Credit Karma — Consumer Duty

Turning a broad regulation into product action

A wider compliance programme was already underway, but no one had audited the end-to-end member experience. In six weeks I designed a cross-functional product audit that exposed risk across teams and turned it into prioritised, owned change.

A cross-functional workshop in progress: participants around a table covered in printed journey screens and worksheets, with a facilitator annotating a whiteboard.
One of three half-day workshops, mapping member journeys across teams.

Context

A compliance programme existed, but there was no end-to-end product audit.

Approach

Audit complete services, test vulnerable circumstances and turn evidence into owned decisions.

Results

A repeatable audit and an owned backlog. Following the wider programme, account-recovery tickets fell 66%.

Context

The regulatory plan existed. The product audit did not.

Credit Karma needed to show its products were ready for the UK’s new Consumer Duty rules. The Board had approved a wider programme and Compliance had completed a gap analysis, but no method assessed the end-to-end member experience across products and teams.

The requirement

Documented evidence of Consumer Duty readiness, including avoidance of foreseeable harm, before the July 2023 deadline.

The reality

Journeys had been built piecemeal over time. No single team held a complete view of a service or the risks running through it.

I designed the product audit and turned its findings into owned action.

I focused six weeks where the risk was greatest

A full audit was not realistic, so I selected three areas with distinct member and business risks:

  • Member support. Account recovery, thin credit files and disputes drove contacts and complaints.
  • Car finance. An external provider created an unclear boundary during a consequential journey.
  • Credit cards. The largest revenue stream, offering lessons for other marketplaces.

This gave the audit meaningful breadth without reducing it to a superficial review of every screen.

Approach

I audited the service, not just the screens

An interface review would find usability problems, but not the risks created between teams, support processes, technical systems and partners.

I used disagreement as evidence

I ran three workshops, with around 50 attendances across Product, Engineering, Support, Business Development, Legal, Compliance, Risk and Security. Groups mapped the same journeys independently. Where their maps diverged, the disagreement revealed product, process and ownership risks that no individual team could see on its own.

Teams then repeated the journeys using vulnerability cards covering dyslexia, temporary impairment, English as an additional language and financial vulnerability. We assessed key content against a reading age of 11 or below.

The workshops made assumptions visible

The sessions gave each function the same member journey to interrogate, then asked them to test it against different member circumstances. That shared evidence made the gaps easier to name and harder to dismiss as isolated usability issues.

Workshop participants reviewing printed journey materials and writing notes during the Consumer Duty audit.
Participants reviewing journeys and recording risks during one of the Consumer Duty workshops.
“I’ve worked here for three years, and this is the first time I’ve looked at the product from a member’s point of view.”
Head of Legal and Compliance.

Small problems were creating larger barriers

Individually minor issues combined into journeys that were hard to recover from and unclear about where Credit Karma’s responsibility ended.

  • Account recovery: Password-reset help led to the generic Help Centre rather than relevant guidance.
  • Contacting support. Members completed a form, then learned it had not been submitted and were redirected to articles.
  • Partner journeys. Members moved from browsing to applying with another company without a clear transition.
Audit board showing credit card marketplace and dashboard screens surrounded by colour-coded sticky notes recording risks, questions and content observations.
Credit card marketplace and dashboard journeys under audit. Each note records a risk, an assumption or a piece of content that would not hold up for a member in difficulty.

The members at greatest risk were missing from our test data

Dummy QA accounts displayed every available card, while employee accounts skewed financially secure. Teams could not reproduce thin credit files, high debt, defaults or repeated declines — the very circumstances the regulation is concerned with.

I recommended representative profiles so design, engineering and compliance could test realistic risk states, not only ideal journeys.

Diagram: QA and employee test accounts cover only the strongest member circumstances, leaving thin files, high debt, defaults and repeated declines untested. What our accounts could show QA accounts Dummy data Every marketplace card shown Employee accounts Real data, but skewed Financially secure profiles What they could not Members at risk Thin files, high debt, defaults Repeated declines Recommendation: representative test profiles So teams can evaluate risk states before release, not after complaint
The gap in our test data. Teams were reviewing and approving journeys they could not experience as a member in difficulty would.

We made a hidden partner hand-off explicit without adding another click

Selecting ‘buy a car’ moved members out of a Credit Karma marketplace and into a CarFinance247 application. Similar branding obscured the hand-off at exactly the point the task changed from browsing to applying.

Business Development was concerned that another step would reduce conversion. Legal and Compliance needed the provider and the potential credit implications to be clear. Both positions were reasonable, which is what made it a design problem rather than a policy one.

Service-level audit board for the car finance journey, showing the sequence of member-facing screens across powered, screen, steps and marketing lanes with risk notes attached.
The car finance journey reconstructed across lanes — what powers each step, what the member sees, what they must do, and what marketing says. The hand-off sits in the middle, unmarked.

The workshops were not the output

Facilitation is easy to mistake for the work. I turned the findings into recommendations and a prioritised backlog, tying each issue to a potential harm and then assessing it with Design, Product, Engineering, Legal and Compliance together.

Diagram: each finding moved from evidence, to potential harm, to a risk rating, to an effort estimate, to a named owner. Evidence Potential harm Risk Effort Owner Every finding ended with a named team and a next action, not a report.
The prioritisation chain. Running it as a joint estimate separated immediate regulatory risks from longer-term improvements, and meant the ratings survived contact with the teams who had to deliver them.

This gave the Board product evidence for its readiness assessment, documented in April 2023 and reflected in the assessment that followed.

Results

Support demand fell and the audit model was reused

66%fewer account-recovery tickets
40,000fewer support contacts, approximatelyTotal support tickets fell from 59,400 between January and July 2023 to 22,000 year-to-date in 2024.
50%fewer queries passed from Member Support to TransUnion

Source: internal reporting across available periods. A £4 million equivalent can be derived by applying an internal £100-per-contact estimate, but it reflects the wider programme, is not solely attributable to this project and is not a confirmed cash saving.

What changed

The findings landed as shipped work, not recommendations

4journeys rebuiltHelp Centre navigation and content, account recovery, the contact form and the car finance hand-off.
2changes to how product work is scopedProduct briefs added ‘member outcomes’ and ‘foreseeable harm’; teams gained Compliance champions.
No.4account recovery’s rank as a support issue in 2024Down from number one in 2023.

Member outcomes became part of ongoing product decisions

Legal and Compliance recommended recurring reviews rather than relying on pre-release checks, and the method was picked up by the US organisation. The audit stopped being a deadline exercise and became a way of working.

Reflection

Looking back, the useful shift was connecting the evidence to the decision. Workshops produce observations; I made each one carry a potential harm, a risk rating, an effort estimate and a named owner, so that a regulatory obligation arrived at the teams as a prioritised backlog they had helped build rather than as a report they had to interpret.