A focused course, tailored for you
Card-Issuer Compliance Operations under CFPB and NYDFS
An integrated card-issuer compliance operations pattern for 2026: CFPB priority-rule readiness, NYDFS cyber and AI examinations, OCC operational resilience expectations, state UDAAP enforcement.
Card-issuer compliance managers face a stacked 2026 agenda. CFPB priority rules, NYDFS cyber and AI examinations, OCC operational resilience expectations, state UDAAP enforcement. The course delivers the integrated operations pattern.
$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Card-issuer compliance managers face a stacked 2026 agenda. CFPB priority rules (NSF and overdraft fee framework, larger participant rule for digital payment apps, credit-card late fee final rule status, complaint-handling expectations). NYDFS dual focus on cybersecurity regulation Part 500 and the AI-systems framework. OCC heightened standards on operational resilience and third-party risk. State attorneys general expanding UDAAP enforcement against card issuers. The internal compliance function is asked to maintain rule-by-rule readiness while operationalising the integrated picture across product, marketing, servicing, and collections.
The default approach handles each rule as a separate workstream. The integrated picture lives in slides for the audit committee and nowhere else. Examiners find the gaps in the seam between workstreams.
The course works through the integrated operations pattern. The rule-by-rule readiness inventory. The cross-rule control framework. The marketing-review pattern that holds across CFPB UDAAP and state UDAAP. The servicing-operations pattern that holds across CFPB complaint expectations and OCC operational resilience. The collections-operations pattern that holds across CFPB and state-specific debt-collection rules. The AI use case framework under NYDFS. The integration with the existing audit-committee cadence. Twelve modules with deliverables. Plus a hand-built playbook for your specific card portfolio.
What you walk away with
- A documented rule-by-rule readiness inventory.
- A cross-rule control framework.
- A marketing-review pattern.
- A servicing-operations pattern.
- A collections-operations pattern.
- An AI use case framework under NYDFS.
- An audit-committee reporting pattern.
- A 10-week build plan.
The 12 modules
Module 1. The 2026 card-issuer regulatory landscape
Walkthrough of the 2026 card-issuer regulatory landscape. CFPB priority rules and the post-litigation status of the late-fee rule. NYDFS Part 500 amendments effective stages. NYDFS AI framework status. OCC heightened standards. State UDAAP enforcement priorities. The competitive landscape across US bank card issuers and the fintech card-issuer cohort. The strategic decisions a card-issuer compliance manager faces in scoping a 12-month workstream programme.
Module 2. Rule-by-rule readiness inventory
Build the rule-by-rule readiness inventory. Each priority rule mapped to the in-scope product, marketing surfaces, servicing surfaces, collections surfaces, data sources, vendor relationships, and operations process. The readiness scoring framework. The gap-tracking pattern. The integration with the customer's existing GRC platform. Plus the worked example for the first ten priority rules under active examination focus.
Module 3. Cross-rule control framework
Build the cross-rule control framework. The shared-control library that handles multiple rules at once. The rule-attribution pattern. The control-effectiveness measurement pattern. The integration with the customer's existing internal-audit cadence. The integration with the customer's existing model risk management framework. Plus the worked example for the first 50 cross-rule controls.
Module 4. Marketing-review pattern
Build the marketing-review pattern. The CFPB UDAAP framework. The state UDAAP framework variations. The CARD Act marketing-specific provisions. The Regulation Z marketing-specific provisions. The integration with the customer's existing marketing operations cadence. The escalation-to-legal pattern. Plus the worked example for the first three marketing channels (digital display, direct mail, partnership-channel) under the integrated review.
Module 5. Servicing-operations pattern
Build the servicing-operations pattern. The CFPB complaint-handling expectations. The OCC operational resilience expectations on customer-impact functions. The Regulation E servicing-specific provisions. The Regulation Z servicing-specific provisions. The integration with the customer's existing complaint-management platform. The integration with the customer's existing operational-resilience programme. Plus the worked example for the customer-service operating model.
Module 6. Collections-operations pattern
Build the collections-operations pattern. The CFPB Regulation F debt-collection framework. The state-specific debt-collection rules. The CFPB UDAAP collections provisions. The integration with the customer's existing collections operating model. The integration with the customer's existing recovery operations cadence. The third-party collections agency oversight framework. Plus the worked example for the customer's typical collections process.
Module 7. AI use case framework under NYDFS
Build the AI use case framework under NYDFS. The credit-decision use case. The fraud-detection use case. The marketing-personalisation use case. The customer-service-assist use case. Each classified under the NYDFS AI framework. The customer-side governance committee integration. The customer-side audit-trail integration. Plus the worked example for the first three AI use cases.
Module 8. NYDFS Part 500 cybersecurity alignment
Build the NYDFS Part 500 cybersecurity alignment. The 500.13 risk-based controls. The 500.17 incident reporting. The 500.11 third-party service provider provisions. The 500.15 multi-factor authentication. The 500.18 audit pattern. The integration with the customer's existing cybersecurity programme. The integration with the customer's existing incident response runbook.
Module 9. OCC operational resilience integration
Build the OCC operational resilience integration. The critical-function identification pattern. The impact-tolerance setting pattern. The severe-but-plausible scenario set tailored to card-issuer operations. The third-party risk integration. The integration with the customer's existing operational-resilience programme. Plus the worked example for the card-issuer's typical critical functions (payments processing, customer access, fraud monitoring).
Module 10. State UDAAP enforcement preparation
Build the state UDAAP enforcement preparation pattern. The state-by-state enforcement priorities. The state attorney general engagement pattern. The state-specific marketing-review overlay. The state-specific servicing-operations overlay. The integration with the customer's existing state-regulatory function. Plus the worked example for the customer's first ten state exposures and the prioritisation framework.
Module 11. Audit-committee reporting pattern
Build the audit-committee reporting pattern. The integrated readiness dashboard structure. The exception-reporting framework. The trend-analysis framework. The forward-look framework. The integration with the customer's existing risk-committee cadence. Plus the worked example for the audit-committee briefing pack that a chair signs without further follow-up.
Module 12. Your 10-week build plan
Week by week. Weeks 1-2: landscape and rule-by-rule readiness inventory. Weeks 3-4: cross-rule control framework and marketing-review pattern. Weeks 5-6: servicing-operations and collections-operations. Weeks 7-8: AI use case framework, NYDFS Part 500, OCC operational resilience. Weeks 9-10: state UDAAP preparation, audit-committee reporting. Deliverable: an integrated card-issuer compliance operations pattern ready for the next examination cycle.
How this addresses your situation
Specific modules that map to what you said you are dealing with.
CFPB rule lands → Module 2.
Cross-rule controls needed → Module 3.
Marketing review → Module 4.
Servicing operations → Module 5.
Collections operations → Module 6.
AI use case under NYDFS → Module 7.
Part 500 cyber → Module 8.
OCC operational resilience → Module 9.
State UDAAP → Module 10.
Audit committee → Module 11.
What you get with this course
- The 12-module course delivered as text plus downloadable templates.
- Templates and worked examples for every module.
- A hand-built playbook generated for your specific card portfolio.
- Three reference operations patterns from peer card-issuer engagements.
- Scripted talking points for the audit committee and examiner engagement.
What you will have in hand by Day 1, Week 1, Month 1
Day 1: Rule-by-rule readiness inventory scaffold drafted.
Week 4: Cross-rule control framework and marketing-review pattern designed.
Week 8: Servicing, collections, AI, NYDFS Part 500, OCC operational resilience operational.
Week 10: Operations pattern ready for next examination cycle.
Before and after
Before
Rule-by-rule workstreams. Integrated picture in slides only. Examiners find seam gaps. Enforcement risk compounds.
After
Integrated operations pattern. Each rule handled by shared controls. Examiners find a coherent operations picture. Audit committee reads a single dashboard.
What happens if you do not address this
CFPB, NYDFS, OCC, and state AG enforcement cadences do not pause. Card-issuer compliance functions that cannot show integration will compound enforcement risk into 2027.
Who it is for
For card-issuer compliance managers, compliance directors at US bank card issuers, principal compliance consultants serving card-issuer customers, and senior compliance leads at fintech card-issuer firms.
Who this is NOT for. Pure non-card-issuer practitioners. Practitioners with no consumer-finance regulatory experience. Pure non-compliance roles.
How it arrives
Text-based course via LMS, plus downloadable templates and worked examples and the hand-built playbook.
Time investment. Roughly 18 hours of reading and 60 to 120 hours of build effort across the 10-week plan.
Why $199 is the right number
External card-issuer compliance operations consultants charge from 100,000 to 500,000 USD for integrated programmes. 199 USD buys the focused playbook and the implementation document for your card portfolio.
FAQ
Does this cover fintech card-issuer specifics?
Yes. Module 1 covers the fintech card-issuer cohort and Modules 5-6 cover the operations differences.
What about Reg E disputes?
Module 5 covers Reg E in the servicing-operations pattern.
Does this cover the post-SCOTUS CFPB constitutionality status?
Module 1 covers the current state of CFPB priority rules under the post-litigation landscape.
What is in the implementation playbook for me specifically?
Operations pattern tuned to your card portfolio, state-by-state preparation matched to your exposure, audit-committee dashboard pre-loaded with your reporting cadence.
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.