ORNL Federal Credit Union has selected Kobalt Labs to modernize its vendor-management program, providing a current example of AI moving into a credit union's second-line risk and compliance workflow. The selection establishes the planned use case. It does not establish that the platform is live, that it has approved a vendor or that ORNL FCU has produced a measurable risk or efficiency result.
The September 4 announcement describes ORNL FCU as a nearly $5 billion institution serving about 230,000 members across 31 branches. Kobalt says its platform can extract evidence from vendor materials, identify control gaps and produce risk analyses. The release says the relationship begins with third-party risk and vendor management, with an intended expansion into enterprise risk management.
Those capability claims come from the provider's announcement. The release does not identify a go-live date, contract value, model architecture, source documents, review volumes, baseline processing time, accuracy measure or independent validation result. It also does not say that the system will make final vendor decisions. Those boundaries keep this story at Standard promotion priority while giving risk leaders a specific operating model to examine.
The useful automation target is evidence handling
Third-party reviews often require employees to gather policies, security reports, financial information, contracts, business-continuity evidence and responses to questionnaires. An AI tool can reduce repetitive work if it extracts a control statement, preserves its source and directs an analyst to missing or contradictory evidence.
The higher-risk step is turning those observations into a final risk conclusion. A concise generated analysis can look complete even when a source is stale, a control applies only to part of the service or a subcontractor sits outside the reviewed boundary. Credit unions should therefore separate three permissions: extracting evidence, proposing an issue or rating, and approving the vendor or residual risk. The announcement supports the first two as plausible uses; it provides no basis to assume autonomous approval.
That separation aligns with the NCUA's April 2026 AI supervision FAQ. The agency says credit unions using an AI vendor should understand how the product functions, which risks it introduces, how it fits the business model and what safeguards, reliability measures and controls the provider uses. The agency also expects internal controls and ongoing risk monitoring around the tool.
Require a source trail for every finding
A defensible AI-assisted review should let an analyst move from the summary back to the underlying evidence. For each extracted control or flagged gap, the record should preserve the document, version, page or section, extraction time and relevant service scope. It should also distinguish a missing answer from an actual control failure.
Reviewers need a reliable way to correct the output without erasing the original. The case file should show the system's proposed finding, the employee's decision, any override reason and who accepted the residual risk. When a model, prompt, policy mapping or document parser changes, owners should know which open and completed assessments may be affected. That dependency belongs in the credit union's AI inventory and change-control record.
The control should work in both directions. The credit union must assess Kobalt as a vendor while using Kobalt to assess other vendors. That means the platform itself needs an approved data boundary, role-based access, retention and deletion terms, subcontractor visibility, incident notification, business-continuity evidence and an exit path. NCUA's longstanding third-party relationship guidance makes clear that outsourcing a function does not remove the credit union's responsibility for safeguarding member assets or maintaining sound operations.
Measure review quality before expanding the scope
A pilot should begin with a defined review type and a pre-AI baseline. Risk leaders can compare cycle time, analyst hours, evidence requests, missed material findings, false gap flags, reopened reviews and disagreements between the tool and a qualified reviewer. Speed is useful only when the evidence remains complete and the residual-risk decision improves or at least holds its quality.
Sampling should include both accepted and rejected machine findings. Reviewing only the cases employees escalated will miss quiet false negatives; reviewing only accepted suggestions will hide automation bias. A second reviewer can compare a sample against the source package without seeing the system's conclusion first. Material mismatches should trigger investigation, not just prompt tuning.
Before expanding into enterprise risk management, ORNL FCU and any peer institution evaluating a similar approach should be able to answer five questions:
- Scope: Which review steps may the system perform, and which decisions remain human?
- Evidence: Can every finding be traced to a current, applicable source?
- Change: How are model, policy and document-processing changes tested and applied to prior work?
- Performance: Which quality measures sit beside cycle-time and labor savings?
- Exit: Can the credit union export source files, findings, decisions and audit history in usable form?
The last question connects the implementation to a broader AI vendor exit plan. A faster review process is not resilient if its evidence and decisions cannot be reconstructed outside the platform.
ORNL FCU's selection is notable because it places AI inside a defined credit-union control workflow rather than describing a general capability. The next evidence should be equally specific: the actual authority boundary, source-traceability rate, reviewer correction pattern, time saved after rework and whether material vendor risks are identified earlier. Until those results are disclosed, the prudent conclusion is selection—not proven transformation.
Follow the operating evidence. Subscribe to the CreditUnionAI Weekly Briefing for practical AI, risk and technology-governance coverage.
Get the Weekly Briefing