Security1 distinct publisher2 min readPublished
H.R.10230 would restore the NCUA's lapsed authority over third-party vendors and extend similar power over the institutions the FHFA regulates. The Defense Credit Union Council says the scope is drawn too wide. No hearing date is on the record.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The practical difference between supervising a credit union and supervising its vendor is who an examiner can compel to answer. With the NCUA's temporary third-party authority lapsed, questions about a core processor or a fraud-scoring model go to the credit union, which can pass along only what its contract entitles it to ask [2]. H.R.10230 would put the vendor itself in scope [1].
The record carries no clock. No introduction date, no committee referral, no hearing, no markup, no effective date, and no definition of the technology provider that would fall in scope appear in the supplied material [8]. A questionnaire backed by an examiner who can audit the vendor directly is what the bill would build; when that exists is not in evidence [8].
That missing definition is where the fight lands. "Technology providers used by the financial institutions they regulate" can be read as the handful of core processors that run the ledger, or as every AI service a credit union puts on a card [1]. Foster's stated rationale is AI-driven attack paths running through third-party relationships [4], which argues for the wider reading. The Defense Credit Union Council's remedy of identifying the specific gaps and consulting credit unions before writing the authority argues for the narrower one [5].
Everything here rests on one brief that credits FedScoop [7]. Bill text, committee record, and any NCUA statement of its own position are absent from it [8]. The named support is also thinner than the named opposition: the Government Accountability Office and unnamed previous regulators on one side [6], one identified trade association on the other [9].
Until the authority is restored, vendor risk at a federally insured credit union is governed by contract language and whatever the vendor volunteers [2]. The Federal Home Loan Bank and government-sponsored enterprise side of the bill is new authority rather than restored authority [3], which is the half most likely to be traded away if the sponsor needs to narrow the scope to answer the DCUC.
Ranked by verification strength, evidence, and original report placement.
H.R.10230, the Strengthening Oversight for the Financial Sector Act, is a new bill in the House of Representatives championed by Rep. Bill Foster that seeks to grant the National Credit Union Administration and the Federal Housing Finance Agency authority to oversee technology providers used by the financial institutions they regulate.
The bill addresses a perceived gap in regulatory power: the NCUA's temporary authority to oversee third-party vendors has lapsed.
The legislation would amend existing acts to provide the FHFA director with regulatory authority over services used by Federal Home Loan Banks and government-sponsored enterprises, among others.
Foster argues the bill is crucial given artificial intelligence and cybersecurity threats, and highlighted concerns that sophisticated AI-powered cyberattacks could exploit weaknesses in third-party relationships, potentially compromising sensitive data and financial assets.
The Defense Credit Union Council opposes the bill, arguing its scope is too broad and urging a more targeted approach after identifying specific regulatory gaps and consulting affected credit unions.
The bill is supported by previous regulators and the Government Accountability Office.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
FinCEN's CTA rollback hands beneficial-ownership diligence back to lenders1 distinct publisher
invest
An FHFA refinance waiver moves the cost of curing title onto whoever holds the loan1 distinct publisher
security
An agent took 17,600 actions against Hugging Face over four and a half days1 distinct publisher
invest
"An inadvertent error is not fraud": Cook turns removal attempt two into a test of "for cause"1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One brief, credited to FedScoop
Sponsor, lapsed NCUA authority, FHFA extension and the Defense Credit Union Council's objection all trace to a single SC Media brief that credits FedScoop for the reporting. None of it is tied to bill text, a committee record or a quoted primary document, and the agency that would gain the power says nothing in it. The facts are plausible and specific, and the sourcing behind them is one step removed and unduplicated.
A bill known so far only by its number
There is nothing yet to count. Examination authority either exists in statute or it does not, and on this record H.R.10230 has no introduction date, referral, hearing or vote attached to it. Putting a number here would mean inventing a legislative calendar the reporting does not contain.
AI framing outruns the cited facts
The brief itself is dry, but the case it relays is not proportionate to what it shows. Foster's argument turns on sophisticated AI-powered attacks moving through third-party relationships, and no incident, examination finding or loss figure is offered behind it. The verifiable part, that a temporary vendor authority expired and a bill would restore and extend it, is narrower and duller than the threat language wrapped around it.
Named parties, all with something at stake
This reads as an argument over who bears examination cost, and the positions line up with interests. The Defense Credit Union Council speaks for the institutions that would host examiners and their vendor contracts, the NCUA would recover authority it lost, and Foster is quoted defending a bill he sponsors. The Government Accountability Office is credited with support but no reasoning of its own is given, and the rest of the support side is an unnamed group of former regulators, which is the weakest part of the roster.
Solid enough to flag, thin for planning purposes
That the bill exists as described, and that one credit union group is arguing it is drawn too wide, is reasonably firm. Past that the story thins quickly: a single publisher working from another outlet's reporting, no statutory language, no calendar, no word from the NCUA, and no definition of a covered provider. That supports watching the bill, not building a compliance assumption on it.