CISI UK RPI — CISI UK Regulation & Professional Integrity Quick Review
Quick Review for CISI UK Regulation & Professional Integrity candidates preparing for exam practice.
Quick Review purpose
Use this Quick Review for the Chartered Institute for Securities & Investment exam CISI UK Regulation & Professional Integrity (CISI UK RPI) as a final consolidation pass before topic drills, mock exams, and detailed explanations.
This page is independent exam-prep support. It is designed to help you connect key UK regulatory concepts, professional integrity principles, and common scenario traps to independent companion practice, original practice questions, and question-bank review.
How to use this page in a short review session
- Read the high-yield map first. Identify weak areas before opening a question bank.
- Review the decision rules. Many CISI UK RPI questions test “what should the firm or individual do next?” rather than pure definition recall.
- Use topic drills immediately after each section. Do not wait until you feel fully ready; original practice questions expose gaps quickly.
- Read detailed explanations carefully. For regulation questions, the explanation often matters more than the answer choice because similar facts can change the outcome.
High-yield exam map
| Area | What to know quickly | Common trap | Practice focus |
|---|---|---|---|
| UK regulatory structure | FCA, PRA, Bank of England, HM Treasury, FOS, FSCS, NCA, firm responsibilities | Assuming one body does everything | “Who regulates / who handles / who compensates?” drills |
| Authorisation | FSMA general prohibition, permissions, regulated activities, exemptions, appointed representatives | Activity is regulated only if both the activity and investment are specified and it is done by way of business | Scenario classification questions |
| FCA principles and conduct | Principles for Businesses, conduct rules, Consumer Duty, client interests, conflicts | Picking a narrow rule when a broad principle is clearly breached | Principle-to-scenario drills |
| Client categorisation | Retail, professional, eligible counterparty; protection levels | Treating eligible counterparties as a universal category for all services | Categorisation and disclosure questions |
| Advice and execution | Suitability, appropriateness, execution-only, best execution | Confusing suitability with appropriateness | Advice-route decision questions |
| Market integrity | Inside information, market abuse, misleading behaviour, personal account dealing | Thinking a trade must succeed to be abusive | Market abuse scenario drills |
| Financial crime | AML, CDD, EDD, sanctions, bribery, fraud, suspicious activity reporting | Tipping off, ignoring beneficial ownership, confusing sanctions with AML | Red-flag and escalation questions |
| Client assets and client money | Segregation, records, reconciliations, custody, client money controls | Assuming all money received by a firm is client money | CASS-style concept drills |
| Complaints and redress | Internal handling, FOS, FSCS, fair outcomes | Confusing compensation schemes with complaint resolution | “Where does the client go?” questions |
| Professional integrity | Honesty, competence, confidentiality, escalation, conflicts, whistleblowing | Choosing loyalty to employer over duty to clients, market integrity, or law | Ethics scenario questions |
UK regulatory architecture
The exam often tests whether you can identify the correct body, rule source, or route for escalation.
| Body or framework | Core role for exam purposes | Candidate mistake to avoid |
|---|---|---|
| HM Treasury | Government department with responsibility for financial services policy and legislation | Treating it as the day-to-day conduct supervisor |
| Bank of England | Financial stability, monetary stability, and key market infrastructure responsibilities | Confusing its macro role with individual retail complaint handling |
| Prudential Regulation Authority | Prudential supervision of certain firms such as banks, insurers, and major investment firms | Assuming all investment firms are PRA-regulated |
| Financial Conduct Authority | Conduct regulation, market integrity, consumer protection, competition, and many firm authorisation/supervision functions | Forgetting that conduct duties can apply even where prudential supervision is elsewhere |
| Financial Ombudsman Service | Independent complaint resolution for eligible complainants | Confusing complaint adjudication with compensation for firm failure |
| Financial Services Compensation Scheme | Compensation scheme where authorised firms are unable, or likely unable, to meet claims | Treating it as the first step for every complaint |
| National Crime Agency | Receives suspicious activity reports through the UK financial crime framework | Confusing external SAR reporting with internal escalation to the MLRO/nominated officer |
| FCA Handbook | Source of many rules and guidance, including PRIN, SYSC, COBS, CASS, DISP, SUP, FIT, COND, DEPP and others | Memorising names without knowing what each sourcebook generally covers |
Common FCA Handbook areas
| Area | Think of it as… | Typical exam angle |
|---|---|---|
| PRIN | High-level Principles for Businesses | Broad conduct failures |
| SYSC | Senior management arrangements, systems and controls | Governance, controls, compliance oversight |
| COBS | Conduct of business for investment business | Client communication, suitability, best execution, conflicts |
| CASS | Client assets and client money | Segregation, custody, reconciliations |
| DISP | Complaints handling | Final response, escalation, Ombudsman rights |
| SUP | Supervision | Notifications, regulator relationship |
| FIT | Fitness and propriety | Honesty, competence, financial soundness |
| COND | Threshold conditions | Minimum standards for authorisation |
| DEPP / ENF | Decision procedure and enforcement | Sanctions, disciplinary outcomes |
Authorisation and regulated activities
A core CISI UK RPI skill is deciding whether a firm or person is permitted to do something.
The quick authorisation test
flowchart TD
A[Proposed business activity] --> B{Is there a specified activity?}
B -- No --> Z[Likely outside regulated activity analysis]
B -- Yes --> C{Is there a specified investment?}
C -- No --> Z
C -- Yes --> D{Is it done by way of business?}
D -- No --> Z
D -- Yes --> E{Is the person authorised or exempt?}
E -- Yes --> F[Check permission scope and conduct rules]
E -- No --> G[Potential breach of general prohibition]
F --> H{Is there a financial promotion?}
H -- Yes --> I[Check approval or exemption and communication standards]
H -- No --> J[Apply relevant conduct, systems, and integrity duties]
Key concepts
| Concept | Quick review point | Exam trap |
|---|---|---|
| General prohibition | A person must not carry on regulated activities in the UK unless authorised or exempt | Focusing only on the product and ignoring the activity |
| Regulated activity | Examples include dealing, arranging, advising, managing investments, safeguarding/administering assets, and other specified activities | Assuming every financial conversation is regulated advice |
| Specified investment | The investment must fall within the relevant statutory categories | Ignoring whether the instrument itself is covered |
| By way of business | The activity must have a business character | Treating a purely private, non-business action as automatically regulated |
| Part 4A permission | Authorised firms need permission for the specific activities they conduct | Assuming authorisation for one activity permits all activities |
| Exempt persons | Some persons may conduct certain activities without direct authorisation where an exemption applies | Treating exemption as unlimited permission |
| Appointed representative | Acts under the responsibility of an authorised principal for permitted activities | Forgetting the principal’s oversight and responsibility |
| Financial promotion | Invitation or inducement to engage in investment activity, communicated in the course of business | Assuming “marketing” is safe if no transaction has yet occurred |
Financial promotion decision rules
A financial promotion question usually turns on four points:
- Is there an invitation or inducement?
- Is it communicated in the course of business?
- Is it approved by an authorised person or covered by an exemption?
- Is it fair, clear, and not misleading?
Common wrong answers:
- “It is only a brochure, so rules do not apply.”
- “The recipient is sophisticated, so no standards apply.”
- “Risk warnings fix any misleading headline.”
- “Past performance can be shown without balanced context.”
FCA Principles for Businesses
The Principles often provide the best answer in broad scenario questions.
| Principle theme | What it means in exam terms | Scenario clue |
|---|---|---|
| Integrity | Act honestly and fairly | Concealment, misleading statements, false records |
| Skill, care and diligence | Competent, careful performance | Poor review, careless recommendation, weak due diligence |
| Management and control | Effective organisation and risk controls | No oversight, unclear responsibilities, weak compliance |
| Financial prudence | Adequate financial resources | Excessive risk to firm stability |
| Market conduct | Proper standards in markets | Manipulation, disorderly trading, abusive behaviour |
| Customers’ interests | Due regard to customer interests and fair treatment | Product sold for firm benefit over client need |
| Communications with clients | Clear, fair and not misleading | Unbalanced risk/return claims |
| Conflicts of interest | Manage conflicts fairly | Undisclosed incentives, self-dealing |
| Customers: relationships of trust | Reasonable care where firm has discretion or client relies on it | Portfolio management or advisory reliance |
| Clients’ assets | Adequate protection for client assets | Poor segregation, weak custody controls |
| Relations with regulators | Open and cooperative | Delayed notification, incomplete information |
| Consumer Duty | Deliver good outcomes for retail customers where applicable | Product value, understanding, support, foreseeable harm |
Consumer Duty quick review
For retail customer scenarios, check:
| Element | Practical meaning |
|---|---|
| Act in good faith | No exploitation of customer behavioural biases or information gaps |
| Avoid foreseeable harm | Identify and reduce harm the firm could reasonably anticipate |
| Enable and support objectives | Do not create unnecessary barriers to customer outcomes |
| Products and services | Target market and product design must be appropriate |
| Price and value | Charges should be assessed against benefits and outcomes |
| Consumer understanding | Communications should support informed decisions |
| Consumer support | Post-sale service should not frustrate reasonable customer needs |
Trap: Consumer Duty is not simply a slogan for “be nice to clients.” It is an outcomes-based standard, especially relevant to product design, distribution, communications, and support.
Client categorisation
Client category affects the level of regulatory protection.
| Category | Broad meaning | Protection level | Exam reminder |
|---|---|---|---|
| Retail client | Default highest-protection category | Highest | If unsure, retail protection is usually the safer assumption |
| Professional client | Has experience, knowledge, and expertise to make investment decisions and assess risks | Lower than retail | Can be per se or elective, but elective treatment requires process and warnings |
| Eligible counterparty | Certain sophisticated counterparties for eligible types of business | Lowest for relevant business | Not a universal label for all interactions |
Suitability, appropriateness, and execution-only
| Route | When it applies | Firm must focus on | Common trap |
|---|---|---|---|
| Suitability | Personal recommendation or portfolio management | Client objectives, financial situation, ability to bear loss, knowledge and experience, risk tolerance | Treating a product as suitable merely because it is “high quality” |
| Appropriateness | Non-advised sale of certain complex products | Whether client has knowledge and experience to understand risks | Confusing it with full suitability |
| Execution-only | Client gives order without advice, often for non-complex products where conditions are met | Clear process, no disguised advice, required disclosures | A helpful suggestion can accidentally become advice |
| Best execution | Executing client orders | Best possible result considering relevant execution factors | Assuming best price alone always decides |
| Product governance | Designing and distributing products | Target market, distribution strategy, review | Selling outside target market without justification |
Suitability red flags
A recommendation is vulnerable if:
- The client’s investment objective is vague.
- Risk tolerance is assumed from age or wealth alone.
- Capacity for loss is ignored.
- Costs and charges are not explained.
- The firm recommends a product because it pays higher commission or benefits the firm.
- The client does not understand leverage, illiquidity, concentration, or capital-at-risk features.
- The adviser relies on old KYC information without checking material changes.
Conflicts of interest and inducements
Conflicts are not automatically prohibited, but they must be identified, prevented, managed, and disclosed where appropriate.
| Conflict type | Example | Proper response |
|---|---|---|
| Firm versus client | Firm earns more from one product than another | Manage incentive, disclose where required, ensure suitable outcome |
| Client versus client | Allocation of limited investment opportunity | Fair allocation policy |
| Employee versus client | Personal account dealing before client order | Restrictions, disclosure, monitoring, possible prohibition |
| Research / corporate finance conflict | Analyst pressure from issuer relationship | Information barriers and independent controls |
| Gifts and hospitality | Benefit from a broker or issuer | Assess materiality, record, approve, decline if improper |
Decision rule: Disclosure alone is not a cure-all. If the conflict cannot be managed so the client is treated fairly, the firm may need to decline or stop acting.
Market integrity and market abuse
Market integrity questions often test whether behaviour damages confidence in fair, orderly, and transparent markets.
Inside information
Information is likely to be inside information if it is:
| Criterion | Meaning |
|---|---|
| Precise | Specific enough to draw a conclusion about possible price effect |
| Non-public | Not generally available to the market |
| Relates to issuer or instrument | Concerns securities, issuers, derivatives, or relevant market matters |
| Price-sensitive | Would be likely to have a significant effect on price if public |
Market abuse patterns
| Behaviour | What it looks like | Trap |
|---|---|---|
| Insider dealing | Trading while in possession of inside information | Profit is not required for the behaviour to be problematic |
| Unlawful disclosure | Passing inside information without proper reason | “I only told one friend” is not a defence |
| Manipulation | False or misleading signals, artificial price levels, abusive orders | Cancelled orders can still matter |
| Rumour misuse | Spreading false or misleading information | Informal channels are still communications |
| Benchmark or price distortion | Conduct designed to influence reference prices | The market-wide effect is central |
| Improper order activity | Layering, spoofing, wash trades, marking the close | “No client complained” does not make it acceptable |
Personal account dealing
If an employee wants to trade personally, ask:
- Does the employee hold inside or confidential information?
- Is there a pending client order?
- Is the trade restricted by the firm’s policy?
- Has pre-clearance been obtained where required?
- Could the trade create a conflict or appearance of impropriety?
If the answer creates doubt, the safe exam action is usually to escalate to compliance and do not trade until cleared.
Financial crime
Financial crime questions reward disciplined escalation. Do not improvise, warn the customer, or investigate beyond your role.
Money laundering stages
| Stage | Meaning | Example |
|---|---|---|
| Placement | Introducing criminal property into the financial system | Cash deposit, initial investment |
| Layering | Creating complex transactions to obscure origin | Transfers across accounts or jurisdictions |
| Integration | Returning funds as apparently legitimate wealth | Investment proceeds, property purchase |
AML and CDD review
| Topic | Quick rule | Scenario clue |
|---|---|---|
| Customer due diligence | Identify and verify customer identity | New relationship, occasional transaction, doubt over identity |
| Beneficial ownership | Identify who ultimately owns or controls the customer | Company, trust, nominee, complex structure |
| Risk-based approach | Higher risk requires stronger controls | Unusual geography, structure, activity, or source of wealth |
| Enhanced due diligence | Apply more scrutiny to higher-risk cases | PEP, high-risk jurisdiction, unusual transaction pattern |
| Ongoing monitoring | Keep information current and review transactions | Activity inconsistent with known profile |
| Record keeping | Maintain evidence of checks and decisions | “We knew the client personally” is not enough |
Suspicion workflow
| Step | Correct exam response |
|---|---|
| Red flag appears | Pause and consider whether suspicion exists |
| Suspicion exists | Report internally to the MLRO or nominated officer |
| Client asks questions | Do not tip off or disclose improper information |
| Transaction pending | Follow internal procedures and MLRO guidance |
| Records | Document facts, decisions, and escalation |
Trap: “SAR” can mean suspicious activity report in AML and subject access request in data protection. Read the context carefully.
Other financial crime areas
| Area | Key exam point | Wrong instinct |
|---|---|---|
| Sanctions | Screen clients, counterparties, and transactions; freeze or stop activity where required | Treating sanctions as merely enhanced AML risk |
| Bribery | Improper advantage, facilitation payments, gifts, hospitality, third-party agents | Assuming small payments are always acceptable |
| Fraud | Deception for gain or to cause loss | Waiting for confirmed loss before escalating |
| Terrorist financing | Funds may be legitimate or illegitimate; purpose is key | Looking only for criminal source of funds |
| Tax evasion facilitation | Firm and employee controls matter | Treating it as solely the client’s problem |
| Cyber-enabled crime | Account takeover, payment diversion, identity compromise | Processing urgent instructions without verification |
Client money and client assets
Client asset protection is a common area for control-based questions.
| Concept | Quick meaning | Exam trap |
|---|---|---|
| Client money | Money held for or on behalf of clients where client money rules apply | Assuming all receipts are client money without checking capacity and arrangement |
| Custody assets | Financial instruments held for clients | Ignoring records and ownership evidence |
| Segregation | Keep client assets separate from firm assets | “We can identify it later” is not adequate |
| Reconciliation | Compare internal records to external records | Treating reconciliation as optional admin |
| Mandates | Authority over client assets or accounts | Underestimating control risk |
| Title transfer collateral | Client transfers full ownership to firm under arrangement | May not be treated as client money/assets in the same way |
| CASS oversight | Senior accountability and controls | Thinking custody is purely an operations issue |
CASS-style decision rules
- If the firm holds client money, ask whether it is segregated, recorded, and reconciled.
- If the firm holds custody assets, ask whether ownership and location are clear.
- If there is a shortfall, poor records, or commingling, the issue is not just operational; it is a client protection and regulatory issue.
- If a third party is used, due skill, care, and diligence in selection and monitoring matter.
Complaints, redress, and regulator relations
Complaints
A complaint scenario usually asks whether the firm responds fairly and follows proper process.
| Issue | Correct approach |
|---|---|
| Client expresses dissatisfaction | Recognise possible complaint; do not dismiss because wording is informal |
| Complaint is validly received | Investigate impartially and promptly |
| Firm made an error | Consider redress, correction, and root-cause analysis |
| Client remains dissatisfied | Provide proper escalation information where applicable |
| Repeated complaints | Identify systemic issues, not only individual cases |
FOS versus FSCS
| Route | Use when… | Not for… |
|---|---|---|
| Financial Ombudsman Service | Eligible complainant disputes firm’s handling or outcome | Compensating all losses from market movements |
| Financial Services Compensation Scheme | Authorised firm cannot, or is likely unable to, meet valid claims | Routine service complaints against a solvent firm |
Relations with regulators
Principle 11-style questions often turn on openness.
Regulated firms should:
- Deal with regulators openly and cooperatively.
- Notify regulators of significant matters where required.
- Avoid misleading, incomplete, or delayed disclosures.
- Maintain records that support regulatory reporting.
- Escalate internally when a breach or potential breach is identified.
Trap: Hoping a problem “goes away” is rarely the correct answer. The exam usually favours early escalation, accurate records, and compliance involvement.
Senior management, conduct, and fitness
Fitness and propriety
| Element | What it covers | Scenario clue |
|---|---|---|
| Honesty, integrity, reputation | Truthfulness, ethical conduct, disciplinary history | False CV, concealed conflict, misleading regulator |
| Competence and capability | Skills, qualifications, experience, training | Person lacks knowledge for role |
| Financial soundness | Personal financial position where relevant | Serious unmanaged financial problems |
Conduct rule mindset
For individual accountability scenarios, ask:
- Did the person act with integrity?
- Did they exercise due skill, care, and diligence?
- Did they deal with regulators appropriately?
- Did they pay due regard to customer interests?
- Did they observe proper standards of market conduct?
- If they were a manager, did they take reasonable steps to control the business area?
Common mistake: Blaming “the firm” only. The exam may test both firm responsibility and individual accountability.
Professional integrity
Professional integrity is not separate from regulation; it is the behaviour that makes regulatory standards work.
Integrity decision framework
When a scenario feels ethical rather than technical, use this sequence:
- Identify the duty. Client interest, market integrity, confidentiality, legal obligation, employer policy, regulator duty.
- Identify the conflict. Personal benefit, firm revenue, client pressure, colleague pressure, time pressure.
- Avoid concealment. Do not hide facts, alter records, backdate documents, or create misleading impressions.
- Escalate properly. Compliance, line manager, MLRO, whistleblowing channel, or senior management as appropriate.
- Document. Record facts and decisions accurately.
- Do not act until cleared where the action could breach law, regulation, or firm policy.
Common professional integrity scenarios
| Scenario | Better answer | Poor answer |
|---|---|---|
| Client asks you to ignore suitability information | Refuse to misstate facts; document and escalate if needed | Let client sign a waiver for everything |
| Manager pressures you to approve misleading material | Challenge and escalate | Approve because manager is responsible |
| You discover a trade allocation error | Report, correct fairly, assess client impact | Hide if no client notices |
| You receive confidential information | Protect it and use only for proper purpose | Share with a colleague who is merely curious |
| You suspect money laundering | Follow internal reporting; do not tip off | Ask the client to explain in a way that alerts them |
| You made a mistake | Disclose internally promptly and support remediation | Delay until you can fix records |
| A gift is offered | Check policy, record, obtain approval or decline | Accept if it does not obviously affect you |
Data protection, confidentiality, and records
| Area | Quick review point | Exam trap |
|---|---|---|
| Confidentiality | Client information should be protected unless disclosure is authorised or required | Sharing internally without need-to-know |
| Data protection | Personal data must be processed lawfully, fairly, securely, and for proper purposes | Keeping data indefinitely “just in case” |
| Data minimisation | Use only what is needed | Collecting excessive personal information |
| Accuracy | Keep relevant records current | Relying on outdated KYC for advice |
| Security | Prevent unauthorised access, loss, or misuse | Sending sensitive data through weak channels |
| Subject rights | Individuals may have rights over their data | Confusing data access with AML SAR handling |
| Record keeping | Maintain evidence of decisions, disclosures, checks, and approvals | Assuming verbal approval is enough |
Fast scenario rules
Use this table when reviewing original practice questions.
| If the question says… | Think… |
|---|---|
| “The client insisted” | Client pressure does not remove firm duties |
| “The employee did not personally profit” | Integrity or market abuse can still be breached |
| “The information was only shared with one person” | Confidentiality and unlawful disclosure still matter |
| “The firm is authorised” | Check whether it has the right permission |
| “The client is wealthy” | Wealth does not automatically mean professional client or suitable product |
| “The product has performed well historically” | Past performance does not remove risk disclosure or suitability duties |
| “The adviser gave no formal recommendation” | Substance matters; informal advice can still be advice |
| “The transaction is urgent” | Urgency increases control risk; do not bypass AML or sanctions checks |
| “No complaint has been made” | The firm may still need to correct harm or notify internally |
| “Everyone in the market does it” | Market custom does not override law, rules, or integrity |
Common candidate mistakes
- Memorising regulator names but not understanding their responsibilities.
- Confusing authorisation with permission for every activity.
- Treating retail, professional, and eligible counterparty labels as interchangeable.
- Choosing disclosure as the answer for every conflict, even where prevention or refusal is required.
- Missing the difference between suitability and appropriateness.
- Thinking AML concerns require proof rather than suspicion.
- Forgetting that tipping off risk can arise after suspicion is reported.
- Assuming market abuse requires profit, loss, or a completed trade.
- Ignoring record keeping as a regulatory control.
- Choosing commercial convenience over escalation, documentation, and client protection.
Short practice plan
For a focused final pass:
- Do 10–15 authorisation and financial promotion questions.
- Do 10 client categorisation, suitability, and conduct questions.
- Do 10 financial crime and market abuse questions.
- Do 5–10 professional integrity scenarios.
- Review every missed item using detailed explanations, then redo a mixed mini-mock.
Your next step: use the Quick Review above to target weak areas, then practise with topic drills, mock exams, and a question bank of original practice questions with detailed explanations.