Mountain America Credit Union Chief Risk Officer Nanette Graviet is leaning on technology amid a changing regulatory environment.
Graviet has been with the $19 billion Sandy, Utah-based credit union for nearly 31 years and was named senior vice president and CRO in April.

What started as a part-time college job at the $19 billion credit union quickly transformed into a fulfilling lifelong journey, Graviet told Bank Automation News, adding that her ability to understand policy implementation and manage risk accordingly is the reason she was promoted to chief risk officer.
In the past two years, MACU:
- Tapped Alkami Technologies in July 2024 to improve digital banking platforms;
- Teamed up with AKUVO in November 2023 for credit risk and delinquency management; and
- Moved its core banking platform to KeyStone Core in March 2023.
BAN sat down with Graviet to discuss MACU’s tech strategy and more. What follows is a lightly edited version of the conversation.
Bank Automation News: What are some of the biggest compliance challenges you face, and how are you addressing them?
Nanette Graviet: There is a constant need to track changes in the regulatory environment, and changes can intensify with each election cycle. Our team members leverage software and subscription solutions that help inform us as changes happen, and we focus on educating the organization and deploying solid change management plans.
BAN: How do you incorporate innovative technologies like AI or new methodologies into your risk management practices?
NG: We are exploring AI for the identification and analysis of regulatory content and related controls and a more dynamically managed [risk and control self-assessment]. Leveraging AI will allow team members to spend less on time-consuming content and more time finding solutions.
BAN: What emerging trends in risk management and compliance do you think will shape the future of the industry?
NG: Technology advancements and AI will play a significant role in the future of compliance and risk management in both the documentation and analysis of risks, including the potential elimination of sample-based testing, summarization and extraction of regulatory obligations, and automated risk assessments.
BAN: With a new administration in the White House, how will risk management and compliance change for FIs in the coming years?
NG: I think risk management changes very little. Those who have implemented regulatory requirements effectively and as intended are recognizing the usefulness of these tools in making better business decisions and will still prioritize prudent risk management activities. Pausing for the current administration is short-sighted and will put financial instructions behind the 8 ball when the pendulum inevitably swings the other way.
BAN: What are your goals for Mountain America’s risk management strategy in the next five years?
NG: MACU’s goal is to make risk management more intuitive, integrated and timely. Understanding the current risk profile and emerging risks helps inform the best decisions and strategies for the credit union. This comes from establishing a strong and agile enterprise framework that allows for the measurement of risks in aggregate and across different taxonomies.






