On June 15, 2026, the National Credit Union Administration (NCUA) issued a final rule on 12 CFR Part 749 – Vital Records Preservation Program. The final rule is effective July 16, 2026.
Under the rule, federally insured credit unions are required to "maintain a vital records preservation program to identify, store, and reconstruct vital records in the event such records are destroyed."
Sounds simple in theory, but what does this look like in practice? Here are five steps a credit union can follow to comply with this updated rule.
The golden rule of information security: "You can't protect your data if you don't know where it lives." 💛
According to the NCUA's final rule, vital records are "the most recent and current versions of the records a credit union needs to restore vital member services." At a minimum, this includes:
|
Timeframe |
Data Type |
Details |
|
End of business day |
Member balances and contact information |
A list of share, deposit, and loan balances for each account that includes individual balances identified by a name or number, multiple loans separately, and a way to contact each member (e.g., address, phone number, etc.). |
|
End of month |
Financial reports and bank reconcilements |
A list of all credit union asset and liability accounts, as well as records confirming the internal books match external statements. |
|
End of month |
Key account information |
A list of the credit union's own financial accounts, insurance policies, investment listings, and related contact details. |
|
As needed |
Emergency contact info |
Contact info for employees, officials, regulatory offices, and vendors |
|
Updated as needed |
Other vital records |
Anything else the credit union determines should be treated as "vital" based on its operations. |
In the previous version of the rule, Appendix A provided guidance on records that should be retained permanently, including charters and bylaws, board and committee meeting minutes, financial reports, audit reports, membership applications, and general ledgers, to name a few. The updated rule removes Appendix A entirely, narrowing the scope to the records a credit union needs to restore vital member services.
While records like charters, bylaws, and other foundational documents fall outside that definition, they should continue to be retained as part of normal governance and legal recordkeeping.
With Tandem Risk Assessment, you can create a list of data types (e.g., account balances, financial reports, contact information), assign a data classification, and associate the types with applicable asset records. Tandem can help you keep track of where your data lives, so you can find it when you need it most.
If you've worked in compliance for long, you've probably heard some form of the phrase: "… but did you document it?" That's what this step is about.
Within six months of getting NCUA insurance, the Board of Directors is expected to establish a written vital records preservation program. According to the rule, the program must:
Records Preservation Log: The previous version of the rule was very prescriptive, requiring the records preservation log to capture things like the record's name, storage location, storage date, and the name of the person sending it for storage. The new rule simply requires a log, leaving the format and content up to the credit union.
Permission to Destroy: The new rule allows credit unions to destroy older versions of vital records once current versions are stored, unless other retention requirements apply. Think of Marie Kondo standing in your datacenter, pulling up an outdated record and saying, "This does not bring me joy." If the current version is safely stored, you now have explicit permission to thank it for its service and let it go.
Tandem Policies includes template Data Management and Data Backup policies built on NCUA and FFIEC guidance. Together, they cover the full data management lifecycle (i.e., creation, storage, use, retention, and destruction), as well as the technical specifics of managing and protecting backups. Use them as the foundation of your vital records preservation program, tailor them to your environment, and track Board approval to demonstrate oversight.
Your records must be stored in a "vital records center" (yes, the same one I mentioned earlier ⬆️). A vital records center is an offsite location that must be geographically separate enough that a single catastrophic event can't take out both the primary and backup records at the same time.
The good news is that you have a lot of flexibility here. The regulations don't prescribe a specific type of facility. This means, your vital records center could be:
There's a new third-party oversight obligation, but we'll cover that next.
Use Tandem Business Continuity Planning to create Backup Profiles for your systems and data. Document everything that matters: backup frequency, media types, storage locations, security and access controls, versioning, and restoration plans. Connect your systems with Tandem's Risk Assessment product to put your backup program in full context.
If you need additional assistance, CoNetrix Technology is a Tandem Partner that specializes in providing managed IT services, including backup and recovery through their Aspire Cloud Hosting service. Learn more about how CoNetrix Technology can help you at CoNetrix.com/Technology.
Vendor Oversight: If using a third-party vendor as the vital records center, the rule requires credit unions to maintain "effective oversight" of that vendor to ensure the records meet the rule's requirements.
While the regulation does not define what constitutes "effective oversight," the NCUA has published guidance on Evaluating Third-Party Relationships (SL 07-01). According to the guidance, the third-party risk management process typically includes planning and risk assessment, due diligence and selection, contract structure and review, ongoing monitoring (think: periodic reviews and testing restoration procedures), and planning for termination.
Learn more in the Tandem Vendor Management Workbook.
Contract Clause: If the credit union uses a third-party service provider to maintain vital records, the service agreement must specify that the vendor safeguards against the simultaneous destruction of production and backup records. (This is particularly relevant when the same vendor serves as both the primary and backup storage provider, but could apply in other circumstances, as well.)
This section is mostly new. The previous version of the rule allowed for outsourcing, but stopped there. The new rule requires effective oversight and the contract clause.
In practice, this means the credit union's responsibility doesn't stop when the contract gets signed. Instead, it's the credit union's responsibility to actively monitor the vendor and make sure they are holding up their end of the bargain.
Tandem Vendor Management is a third-party risk management platform. Demonstrate effective oversight by creating third-party service records, documenting risk assessments, storing contact information, uploading contracts, and performing reviews of relevant third-party relationships.
Last, but certainly not least, the credit union is required to ensure the records are accessible and usable. The three core usability requirements are identical in both versions of the rule. The records must:
This means if anyone needs to get access to the record (examiners included), the credit union should have the tools and capabilities to ensure they can do so in a timely and effective manner. (No cold storage. 🥶)
Nothing changed here. Just a couple of minor grammar updates.
While this topic is operational in nature, it is addressed in the Tandem Policies template Data Backup policy. The policy implementation procedures require credit unions to restore data from a backup on a regular basis as part of the credit union's BCP exercise and testing program.
Use Tandem Business Continuity Planning to perform exercises and tests. Use the template scenarios or create your own, and use the software to set reminders, record lessons learned, and generate professional documentation.