Being part of management should not mean delivering only the answers management wants.
Credit union leadership needs a candid conversation about independence—and accountability. In this two-part series, we explore how compliance and internal audit professionals can work effectively with management without compromising their judgment. We begin with compliance, where working within management can make those boundaries less clear.
This may be a hot take, but compliance cannot make a credit union stronger if it is expected to deliver only comfortable answers. And it cannot provide useful guidance without understanding how the credit union actually operates.
Management often welcomes oversight that protects members and catches problems before examiners do. But that support can wear thin when a review delays a project or identifies a time-consuming fix. Compliance professionals can contribute to the friction, too—by misunderstanding a process, overstating a concern, or presenting a recommendation as a requirement.
Neither side gets a pass. Management needs room to question an assessment, and compliance needs freedom to stand behind a supported conclusion. Both have a responsibility to get the facts right before deciding how to respond.
Part of the team, with room to disagree
Compliance’s position is complicated. It often works within management, helping develop products, review vendors, and design processes. Its role includes providing expertise, monitoring, and objective challenge—not necessarily the structural separation associated with internal audit.theiia
That is the conundrum: compliance needs to be close enough to understand the business without becoming so invested in a decision that it cannot question it. In this context, protecting independent judgment means preserving the freedom to raise concerns, evaluate alternatives objectively, and escalate unresolved issues.
Consider a lending product days from launch. Testing reveals that the system is generating inaccurate required disclosures. Leadership has announced the launch and asks compliance to sign off, with corrections to follow.
Compliance should consider workable alternatives, such as providing accurate disclosures through another process that satisfies the applicable requirements. But a deadline does not resolve the compliance gap. Nor does compliance’s involvement in developing the product excuse it from raising the concern.
Being part of the team cannot mean shielding the team’s decisions from an honest assessment.
Negotiate the solution, not the facts
Too often, the conversation shifts from resolving an issue to reducing its visibility: Can we soften the wording? Lower the risk rating? Leave it out of the report?
There may be sound reasons to revise the wording or rating—or withdraw an unsupported conclusion. But those changes should follow the evidence, not the discomfort. A cleaner report is not necessarily a stronger operation.
A better working relationship requires clear responsibilities and shared commitments.
Compliance’s responsibilities
Understand before concluding. Learn how the process and core system work, verify the facts, and distinguish requirements from recommendations.
Bring practical options. Explain what must change and where flexibility exists. Your preferred solution may not be the only defensible one.
Management’s responsibilities
Challenge with evidence. Provide context and supporting facts—not pressure for a preferred answer.
Own the response. Assign responsibility, resources, and a realistic deadline. Address why recurring issues remain unresolved.
Shared commitments
Keep reporting honest. Change the assessment when the evidence changes—not when the pressure increases.
Protect escalation. Establish a path for unresolved concerns to reach the appropriate decision-maker or oversight body, even when compliance and management disagree.
These boundaries matter especially in smaller credit unions, where responsibilities overlap. Close working relationships should help compliance understand the operation—not make candid disagreement harder.
Keep the goal in view
At Crimson Oak Strategies, we help credit unions navigate this tension with clarity and independent judgment. We understand operational realities, distinguish requirements from recommendations, and identify practical, defensible solutions—without allowing a preferred outcome to shape our conclusions.
The goal is to protect the credit union, serve members, and resolve weaknesses. Compliance should help the team move forward. Sometimes that means saying, “Not this way.”
In Part 2, we will examine internal audit and the supervisory committee’s role in making independent oversight work.