Plan your credit union's 2027 AI budget, a free working session with BCU's COO Register →
ApproachStage 01

Clear the Runway

Get an AI policy your board will actually approve and the education to get them and the rest of the C-suite there.

What This Stage Solves

A board cannot approve what it does not understand, and most credit union boards have not been given a straight explanation of what AI does with member data. So the vote gets deferred, and every AI conversation after that stalls behind it.

Meanwhile the core banking provider is shipping AI features into products the credit union already runs. That is the exposure almost nobody has written down: AI is already in the building, arriving through vendors, governed by nothing.

The policy is not the point. Getting unblocked is the point. Everything in the next two stages depends on the board having said yes to how member data gets used.

Some of the Things You Get

01

Board ready AI policy

A standalone policy the board votes on, not a paragraph bolted onto the end-user IT policy. Standalone matters because it gets its own review cycle, its own owner, and its own place in the board minutes. A pointer stays in the IT policy so nothing is orphaned. It covers approved tool classes, what data may go into them, a control row for each tool the credit union actually uses, and the states a tool can be in, including what restricted means in practice.

02

Board education session on AI

A working session built for directors, not for engineers. The framing that lands is task replacement rather than job replacement, because that is the question directors are actually asking and nobody says it out loud. Runs roughly thirty minutes with fifteen for questions, anchored on two case studies from comparable institutions, including at least one where over-control was the mistake.

03

2027 AI roadmap

A ranked list of initiatives with cost estimates the board can budget against, built from what staff say actually eats their week rather than from a vendor catalogue. Ranked by time recovered against effort to build, so the first initiative is defensible on its own.

How It Runs

  • ·Read the existing policy set: end-user IT policy, privacy, third-party risk. The AI policy has to sit beside these without contradicting them.
  • ·A working session to make the decisions only the credit union can make. Standalone or section. Which tool classes are approved. What goes in the control row for the tools already deployed. What restricted means.
  • ·Draft, redline, and a review memo, then the version that goes into the board package ahead of the deadline the credit union is actually working to.
  • ·Staff input gathered before the roadmap, framed around time and frustration rather than around AI, because asking people about AI produces opinions and asking them about their week produces a roadmap.
Proof

BCU Financial, an Ontario credit union with roughly $1B in assets and about 95 staff, engaged The General Consulting Company for embedded AI engineering across Finance, Compliance, Wealth, and Operations.

Read the Full Story

Common Questions

Should the AI policy be standalone or part of our IT policy?

Standalone, in most cases. A standalone AI policy gets its own owner, its own review cycle, and its own line in the board minutes, which is what makes it enforceable later. An amendment buried in the end-user IT policy tends to be invisible within a year. Leave a pointer in the IT policy so the two stay connected, and revisit at the next annual review whether it can be folded back in.

Does the policy need to cover AI our vendors add to their products?

Yes, and this is the clause most policies miss. Core banking providers and other vendors ship AI features into existing products without you procuring anything. If the policy only governs tools staff go out and adopt, it does not govern most of the AI in the building. The policy needs a position on vendor-embedded AI and a control for each tool already deployed. OSFI takes the same position in Guideline E-23, which expects externally developed models to be assessed on their own.

How long does it take to get an AI policy in front of the board?

The constraint is the board calendar, not the drafting. Board packages are typically due two to four weeks before the meeting, and there is often an audit or risk committee that sees the policy first. Work backward from the meeting date. The drafting and the decision session fit inside that window. Our team at The GCC works around the clock to ensure you can get that AI policy approved ASAP.

Our board is not asking about AI yet. Do we still need this?

Definitely. The vendors are not waiting for the board to ask. If AI features are already live in products you run, the governance gap exists whether or not anyone has raised it. The board education session is often what turns a quiet or hesitant board into an engaged one.

Ready to Build AI Confidence?

Start with a free 30-minute call, or download the AI Policy Template to get a head start.