Discovering the Hidden AI Already Operating in CU Systems
- Roy Urrico

- 3 hours ago
- 5 min read
By Roy Urrico

For many credit unions the use of artificial intelligence represents their future. However, most credit unions already have some artificial intelligence in use. They did not decide to adopt AI. They inherited it. It arrived inside systems and tools already used, switched on through routine releases, often with no contract amendment and no meaningful notification.

That is the position of Lisa Pent, Founder and CEO of Albany, N.Y.-based PentEdge, which helps community financial institutions find, score, and govern the AI inside their tech stack. PentEdge is currently launching two products under its umbrella AIMS™ (an acronym for “AI monitoring and governance system.”) to help credit unions and other financial institutions manage AI utilization.
Pent sat down with Finopotamus to discuss why AI cannot be managed like another third-party relationships, and what credit unions can do about it.
The Vendor Management Problem
The existing vendor management process was never designed to help credit unions control the gradual evolution of AI into their banking system. “It came in through the core, the fraud platform, the lending system, and the marketing tools they already licensed, and the annual vendor review was not built to catch it,” said Pent.
Third-party review, Pent explained, is periodic by design: onboard, diligence, review annually. “AI does not hold still for a year. A tool assessed in January can carry a different risk profile by June, and an annual questionnaire will not surface it. Meanwhile examiners are asking what AI an institution uses and who owns it, and most institutions have no inventory to answer from.”
When she has conversations with potential credit union clients about AI use in their environment, the most common response is “We are not using it,” noted Pent. “As part of that process, I always say, ‘send me your vendor list. I am going to show you how many of those tools and vendors are using AI in their product,’” said Pent.
One prospect’s list revealed 418 vendors, including local individuals and businesses providing some service, “but most of them were software vendors,” noted Pent. “Out of 418 vendors, 216 had AI in their tools,” Pent noted. “The risk of 216 different AI products in one environment is a lot to think about.”
The other part of the conversation is to make sure that organizations are looking holistically about AI risk exposure. “All of these free tools like ChatGPT and Claude and using Gemini through their Google browser are not necessarily things that they made a specific decision to purchase, but that are very likely being used within the credit union's environment by at least some employees.”
Asking the Right Questions
Why is third-party AI risk different? “Because you do not know you have it. If we fast-forward to an examiner situation. They want to believe that you are aware of all of the AI that is in your environment,” Pent said. She recommended credit unions need to ask every vendor if a tool or platform uses AI, how does it use AI, and does it use third party AI?
An important component of controlling AI use is receiving comprehensive updates from vendors more frequently. “You send out a questionnaire, you hire a firm to send out the questionnaires for you. That is like a moment in time,” said Pent. “They very likely are adding AI capabilities into their products on a continual basis. Let's say you send the questionnaire out every December and you aggregate all the data in January. It is stale already.”
Getting more specific disclosure from vendors would help. “A question would be, ‘Can you update us in real time when adding AI to our product?’ Because they are just pushing it through the backend. it might be in some release notes that they send you or maybe not,” said Pent.
“Keep sending out those annual questionnaires,” advised Pent. “Don't in any way, shape or form stop doing that. But also work with your vendors, especially vendors you might have multiple products, and see if you can get them to increase the frequency with which they are providing you with disclosure without you having to reach out and grab it.”
Taking Inventory
U.S. financial regulators currently oversee AI mainly by employing existing risk-management frameworks — such as SR 11-7 (Guidance on Model Risk Management), which govern AI algorithms and machine learning models — rather than applying one comprehensive federal AI law.
“The examiners and former examiners that I've spoken as well as the regulators themselves, do not require that level of specificity,” explained Pent. With the advent of PentEdge and the rollout of AIMS Manifest and AIMS Watch, the company is trying “to create some early awareness so that when the regulatory piece catches up, our community institutions are ready.”
For now, credit unions should start with an inventory of all AI in their environment, both vendor related and non-vendor related, suggested Pent. She listed the most important elements: “Number one, you need an inventory of your AI. Number two, once you know what that inventory is, you really need to think about your risk appetite. Let us start with just understanding what the risk is.”
The way to do that involves working with the credit union’s technical team, suggested Pent. “They can look at the log files of the activity, and it will show you where AI is present across your organization. We have a tool that does it, but you can also just do it by working together with your technology team.”
PentEdge wants to facilitate the inventory process, particularly to help smaller institutions. So, they created an AI catalog with more than 560 tools. “If you were running a credit union, and you sent me your list, a good number of the tools that you are using would match the tools that we have in our catalog. All the tools have an inherent risk score,” Pent explained..
Providing a PentEdge
Pent spent 30 years in financial services — including credit risk leadership on Wall Street, a decade at Thomson Reuters building software for financial institutions, and senior leadership at Cognizant, an AI Builder and technology services provider — before founding PentEdge in 2025.
“PentEdge intends to target the 9,000 credit unions and community banks,” said Pent. “I have known for a long time how absolutely critical community financial institutions are for our country. That is the audience that I want to target. I want to bring some real world-class problem solving to community-based financial institutions.”
To help credit union and other financial institutions manage AI utilization, PentEdge offers two products under its AIMS umbrella.
AIMS Manifest covers the governance side: AI inventory, AI Risk Score, and examiner-ready reporting.
AIMS Watch covers personally identifiable information (PII) blocking and AI activity monitoring.
Both are priced well below what institutions expect to pay for this category, said Pent. Manifest runs $3,000 per year for up to five users, $5,000 for ten, and $8,000 for unlimited.
Pent said she will demo these products at several upcoming banking events including the GoWest Credit Union Association’s MAXX event Oct. 6-9, 2026 in Denver; and VentureTech, for which Finopotamus is a media partner, November 16–18, 2026 in Fort Worth, Texas.



