Takes about 10 minutes. Answer “Yes,” “Partial,” or “No” for each of the 31 controls below — your score and priority gaps update live as you go (0/31 answered).
Score your credit union’s program across privacy notices, administrative/technical/physical safeguards, vendor oversight, and incident response readiness. Based on RiskInMind’s member data protection guidance.
Our privacy notice language matches what we actually do with member data
Members have a clear, working way to opt out of nonaffiliated third-party sharing
We correctly assess each year whether the annual notice requirement applies to us
The categories of NPI we collect and disclose are documented and kept current
Privacy notice language is reviewed and aligned before every exam cycle
Field note: Examiners compare your privacy notice to your actual data-sharing behavior — a mismatch is a finding regardless of whether a member was harmed.
Breakdown by control area
Answer the questions on the left to see which control areas need attention first.
Educational self-assessment tool — not a substitute for a formal risk assessment, legal review, or NCUA examination.
Read the full compliance guide