VyStar Issues With Banking System Rollout Put Vendor Management Processes In UDAAP Crosshairs

By Ray Birch

WASHINGTON—What should credit unions learn from VyStar’s troubled rollout of its new online and mobile banking platforms? According to experts—vendor management processes are now subject to UDAAP rules.

“Vendor management processes can now overlap with unfair, deceptive, and abusive acts and practices,” said Brandy Bruyere, a partner at Honigman, LLP, about the VyStar fine. “The CFPB has hinted at this in the past in supervisory guidance or other consent orders. But this is one (CFPB’s $1.5-million fine against VyStar) that's very much homed in on how handling a switch of critical vendors led to harm to consumers.”

Bruyere emphasized what the CFPB is saying with this recent enforcement action is when an organization creates a project plan for switching critical vendors that are key to providing services consumers rely on for accessing or moving their money, they must consider and mitigate the risks of an unsuccessful conversion or migration of those services.

Vystar 2

Bruyere noted VyStar members did not have access to services for a long period of time.

“It's pretty difficult to call that a successful rollout,” she said, reminding that CFPB consent orders are written by the CFPB and its view of the facts. “There were some mistakes here, right? Otherwise people wouldn't have gone that long without those services.”

Bruyere advised credit unions that when formulating a project plan for these kinds of major platform rollouts, to make sure timelines are realistic and timelines are being updated to account for any issues or concerns that may arise.

Many Moving Parts

bruyere_brandy 006 16_rt

Brandy Bruyere

“Every project plan for some type of core conversion or critical service migration has a lot of moving parts, has a lot of technology and data involved,” she said. “The project plan is probably based on our best-case scenario, the best information we have available. But as we get into the project and we learn things, or we hit hiccups, we need to be making adjustments for that, and we need to not necessarily treat having to adjust our project plan as a failure.

“I would consider does our project team have the right people and do they have the right resources. I think we need to be careful about what our testing processes look like and how we are onboarding the results of those testing processes,” continued Bruyere. “I think the biggest thing we should take away from this is what are our contingency plans for maintaining key services with minimal to no disruption if the worst-case scenario is what comes out the back end, or at least not our best-case scenario.”

Bruyere reminded that mistakes are going to happen, hiccups are going to occur, even with the best-laid plans.

Extension Of CFPB’s Authority?

Was the CFPB’s enforcement action against VyStar an example of the agency’s overreach?

“I think it's interesting to tie vendor management to UDAAP,” Bruyere said, adding that comments from NCUA board members regarding the CFPB action indicate NCUA cooperated with the CFPB during its investigation of VyStar. “I think it's just a sign that the CFPB, at least under its current leadership, is going to be continually aggressive in using UDAAP to affect the market. I don't know that vendor management is necessarily clearly part of the Bureau's purview. We often think of them as the safety and soundness regulator, that’s their role. But what the CFPB is signaling here is if it’s insufficient vendor management, and the insufficient vendor management leads to consumer harm, then the door is open for the Bureau—at least if you're over $10 billion in assets—to scrutinize that.”

ACU’s Perspective

America’s Credit Unions Chief Advocacy Officer Carrie Hunt emphasized what has not made headlines is VyStar moved quickly to begin rectifying the rollout’s problems.

“I think it is certainly a bit surprising that this type of enforcement action results in a $1.5-million consent order,” she said. “I think it is surprising and questionable as to whether or not penalizing the credit union under UDAAP this way is fair.”

Hunt stressed that clarity is needed from the CFPB about its general authority in this area.

Hunt, Carrie

Carrie Hunt

“I feel like we're seeing example after example of the CFPB using this as a catch-all,” Hunt said. “I think what was surprising is the way this enforcement action was handed down. I think that the specific set of facts were surprising. Generally, when you issue any type of civil money penalty, its goal is twofold—to prevent something from happening again and to punish a bad actor.”

Hunt acknowledged VyStar made errors.

“But I certainly think no one ever intended for the (problems with the rollout) to happen,” Hunt said. “VyStar has made everyone whole, as they have indicated in a public statement. So, the question of restitution seems superfluous.”

Hunt pointed to what she sees as a growing concern from the CFPB’s action against VyStar.

“This just begs the question of how a credit union, or any financial services organization, knows how to act if there's always going to be this looming question as to whether or not they are going to get punished for something, even if they self-correct,” she said.

NCUA Third-Party Vendor Oversight

Does VyStar’s problems support NCUA’s desire to obtain oversight of credit union third-party vendors?

“I'm not saying it does or does not. But even if the NCUA had third-party vendor authority, examining any third party down to the execution of a product is questionable,” Hunt said. “When you look at what other agencies are doing relative to third-party vendor authority, I think in reality the solution for NCUA needing this authority is to clarify there can be information sharing between various agencies. Again, I will not guess as to what the NCUA is going to do, but I don't think even if they had third-party vendor authority that would have resolved this (VyStar) issue.”

Bruyere said she believes NCUA may leverage the VyStar rollout to help it gain third-party vendor oversight.

“I think the VyStar action is going to add to a growing pile of data and evidence for NCUA to take to Congress and ask for third-party vendor management authority,” Bruyere said. “I don't have strong opinions on that. And I certainly have seen credit union opinions in my time in this industry start to shift from a rather universal, we are not a fan of that, to now at least some credit unions saying maybe it would be helpful if NCUA fought some of these battles for us. But I also believe that involving NCUA in something is not always going to make it better. The fact that we're a little more than a year out from when credit unions had to start reporting cyber incidents to the NCUA, I have a feeling the agency is compiling quite the pile of data that would help them make their case here.”

Section: Standard
Word Count: 1472
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/VyStar-Issues-With-Banking-System-Rollout-Put-Vendor-Management-Processes-In-UDAAP-Crosshairs