bR2bR Compliance Officer — Financial Services
Run governed, AI-assisted financial-services compliance reviews: SOX ITGC, PCI DSS, model risk, GLBA, NYDFS, FINRA and AML.
- Level
- Practitioner
- Learning time
- 20 hours
- Price
- $499
- Credential
- Valid 3 years
What changed in this edition.
- bR2bR is now taught as an audit-engagement method built from real controls: scoped custom roles with per-project Read, two recorded approvals, Robo Compliance sealed sessions and auditor-portal shares, the hash-chained audit log and revocation.
- AI co-pilot work follows the MCP-first session method, with a citation register, a four-gate Citation-Acceptance check and evidence-locator rules against fabrication.
- Regulatory content brought current: PCI DSS v4.0.1 with the future-dated requirements in force since 31 March 2025, the FFIEC CAT retirement, the FTC Safeguards notification amendment, NYDFS Part 500 phase-in completed 1 November 2025, and the 2024 Regulation S-P amendments.
- Model-risk module rebuilt around SR 11-7 / OCC 2011-12 with AI models evidenced through LLMOps model cards, evaluations, fairness reports and drift monitoring.
- Nine AI role-play labs (Access Controller, Controller, Head of Model Risk, CISO, CCO, Director of Internal Audit, bank examiner and others) and a written capstone scored against a published rubric.
- A fresh LOFT exam bank replaces every v1 item; seat time is 20 hours at Practitioner level.
What you will be able to do.
- You will be able to scope and authorize a financial-services engagement with read-only access, two recorded approvals and a planned closure.
- You will be able to run AI-assisted fieldwork with the MCP session tools, a citation register and controls against mis-citation, fabrication, severity drift and out-of-scope reads.
- You will be able to obtain and verify evidence with chain of custody using Robo Compliance sealed sessions, the auditor portal and the audit log.
- You will be able to test SOX IT general controls and PCI DSS v4.0.1 requirements, including CDE scope claims based on tokenization and segmentation.
- You will be able to assess model risk under SR 11-7 / OCC 2011-12, including AI models evidenced through LLMOps governance records.
- You will be able to test GLBA safeguards, NYDFS Part 500, Regulation S-P, FINRA Rule 3110 and AML/BSA controls, including notification clocks.
- You will be able to write findings with explicit severity criteria and a remediation roadmap, and communicate them to management, committees and examiners.
Who it's for
- Compliance officers and auditors at banks, broker-dealers, investment advisers, fintechs and payment processors
- CISOs and security leads at NYDFS-regulated and GLBA-covered institutions
- Internal audit and model-risk teams at financial institutions
- Assurance and consulting professionals serving financial-services clients
- AML compliance officers and BSA teams
Not covered here
- Financial-statement audit procedures (this course covers IT general controls and compliance, not substantive audit)
- Consumer-protection regulation such as UDAAP (not covered)
- Non-US regimes such as DORA (Robo Compliance includes a DORA template; the course does not teach it)
- Conferring CPA, CISA, CIA or PCI QSA status, or issuing attestations under professional standards
9 modules, 67 lessons.
About 20 hours of learning. Open a module to see every lesson.
-
The Audit-Engagement Method on bRRAIn
bR2bR as an engagement method built from real controls, the eight zones as audit questions, evidence classes, read-only access by construction, and a full engagement setup from scope specification to closure.
- Pretest: the audit-engagement method on bRRAIn
- The bR2bR audit-engagement method: what it is and what it is not
- The eight zones from the auditor's seat
- Evidence classes: logs, configurations, decisions, models, transactions
- Read-only by construction: grants, approvals and revocation
- Setting up an engagement end to end
- Lab: Scope and authorize an engagement with the auditee
- Retrieval: 8 questions across Module 1
-
The AI Co-Pilot for Auditors
The MCP-first session method for engagement work, the four-frame prompt, citation discipline and the citation register, the five forms of mis-cited regulation, and the four-gate Citation-Acceptance check.
- Pretest: the AI co-pilot for auditors
- The AI co-pilot session: MCP-first method and the four-frame prompt
- Citation discipline: exact references, current versions, primary sources
- AI failure mode: the mis-cited regulation
- The Citation-Acceptance gate
- Lab: Run the Citation-Acceptance gate on an AI-drafted test plan
- Retrieval: 8 questions across Module 2
-
Evidence, Memory and Chain of Custody
POPE-tagged evidence, reconciling canonical claims with runtime evidence, decision records as the why, chain of custody with sealed-session verification and the audit log, and Robo Compliance from the auditor's seat.
- Pretest: evidence, memory and chain of custody
- Walking a POPE-tagged evidence corpus
- Reconciling what the organization says with what the systems show
- Decision records as the why behind a control
- Chain of custody for cited evidence
- Robo Compliance from the auditor's seat
- Lab: Negotiate the evidence room and reconcile the posture
- Retrieval: 8 questions across Module 3
-
SOX IT General Controls and PCI DSS v4.0.1
Top-down ITGC scoping and testing, deficiency evaluation, PCI DSS v4.0.1 with the future-dated requirements in force since 31 March 2025, and CDE scoping with tokenization and segmentation.
- Pretest: SOX ITGCs and PCI DSS v4.0.1
- SOX IT general controls: scope and structure
- PCI DSS v4.0.1 in 2026: structure, approaches and the requirements now in force
- Scoping the cardholder data environment, with tokenization
- ITGC testing walkthrough: from control to conclusion
- Lab: Walk ITGC and PCI results with the Controller
- Retrieval: 8 questions across the SOX ITGC and PCI DSS module
-
Model Risk Management and AI Models
SR 11-7 / OCC 2011-12 definitions, inventory and validation with effective challenge, a defensible institutional position on AI and generative models, and LLMOps governance evidence as model-risk evidence.
- Pretest: model risk management
- SR 11-7 foundations and the model inventory
- Validation and effective challenge
- Applying model-risk principles to AI and generative models
- Reading LLMOps governance evidence for model-risk work
- Lab: Model-risk review with the Head of Model Risk Management
- Retrieval: 8 questions across the model-risk module
-
GLBA, NYDFS Part 500 and Regulation S-P
Which GLBA safeguards rule applies, the FTC Safeguards Rule and its 2024 notification amendment, NYDFS Part 500 as amended with phase-in completed 1 November 2025, overlapping regimes and notification clocks, the FFIEC CAT retirement, and the 2024 Regulation S-P amendments.
- Pretest: GLBA, NYDFS Part 500 and Regulation S-P
- GLBA safeguards: which rule applies, and what it requires
- NYDFS 23 NYCRR Part 500 after the 2023 amendment
- Overlapping regimes and notification clocks
- SEC Regulation S-P: the 2024 amendments
- Lab: Incident clocks and Part 500 posture with the CISO
- Retrieval: 8 questions across the GLBA, NYDFS and Regulation S-P module
-
FINRA Supervision and AML/BSA
FINRA Rule 3110 with Rules 3120, 3130 and 3310, AML program pillars, CIP, CDD and beneficial ownership, EDD, transaction monitoring, SAR timeliness and SAR confidentiality.
- Pretest: FINRA supervision and AML
- FINRA Rule 3110: testing a broker-dealer's supervisory system
- AML program foundations: CIP, CDD, beneficial ownership and EDD
- Transaction monitoring and SAR decisions
- Lab: Supervision and AML review with the Chief Compliance Officer
- Retrieval: 8 questions across the FINRA and AML module
-
Findings, Severity and AI Failure Modes
This course's recommended seven-element finding format, a five-level severity scale with explicit criteria, and the AI failure modes of fabricated evidence, severity drift and out-of-scope reads.
- Pretest: findings, severity and AI failure modes
- Writing a finding: the seven-element format
- Severity: a five-level scale with explicit criteria
- AI failure mode: fabricated evidence
- AI failure mode: severity drift
- Out-of-scope reads: prevention, detection and response
- Lab: Catch and correct four AI failures in draft working papers
- Retrieval: 8 questions across the findings and AI failure modes module
-
Communicating Findings, Remediation and the Capstone
Findings for management, committees and examiners, remediation plans and roadmaps, what each supervisor looks for, conclusion language that matches the work, the report package and engagement closure, and the capstone.
- Pretest: communicating findings and the report package
- Communicating findings to three audiences
- Remediation plans that hold up
- What each supervisor will look for in remediation
- Conclusion language that says exactly what you know
- The report package: what you deliver and keep
- Lab: Defend your findings to a bank examiner
- Retrieval: 8 questions across the communication and reporting module
- Capstone: Pre-examination review of Harborline Bank
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · The Audit-Engagement Method on bRRAIn
AI role-play: scoping and authorizing an engagement with the auditee's Access Controller
-
Lab 2 · The AI Co-Pilot for Auditors
AI role-play: running the Citation-Acceptance gate on an AI-drafted test plan with the engagement manager
-
Lab 3 · Evidence, Memory and Chain of Custody
AI role-play: negotiating the evidence room and reconciling Robo Compliance posture with the auditee's compliance manager
-
Lab 4 · SOX IT General Controls and PCI DSS v4.0.1
AI role-play: presenting ITGC and PCI DSS scope results to the Controller
-
Lab 5 · Model Risk Management and AI Models
AI role-play: model-risk review of three models with the Head of Model Risk Management
-
Lab 6 · GLBA, NYDFS Part 500 and Regulation S-P
AI role-play: incident clocks and Part 500 posture with the CISO
-
Lab 7 · FINRA Supervision and AML/BSA
AI role-play: FINRA supervision and AML review with the Chief Compliance Officer
-
Lab 8 · Findings, Severity and AI Failure Modes
AI role-play: correcting four AI failures in draft working papers with the Director of Internal Audit
-
Lab 9 · Communicating Findings, Remediation and the Capstone
AI role-play: defending findings to a bank examiner
-
Lab 10 · Communicating Findings, Remediation and the Capstone
Written engagement report package from a complete evidence file
Pre-examination review of Harborline Bank
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 72%
Scored on
- Engagement governance and scope discipline15%
- Finding detection and evidence accuracy25%
- Regulatory application and citation integrity20%
- Severity and risk judgment15%
- Remediation roadmap15%
- Report quality and conclusion language10%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: Renewal at 3 years by passing the then-current exam
Where this course sits.
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $299 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
bR2bR Compliance Officer — Financial Services
Run governed, AI-assisted financial-services compliance reviews: SOX ITGC, PCI DSS, model risk, GLBA, NYDFS, FINRA and AML.