« Back to The Blog

DCU Bulletin B-17-06 Obtaining Audit Reports from Third-Party Providers

The Division of Credit Unions has published Bulletin B-17-06 regarding examiners obtaining audit reports from third-party providers.

Annual audit reports are required for Federally Insured State Credit Union’s (FISCUs) with $500 million or more in assets. For those with less than $500 million, either of three supervisory committee audit options are available.   See:   §715.4   Audit responsibility of the Supervisory Committee.  http://www.ecfr.gov/cgi-bin/textidx?SID=3a2a547a46463337db3cc01b1fb68f21&mc=true&node=pt12.7.715&rgn=div5 

Obtaining Audit Reports from Third-Party Providers

The National Credit Union Administration (NCUA) recently announced a change in their supervision policy that requires their examiners to obtain a copy of a newly completed audit report directly from the outside audit firm from all federally insured credit unions. This change is in response to recommendations made by the Office of Inspector General following material loss reviews conducted by that office.

NCUA examiners conduct off-site reviews for all federally insured credit unions once a quarter. These reviews primarily consist in studying the most recent Financial Performance Report and 5300 Call Report. In addition, and as part of the off-site monitoring process, NCUA now requires their examiners to review each credit union’s Online Profile to determine if the credit union has reported a newly completed annual audit completed by a third-party. If so, the NCUA examiner is required to contact the auditor, supervisory committee, and/or audit committee to obtain a copy of the audit report directly from the auditor. Once received, the examiner will read the audit report, and if material problems are identified, will follow up as necessary.

In order to reduce the burden to credit unions (and third-party audit providers) from receiving multiple requests for audit reports by both the Division of Credit Unions (DCU) and the NCUA, DCU will coordinate the audit report requests as a single point of contact.

When required, NCUA will notify DCU of the need to obtain an audit report, and DCU will notify the credit union and/or third-party audit provider to request an electronic copy of the audit and the applicable management letter be sent directly (via encrypted email) to both the DCU at DCU@dfi.wa.gov and at the same time, send a cc to NCUA at r5dosmail@ncua.gov. Upon review and as required, the DCU, NCUA, and the credit union will work together to resolve any concerns.

If you have any questions about this Bulletin, please contact Keith Schuster at Keith.Schuster@dfi.wa.gov or (360) 902-8717.

Passwords to access the blog posts, and blog posts are only for NWCG owners and retained clients. These should not be shared outside of the credit union. Blog posts generally contain only a summary of any requirements, and do not represent all potential impact on the credit unions. For further details on any blog post, contact NWCG or references cited in the blog post. The information contained on this site is provided for informational purposes only, and should not be construed as legal advice.

   

Compliance Services Group Copyright 2026.© All Rights Reserved | Privacy Policy

No Legal Advice Intended

The information on this website is provided as a service to our clients and visitors. The contents of this website, and the posting and viewing of the information on this website may convey information that can be characterized as “law related services” as defined by Rule 5.7 of the Rules of Professional Conduct (“RPC”) governing lawyers, but should not be construed as, and is not intended to be legal services, legal advice, or forming a client-lawyer relationship. Since CSG is not engaged in the practice of law, neither our services nor our relationship will be governed by the RPCs governing lawyers including, but not limited to, specific RPC rules applicable to privileged communications and prohibitions of conflicts of interest. While CSG uses reasonable efforts to include accurate, up-to-date information on this website, CSG makes no warranties or representations as to its accuracy and assumes no liability or responsibility for any errors or omissions in the content of this website or any third-party websites accessed through links from this website.

Formal Agreement Required for Services

You cannot engage CSG to render services for you through e-mail. CSG is not committed to provide services of any kind to you unless a formal services agreement has been executed by both you and CSG. CSG makes no commitment to you to maintain the confidentiality of any e-mail you send to us nor to respond to any e-mail.

Copyrights

Except for information in the public domain, or whether other ownership is acknowledged, CSG owns the copyright to this web site and all of its content. You may not copy or distribute materials from this web site except for personal, noncommercial use.

Links

Links provided by this web site are to assist our clients and visitors in identifying other useful resources and are not intended to state or imply that CSG sponsors or is associated with these resources or endorses or recommends any of the third party information, products, or services found there.

Compliance Services Group
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.