly cadence with your team for the full ninety days. Issues that surface get addressed inside the same week, not in a quarterly release cycle. The roadmap input is direct. By day 90, your CU is on a platform that has been shaped, in part, by the realities of your operation — and your relationship with us is the kind of vendor relationship that compliance officers describe as “a partner,” not as “another login.”

Ninety days is achievable. We’ve laid out the structure and we walk every design partner through it together.

The Modern Middle: Why Sub-$2B Credit Unions Are the Most Underserved Segment in Regtech

The U.S. credit union market has a coverage gap. The top of the market — CUs over $1B in assets — runs on Wolters Kluwer, CCH, or another legacy compliance suite. The bottom of the market — CUs under $50M — runs on spreadsheets and free regulator portals. Every credit union in the middle is paying too much for tools that don’t fit, or burning their compliance team’s hours on manual processes that scale poorly.

Wolters Kluwer ARC is a fine product if you have a $1.2 billion balance sheet and a five-person compliance team. At $50,000 to $200,000 per year, with a five-year contract that auto-renews, it’s built for a buyer that has both the budget and the institutional muscle to make a decade-long decision. FedReporter SmartCall does NCUA 5300 well and only NCUA 5300 — if HMDA, BSA, and CAMEL each need their own vendor, you’re reassembling the same fragmented stack the legacy suite was built to consolidate. Continuity tracks regulatory changes but doesn’t file anything. The mid-market CU ends up choosing between a Cadillac, a unicycle, and a binoculars.

The opening for a modern, multi-regulator platform priced for the $100M–$2B credit union has been there for years. The legacy vendors haven’t closed it because their cost structure doesn’t allow it. We were built specifically to close it.

The trigger for switching, almost always, is the vendor renewal. The Wolters Kluwer contract comes up. The price went up 30 percent. The CFO asks finance: “What else is out there?” And until recently, the honest answer was “not much that fits a CU your size.” That’s changing. Modern multi-regulator coverage at sub-$1B-CU pricing is now a real choice on the table — and the renewal cycle is when CUs make it.

Why Your Compliance Team Is Stuck in a Quarterly Scramble — and How to End It

There’s a pattern that plays out in credit unions of every size, every quarter: the weeks before the NCUA 5300 deadline become a sprint. GL exports. Manual mapping. Spreadsheet reconciliation. A race to catch edit check errors before they become CUOnline rejections. Then it’s over — until next quarter, when it starts again.

This isn’t a staffing problem. It isn’t a training problem. It’s a tools problem. The NCUA filing process involves a long list of published edit checks across every schedule. Legacy tools validate only after submission, meaning every error surfaces as a post-submission rework cycle.

The labor cost of quarterly manual compliance workflows compounds across rework cycles, resubmission delays, and the opportunity cost of compliance staff time.

Automated validation checks, automatic GL mapping, and pre-submission simulation are designed to surface issues earlier in the workflow, reducing the rework cycles that follow post-submission error discovery.

Before the Examiner Arrives: The Case for Continuous Exam Readiness

NCUA examinations are not audits you prepare for. They’re assessments of how you’ve been operating all year. But most credit unions treat examination preparation as a sprint — a sudden burst of documentation gathering, evidence packaging, and CAMEL analysis that happens only when the exam is scheduled.

The problem: by the time the examiner is scheduled, your CAMEL trajectory has already been set. A 12-month net worth trend that’s been drifting toward the undercapitalized threshold can’t be reversed in four weeks. A concentration risk that’s been building in your loan portfolio can’t be recharacterized on the eve of an exam.

Institutions that maintain visibility into their CAMEL posture throughout the year are better positioned to identify and address emerging issues before the examination cycle begins.

Continuous CAMEL monitoring gives compliance teams visibility into regulatory posture throughout the year, not just when an examination is scheduled.

The 8-Vendor Problem: Why Compliance Fragmentation Is Costing Your CU More Than You Think

Ask any credit union compliance officer how many vendor contracts touch their regulatory workflow. The answer is almost never fewer than five. Often it’s eight. One for NCUA call reports. One for BSA/AML transaction monitoring. One for HMDA. One for CRA. A data warehouse for analytics. A fraud detection tool. A GRC platform for policy management. An examinations prep tool.

Each contract has its own renewal cycle. Each has its own data import process. Each has its own user interface, its own support team, its own data model. And none of them talk to each other. The compliance officer sits at the intersection of all of them, manually reconciling numbers between systems that were never designed to work together.

The direct cost — $80K to $200K per year across the typical vendor stack — is only part of the problem. The hidden cost is the integration tax: the hours every quarter spent re-importing the same data into different tools, resolving discrepancies between systems that use different GL code mappings, and explaining to your board why your NCUA filing numbers don’t match your internal analytics dashboard.

One integrated platform eliminates the integration tax entirely. When every workflow runs on the same data model, the numbers reconcile automatically. When every module shares the same audit trail, examination documentation packages itself. When your compliance team stops being the integration layer, they can do the work they were actually hired to do.

How Many Vendors Does Your Compliance Stack Have?

See how PinotPulse replaces them all in a 30-minute demo with your own data.

Request a Demo →

Know Your CAMEL Rating Before Your Examiner Does

The CAMEL rating is the single most consequential number in a credit union’s regulatory life. A composite 1 or 2 means routine supervision. A 3 triggers increased examination frequency. A 4 or 5 brings formal enforcement actions, capital requirements, and board-level scrutiny. Yet most credit unions recalculate their CAMEL posture once per year, when the NCUA does it for them.

Continuous CAMEL monitoring changes the strategic picture entirely. When you know your Capital Adequacy trend before your examiner does, you have runway to act. When your Liquidity component shows stress against peer benchmarks, you can adjust asset-liability positioning before it becomes an examination finding. When your Earnings trajectory shows deterioration, you can have the management conversation in the boardroom — not in the examination room.

The credit unions that consistently maintain strong CAMEL ratings aren’t necessarily the ones with the best underlying fundamentals. They’re the ones that know their numbers continuously, benchmark against their peers honestly, and act on what they see before it becomes a problem.

The Future of Credit Union Compliance: Automated, Integrated, and Always On

The regulatory environment facing U.S. credit unions is only getting more complex. AMLA 2020 is driving increased BSA/AML examination scrutiny. Fair lending enforcement is intensifying. The NCUA’s data-driven examination approach means examiners arrive with your numbers already analyzed. The credit unions that thrive in this environment will be the ones whose compliance function is a source of strategic intelligence — not a quarterly fire drill.

Institutions still relying on disconnected point solutions and post-submission error correction face growing friction as regulatory complexity increases. The tools built for earlier compliance environments create manual overhead that compounds each quarter.

The direction is toward integrated, automated compliance workflows that surface issues earlier in the process and reduce the manual coordination typical of multi-vendor stacks.

Ready to See the Future of Compliance?

30-minute demo. Your own data. No commitment required.

Request a Demo →