CISI Risk in Financial Services Cheat Sheet

Compact independent Cheat sheet for Chartered Institute for Securities & Investment CISI Risk in Financial Services (CISI Risk) candidates: risk types, controls, governance, formulas, and scenario decision points.

Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.

Scope and study context
  1. Identify the risk type from a short scenario.
  2. Separate cause, event, impact, control, and owner.
  3. Choose the best control or governance response.
  4. Interpret risk metrics and formulas without confusing related terms.
  5. Recognize common traps: residual vs inherent risk, market vs credit risk, conduct vs compliance risk, liquidity vs solvency, audit vs risk ownership.

Core risk-management workflow

    flowchart LR
	    A[Identify risk] --> B[Assess inherent risk]
	    B --> C[Select response and controls]
	    C --> D[Measure residual risk]
	    D --> E[Monitor KRIs, limits, losses]
	    E --> F[Report and escalate]
	    F --> G[Review appetite, policies, lessons learned]
	    G --> A
StepCandidate focusTypical exam clue
IdentifyWhat could go wrong? Which risk category?New product, failed process, counterparty default, cyber incident
AssessLikelihood, impact, velocity, correlation, concentrationHeat map, scoring, scenario estimate, expected loss
RespondAvoid, reduce, transfer, acceptHedge, insure, collateralize, outsource, set limits
ControlPreventive, detective, corrective measuresSegregation, reconciliation, confirmation, monitoring
MonitorIndicators and breachesKRI trend, limit excess, near miss, audit finding
ReportRight audience, frequency, escalationBoard risk pack, risk committee, regulatory notification
ReviewLessons learned and continuous improvementPost-incident review, control redesign, policy update
Notes and examples

High-Yield Risk Map

AreaWhat to know quicklyCommon exam trap
Risk governanceBoard oversight, risk appetite, policies, reporting, escalation, three lines modelTreating risk management as only a compliance or audit function
Risk processIdentify, assess, measure, mitigate, monitor, report, reviewJumping to controls before defining the risk event and cause
Credit riskDefault risk, counterparty risk, settlement risk, concentration, collateral, nettingConfusing issuer credit risk with market price movement
Market riskInterest rate, FX, equity, commodity, spread, volatility, basis riskAssuming VaR predicts the maximum possible loss
Liquidity riskFunding liquidity vs market liquidity, cash flow mismatch, contingency fundingConfusing a solvent firm with a liquid firm
Operational riskPeople, process, systems, external events; cyber, fraud, outsourcing, business continuityClassifying every loss as operational risk without identifying the root cause
Conduct and compliance riskFair client treatment, conflicts, suitability, market abuse controls, regulatory obligationsThinking compliance risk is only about fines, not client and market outcomes
Model and data riskAssumptions, validation, data quality, limitations, change controlTreating model output as fact rather than a decision input
Capital and stress testingCapital absorbs unexpected losses; stress tests explore severe but plausible conditionsConfusing expected loss provisions with capital for unexpected loss
Risk cultureIncentives, challenge, escalation, accountability, tone from the topBelieving policies alone create effective risk management

High-yield risk vocabulary

TermMeaningExam trap
RiskEffect of uncertainty on objectivesRisk is not always purely negative; some risk is accepted for return
Risk eventOccurrence that creates loss or adverse outcomeDo not confuse event with root cause
CauseUnderlying driver of a risk eventExample: weak access control causes unauthorized payment
ImpactConsequence if the event occursCan be financial, regulatory, customer, operational, reputational
Inherent riskRisk before controlsUsually higher than residual risk if controls are effective
Residual riskRisk remaining after controlsNot automatically acceptable; compare with appetite
Risk appetiteAmount/type of risk the firm is willing to acceptBoard-level concept, not a single operational limit
Risk tolerancePermitted variation around appetiteOften expressed through thresholds or ranges
Risk capacityMaximum risk the firm can bearCapacity constrains appetite
Risk limitQuantified boundary for activity or exposureBreach should trigger action/escalation
KRIKey risk indicator; forward-looking or risk-focused metricDifferent from KPI, which measures performance
KPIKey performance indicatorHigh sales KPI can increase conduct risk
KCIKey control indicatorMeasures whether a control is operating
RCSARisk and control self-assessmentSelf-assessment needs challenge; not independent assurance
Loss eventActual incident causing lossNear misses matter even without financial loss
Near missIncident avoided before loss crystallizedUseful for trend analysis and control improvement
Risk ownerPerson/function accountable for managing the riskUsually first line, not internal audit
Control ownerPerson responsible for operating a controlControl ownership may differ from risk ownership
AssuranceIndependent check over control design/effectivenessAssurance does not transfer risk ownership
EscalationRaising a breach or issue to the right levelReporting alone is not remediation

Risk appetite, limits, and escalation

ConceptLevelPractical exampleWhat to remember
CapacityFirm survival / capital / liquidityMaximum loss the firm could withstandHard boundary; appetite must sit within it
AppetiteBoard and strategyLow appetite for regulatory breachesGuides business decisions
ToleranceBusiness/risk policyAcceptable range of operational lossesMore granular than appetite
LimitDesk, portfolio, product, counterpartyFX VaR limit, single-name credit limitBreach requires defined action
TriggerEarly warning80% of limit used, rising complaintsPrompts monitoring before breach
BreachControl boundary exceededTrader exceeds position limitRequires escalation and remediation

Common distinction: risk appetite is a governance choice; risk limit is an operating control.

Three lines and governance roles

RoleMain responsibilityShould not be mistaken for
Board / governing bodySet strategy, risk appetite, oversight cultureDay-to-day control operator
Board risk committeeChallenge risk profile, limits, major exposuresFirst-line risk owner
Senior managementImplement strategy, allocate resources, enforce accountabilityIndependent assurance
First lineOwn and manage risks in business activitiesPassive recipient of risk reports
Second lineRisk, compliance, oversight, frameworks, challengeFinal owner of business risk
Third lineInternal audit; independent assuranceControl designer/operator for management
External auditFinancial statement assurance and selected controls reviewSubstitute for internal risk management
RegulatorSupervisory expectations and enforcementInternal governance function
Notes and examples

Governance traps

  • Internal audit does not own risk; it provides independent assurance.
  • Risk function challenge is not the same as business approval.
  • A policy is not a control unless implemented and evidenced.
  • Tone from the top matters, but culture also depends on incentives, accountability, escalation, and consequences.
  • Conflicts of interest are conduct and governance risks, not merely administrative issues.

Roles and Responsibilities

FunctionMain roleWhat not to confuse
Board / governing bodySets strategy, approves risk appetite, oversees risk frameworkDoes not usually run day-to-day controls
Senior managementImplements strategy and risk appetite, owns business risksCannot delegate accountability entirely to risk or compliance teams
First lineBusiness and operational management owning risks and controlsNot merely “sales”; includes control ownership
Second lineRisk, compliance, financial crime, specialist oversight functionsChallenges and advises; does not replace first-line ownership
Third lineInternal audit independent assuranceTests the framework; does not design or operate routine controls
External audit / regulatorsExternal assurance or supervision where applicableNot part of daily risk ownership

Risk Appetite, Limits, and Escalation

ConceptPractical interpretation
Appetite statement“How much and what type of risk are we prepared to take?”
Limit“What boundary must a desk, portfolio, process, or person stay within?”
BreachA limit or policy exception requiring action
EscalationTimely reporting to the right level of authority
RemediationAction to correct the breach and address root causes

Exam questions often test whether a breach should be ignored because no loss has occurred. The safer answer is usually that breaches matter because they indicate control failure or risk outside agreed boundaries.

Major risk categories

Risk typeWhat can go wrongCommon measuresCommon controls / mitigantsExam distinction
Credit riskBorrower/counterparty fails to meet obligationPD, LGD, EAD, ratings, arrears, exposure limitsCredit approval, limits, collateral, covenants, diversificationDefault risk is not the same as market price movement
Counterparty riskTrading counterparty defaults before final settlementCurrent exposure, potential future exposure, net exposureNetting, margin, collateral, central clearingOften arises in derivatives and securities financing
Settlement riskOne party delivers but does not receive valueFailed settlements, unmatched tradesDelivery versus payment, payment versus payment, confirmationsShort-lived but potentially severe
Market riskLoss from market price movementsVaR, stress loss, sensitivities, volatilityLimits, hedging, diversification, stop-loss, stress testingIncludes rates, FX, equity, commodity, spreads, volatility
Liquidity riskCannot meet obligations or exit positions at fair priceCash-flow gaps, funding concentration, liquidity coverage metricsBuffers, contingency funding, maturity ladder, diversified fundingLiquidity risk differs from solvency risk
Operational riskFailure of people, process, systems, or external eventsLoss data, KRIs, RCSA scores, incidentsSegregation, reconciliations, access controls, BCP, trainingIncludes cyber, fraud, processing, outsourcing
Conduct riskPoor customer/market outcomes from firm behaviorComplaints, redress, sales patterns, suitability exceptionsProduct governance, training, surveillance, incentives reviewBroader than rule breach; focuses on outcomes
Compliance riskBreach of laws, rules, regulations, or standardsBreaches, monitoring findings, regulatory correspondencePolicies, monitoring, advice, training, attestationsRelated to conduct, but not identical
Legal riskContracts unenforceable or litigation exposureClaims, disputes, contract exceptionsLegal review, enforceable documentation, jurisdiction analysisOften embedded in credit, collateral, outsourcing
Financial crime riskMoney laundering, fraud, bribery, sanctions evasionAlerts, suspicious activity, fraud lossesCDD/KYC, screening, transaction monitoring, segregationControl failure can create regulatory and reputational impact
Model riskModel produces wrong or misused outputBacktesting, validation findings, overridesIndependent validation, governance, documentation, limitationsA correct model can still be misused
Strategic riskPoor strategic decisions or business model weaknessRevenue concentration, competitor trends, plan varianceStrategy review, scenario planning, board challengeNot usually solved by a simple operational control
Reputational riskStakeholder trust damagedMedia, complaints, client exits, funding impactStrong governance, incident response, conduct controlsOften secondary to another risk event
Climate / ESG riskPhysical, transition, liability, or governance exposureSector concentration, scenario results, disclosuresDue diligence, limits, scenario analysis, engagementCan transmit through credit, market, operational, legal risk

Credit risk quick reference

ConceptMeaningPractical use
PDProbability of defaultLikelihood borrower/counterparty defaults
LGDLoss given defaultSeverity after recoveries and collateral
EADExposure at defaultAmount exposed when default occurs
Expected lossAverage credit loss expected over timePricing, provisioning, portfolio planning
Unexpected lossLoss above expected levelEconomic capital and stress resilience
Credit ratingRelative creditworthiness indicatorInput to limits and pricing, not a guarantee
CollateralAsset pledged to reduce lossReduces LGD, but introduces valuation/legal/liquidity risk
CovenantContractual restriction or triggerEarly warning or control over borrower behavior
Concentration riskToo much exposure to one name, sector, geography, or correlationDiversification and limits
Wrong-way riskExposure increases as counterparty credit quality worsensImportant in derivatives and collateral arrangements
NettingOffsetting exposures under enforceable agreementReduces net exposure if legally valid
MarginCollateral exchanged to cover exposureRequires operations, valuation, and liquidity management
Notes and examples

Credit-risk scenario clues

Scenario wordingLikely issueBest response logic
Borrower misses interest paymentDefault / credit deteriorationReview rating, provisions, collateral, recovery
Collateral value falls sharplyHigher LGD / margin shortfallRevalue, call margin, review haircut
Large exposure to one industryConcentration riskSet sector limits, diversify, stress test
Derivative counterparty weakens as exposure risesWrong-way counterparty riskIncrease collateral, reduce exposure, review limits
Loan documentation unclearLegal risk within credit exposureLegal review, documentation remediation

Credit Risk

Credit risk is the risk of loss from a borrower, issuer, or counterparty failing to meet obligations.

Credit Risk Types

TypeMeaningExample
Default riskBorrower or issuer fails to payBond issuer misses interest payment
Counterparty credit riskTrading counterparty defaults before final settlementDerivatives counterparty fails while contract has positive value
Settlement riskOne party pays or delivers but does not receive the counter-valueSecurities or FX settlement failure
Concentration riskExcessive exposure to one borrower, sector, region, product, or correlated groupLoan book concentrated in commercial property
Country / sovereign riskGovernment or country conditions impair repayment or transferCapital controls prevent payment
Wrong-way riskExposure increases when counterparty credit quality worsensCounterparty likely to default exactly when exposure is largest

Credit Risk Mitigation

ToolHow it helpsWatch for
Credit analysisAssesses ability and willingness to repayHistoric data may not capture future stress
LimitsCaps exposure by name, sector, rating, or productLimits must be monitored and enforced
CollateralProvides recovery sourceValuation, haircuts, liquidity, legal enforceability
NettingReduces gross exposures to net exposureDepends on legal enforceability
GuaranteesAdds another repayment sourceGuarantor credit quality matters
CovenantsTrigger early action if credit quality deterioratesWeak monitoring reduces value
DiversificationReduces idiosyncratic riskDoes not eliminate systematic risk

Credit Risk Traps

  • A high-quality counterparty can still create settlement or operational risk.
  • Collateral reduces loss given default but may not prevent default.
  • Diversification helps only when exposures are not highly correlated.
  • Credit ratings are inputs, not guarantees.
  • A lower probability of default does not always mean a lower expected loss if exposure or loss severity is high.

Market risk quick reference

Risk factorExposure exampleMeasure / sensitivityCandidate note
Interest rateBond portfolio, swaps, loansDuration, PV01/DV01, yield curve shiftBond prices generally fall when yields rise
EquityShares, equity derivativesBeta, delta, stress lossDiversification reduces idiosyncratic risk, not all market risk
FXForeign currency assets/liabilitiesNet open position, VaR, sensitivityTranslation, transaction, and economic FX exposures differ
CommodityEnergy, metals, agricultural positionsPrice sensitivity, basis riskHedging may create margin/liquidity needs
Credit spreadCorporate bonds, CDSSpread duration, spread VaRSpread widening can cause loss without default
VolatilityOptionsVegaOption value often rises with volatility, depending on position
CorrelationMulti-asset portfolioCorrelation stressCorrelations can increase in stress
BasisHedge and underlying do not move togetherBasis sensitivityHedge may reduce but not eliminate risk
Notes and examples

Derivatives sensitivity terms

TermMain meaningCommon trap
DeltaPrice sensitivity to underlyingDelta changes for nonlinear instruments
GammaSensitivity of delta to underlyingHigh gamma means delta hedge changes quickly
VegaSensitivity to volatilityNot the same as value-at-risk
ThetaSensitivity to time decayOften important for options
RhoSensitivity to interest ratesRelevant for options and rates products
DurationBond price sensitivity to yieldLonger duration usually means more rate sensitivity
ConvexityChange in duration as yield changesImproves estimate for large yield moves

Market Risk

Market risk is the risk of loss from movements in market prices or rates.

Main Market Risk Categories

RiskDriverExample
Interest rate riskChanges in yield curves or ratesBond value falls when yields rise
Equity riskShare price or index movementEquity portfolio loses value
FX riskExchange rate movementForeign currency asset declines in home currency terms
Commodity riskCommodity price movementEnergy price exposure
Credit spread riskChange in spread over risk-free ratesCorporate bond spread widens
Volatility riskChange in expected volatilityOption values move as implied volatility changes
Basis riskImperfect relationship between hedge and exposureHedge instrument does not move exactly with hedged item

Interest Rate Review

For plain fixed-rate bonds:

  • When yields rise, bond prices generally fall.
  • When yields fall, bond prices generally rise.
  • Longer duration usually means greater price sensitivity.
  • Convexity means the price-yield relationship is curved, not linear.

VaR, Stress Testing, and Backtesting

ToolWhat it doesLimitation
Value at Risk (VaR)Estimates potential loss over a time horizon at a confidence levelDoes not show worst possible loss beyond the confidence level
Stress testMeasures effect of severe but plausible scenariosScenario design may miss real future shocks
Scenario analysisExplores impact of defined market or business eventsDepends on assumptions
Sensitivity analysisTests effect of changing one variableMay ignore interactions between variables
BacktestingCompares model forecasts with actual outcomesPast performance may not validate future accuracy

Exam trap: if a question says “maximum possible loss,” VaR is usually not the correct description. VaR is a probabilistic estimate under assumptions.

Liquidity risk quick reference

Liquidity conceptMeaningExam use
Funding liquidityAbility to obtain cash to meet obligationsPayroll, margin calls, deposit outflows, debt maturities
Market liquidityAbility to sell/hedge assets without large price impactBid-ask spread, market depth, time to liquidate
Maturity mismatchShort-term liabilities fund longer-term assetsCore banking and broker-dealer funding risk
Liquidity bufferReadily available cash/high-quality liquid assetsBuys time during stress
EncumbranceAssets pledged or restrictedReduces assets available for new funding
Contingency funding planPre-agreed stress funding actionsShould include triggers, roles, communication
Cash-flow ladderTime-bucketed inflows and outflowsIdentifies gaps and rollover needs
Fire-sale riskForced sale at depressed pricesLinks liquidity risk and market risk

Key distinction: a firm can be solvent but illiquid if assets exceed liabilities but cash is unavailable when needed. A firm can also appear liquid temporarily while being economically weak.

Notes and examples

Liquidity Risk

Liquidity risk is the risk that a firm cannot meet obligations as they fall due, or can do so only at unacceptable cost.

Funding Liquidity vs Market Liquidity

TypeMeaningExample
Funding liquidity riskInability to raise cash or meet payment obligationsFirm cannot roll over short-term funding
Market liquidity riskInability to sell or close a position quickly without large price impactThinly traded bond must be sold at a deep discount

Key Liquidity Concepts

ConceptReview point
Cash flow mismatchTiming gap between inflows and outflows
Contingency funding planPre-agreed actions for liquidity stress
Liquid asset bufferAssets available to generate cash under stress
HaircutDiscount applied to collateral or asset value
Intraday liquidityAbility to meet obligations during the business day
Encumbered assetsAssets already pledged and not freely available
Liquidity stressSudden withdrawals, margin calls, market closure, funding freeze

A firm may be solvent on a balance-sheet basis but illiquid if it cannot generate cash quickly enough.

Operational risk and resilience

Operational risk sourceExampleKey controls
PeopleError, fraud, lack of training, key-person dependencySegregation, supervision, training, mandatory leave, fit-and-proper checks
ProcessFailed reconciliation, manual workaround, weak approvalProcess mapping, maker-checker, reconciliations, exception reporting
SystemsOutage, data corruption, poor access controlChange management, backups, access reviews, monitoring
External eventsNatural disaster, vendor outage, cyberattackBCP, insurance, alternate sites, incident response
OutsourcingService failure, data breach, concentration on vendorDue diligence, SLAs, right to audit, exit plan
CyberPhishing, ransomware, unauthorized accessMFA, patching, monitoring, awareness, response plan
ChangeNew system/product not controlledProject governance, testing, approvals, post-implementation review
Notes and examples

Business continuity and incident terms

TermMeaningExam trap
BCPBusiness continuity plan to maintain critical operationsBroader than IT recovery
DRDisaster recovery, usually technology recoveryPart of resilience, not the whole plan
RTORecovery time objective: target time to restoreTime measure
RPORecovery point objective: acceptable data loss pointData-loss measure
Crisis managementStrategic response and communicationsIncludes clients, regulators, staff, media
Incident managementDetect, contain, recover, learnShould include root-cause analysis
ResilienceAbility to prevent, adapt, respond, recover, learnNot just backup systems

Operational Risk

Operational risk arises from inadequate or failed internal processes, people, systems, or external events.

Operational Risk Sources

SourceExamples
PeopleError, fraud, inadequate training, misconduct
ProcessPoor procedures, failed reconciliations, weak approvals
SystemsOutage, cyber incident, data corruption, failed interface
External eventsNatural disaster, supplier failure, terrorism, pandemic disruption

Operational Risk Tools

ToolPurpose
Risk and control self-assessmentIdentifies key risks and evaluates controls
Loss event databaseRecords incidents and near misses
Key risk indicatorsMonitors emerging risk trends
Scenario analysisTests severe operational events
Business continuity planningMaintains critical services during disruption
Disaster recoveryRestores systems and data
Outsourcing oversightManages third-party service risks
Cyber controlsProtect confidentiality, integrity, and availability

Operational Risk Traps

  • A trading loss caused by market movement is market risk; a trading loss caused by booking error may be operational risk.
  • Outsourcing does not remove accountability for the activity.
  • A near miss matters because it may reveal control weakness.
  • Insurance may reduce financial impact but not reputational, client, regulatory, or continuity consequences.

Conduct, compliance, and financial crime

AreaFocusCommon controlsExam distinction
Conduct riskFair customer and market outcomesProduct governance, suitability checks, remuneration review, complaints analysisOutcome-focused, even where no explicit rule breach is obvious
Compliance riskBreach of rules or regulatory obligationsCompliance monitoring, policy advice, training, breach logsRule-focused
Market abuse riskInsider dealing, manipulation, misuse of informationSurveillance, restricted lists, wall-crossing controlsOften linked to trading and information barriers
Conflicts of interestFirm/staff incentive conflicts with client dutyDisclosure, avoidance, independent approval, gifts policyDisclosure alone may not be enough
Financial crimeAML, fraud, bribery, sanctions evasionCDD/KYC, transaction monitoring, screening, suspicious activity processesRed flags require investigation and escalation
Data protection / confidentialityMisuse or loss of client/personal dataAccess controls, encryption, clean desk, data retentionAlso operational, legal, and reputational risk

Capital, prudential risk, and Basel-style concepts

ConceptMeaningCandidate note
Regulatory capitalCapital required under applicable rulesRule-based and externally supervised
Economic capitalInternal estimate of capital needed for risksModel-based and management-focused
Risk-weighted assetsAssets/exposures adjusted for riskHigher-risk exposures generally require more capital
Capital adequacySufficiency of capital relative to risksLinks risk appetite, strategy, and resilience
Pillar 1Minimum capital framework for key risk categoriesConceptual categories matter more than memorizing figures unless supplied
Pillar 2Supervisory/internal review of wider risks and capital adequacyCaptures risks not fully covered by minimum formulas
Pillar 3Market discipline through disclosureTransparency to external stakeholders
LeverageUse of debt or exposure relative to capitalCan magnify losses even if risk weights appear low
Stress capital impactCapital effect under adverse scenariosTests resilience beyond normal conditions

Key formulas and calculation reminders

Expected credit loss

\[ \text{Expected loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]

Use this for average expected credit loss. Do not confuse expected loss with worst-case loss or capital for unexpected loss.

Risk score

\[ \text{Risk score} = \text{Likelihood} \times \text{Impact} \]

Risk matrices are simple prioritization tools. They are not precise measurement models.

Capital ratio

\[ \text{Capital ratio} = \frac{\text{Eligible regulatory capital}}{\text{Risk-weighted assets}} \]

Higher capital supports loss absorption. Do not assume a specific required percentage unless it is provided in the question or study material.

RAROC

\[ \text{RAROC} = \frac{\text{Risk-adjusted return}}{\text{Economic capital}} \]

RAROC helps compare business returns after considering the risk capital consumed.

Parametric VaR approximation

\[ \text{VaR} \approx z_c \times \sigma \times V \times \sqrt{t} \]

Where \(z_c\) is the confidence-level factor, \(\sigma\) is volatility, \(V\) is portfolio value, and \(t\) is the time horizon. Watch sign conventions: VaR is normally expressed as a positive loss amount.

Bond price sensitivity

\[ \Delta P \approx -D_{\text{mod}} \times P \times \Delta y \]

A rise in yield usually reduces a fixed-rate bond price. Longer modified duration means greater sensitivity.

PV01 / DV01 approximation

\[ \text{PV01} \approx D_{\text{mod}} \times P \times 0.0001 \]

PV01 estimates the price change for a one basis point yield move.

VaR, stress testing, and scenarios

ToolPurposeStrengthLimitation
VaREstimates loss not expected to be exceeded at a confidence level over a time horizonUseful common market-risk metricDoes not show size of losses beyond the confidence level
Expected shortfallAverage loss beyond VaR thresholdBetter tail-risk viewMore model-dependent
Sensitivity analysisChanges one variable or factorEasy to interpretIgnores multi-factor interactions
Scenario analysisApplies a coherent set of assumptionsCaptures plausible narrativesScenario selection is subjective
Stress testingTests extreme but plausible conditionsHighlights vulnerabilitiesNot a forecast
Reverse stress testingStarts with failure outcome and asks what could cause itIdentifies existential vulnerabilitiesCan be uncomfortable and judgment-heavy
BacktestingCompares model predictions with actual outcomesTests model performancePast data may not represent future stress
BenchmarkingCompares against alternatives or peersHelps challenge assumptionsBenchmark may not fit portfolio
Notes and examples

VaR traps

  • A 99% VaR is not the maximum possible loss.
  • VaR depends on horizon, confidence level, data, model, and assumptions.
  • Diversification benefits may disappear when correlations rise in stress.
  • VaR may understate illiquid positions, basis risk, jump risk, and model risk.
  • Backtesting exceptions do not automatically prove fraud or misconduct; they may indicate model weakness, volatility change, or data issues.

Controls and assurance

Control typePurposeExamplesExam clue
PreventiveStop error or breach before it occursPre-trade limits, approvals, access restrictionsBest when loss prevention is critical
DetectiveIdentify errors or breaches after occurrenceReconciliations, exception reports, surveillanceUseful where prevention cannot be complete
CorrectiveFix issue and reduce recurrenceRoot-cause remediation, system patch, process redesignNot just compensation or apology
DirectiveGuide expected behaviorPolicies, procedures, trainingWeak if not monitored
AutomatedSystem-enforced controlHard limits, mandatory fieldsStrong consistency but needs change control
ManualHuman-operated controlReview sign-off, call-back confirmationFlexible but prone to error
CompensatingAlternative control when primary control is weak/unavailableExtra review during system outageUsually temporary or risk-based
Notes and examples

Control effectiveness

AssessmentQuestion to askEvidence
Design effectivenessWould the control address the risk if performed correctly?Policy, process map, control description
Operating effectivenessDid the control operate as intended over time?Samples, logs, approvals, reconciliations
CoverageDoes it cover all relevant products/entities/processes?Scope, population testing
TimelinessIs the control performed soon enough?Timestamps, escalation records
IndependenceIs review performed by someone sufficiently independent?Role segregation, reporting lines

Risk responses

ResponseMeaningBest forTrap
AvoidStop the activityRisk outside appetiteMay sacrifice return or strategic opportunity
ReduceLower likelihood or impactMost controllable operational and credit risksRequires control evidence
TransferShift some financial impactInsurance, guarantees, hedging, outsourcingDoes not remove all risk; creates counterparty/legal/basis risk
AcceptRetain risk knowinglyLow risk or cost of control exceeds benefitMust be within appetite and documented
Exploit / pursueTake risk for rewardMarket, credit, strategic opportunitiesNeeds pricing, limits, and governance

Reporting and escalation

Report elementWhy it matters
Current exposure vs limitShows whether activity is within approved boundaries
TrendDeterioration may matter before a breach occurs
Appetite statusLinks metrics to board-approved risk stance
Breaches and exceptionsRequires ownership, root cause, remediation date
Losses and near missesIndicates control weakness and emerging risk
Top and emerging risksHelps governance focus on material risks
Stress/scenario resultsShows vulnerability under adverse conditions
Action trackingEnsures reporting leads to remediation
Owner and due dateCreates accountability

Good risk reporting is accurate, timely, relevant, escalated, and action-oriented.

Scenario decision table

If the question emphasizes…Think first of…Strong answer usually includes…
Customer sold unsuitable productConduct riskProduct governance, suitability, training, incentive review
Policy exists but staff bypass itControl operating failure / cultureMonitoring, enforcement, root-cause analysis
Unreconciled cash breaksOperational riskDaily reconciliation, exception escalation
Bond portfolio loses value after yield riseMarket risk, interest-rate riskDuration/PV01, hedging, limits
Client defaults on loanCredit riskPD/LGD/EAD, collateral, recovery
Derivative counterparty fails before maturityCounterparty credit riskNetting, collateral, exposure replacement
Cannot sell assets except at large discountMarket liquidity riskLiquidity buffer, stress haircut, funding plan
Cannot roll over short-term fundingFunding liquidity riskCash-flow ladder, contingency funding
Losses exceed model forecast repeatedlyModel riskBacktesting, validation, recalibration, governance
Outsourced provider outageOperational / outsourcing riskSLA, resilience testing, exit plan, incident management
Suspicious transaction patternFinancial crime riskMonitoring, investigation, escalation
Traders share confidential information improperlyConduct / market abuse / information barrier riskSurveillance, restricted lists, training, discipline
Concentrated exposure to one sectorConcentration riskLimits, diversification, stress testing
Rapid business growth with weak controlsStrategic plus operational riskGovernance, capacity, control investment
Regulator criticizes breach reportingCompliance/governance riskBreach process, accountability, timely escalation

Common exam traps checklist

  • Do not choose insurance as eliminating operational risk; it only transfers some financial impact.
  • Do not call every regulatory issue conduct risk; conduct focuses on customer/market outcomes, compliance on rule adherence.
  • Do not call every price movement credit risk; market risk can occur without default.
  • Do not treat collateral as risk-free; value, enforceability, liquidity, and concentration matter.
  • Do not confuse funding liquidity with market liquidity.
  • Do not confuse risk appetite with risk capacity or limits.
  • Do not assume diversification removes systemic risk.
  • Do not assume outsourcing transfers accountability away from the firm.
  • Do not treat VaR as a worst-case loss.
  • Do not let a strong KPI hide a worsening KRI.
  • Do not confuse root cause remediation with temporary workaround.
  • Do not select internal audit as the owner of first-line controls.
  • Do not assume high capital fixes poor culture, conduct, or operational control weaknesses.
  • Do not ignore correlation and concentration in stress scenarios.
  • Do not overlook reputational impact as a secondary consequence.

Fast revision drill

For any practice question, answer in this order:

  1. Risk type: credit, market, liquidity, operational, conduct, compliance, model, strategic, reputational, financial crime, or legal.
  2. Risk driver: people, process, system, market factor, counterparty, behavior, governance, external event.
  3. Exposure metric: PD/LGD/EAD, VaR, duration, cash-flow gap, KRI, loss data, breach count, complaints.
  4. Control: preventive, detective, corrective, or governance response.
  5. Owner: first line owns; second line challenges; third line assures.
  6. Escalation: compare with appetite/limit, report breach, remediate root cause.
  7. Residual risk: decide whether remaining risk is acceptable.

Cheat Sheet for CISI Risk in Financial Services

This Cheat Sheet is an independent companion for candidates preparing for the Chartered Institute for Securities & Investment CISI Risk in Financial Services exam, official code CISI Risk. Use it to refresh high-yield concepts before moving into topic drills, mock exams, original practice questions, and detailed explanations.

The exam rewards candidates who can connect risk definitions to practical decisions: identifying the source of risk, choosing an appropriate control, understanding governance responsibilities, and recognising the limitations of measurement tools.

Core Risk Language

Essential Definitions

TermQuick meaningCandidate decision point
RiskUncertainty that may affect objectivesAsk: what objective is threatened?
Risk eventThe incident that could occurSeparate the event from its cause and impact
CauseWhy the event could happenControls should usually address causes
ImpactThe consequence if the event occursImpacts may be financial, regulatory, operational, client, or reputational
Inherent riskRisk before controlsUsed to understand the raw exposure
Residual riskRisk after controlsCompare this with risk appetite
Risk appetiteBroad amount/type of risk an organisation is willing to acceptSet by senior governance, not by operational teams alone
Risk toleranceMore specific acceptable variation around appetiteOften translated into measurable thresholds
LimitsOperational boundaries for day-to-day controlBreaches require monitoring and escalation
KRIKey risk indicator: signals changing risk exposureForward-looking where possible
KPIKey performance indicator: measures performanceHigh performance can still create high risk
KCIKey control indicator: measures control effectivenessUseful for detecting control weakness
Notes and examples

Expected Loss and Unexpected Loss

Credit risk often uses the expected loss relationship:

\[ \text{Expected Loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]

Where:

  • PD = probability of default.
  • LGD = loss given default.
  • EAD = exposure at default.

Expected loss is the average loss anticipated over a period. Unexpected loss is the adverse variation around that expectation and is a key reason firms hold capital.

Risk Management Framework

A strong framework does not eliminate risk. It makes risk visible, owned, measured, controlled, and escalated.

    flowchart LR
	    A[Identify risks] --> B[Assess likelihood and impact]
	    B --> C[Measure exposure]
	    C --> D[Choose response]
	    D --> E[Implement controls]
	    E --> F[Monitor indicators and limits]
	    F --> G[Report and escalate]
	    G --> H[Review and improve]
	    H --> A

The Risk Response Decision

ResponseMeaningExample
AvoidStop the activity creating the riskExit a product or market that cannot be controlled
Reduce / mitigateLower likelihood or impactLimits, collateral, segregation of duties, system controls
TransferShift part of the risk to another partyInsurance, guarantees, hedging, outsourcing with contractual protections
AcceptRetain the risk consciouslyAccept low residual risk within appetite

A common exam mistake is to choose a risk transfer answer as if it removes the risk completely. Transfer normally changes the risk profile; it may introduce counterparty, legal, basis, or operational risk.

Controls: Fast Classification

Control typePurposeExamples
PreventiveStop errors or events before they occurPre-trade limits, access controls, approvals, segregation of duties
DetectiveIdentify problems after occurrenceReconciliations, exception reports, surveillance, audit testing
CorrectiveFix issues and reduce recurrenceRemediation plans, process redesign, disciplinary action
DirectiveGuide behaviourPolicies, procedures, training, risk appetite statements
CompensatingOffset weakness in another controlAdditional review where automation is unavailable

Control Quality Checklist

A good control is:

  1. Linked to a specific risk and cause.
  2. Owned by a named person or team.
  3. Performed at the right frequency.
  4. Evidenced and auditable.
  5. Escalated when exceptions occur.
  6. Reviewed when business activity changes.

Distinguish the Concepts

RiskFocusExample
Conduct riskPoor outcomes for clients or market integrityUnsuitable product recommendation
Compliance riskBreach of laws, rules, regulations, or internal standardsFailure to follow regulatory reporting requirements
Legal riskContracts, enforceability, litigation, documentationNetting agreement not enforceable
Reputational riskLoss of trust or confidencePublic criticism after control failure
Financial crime riskMoney laundering, sanctions, fraud, bribery, corruptionInadequate client due diligence
Notes and examples

Conduct risk can exist even where a narrow rule breach is not obvious. Look for fairness, transparency, conflicts of interest, suitability, market abuse prevention, and client outcomes.

Conflicts of Interest

Common controls include:

  • Disclosure where appropriate.
  • Avoidance where the conflict cannot be managed.
  • Information barriers.
  • Independent review.
  • Personal account dealing rules.
  • Gifts and entertainment controls.
  • Fair allocation policies.

Exam questions often include a tempting answer of “disclose and continue.” Disclosure alone is not always enough if the conflict remains unmanaged.

Model Risk and Data Risk

Model risk is the risk of loss or poor decision-making from incorrect, misused, or poorly governed models.

Source of model riskExample control
Incorrect assumptionsIndependent validation
Poor data qualityData lineage, reconciliation, quality checks
Coding or implementation errorTesting, change control, peer review
Misuse outside intended purposeModel documentation and usage limits
Lack of monitoringPerformance tracking and periodic review
OverrelianceManagement challenge and expert judgment

Model output should support judgment, not replace it. A precise number can still be wrong if assumptions are unrealistic.

Capital, Solvency, and Prudential Thinking

Capital protects a firm and its stakeholders by absorbing losses. Risk management connects business activity to the amount and quality of capital needed.

ConceptQuick review
Regulatory capitalCapital required under applicable regulatory frameworks
Economic capitalInternal estimate of capital needed for the firm’s risk profile
Risk-weighted exposureExposure adjusted for risk characteristics
LeverageRelationship between assets/exposures and capital
Stress capital impactCapital effect under severe adverse scenarios
ProvisioningRecognition of expected credit losses or impairments
Capital planningEnsuring adequate capital under normal and stressed conditions

Do not confuse:

  • Provisions for expected losses with capital for unexpected losses.
  • Liquidity with solvency.
  • Accounting value with realisable value under stress.

Enterprise-Wide Risk and Aggregation

Risks interact. A strong answer recognises second-order effects.

Initial eventPossible linked risks
Market shockMargin calls, liquidity strain, credit downgrade, client complaints
Cyber incidentOperational disruption, data breach, legal liability, reputational damage
Counterparty defaultCredit loss, replacement cost, liquidity pressure, legal dispute
Mis-selling issueConduct breach, remediation cost, regulatory attention, reputational harm
Outsourcing failureOperational disruption, client harm, compliance breach

Correlation and concentration matter. Risks that look diversified in normal conditions may become highly correlated in stress.

Common Decision Rules

When Asked “What Is the Best Control?”

Choose the control that directly addresses the cause of the risk.

Scenario clueStrong control response
Unauthorised transactionAccess control, approval, segregation of duties
Repeated processing errorsProcedure redesign, automation, training, reconciliation
Limit breachImmediate escalation, investigation, remediation
Unclear ownershipAssign accountable owner and reporting line
Third-party failureDue diligence, service levels, monitoring, exit planning
Poor client outcomeSuitability review, disclosure improvement, conflict management
Model output questionedIndependent validation, assumption review, backtesting where relevant
Notes and examples

When Asked “Who Is Responsible?”

If the issue is…Likely responsibility
Day-to-day risk taking and controlsFirst line
Policy, oversight, challenge, compliance monitoringSecond line
Independent assurance over the frameworkThird line / internal audit
Risk appetite and oversightBoard / governing body
Implementation of appetite and controlsSenior management

When Asked “What Should Happen After a Breach?”

A practical sequence is:

  1. Stop or contain the issue where necessary.
  2. Escalate promptly.
  3. Assess impact.
  4. Identify root cause.
  5. Remediate the immediate breach.
  6. Strengthen controls to prevent recurrence.
  7. Record evidence and monitor completion.

Common Candidate Mistakes

MistakeBetter approach
Memorising definitions without applying themIdentify event, cause, impact, control, and owner
Assuming risk transfer removes riskConsider residual, legal, counterparty, and operational risks
Treating VaR as a worst-case lossRemember it is a confidence-based estimate
Confusing compliance and conductConduct focuses on client and market outcomes
Ignoring near missesNear misses are evidence of possible control weakness
Thinking audit owns riskAudit provides independent assurance; management owns risk
Choosing the most severe control automaticallyMatch the response to materiality and appetite
Overlooking liquidity effectsAsk whether cash is available when needed
Confusing inherent and residual riskInherent is before controls; residual is after controls
Assuming policies equal control effectivenessLook for evidence, monitoring, exceptions, and escalation

Rapid Review Tables by Risk Type

Risk Type, Signal, and Control

Risk typeWarning signalTypical control
CreditRising arrears, downgrade, covenant breachLimits, collateral, monitoring, restructuring action
MarketVolatile prices, limit utilisation, basis mismatchPosition limits, hedging, stress testing
LiquidityFunding concentration, margin calls, cash gapLiquidity buffer, contingency funding plan
OperationalIncidents, near misses, high manual processingRCSA, reconciliations, automation, training
ConductComplaints, unsuitable sales, poor disclosureProduct governance, suitability checks, monitoring
ComplianceRule breach, late reporting, failed surveillanceCompliance monitoring, policy controls, escalation
LegalContract dispute, unenforceable clauseLegal review, documentation standards
ReputationalNegative media, loss of client trustGovernance, communication, remediation
ModelOverride spikes, poor backtesting, stale assumptionsValidation, monitoring, change control
OutsourcingSLA failures, weak oversight, concentrationDue diligence, reporting, exit plan
Notes and examples

Measurement Tools

ToolBest forWeakness
Heat mapPrioritising risks by likelihood and impactCan be subjective
LimitsDay-to-day controlMust be calibrated and enforced
KRIsEarly warningPoor indicators create false comfort
Stress testsSevere scenario analysisScenario selection is judgmental
Loss dataLearning from incidentsPast losses may understate future exposure
RCSABusiness-led risk assessmentCan become a checklist exercise
Audit testingIndependent assurancePeriodic, not continuous
DashboardsManagement oversightCan hide detail if poorly designed

Practice Strategy for CISI Risk

Use this Cheat Sheet first, then move into independent companion practice. The fastest improvement usually comes from alternating short review with original practice questions and detailed explanations.

Suggested Practice Sequence

  1. Definitions drill Practise appetite, tolerance, inherent risk, residual risk, KRI, operational risk, credit risk, market risk, and liquidity risk.

  2. Risk classification drill For each scenario, identify the primary risk and any secondary risks.

  3. Control selection drill Match risk causes to preventive, detective, corrective, and compensating controls.

  4. Governance drill Decide whether the issue belongs mainly to the first line, second line, third line, senior management, or board oversight.

  5. Scenario mixed practice Use question bank sets that combine risk types, escalation, controls, and measurement limitations.

  6. Mock exam practice Sit timed mock exams only after you can explain why wrong answers are wrong.

What to Review After Each Question

For every missed question, write one line for each:

  • What risk type was being tested?
  • What clue in the wording mattered?
  • Which answer was tempting but wrong?
  • What rule would help next time?

Final Exam-Readiness Checklist

Before attempting a full mock exam, make sure you can:

  • Explain risk appetite, tolerance, limits, inherent risk, and residual risk.
  • Distinguish credit, market, liquidity, operational, conduct, compliance, legal, and reputational risk.
  • Apply the three lines model to practical scenarios.
  • Choose controls based on the cause of the risk.
  • Recognise the limits of VaR, stress testing, ratings, models, and collateral.
  • Explain why outsourcing, insurance, hedging, and collateral reduce but do not eliminate risk.
  • Identify when escalation is required.
  • Connect risk events to second-order impacts.
  • Learn from detailed explanations, not just answer keys.

Use this Cheat Sheet as your final concept check, then move into topic drills, original practice questions, and timed question bank practice with detailed explanations to convert recognition into exam-ready judgment.

Put the review into practice

Browse Practice Tests & Interview Prep