CISI Risk in Financial Services Cheat Sheet
Compact independent Cheat sheet for Chartered Institute for Securities & Investment CISI Risk in Financial Services (CISI Risk) candidates: risk types, controls, governance, formulas, and scenario decision points.
Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.
Scope and study context
- Identify the risk type from a short scenario.
- Separate cause, event, impact, control, and owner.
- Choose the best control or governance response.
- Interpret risk metrics and formulas without confusing related terms.
- Recognize common traps: residual vs inherent risk, market vs credit risk, conduct vs compliance risk, liquidity vs solvency, audit vs risk ownership.
Core risk-management workflow
flowchart LR
A[Identify risk] --> B[Assess inherent risk]
B --> C[Select response and controls]
C --> D[Measure residual risk]
D --> E[Monitor KRIs, limits, losses]
E --> F[Report and escalate]
F --> G[Review appetite, policies, lessons learned]
G --> A
| Step | Candidate focus | Typical exam clue |
|---|---|---|
| Identify | What could go wrong? Which risk category? | New product, failed process, counterparty default, cyber incident |
| Assess | Likelihood, impact, velocity, correlation, concentration | Heat map, scoring, scenario estimate, expected loss |
| Respond | Avoid, reduce, transfer, accept | Hedge, insure, collateralize, outsource, set limits |
| Control | Preventive, detective, corrective measures | Segregation, reconciliation, confirmation, monitoring |
| Monitor | Indicators and breaches | KRI trend, limit excess, near miss, audit finding |
| Report | Right audience, frequency, escalation | Board risk pack, risk committee, regulatory notification |
| Review | Lessons learned and continuous improvement | Post-incident review, control redesign, policy update |
Notes and examples
High-Yield Risk Map
| Area | What to know quickly | Common exam trap |
|---|---|---|
| Risk governance | Board oversight, risk appetite, policies, reporting, escalation, three lines model | Treating risk management as only a compliance or audit function |
| Risk process | Identify, assess, measure, mitigate, monitor, report, review | Jumping to controls before defining the risk event and cause |
| Credit risk | Default risk, counterparty risk, settlement risk, concentration, collateral, netting | Confusing issuer credit risk with market price movement |
| Market risk | Interest rate, FX, equity, commodity, spread, volatility, basis risk | Assuming VaR predicts the maximum possible loss |
| Liquidity risk | Funding liquidity vs market liquidity, cash flow mismatch, contingency funding | Confusing a solvent firm with a liquid firm |
| Operational risk | People, process, systems, external events; cyber, fraud, outsourcing, business continuity | Classifying every loss as operational risk without identifying the root cause |
| Conduct and compliance risk | Fair client treatment, conflicts, suitability, market abuse controls, regulatory obligations | Thinking compliance risk is only about fines, not client and market outcomes |
| Model and data risk | Assumptions, validation, data quality, limitations, change control | Treating model output as fact rather than a decision input |
| Capital and stress testing | Capital absorbs unexpected losses; stress tests explore severe but plausible conditions | Confusing expected loss provisions with capital for unexpected loss |
| Risk culture | Incentives, challenge, escalation, accountability, tone from the top | Believing policies alone create effective risk management |
High-yield risk vocabulary
| Term | Meaning | Exam trap |
|---|---|---|
| Risk | Effect of uncertainty on objectives | Risk is not always purely negative; some risk is accepted for return |
| Risk event | Occurrence that creates loss or adverse outcome | Do not confuse event with root cause |
| Cause | Underlying driver of a risk event | Example: weak access control causes unauthorized payment |
| Impact | Consequence if the event occurs | Can be financial, regulatory, customer, operational, reputational |
| Inherent risk | Risk before controls | Usually higher than residual risk if controls are effective |
| Residual risk | Risk remaining after controls | Not automatically acceptable; compare with appetite |
| Risk appetite | Amount/type of risk the firm is willing to accept | Board-level concept, not a single operational limit |
| Risk tolerance | Permitted variation around appetite | Often expressed through thresholds or ranges |
| Risk capacity | Maximum risk the firm can bear | Capacity constrains appetite |
| Risk limit | Quantified boundary for activity or exposure | Breach should trigger action/escalation |
| KRI | Key risk indicator; forward-looking or risk-focused metric | Different from KPI, which measures performance |
| KPI | Key performance indicator | High sales KPI can increase conduct risk |
| KCI | Key control indicator | Measures whether a control is operating |
| RCSA | Risk and control self-assessment | Self-assessment needs challenge; not independent assurance |
| Loss event | Actual incident causing loss | Near misses matter even without financial loss |
| Near miss | Incident avoided before loss crystallized | Useful for trend analysis and control improvement |
| Risk owner | Person/function accountable for managing the risk | Usually first line, not internal audit |
| Control owner | Person responsible for operating a control | Control ownership may differ from risk ownership |
| Assurance | Independent check over control design/effectiveness | Assurance does not transfer risk ownership |
| Escalation | Raising a breach or issue to the right level | Reporting alone is not remediation |
Risk appetite, limits, and escalation
| Concept | Level | Practical example | What to remember |
|---|---|---|---|
| Capacity | Firm survival / capital / liquidity | Maximum loss the firm could withstand | Hard boundary; appetite must sit within it |
| Appetite | Board and strategy | Low appetite for regulatory breaches | Guides business decisions |
| Tolerance | Business/risk policy | Acceptable range of operational losses | More granular than appetite |
| Limit | Desk, portfolio, product, counterparty | FX VaR limit, single-name credit limit | Breach requires defined action |
| Trigger | Early warning | 80% of limit used, rising complaints | Prompts monitoring before breach |
| Breach | Control boundary exceeded | Trader exceeds position limit | Requires escalation and remediation |
Common distinction: risk appetite is a governance choice; risk limit is an operating control.
Three lines and governance roles
| Role | Main responsibility | Should not be mistaken for |
|---|---|---|
| Board / governing body | Set strategy, risk appetite, oversight culture | Day-to-day control operator |
| Board risk committee | Challenge risk profile, limits, major exposures | First-line risk owner |
| Senior management | Implement strategy, allocate resources, enforce accountability | Independent assurance |
| First line | Own and manage risks in business activities | Passive recipient of risk reports |
| Second line | Risk, compliance, oversight, frameworks, challenge | Final owner of business risk |
| Third line | Internal audit; independent assurance | Control designer/operator for management |
| External audit | Financial statement assurance and selected controls review | Substitute for internal risk management |
| Regulator | Supervisory expectations and enforcement | Internal governance function |
Notes and examples
Governance traps
- Internal audit does not own risk; it provides independent assurance.
- Risk function challenge is not the same as business approval.
- A policy is not a control unless implemented and evidenced.
- Tone from the top matters, but culture also depends on incentives, accountability, escalation, and consequences.
- Conflicts of interest are conduct and governance risks, not merely administrative issues.
Roles and Responsibilities
| Function | Main role | What not to confuse |
|---|---|---|
| Board / governing body | Sets strategy, approves risk appetite, oversees risk framework | Does not usually run day-to-day controls |
| Senior management | Implements strategy and risk appetite, owns business risks | Cannot delegate accountability entirely to risk or compliance teams |
| First line | Business and operational management owning risks and controls | Not merely “sales”; includes control ownership |
| Second line | Risk, compliance, financial crime, specialist oversight functions | Challenges and advises; does not replace first-line ownership |
| Third line | Internal audit independent assurance | Tests the framework; does not design or operate routine controls |
| External audit / regulators | External assurance or supervision where applicable | Not part of daily risk ownership |
Risk Appetite, Limits, and Escalation
| Concept | Practical interpretation |
|---|---|
| Appetite statement | “How much and what type of risk are we prepared to take?” |
| Limit | “What boundary must a desk, portfolio, process, or person stay within?” |
| Breach | A limit or policy exception requiring action |
| Escalation | Timely reporting to the right level of authority |
| Remediation | Action to correct the breach and address root causes |
Exam questions often test whether a breach should be ignored because no loss has occurred. The safer answer is usually that breaches matter because they indicate control failure or risk outside agreed boundaries.
Major risk categories
| Risk type | What can go wrong | Common measures | Common controls / mitigants | Exam distinction |
|---|---|---|---|---|
| Credit risk | Borrower/counterparty fails to meet obligation | PD, LGD, EAD, ratings, arrears, exposure limits | Credit approval, limits, collateral, covenants, diversification | Default risk is not the same as market price movement |
| Counterparty risk | Trading counterparty defaults before final settlement | Current exposure, potential future exposure, net exposure | Netting, margin, collateral, central clearing | Often arises in derivatives and securities financing |
| Settlement risk | One party delivers but does not receive value | Failed settlements, unmatched trades | Delivery versus payment, payment versus payment, confirmations | Short-lived but potentially severe |
| Market risk | Loss from market price movements | VaR, stress loss, sensitivities, volatility | Limits, hedging, diversification, stop-loss, stress testing | Includes rates, FX, equity, commodity, spreads, volatility |
| Liquidity risk | Cannot meet obligations or exit positions at fair price | Cash-flow gaps, funding concentration, liquidity coverage metrics | Buffers, contingency funding, maturity ladder, diversified funding | Liquidity risk differs from solvency risk |
| Operational risk | Failure of people, process, systems, or external events | Loss data, KRIs, RCSA scores, incidents | Segregation, reconciliations, access controls, BCP, training | Includes cyber, fraud, processing, outsourcing |
| Conduct risk | Poor customer/market outcomes from firm behavior | Complaints, redress, sales patterns, suitability exceptions | Product governance, training, surveillance, incentives review | Broader than rule breach; focuses on outcomes |
| Compliance risk | Breach of laws, rules, regulations, or standards | Breaches, monitoring findings, regulatory correspondence | Policies, monitoring, advice, training, attestations | Related to conduct, but not identical |
| Legal risk | Contracts unenforceable or litigation exposure | Claims, disputes, contract exceptions | Legal review, enforceable documentation, jurisdiction analysis | Often embedded in credit, collateral, outsourcing |
| Financial crime risk | Money laundering, fraud, bribery, sanctions evasion | Alerts, suspicious activity, fraud losses | CDD/KYC, screening, transaction monitoring, segregation | Control failure can create regulatory and reputational impact |
| Model risk | Model produces wrong or misused output | Backtesting, validation findings, overrides | Independent validation, governance, documentation, limitations | A correct model can still be misused |
| Strategic risk | Poor strategic decisions or business model weakness | Revenue concentration, competitor trends, plan variance | Strategy review, scenario planning, board challenge | Not usually solved by a simple operational control |
| Reputational risk | Stakeholder trust damaged | Media, complaints, client exits, funding impact | Strong governance, incident response, conduct controls | Often secondary to another risk event |
| Climate / ESG risk | Physical, transition, liability, or governance exposure | Sector concentration, scenario results, disclosures | Due diligence, limits, scenario analysis, engagement | Can transmit through credit, market, operational, legal risk |
Credit risk quick reference
| Concept | Meaning | Practical use |
|---|---|---|
| PD | Probability of default | Likelihood borrower/counterparty defaults |
| LGD | Loss given default | Severity after recoveries and collateral |
| EAD | Exposure at default | Amount exposed when default occurs |
| Expected loss | Average credit loss expected over time | Pricing, provisioning, portfolio planning |
| Unexpected loss | Loss above expected level | Economic capital and stress resilience |
| Credit rating | Relative creditworthiness indicator | Input to limits and pricing, not a guarantee |
| Collateral | Asset pledged to reduce loss | Reduces LGD, but introduces valuation/legal/liquidity risk |
| Covenant | Contractual restriction or trigger | Early warning or control over borrower behavior |
| Concentration risk | Too much exposure to one name, sector, geography, or correlation | Diversification and limits |
| Wrong-way risk | Exposure increases as counterparty credit quality worsens | Important in derivatives and collateral arrangements |
| Netting | Offsetting exposures under enforceable agreement | Reduces net exposure if legally valid |
| Margin | Collateral exchanged to cover exposure | Requires operations, valuation, and liquidity management |
Notes and examples
Credit-risk scenario clues
| Scenario wording | Likely issue | Best response logic |
|---|---|---|
| Borrower misses interest payment | Default / credit deterioration | Review rating, provisions, collateral, recovery |
| Collateral value falls sharply | Higher LGD / margin shortfall | Revalue, call margin, review haircut |
| Large exposure to one industry | Concentration risk | Set sector limits, diversify, stress test |
| Derivative counterparty weakens as exposure rises | Wrong-way counterparty risk | Increase collateral, reduce exposure, review limits |
| Loan documentation unclear | Legal risk within credit exposure | Legal review, documentation remediation |
Credit Risk
Credit risk is the risk of loss from a borrower, issuer, or counterparty failing to meet obligations.
Credit Risk Types
| Type | Meaning | Example |
|---|---|---|
| Default risk | Borrower or issuer fails to pay | Bond issuer misses interest payment |
| Counterparty credit risk | Trading counterparty defaults before final settlement | Derivatives counterparty fails while contract has positive value |
| Settlement risk | One party pays or delivers but does not receive the counter-value | Securities or FX settlement failure |
| Concentration risk | Excessive exposure to one borrower, sector, region, product, or correlated group | Loan book concentrated in commercial property |
| Country / sovereign risk | Government or country conditions impair repayment or transfer | Capital controls prevent payment |
| Wrong-way risk | Exposure increases when counterparty credit quality worsens | Counterparty likely to default exactly when exposure is largest |
Credit Risk Mitigation
| Tool | How it helps | Watch for |
|---|---|---|
| Credit analysis | Assesses ability and willingness to repay | Historic data may not capture future stress |
| Limits | Caps exposure by name, sector, rating, or product | Limits must be monitored and enforced |
| Collateral | Provides recovery source | Valuation, haircuts, liquidity, legal enforceability |
| Netting | Reduces gross exposures to net exposure | Depends on legal enforceability |
| Guarantees | Adds another repayment source | Guarantor credit quality matters |
| Covenants | Trigger early action if credit quality deteriorates | Weak monitoring reduces value |
| Diversification | Reduces idiosyncratic risk | Does not eliminate systematic risk |
Credit Risk Traps
- A high-quality counterparty can still create settlement or operational risk.
- Collateral reduces loss given default but may not prevent default.
- Diversification helps only when exposures are not highly correlated.
- Credit ratings are inputs, not guarantees.
- A lower probability of default does not always mean a lower expected loss if exposure or loss severity is high.
Market risk quick reference
| Risk factor | Exposure example | Measure / sensitivity | Candidate note |
|---|---|---|---|
| Interest rate | Bond portfolio, swaps, loans | Duration, PV01/DV01, yield curve shift | Bond prices generally fall when yields rise |
| Equity | Shares, equity derivatives | Beta, delta, stress loss | Diversification reduces idiosyncratic risk, not all market risk |
| FX | Foreign currency assets/liabilities | Net open position, VaR, sensitivity | Translation, transaction, and economic FX exposures differ |
| Commodity | Energy, metals, agricultural positions | Price sensitivity, basis risk | Hedging may create margin/liquidity needs |
| Credit spread | Corporate bonds, CDS | Spread duration, spread VaR | Spread widening can cause loss without default |
| Volatility | Options | Vega | Option value often rises with volatility, depending on position |
| Correlation | Multi-asset portfolio | Correlation stress | Correlations can increase in stress |
| Basis | Hedge and underlying do not move together | Basis sensitivity | Hedge may reduce but not eliminate risk |
Notes and examples
Derivatives sensitivity terms
| Term | Main meaning | Common trap |
|---|---|---|
| Delta | Price sensitivity to underlying | Delta changes for nonlinear instruments |
| Gamma | Sensitivity of delta to underlying | High gamma means delta hedge changes quickly |
| Vega | Sensitivity to volatility | Not the same as value-at-risk |
| Theta | Sensitivity to time decay | Often important for options |
| Rho | Sensitivity to interest rates | Relevant for options and rates products |
| Duration | Bond price sensitivity to yield | Longer duration usually means more rate sensitivity |
| Convexity | Change in duration as yield changes | Improves estimate for large yield moves |
Market Risk
Market risk is the risk of loss from movements in market prices or rates.
Main Market Risk Categories
| Risk | Driver | Example |
|---|---|---|
| Interest rate risk | Changes in yield curves or rates | Bond value falls when yields rise |
| Equity risk | Share price or index movement | Equity portfolio loses value |
| FX risk | Exchange rate movement | Foreign currency asset declines in home currency terms |
| Commodity risk | Commodity price movement | Energy price exposure |
| Credit spread risk | Change in spread over risk-free rates | Corporate bond spread widens |
| Volatility risk | Change in expected volatility | Option values move as implied volatility changes |
| Basis risk | Imperfect relationship between hedge and exposure | Hedge instrument does not move exactly with hedged item |
Interest Rate Review
For plain fixed-rate bonds:
- When yields rise, bond prices generally fall.
- When yields fall, bond prices generally rise.
- Longer duration usually means greater price sensitivity.
- Convexity means the price-yield relationship is curved, not linear.
VaR, Stress Testing, and Backtesting
| Tool | What it does | Limitation |
|---|---|---|
| Value at Risk (VaR) | Estimates potential loss over a time horizon at a confidence level | Does not show worst possible loss beyond the confidence level |
| Stress test | Measures effect of severe but plausible scenarios | Scenario design may miss real future shocks |
| Scenario analysis | Explores impact of defined market or business events | Depends on assumptions |
| Sensitivity analysis | Tests effect of changing one variable | May ignore interactions between variables |
| Backtesting | Compares model forecasts with actual outcomes | Past performance may not validate future accuracy |
Exam trap: if a question says “maximum possible loss,” VaR is usually not the correct description. VaR is a probabilistic estimate under assumptions.
Liquidity risk quick reference
| Liquidity concept | Meaning | Exam use |
|---|---|---|
| Funding liquidity | Ability to obtain cash to meet obligations | Payroll, margin calls, deposit outflows, debt maturities |
| Market liquidity | Ability to sell/hedge assets without large price impact | Bid-ask spread, market depth, time to liquidate |
| Maturity mismatch | Short-term liabilities fund longer-term assets | Core banking and broker-dealer funding risk |
| Liquidity buffer | Readily available cash/high-quality liquid assets | Buys time during stress |
| Encumbrance | Assets pledged or restricted | Reduces assets available for new funding |
| Contingency funding plan | Pre-agreed stress funding actions | Should include triggers, roles, communication |
| Cash-flow ladder | Time-bucketed inflows and outflows | Identifies gaps and rollover needs |
| Fire-sale risk | Forced sale at depressed prices | Links liquidity risk and market risk |
Key distinction: a firm can be solvent but illiquid if assets exceed liabilities but cash is unavailable when needed. A firm can also appear liquid temporarily while being economically weak.
Notes and examples
Liquidity Risk
Liquidity risk is the risk that a firm cannot meet obligations as they fall due, or can do so only at unacceptable cost.
Funding Liquidity vs Market Liquidity
| Type | Meaning | Example |
|---|---|---|
| Funding liquidity risk | Inability to raise cash or meet payment obligations | Firm cannot roll over short-term funding |
| Market liquidity risk | Inability to sell or close a position quickly without large price impact | Thinly traded bond must be sold at a deep discount |
Key Liquidity Concepts
| Concept | Review point |
|---|---|
| Cash flow mismatch | Timing gap between inflows and outflows |
| Contingency funding plan | Pre-agreed actions for liquidity stress |
| Liquid asset buffer | Assets available to generate cash under stress |
| Haircut | Discount applied to collateral or asset value |
| Intraday liquidity | Ability to meet obligations during the business day |
| Encumbered assets | Assets already pledged and not freely available |
| Liquidity stress | Sudden withdrawals, margin calls, market closure, funding freeze |
A firm may be solvent on a balance-sheet basis but illiquid if it cannot generate cash quickly enough.
Operational risk and resilience
| Operational risk source | Example | Key controls |
|---|---|---|
| People | Error, fraud, lack of training, key-person dependency | Segregation, supervision, training, mandatory leave, fit-and-proper checks |
| Process | Failed reconciliation, manual workaround, weak approval | Process mapping, maker-checker, reconciliations, exception reporting |
| Systems | Outage, data corruption, poor access control | Change management, backups, access reviews, monitoring |
| External events | Natural disaster, vendor outage, cyberattack | BCP, insurance, alternate sites, incident response |
| Outsourcing | Service failure, data breach, concentration on vendor | Due diligence, SLAs, right to audit, exit plan |
| Cyber | Phishing, ransomware, unauthorized access | MFA, patching, monitoring, awareness, response plan |
| Change | New system/product not controlled | Project governance, testing, approvals, post-implementation review |
Notes and examples
Business continuity and incident terms
| Term | Meaning | Exam trap |
|---|---|---|
| BCP | Business continuity plan to maintain critical operations | Broader than IT recovery |
| DR | Disaster recovery, usually technology recovery | Part of resilience, not the whole plan |
| RTO | Recovery time objective: target time to restore | Time measure |
| RPO | Recovery point objective: acceptable data loss point | Data-loss measure |
| Crisis management | Strategic response and communications | Includes clients, regulators, staff, media |
| Incident management | Detect, contain, recover, learn | Should include root-cause analysis |
| Resilience | Ability to prevent, adapt, respond, recover, learn | Not just backup systems |
Operational Risk
Operational risk arises from inadequate or failed internal processes, people, systems, or external events.
Operational Risk Sources
| Source | Examples |
|---|---|
| People | Error, fraud, inadequate training, misconduct |
| Process | Poor procedures, failed reconciliations, weak approvals |
| Systems | Outage, cyber incident, data corruption, failed interface |
| External events | Natural disaster, supplier failure, terrorism, pandemic disruption |
Operational Risk Tools
| Tool | Purpose |
|---|---|
| Risk and control self-assessment | Identifies key risks and evaluates controls |
| Loss event database | Records incidents and near misses |
| Key risk indicators | Monitors emerging risk trends |
| Scenario analysis | Tests severe operational events |
| Business continuity planning | Maintains critical services during disruption |
| Disaster recovery | Restores systems and data |
| Outsourcing oversight | Manages third-party service risks |
| Cyber controls | Protect confidentiality, integrity, and availability |
Operational Risk Traps
- A trading loss caused by market movement is market risk; a trading loss caused by booking error may be operational risk.
- Outsourcing does not remove accountability for the activity.
- A near miss matters because it may reveal control weakness.
- Insurance may reduce financial impact but not reputational, client, regulatory, or continuity consequences.
Conduct, compliance, and financial crime
| Area | Focus | Common controls | Exam distinction |
|---|---|---|---|
| Conduct risk | Fair customer and market outcomes | Product governance, suitability checks, remuneration review, complaints analysis | Outcome-focused, even where no explicit rule breach is obvious |
| Compliance risk | Breach of rules or regulatory obligations | Compliance monitoring, policy advice, training, breach logs | Rule-focused |
| Market abuse risk | Insider dealing, manipulation, misuse of information | Surveillance, restricted lists, wall-crossing controls | Often linked to trading and information barriers |
| Conflicts of interest | Firm/staff incentive conflicts with client duty | Disclosure, avoidance, independent approval, gifts policy | Disclosure alone may not be enough |
| Financial crime | AML, fraud, bribery, sanctions evasion | CDD/KYC, transaction monitoring, screening, suspicious activity processes | Red flags require investigation and escalation |
| Data protection / confidentiality | Misuse or loss of client/personal data | Access controls, encryption, clean desk, data retention | Also operational, legal, and reputational risk |
Capital, prudential risk, and Basel-style concepts
| Concept | Meaning | Candidate note |
|---|---|---|
| Regulatory capital | Capital required under applicable rules | Rule-based and externally supervised |
| Economic capital | Internal estimate of capital needed for risks | Model-based and management-focused |
| Risk-weighted assets | Assets/exposures adjusted for risk | Higher-risk exposures generally require more capital |
| Capital adequacy | Sufficiency of capital relative to risks | Links risk appetite, strategy, and resilience |
| Pillar 1 | Minimum capital framework for key risk categories | Conceptual categories matter more than memorizing figures unless supplied |
| Pillar 2 | Supervisory/internal review of wider risks and capital adequacy | Captures risks not fully covered by minimum formulas |
| Pillar 3 | Market discipline through disclosure | Transparency to external stakeholders |
| Leverage | Use of debt or exposure relative to capital | Can magnify losses even if risk weights appear low |
| Stress capital impact | Capital effect under adverse scenarios | Tests resilience beyond normal conditions |
Key formulas and calculation reminders
Expected credit loss
\[ \text{Expected loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]Use this for average expected credit loss. Do not confuse expected loss with worst-case loss or capital for unexpected loss.
Risk score
\[ \text{Risk score} = \text{Likelihood} \times \text{Impact} \]Risk matrices are simple prioritization tools. They are not precise measurement models.
Capital ratio
\[ \text{Capital ratio} = \frac{\text{Eligible regulatory capital}}{\text{Risk-weighted assets}} \]Higher capital supports loss absorption. Do not assume a specific required percentage unless it is provided in the question or study material.
RAROC
\[ \text{RAROC} = \frac{\text{Risk-adjusted return}}{\text{Economic capital}} \]RAROC helps compare business returns after considering the risk capital consumed.
Parametric VaR approximation
\[ \text{VaR} \approx z_c \times \sigma \times V \times \sqrt{t} \]Where \(z_c\) is the confidence-level factor, \(\sigma\) is volatility, \(V\) is portfolio value, and \(t\) is the time horizon. Watch sign conventions: VaR is normally expressed as a positive loss amount.
Bond price sensitivity
\[ \Delta P \approx -D_{\text{mod}} \times P \times \Delta y \]A rise in yield usually reduces a fixed-rate bond price. Longer modified duration means greater sensitivity.
PV01 / DV01 approximation
\[ \text{PV01} \approx D_{\text{mod}} \times P \times 0.0001 \]PV01 estimates the price change for a one basis point yield move.
VaR, stress testing, and scenarios
| Tool | Purpose | Strength | Limitation |
|---|---|---|---|
| VaR | Estimates loss not expected to be exceeded at a confidence level over a time horizon | Useful common market-risk metric | Does not show size of losses beyond the confidence level |
| Expected shortfall | Average loss beyond VaR threshold | Better tail-risk view | More model-dependent |
| Sensitivity analysis | Changes one variable or factor | Easy to interpret | Ignores multi-factor interactions |
| Scenario analysis | Applies a coherent set of assumptions | Captures plausible narratives | Scenario selection is subjective |
| Stress testing | Tests extreme but plausible conditions | Highlights vulnerabilities | Not a forecast |
| Reverse stress testing | Starts with failure outcome and asks what could cause it | Identifies existential vulnerabilities | Can be uncomfortable and judgment-heavy |
| Backtesting | Compares model predictions with actual outcomes | Tests model performance | Past data may not represent future stress |
| Benchmarking | Compares against alternatives or peers | Helps challenge assumptions | Benchmark may not fit portfolio |
Notes and examples
VaR traps
- A 99% VaR is not the maximum possible loss.
- VaR depends on horizon, confidence level, data, model, and assumptions.
- Diversification benefits may disappear when correlations rise in stress.
- VaR may understate illiquid positions, basis risk, jump risk, and model risk.
- Backtesting exceptions do not automatically prove fraud or misconduct; they may indicate model weakness, volatility change, or data issues.
Controls and assurance
| Control type | Purpose | Examples | Exam clue |
|---|---|---|---|
| Preventive | Stop error or breach before it occurs | Pre-trade limits, approvals, access restrictions | Best when loss prevention is critical |
| Detective | Identify errors or breaches after occurrence | Reconciliations, exception reports, surveillance | Useful where prevention cannot be complete |
| Corrective | Fix issue and reduce recurrence | Root-cause remediation, system patch, process redesign | Not just compensation or apology |
| Directive | Guide expected behavior | Policies, procedures, training | Weak if not monitored |
| Automated | System-enforced control | Hard limits, mandatory fields | Strong consistency but needs change control |
| Manual | Human-operated control | Review sign-off, call-back confirmation | Flexible but prone to error |
| Compensating | Alternative control when primary control is weak/unavailable | Extra review during system outage | Usually temporary or risk-based |
Notes and examples
Control effectiveness
| Assessment | Question to ask | Evidence |
|---|---|---|
| Design effectiveness | Would the control address the risk if performed correctly? | Policy, process map, control description |
| Operating effectiveness | Did the control operate as intended over time? | Samples, logs, approvals, reconciliations |
| Coverage | Does it cover all relevant products/entities/processes? | Scope, population testing |
| Timeliness | Is the control performed soon enough? | Timestamps, escalation records |
| Independence | Is review performed by someone sufficiently independent? | Role segregation, reporting lines |
Risk responses
| Response | Meaning | Best for | Trap |
|---|---|---|---|
| Avoid | Stop the activity | Risk outside appetite | May sacrifice return or strategic opportunity |
| Reduce | Lower likelihood or impact | Most controllable operational and credit risks | Requires control evidence |
| Transfer | Shift some financial impact | Insurance, guarantees, hedging, outsourcing | Does not remove all risk; creates counterparty/legal/basis risk |
| Accept | Retain risk knowingly | Low risk or cost of control exceeds benefit | Must be within appetite and documented |
| Exploit / pursue | Take risk for reward | Market, credit, strategic opportunities | Needs pricing, limits, and governance |
Reporting and escalation
| Report element | Why it matters |
|---|---|
| Current exposure vs limit | Shows whether activity is within approved boundaries |
| Trend | Deterioration may matter before a breach occurs |
| Appetite status | Links metrics to board-approved risk stance |
| Breaches and exceptions | Requires ownership, root cause, remediation date |
| Losses and near misses | Indicates control weakness and emerging risk |
| Top and emerging risks | Helps governance focus on material risks |
| Stress/scenario results | Shows vulnerability under adverse conditions |
| Action tracking | Ensures reporting leads to remediation |
| Owner and due date | Creates accountability |
Good risk reporting is accurate, timely, relevant, escalated, and action-oriented.
Scenario decision table
| If the question emphasizes… | Think first of… | Strong answer usually includes… |
|---|---|---|
| Customer sold unsuitable product | Conduct risk | Product governance, suitability, training, incentive review |
| Policy exists but staff bypass it | Control operating failure / culture | Monitoring, enforcement, root-cause analysis |
| Unreconciled cash breaks | Operational risk | Daily reconciliation, exception escalation |
| Bond portfolio loses value after yield rise | Market risk, interest-rate risk | Duration/PV01, hedging, limits |
| Client defaults on loan | Credit risk | PD/LGD/EAD, collateral, recovery |
| Derivative counterparty fails before maturity | Counterparty credit risk | Netting, collateral, exposure replacement |
| Cannot sell assets except at large discount | Market liquidity risk | Liquidity buffer, stress haircut, funding plan |
| Cannot roll over short-term funding | Funding liquidity risk | Cash-flow ladder, contingency funding |
| Losses exceed model forecast repeatedly | Model risk | Backtesting, validation, recalibration, governance |
| Outsourced provider outage | Operational / outsourcing risk | SLA, resilience testing, exit plan, incident management |
| Suspicious transaction pattern | Financial crime risk | Monitoring, investigation, escalation |
| Traders share confidential information improperly | Conduct / market abuse / information barrier risk | Surveillance, restricted lists, training, discipline |
| Concentrated exposure to one sector | Concentration risk | Limits, diversification, stress testing |
| Rapid business growth with weak controls | Strategic plus operational risk | Governance, capacity, control investment |
| Regulator criticizes breach reporting | Compliance/governance risk | Breach process, accountability, timely escalation |
Common exam traps checklist
- Do not choose insurance as eliminating operational risk; it only transfers some financial impact.
- Do not call every regulatory issue conduct risk; conduct focuses on customer/market outcomes, compliance on rule adherence.
- Do not call every price movement credit risk; market risk can occur without default.
- Do not treat collateral as risk-free; value, enforceability, liquidity, and concentration matter.
- Do not confuse funding liquidity with market liquidity.
- Do not confuse risk appetite with risk capacity or limits.
- Do not assume diversification removes systemic risk.
- Do not assume outsourcing transfers accountability away from the firm.
- Do not treat VaR as a worst-case loss.
- Do not let a strong KPI hide a worsening KRI.
- Do not confuse root cause remediation with temporary workaround.
- Do not select internal audit as the owner of first-line controls.
- Do not assume high capital fixes poor culture, conduct, or operational control weaknesses.
- Do not ignore correlation and concentration in stress scenarios.
- Do not overlook reputational impact as a secondary consequence.
Fast revision drill
For any practice question, answer in this order:
- Risk type: credit, market, liquidity, operational, conduct, compliance, model, strategic, reputational, financial crime, or legal.
- Risk driver: people, process, system, market factor, counterparty, behavior, governance, external event.
- Exposure metric: PD/LGD/EAD, VaR, duration, cash-flow gap, KRI, loss data, breach count, complaints.
- Control: preventive, detective, corrective, or governance response.
- Owner: first line owns; second line challenges; third line assures.
- Escalation: compare with appetite/limit, report breach, remediate root cause.
- Residual risk: decide whether remaining risk is acceptable.
Cheat Sheet for CISI Risk in Financial Services
This Cheat Sheet is an independent companion for candidates preparing for the Chartered Institute for Securities & Investment CISI Risk in Financial Services exam, official code CISI Risk. Use it to refresh high-yield concepts before moving into topic drills, mock exams, original practice questions, and detailed explanations.
The exam rewards candidates who can connect risk definitions to practical decisions: identifying the source of risk, choosing an appropriate control, understanding governance responsibilities, and recognising the limitations of measurement tools.
Core Risk Language
Essential Definitions
| Term | Quick meaning | Candidate decision point |
|---|---|---|
| Risk | Uncertainty that may affect objectives | Ask: what objective is threatened? |
| Risk event | The incident that could occur | Separate the event from its cause and impact |
| Cause | Why the event could happen | Controls should usually address causes |
| Impact | The consequence if the event occurs | Impacts may be financial, regulatory, operational, client, or reputational |
| Inherent risk | Risk before controls | Used to understand the raw exposure |
| Residual risk | Risk after controls | Compare this with risk appetite |
| Risk appetite | Broad amount/type of risk an organisation is willing to accept | Set by senior governance, not by operational teams alone |
| Risk tolerance | More specific acceptable variation around appetite | Often translated into measurable thresholds |
| Limits | Operational boundaries for day-to-day control | Breaches require monitoring and escalation |
| KRI | Key risk indicator: signals changing risk exposure | Forward-looking where possible |
| KPI | Key performance indicator: measures performance | High performance can still create high risk |
| KCI | Key control indicator: measures control effectiveness | Useful for detecting control weakness |
Notes and examples
Expected Loss and Unexpected Loss
Credit risk often uses the expected loss relationship:
\[ \text{Expected Loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]Where:
- PD = probability of default.
- LGD = loss given default.
- EAD = exposure at default.
Expected loss is the average loss anticipated over a period. Unexpected loss is the adverse variation around that expectation and is a key reason firms hold capital.
Risk Management Framework
A strong framework does not eliminate risk. It makes risk visible, owned, measured, controlled, and escalated.
flowchart LR
A[Identify risks] --> B[Assess likelihood and impact]
B --> C[Measure exposure]
C --> D[Choose response]
D --> E[Implement controls]
E --> F[Monitor indicators and limits]
F --> G[Report and escalate]
G --> H[Review and improve]
H --> A
The Risk Response Decision
| Response | Meaning | Example |
|---|---|---|
| Avoid | Stop the activity creating the risk | Exit a product or market that cannot be controlled |
| Reduce / mitigate | Lower likelihood or impact | Limits, collateral, segregation of duties, system controls |
| Transfer | Shift part of the risk to another party | Insurance, guarantees, hedging, outsourcing with contractual protections |
| Accept | Retain the risk consciously | Accept low residual risk within appetite |
A common exam mistake is to choose a risk transfer answer as if it removes the risk completely. Transfer normally changes the risk profile; it may introduce counterparty, legal, basis, or operational risk.
Controls: Fast Classification
| Control type | Purpose | Examples |
|---|---|---|
| Preventive | Stop errors or events before they occur | Pre-trade limits, access controls, approvals, segregation of duties |
| Detective | Identify problems after occurrence | Reconciliations, exception reports, surveillance, audit testing |
| Corrective | Fix issues and reduce recurrence | Remediation plans, process redesign, disciplinary action |
| Directive | Guide behaviour | Policies, procedures, training, risk appetite statements |
| Compensating | Offset weakness in another control | Additional review where automation is unavailable |
Control Quality Checklist
A good control is:
- Linked to a specific risk and cause.
- Owned by a named person or team.
- Performed at the right frequency.
- Evidenced and auditable.
- Escalated when exceptions occur.
- Reviewed when business activity changes.
Conduct, Compliance, Legal, and Reputational Risk
Distinguish the Concepts
| Risk | Focus | Example |
|---|---|---|
| Conduct risk | Poor outcomes for clients or market integrity | Unsuitable product recommendation |
| Compliance risk | Breach of laws, rules, regulations, or internal standards | Failure to follow regulatory reporting requirements |
| Legal risk | Contracts, enforceability, litigation, documentation | Netting agreement not enforceable |
| Reputational risk | Loss of trust or confidence | Public criticism after control failure |
| Financial crime risk | Money laundering, sanctions, fraud, bribery, corruption | Inadequate client due diligence |
Notes and examples
Conduct risk can exist even where a narrow rule breach is not obvious. Look for fairness, transparency, conflicts of interest, suitability, market abuse prevention, and client outcomes.
Conflicts of Interest
Common controls include:
- Disclosure where appropriate.
- Avoidance where the conflict cannot be managed.
- Information barriers.
- Independent review.
- Personal account dealing rules.
- Gifts and entertainment controls.
- Fair allocation policies.
Exam questions often include a tempting answer of “disclose and continue.” Disclosure alone is not always enough if the conflict remains unmanaged.
Model Risk and Data Risk
Model risk is the risk of loss or poor decision-making from incorrect, misused, or poorly governed models.
| Source of model risk | Example control |
|---|---|
| Incorrect assumptions | Independent validation |
| Poor data quality | Data lineage, reconciliation, quality checks |
| Coding or implementation error | Testing, change control, peer review |
| Misuse outside intended purpose | Model documentation and usage limits |
| Lack of monitoring | Performance tracking and periodic review |
| Overreliance | Management challenge and expert judgment |
Model output should support judgment, not replace it. A precise number can still be wrong if assumptions are unrealistic.
Capital, Solvency, and Prudential Thinking
Capital protects a firm and its stakeholders by absorbing losses. Risk management connects business activity to the amount and quality of capital needed.
| Concept | Quick review |
|---|---|
| Regulatory capital | Capital required under applicable regulatory frameworks |
| Economic capital | Internal estimate of capital needed for the firm’s risk profile |
| Risk-weighted exposure | Exposure adjusted for risk characteristics |
| Leverage | Relationship between assets/exposures and capital |
| Stress capital impact | Capital effect under severe adverse scenarios |
| Provisioning | Recognition of expected credit losses or impairments |
| Capital planning | Ensuring adequate capital under normal and stressed conditions |
Do not confuse:
- Provisions for expected losses with capital for unexpected losses.
- Liquidity with solvency.
- Accounting value with realisable value under stress.
Enterprise-Wide Risk and Aggregation
Risks interact. A strong answer recognises second-order effects.
| Initial event | Possible linked risks |
|---|---|
| Market shock | Margin calls, liquidity strain, credit downgrade, client complaints |
| Cyber incident | Operational disruption, data breach, legal liability, reputational damage |
| Counterparty default | Credit loss, replacement cost, liquidity pressure, legal dispute |
| Mis-selling issue | Conduct breach, remediation cost, regulatory attention, reputational harm |
| Outsourcing failure | Operational disruption, client harm, compliance breach |
Correlation and concentration matter. Risks that look diversified in normal conditions may become highly correlated in stress.
Common Decision Rules
When Asked “What Is the Best Control?”
Choose the control that directly addresses the cause of the risk.
| Scenario clue | Strong control response |
|---|---|
| Unauthorised transaction | Access control, approval, segregation of duties |
| Repeated processing errors | Procedure redesign, automation, training, reconciliation |
| Limit breach | Immediate escalation, investigation, remediation |
| Unclear ownership | Assign accountable owner and reporting line |
| Third-party failure | Due diligence, service levels, monitoring, exit planning |
| Poor client outcome | Suitability review, disclosure improvement, conflict management |
| Model output questioned | Independent validation, assumption review, backtesting where relevant |
Notes and examples
When Asked “Who Is Responsible?”
| If the issue is… | Likely responsibility |
|---|---|
| Day-to-day risk taking and controls | First line |
| Policy, oversight, challenge, compliance monitoring | Second line |
| Independent assurance over the framework | Third line / internal audit |
| Risk appetite and oversight | Board / governing body |
| Implementation of appetite and controls | Senior management |
When Asked “What Should Happen After a Breach?”
A practical sequence is:
- Stop or contain the issue where necessary.
- Escalate promptly.
- Assess impact.
- Identify root cause.
- Remediate the immediate breach.
- Strengthen controls to prevent recurrence.
- Record evidence and monitor completion.
Common Candidate Mistakes
| Mistake | Better approach |
|---|---|
| Memorising definitions without applying them | Identify event, cause, impact, control, and owner |
| Assuming risk transfer removes risk | Consider residual, legal, counterparty, and operational risks |
| Treating VaR as a worst-case loss | Remember it is a confidence-based estimate |
| Confusing compliance and conduct | Conduct focuses on client and market outcomes |
| Ignoring near misses | Near misses are evidence of possible control weakness |
| Thinking audit owns risk | Audit provides independent assurance; management owns risk |
| Choosing the most severe control automatically | Match the response to materiality and appetite |
| Overlooking liquidity effects | Ask whether cash is available when needed |
| Confusing inherent and residual risk | Inherent is before controls; residual is after controls |
| Assuming policies equal control effectiveness | Look for evidence, monitoring, exceptions, and escalation |
Rapid Review Tables by Risk Type
Risk Type, Signal, and Control
| Risk type | Warning signal | Typical control |
|---|---|---|
| Credit | Rising arrears, downgrade, covenant breach | Limits, collateral, monitoring, restructuring action |
| Market | Volatile prices, limit utilisation, basis mismatch | Position limits, hedging, stress testing |
| Liquidity | Funding concentration, margin calls, cash gap | Liquidity buffer, contingency funding plan |
| Operational | Incidents, near misses, high manual processing | RCSA, reconciliations, automation, training |
| Conduct | Complaints, unsuitable sales, poor disclosure | Product governance, suitability checks, monitoring |
| Compliance | Rule breach, late reporting, failed surveillance | Compliance monitoring, policy controls, escalation |
| Legal | Contract dispute, unenforceable clause | Legal review, documentation standards |
| Reputational | Negative media, loss of client trust | Governance, communication, remediation |
| Model | Override spikes, poor backtesting, stale assumptions | Validation, monitoring, change control |
| Outsourcing | SLA failures, weak oversight, concentration | Due diligence, reporting, exit plan |
Notes and examples
Measurement Tools
| Tool | Best for | Weakness |
|---|---|---|
| Heat map | Prioritising risks by likelihood and impact | Can be subjective |
| Limits | Day-to-day control | Must be calibrated and enforced |
| KRIs | Early warning | Poor indicators create false comfort |
| Stress tests | Severe scenario analysis | Scenario selection is judgmental |
| Loss data | Learning from incidents | Past losses may understate future exposure |
| RCSA | Business-led risk assessment | Can become a checklist exercise |
| Audit testing | Independent assurance | Periodic, not continuous |
| Dashboards | Management oversight | Can hide detail if poorly designed |
Practice Strategy for CISI Risk
Use this Cheat Sheet first, then move into independent companion practice. The fastest improvement usually comes from alternating short review with original practice questions and detailed explanations.
Suggested Practice Sequence
Definitions drill Practise appetite, tolerance, inherent risk, residual risk, KRI, operational risk, credit risk, market risk, and liquidity risk.
Risk classification drill For each scenario, identify the primary risk and any secondary risks.
Control selection drill Match risk causes to preventive, detective, corrective, and compensating controls.
Governance drill Decide whether the issue belongs mainly to the first line, second line, third line, senior management, or board oversight.
Scenario mixed practice Use question bank sets that combine risk types, escalation, controls, and measurement limitations.
Mock exam practice Sit timed mock exams only after you can explain why wrong answers are wrong.
What to Review After Each Question
For every missed question, write one line for each:
- What risk type was being tested?
- What clue in the wording mattered?
- Which answer was tempting but wrong?
- What rule would help next time?
Final Exam-Readiness Checklist
Before attempting a full mock exam, make sure you can:
- Explain risk appetite, tolerance, limits, inherent risk, and residual risk.
- Distinguish credit, market, liquidity, operational, conduct, compliance, legal, and reputational risk.
- Apply the three lines model to practical scenarios.
- Choose controls based on the cause of the risk.
- Recognise the limits of VaR, stress testing, ratings, models, and collateral.
- Explain why outsourcing, insurance, hedging, and collateral reduce but do not eliminate risk.
- Identify when escalation is required.
- Connect risk events to second-order impacts.
- Learn from detailed explanations, not just answer keys.
Use this Cheat Sheet as your final concept check, then move into topic drills, original practice questions, and timed question bank practice with detailed explanations to convert recognition into exam-ready judgment.