bR2bR Compliance · Practitioner
v2.0

bR2bR Compliance Officer — Financial Services

Run governed, AI-assisted financial-services compliance reviews: SOX ITGC, PCI DSS, model risk, GLBA, NYDFS, FINRA and AML.

Level
Practitioner
Learning time
20 hours
Price
$499
Credential
Valid 3 years
What's new in v2.0

What changed in this edition.

  • bR2bR is now taught as an audit-engagement method built from real controls: scoped custom roles with per-project Read, two recorded approvals, Robo Compliance sealed sessions and auditor-portal shares, the hash-chained audit log and revocation.
  • AI co-pilot work follows the MCP-first session method, with a citation register, a four-gate Citation-Acceptance check and evidence-locator rules against fabrication.
  • Regulatory content brought current: PCI DSS v4.0.1 with the future-dated requirements in force since 31 March 2025, the FFIEC CAT retirement, the FTC Safeguards notification amendment, NYDFS Part 500 phase-in completed 1 November 2025, and the 2024 Regulation S-P amendments.
  • Model-risk module rebuilt around SR 11-7 / OCC 2011-12 with AI models evidenced through LLMOps model cards, evaluations, fairness reports and drift monitoring.
  • Nine AI role-play labs (Access Controller, Controller, Head of Model Risk, CISO, CCO, Director of Internal Audit, bank examiner and others) and a written capstone scored against a published rubric.
  • A fresh LOFT exam bank replaces every v1 item; seat time is 20 hours at Practitioner level.
Outcomes

What you will be able to do.

  • You will be able to scope and authorize a financial-services engagement with read-only access, two recorded approvals and a planned closure.
  • You will be able to run AI-assisted fieldwork with the MCP session tools, a citation register and controls against mis-citation, fabrication, severity drift and out-of-scope reads.
  • You will be able to obtain and verify evidence with chain of custody using Robo Compliance sealed sessions, the auditor portal and the audit log.
  • You will be able to test SOX IT general controls and PCI DSS v4.0.1 requirements, including CDE scope claims based on tokenization and segmentation.
  • You will be able to assess model risk under SR 11-7 / OCC 2011-12, including AI models evidenced through LLMOps governance records.
  • You will be able to test GLBA safeguards, NYDFS Part 500, Regulation S-P, FINRA Rule 3110 and AML/BSA controls, including notification clocks.
  • You will be able to write findings with explicit severity criteria and a remediation roadmap, and communicate them to management, committees and examiners.

Who it's for

  • Compliance officers and auditors at banks, broker-dealers, investment advisers, fintechs and payment processors
  • CISOs and security leads at NYDFS-regulated and GLBA-covered institutions
  • Internal audit and model-risk teams at financial institutions
  • Assurance and consulting professionals serving financial-services clients
  • AML compliance officers and BSA teams

Not covered here

  • Financial-statement audit procedures (this course covers IT general controls and compliance, not substantive audit)
  • Consumer-protection regulation such as UDAAP (not covered)
  • Non-US regimes such as DORA (Robo Compliance includes a DORA template; the course does not teach it)
  • Conferring CPA, CISA, CIA or PCI QSA status, or issuing attestations under professional standards
Syllabus

9 modules, 67 lessons.

About 20 hours of learning. Open a module to see every lesson.

  1. The Audit-Engagement Method on bRRAIn 8 lessons · 2 h 15 min

    bR2bR as an engagement method built from real controls, the eight zones as audit questions, evidence classes, read-only access by construction, and a full engagement setup from scope specification to closure.

    1. Pretest: the audit-engagement method on bRRAIn Diagnostic pretest · 5 min
    2. The bR2bR audit-engagement method: what it is and what it is not Reading · 15 min
    3. The eight zones from the auditor's seat Reading · 15 min
    4. Evidence classes: logs, configurations, decisions, models, transactions Reading · 15 min
    5. Read-only by construction: grants, approvals and revocation Reading · 15 min
    6. Setting up an engagement end to end Worked example · 15 min
    7. Lab: Scope and authorize an engagement with the auditee AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 1 Retrieval check · 10 min
  2. The AI Co-Pilot for Auditors 7 lessons · 2 h

    The MCP-first session method for engagement work, the four-frame prompt, citation discipline and the citation register, the five forms of mis-cited regulation, and the four-gate Citation-Acceptance check.

    1. Pretest: the AI co-pilot for auditors Diagnostic pretest · 5 min
    2. The AI co-pilot session: MCP-first method and the four-frame prompt Reading · 15 min
    3. Citation discipline: exact references, current versions, primary sources Reading · 15 min
    4. AI failure mode: the mis-cited regulation Worked example · 15 min
    5. The Citation-Acceptance gate Worked example · 15 min
    6. Lab: Run the Citation-Acceptance gate on an AI-drafted test plan AI role-play lab · 45 min
    7. Retrieval: 8 questions across Module 2 Retrieval check · 10 min
  3. Evidence, Memory and Chain of Custody 8 lessons · 2 h 15 min

    POPE-tagged evidence, reconciling canonical claims with runtime evidence, decision records as the why, chain of custody with sealed-session verification and the audit log, and Robo Compliance from the auditor's seat.

    1. Pretest: evidence, memory and chain of custody Diagnostic pretest · 5 min
    2. Walking a POPE-tagged evidence corpus Reading · 15 min
    3. Reconciling what the organization says with what the systems show Worked example · 15 min
    4. Decision records as the why behind a control Reading · 15 min
    5. Chain of custody for cited evidence Reading · 15 min
    6. Robo Compliance from the auditor's seat Reading · 15 min
    7. Lab: Negotiate the evidence room and reconcile the posture AI role-play lab · 45 min
    8. Retrieval: 8 questions across Module 3 Retrieval check · 10 min
  4. SOX IT General Controls and PCI DSS v4.0.1 7 lessons · 2 h

    Top-down ITGC scoping and testing, deficiency evaluation, PCI DSS v4.0.1 with the future-dated requirements in force since 31 March 2025, and CDE scoping with tokenization and segmentation.

    1. Pretest: SOX ITGCs and PCI DSS v4.0.1 Diagnostic pretest · 5 min
    2. SOX IT general controls: scope and structure Reading · 15 min
    3. PCI DSS v4.0.1 in 2026: structure, approaches and the requirements now in force Reading · 15 min
    4. Scoping the cardholder data environment, with tokenization Worked example · 15 min
    5. ITGC testing walkthrough: from control to conclusion Worked example · 15 min
    6. Lab: Walk ITGC and PCI results with the Controller AI role-play lab · 45 min
    7. Retrieval: 8 questions across the SOX ITGC and PCI DSS module Retrieval check · 10 min
  5. Model Risk Management and AI Models 7 lessons · 2 h

    SR 11-7 / OCC 2011-12 definitions, inventory and validation with effective challenge, a defensible institutional position on AI and generative models, and LLMOps governance evidence as model-risk evidence.

    1. Pretest: model risk management Diagnostic pretest · 5 min
    2. SR 11-7 foundations and the model inventory Reading · 15 min
    3. Validation and effective challenge Reading · 15 min
    4. Applying model-risk principles to AI and generative models Scenario · 15 min
    5. Reading LLMOps governance evidence for model-risk work Worked example · 15 min
    6. Lab: Model-risk review with the Head of Model Risk Management AI role-play lab · 45 min
    7. Retrieval: 8 questions across the model-risk module Retrieval check · 10 min
  6. GLBA, NYDFS Part 500 and Regulation S-P 7 lessons · 2 h

    Which GLBA safeguards rule applies, the FTC Safeguards Rule and its 2024 notification amendment, NYDFS Part 500 as amended with phase-in completed 1 November 2025, overlapping regimes and notification clocks, the FFIEC CAT retirement, and the 2024 Regulation S-P amendments.

    1. Pretest: GLBA, NYDFS Part 500 and Regulation S-P Diagnostic pretest · 5 min
    2. GLBA safeguards: which rule applies, and what it requires Reading · 15 min
    3. NYDFS 23 NYCRR Part 500 after the 2023 amendment Reading · 15 min
    4. Overlapping regimes and notification clocks Worked example · 15 min
    5. SEC Regulation S-P: the 2024 amendments Reading · 15 min
    6. Lab: Incident clocks and Part 500 posture with the CISO AI role-play lab · 45 min
    7. Retrieval: 8 questions across the GLBA, NYDFS and Regulation S-P module Retrieval check · 10 min
  7. FINRA Supervision and AML/BSA 6 lessons · 1 h 45 min

    FINRA Rule 3110 with Rules 3120, 3130 and 3310, AML program pillars, CIP, CDD and beneficial ownership, EDD, transaction monitoring, SAR timeliness and SAR confidentiality.

    1. Pretest: FINRA supervision and AML Diagnostic pretest · 5 min
    2. FINRA Rule 3110: testing a broker-dealer's supervisory system Reading · 15 min
    3. AML program foundations: CIP, CDD, beneficial ownership and EDD Reading · 15 min
    4. Transaction monitoring and SAR decisions Scenario · 15 min
    5. Lab: Supervision and AML review with the Chief Compliance Officer AI role-play lab · 45 min
    6. Retrieval: 8 questions across the FINRA and AML module Retrieval check · 10 min
  8. Findings, Severity and AI Failure Modes 8 lessons · 2 h 15 min

    This course's recommended seven-element finding format, a five-level severity scale with explicit criteria, and the AI failure modes of fabricated evidence, severity drift and out-of-scope reads.

    1. Pretest: findings, severity and AI failure modes Diagnostic pretest · 5 min
    2. Writing a finding: the seven-element format Worked example · 15 min
    3. Severity: a five-level scale with explicit criteria Reading · 15 min
    4. AI failure mode: fabricated evidence Worked example · 15 min
    5. AI failure mode: severity drift Scenario · 15 min
    6. Out-of-scope reads: prevention, detection and response Scenario · 15 min
    7. Lab: Catch and correct four AI failures in draft working papers AI role-play lab · 45 min
    8. Retrieval: 8 questions across the findings and AI failure modes module Retrieval check · 10 min
  9. Communicating Findings, Remediation and the Capstone 9 lessons · 3 h

    Findings for management, committees and examiners, remediation plans and roadmaps, what each supervisor looks for, conclusion language that matches the work, the report package and engagement closure, and the capstone.

    1. Pretest: communicating findings and the report package Diagnostic pretest · 5 min
    2. Communicating findings to three audiences Reading · 15 min
    3. Remediation plans that hold up Worked example · 15 min
    4. What each supervisor will look for in remediation Reading · 15 min
    5. Conclusion language that says exactly what you know Worked example · 15 min
    6. The report package: what you deliver and keep Reading · 15 min
    7. Lab: Defend your findings to a bank examiner AI role-play lab · 45 min
    8. Retrieval: 8 questions across the communication and reporting module Retrieval check · 10 min
    9. Capstone: Pre-examination review of Harborline Bank AI role-play lab · 45 min
Labs and capstone

Practice against someone who pushes back.

Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.

  • Lab 1 · The Audit-Engagement Method on bRRAIn

    AI role-play: scoping and authorizing an engagement with the auditee's Access Controller

  • Lab 2 · The AI Co-Pilot for Auditors

    AI role-play: running the Citation-Acceptance gate on an AI-drafted test plan with the engagement manager

  • Lab 3 · Evidence, Memory and Chain of Custody

    AI role-play: negotiating the evidence room and reconciling Robo Compliance posture with the auditee's compliance manager

  • Lab 4 · SOX IT General Controls and PCI DSS v4.0.1

    AI role-play: presenting ITGC and PCI DSS scope results to the Controller

  • Lab 5 · Model Risk Management and AI Models

    AI role-play: model-risk review of three models with the Head of Model Risk Management

  • Lab 6 · GLBA, NYDFS Part 500 and Regulation S-P

    AI role-play: incident clocks and Part 500 posture with the CISO

  • Lab 7 · FINRA Supervision and AML/BSA

    AI role-play: FINRA supervision and AML review with the Chief Compliance Officer

  • Lab 8 · Findings, Severity and AI Failure Modes

    AI role-play: correcting four AI failures in draft working papers with the Director of Internal Audit

  • Lab 9 · Communicating Findings, Remediation and the Capstone

    AI role-play: defending findings to a bank examiner

  • Lab 10 · Communicating Findings, Remediation and the Capstone

    Written engagement report package from a complete evidence file

Capstone

Pre-examination review of Harborline Bank

Artefact submitted in the capstone lab, AI-scored against the published rubric

Pass mark: 72%

Scored on

  • Engagement governance and scope discipline15%
  • Finding detection and evidence accuracy25%
  • Regulatory application and citation integrity20%
  • Severity and risk judgment15%
  • Remediation roadmap15%
  • Report quality and conclusion language10%
Exam and credential

One exam. A credential anyone can verify.

The exam

Items per form
59
Time allowed
120 min
Pass mark
72%
Performance tasks
4
Attempts included
2
Wait between attempts
7 days
  • Online and timed, taken on learn.brrain.io.
  • Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
  • Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.

The credential

  • A verifiable digital badge in your name.
  • A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
  • Valid for 3 years.
  • Renewal: Renewal at 3 years by passing the then-current exam
Before and after

Where this course sits.

Questions

Frequently asked.

Do I need to install anything for the labs?

No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.

How is the exam delivered?

Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.

What if I don't pass first time?

You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.

How long is the credential valid?

3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.

I hold the v1 credential. Is it still valid?

Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.

Can my company enroll a team?

Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.

Enroll

bR2bR Compliance Officer — Financial Services

Run governed, AI-assisted financial-services compliance reviews: SOX ITGC, PCI DSS, model risk, GLBA, NYDFS, FINRA and AML.