Context
The regulatory plan existed. The product audit did not.
Credit Karma needed to show its products were ready for the UK’s new Consumer Duty rules. The Board had approved a wider programme and Compliance had completed a gap analysis, but no method assessed the end-to-end member experience across products and teams.
The requirement
Documented evidence of Consumer Duty readiness, including avoidance of foreseeable harm, before the July 2023 deadline.
The reality
Journeys had been built piecemeal over time. No single team held a complete view of a service or the risks running through it.
I designed the product audit and turned its findings into owned action.
I focused six weeks where the risk was greatest
A full audit was not realistic, so I selected three areas with distinct member and business risks:
- Member support. Account recovery, thin credit files and disputes drove contacts and complaints.
- Car finance. An external provider created an unclear boundary during a consequential journey.
- Credit cards. The largest revenue stream, offering lessons for other marketplaces.
This gave the audit meaningful breadth without reducing it to a superficial review of every screen.
Approach
I audited the service, not just the screens
An interface review would find usability problems, but not the risks created between teams, support processes, technical systems and partners.
I used disagreement as evidence
I ran three workshops, with around 50 attendances across Product, Engineering, Support, Business Development, Legal, Compliance, Risk and Security. Groups mapped the same journeys independently. Where their maps diverged, the disagreement revealed product, process and ownership risks that no individual team could see on its own.
Teams then repeated the journeys using vulnerability cards covering dyslexia, temporary impairment, English as an additional language and financial vulnerability. We assessed key content against a reading age of 11 or below.
The workshops made assumptions visible
The sessions gave each function the same member journey to interrogate, then asked them to test it against different member circumstances. That shared evidence made the gaps easier to name and harder to dismiss as isolated usability issues.
“I’ve worked here for three years, and this is the first time I’ve looked at the product from a member’s point of view.”
Small problems were creating larger barriers
Individually minor issues combined into journeys that were hard to recover from and unclear about where Credit Karma’s responsibility ended.
- Account recovery: Password-reset help led to the generic Help Centre rather than relevant guidance.
- Contacting support. Members completed a form, then learned it had not been submitted and were redirected to articles.
- Partner journeys. Members moved from browsing to applying with another company without a clear transition.
The members at greatest risk were missing from our test data
Dummy QA accounts displayed every available card, while employee accounts skewed financially secure. Teams could not reproduce thin credit files, high debt, defaults or repeated declines — the very circumstances the regulation is concerned with.
I recommended representative profiles so design, engineering and compliance could test realistic risk states, not only ideal journeys.
We made a hidden partner hand-off explicit without adding another click
Selecting ‘buy a car’ moved members out of a Credit Karma marketplace and into a CarFinance247 application. Similar branding obscured the hand-off at exactly the point the task changed from browsing to applying.
Business Development was concerned that another step would reduce conversion. Legal and Compliance needed the provider and the potential credit implications to be clear. Both positions were reasonable, which is what made it a design problem rather than a policy one.
The workshops were not the output
Facilitation is easy to mistake for the work. I turned the findings into recommendations and a prioritised backlog, tying each issue to a potential harm and then assessing it with Design, Product, Engineering, Legal and Compliance together.
This gave the Board product evidence for its readiness assessment, documented in April 2023 and reflected in the assessment that followed.
Results
Support demand fell and the audit model was reused
Source: internal reporting across available periods. A £4 million equivalent can be derived by applying an internal £100-per-contact estimate, but it reflects the wider programme, is not solely attributable to this project and is not a confirmed cash saving.
What changed
The findings landed as shipped work, not recommendations
Member outcomes became part of ongoing product decisions
Legal and Compliance recommended recurring reviews rather than relying on pre-release checks, and the method was picked up by the US organisation. The audit stopped being a deadline exercise and became a way of working.
Reflection
Looking back, the useful shift was connecting the evidence to the decision. Workshops produce observations; I made each one carry a potential harm, a risk rating, an effort estimate and a named owner, so that a regulatory obligation arrived at the teams as a prioritised backlog they had helped build rather than as a report they had to interpret.