Get the iPhone app
CISI Guide

How to Pass the CISI Risk in Financial Services Exam

Pass the CISI Risk in Financial Services exam: the ten elements and their weightings, the credit, market and operational risk detail that carries the paper, and how to revise it.

7 min readUpdated 13 August 2026
Sit the free 100-question Risk in Financial Services mock120 minutes, weighted like the real paper, scored instantly. No account.

What is the CISI Risk in Financial Services exam?

Risk in Financial Services is CISI's standalone Level 3 Award in risk management. It can also be combined with a CISI regulatory exam to complete the Level 3 Certificate in Risk in Financial Services, or taken as part of the Investment Operations Certificate. The exam is 100 multiple-choice questions in 120 minutes with a 70% pass mark, so you need 70 correct answers, computer based with no negative marking. Ten syllabus elements are covered; Operational, Credit and Market Risk together account for 45 of the 100 marks.

Format
100 multiple-choice questions, 120 minutes, 70% to pass, which is 70 correct answers
Trial questions
Up to 10% of the paper can be unscored trial questions, and you cannot tell which
Syllabus elements
Ten: 14, 7, 15, 15, 15, 11, 10, 3, 5 and 5 questions respectively
Heaviest areas
Operational Risk, Credit Risk and Market Risk, 15 questions each, 45 of the 100 marks
Smallest element
Model Risk, 3 questions
Workbook edition
Use the edition assigned to your booked sitting; CISI introduced a revised syllabus for exams from 11 August 2026
Study time
CISI recommends around 100 hours
Who sits it
People in risk roles across banking, insurance and asset management, including widely across the Gulf

Risk in Financial Services is CISI's standalone Level 3 Award in risk management. It can also be combined with a CISI regulatory exam to complete the Level 3 Certificate in Risk in Financial Services, or taken as part of the Investment Operations Certificate. It's a recognised route into risk roles across banking, insurance and asset management, and it's widely taken outside the UK too, including across the Gulf, where risk and compliance hiring increasingly expects it. If your job involves identifying, measuring or managing risk in any of its forms, this is the paper built for you.

Risk in Financial Services exam format at a glanceFour figures describing the paper: 100 multiple-choice questions, 120 minutes to answer them, a pass mark of 70 per cent which is 70 correct answers, and 10 syllabus elements. That works out at about 72 seconds per question.100questions120 minon the clock70%70 correct10syllabus elements
100 questions in two hours is roughly 72 seconds each: comfortable if you know the material cold, and tight if you are still reasoning every question out from first principles.

The exam is 100 multiple-choice questions in 120 minutes, with a 70% pass mark, which means 70 correct answers. It is computer based, with no negative marking, so answer every question, and up to 10% of the paper can be additional trial questions that don't count towards your score, used by CISI to test material for future sittings. You won't know which questions these are, so there's no way to identify or skip them; treat every question as if it counts. CISI recommends around 100 hours of study, and given the breadth of the syllabus, that estimate is not generous.

The ten elements that make up the syllabus are not evenly weighted, and the imbalance is significant enough to shape how you revise. Operational, credit and market risk between them account for 45 of the 100 marks; Model Risk, by contrast, is worth just 3. Revising in the order the workbook presents the chapters, rather than in order of weight, is one of the most common planning mistakes candidates make.

Know the weightings before you revise

The table below sets out all ten elements and their approximate share of the 100 questions. CISI notes the exact split can move by a question or two between sittings, but the shape holds: this is a paper dominated by operational, credit and market risk, with international regulation, investment and liquidity risk forming a solid second tier, and model risk, governance and enterprise risk management rounding out the paper in smaller, more precise doses.

# Element Questions
1 Principles of Risk Management 14
2 International Risk Regulation 7
3 Operational Risk 15
4 Credit Risk 15
5 Market Risk 15
6 Investment Risk 11
7 Liquidity Risk 10
8 Model Risk 3
9 Risk Oversight and Corporate Governance 5
10 Enterprise Risk Management (ERM) 5
Question weighting by syllabus element, Risk in Financial ServicesHorizontal bar chart of how the 100 questions are split across 10 syllabus elements. Principles of Risk Management 14, International Risk Regulation 7, Operational Risk 15, Credit Risk 15, Market Risk 15, Investment Risk 11, Liquidity Risk 10, Model Risk 3, Risk Oversight and Corporate Governance 5, Enterprise Risk Management (ERM) 5. The 4 heaviest elements are Principles of Risk Management, Operational Risk, Credit Risk and Market Risk, carrying 59 of the 100 marks between them.QUESTIONS PER ELEMENT · 100 TOTAL1 Principles of Risk Management142 International Risk Regulation73 Operational Risk154 Credit Risk155 Market Risk156 Investment Risk117 Liquidity Risk108 Model Risk39 Risk Oversight and Corporate Governance510 Enterprise Risk Management (ERM)5Shaded bars: Principles of Risk Management, Operational Risk, Credit Risk and Market Risk. 59...
The 100 questions are not spread evenly. Principles of Risk Management, Operational Risk, Credit Risk and Market Risk carry 59 of the 100 marks between them, so 4 of the 10 elements decide 59% of your result. Weight your revision hours the same way.

Notice how much rides on the middle of the table. Elements 3 to 5 alone are 45 of the 100 marks, close to half the exam, and they share genuine overlap: an operational failure can trigger a credit loss, a credit event can crystallise as a market loss, and all three interact with liquidity. Study them as a connected block rather than three isolated topics, and the exam's habit of testing cause-and-effect chains between risk types stops being a trap.

Test yourself on Risk in Fin. Services

4 questions written to the current syllabus, in the format of the real paper. Pick an answer and the explanation appears. Nothing to sign up for.

Question 1Principles of Risk Management

Combining separate credit, market, liquidity and operational risk reports into one succinct firm-wide report best illustrates:

Not quite. The answer is B.

Enterprise risk management gives senior management a succinct, firm-wide view of all key risk information, much as a balance sheet gives a focused view of finances, so that balanced decisions can be taken across risk types. Risk appetite setting concerns how much risk to accept rather than how risk information is reported. Business process analysis examines individual processes and the factors influencing them, and the 'use test' concerns whether risk models are genuinely used in decision-making.

Question 2International Risk Regulation

Where is the Bank for International Settlements headquartered, and in what year was it established?

Not quite. The answer is B.

The BIS was established in 1930 and is headquartered in Basel, Switzerland, making it the world's oldest international regulatory organisation, often called the 'regulators' regulator'. The other cities and dates relate to different institutions, such as the Bretton Woods conference or the Federal Reserve's founding.

Question 3Operational Risk

Which of the following is explicitly included within the Basel Committee's definition of operational risk?

Not quite. The answer is A.

The Basel definition expressly includes legal risk, such as fines, penalties and private settlements. Reputational risk is expressly excluded from the definition, even though it is a common consequence of an operational risk event. Market risk and strategic risk are separate risk categories entirely.

Question 4Credit Risk

The party that owes a financial obligation within a credit risk relationship is termed the:

Not quite. The answer is B.

The party with the financial obligation is termed the obligor. A guarantor is a separate third party who steps in only if the obligor cannot pay, an originator is the firm whose assets are being securitised, and a protection seller is a specific role within a credit default swap, none of which describe the obligor itself.

That is 4 of more than 10,800 questions in the PasskeyPrep bank. Chapter 1 of every exam is free, with the study notes and flashcards that go with it, and every answer is marked and explained the way these were.

Open chapter 1 freeMore free questions on Risk in Fin. Services
Sit the free 100-question Risk in Financial Services mock120 minutes, weighted like the real paper, scored instantly. No account.

What each element tests

Principles of Risk Management (14 questions)

The foundation chapter, and it covers more ground than its position suggests: risk versus uncertainty, the simple risk management framework, and the external drivers of risk, economic, political, competitive, social, technological and cyber, shocks and natural events, stakeholders and third parties, and environmental, social and governance (ESG) factors. It moves on to the internal drivers, strategic, operational and financial, and to terminology the rest of the syllabus assumes you already know: risk appetite, inherent (gross) versus residual (net) risk, risk profile, risk mitigation and reputational risk. It closes with systemic risk and contagion, and the emerging territory of Fintech, Regtech, digital assets and cryptoassets.

International Risk Regulation (7 questions)

The Bank for International Settlements and the Basel Committee on Banking Supervision: what each does, the three Pillars of the Basel Accord (minimum capital requirements, supervisory review and market discipline), and the Core Principles for Effective Banking Supervision. It also covers home and host state regulation for cross-border banks, the difference between statutory and principles-based regulation, and the UK's approach through the FCA's statutory objectives and its Principles for Businesses.

Operational Risk (15 questions)

The Basel definition and its seven event types, internal fraud, external fraud, employment practices and workplace safety, clients, products and business practices, damage to physical assets, business disruption and systems failures, and execution, delivery and process management, together with the risk management framework that identifies, measures, controls and monitors them. It covers key risk indicators, historical loss data, and the practical mitigation toolkit: controls, financial crime compliance and the three stages of money laundering, business continuity and disaster recovery, outsourcing, insurance and cyber security.

Credit Risk (15 questions)

Counterparty risk, issuer risk and concentration risk, and the measurement toolkit built around them: credit exposure, credit ratings, and the expected loss formula that combines probability of default, exposure at default and loss given default. It covers the role and limitations of credit rating agencies, mitigation techniques from netting and collateral to credit default swaps and central counterparties, and the measures used to control concentration risk, including the Herfindahl-Hirschman Index.

Market Risk (15 questions)

The different types of market risk, volatility, market liquidity, currency, basis, interest rate, commodity and equity risk, and the statistical toolkit used to measure them: mean, median, standard deviation, correlation, and the normal distribution. The centrepiece is Value-at-Risk, its three calculation methods (historical simulation, parametric and Monte Carlo), and the scenario analysis and stress testing that fill in what VaR cannot show.

Investment Risk (11 questions)

The risks involved in generating the right return for investors: currency, interest rate, issuer, equity, commodity, property and fund liquidity risk. It covers the ratios used to judge a portfolio's performance, alpha, beta, the Sharpe ratio and the information ratio, the case for diversification and optimisation, and illiquid asset classes such as venture capital and private equity, alongside responsible investment and ESG considerations.

Liquidity Risk (10 questions)

The difference between asset liquidity and funding liquidity, and the tools used to identify and measure them: the maturity ladder, liquidity gap analysis, and the key measures of market liquidity, bid-offer spread, market depth, immediacy and resilience. It covers how liquidity risk is managed day to day, through limits, scenario analysis and diversification of funding sources, with the collapse of Northern Rock as the syllabus's central illustration of what happens when it isn't.

Model Risk (3 questions)

The smallest element, but a precise one: the benefits and limitations of using models, the models commonly used across operational, credit, market and liquidity risk, and the governance expected of firms that rely on them, from board oversight and validation to documentation and back testing.

Risk Oversight and Corporate Governance (5 questions)

The board, the risk committee and the chief risk officer, and how risk appetite is set and cascaded through the firm. Its centrepiece is the three lines of defence, business management, the independent risk function, and internal audit, along with the factors that build a healthy risk culture and the concept of moral hazard.

Enterprise Risk Management (5 questions)

How firms aggregate credit, market, operational and liquidity risk into a single, firm-wide view, why Basel's Pillar 2 has driven firms towards it, and the practical challenges of doing it well: exception-based escalation, data aggregation across inconsistent measurement approaches and timescales, and building genuine accountability.

Where people slip

The first trap is treating the ten elements as ten equal topics. They aren't. Spending as long revising Model Risk, worth 3 marks, as Credit Risk, worth 15, is one of the biggest inefficiencies candidates build into their own plans.

The second is the quantitative material in Market Risk. Mean, median, standard deviation, correlation and the three approaches to Value-at-Risk are not conceptually hard, but they are unfamiliar to candidates who haven't touched statistics since school, and questions like to test the calculation itself, not just the definition. The credit risk formulas, expected loss as the product of probability of default, exposure at default and loss given default, and the Herfindahl-Hirschman Index for concentration risk, cause the same problem for the same reason: they look abstract until you have actually worked through a few by hand.

The third is the boundary between risk types. An IT failure is operational risk, but if it causes a breach of a market risk limit, or a missed payment that damages the firm's credit standing, the exam expects you to trace the chain, not just label the first event. The syllabus is explicit that operational, credit and market risk move together, and questions are written to test whether you can follow a scenario through more than one risk type.

The fourth is dismissing the small elements late in revision. Model Risk, Risk Oversight and Corporate Governance, and Enterprise Risk Management are worth 13 marks combined, roughly the same as Liquidity Risk on its own, and their content is precise rather than broad: the three lines of defence, the definition of model risk, the drivers behind ERM. Treating them as footnotes gives away marks that are genuinely easy to secure.

How to revise it

Weight your hours to the marks, not the page count. Operational, credit and market risk between them are 45 of the 100 questions and deserve close to half your revision time; international regulation, investment risk and liquidity risk form a solid second tier; and model risk, governance and ERM, while individually small, add up to more than liquidity risk alone and reward a focused final pass.

Treat the calculations as a skill to drill, not a concept to read about. Work through expected loss, netting, the Herfindahl-Hirschman Index, the Sharpe and information ratios, and at least one worked example of each VaR method, until you could reproduce the method under exam pressure, not just recognise it on the page.

Study the interconnections deliberately. When you revise operational risk, note where it can trigger a credit or market loss; when you revise credit risk, note the liquidity consequences of a downgrade. The workbook draws these links explicitly and the exam tests them, so build them into your notes from the first pass rather than trying to bolt them on later.

Finish with timed, weighted mock papers rather than more re-reading. A 100-question, 120-minute mock built to the real weightings will surface which of the ten elements is actually weak, as opposed to which one merely feels unfamiliar. Use repeated full, timed mock results alongside your timetable, confidence and remaining weak areas when deciding whether to book; no mock score can predict an individual result.

Drill it for free. Try a set of free Risk in Financial Services practice questions. For the full method, see the complete guide to passing your CISI exams.

Hunting for past papers? Read Risk in Financial Services past papers: what actually exists.

Sit a whole paper for free. The free 100-question Risk in Financial Services mock exam runs to the real time limit and the published element weighting, with a score, an element breakdown and an explanation for every answer. No sign-up.

Frequently asked questions

How many questions are on the CISI Risk in Financial Services exam?

100 multiple-choice questions in 120 minutes, with a 70% pass mark, so you need 70 correct answers. It is computer based with no negative marking, and up to 10% of the paper can be additional, unscored trial questions used to test material for future sittings, so answer every question.

Which element should I revise most?

Operational, Credit and Market risk. Together they are 45 of the 100 questions, easily the largest share of the paper, and their content overlaps heavily, an operational failure can trigger a credit loss that shows up as a market loss. International Risk Regulation, Investment Risk and Liquidity Risk form a solid second tier, and Model Risk, Governance and ERM, while small individually, are worth revising properly precisely because their content is so precise and quick to master.

How long does it take to prepare for the CISI Risk in Financial Services exam?

CISI recommends around 100 hours of study. Given how wide the syllabus is, that figure is realistic rather than generous, and it is best spread across all ten elements in proportion to their weighting rather than crammed into the final fortnight.

Which workbook edition should I be studying from?

Use the workbook edition assigned to your booked sitting in My Study. CISI introduced a revised syllabus for exams from 11 August 2026, so Edition 11 material only applies to earlier sittings. Check any notes or secondhand PDFs against the edition for your exam date.

Written by

Rueben Yu · Founder · passed all three CISI Capital Markets Programme papers

Rueben passed UK Financial Regulation, Securities and Derivatives, completing both UK CISI Capital Markets Programme routes, and prepared for all three with PasskeyPrep. He works in project finance and writes every guide from the inside, against the current syllabus and current UK regulation. How he passed, and why he built this

Reading is not revision. Being tested is.

Chapter 1 of every supported exam is free, with no card. When you are ready for the whole paper it is one payment, not a subscription.

0+exam-style questions
0CISI papers covered
0days for one payment

Pass guarantee: average 80% or more across your last three PasskeyPrep mocks, sit the real exam within 30 days and fail, and you are refunded. Full terms.

Keep reading