A focused course, tailored for you
Enterprise Risk Management at a US Card Issuer
An integrated ERM operating model for US card issuer ERM practitioners in 2026: CFPB priority rules, NYDFS cyber and AI examinations, OCC heightened standards, state UDAAP enforcement, customer-side ESG integration.
US card issuer ERM practitioners map 47 active regulatory pressures across five risk areas. The 18 shared controls reconcile across the five only with a manual roll-up.
$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Enterprise Risk Management practitioners at US card issuers (the firm, Capital One, Discover, the firm card services, Citi card services, Bank of America card services) map 47 active regulatory pressures across CFPB, NYDFS, OCC, state AGs, and customer-side ESG. The five risk areas share 18 controls. The reporting does not yet reconcile across the five. The default approach maintains five separate workstreams and reconciles manually before each ERM committee meeting.
The course delivers the integrated ERM operating model. The cross-rule control framework. The marketing-review pattern. The servicing-operations pattern. The collections-operations pattern. The ESG integration. The customer-side AI use-case framework under NYDFS. The customer-side state UDAAP enforcement preparation. The customer-side OCC operational resilience integration. The customer-side audit committee reporting framework. Twelve modules with deliverables. Plus a hand-built playbook for your specific card portfolio.
What you walk away with
- An integrated ERM operating model.
- A cross-rule control framework.
- A marketing-review pattern.
- A servicing-operations pattern.
- A collections-operations pattern.
- An ESG integration framework.
- An AI use-case framework under NYDFS.
- A state UDAAP enforcement preparation framework.
- An OCC operational resilience integration.
- An audit committee reporting framework.
- A 10-week build plan.
The 12 modules
Module 1. The 2026 US card issuer ERM landscape
Walkthrough of the 2026 US card issuer ERM landscape. The CFPB priority rule pattern. The NYDFS Part 500 and AI framework pattern. The OCC heightened standards pattern. The state UDAAP enforcement pattern. The competitive landscape across US card issuers. The strategic decisions an ERM practitioner faces in 12-month integration programme planning.
Module 2. Cross-rule control framework
Build the cross-rule control framework. The shared-control library that handles multiple rules at once. The rule-attribution pattern. The control-effectiveness measurement pattern. The integration with the customer's existing internal-audit cadence. The integration with the customer's existing model risk management framework. Plus the worked example for the customer's first 50 cross-rule controls.
Module 3. Marketing-review pattern
Build the marketing-review pattern. The CFPB UDAAP framework. The state UDAAP framework variations. The CARD Act marketing-specific provisions. The Regulation Z marketing-specific provisions. The integration with the customer's existing marketing operations cadence. The escalation-to-legal pattern. Plus the worked example for the customer's first three marketing channels under the integrated review.
Module 4. Servicing-operations pattern
Build the servicing-operations pattern. The CFPB complaint-handling expectations. The OCC operational resilience expectations on customer-impact functions. The Regulation E servicing-specific provisions. The Regulation Z servicing-specific provisions. The integration with the customer's existing complaint-management platform. The integration with the customer's existing operational-resilience programme. Plus the worked example for the customer-service operating model.
Module 5. Collections-operations pattern
Build the collections-operations pattern. The CFPB Regulation F debt-collection framework. The state-specific debt-collection rules. The CFPB UDAAP collections provisions. The integration with the customer's existing collections operating model. The integration with the customer's existing recovery operations cadence. The third-party collections agency oversight framework. Plus the worked example for the customer's typical collections process.
Module 6. ESG integration framework
Build the ESG integration framework. The customer-side scope-1 reporting. The customer-side scope-2 reporting. The customer-side scope-3 reporting. The customer-side governance disclosure. The customer-side ISSB S1 and S2 alignment. The customer-side EU CSRD overlay where applicable. Plus the worked example for the customer's first three ESG integration cycles.
Module 7. AI use-case framework under NYDFS
Build the AI use-case framework under NYDFS. The credit-decision use case. The fraud-detection use case. The marketing-personalisation use case. The customer-service-assist use case. Each classified under the NYDFS AI framework. The customer-side governance committee integration. The customer-side audit-trail integration. Plus the worked example for the customer's first three AI use cases.
Module 8. State UDAAP enforcement preparation
Build the state UDAAP enforcement preparation pattern. The state-by-state enforcement priorities. The state attorney general engagement pattern. The state-specific marketing-review overlay. The state-specific servicing-operations overlay. The integration with the customer's existing state-regulatory function. Plus the worked example for the customer's first ten state exposures and the prioritisation framework.
Module 9. OCC operational resilience integration
Build the OCC operational resilience integration. The critical-function identification pattern. The impact-tolerance setting pattern. The severe-but-plausible scenario set tailored to card-issuer operations. The third-party risk integration. The integration with the customer's existing operational-resilience programme. Plus the worked example for the card-issuer's typical critical functions.
Module 10. Audit committee reporting framework
Build the audit committee reporting framework. The integrated readiness dashboard structure. The exception-reporting framework. The trend-analysis framework. The forward-look framework. The integration with the customer's existing risk-committee cadence. Plus the worked example for the audit-committee briefing pack that a chair signs without further follow-up.
Module 11. Customer engagement structure
Build the customer engagement structure. The discovery phase. The diagnostic phase. The transformation phase. The sustainment phase. The renewal conversation. The customer-side programme-governance committee integration. Plus the worked example for a 12-month customer engagement and the pricing framework. Plus the integration with the customer's existing programme cadence and the worked example for the customer's typical operating model under the integrated framework.
Module 12. Your 10-week build plan
Week by week. Weeks 1-2: landscape and cross-rule control framework. Weeks 3-4: marketing-review and servicing-operations patterns. Weeks 5-6: collections-operations and ESG integration. Weeks 7-8: AI use-case framework, state UDAAP, OCC operational resilience. Weeks 9-10: audit committee reporting framework, customer engagement structure. Deliverable: an integrated ERM operating model ready for the next examination cycle.
How this addresses your situation
Specific modules that map to what you said you are dealing with.
CFPB rule → Module 2.
State UDAAP → Module 8.
NYDFS AI → Module 7.
OCC operational resilience → Module 9.
ESG → Module 6.
Marketing review → Module 3.
Servicing operations → Module 4.
Collections operations → Module 5.
Audit committee → Module 10.
What you get with this course
- The 12-module course delivered as text plus downloadable templates.
- Templates and worked examples for every module.
- A hand-built playbook generated for your specific card portfolio.
- Three reference operating models from peer card-issuer ERM functions.
- Scripted talking points for the customer audit committee engagement.
What you will have in hand by Day 1, Week 1, Month 1
Day 1: Cross-rule control framework scaffold drafted.
Week 4: Marketing-review and servicing-operations patterns designed.
Week 8: Collections, ESG, AI use-case framework, state UDAAP, OCC operational resilience operational.
Week 10: Operating model ready for next examination cycle.
Before and after
Before
Five workstreams. Manual reconciliation. ERM committee reads fragmented. Enforcement risk compounds.
After
Integrated ERM operating model. Five rule areas handled by shared controls. ERM committee reads single dashboard.
What happens if you do not address this
CFPB, NYDFS, OCC, and state AG enforcement cadences do not pause. Card-issuer ERM practices that do not integrate compound enforcement risk into 2027.
Who it is for
For Enterprise Risk Management practitioners at US card issuers, principal ERM consultants serving card issuers, senior ERM leaders at peer card issuers.
Who this is NOT for. Pure non-card-issuer practitioners. Practitioners with no ERM context.
How it arrives
Text-based course via LMS, plus downloadable templates and worked examples and the hand-built playbook.
Time investment. Roughly 18 hours of reading and 60 to 120 hours of build effort across the 10-week plan.
Why $199 is the right number
External card-issuer ERM operations consultants charge from 100,000 to 500,000 USD. 199 USD buys the focused playbook and the implementation document for your card portfolio.
FAQ
Does this cover fintech card-issuer ERM?
Module 1 covers fintech card-issuer adjacency.
What about prepaid card ERM?
Module 1 covers prepaid card adjacency.
Does this cover commercial card ERM?
Module 1 covers commercial card adjacency.
What is in the implementation playbook for me specifically?
Operating model tuned to your specific card portfolio.
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.