CISI UK RPI — CISI UK Regulation & Professional Integrity Cheat Sheet
Last revised: September 28, 2026
Cheat sheet for CISI UK Regulation & Professional Integrity (CISI UK RPI): UK regulators, FCA conduct, SMCR, market abuse, AML, complaints, and ethics.
Use the tables for a quick pre-exam check. Expand a topic’s notes for explanations, examples, and additional distinctions.
Scope and study context
Use this Cheat Sheet for the Chartered Institute for Securities & Investment exam CISI UK Regulation & Professional Integrity (CISI UK RPI) as a final consolidation pass before topic drills, mock exams, and detailed explanations.
This page is independent exam-prep support. It is designed to help you connect key UK regulatory concepts, professional integrity principles, and common scenario traps to independent companion practice, original practice questions, and question-bank review.
Read the high-yield map first. Identify weak areas before opening a question bank.
Review the decision rules. Many CISI UK RPI questions test “what should the firm or individual do next?” rather than pure definition recall.
Use topic drills immediately after each section. Do not wait until you feel fully ready; original practice questions expose gaps quickly.
Read detailed explanations carefully. For regulation questions, the explanation often matters more than the answer choice because similar facts can change the outcome.
Identity and exam-use focus
This independent Cheat Sheet supports candidates preparing for the Chartered Institute for Securities & Investment exam CISI UK Regulation & Professional Integrity with official exam code CISI UK RPI.
Use it to revise the practical distinctions the exam commonly tests: who regulates what, when FCA rules apply, how client protections differ, what must be escalated, and how professional integrity changes the correct answer.
Area
What to be able to do quickly
UK regulatory structure
Distinguish FCA, PRA, Bank of England, HM Treasury, FOS, FSCS, and market infrastructure roles.
Choose the answer that protects clients, markets, the firm, and the profession, not just the answer that is technically convenient.
UK regulatory map
Body
Core role
Exam distinction
HM Treasury
Sets financial services policy and legislation framework.
Policy maker, not the day-to-day conduct supervisor of firms.
Parliament
Creates primary legislation such as FSMA-based powers.
Statute creates the legal perimeter; regulators make detailed rules within powers.
Bank of England
Monetary stability, financial stability, resolution, and oversight of key financial infrastructure.
Think system-wide stability, not retail conduct.
Financial Policy Committee, or FPC
Monitors and acts on systemic risk.
Macroprudential focus: stability of the financial system as a whole.
Prudential Regulation Authority, or PRA
Prudential regulation of banks, building societies, credit unions, insurers, and designated investment firms.
Safety and soundness; dual-regulated firms also have FCA conduct supervision.
Financial Conduct Authority, or FCA
Conduct regulation, market integrity, consumer protection, competition, and prudential regulation of FCA-only firms.
Main exam regulator for conduct, client treatment, market abuse, authorisation, and enforcement.
Payment Systems Regulator, or PSR
Regulation of payment systems.
Competition, access, innovation, and service-user interests in payment systems.
Financial Ombudsman Service, or FOS
Independent dispute resolution for eligible complaints.
Resolves complaints; not a prudential regulator and not a compensation fund.
Financial Services Compensation Scheme, or FSCS
Last-resort compensation when authorised firms cannot meet eligible claims.
Compensates default/insolvency-type failures, not ordinary investment losses.
Information Commissioner’s Office, or ICO
UK data protection regulator.
Relevant for personal data, privacy, breach handling, and data subject rights.
Office of Financial Sanctions Implementation, or OFSI
UK financial sanctions implementation and enforcement.
Relevant to sanctions screening, asset freezes, and sanctions reporting.
Notes and examples
FCA versus PRA
Scenario
Likely regulator focus
Bank capital adequacy, liquidity, recovery planning
PRA, with FCA conduct issues still possible.
Misleading investment promotion to retail clients
FCA.
Poor complaint handling
FCA rules and FOS process.
Market manipulation or insider dealing
FCA and possible criminal authorities depending on facts.
Client money segregation failure
FCA CASS.
Insurer solvency risk
PRA prudential focus plus FCA conduct obligations.
Senior manager accountability in a dual-regulated bank
FCA and/or PRA depending on function and issue.
UK regulatory architecture
The exam often tests whether you can identify the correct body, rule source, or route for escalation.
Body or framework
Core role for exam purposes
Candidate mistake to avoid
HM Treasury
Government department with responsibility for financial services policy and legislation
Treating it as the day-to-day conduct supervisor
Bank of England
Financial stability, monetary stability, and key market infrastructure responsibilities
Confusing its macro role with individual retail complaint handling
Prudential Regulation Authority
Prudential supervision of certain firms such as banks, insurers, and major investment firms
Assuming all investment firms are PRA-regulated
Financial Conduct Authority
Conduct regulation, market integrity, consumer protection, competition, and many firm authorisation/supervision functions
Forgetting that conduct duties can apply even where prudential supervision is elsewhere
Financial Ombudsman Service
Independent complaint resolution for eligible complainants
Confusing complaint adjudication with compensation for firm failure
Financial Services Compensation Scheme
Compensation scheme where authorised firms are unable, or likely unable, to meet claims
Treating it as the first step for every complaint
National Crime Agency
Receives suspicious activity reports through the UK financial crime framework
Confusing external SAR reporting with internal escalation to the MLRO/nominated officer
FCA Handbook
Source of many rules and guidance, including PRIN, SYSC, COBS, CASS, DISP, SUP, FIT, COND, DEPP and others
Memorising names without knowing what each sourcebook generally covers
Common FCA Handbook areas
Area
Think of it as…
Typical exam angle
PRIN
High-level Principles for Businesses
Broad conduct failures
SYSC
Senior management arrangements, systems and controls
Governance, controls, compliance oversight
COBS
Conduct of business for investment business
Client communication, suitability, best execution, conflicts
CASS
Client assets and client money
Segregation, custody, reconciliations
DISP
Complaints handling
Final response, escalation, Ombudsman rights
SUP
Supervision
Notifications, regulator relationship
FIT
Fitness and propriety
Honesty, competence, financial soundness
COND
Threshold conditions
Minimum standards for authorisation
DEPP / ENF
Decision procedure and enforcement
Sanctions, disciplinary outcomes
FSMA perimeter and authorisation
General prohibition logic
Under the FSMA framework, a person generally must not carry on a regulated activity in the UK by way of business unless authorised or exempt. For exam questions, work through four tests.
Test
Ask
Why it matters
Activity
Is the person dealing, arranging, advising, managing, safeguarding, administering, accepting deposits, effecting insurance, or another regulated activity?
If no regulated activity, FSMA authorisation may not be required, though other rules may still apply.
Investment
Does it involve a specified investment such as shares, debt securities, units in funds, derivatives, insurance contracts, deposits, or similar instruments?
Regulated activity must usually relate to a specified investment.
Business element
Is it carried on by way of business rather than as a purely private one-off?
The perimeter targets business activity.
UK connection
Is the activity carried on in the UK or sufficiently connected to the UK regime?
Location and territorial scope matter.
Notes and examples
Common regulated activity traps
Activity
Meaning in exam scenarios
Trap
Dealing as principal
Firm buys/sells investments for its own account.
Still regulated if done as a business activity in specified investments.
Dealing as agent
Firm executes transactions for clients.
Agency execution is not the same as giving advice.
Arranging
Bringing about or making arrangements with a view to investment transactions.
“I only introduced them” may still be arranging depending on facts.
Advising on investments
Personal recommendation on the merits of buying, selling, subscribing for, holding, or underwriting a specific investment.
Generic education is different from a recommendation tailored to the person.
Managing investments
Discretionary management of assets belonging to another.
Decision-making discretion is the key trigger.
Safeguarding/administering
Custody or administration of assets.
CASS issues often arise once client assets are held or controlled.
Agreeing to carry on activities
Agreement to perform a regulated activity can itself be caught.
Do not wait for execution to identify the perimeter issue.
Authorised, exempt, appointed, approved
Term
Meaning
Exam distinction
Authorised person
Firm with permission from FCA and/or PRA.
Authorisation belongs to the firm, not automatically to every employee.
Part 4A permission
Permission to carry on specified regulated activities.
A firm must stay within its permission scope.
Exempt person
Person exempt from needing authorisation for particular activities.
Exemptions are narrow and fact-specific.
Appointed representative
Person who conducts certain regulated activities under an authorised principal.
Principal accepts regulatory responsibility for the appointed representative’s relevant activities.
Approved person / Senior Manager approval
Individual approved to perform controlled or senior management functions.
Individual approval is separate from firm authorisation.
Certified person
Individual performing a certification function, assessed as fit and proper by the firm.
Certified by firm, not pre-approved by FCA for that function.
No exploitation of customer behavioural biases or information gaps
Avoid foreseeable harm
Identify and reduce harm the firm could reasonably anticipate
Enable and support objectives
Do not create unnecessary barriers to customer outcomes
Products and services
Target market and product design must be appropriate
Price and value
Charges should be assessed against benefits and outcomes
Consumer understanding
Communications should support informed decisions
Consumer support
Post-sale service should not frustrate reasonable customer needs
Trap: Consumer Duty is not simply a slogan for “be nice to clients.” It is an outcomes-based standard, especially relevant to product design, distribution, communications, and support.
Be alert to tighter limits on third-party benefits.
Soft commission / research
Must be controlled, justified, and not used to disguise improper benefits.
Sales targets
Cannot override suitability, Consumer Duty, or fair treatment.
Disclosure
Useful but not a substitute for preventing or properly managing a serious conflict.
Conflicts of interest and inducements
Conflicts are not automatically prohibited, but they must be identified, prevented, managed, and disclosed where appropriate.
Conflict type
Example
Proper response
Firm versus client
Firm earns more from one product than another
Manage incentive, disclose where required, ensure suitable outcome
Client versus client
Allocation of limited investment opportunity
Fair allocation policy
Employee versus client
Personal account dealing before client order
Restrictions, disclosure, monitoring, possible prohibition
Research / corporate finance conflict
Analyst pressure from issuer relationship
Information barriers and independent controls
Gifts and hospitality
Benefit from a broker or issuer
Assess materiality, record, approve, decline if improper
Decision rule: Disclosure alone is not a cure-all. If the conflict cannot be managed so the client is treated fairly, the firm may need to decline or stop acting.
Best execution and order handling
Topic
Rule of thumb
Core duty
Take all sufficient steps to obtain the best possible result for the client.
Execution factors
Price, costs, speed, likelihood of execution and settlement, size, nature, and other relevant considerations.
Retail priority
Total consideration, meaning price plus costs, is usually central.
Order execution policy
Firm must establish, disclose as required, follow, and monitor it.
Client instructions
Specific client instructions can limit the firm’s best execution obligation for that part of the order.
Aggregation
Permitted only with controls and fair allocation; cannot systematically disadvantage clients.
Timely execution
Execute promptly, fairly, and sequentially unless conditions justify otherwise.
Records
Evidence matters: venue choice, allocation, instructions, and monitoring.
CASS: client money and custody assets
Concept
Meaning
Key controls
Client money
Money held for or on behalf of clients.
Segregation, trust status, client bank accounts, reconciliations, prompt allocation and return.
Independent assurance over controls where proportionate.
Recordkeeping
Evidence of decisions, advice, transactions, communications, controls, and remediation.
Training and competence
Staff competent for roles, supervised until competent, ongoing CPD where required.
Whistleblowing
Safe channels for raising concerns; no retaliation.
Outsourcing
Due diligence, written agreement, monitoring, access/audit rights, exit plan, and retained responsibility.
Outsourcing trap
A firm can outsource an activity, but it cannot outsource regulatory responsibility. If a service provider fails, the regulated firm must still show it selected, contracted with, monitored, and controlled the provider appropriately.
Professional integrity
The CISI UK RPI exam does not test rules in isolation. It also tests whether you can apply the professional standards expected by the Chartered Institute for Securities & Investment and by regulators.
CISI Code of Conduct themes: exam-use summary
Theme
Practical behaviour
Common wrong answer
Act honestly and fairly
Put client and market integrity ahead of personal gain.
“Everyone does it” or “the client will never know.”
Act with integrity
Avoid conduct damaging to the firm, profession, or public trust.
Concealing errors to protect reputation.
Follow law, regulation, and standards
Apply both letter and spirit of rules.
Looking for loopholes to avoid fair outcomes.
Maintain market integrity and confidentiality
Do not misuse information or distort markets.
Trading on confidential information after hearing it informally.
Manage conflicts
Identify, avoid, control, disclose, and record conflicts.
Disclosure only after conflict has already harmed client.
Maintain competence
Keep knowledge current and work within capability.
Advising on unfamiliar products without support.
Decline work beyond competence
Seek assistance or refuse where not competent.
Accepting work to please a client or manager.
Uphold high personal standards
Behave professionally inside and outside formal client interactions.
Assuming private misconduct cannot affect fitness and propriety.
Notes and examples
Integrity decision checklist
When two answers both seem technically possible, choose the answer that best satisfies this sequence:
Is it legal and within permission?
Is it fair to the client or customer?
Does it preserve market integrity?
Does it avoid or properly manage conflicts?
Would the FCA, PRA, employer, client, and public view it as transparent and honest?
Is it within the individual’s competence and authority?
Has it been escalated, recorded, and disclosed where required?
Professional integrity
Professional integrity is not separate from regulation; it is the behaviour that makes regulatory standards work.
Integrity decision framework
When a scenario feels ethical rather than technical, use this sequence:
Choosing loyalty to employer over duty to clients, market integrity, or law
Ethics scenario questions
Authorisation and regulated activities
A core CISI UK RPI skill is deciding whether a firm or person is permitted to do something.
The quick authorisation test
flowchart TD
A[Proposed business activity] --> B{Is there a specified activity?}
B -- No --> Z[Likely outside regulated activity analysis]
B -- Yes --> C{Is there a specified investment?}
C -- No --> Z
C -- Yes --> D{Is it done by way of business?}
D -- No --> Z
D -- Yes --> E{Is the person authorised or exempt?}
E -- Yes --> F[Check permission scope and conduct rules]
E -- No --> G[Potential breach of general prohibition]
F --> H{Is there a financial promotion?}
H -- Yes --> I[Check approval or exemption and communication standards]
H -- No --> J[Apply relevant conduct, systems, and integrity duties]
Notes and examples
Key concepts
Concept
Quick review point
Exam trap
General prohibition
A person must not carry on regulated activities in the UK unless authorised or exempt
Focusing only on the product and ignoring the activity
Regulated activity
Examples include dealing, arranging, advising, managing investments, safeguarding/administering assets, and other specified activities
Assuming every financial conversation is regulated advice
Specified investment
The investment must fall within the relevant statutory categories
Ignoring whether the instrument itself is covered
By way of business
The activity must have a business character
Treating a purely private, non-business action as automatically regulated
Part 4A permission
Authorised firms need permission for the specific activities they conduct
Assuming authorisation for one activity permits all activities
Exempt persons
Some persons may conduct certain activities without direct authorisation where an exemption applies
Treating exemption as unlimited permission
Appointed representative
Acts under the responsibility of an authorised principal for permitted activities
Forgetting the principal’s oversight and responsibility
Financial promotion
Invitation or inducement to engage in investment activity, communicated in the course of business
Assuming “marketing” is safe if no transaction has yet occurred
Financial promotion decision rules
A financial promotion question usually turns on four points:
Is there an invitation or inducement?
Is it communicated in the course of business?
Is it approved by an authorised person or covered by an exemption?
Is it fair, clear, and not misleading?
Common wrong answers:
“It is only a brochure, so rules do not apply.”
“The recipient is sophisticated, so no standards apply.”
“Risk warnings fix any misleading headline.”
“Past performance can be shown without balanced context.”
Complaints, redress, and regulator relations
Complaints
A complaint scenario usually asks whether the firm responds fairly and follows proper process.
Issue
Correct approach
Client expresses dissatisfaction
Recognise possible complaint; do not dismiss because wording is informal
Complaint is validly received
Investigate impartially and promptly
Firm made an error
Consider redress, correction, and root-cause analysis
Client remains dissatisfied
Provide proper escalation information where applicable
Repeated complaints
Identify systemic issues, not only individual cases
Notes and examples
FOS versus FSCS
Route
Use when…
Not for…
Financial Ombudsman Service
Eligible complainant disputes firm’s handling or outcome
Compensating all losses from market movements
Financial Services Compensation Scheme
Authorised firm cannot, or is likely unable to, meet valid claims
Routine service complaints against a solvent firm
Relations with regulators
Principle 11-style questions often turn on openness.
Regulated firms should:
Deal with regulators openly and cooperatively.
Notify regulators of significant matters where required.
Avoid misleading, incomplete, or delayed disclosures.
Maintain records that support regulatory reporting.
Escalate internally when a breach or potential breach is identified.
Trap: Hoping a problem “goes away” is rarely the correct answer. The exam usually favours early escalation, accurate records, and compliance involvement.
Senior management, conduct, and fitness
Fitness and propriety
Element
What it covers
Scenario clue
Honesty, integrity, reputation
Truthfulness, ethical conduct, disciplinary history
Did they observe proper standards of market conduct?
If they were a manager, did they take reasonable steps to control the business area?
Common mistake: Blaming “the firm” only. The exam may test both firm responsibility and individual accountability.
Fast scenario rules
Use this table when reviewing original practice questions.
If the question says…
Think…
“The client insisted”
Client pressure does not remove firm duties
“The employee did not personally profit”
Integrity or market abuse can still be breached
“The information was only shared with one person”
Confidentiality and unlawful disclosure still matter
“The firm is authorised”
Check whether it has the right permission
“The client is wealthy”
Wealth does not automatically mean professional client or suitable product
“The product has performed well historically”
Past performance does not remove risk disclosure or suitability duties
“The adviser gave no formal recommendation”
Substance matters; informal advice can still be advice
“The transaction is urgent”
Urgency increases control risk; do not bypass AML or sanctions checks
“No complaint has been made”
The firm may still need to correct harm or notify internally
“Everyone in the market does it”
Market custom does not override law, rules, or integrity
Common candidate mistakes
Memorising regulator names but not understanding their responsibilities.
Confusing authorisation with permission for every activity.
Treating retail, professional, and eligible counterparty labels as interchangeable.
Choosing disclosure as the answer for every conflict, even where prevention or refusal is required.
Missing the difference between suitability and appropriateness.
Thinking AML concerns require proof rather than suspicion.
Forgetting that tipping off risk can arise after suspicion is reported.
Assuming market abuse requires profit, loss, or a completed trade.
Ignoring record keeping as a regulatory control.
Choosing commercial convenience over escalation, documentation, and client protection.
Short practice plan
For a focused final pass:
Do 10–15 authorisation and financial promotion questions.
Do 10 client categorisation, suitability, and conduct questions.
Do 10 financial crime and market abuse questions.
Do 5–10 professional integrity scenarios.
Review every missed item using detailed explanations, then redo a mixed mini-mock.
Your next step: use the Cheat Sheet above to target weak areas, then practise with topic drills, mock exams, and a question bank of original practice questions with detailed explanations.