Colorado credit unions should treat the new ASSET Act as a case-management workflow, not simply another fraud alert. A qualified employee’s reasonable belief can trigger a mandatory agency report. A separate decision to delay a disbursement activates written-notice, reporting, investigation and release-or-refuse controls that must remain traceable for as long as 180 days.
The Adults’ Security and Safeguards from Exploitation in Transactions Act, or ASSET Act, took effect August 12. The enacted law applies to banks and credit unions and defines an eligible adult as someone age 70 or older, or an adult age 18 or older who meets the law’s vulnerability criteria.
Its definition of a disbursement is deliberately channel-neutral: a transaction to or for a member’s benefit counts regardless of the method, medium, instrument, channel or technology. That means an implementation limited to teller cash withdrawals would be too narrow. Digital transfers, checks, cards, wires, loans and other channels need a common escalation path where the transaction fits the statute.
Reporting is mandatory; a hold is optional
The first policy distinction is the most important. Under the signed act, a qualified employee who reasonably believes that financial exploitation may have occurred, may have been attempted or may be underway must notify local law enforcement or the county adult-protective-services agency where the eligible adult lives.
“Qualified individual” is not limited to the fraud department. It includes employees who conduct monetary transactions, sell financial services, approve loans, supervise those employees or ensure compliance with the institution’s legal duties. Training and escalation design therefore have to reach the branch, contact center, lending, operations, supervision and compliance functions—not only fraud analysts.
The law separately permits, but does not require, the credit union or qualified employee to delay a disbursement when there is a reasonable belief that the eligible adult is being exploited. If the institution uses that authority, the operational clock starts.
Two business days start the control sequence
As soon as possible, but no later than two business days after the requested disbursement, the credit union must send written notice of the delay and its specific reason to parties authorized to transact on the account. It does not have to notify a party reasonably believed to be involved in the suspected exploitation. The notice may be electronic.
Within the same two-business-day window, the institution must make the required agency notification and continue an internal review. It may also notify a third party previously designated by or reasonably associated with the member, but must take reasonable care not to contact a person suspected of exploitation or other abuse.
The delay can end when the credit union reasonably believes exploitation is not occurring, an agency concludes its investigation or a court orders release. The institution must make a determination within 90 days after the delay starts; if it is waiting for an agency investigation, the outside period is 180 days. It then must make or refuse the disbursement based on the investigation or the time limit.
Good-faith immunity is meaningful, but it is not a blank check. The statute ties protection to good faith and reasonable care. It also requires institutions to provide relevant records to adult-protective-services agencies and law enforcement. The defensible record is therefore the sequence: what the employee observed, why the belief was reasonable, whom the credit union notified, what it delayed, how it reviewed the case and why it released or refused the transaction.
A six-part implementation test
1. Map the people and decisions. Identify every role that falls within the law’s qualified-individual definition. Put the mandatory report and optional hold on separate branches of the procedure, with named authority for each.
2. Configure the clocks. The case record should timestamp the requested disbursement, member notice, agency report, internal-review updates and the 90-day determination. If an external investigation supports the extension, record the basis and the 180-day endpoint.
3. Test every material channel. Run scenarios through branch, call-center and digital channels. Confirm that a hold can be placed and released accurately without freezing unrelated funds by default or losing the audit trail when a case crosses systems.
4. Prepare notices and trusted-contact rules. Create a notice template that states the specific reason without disclosing unnecessary sensitive information. Make the suspected-abuser exclusion explicit both for authorized-account parties and for trusted contacts.
5. Join the state and federal paths. NCUA’s interagency statement on elder financial exploitation recommends governance, employee training, transaction holds consistent with applicable law, trusted contacts, suspicious-activity reporting and coordination with law enforcement and adult protective services. Colorado reporting does not replace Bank Secrecy Act analysis; the case process should route both without treating one as proof that the other is complete.
6. Run a tabletop before the first case. Use a member who is being coached by a scammer, a caregiver who may be the suspected exploiter and a digital transfer requested near a weekend. Test who recognizes the signal, who reports, who starts the delay, who sends the notice and who owns the final determination.
The broader credit-union decision
Credit unions outside Colorado should not copy this statute into policy as though it applied nationwide. State definitions, reporting duties, hold authority, notification rules and immunity vary. But the ASSET Act is a useful design test: can the institution distinguish suspicion from proof, mandatory reporting from discretionary action, and temporary protection from an indefinite freeze?
NCUA’s current elder-financial-abuse guidance also says that reporting suspected abuse to appropriate authorities generally does not violate federal privacy rules. Legal counsel should still map the credit union’s state-specific duties and disclosures.
For related controls, CreditUnionAI News’s coverage of impersonation-scam investigations explains why successful authentication is not the same as a fully investigated authorization decision, while the FinCEN student-aid fraud alert shows how fraud operations and BSA monitoring can share evidence without collapsing into one process.
The immediate decision is straightforward: Colorado credit unions should assign one owner to validate the end-to-end ASSET Act workflow now. The test should prove that a reasonable suspicion reaches the right agency, an optional hold activates the correct two-day notices, and no case can age past its 90- or 180-day decision point unnoticed.
