CISI Risk in Financial Services Quick Review
Quick review for Chartered Institute for Securities & Investment CISI Risk in Financial Services (CISI Risk): core risk concepts, controls, traps, and practice focus.
Quick Review for CISI Risk in Financial Services
This Quick Review is an independent companion for candidates preparing for the Chartered Institute for Securities & Investment CISI Risk in Financial Services exam, official code CISI Risk. Use it to refresh high-yield concepts before moving into topic drills, mock exams, original practice questions, and detailed explanations.
The exam rewards candidates who can connect risk definitions to practical decisions: identifying the source of risk, choosing an appropriate control, understanding governance responsibilities, and recognising the limitations of measurement tools.
High-Yield Risk Map
| Area | What to know quickly | Common exam trap |
|---|---|---|
| Risk governance | Board oversight, risk appetite, policies, reporting, escalation, three lines model | Treating risk management as only a compliance or audit function |
| Risk process | Identify, assess, measure, mitigate, monitor, report, review | Jumping to controls before defining the risk event and cause |
| Credit risk | Default risk, counterparty risk, settlement risk, concentration, collateral, netting | Confusing issuer credit risk with market price movement |
| Market risk | Interest rate, FX, equity, commodity, spread, volatility, basis risk | Assuming VaR predicts the maximum possible loss |
| Liquidity risk | Funding liquidity vs market liquidity, cash flow mismatch, contingency funding | Confusing a solvent firm with a liquid firm |
| Operational risk | People, process, systems, external events; cyber, fraud, outsourcing, business continuity | Classifying every loss as operational risk without identifying the root cause |
| Conduct and compliance risk | Fair client treatment, conflicts, suitability, market abuse controls, regulatory obligations | Thinking compliance risk is only about fines, not client and market outcomes |
| Model and data risk | Assumptions, validation, data quality, limitations, change control | Treating model output as fact rather than a decision input |
| Capital and stress testing | Capital absorbs unexpected losses; stress tests explore severe but plausible conditions | Confusing expected loss provisions with capital for unexpected loss |
| Risk culture | Incentives, challenge, escalation, accountability, tone from the top | Believing policies alone create effective risk management |
Core Risk Language
Essential Definitions
| Term | Quick meaning | Candidate decision point |
|---|---|---|
| Risk | Uncertainty that may affect objectives | Ask: what objective is threatened? |
| Risk event | The incident that could occur | Separate the event from its cause and impact |
| Cause | Why the event could happen | Controls should usually address causes |
| Impact | The consequence if the event occurs | Impacts may be financial, regulatory, operational, client, or reputational |
| Inherent risk | Risk before controls | Used to understand the raw exposure |
| Residual risk | Risk after controls | Compare this with risk appetite |
| Risk appetite | Broad amount/type of risk an organisation is willing to accept | Set by senior governance, not by operational teams alone |
| Risk tolerance | More specific acceptable variation around appetite | Often translated into measurable thresholds |
| Limits | Operational boundaries for day-to-day control | Breaches require monitoring and escalation |
| KRI | Key risk indicator: signals changing risk exposure | Forward-looking where possible |
| KPI | Key performance indicator: measures performance | High performance can still create high risk |
| KCI | Key control indicator: measures control effectiveness | Useful for detecting control weakness |
Expected Loss and Unexpected Loss
Credit risk often uses the expected loss relationship:
\[ \text{Expected Loss} = \text{PD} \times \text{LGD} \times \text{EAD} \]Where:
- PD = probability of default.
- LGD = loss given default.
- EAD = exposure at default.
Expected loss is the average loss anticipated over a period. Unexpected loss is the adverse variation around that expectation and is a key reason firms hold capital.
Risk Management Framework
A strong framework does not eliminate risk. It makes risk visible, owned, measured, controlled, and escalated.
flowchart LR
A[Identify risks] --> B[Assess likelihood and impact]
B --> C[Measure exposure]
C --> D[Choose response]
D --> E[Implement controls]
E --> F[Monitor indicators and limits]
F --> G[Report and escalate]
G --> H[Review and improve]
H --> A
The Risk Response Decision
| Response | Meaning | Example |
|---|---|---|
| Avoid | Stop the activity creating the risk | Exit a product or market that cannot be controlled |
| Reduce / mitigate | Lower likelihood or impact | Limits, collateral, segregation of duties, system controls |
| Transfer | Shift part of the risk to another party | Insurance, guarantees, hedging, outsourcing with contractual protections |
| Accept | Retain the risk consciously | Accept low residual risk within appetite |
A common exam mistake is to choose a risk transfer answer as if it removes the risk completely. Transfer normally changes the risk profile; it may introduce counterparty, legal, basis, or operational risk.
Governance and the Three Lines Model
Roles and Responsibilities
| Function | Main role | What not to confuse |
|---|---|---|
| Board / governing body | Sets strategy, approves risk appetite, oversees risk framework | Does not usually run day-to-day controls |
| Senior management | Implements strategy and risk appetite, owns business risks | Cannot delegate accountability entirely to risk or compliance teams |
| First line | Business and operational management owning risks and controls | Not merely “sales”; includes control ownership |
| Second line | Risk, compliance, financial crime, specialist oversight functions | Challenges and advises; does not replace first-line ownership |
| Third line | Internal audit independent assurance | Tests the framework; does not design or operate routine controls |
| External audit / regulators | External assurance or supervision where applicable | Not part of daily risk ownership |
Risk Appetite, Limits, and Escalation
| Concept | Practical interpretation |
|---|---|
| Appetite statement | “How much and what type of risk are we prepared to take?” |
| Limit | “What boundary must a desk, portfolio, process, or person stay within?” |
| Breach | A limit or policy exception requiring action |
| Escalation | Timely reporting to the right level of authority |
| Remediation | Action to correct the breach and address root causes |
Exam questions often test whether a breach should be ignored because no loss has occurred. The safer answer is usually that breaches matter because they indicate control failure or risk outside agreed boundaries.
Controls: Fast Classification
| Control type | Purpose | Examples |
|---|---|---|
| Preventive | Stop errors or events before they occur | Pre-trade limits, access controls, approvals, segregation of duties |
| Detective | Identify problems after occurrence | Reconciliations, exception reports, surveillance, audit testing |
| Corrective | Fix issues and reduce recurrence | Remediation plans, process redesign, disciplinary action |
| Directive | Guide behaviour | Policies, procedures, training, risk appetite statements |
| Compensating | Offset weakness in another control | Additional review where automation is unavailable |
Control Quality Checklist
A good control is:
- Linked to a specific risk and cause.
- Owned by a named person or team.
- Performed at the right frequency.
- Evidenced and auditable.
- Escalated when exceptions occur.
- Reviewed when business activity changes.
Credit Risk
Credit risk is the risk of loss from a borrower, issuer, or counterparty failing to meet obligations.
Credit Risk Types
| Type | Meaning | Example |
|---|---|---|
| Default risk | Borrower or issuer fails to pay | Bond issuer misses interest payment |
| Counterparty credit risk | Trading counterparty defaults before final settlement | Derivatives counterparty fails while contract has positive value |
| Settlement risk | One party pays or delivers but does not receive the counter-value | Securities or FX settlement failure |
| Concentration risk | Excessive exposure to one borrower, sector, region, product, or correlated group | Loan book concentrated in commercial property |
| Country / sovereign risk | Government or country conditions impair repayment or transfer | Capital controls prevent payment |
| Wrong-way risk | Exposure increases when counterparty credit quality worsens | Counterparty likely to default exactly when exposure is largest |
Credit Risk Mitigation
| Tool | How it helps | Watch for |
|---|---|---|
| Credit analysis | Assesses ability and willingness to repay | Historic data may not capture future stress |
| Limits | Caps exposure by name, sector, rating, or product | Limits must be monitored and enforced |
| Collateral | Provides recovery source | Valuation, haircuts, liquidity, legal enforceability |
| Netting | Reduces gross exposures to net exposure | Depends on legal enforceability |
| Guarantees | Adds another repayment source | Guarantor credit quality matters |
| Covenants | Trigger early action if credit quality deteriorates | Weak monitoring reduces value |
| Diversification | Reduces idiosyncratic risk | Does not eliminate systematic risk |
Credit Risk Traps
- A high-quality counterparty can still create settlement or operational risk.
- Collateral reduces loss given default but may not prevent default.
- Diversification helps only when exposures are not highly correlated.
- Credit ratings are inputs, not guarantees.
- A lower probability of default does not always mean a lower expected loss if exposure or loss severity is high.
Market Risk
Market risk is the risk of loss from movements in market prices or rates.
Main Market Risk Categories
| Risk | Driver | Example |
|---|---|---|
| Interest rate risk | Changes in yield curves or rates | Bond value falls when yields rise |
| Equity risk | Share price or index movement | Equity portfolio loses value |
| FX risk | Exchange rate movement | Foreign currency asset declines in home currency terms |
| Commodity risk | Commodity price movement | Energy price exposure |
| Credit spread risk | Change in spread over risk-free rates | Corporate bond spread widens |
| Volatility risk | Change in expected volatility | Option values move as implied volatility changes |
| Basis risk | Imperfect relationship between hedge and exposure | Hedge instrument does not move exactly with hedged item |
Interest Rate Review
For plain fixed-rate bonds:
- When yields rise, bond prices generally fall.
- When yields fall, bond prices generally rise.
- Longer duration usually means greater price sensitivity.
- Convexity means the price-yield relationship is curved, not linear.
VaR, Stress Testing, and Backtesting
| Tool | What it does | Limitation |
|---|---|---|
| Value at Risk (VaR) | Estimates potential loss over a time horizon at a confidence level | Does not show worst possible loss beyond the confidence level |
| Stress test | Measures effect of severe but plausible scenarios | Scenario design may miss real future shocks |
| Scenario analysis | Explores impact of defined market or business events | Depends on assumptions |
| Sensitivity analysis | Tests effect of changing one variable | May ignore interactions between variables |
| Backtesting | Compares model forecasts with actual outcomes | Past performance may not validate future accuracy |
Exam trap: if a question says “maximum possible loss,” VaR is usually not the correct description. VaR is a probabilistic estimate under assumptions.
Liquidity Risk
Liquidity risk is the risk that a firm cannot meet obligations as they fall due, or can do so only at unacceptable cost.
Funding Liquidity vs Market Liquidity
| Type | Meaning | Example |
|---|---|---|
| Funding liquidity risk | Inability to raise cash or meet payment obligations | Firm cannot roll over short-term funding |
| Market liquidity risk | Inability to sell or close a position quickly without large price impact | Thinly traded bond must be sold at a deep discount |
Key Liquidity Concepts
| Concept | Review point |
|---|---|
| Cash flow mismatch | Timing gap between inflows and outflows |
| Contingency funding plan | Pre-agreed actions for liquidity stress |
| Liquid asset buffer | Assets available to generate cash under stress |
| Haircut | Discount applied to collateral or asset value |
| Intraday liquidity | Ability to meet obligations during the business day |
| Encumbered assets | Assets already pledged and not freely available |
| Liquidity stress | Sudden withdrawals, margin calls, market closure, funding freeze |
A firm may be solvent on a balance-sheet basis but illiquid if it cannot generate cash quickly enough.
Operational Risk
Operational risk arises from inadequate or failed internal processes, people, systems, or external events.
Operational Risk Sources
| Source | Examples |
|---|---|
| People | Error, fraud, inadequate training, misconduct |
| Process | Poor procedures, failed reconciliations, weak approvals |
| Systems | Outage, cyber incident, data corruption, failed interface |
| External events | Natural disaster, supplier failure, terrorism, pandemic disruption |
Operational Risk Tools
| Tool | Purpose |
|---|---|
| Risk and control self-assessment | Identifies key risks and evaluates controls |
| Loss event database | Records incidents and near misses |
| Key risk indicators | Monitors emerging risk trends |
| Scenario analysis | Tests severe operational events |
| Business continuity planning | Maintains critical services during disruption |
| Disaster recovery | Restores systems and data |
| Outsourcing oversight | Manages third-party service risks |
| Cyber controls | Protect confidentiality, integrity, and availability |
Operational Risk Traps
- A trading loss caused by market movement is market risk; a trading loss caused by booking error may be operational risk.
- Outsourcing does not remove accountability for the activity.
- A near miss matters because it may reveal control weakness.
- Insurance may reduce financial impact but not reputational, client, regulatory, or continuity consequences.
Conduct, Compliance, Legal, and Reputational Risk
Distinguish the Concepts
| Risk | Focus | Example |
|---|---|---|
| Conduct risk | Poor outcomes for clients or market integrity | Unsuitable product recommendation |
| Compliance risk | Breach of laws, rules, regulations, or internal standards | Failure to follow regulatory reporting requirements |
| Legal risk | Contracts, enforceability, litigation, documentation | Netting agreement not enforceable |
| Reputational risk | Loss of trust or confidence | Public criticism after control failure |
| Financial crime risk | Money laundering, sanctions, fraud, bribery, corruption | Inadequate client due diligence |
Conduct risk can exist even where a narrow rule breach is not obvious. Look for fairness, transparency, conflicts of interest, suitability, market abuse prevention, and client outcomes.
Conflicts of Interest
Common controls include:
- Disclosure where appropriate.
- Avoidance where the conflict cannot be managed.
- Information barriers.
- Independent review.
- Personal account dealing rules.
- Gifts and entertainment controls.
- Fair allocation policies.
Exam questions often include a tempting answer of “disclose and continue.” Disclosure alone is not always enough if the conflict remains unmanaged.
Model Risk and Data Risk
Model risk is the risk of loss or poor decision-making from incorrect, misused, or poorly governed models.
| Source of model risk | Example control |
|---|---|
| Incorrect assumptions | Independent validation |
| Poor data quality | Data lineage, reconciliation, quality checks |
| Coding or implementation error | Testing, change control, peer review |
| Misuse outside intended purpose | Model documentation and usage limits |
| Lack of monitoring | Performance tracking and periodic review |
| Overreliance | Management challenge and expert judgment |
Model output should support judgment, not replace it. A precise number can still be wrong if assumptions are unrealistic.
Capital, Solvency, and Prudential Thinking
Capital protects a firm and its stakeholders by absorbing losses. Risk management connects business activity to the amount and quality of capital needed.
| Concept | Quick review |
|---|---|
| Regulatory capital | Capital required under applicable regulatory frameworks |
| Economic capital | Internal estimate of capital needed for the firm’s risk profile |
| Risk-weighted exposure | Exposure adjusted for risk characteristics |
| Leverage | Relationship between assets/exposures and capital |
| Stress capital impact | Capital effect under severe adverse scenarios |
| Provisioning | Recognition of expected credit losses or impairments |
| Capital planning | Ensuring adequate capital under normal and stressed conditions |
Do not confuse:
- Provisions for expected losses with capital for unexpected losses.
- Liquidity with solvency.
- Accounting value with realisable value under stress.
Enterprise-Wide Risk and Aggregation
Risks interact. A strong answer recognises second-order effects.
| Initial event | Possible linked risks |
|---|---|
| Market shock | Margin calls, liquidity strain, credit downgrade, client complaints |
| Cyber incident | Operational disruption, data breach, legal liability, reputational damage |
| Counterparty default | Credit loss, replacement cost, liquidity pressure, legal dispute |
| Mis-selling issue | Conduct breach, remediation cost, regulatory attention, reputational harm |
| Outsourcing failure | Operational disruption, client harm, compliance breach |
Correlation and concentration matter. Risks that look diversified in normal conditions may become highly correlated in stress.
Common Decision Rules
When Asked “What Is the Best Control?”
Choose the control that directly addresses the cause of the risk.
| Scenario clue | Strong control response |
|---|---|
| Unauthorised transaction | Access control, approval, segregation of duties |
| Repeated processing errors | Procedure redesign, automation, training, reconciliation |
| Limit breach | Immediate escalation, investigation, remediation |
| Unclear ownership | Assign accountable owner and reporting line |
| Third-party failure | Due diligence, service levels, monitoring, exit planning |
| Poor client outcome | Suitability review, disclosure improvement, conflict management |
| Model output questioned | Independent validation, assumption review, backtesting where relevant |
When Asked “Who Is Responsible?”
| If the issue is… | Likely responsibility |
|---|---|
| Day-to-day risk taking and controls | First line |
| Policy, oversight, challenge, compliance monitoring | Second line |
| Independent assurance over the framework | Third line / internal audit |
| Risk appetite and oversight | Board / governing body |
| Implementation of appetite and controls | Senior management |
When Asked “What Should Happen After a Breach?”
A practical sequence is:
- Stop or contain the issue where necessary.
- Escalate promptly.
- Assess impact.
- Identify root cause.
- Remediate the immediate breach.
- Strengthen controls to prevent recurrence.
- Record evidence and monitor completion.
Common Candidate Mistakes
| Mistake | Better approach |
|---|---|
| Memorising definitions without applying them | Identify event, cause, impact, control, and owner |
| Assuming risk transfer removes risk | Consider residual, legal, counterparty, and operational risks |
| Treating VaR as a worst-case loss | Remember it is a confidence-based estimate |
| Confusing compliance and conduct | Conduct focuses on client and market outcomes |
| Ignoring near misses | Near misses are evidence of possible control weakness |
| Thinking audit owns risk | Audit provides independent assurance; management owns risk |
| Choosing the most severe control automatically | Match the response to materiality and appetite |
| Overlooking liquidity effects | Ask whether cash is available when needed |
| Confusing inherent and residual risk | Inherent is before controls; residual is after controls |
| Assuming policies equal control effectiveness | Look for evidence, monitoring, exceptions, and escalation |
Rapid Review Tables by Risk Type
Risk Type, Signal, and Control
| Risk type | Warning signal | Typical control |
|---|---|---|
| Credit | Rising arrears, downgrade, covenant breach | Limits, collateral, monitoring, restructuring action |
| Market | Volatile prices, limit utilisation, basis mismatch | Position limits, hedging, stress testing |
| Liquidity | Funding concentration, margin calls, cash gap | Liquidity buffer, contingency funding plan |
| Operational | Incidents, near misses, high manual processing | RCSA, reconciliations, automation, training |
| Conduct | Complaints, unsuitable sales, poor disclosure | Product governance, suitability checks, monitoring |
| Compliance | Rule breach, late reporting, failed surveillance | Compliance monitoring, policy controls, escalation |
| Legal | Contract dispute, unenforceable clause | Legal review, documentation standards |
| Reputational | Negative media, loss of client trust | Governance, communication, remediation |
| Model | Override spikes, poor backtesting, stale assumptions | Validation, monitoring, change control |
| Outsourcing | SLA failures, weak oversight, concentration | Due diligence, reporting, exit plan |
Measurement Tools
| Tool | Best for | Weakness |
|---|---|---|
| Heat map | Prioritising risks by likelihood and impact | Can be subjective |
| Limits | Day-to-day control | Must be calibrated and enforced |
| KRIs | Early warning | Poor indicators create false comfort |
| Stress tests | Severe scenario analysis | Scenario selection is judgmental |
| Loss data | Learning from incidents | Past losses may understate future exposure |
| RCSA | Business-led risk assessment | Can become a checklist exercise |
| Audit testing | Independent assurance | Periodic, not continuous |
| Dashboards | Management oversight | Can hide detail if poorly designed |
Practice Strategy for CISI Risk
Use this Quick Review first, then move into independent companion practice. The fastest improvement usually comes from alternating short review with original practice questions and detailed explanations.
Suggested Practice Sequence
Definitions drill Practise appetite, tolerance, inherent risk, residual risk, KRI, operational risk, credit risk, market risk, and liquidity risk.
Risk classification drill For each scenario, identify the primary risk and any secondary risks.
Control selection drill Match risk causes to preventive, detective, corrective, and compensating controls.
Governance drill Decide whether the issue belongs mainly to the first line, second line, third line, senior management, or board oversight.
Scenario mixed practice Use question bank sets that combine risk types, escalation, controls, and measurement limitations.
Mock exam practice Sit timed mock exams only after you can explain why wrong answers are wrong.
What to Review After Each Question
For every missed question, write one line for each:
- What risk type was being tested?
- What clue in the wording mattered?
- Which answer was tempting but wrong?
- What rule would help next time?
Final Exam-Readiness Checklist
Before attempting a full mock exam, make sure you can:
- Explain risk appetite, tolerance, limits, inherent risk, and residual risk.
- Distinguish credit, market, liquidity, operational, conduct, compliance, legal, and reputational risk.
- Apply the three lines model to practical scenarios.
- Choose controls based on the cause of the risk.
- Recognise the limits of VaR, stress testing, ratings, models, and collateral.
- Explain why outsourcing, insurance, hedging, and collateral reduce but do not eliminate risk.
- Identify when escalation is required.
- Connect risk events to second-order impacts.
- Learn from detailed explanations, not just answer keys.
Use this Quick Review as your final concept check, then move into topic drills, original practice questions, and timed question bank practice with detailed explanations to convert recognition into exam-ready judgment.