CISI Risk in Financial Services: Common Mistakes That Cost You the Pass Mark
The most common, avoidable mistakes candidates make preparing for and sitting the CISI Risk in Financial Services exam, and how to avoid them.
Most candidates who fail the CISI Risk in Financial Services exam do not fail because they didn't study, they fail because of a small number of recurring, avoidable mistakes in how they prepared or how they approached the exam itself. This article covers the most common ones, based on patterns that show up repeatedly across candidates.
Mistake 1: Treating Regulation as Background Reading
International Risk Regulation is one of the most heavily weighted topics on the exam, but it is also the one candidates most often under-prepare for, treating it as contextual knowledge rather than core, testable material.
The fix is straightforward: study the regulatory topic with the same intensity as operational or credit risk. Know the specific roles of the FCA and PRA, understand SM&CR in detail, and be able to identify which regulatory body or regime applies in a given scenario, not just recognise the names.
Mistake 2: Studying Topics in Isolation
Because the syllabus is organised into ten distinct topic areas, candidates often study them as separate, disconnected blocks. In practice, the exam frequently tests how topics relate to each other: how liquidity risk connects to market risk during a crisis, or how operational risk events trigger governance and reporting obligations.
Building connections between topics as you study, rather than treating each one as a closed unit, makes scenario-based questions significantly easier, since these questions often require recognising which of several related risk types is actually the right answer.
Mistake 3: Skipping the Practice Exam
Candidates who study the material thoroughly but never sit a full practice exam under timed conditions are consistently more likely to underperform relative to their actual knowledge. The exam format itself, 100 questions in 2 hours, roughly 1.2 minutes per question, takes adjustment, and that adjustment is best made before the real exam, not during it.
A full practice exam also reveals which topics need more review in a way that passive reading does not. Getting a question wrong under timed pressure is a more accurate signal of readiness than feeling confident while reading notes.
Mistake 4: Answering Slowly on Familiar Topics
With 100 questions and 2 hours, time management matters more than candidates expect. A common pattern is spending too long second-guessing answers on topics the candidate actually knows well, leaving insufficient time for the questions later in the exam, which are not weighted any differently but get rushed as a result.
Since there is no negative marking, the better approach is to answer confidently and move on for topics you know well, saving deliberation time for genuinely uncertain questions, and flagging anything you're unsure about to revisit if time allows at the end.
Mistake 5: Memorising Definitions Without Application
Candidates sometimes prepare by memorising textbook definitions of each risk type without practising how those definitions apply to specific scenarios. The exam rarely asks for a definition directly; it more often presents a situation and asks which risk type, regulatory requirement, or governance structure applies.
The more effective preparation method is working through scenario-based questions throughout study, not just at the end, so that applying knowledge becomes as familiar as recalling it.
Mistake 6: Underestimating Model Risk and Enterprise Risk Management
These two topics are newer additions to many candidates' general risk knowledge compared to more familiar areas like credit or market risk, and they are often the most neglected during study as a result. Both are fully testable and carry meaningful weight in the exam.
If your professional background does not naturally cover model governance or enterprise-wide risk frameworks, allow proportionally more study time for these two areas rather than assuming general risk experience covers them.
Mistake 7: Not Checking Readiness Before Booking
Some candidates book their exam date before confirming, through practice questions, that they are consistently scoring above the 70% pass mark across the full syllabus, not just in their strongest topics. Booking too early creates unnecessary pressure and increases the likelihood of needing a resit.
A more reliable approach is using practice performance as the trigger for booking, rather than a fixed calendar date decided before study even begins.
The Common Thread
Most of these mistakes come down to the same underlying issue: treating the exam as a recall test rather than an applied one, and under-investing in the specific topics (regulation, model risk, enterprise risk management) that tend to be less familiar from day-to-day professional experience. Addressing these directly during preparation, rather than discovering them on exam day, is the most reliable way to avoid an avoidable resit.
Ready to start preparing?
Qudrane's CISI Risk in Financial Services course covers all ten topic areas across structured modules, with audio narration, a full mock exam, and 12 CPD hours on completion. Self-paced and accessible from any device.
View the course