CISI Risk in Financial Services: Syllabus Breakdown
A topic-by-topic guide to what the CISI Risk in Financial Services exam covers, where the most marks are available, and where candidates most often drop points.
The CISI Risk in Financial Services exam draws questions from ten topic areas. Understanding what each area covers, and where the exam places the most weight, is one of the most useful things you can do before you start studying. This breakdown covers each topic in turn, with notes on what examiners tend to focus on and where candidates most often drop marks.
How the Syllabus is Structured
The exam consists of 100 multiple-choice questions covering all ten topic areas. Questions are not evenly distributed: some areas carry more weight than others, and the regulatory content in particular tends to be more heavily represented than candidates expect. The pass mark is 70%, meaning you need to answer at least 70 questions correctly.
Most questions present a scenario or definition and ask you to identify the correct risk type, regulatory requirement, or appropriate response. Recall alone is rarely enough. The exam tests whether you can apply the right framework to a given situation.
Topic 1: Principles of Risk Management
This topic establishes the conceptual foundations that the rest of the syllabus builds on. It covers what risk is, how firms structure their approach to managing it, and the governance frameworks that sit around risk functions.
Key areas include the three lines of defence model, risk appetite and risk tolerance, the role of the board and senior management in risk oversight, and how risk culture is defined and embedded. The three lines of defence comes up repeatedly across the exam, not just in this topic, so understanding it properly is worth the time.
Topic 2: International Risk Regulation
This is consistently one of the most heavily weighted areas and the one that catches the most candidates off guard. It covers the UK regulatory framework in detail: the roles of the FCA and PRA, the Senior Managers and Certification Regime (SM&CR), conduct standards, and the regulatory capital frameworks that came out of Basel II and Basel III.
Candidates who treat this as background reading rather than core study material tend to struggle. The exam expects you to know not just what these bodies do but how specific rules and regimes apply in practice.
Topic 3: Operational Risk
Operational risk covers losses arising from inadequate or failed internal processes, people, systems, or external events. The Basel definition of operational risk is testable directly, and you should know it precisely.
Key areas include the main categories of operational risk events, the frameworks used to identify and assess them (risk and control self-assessments, key risk indicators, loss data), business continuity planning, and IT and cyber risk. The exam often presents scenarios describing an event and asks you to classify it correctly as operational risk rather than another type.
Topic 4: Credit Risk
Credit risk is the risk of loss from a borrower or counterparty failing to meet their obligations. This topic covers how credit risk is measured, how it is managed at the firm level, and how the regulatory capital framework addresses it.
The distinction between expected loss and unexpected loss is frequently tested, as is the concept of counterparty credit risk in derivatives. The Basel framework for credit risk, including the standardised approach and internal ratings-based approach, features in the regulatory content as well as here.
Topic 5: Market Risk
Market risk covers the risk of losses from movements in market prices: interest rates, foreign exchange rates, equity prices, and commodity prices. The exam focuses on conceptual understanding rather than complex calculations.
Value at Risk (VaR) is the key measurement concept to understand: what it is, what it measures, and what its limitations are. Stress testing and scenario analysis as complements to VaR also appear in this topic. Candidates sometimes conflate market risk and investment risk; they are distinct topic areas with different scope.
Topic 6: Investment Risk
Investment risk focuses on the risks specific to investment portfolios and asset management. It covers systematic and unsystematic risk, how diversification affects portfolio risk, and the risk measures used in investment management.
This topic overlaps with market risk in places but is specifically concerned with how risk is assessed and managed from an investor or portfolio manager perspective, rather than from a firm-wide balance sheet perspective.
Topic 7: Liquidity Risk
Liquidity risk covers the risk that a firm cannot meet its obligations as they fall due, either because it cannot liquidate assets quickly enough or because it cannot access funding at acceptable cost. The 2008 financial crisis features prominently as the context for understanding why liquidity regulation tightened significantly.
Key regulatory concepts include the Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR), both introduced under Basel III. Understanding what each measures and why they were introduced is more important than being able to calculate them.
Topic 8: Model Risk
Model risk is the risk of loss arising from reliance on financial models that are incorrect, misused, or misunderstood. This is a relatively newer area of regulatory focus and has grown in importance as firms rely on increasingly complex quantitative models for pricing, risk measurement, and decision-making.
Key areas include the sources of model risk, model validation processes, model governance frameworks, and the role of model risk management functions. The exam tends to test understanding of what model risk is and how it is controlled, rather than technical modelling knowledge.
Topic 9: Risk Oversight and Corporate Governance
This topic focuses on the board and committee structures through which risk is overseen at the firm level. It covers the role of risk committees, the Chief Risk Officer function, and how risk reporting flows from operational levels to senior management and the board.
The SM&CR framework is relevant here as well as in the regulatory topic, specifically around individual accountability for risk at senior management level. Questions often ask you to identify which body or individual is responsible for a particular aspect of risk oversight.
Topic 10: Enterprise Risk Management
Enterprise Risk Management (ERM) covers integrated approaches to managing risk across an entire organisation, rather than managing individual risk types in isolation. It addresses how firms build a consistent risk framework that connects risk appetite at board level to risk management activity at operational level.
Key frameworks include the COSO ERM framework. The exam tests understanding of what ERM is trying to achieve and how it differs from a siloed approach to risk management, rather than detailed knowledge of any one framework.
Where to Focus Your Preparation
Based on the structure of the syllabus, the areas that tend to carry the most weight and where investment in study time pays off most reliably are:
- International Risk Regulation, particularly the FCA and PRA frameworks and SM&CR
- Operational Risk, including the Basel definition and risk event categories
- Principles of Risk Management, particularly the three lines of defence
- Credit Risk, particularly expected versus unexpected loss
The remaining topics are all testable and should not be neglected, but the regulatory and operational risk areas are where the exam most commonly separates candidates who pass from those who do not.
Ready to start preparing?
Qudrane's CISI Risk in Financial Services course covers all ten topic areas across structured modules, with audio narration, a full mock exam, and 12 CPD hours on completion. Self-paced and accessible from any device.
View the course