CISI Guide

How to Pass the CISI Global Financial Compliance Exam

Pass the CISI Global Financial Compliance exam: the five elements and their weightings, the financial crime and ethics detail that trips people, and how to revise.

7 min readUpdated June 2026By Rueben Yu

The CISI Certificate in Global Financial Compliance is a Level 3 qualification for compliance officers, financial crime analysts, MLROs and regulatory professionals working across borders rather than in any one jurisdiction's rulebook. It sits within CISI's compliance pathway, and unlike papers built mainly around UK regulation, its frame of reference is genuinely international: the same firm might answer to the FCA, the SEC and a Middle Eastern regulator in the same week, and this exam tests whether you can hold all three in your head at once.

The exam is 100 multiple-choice questions in 120 minutes, with a 70% pass mark, which means 70 correct answers. It is computer based, with no negative marking, so answer every question, and up to 10% of the paper can be additional trial questions that are not scored, though you will not know which ones. CISI recommends around 100 hours of study, spread across a syllabus that runs from the mechanics of regulation to the ethics of a boardroom.

Candidates typically come from compliance, financial crime, risk and legal functions at banks, asset managers, insurers and corporates with international operations, alongside people moving into compliance from operations or audit. The paper rewards breadth: it expects you to move comfortably between the international regulatory environment, the practical running of a compliance function, the detection and prevention of financial crime, professional ethics, and governance, often within the same sitting.

Know the weightings before you revise

The 100 questions span five elements, and the split is closer than on some CISI papers, which changes how you should plan your revision.

# Element Questions
1 The International Regulatory Environment 20
2 The Compliance Function 24
3 Managing the Risk of Financial Crime 20
4 Ethics, Integrity and Fairness 19
5 Governance, Risk Management and Compliance 17

The Compliance Function is the single heaviest element at 24 of the 100 marks, and it is worth the extra attention. But there is no small element here to write off: even Governance, Risk Management and Compliance at 17 questions sits close behind the rest. Unlike a paper with one dominant topic and a token afterthought, this one is evenly demanding across all five, so a revision plan that neglects any element is giving away marks unnecessarily.

What each element tests

The International Regulatory Environment (20 questions). Why regulation exists and the trade-off between rules-based and principles-based approaches, models of self-regulation and self-regulatory organisations, and the regulation of faith- and ethical-based finance, including Shariah-compliant standards set by bodies such as AAOIFI and the IFSB. The bulk of the element is the extra-territorial reach of legislation: GDPR, MiFID II and MiFIR, the Market Abuse Regulation, EMIR, PSD2, Sarbanes-Oxley, CSDR, the UK Bribery Act, the US Foreign Corrupt Practices Act, FATCA, the EU's Anti-Money Laundering Directives and the Common Reporting Standard. It closes with exchanges, MTFs, OTFs and systematic internalisers, OTC derivatives and the post-crisis reforms, and how regulators approach FinTech, from distributed ledger technology to robo-advice.

The Compliance Function (24 questions). The heaviest element, and the most operational. The Basel Committee's ten principles on compliance, the responsibilities of the board and senior management, the compliance manual, and what makes a compliance function genuinely effective rather than a box-ticking exercise. It covers the compliance monitoring programme in detail, including how firms score risk events for financial impact, exposure and probability, plus the practical implications of outsourcing, capital requirements and variations of permission. The three lines of defence sit here too, along with how compliance trains staff, deals with individual non-compliance, and manages the relationship with the regulator.

Managing the Risk of Financial Crime (20 questions). Money laundering and terrorist financing, and the three stages every candidate needs cold: placement, layering and integration. The role of international agencies (the UNODC, IMF, World Bank and, above all, the FATF and its 40 Recommendations), predicate offences such as fraud, embezzlement, bribery and corruption, and the ways firms are exploited, from Ponzi schemes and boiler rooms to offshore trusts, beneficial ownership and cybercrime. It finishes with tax evasion versus tax avoidance, dual criminality and extradition, the role of the MLRO, and sanctions screening and politically exposed persons.

Ethics, Integrity and Fairness (19 questions). How ethical principles apply in financial services, including professional codes such as the CISI's own Code of Conduct, also known as the Lord George Principles, and the CFA Institute's Code of Ethics. It covers self-interest, fiduciary duty and the role of the agent, then moves into market integrity: inside information and insider dealing, Chinese walls, insider lists, watch and restricted lists, personal account dealing, gifts and entertainment, and conflicts of interest, plus the importance of whistleblowing. The element closes with fair conduct and fair dealing, including the regulator's customer-outcome framework, and environmental, social and governance considerations.

Governance, Risk Management and Compliance (17 questions). Corporate governance, from the OECD's principles through to the BCBS's principles for enhancing corporate governance in banks, board structures (unitary versus dual, or two-tier), and the practical difference between matrix and silo organisational models. The risk half of the element covers external sources of business risk (economic, political, competitive, technological) and internal sources (strategic, operational, financial), how firms assess and rank risk, risk appetite, and the risk register, before defining compliance risk itself and how technology, including RegTech, is changing how it is managed.

Where people slip

The first trap is treating the five elements as separate silos when the exam does not. The three lines of defence, the role of the MLRO, and sanctions and PEP screening are introduced in one element but assumed knowledge in the others. Learn each element in isolation and you will be caught out by a question in Governance that quietly depends on something from Financial Crime.

The second is the sheer density of named legislation in Element 1. GDPR, MiFID II/MiFIR, MAR, EMIR, PSD2, SOX, CSDR, the UK Bribery Act, the FCPA, the AMLDs, FATCA and CRS all appear within a few pages of the workbook, and it is tempting to skim them as a list of acronyms. The exam tests what each one actually does and to whom it applies extra-territorially, not just the name, so build yourself a short table of scope, purpose and penalty for each and drill it.

The third is the money laundering stages. Placement, layering and integration sound simple until a question describes a specific transaction and asks which stage it represents, and which type of firm is most exposed to it. Layering is the one most candidates under-prepare for, since it is the stage that looks most like ordinary client activity.

The fourth is confusing ethics with compliance. The workbook is precise about the difference between a code of ethics and a code of conduct, and about which named principles belong to which body: the CISI's Lord George Principles are not the CFA Institute's Code of Ethics, and the exam will ask you to tell them apart.

Finally, do not assume any element is safe to under-revise. With the weightings this close, a candidate who masters Financial Crime and Ethics but skims Governance can still fail on a shortfall in the smallest element, because 17 questions is still 17% of the paper.

How to revise it

Split your roughly 100 hours across the five elements in something close to their weightings, with a little extra time on The Compliance Function since it carries the most marks. Learn the frameworks that recur first, the three lines of defence, the BCBS's ten compliance principles, the FATF's 40 Recommendations, and the three stages of money laundering, before the detail around them, since everything else hangs off these structures.

Treat the extra-territorial reach section as deliberate memory work: a table of each regulation's origin, scope and penalty, drilled little and often, will do more for you than another read of the chapter. Do the same for the named ethical codes and the sanctions and PEP definitions, since both reward precision over general recollection.

Above all, revise by being tested rather than by rereading. This is a broad, detail-heavy paper, and the gap between recognising a term and knowing it cold only shows up under exam conditions. Finish your preparation with timed 100-question mocks weighted like the real paper, and book your sitting once you are clearing 70% comfortably on more than one.

Drill it for free. Try a set of free Global Financial Compliance practice questions, or take the free diagnostic to see which elements need the most work. For the money laundering stages in more depth, see placement, layering and integration explained, and for the full method, see the complete guide to passing your CISI exams.

Hunting for past papers? Read Global Financial Compliance past papers: what actually exists.

Frequently asked questions

How many questions are on the CISI Global Financial Compliance exam?

100 multiple-choice questions in 120 minutes, with a 70% pass mark, so you need 70 correct answers. It is computer based with no negative marking, so answer every question, and up to 10% of the paper may be additional unscored trial questions.

Who should sit the Global Financial Compliance exam?

It's aimed at compliance officers, financial crime analysts, MLROs, and risk and legal professionals working across more than one jurisdiction. It's a Level 3 qualification that sits within CISI's compliance pathway, and it suits candidates whose role has an international reach rather than a single domestic rulebook.

How long does it take to prepare for the Global Financial Compliance exam?

CISI recommends around 100 hours of study. Because the five elements carry similar weightings, from 17 to 24 questions each, it pays to spread your time across all of them rather than concentrating on one or two, with a little extra on The Compliance Function since it carries the most marks.

Which element should I revise most?

The Compliance Function. At 24 of the 100 questions it's the single heaviest element, covering how a compliance function actually operates day to day, from monitoring programmes to managing the regulator relationship. That said, the five elements are weighted closely (20, 24, 20, 19 and 17 questions), so no element is safe to skip.

Written by

Rueben Yu · Markets professional, CISI candidate

Rueben works in capital markets and is sitting the CISI exams himself. Every Passkey guide is written from the inside, against the current syllabus and current UK regulation.

Find your weak spots before exam day.

Start free with chapter 1 of every exam, take the free diagnostic to see where you stand, then unlock everything for one payment of £59, backed by our 80% mock guarantee.

Start free — chapter 1 of every examSee the £59 offer

Keep reading