CISI Guide

How to Pass the CISI Risk in Financial Services Exam

Pass the CISI Risk in Financial Services exam: the ten elements and their weightings, the credit, market and operational risk detail that carries the paper, and how to revise it.

7 min readUpdated June 2026By Rueben Yu

Risk in Financial Services is CISI's standalone Level 3 certificate in risk management, and it stands apart from most of the other papers Passkey covers in one respect: it isn't a unit within a larger certificate, it's a qualification in its own right. It's a recognised route into risk roles across banking, insurance and asset management, and it's widely taken outside the UK too, including across the Gulf, where risk and compliance hiring increasingly expects it. If your job involves identifying, measuring or managing risk in any of its forms, this is the paper built for you.

The exam is 100 multiple-choice questions in 120 minutes, with a 70% pass mark, which means 70 correct answers. It is computer based, with no negative marking, so answer every question, and up to 10% of the paper can be additional trial questions that don't count towards your score, used by CISI to test material for future sittings. You won't know which questions these are, so there's no way to identify or skip them; treat every question as if it counts. CISI recommends around 100 hours of study, and given the breadth of the syllabus, that estimate is not generous.

The ten elements that make up the syllabus are not evenly weighted, and the imbalance is significant enough to shape how you revise. Operational, credit and market risk between them account for 45 of the 100 marks; Model Risk, by contrast, is worth just 3. Revising in the order the workbook presents the chapters, rather than in order of weight, is one of the most common planning mistakes candidates make.

Know the weightings before you revise

The table below sets out all ten elements and their approximate share of the 100 questions. CISI notes the exact split can move by a question or two between sittings, but the shape holds: this is a paper dominated by operational, credit and market risk, with international regulation, investment and liquidity risk forming a solid second tier, and model risk, governance and enterprise risk management rounding out the paper in smaller, more precise doses.

# Element Questions
1 Principles of Risk Management 14
2 International Risk Regulation 7
3 Operational Risk 15
4 Credit Risk 15
5 Market Risk 15
6 Investment Risk 11
7 Liquidity Risk 10
8 Model Risk 3
9 Risk Oversight and Corporate Governance 5
10 Enterprise Risk Management (ERM) 5

Notice how much rides on the middle of the table. Elements 3 to 5 alone are 45 of the 100 marks, close to half the exam, and they share genuine overlap: an operational failure can trigger a credit loss, a credit event can crystallise as a market loss, and all three interact with liquidity. Study them as a connected block rather than three isolated topics, and the exam's habit of testing cause-and-effect chains between risk types stops being a trap.

What each element tests

Principles of Risk Management (14 questions). The foundation chapter, and it covers more ground than its position suggests: risk versus uncertainty, the simple risk management framework, and the external drivers of risk, economic, political, competitive, social, technological and cyber, shocks and natural events, stakeholders and third parties, and environmental, social and governance (ESG) factors. It moves on to the internal drivers, strategic, operational and financial, and to terminology the rest of the syllabus assumes you already know: risk appetite, inherent (gross) versus residual (net) risk, risk profile, risk mitigation and reputational risk. It closes with systemic risk and contagion, and the emerging territory of Fintech, Regtech, digital assets and cryptoassets.

International Risk Regulation (7 questions). The Bank for International Settlements and the Basel Committee on Banking Supervision: what each does, the three Pillars of the Basel Accord (minimum capital requirements, supervisory review and market discipline), and the Core Principles for Effective Banking Supervision. It also covers home and host state regulation for cross-border banks, the difference between statutory and principles-based regulation, and the UK's approach through the FCA's statutory objectives and its Principles for Businesses.

Operational Risk (15 questions). The Basel definition and its seven event types, internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and systems failures, and execution, delivery and process management, together with the risk management framework that identifies, measures, controls and monitors them. It covers key risk indicators, historical loss data, and the practical mitigation toolkit: controls, financial crime compliance and the three stages of money laundering, business continuity and disaster recovery, outsourcing, insurance and cyber security.

Credit Risk (15 questions). Counterparty risk, issuer risk and concentration risk, and the measurement toolkit built around them: credit exposure, credit ratings, and the expected loss formula that combines probability of default, exposure at default and loss given default. It covers the role and limitations of credit rating agencies, mitigation techniques from netting and collateral to credit default swaps and central counterparties, and the measures used to control concentration risk, including the Herfindahl-Hirschman Index.

Market Risk (15 questions). The different types of market risk, volatility, market liquidity, currency, basis, interest rate, commodity and equity risk, and the statistical toolkit used to measure them: mean, median, standard deviation, correlation, and the normal distribution. The centrepiece is Value-at-Risk, its three calculation methods (historical simulation, parametric and Monte Carlo), and the scenario analysis and stress testing that fill in what VaR cannot show.

Investment Risk (11 questions). The risks involved in generating the right return for investors: currency, interest rate, issuer, equity, commodity, property and fund liquidity risk. It covers the ratios used to judge a portfolio's performance, alpha, beta, the Sharpe ratio and the information ratio, the case for diversification and optimisation, and illiquid asset classes such as venture capital and private equity, alongside responsible investment and ESG considerations.

Liquidity Risk (10 questions). The difference between asset liquidity and funding liquidity, and the tools used to identify and measure them: the maturity ladder, liquidity gap analysis, and the key measures of market liquidity, bid-offer spread, market depth, immediacy and resilience. It covers how liquidity risk is managed day to day, through limits, scenario analysis and diversification of funding sources, with the collapse of Northern Rock as the syllabus's central illustration of what happens when it isn't.

Model Risk (3 questions). The smallest element, but a precise one: the benefits and limitations of using models, the models commonly used across operational, credit, market and liquidity risk, and the governance expected of firms that rely on them, from board oversight and validation to documentation and back testing.

Risk Oversight and Corporate Governance (5 questions). The board, the risk committee and the chief risk officer, and how risk appetite is set and cascaded through the firm. Its centrepiece is the three lines of defence, business management, the independent risk function, and internal audit, along with the factors that build a healthy risk culture and the concept of moral hazard.

Enterprise Risk Management (5 questions). How firms aggregate credit, market, operational and liquidity risk into a single, firm-wide view, why Basel's Pillar 2 has driven firms towards it, and the practical challenges of doing it well: exception-based escalation, data aggregation across inconsistent measurement approaches and timescales, and building genuine accountability.

Where people slip

The first trap is treating the ten elements as ten equal topics. They aren't. Spending as long revising Model Risk, worth 3 marks, as Credit Risk, worth 15, is one of the biggest inefficiencies candidates build into their own plans.

The second is the quantitative material in Market Risk. Mean, median, standard deviation, correlation and the three approaches to Value-at-Risk are not conceptually hard, but they are unfamiliar to candidates who haven't touched statistics since school, and questions like to test the calculation itself, not just the definition. The credit risk formulas, expected loss as the product of probability of default, exposure at default and loss given default, and the Herfindahl-Hirschman Index for concentration risk, cause the same problem for the same reason: they look abstract until you have actually worked through a few by hand.

The third is the boundary between risk types. An IT failure is operational risk, but if it causes a breach of a market risk limit, or a missed payment that damages the firm's credit standing, the exam expects you to trace the chain, not just label the first event. The syllabus is explicit that operational, credit and market risk move together, and questions are written to test whether you can follow a scenario through more than one risk type.

The fourth is dismissing the small elements late in revision. Model Risk, Risk Oversight and Corporate Governance, and Enterprise Risk Management are worth 13 marks combined, roughly the same as Liquidity Risk on its own, and their content is precise rather than broad: the three lines of defence, the definition of model risk, the drivers behind ERM. Treating them as footnotes gives away marks that are genuinely easy to secure.

How to revise it

Weight your hours to the marks, not the page count. Operational, credit and market risk between them are 45 of the 100 questions and deserve close to half your revision time; international regulation, investment risk and liquidity risk form a solid second tier; and model risk, governance and ERM, while individually small, add up to more than liquidity risk alone and reward a focused final pass.

Treat the calculations as a skill to drill, not a concept to read about. Work through expected loss, netting, the Herfindahl-Hirschman Index, the Sharpe and information ratios, and at least one worked example of each VaR method, until you could reproduce the method under exam pressure, not just recognise it on the page.

Study the interconnections deliberately. When you revise operational risk, note where it can trigger a credit or market loss; when you revise credit risk, note the liquidity consequences of a downgrade. The workbook draws these links explicitly and the exam tests them, so build them into your notes from the first pass rather than trying to bolt them on later.

Finish with timed, weighted mock papers rather than more re-reading. A 100-question, 120-minute mock built to the real weightings will surface which of the ten elements is actually weak, as opposed to which one merely feels unfamiliar. Book the exam once you are clearing 70% comfortably across more than one.

Drill it for free. Try a set of free Risk in Financial Services practice questions, or take the free diagnostic to see which elements need the most work. For the full method, see the complete guide to passing your CISI exams.

Hunting for past papers? Read Risk in Financial Services past papers: what actually exists.

Frequently asked questions

How many questions are on the CISI Risk in Financial Services exam?

100 multiple-choice questions in 120 minutes, with a 70% pass mark, so you need 70 correct answers. It is computer based with no negative marking, and up to 10% of the paper can be additional, unscored trial questions used to test material for future sittings, so answer every question.

Which element should I revise most?

Operational, Credit and Market risk. Together they are 45 of the 100 questions, easily the largest share of the paper, and their content overlaps heavily, an operational failure can trigger a credit loss that shows up as a market loss. International Risk Regulation, Investment Risk and Liquidity Risk form a solid second tier, and Model Risk, Governance and ERM, while small individually, are worth revising properly precisely because their content is so precise and quick to master.

How long does it take to prepare for the CISI Risk in Financial Services exam?

CISI recommends around 100 hours of study. Given how wide the syllabus is, that figure is realistic rather than generous, and it is best spread across all ten elements in proportion to their weighting rather than crammed into the final fortnight.

Which workbook edition should I be studying from?

Edition 11, published May 2024, which is valid for exams sat up to 10 August 2026. If you are working from older notes or a secondhand PDF, check it matches this edition, particularly for the regulatory detail in International Risk Regulation and the emerging-risk material in Principles of Risk Management, both of which move between editions.

Written by

Rueben Yu · Markets professional, CISI candidate

Rueben works in capital markets and is sitting the CISI exams himself. Every Passkey guide is written from the inside, against the current syllabus and current UK regulation.

Find your weak spots before exam day.

Start free with chapter 1 of every exam, take the free diagnostic to see where you stand, then unlock everything for one payment of £59, backed by our 80% mock guarantee.

Start free — chapter 1 of every examSee the £59 offer

Keep reading