Cheat sheet: exam-prep reference for the CIRO Director and Executive Exam covering governance, supervision, risk, capital, conduct, conflicts, and compliance.
Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.
Scope and study context
Item
Reference
Official provider
Canadian Investment Regulatory Organization
Official exam title
CIRO Director and Executive Exam
Official exam code
Director & Executive Exam
Candidate lens
Director, executive, senior officer, or control-function candidate at a CIRO-regulated dealer
Best study approach
Think like an accountable executive: governance, supervision, escalation, controls, client protection, financial soundness, and regulatory cooperation
This independent Cheat Sheet is for candidates preparing for the Canadian Investment Regulatory OrganizationCIRO Director and Executive Exam — official exam code: Director & Executive Exam.
Best Use Before Practice Questions
Read the governance and supervision tables first.
Review the decision rules and common traps.
Complete targeted original practice questions by topic.
Review every explanation, especially for questions you got right by guessing.
Build an error log around missed themes: conflicts, escalation, documentation, client harm, regulatory reporting, and board oversight.
Confirm the firm has a current regulatory obligation inventory.
Review risk appetite and ensure it matches products, clients, leverage, geography, and technology.
Require dashboards for capital, liquidity, complaints, supervision exceptions, cybersecurity, AML, and high-risk products.
Ask whether compliance and supervision teams have enough authority, independence, staffing, and technology.
Track repeat findings from CIRO exams, internal audit, external audit, client complaints, and branch reviews.
Ensure conflicts are identified before products, compensation grids, referrals, or acquisitions are implemented.
Require documented escalation criteria for material breaches, client harm, financial deterioration, and regulatory inquiries.
Verify board minutes reflect challenge, not passive receipt of reports.
Registration, approval, and proficiency decision points
Scenario
Exam-relevant issue
Better answer
New executive joins with authority over dealer operations
May require approval, registration, disclosure, or proficiency depending on function.
Analyze actual authority and regulated activities, not only job title.
Director is not client-facing
Still may be subject to CIRO approval and conduct expectations.
Director oversight role can create regulatory obligations even without sales activity.
Employee gives investment recommendations
Registration category and proficiency may be required.
Do not permit advice activity through an unregistered or improperly supervised person.
Approved person starts side business
Outside activity, conflict, reputation, time commitment, and client confusion concerns.
Require prior disclosure, firm review, approval where required, and ongoing monitoring.
Executive controls another entity doing business with dealer
Related-party, referral, conflict, outsourcing, and financial exposure concerns.
Escalate to conflict review, board oversight, documentation, and client disclosure where appropriate.
Individual changes role or authority
Registration/approval records may need updates.
Use change-management controls for role, ownership, discipline, outside activity, and location changes.
Three-lines-of-defence view
Line
Function
Director/executive exam focus
First line
Business units and supervisors own risks in client activity, trading, operations, and products.
Business cannot outsource compliance thinking to the compliance department.
Second line
Compliance, risk, AML, privacy, finance controls, and other oversight functions.
Must have authority, independence, reporting access, and resources.
Third line
Internal audit or independent assurance.
Tests whether controls work; repeat findings are major governance red flags.
Board / committees
Oversight above all lines.
Must challenge, approve appetite, monitor remediation, and ensure accountability.
Notes and examples
Three Lines of Defence: Cheat Sheet
Line
Main Owner
Exam-Relevant Function
Trap
First line
Business units and supervisors
Own and manage risks in daily activity
Thinking revenue producers do not own compliance risk
Second line
Compliance, risk, finance, privacy, AML, control functions
Set frameworks, monitor, advise, challenge, escalate
Letting compliance “approve” everything without business accountability
Third line
Internal audit or independent review, where used
Independent assurance on controls
Treating audit findings as optional suggestions
Board / committees
Governance oversight
Challenge management and ensure remediation
Accepting management explanations without evidence
Client account and conduct reference
Area
Required exam thinking
KYC
Know the client’s identity, financial circumstances, investment knowledge, objectives, risk profile, time horizon, liquidity needs, constraints, and relevant personal circumstances.
KYP
Understand each product’s structure, costs, risks, liquidity, complexity, conflicts, target client, restrictions, and ongoing monitoring needs.
Suitability
Assess recommendations and accepted orders using KYC and KYP, with the client’s interest placed first where required.
Relationship disclosure
Clients must understand account type, services, fees, conflicts, reporting, complaint process, and firm/client responsibilities.
Conflicts
Identify, avoid or address material conflicts in the client’s interest, and disclose clearly when disclosure is part of the control set.
Requires special attention to risk tolerance, ability to absorb loss, liquidity, suitability, and supervision.
Discretionary authority
Higher control standard; authority must be permitted, documented, supervised, and limited to approved arrangements.
Vulnerable clients
Watch for diminished capacity, financial exploitation, trusted contact issues, power of attorney concerns, and temporary hold escalation where applicable.
Complaints
Treat possible misconduct, client loss, or unsuitable advice seriously; investigate impartially and document resolution.
KYC, KYP, and suitability traps
Trap
Why it is wrong
Exam-safe correction
“The client signed the form, so suitability is satisfied.”
Signature is evidence, not analysis.
Confirm information is reasonable, current, and applied to the recommendation/order.
“High net worth means high risk tolerance.”
Capacity for loss is not the same as willingness to accept risk.
Assess risk tolerance and risk capacity separately.
“The product is approved, so it is suitable for everyone.”
KYP approval is product-level; suitability is client-specific.
Match product attributes to the client profile and account context.
“OEO account means no controls.”
Order-execution-only reduces advice obligations but not all conduct, disclosure, conflict, or market integrity obligations.
Maintain appropriate account, disclosure, trading, and complaint controls.
“Disclosure fixes the conflict.”
Some conflicts must be avoided or controlled; disclosure alone may be inadequate.
Identify, assess materiality, control or avoid, disclose clearly when appropriate.
“Institutional client means no oversight.”
Some obligations may differ, but fair dealing, conflicts, market integrity, and documentation still matter.
Apply the correct standard for the client category and activity.
Notes and examples
Know Your Client: What Matters
KYC Area
Review Point
Identity and authority
Confirm who the client is and who may act for the client
Investment objectives
Understand what the client is trying to accomplish
Time horizon
Match recommendations to when funds are needed
Risk tolerance
Client’s willingness to accept volatility or loss
Risk capacity
Client’s financial ability to withstand loss
Financial circumstances
Income, assets, liabilities, liquidity needs
Investment knowledge
Helps determine explanation depth and product complexity
Tax and account context
Relevant to recommendations and account type
Life changes
KYC must be updated when material changes occur
Know Your Product: What Matters
KYP Area
Questions to Ask
Structure
How does the product work?
Risk
What can go wrong? Market, credit, liquidity, leverage, concentration?
Costs
What fees, embedded compensation, penalties, or spreads apply?
Liquidity
Can the client exit? At what cost and when?
Complexity
Can the target client reasonably understand it?
Conflicts
Does the firm or representative benefit in a way that could bias advice?
Target market
For whom is the product appropriate or inappropriate?
Due diligence
Has the firm reviewed and approved the product before sale?
Suitability Review
A suitability analysis should be:
Based on current KYC information.
Informed by proper KYP.
Connected to the client’s objectives, risk profile, time horizon, and financial circumstances.
Reassessed when triggering events occur.
Documented.
Focused on the client, not the representative’s compensation or firm inventory.
Common Suitability Traps
Scenario
Better Exam Answer
Client wants unsuitable trade
Warn, explain risks, document, follow firm policy; do not simply process without review
Product is approved generally
Still assess suitability for this client
Client has high risk tolerance
Also assess risk capacity and concentration
Client signs disclosure
Disclosure does not replace suitability
Representative knows client socially
Still obtain and document proper KYC
Account is profitable
Profit does not prove suitability or proper supervision
flowchart TD
A[Potential conflict identified] --> B{Is it material?}
B -- No --> C[Document assessment and monitor]
B -- Yes --> D{Can it be avoided?}
D -- Yes --> E[Avoid or prohibit activity]
D -- No --> F[Design controls in client's interest]
F --> G{Is disclosure also needed?}
G -- Yes --> H[Clear, timely, specific disclosure]
G -- No --> I[Document why disclosure not required]
H --> J[Supervise, test, and escalate breaches]
I --> J
E --> J
Conflicts of Interest
Conflicts are heavily testable because directors and executives are expected to build systems that identify and manage them.
Hiding errors, allocating losses to clients, inconsistent correction.
Notes and examples
Market Conduct and Trading Oversight
For firms involved in securities trading, directors and executives should understand the governance controls around fair and orderly markets.
Topic
Review Point
Manipulative or deceptive trading
Systems must detect and escalate suspicious trading patterns
Insider trading
Material non-public information must be controlled
Information barriers
Needed where business lines may access sensitive information
Best execution
Client orders should be handled under appropriate policies and controls
Order handling
Priority, fairness, and recordkeeping matter
Short selling and margin-related controls
Must follow applicable rules and supervision
Trade errors
Identify, correct, document, and analyze root cause
Employee trading
Preclearance, restricted lists, monitoring, and conflict controls may apply
Common Market Conduct Mistakes
Ignoring suspicious trading because the client is sophisticated.
Allowing business pressure to override information barriers.
Treating trade errors as isolated without root-cause review.
Failing to supervise electronic or algorithmic processes where used.
Not preserving order and communication records.
Financial, capital, and operations reference
Area
Director/executive focus
Capital adequacy
Dealer must maintain required capital and monitor deterioration. Board should receive trend reporting and early-warning indicators.
Liquidity
Ability to meet obligations during normal and stressed conditions, including settlement, margin calls, client withdrawals, and funding disruptions.
Books and records
Accurate, complete, timely records support supervision, financial reporting, tax, audit, and regulatory examination.
Client asset segregation
Client property must be identified, safeguarded, reconciled, and separated from firm misuse.
Margin
Margin rules reduce credit exposure but do not eliminate market, liquidity, or suitability risk.
Reconciliations
Bank, custodian, security position, client ledger, suspense, and control-account breaks must be investigated.
Pricing and valuation
Hard-to-value securities require independent review, documentation, and escalation.
Insurance
Fidelity, fraud, and operational coverage should align with business risks and regulatory expectations.
Introducing/carrying arrangements
Responsibilities for accounts, custody, statements, margin, supervision, and client communications must be clear.
Outsourcing
Outsourced functions require due diligence, contracts, monitoring, access to records, BCP, privacy, and regulatory access.
Business continuity
Plans must cover people, premises, technology, vendors, cyber incidents, market disruption, and communications.
Notes and examples
Core finance formulas worth remembering
\[
\text{Working Capital} = \text{Current Assets} - \text{Current Liabilities}
\]\[
\text{Equity in a Margin Account} = \text{Market Value of Securities} + \text{Credit Balance} - \text{Debit Balance}
\]\[
\text{Loan Value} = \text{Market Value} \times \text{Permitted Loan Rate}
\]\[
\text{Concentration Percentage} = \frac{\text{Exposure to Issuer, Sector, Client, or Counterparty}}{\text{Relevant Portfolio, Capital, or Exposure Base}} \times 100
\]
Use these as conceptual tools. For the real exam, apply any CIRO-specific capital, margin, or reporting rule stated in the question.
Financial and Operational Controls
Directors and executives do not need to perform every calculation personally, but they must understand whether the firm’s financial controls are reliable and whether warning signs are escalated.
Area
What to Review
Capital adequacy
Firm must maintain required financial strength under applicable rules
Liquidity
Firm must be able to meet obligations as they come due
Books and records
Records must be complete, accurate, timely, and retrievable
Reconciliations
Cash, securities, client positions, and internal records must be reconciled
Exposure to issuers, counterparties, products, or strategies must be controlled
Financial reporting
Regulatory and board reports must be accurate and escalated if issues arise
Insurance and bonding
Required coverage should be maintained and reviewed
Expense and fee billing
Errors can create client harm and conduct risk
Financial Control Traps
Trap
Better Answer
“The firm is profitable, so capital is fine”
Profitability and regulatory capital are different concepts
“Finance will handle it”
Senior management and directors still need oversight and escalation
“Small reconciliation breaks are normal”
Repeated breaks may indicate a systemic issue
“No client complained, so billing errors are minor”
Billing errors require review, correction, and possible broader remediation
“Temporary capital issue can wait until month-end”
Capital or liquidity concerns require prompt escalation under firm procedures
Risk taxonomy for directors and executives
Risk
Meaning
Board-level question
Conduct risk
Clients or markets harmed by behaviour, incentives, weak supervision, or culture.
What behaviours are rewarded, tolerated, and escalated?
Compliance risk
Breach of CIRO rules, securities law, AML, privacy, tax, or internal policy.
Are obligations mapped to controls and tested?
Credit risk
Counterparty, issuer, client margin, or settlement failure.
What exposures are concentrated and how are they collateralized?
Market risk
Loss from price, rate, FX, volatility, or spread movement.
What stress scenarios could exceed appetite?
Liquidity risk
Inability to meet obligations or unwind positions without unacceptable loss.
What funding sources and contingency plans exist?
Operational risk
People, process, system, fraud, error, or vendor failure.
Which key controls are manual, fragile, or untested?
Cyber risk
Unauthorized access, ransomware, data loss, service disruption.
Are incident plans tested and reported to the board?
Model risk
Incorrect models for margin, valuation, surveillance, credit, or advice tools.
Who validates assumptions and overrides?
Legal risk
Contracts, litigation, enforceability, disclosure, fiduciary or agency issues.
Are legal risks escalated before launch or transaction approval?
Reputational risk
Loss of trust from client harm, enforcement, media, or control failure.
Are issues addressed early or minimized until they become public?
Strategic risk
Business model, acquisition, expansion, or technology risk.
Does the firm’s control environment match its growth plan?
Third-party risk
Vendor, affiliate, cloud, custodian, or carrying broker failure.
Can the firm continue and access records if the vendor fails?
AML, sanctions, and financial crime controls
Control
Exam focus
Client identification
Verify identity and understand the nature of the client relationship.
Beneficial ownership
Identify individuals who own or control entities where required.
Politically exposed persons / high-risk clients
Apply enhanced review and senior approval where required.
Ongoing monitoring
Review activity against expected account behaviour.
Suspicious activity
Escalate and report according to AML procedures and legal requirements.
Sanctions screening
Screen clients, counterparties, and transactions against applicable sanctions controls.
Training
Tailor training to roles: front office, operations, compliance, executives, and board.
Independent effectiveness review
Test whether AML controls work, not just whether policies exist.
Recordkeeping
Maintain records that support regulatory review and investigations.
Notes and examples
AML/ATF Governance Points
Area
Review Focus
Client identification
Verify identity and authority according to applicable requirements
Risk assessment
Higher-risk clients, jurisdictions, products, and activity require enhanced controls
Ongoing monitoring
Activity should be reviewed for unusual or suspicious patterns
Suspicious transactions
Escalate and report according to legal and firm requirements
Politically exposed persons and high-risk clients
Apply enhanced review where required
Sanctions
Screen and escalate potential matches
Training
Staff must understand red flags and escalation procedures
Independent review
AML program effectiveness should be tested
Recordkeeping
Maintain required AML records and evidence of decisions
Financial Crime Red Flags
Client refuses to provide information.
Unexplained third-party deposits or withdrawals.
Activity inconsistent with known profile.
Rapid in-and-out movement of funds.
Use of multiple accounts without clear purpose.
Suspicious source of funds or wealth.
Unusual cross-border activity.
Pressure to bypass normal procedures.
Exam Trap
AML issues are not solved by “getting the trade done and checking later.” If required information or risk review is missing, the proper response is escalation, restriction, or refusal under firm procedures.
Complaints, investigations, and enforcement
Item
Practical distinction
Service issue
Administrative or service concern without misconduct, loss, or rule breach indicators; still track for patterns.
Regulatory complaint
Allegation of unsuitable advice, misrepresentation, unauthorized trading, fraud, fee issue, conflict, or other misconduct.
Internal investigation
Must be impartial, documented, timely, and independent of conflicted personnel.
Client remediation
Consider financial harm, account correction, fee reversal, interest, tax consequences, and communication clarity.
External dispute resolution
Clients may have access to independent dispute resolution processes where applicable.
CIRO examination
Regulatory review of books, records, supervision, capital, and conduct; cooperation is expected.
Enforcement matter
Can involve document requests, interviews, allegations, settlements, hearings, and sanctions.
Individual exposure
Directors, executives, supervisors, and approved persons can face consequences for personal misconduct or failure to supervise.
Escalation workflow for material issues
flowchart TD
A[Issue or red flag discovered] --> B[Stabilize client, market, capital, or data risk]
B --> C[Preserve records and facts]
C --> D{Potential rule breach, client harm, AML, privacy, or capital issue?}
D -- No --> E[Resolve, document, monitor trend]
D -- Yes --> F[Escalate to responsible executive, compliance, legal, and risk]
F --> G{Regulatory/client reporting required?}
G -- Yes --> H[Report through approved process]
G -- No --> I[Document rationale]
H --> J[Remediate root cause]
I --> J
J --> K[Test fix and report closure to management/board]
Records and evidence that exam scenarios often imply
Test controls, advise on rules, identify deficiencies, escalate serious issues
Become the sole owner of business risk or replace supervision
Front-line supervisors
Direct oversight of people, accounts, trading, sales, and branch activity
Review activity, approve accounts where required, investigate red flags, coach and discipline
Rubber-stamp activity or rely only on annual reviews
Notes and examples
Fast Rule
Delegation is allowed. Abdication is not. A director or executive can rely on qualified people and systems, but must act reasonably, ask questions, monitor results, and respond to red flags.
Governance Essentials
What Strong Governance Looks Like
Governance Element
High-Yield Review Point
Clear roles
Board, committees, executives, compliance, finance, operations, and business lines know their duties
Written policies
Policies are current, approved, communicated, and tested
Reporting
Management provides timely, accurate, risk-focused information
Challenge
Directors ask informed questions, especially when results look unusual
Escalation
Serious issues move quickly to appropriate decision-makers
Minutes and records
Decisions, concerns, dissent, follow-up items, and approvals are documented
Independence
Conflicts are managed; oversight is not dominated by revenue interests
Resources
Compliance, supervision, finance, technology, and operations have sufficient support
Remediation
Deficiencies lead to root-cause analysis, corrective action, and follow-up testing
Notes and examples
Board and Committee Oversight Topics
Directors should be prepared to oversee:
Regulatory compliance framework
Financial condition and capital adequacy
Risk appetite and risk limits
Conflicts of interest
Client complaint trends
Significant supervisory deficiencies
Internal control failures
Material technology or cybersecurity incidents
Outsourcing and third-party risks
Regulatory inquiries, examinations, and enforcement matters
Business continuity planning
Culture, compensation, and conduct risk
Common Governance Mistakes
Approving a policy but never asking whether it works.
Receiving reports that are too vague and not demanding better metrics.
Ignoring repeated “minor” issues that reveal a systemic problem.
Letting a high-revenue business unit bypass controls.
Failing to document challenge, follow-up, and dissent.
Treating compliance as a cost centre rather than a core control function.
Regulatory Framework: What to Keep Straight
The Canadian Investment Regulatory Organization regulates member conduct and supervises compliance with applicable rules and standards. Candidates should also understand that CIRO obligations interact with broader securities, financial crime, privacy, employment, and corporate governance requirements.
Authority / Framework
Typical Relevance
Canadian Investment Regulatory Organization
Member rules, supervision, business conduct, enforcement, proficiency and approval-related obligations
Provincial and territorial securities regulators / CSA framework
Client information safeguards, breach handling, records, consent, vendor controls
Corporate law and firm governance documents
Director duties, board process, conflicts, fiduciary-style governance responsibilities
Ombudsman or external dispute resolution processes, where applicable
Client complaint escalation and dispute resolution
Notes and examples
Exam Trap
Do not answer as though CIRO membership replaces all other legal obligations. A firm may need to comply with CIRO rules, securities law, AML/ATF requirements, privacy obligations, and its own internal policies at the same time.
Core Conduct Principles
Even when a question is detailed, the correct answer often follows a few core principles.
Principle
What It Means in Exam Scenarios
Integrity
Do not mislead clients, regulators, the board, auditors, or compliance
Fair dealing
Treat clients honestly and fairly; avoid taking advantage of information gaps
Client-first mindset
Address material conflicts and suitability concerns before revenue goals
Market integrity
Prevent manipulation, deceptive conduct, insider trading, and abusive practices
Accountability
Escalate, document, remediate, and test corrective action
Competence
Ensure people performing regulated functions are qualified, supervised, and trained
Transparency
Disclose what must be disclosed, but do not rely on disclosure when avoidance/control is required
Account Approval and Client Authority
Issue
High-Yield Rule
New account opening
Must be properly documented, reviewed, and approved under firm procedures
Margin account
Requires specific risk review and controls
Options or complex strategies
Require appropriate approval, education, and supervision
Discretionary authority
Must be specifically authorized and controlled; casual verbal permission is not enough
Power of attorney / trading authority
Verify authority, scope, and potential conflicts
Corporate or trust account
Confirm authorized individuals and governing documents
Vulnerable client concerns
Escalate, document, consider trusted contact or temporary hold processes where applicable
Fee-based account
Assess whether fee arrangement is appropriate given expected service and activity
Supervision: What Effective Oversight Requires
Supervision Must Be More Than a Policy
Component
What Examiners Like to Test
Risk-based procedures
Higher-risk clients, products, representatives, and branches need more scrutiny
Qualified supervisors
Supervisors must understand the business they supervise
Timely review
Red flags cannot wait indefinitely
Evidence
Reviews, approvals, inquiries, and resolutions must be documented
Escalation
Serious or repeated issues must move upward
Corrective action
Training, restrictions, discipline, restitution, reporting, or process changes may be needed
Follow-up testing
Management should confirm the fix worked
Notes and examples
Red Flags Requiring Attention
Frequent client complaints.
Unusual trading patterns.
High concentration in one issuer, sector, or product.
Excessive trading or switching.
Patterns of losses inconsistent with client profile.
Use of personal email, messaging apps, or unapproved communication channels.
Undisclosed outside activities.
Borrowing from or lending to clients.
Client signatures that appear irregular.
Large transfers to third parties.
Representatives resisting supervision.
Branches with repeated deficiencies.
High-revenue individuals receiving special treatment.
Products sold before proper due diligence or training.
Escalation Workflow
flowchart TD
A[Issue, complaint, exception, or red flag] --> B{Possible client harm, rule breach, misconduct, or financial risk?}
B -- No --> C[Document review and monitor]
B -- Yes --> D[Escalate to supervisor, compliance, or senior management]
D --> E[Preserve records and stop ongoing harm]
E --> F{Material, systemic, or reportable?}
F -- Yes --> G[Make required internal and regulatory reporting]
F -- No --> H[Remediate and document rationale]
G --> I[Root-cause analysis and corrective action]
H --> I
I --> J[Follow-up testing and board or committee reporting if significant]
Complaints and Client Harm
Complaint Handling Priorities
Step
Review Point
Recognize the complaint
Allegations of misconduct, loss, unsuitable advice, unauthorized trading, misrepresentation, or poor handling require formal attention
Acknowledge and record
Do not treat serious complaints as casual service issues
Investigate fairly
Use independent review where appropriate
Preserve evidence
Communications, account records, approvals, notes, trading history
Communicate appropriately
Avoid misleading, defensive, or dismissive responses
Escalate
Compliance, legal, senior management, insurers, board committees, or regulators may need involvement
Remediate
Correct client harm and control failures
Analyze trends
Repeated complaints may indicate systemic risk
Complaint Traps
Calling a complaint a “misunderstanding” to avoid process.
Letting the representative accused of misconduct control the investigation.
Settling without understanding root cause.
Failing to review other clients with similar exposure.
Must be appropriate, supervised, and retained under firm policy
Marketing materials
Should be fair, balanced, and not misleading
Performance claims
Need proper basis, context, and disclosure
Titles and credentials
Must not mislead clients about expertise or authority
Social media
Must follow approval, supervision, and recordkeeping requirements
Research or commentary
Avoid misleading statements, unsupported claims, and conflicts
Client presentations
Must be consistent with approved materials and risk disclosure
Exam Trap
A communication can be problematic even if the facts are technically true. The exam may ask whether the overall impression is misleading, incomplete, overly promotional, or unsuitable for the audience.
Technology, Cybersecurity, Privacy, and Outsourcing
Monitor liquidity, margin, client communication, and operational capacity
Media or reputational crisis
Coordinate accurate communication; avoid misleading statements
Quick Rule
A crisis plan is only useful if it is tested, updated, owned, and understood.
Registration, Proficiency, and Approved Activities
Area
Review Point
Approved roles
Individuals must operate within their approved or permitted functions
Proficiency
Training and qualifications must match responsibilities
Supervisory capacity
Supervisors must have authority, competence, and resources
Changes in status
Reportable changes should be escalated under applicable requirements
Outside activities
Require review for conflicts, client confusion, time commitment, and reputational risk
Termination issues
Misconduct, complaints, investigations, or client harm should not be hidden
Continuing education / training
Programs should address regulatory changes, products, supervision, and conduct risks
Exam Trap
A person’s experience or revenue production does not excuse missing approval, proficiency, supervision, or conflict requirements.
Ethics and Culture
The CIRO Director and Executive Exam can test ethics through practical governance scenarios rather than abstract definitions.
Culture Indicators
Healthy Culture
Weak Culture
Bad news escalates quickly
Employees hide issues
Compliance has authority and resources
Compliance is ignored or bypassed
Compensation supports suitable advice
Sales incentives override client interests
Leaders document and remediate
Leaders rely on informal fixes
Complaints are investigated fairly
Complaints are minimized
Training is practical and current
Training is check-the-box
Supervisors challenge top performers
Top performers receive exceptions
Tone from the Top
Directors and executives set expectations through:
Hiring and promotion decisions.
Compensation design.
Response to misconduct.
Budgeting for compliance and supervision.
Board and management reporting.
Willingness to challenge profitable but risky activity.
Treatment of clients during errors or complaints.
Breach Response Model
Use this simple model for scenario questions:
Step
Action
1. Recognize
Identify the rule breach, client harm, red flag, or control failure
2. Stabilize
Stop ongoing harm and preserve records
3. Escalate
Notify the correct supervisor, compliance, legal, senior management, board committee, or regulator as required
4. Investigate
Determine facts, scope, root cause, affected clients, and financial impact
5. Remediate
Correct client harm, discipline if needed, improve controls
6. Report
Make required regulatory, client, insurer, board, or internal reports
7. Test
Confirm the fix works and document follow-up
Notes and examples
Strong Exam Answers Usually Include
Prompt escalation.
Independent review.
Documentation.
Client protection.
Root-cause analysis.
Corrective action.
Follow-up monitoring.
Regulatory reporting where required.
Weak Exam Answers Often Include
“Wait and see.”
“Handle it informally.”
“Let the representative explain it to the client.”
“Do nothing because no loss occurred.”
“Rely on disclosure only.”
“Ignore because the client is sophisticated.”
“Delay until the next scheduled board meeting.”
“Assume compliance is responsible for everything.”
Scenario Decision Rules
1. If There Is a Red Flag, Investigate Before Approving
A red flag does not always prove misconduct, but it requires inquiry. The wrong answer is often the one that approves the activity without follow-up.
2. If There Is Client Harm, Think Escalation and Remediation
Client harm usually requires more than internal coaching. Consider records, investigation, communication, compensation, broader review, and reporting.
3. If There Is a Conflict, Disclosure May Not Be Enough
Serious conflicts may require avoidance, restrictions, independent supervision, compensation changes, or prohibition.
4. If a Policy Exists, Ask Whether It Works
A written policy is only one control. Look for training, monitoring, exception reports, testing, escalation, and remediation.
5. If a High Producer Is Involved, Apply More Scrutiny — Not Less
Revenue does not reduce supervisory expectations. It can increase conduct risk.
6. If the Issue Is Systemic, Board-Level Attention May Be Needed
Repeated incidents, widespread client impact, capital issues, cyber events, or control breakdowns may require board or committee reporting.
7. If a Function Is Outsourced, the Firm Still Owns the Risk
Vendor failure can still be the firm’s regulatory problem.
8. If Records Are Missing, That Is Itself a Control Failure
Good conduct without records is difficult to prove. Documentation is part of the control environment.
Common Exam Traps by Topic
Topic
Trap Answer
Better Answer
Governance
Board approves policy once and moves on
Board receives reporting, challenges, and monitors remediation
Supervision
Supervisor verbally warns representative
Supervisor documents, escalates if needed, and follows up
Conflicts
Client disclosure solves everything
Avoid/control conflict and disclose where appropriate
Suitability
Client requested the trade
Firm still assesses suitability and documents concerns
Complaints
Treat as customer service issue
Recognize, record, investigate, and escalate
AML
Process first, review later
Complete required review and escalate red flags
Financial controls
Wait until routine reporting cycle
Escalate material capital, liquidity, or reconciliation concerns promptly
Cybersecurity
IT department handles it alone
Cross-functional incident response with governance oversight
Outsourcing
Vendor is responsible
Firm retains accountability and monitors vendor
Culture
Compliance owns ethics
Leadership, supervisors, and business lines own conduct culture
Mini Review: “Best Answer” Pattern
When two answers seem plausible, prefer the one that includes the strongest governance process:
Protect clients and market integrity.
Follow current rules and firm procedures.
Escalate to the right authority.
Preserve evidence and document decisions.
Investigate independently where needed.
Correct root cause, not just the symptom.
Report where required.
Monitor and test the fix.
Rapid-Fire Review Questions to Ask Yourself
Before starting a mock exam or topic drill, make sure you can answer these without notes:
What is the difference between board oversight and executive implementation?
Why does delegation not eliminate accountability?
What makes supervision “effective” rather than merely documented?
When is disclosure insufficient for a conflict of interest?
What is the relationship between KYC, KYP, and suitability?
How should a firm respond to repeated small complaints?
What red flags suggest possible AML or financial crime concerns?
Why can a profitable firm still have regulatory financial problems?
What should happen after a cybersecurity incident is identified?
How should directors respond when management reports a material control failure?
Why is a high-producing representative often a higher supervisory risk?
What records should exist after an exception, complaint, or remediation decision?
How should outsourcing risk be governed?
What does “tone from the top” look like in practical decisions?
What makes a breach response complete?
Last-Minute Review Checklist
Governance
Board and management roles are distinct.
Delegation does not eliminate oversight.
Policies must be implemented, monitored, and tested.
Significant issues require escalation and documentation.
Directors should challenge incomplete or overly optimistic reporting.
Notes and examples
Compliance and Supervision
Supervision is risk-based and evidenced.
Red flags require inquiry.
Compliance advises, monitors, and escalates; business lines still own risk.
High-risk products, clients, representatives, and branches require enhanced oversight.
Corrective action should address root cause.
Client Protection
KYC must be current and meaningful.
KYP must support suitability.
Suitability is client-specific.
Complaints require fair investigation.
Vulnerable client concerns require careful escalation and documentation.
Conflicts and Ethics
Identify, assess, avoid/control, disclose, document, and monitor conflicts.
Disclosure alone may not be enough.
Compensation incentives can create conduct risk.
Culture is shown by decisions, not slogans.
Risk and Operations
Capital, liquidity, custody, segregation, and reconciliations need oversight.
AML, sanctions, privacy, cyber, and outsourcing risks require governance.
Incidents require containment, escalation, remediation, and reporting where required.
Records must support the firm’s decisions.
Practice Strategy After This Review
Use this page as a quick refresher, then move into independent companion practice:
Start with topic drills on governance, conflicts, supervision, and client protection.
Review detailed explanations for every missed question.
Rework questions involving escalation, documentation, and remediation.
Take a mixed mock exam only after your weak topics improve.
Use an error log to track repeated mistakes, especially where you chose informal action over a structured regulatory response.
The most productive next step is to practice with original practice questions in a focused question bank, then use the explanations to connect each scenario back to director and executive accountability.