CISI Risk in Financial Services Quick Review

Quick review for Chartered Institute for Securities & Investment CISI Risk in Financial Services (CISI Risk): core risk concepts, controls, traps, and practice focus.

Quick Review for CISI Risk in Financial Services

This Quick Review is an independent companion for candidates preparing for the Chartered Institute for Securities & Investment CISI Risk in Financial Services exam, official code CISI Risk. Use it to refresh high-yield concepts before moving into topic drills, mock exams, original practice questions, and detailed explanations.

The exam rewards candidates who can connect risk definitions to practical decisions: identifying the source of risk, choosing an appropriate control, understanding governance responsibilities, and recognising the limitations of measurement tools.

High-Yield Risk Map

AreaWhat to know quicklyCommon exam trap
Risk governanceBoard oversight, risk appetite, policies, reporting, escalation, three lines modelTreating risk management as only a compliance or audit function
Risk processIdentify, assess, measure, mitigate, monitor, report, reviewJumping to controls before defining the risk event and cause
Credit riskDefault risk, counterparty risk, settlement risk, concentration, collateral, nettingConfusing issuer credit risk with market price movement
Market riskInterest rate, FX, equity, commodity, spread, volatility, basis riskAssuming VaR predicts the maximum possible loss
Liquidity riskFunding liquidity vs market liquidity, cash flow mismatch, contingency fundingConfusing a solvent firm with a liquid firm
Operational riskPeople, process, systems, external events; cyber, fraud, outsourcing, business continuityClassifying every loss as operational risk without identifying the root cause
Conduct and compliance riskFair client treatment, conflicts, suitability, market abuse controls, regulatory obligationsThinking compliance risk is only about fines, not client and market outcomes
Model and data riskAssumptions, validation, data quality, limitations, change controlTreating model output as fact rather than a decision input
Capital and stress testingCapital absorbs unexpected losses; stress tests explore severe but plausible conditionsConfusing expected loss provisions with capital for unexpected loss
Risk cultureIncentives, challenge, escalation, accountability, tone from the topBelieving policies alone create effective risk management

Core Risk Language

Essential Definitions

TermQuick meaningCandidate decision point
RiskUncertainty that may affect objectivesAsk: what objective is threatened?
Risk eventThe incident that could occurSeparate the event from its cause and impact
CauseWhy the event could happenControls should usually address causes
ImpactThe consequence if the event occursImpacts may be financial, regulatory, operational, client, or reputational
Inherent riskRisk before controlsUsed to understand the raw exposure
Residual riskRisk after controlsCompare this with risk appetite
Risk appetiteBroad amount/type of risk an organisation is willing to acceptSet by senior governance, not by operational teams alone
Risk toleranceMore specific acceptable variation around appetiteOften translated into measurable thresholds
LimitsOperational boundaries for day-to-day controlBreaches require monitoring and escalation
KRIKey risk indicator: signals changing risk exposureForward-looking where possible
KPIKey performance indicator: measures performanceHigh performance can still create high risk
KCIKey control indicator: measures control effectivenessUseful for detecting control weakness

Expected Loss and Unexpected Loss

Credit risk often uses the expected loss relationship:

\[ \text{Expected Loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]

Where:

  • PD = probability of default.
  • LGD = loss given default.
  • EAD = exposure at default.

Expected loss is the average loss anticipated over a period. Unexpected loss is the adverse variation around that expectation and is a key reason firms hold capital.

Risk Management Framework

A strong framework does not eliminate risk. It makes risk visible, owned, measured, controlled, and escalated.

    flowchart LR
	    A[Identify risks] --> B[Assess likelihood and impact]
	    B --> C[Measure exposure]
	    C --> D[Choose response]
	    D --> E[Implement controls]
	    E --> F[Monitor indicators and limits]
	    F --> G[Report and escalate]
	    G --> H[Review and improve]
	    H --> A

The Risk Response Decision

ResponseMeaningExample
AvoidStop the activity creating the riskExit a product or market that cannot be controlled
Reduce / mitigateLower likelihood or impactLimits, collateral, segregation of duties, system controls
TransferShift part of the risk to another partyInsurance, guarantees, hedging, outsourcing with contractual protections
AcceptRetain the risk consciouslyAccept low residual risk within appetite

A common exam mistake is to choose a risk transfer answer as if it removes the risk completely. Transfer normally changes the risk profile; it may introduce counterparty, legal, basis, or operational risk.

Governance and the Three Lines Model

Roles and Responsibilities

FunctionMain roleWhat not to confuse
Board / governing bodySets strategy, approves risk appetite, oversees risk frameworkDoes not usually run day-to-day controls
Senior managementImplements strategy and risk appetite, owns business risksCannot delegate accountability entirely to risk or compliance teams
First lineBusiness and operational management owning risks and controlsNot merely “sales”; includes control ownership
Second lineRisk, compliance, financial crime, specialist oversight functionsChallenges and advises; does not replace first-line ownership
Third lineInternal audit independent assuranceTests the framework; does not design or operate routine controls
External audit / regulatorsExternal assurance or supervision where applicableNot part of daily risk ownership

Risk Appetite, Limits, and Escalation

ConceptPractical interpretation
Appetite statement“How much and what type of risk are we prepared to take?”
Limit“What boundary must a desk, portfolio, process, or person stay within?”
BreachA limit or policy exception requiring action
EscalationTimely reporting to the right level of authority
RemediationAction to correct the breach and address root causes

Exam questions often test whether a breach should be ignored because no loss has occurred. The safer answer is usually that breaches matter because they indicate control failure or risk outside agreed boundaries.

Controls: Fast Classification

Control typePurposeExamples
PreventiveStop errors or events before they occurPre-trade limits, access controls, approvals, segregation of duties
DetectiveIdentify problems after occurrenceReconciliations, exception reports, surveillance, audit testing
CorrectiveFix issues and reduce recurrenceRemediation plans, process redesign, disciplinary action
DirectiveGuide behaviourPolicies, procedures, training, risk appetite statements
CompensatingOffset weakness in another controlAdditional review where automation is unavailable

Control Quality Checklist

A good control is:

  1. Linked to a specific risk and cause.
  2. Owned by a named person or team.
  3. Performed at the right frequency.
  4. Evidenced and auditable.
  5. Escalated when exceptions occur.
  6. Reviewed when business activity changes.

Credit Risk

Credit risk is the risk of loss from a borrower, issuer, or counterparty failing to meet obligations.

Credit Risk Types

TypeMeaningExample
Default riskBorrower or issuer fails to payBond issuer misses interest payment
Counterparty credit riskTrading counterparty defaults before final settlementDerivatives counterparty fails while contract has positive value
Settlement riskOne party pays or delivers but does not receive the counter-valueSecurities or FX settlement failure
Concentration riskExcessive exposure to one borrower, sector, region, product, or correlated groupLoan book concentrated in commercial property
Country / sovereign riskGovernment or country conditions impair repayment or transferCapital controls prevent payment
Wrong-way riskExposure increases when counterparty credit quality worsensCounterparty likely to default exactly when exposure is largest

Credit Risk Mitigation

ToolHow it helpsWatch for
Credit analysisAssesses ability and willingness to repayHistoric data may not capture future stress
LimitsCaps exposure by name, sector, rating, or productLimits must be monitored and enforced
CollateralProvides recovery sourceValuation, haircuts, liquidity, legal enforceability
NettingReduces gross exposures to net exposureDepends on legal enforceability
GuaranteesAdds another repayment sourceGuarantor credit quality matters
CovenantsTrigger early action if credit quality deterioratesWeak monitoring reduces value
DiversificationReduces idiosyncratic riskDoes not eliminate systematic risk

Credit Risk Traps

  • A high-quality counterparty can still create settlement or operational risk.
  • Collateral reduces loss given default but may not prevent default.
  • Diversification helps only when exposures are not highly correlated.
  • Credit ratings are inputs, not guarantees.
  • A lower probability of default does not always mean a lower expected loss if exposure or loss severity is high.

Market Risk

Market risk is the risk of loss from movements in market prices or rates.

Main Market Risk Categories

RiskDriverExample
Interest rate riskChanges in yield curves or ratesBond value falls when yields rise
Equity riskShare price or index movementEquity portfolio loses value
FX riskExchange rate movementForeign currency asset declines in home currency terms
Commodity riskCommodity price movementEnergy price exposure
Credit spread riskChange in spread over risk-free ratesCorporate bond spread widens
Volatility riskChange in expected volatilityOption values move as implied volatility changes
Basis riskImperfect relationship between hedge and exposureHedge instrument does not move exactly with hedged item

Interest Rate Review

For plain fixed-rate bonds:

  • When yields rise, bond prices generally fall.
  • When yields fall, bond prices generally rise.
  • Longer duration usually means greater price sensitivity.
  • Convexity means the price-yield relationship is curved, not linear.

VaR, Stress Testing, and Backtesting

ToolWhat it doesLimitation
Value at Risk (VaR)Estimates potential loss over a time horizon at a confidence levelDoes not show worst possible loss beyond the confidence level
Stress testMeasures effect of severe but plausible scenariosScenario design may miss real future shocks
Scenario analysisExplores impact of defined market or business eventsDepends on assumptions
Sensitivity analysisTests effect of changing one variableMay ignore interactions between variables
BacktestingCompares model forecasts with actual outcomesPast performance may not validate future accuracy

Exam trap: if a question says “maximum possible loss,” VaR is usually not the correct description. VaR is a probabilistic estimate under assumptions.

Liquidity Risk

Liquidity risk is the risk that a firm cannot meet obligations as they fall due, or can do so only at unacceptable cost.

Funding Liquidity vs Market Liquidity

TypeMeaningExample
Funding liquidity riskInability to raise cash or meet payment obligationsFirm cannot roll over short-term funding
Market liquidity riskInability to sell or close a position quickly without large price impactThinly traded bond must be sold at a deep discount

Key Liquidity Concepts

ConceptReview point
Cash flow mismatchTiming gap between inflows and outflows
Contingency funding planPre-agreed actions for liquidity stress
Liquid asset bufferAssets available to generate cash under stress
HaircutDiscount applied to collateral or asset value
Intraday liquidityAbility to meet obligations during the business day
Encumbered assetsAssets already pledged and not freely available
Liquidity stressSudden withdrawals, margin calls, market closure, funding freeze

A firm may be solvent on a balance-sheet basis but illiquid if it cannot generate cash quickly enough.

Operational Risk

Operational risk arises from inadequate or failed internal processes, people, systems, or external events.

Operational Risk Sources

SourceExamples
PeopleError, fraud, inadequate training, misconduct
ProcessPoor procedures, failed reconciliations, weak approvals
SystemsOutage, cyber incident, data corruption, failed interface
External eventsNatural disaster, supplier failure, terrorism, pandemic disruption

Operational Risk Tools

ToolPurpose
Risk and control self-assessmentIdentifies key risks and evaluates controls
Loss event databaseRecords incidents and near misses
Key risk indicatorsMonitors emerging risk trends
Scenario analysisTests severe operational events
Business continuity planningMaintains critical services during disruption
Disaster recoveryRestores systems and data
Outsourcing oversightManages third-party service risks
Cyber controlsProtect confidentiality, integrity, and availability

Operational Risk Traps

  • A trading loss caused by market movement is market risk; a trading loss caused by booking error may be operational risk.
  • Outsourcing does not remove accountability for the activity.
  • A near miss matters because it may reveal control weakness.
  • Insurance may reduce financial impact but not reputational, client, regulatory, or continuity consequences.

Distinguish the Concepts

RiskFocusExample
Conduct riskPoor outcomes for clients or market integrityUnsuitable product recommendation
Compliance riskBreach of laws, rules, regulations, or internal standardsFailure to follow regulatory reporting requirements
Legal riskContracts, enforceability, litigation, documentationNetting agreement not enforceable
Reputational riskLoss of trust or confidencePublic criticism after control failure
Financial crime riskMoney laundering, sanctions, fraud, bribery, corruptionInadequate client due diligence

Conduct risk can exist even where a narrow rule breach is not obvious. Look for fairness, transparency, conflicts of interest, suitability, market abuse prevention, and client outcomes.

Conflicts of Interest

Common controls include:

  • Disclosure where appropriate.
  • Avoidance where the conflict cannot be managed.
  • Information barriers.
  • Independent review.
  • Personal account dealing rules.
  • Gifts and entertainment controls.
  • Fair allocation policies.

Exam questions often include a tempting answer of “disclose and continue.” Disclosure alone is not always enough if the conflict remains unmanaged.

Model Risk and Data Risk

Model risk is the risk of loss or poor decision-making from incorrect, misused, or poorly governed models.

Source of model riskExample control
Incorrect assumptionsIndependent validation
Poor data qualityData lineage, reconciliation, quality checks
Coding or implementation errorTesting, change control, peer review
Misuse outside intended purposeModel documentation and usage limits
Lack of monitoringPerformance tracking and periodic review
OverrelianceManagement challenge and expert judgment

Model output should support judgment, not replace it. A precise number can still be wrong if assumptions are unrealistic.

Capital, Solvency, and Prudential Thinking

Capital protects a firm and its stakeholders by absorbing losses. Risk management connects business activity to the amount and quality of capital needed.

ConceptQuick review
Regulatory capitalCapital required under applicable regulatory frameworks
Economic capitalInternal estimate of capital needed for the firm’s risk profile
Risk-weighted exposureExposure adjusted for risk characteristics
LeverageRelationship between assets/exposures and capital
Stress capital impactCapital effect under severe adverse scenarios
ProvisioningRecognition of expected credit losses or impairments
Capital planningEnsuring adequate capital under normal and stressed conditions

Do not confuse:

  • Provisions for expected losses with capital for unexpected losses.
  • Liquidity with solvency.
  • Accounting value with realisable value under stress.

Enterprise-Wide Risk and Aggregation

Risks interact. A strong answer recognises second-order effects.

Initial eventPossible linked risks
Market shockMargin calls, liquidity strain, credit downgrade, client complaints
Cyber incidentOperational disruption, data breach, legal liability, reputational damage
Counterparty defaultCredit loss, replacement cost, liquidity pressure, legal dispute
Mis-selling issueConduct breach, remediation cost, regulatory attention, reputational harm
Outsourcing failureOperational disruption, client harm, compliance breach

Correlation and concentration matter. Risks that look diversified in normal conditions may become highly correlated in stress.

Common Decision Rules

When Asked “What Is the Best Control?”

Choose the control that directly addresses the cause of the risk.

Scenario clueStrong control response
Unauthorised transactionAccess control, approval, segregation of duties
Repeated processing errorsProcedure redesign, automation, training, reconciliation
Limit breachImmediate escalation, investigation, remediation
Unclear ownershipAssign accountable owner and reporting line
Third-party failureDue diligence, service levels, monitoring, exit planning
Poor client outcomeSuitability review, disclosure improvement, conflict management
Model output questionedIndependent validation, assumption review, backtesting where relevant

When Asked “Who Is Responsible?”

If the issue is…Likely responsibility
Day-to-day risk taking and controlsFirst line
Policy, oversight, challenge, compliance monitoringSecond line
Independent assurance over the frameworkThird line / internal audit
Risk appetite and oversightBoard / governing body
Implementation of appetite and controlsSenior management

When Asked “What Should Happen After a Breach?”

A practical sequence is:

  1. Stop or contain the issue where necessary.
  2. Escalate promptly.
  3. Assess impact.
  4. Identify root cause.
  5. Remediate the immediate breach.
  6. Strengthen controls to prevent recurrence.
  7. Record evidence and monitor completion.

Common Candidate Mistakes

MistakeBetter approach
Memorising definitions without applying themIdentify event, cause, impact, control, and owner
Assuming risk transfer removes riskConsider residual, legal, counterparty, and operational risks
Treating VaR as a worst-case lossRemember it is a confidence-based estimate
Confusing compliance and conductConduct focuses on client and market outcomes
Ignoring near missesNear misses are evidence of possible control weakness
Thinking audit owns riskAudit provides independent assurance; management owns risk
Choosing the most severe control automaticallyMatch the response to materiality and appetite
Overlooking liquidity effectsAsk whether cash is available when needed
Confusing inherent and residual riskInherent is before controls; residual is after controls
Assuming policies equal control effectivenessLook for evidence, monitoring, exceptions, and escalation

Rapid Review Tables by Risk Type

Risk Type, Signal, and Control

Risk typeWarning signalTypical control
CreditRising arrears, downgrade, covenant breachLimits, collateral, monitoring, restructuring action
MarketVolatile prices, limit utilisation, basis mismatchPosition limits, hedging, stress testing
LiquidityFunding concentration, margin calls, cash gapLiquidity buffer, contingency funding plan
OperationalIncidents, near misses, high manual processingRCSA, reconciliations, automation, training
ConductComplaints, unsuitable sales, poor disclosureProduct governance, suitability checks, monitoring
ComplianceRule breach, late reporting, failed surveillanceCompliance monitoring, policy controls, escalation
LegalContract dispute, unenforceable clauseLegal review, documentation standards
ReputationalNegative media, loss of client trustGovernance, communication, remediation
ModelOverride spikes, poor backtesting, stale assumptionsValidation, monitoring, change control
OutsourcingSLA failures, weak oversight, concentrationDue diligence, reporting, exit plan

Measurement Tools

ToolBest forWeakness
Heat mapPrioritising risks by likelihood and impactCan be subjective
LimitsDay-to-day controlMust be calibrated and enforced
KRIsEarly warningPoor indicators create false comfort
Stress testsSevere scenario analysisScenario selection is judgmental
Loss dataLearning from incidentsPast losses may understate future exposure
RCSABusiness-led risk assessmentCan become a checklist exercise
Audit testingIndependent assurancePeriodic, not continuous
DashboardsManagement oversightCan hide detail if poorly designed

Practice Strategy for CISI Risk

Use this Quick Review first, then move into independent companion practice. The fastest improvement usually comes from alternating short review with original practice questions and detailed explanations.

Suggested Practice Sequence

  1. Definitions drill Practise appetite, tolerance, inherent risk, residual risk, KRI, operational risk, credit risk, market risk, and liquidity risk.

  2. Risk classification drill For each scenario, identify the primary risk and any secondary risks.

  3. Control selection drill Match risk causes to preventive, detective, corrective, and compensating controls.

  4. Governance drill Decide whether the issue belongs mainly to the first line, second line, third line, senior management, or board oversight.

  5. Scenario mixed practice Use question bank sets that combine risk types, escalation, controls, and measurement limitations.

  6. Mock exam practice Sit timed mock exams only after you can explain why wrong answers are wrong.

What to Review After Each Question

For every missed question, write one line for each:

  • What risk type was being tested?
  • What clue in the wording mattered?
  • Which answer was tempting but wrong?
  • What rule would help next time?

Final Exam-Readiness Checklist

Before attempting a full mock exam, make sure you can:

  • Explain risk appetite, tolerance, limits, inherent risk, and residual risk.
  • Distinguish credit, market, liquidity, operational, conduct, compliance, legal, and reputational risk.
  • Apply the three lines model to practical scenarios.
  • Choose controls based on the cause of the risk.
  • Recognise the limits of VaR, stress testing, ratings, models, and collateral.
  • Explain why outsourcing, insurance, hedging, and collateral reduce but do not eliminate risk.
  • Identify when escalation is required.
  • Connect risk events to second-order impacts.
  • Learn from detailed explanations, not just answer keys.

Use this Quick Review as your final concept check, then move into topic drills, original practice questions, and timed question bank practice with detailed explanations to convert recognition into exam-ready judgment.

Browse Certification Practice Tests by Exam Family