Skip to main content
Image coming soon

QA Evidence That Satisfies Bank Examiners

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

QA Evidence That Satisfies Bank Examiners

Build test artefacts that close OCC and CFPB findings before the examiner asks the second question.

Your test cycle passes. The control owner approves. The OCC examiner opens your test log and asks why the sample size was 25 transactions instead of a risk-stratified pull from the highest-velocity accounts. The documentation doesn't answer that question. Now it's an MRA.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Senior QA Analysts at regulated financial institutions operate at the intersection of two evidence standards: the internal SDLC gate (did the build work?) and the regulatory evidence standard (does this test log demonstrate adequate control assurance?). These standards are not the same, and most QA methodology training ignores the second one entirely. The result: test cycles that satisfy the development team and flag as inadequate during examination. Defect logs that track resolution but don't map remediation back to the control objective. Sample-size decisions documented as 'standard practice' with no risk rationale. Each of these is a finding waiting to surface. This course teaches you to build the test artefact that answers the examiner's question before it's asked.

What you walk away with

  • Write test objectives that map explicitly to the control being tested, so the examiner can trace from finding to evidence in under two minutes.
  • Build risk-stratified sampling rationale that is documented in the test plan, not reconstructed after the examination begins.
  • Structure defect logs so that each finding includes the control impact, the remediation owner, and the retest evidence in a single artefact.
  • Apply a pre-examination QA evidence review that identifies documentation gaps before the examiner's first request list arrives.
  • Distinguish between an SDLC test pass and an examination-grade test pass, and know when you need both in the same cycle.
  • Produce a QA methodology summary the Chief Risk Officer can hand to the examination team without supplemental narrative.

The 12 modules

Module 1. The Two Evidence Standards: SDLC vs. Examination
Most QA training addresses the SDLC gate: does the build meet requirements? This module maps the second, parallel standard: does the test artefact demonstrate control assurance to an OCC or CFPB examiner? You will identify the specific documentation elements that satisfy each standard, understand where they overlap and where they diverge, and build a checklist for any test cycle that must satisfy both. Covers OCC Handbook QA expectations and CFPB supervisory priorities for operational controls.
Module 2. Control-Mapped Test Objectives
An SDLC test objective says 'verify interest calculation is correct.' An examination objective says 'verify interest-calculation logic operates within the parameters of the TILA compliance control, as documented in the Q3 control inventory.' This module teaches you to rewrite every test objective so it traces explicitly to the control, the regulatory requirement, and the risk rating that set the scope. Worked examples from payment systems, lending, and deposit operations.
Module 3. Risk-Stratified Sampling: Documentation That Holds Under Review
Sample-size decisions are among the most common examination flashpoints for QA teams. 'We tested 25 transactions' is not a rationale. This module covers how to document the risk basis for your sample: transaction volume by risk tier, exception history from prior cycles, regulatory guidance on statistical confidence for control testing, and the written rationale that answers the examiner's question before it is asked. Includes a reusable sampling-rationale template calibrated for OCC Model Risk Management and CFPB examination workflows.
Module 4. Defect Logs as Control Evidence
A defect log that tracks issue status is an SDLC artefact. A defect log that maps each finding to a control objective, documents the control impact, names the remediation owner, and captures retest evidence in the same record is an examination artefact. This module restructures your defect log fields so every entry carries the full evidence chain. You will build a schema that satisfies both development workflow and the examiner's request list, with spreadsheet templates for common banking core systems.
Module 5. UAT in Regulated Environments: What Changes
Bank UAT acceptance criteria include regulatory compliance, not just functional correctness. This module extends your UAT scripts to capture compliance-relevant behaviour: edge cases under Regulation E, Regulation Z, and UDAP; sign-off chains that satisfy the three-lines model; and the documentation that places business ownership on the compliance outcome. Includes a UAT script extension template for payments and lending systems.
Module 6. Change Management Testing and the Examination Artefact
Regulatory examiners review change management testing as a proxy for operational risk discipline. This module covers what the OCC Model Risk Management guidance expects from change-testing documentation: the impact assessment, the regression scope rationale, the sign-off chain, and the evidence that the change did not introduce new control gaps. You will build a change-testing evidence package template that satisfies both the internal change-management board and the examiner's substantive review. Includes worked examples from core banking upgrades and AML rule-set changes.
Module 7. The Pre-Examination QA Evidence Review
Two weeks before an examination is not the time to discover your test logs are missing the Q4 sampling rationale. This module builds a structured pre-exam review: the gap-identification checklist, remediation priority matrix, and a triage of which documentation reconstructs quickly versus which requires the original author. You will build a standing quarterly review process that one analyst can run in three hours.
Module 8. Model Validation QA: Unique Requirements
QA on model-driven outputs (credit scoring, AML transaction monitoring, fair-lending analytics) carries additional documentation requirements under OCC Model Risk Management guidance (SR 11-7 and its successors). This module covers the specific QA evidence elements that model validation requires: the conceptual soundness review, the outcome analysis, the benchmarking artefact, and the ongoing monitoring documentation. You will learn to distinguish QA performed by the model development team from independent validation QA, and build the evidence package that satisfies the independence requirement.
Module 9. Communicating QA Findings to the Three Lines
First-line wants to know the build is ready. Second-line wants control effectiveness. Third-line audit wants the evidence chain. A single-audience report fails two of them. This module structures QA finding communication for a three-lines environment: executive summary for the business owner, control-effectiveness assessment for risk management, artefact package for internal audit. Includes a version-controlled report template ready for examination use.
Module 10. Automated Testing Evidence in Manual Examination Frameworks
Automated test suites produce pass/fail results, not examiner-ready evidence packages. The OCC examiner reviewing your Selenium or API test output cannot see the control objective behind the test or the risk rationale behind the scope. This module covers how to bridge automated test output into examination-grade documentation: the test-to-control mapping table, the automated coverage statement, and the manual-override documentation that addresses what automation cannot test. Includes a configuration guide for common banking QA platforms.
Module 11. Handling QA Findings During an Active Examination
When an examination is in progress and a QA artefact is pulled, the documentation you provide must be complete and self-contained. This module covers examination-room protocol for QA teams: what to produce, what to withhold (privilege considerations), how to respond to follow-on requests without opening new examination threads, and how to document your examination-response activity so that it serves future preparation. Includes a request-log template and a response-review checklist for QA leads.
Module 12. Building the Standing QA Methodology Document
The course output is a QA methodology document the Chief Risk Officer can hand to the examination team without supplemental narrative. This module assembles it: sampling framework, control-mapping approach, defect-log schema, pre-exam review cadence, and escalation path for examination-threatening findings. The finished document doubles as the onboarding reference for every new QA analyst who joins your team.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

OCC or CFPB examination is scheduled and QA artefacts need to be examination-ready before the first request list arrives: modules 3, 7, 11.
Test cycles are passing internal gates but generating MRAs or MRIAs on examination: modules 1, 2, 4.
Model-driven outputs (AML, credit scoring, fair lending) are in scope for an upcoming model risk management review: module 8.
New QA analyst joining the team and methodology needs to be documented and transferable: modules 9, 12.

What you get with this course

  • Twelve written modules covering OCC, CFPB, and Fed examination evidence standards for QA teams.
  • Reusable templates: risk-stratified sampling rationale, control-mapped test objective, defect-log schema, pre-exam review checklist, QA methodology document.
  • Worked examples from payment systems, lending, deposit operations, AML, and model risk management.
  • Hand-built implementation playbook tailored to your institution's examination history and QA environment, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Before and after

Before

QA cycles pass internal gates, but test logs become examination flashpoints. Sampling decisions are documented as 'standard practice.' Defect logs track status, not control impact. The pre-examination scramble to reconstruct rationale takes two weeks every cycle.

After

Every test artefact carries its own examination-ready evidence chain. Sample size decisions are documented in the test plan. Defect logs trace from finding to remediation to retest to control assurance. The pre-examination review runs in three hours.

What happens if you do not address this

Each examination cycle where QA documentation gaps surface as findings adds to the MRA inventory and increases examiner scrutiny on the next cycle. A pattern of QA-related findings creates a management attention item that extends well beyond the QA function. The documentation gap is fixable before the next examination; it is much harder to fix during one.

Who it is for

Senior QA Analysts and QA leads at US commercial banks, regional banks, and bank holding companies who are accountable for testing evidence that may be reviewed by OCC, CFPB, Fed, or state examiners. You run test cycles, manage defect logs, and sign off on UAT. You have seen at least one examination where a QA artefact became the focus of an MRA or MRIA. You want a methodology that produces examination-ready evidence without doubling your cycle time.

Who this is NOT for. Software QA analysts at non-regulated technology companies. Test automation engineers whose primary accountability is build quality, not regulatory evidence. QA professionals in insurance or healthcare who operate under different examiner frameworks (NAIC, CMS) than OCC/CFPB.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Each module is designed for a 45-60 minute focused session. The full twelve-module course completes in approximately ten hours of study time. Templates are ready to use at the end of each module, not at the end of the course.

Why $199 is the right number

Internal QA methodology training at banks typically covers the SDLC gate and stops there. External QA certifications (ISTQB, CSTE) address general software quality assurance, not the regulatory evidence requirements specific to OCC, CFPB, or Fed-supervised institutions. Consulting engagements that produce QA methodology documents run from $30,000 to $80,000 and take three to six months. This course delivers the methodology and the templates in ten hours of self-paced study, at $199.

FAQ

Does this course address state-chartered bank examination frameworks, or only OCC-supervised institutions?
The core evidence principles (control-mapped objectives, risk-stratified sampling, defect-log chain of custody) apply across OCC, Fed, FDIC, and state examination frameworks. Where the modules reference specific regulatory guidance, they note the OCC source and identify the equivalent Fed or FDIC parallel. The implementation playbook is calibrated to your institution's primary regulator.
My team uses automated test suites for the majority of our coverage. Is this course still relevant?
Yes. Module 10 specifically addresses how to bridge automated test output into examination-grade documentation. The sampling rationale, control-mapping, and defect-log modules apply whether the underlying test execution is manual or automated. The gap this course addresses is the documentation layer above the test execution, which automated suites do not produce.
How does the tailored implementation playbook differ from the course modules?
The modules teach the methodology. The implementation playbook applies it: it maps the templates and frameworks to your institution's examination history, your current QA toolchain, and the specific control areas most likely to surface in your next examination cycle. It is hand-built after you enrol, not a generic appendix.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.