Table of Contents
CISI Operational Risk
Explore syllabus-aligned study tools, realistic practice and course-grounded AI support.
The CISI Operational Risk qualification is a pivotal certification for professionals navigating the complex landscape of risk management in modern financial services. From the principles of the Basel Committee to the nuances of cyber risk and internal governance, this exam tests your ability to identify, assess, and mitigate risks that could severely impact a firm’s operational stability.
In this guide, we will break down the syllabus, explore key topics, and provide actionable strategies to help you pass the exam on your first attempt.
Understanding the Syllabus
The current Edition 26 workbook supports Version 22 of the syllabus, used for exams from 20 September 2025 to 19 September 2027. The exam consists of 50 multiple-choice questions in 60 minutes. The public syllabus does not publish a pass mark; our course uses 70% as a practice target.
The syllabus has seven elements, in the same order as the workbook chapters, with nominal allocations of 3, 7, 20, 4, 5, 7 and 4 questions:
- Risk Basics
- Other Major Risks
- The Nature of Operational Risk
- The Causes and Impacts of Operational Risk
- Operational Risks Arising in the Trade Cycle
- The Support and Control Functions
- Operational Risk in the Regulatory Environment
Key Focus Areas for the Exam
1. The Basel Frameworks
The regulatory element covers the Basel Committee on Banking Supervision (BCBS). Understand the evolution from Basel I to Basel III and the three pillars:
- Pillar 1: Minimum Capital Requirements
- Pillar 2: Supervisory Review Process
- Pillar 3: Market Discipline
Keep the historical Basel II Basic Indicator, Standardised and Advanced Measurement Approaches distinct from the later Basel III standardised approach (SA). The current workbook presents the latter using the Business Indicator Component (BIC) and Internal Loss Multiplier (ILM).
2. Risk Assessment and Mitigation
You will be tested on the tools used to identify and assess operational risk. Familiarize yourself with:
- Risk Registers: Central databases of all identified risks.
- Key Risk Indicators (KRIs): Metrics used to signal changes in the risk profile.
- Scenario Analysis: Evaluating the impact of extreme but plausible events.
Free CISI Operational Risk Practice Questions & Exam Preview
Try 15 CISI Operational Risk practice questions from The Nature of Operational Risk
Practice CISI Operational Risk exam questions with answers and explanations. The full course includes 5 mock exams and chapter study tools.
Exam Preview
An international bank is drafting its new operational risk policy to define risk appetite and establish boundaries between operational, market, and credit risk. The Chief Risk Officer proposes that the policy only be signed off by the heads of each division to ensure local buy-in. According to best practices in operational risk management, what is the primary flaw in this approach?
Flashcards
How does the Basel Committee on Banking Supervision (BCBS) formally define Operational Risk?
Focus Learn
- Distinguish likelihood from consequence in a risk definition.
- Classify credit, market, liquidity and operational risk in practical scenarios.
- Explain what Invesco, PPI, LIBOR, HSBC, Bank of Bangladesh and other named events show about controls.
- State ERM's four practical aims and its firm-wide scope.
- Explain why common definitions, data and culture matter to ERM.
Risk is the possibility of an adverse consequence, not the certainty that an event will occur. A firm therefore considers both the likelihood of an event and what it would lose if the event happened. In financial services, the four broad categories are credit, market, liquidity and operational risk. Credit concerns a borrower or counterparty failing to meet an obligation. Market risk concerns adverse changes in financial-instrument values. Liquidity has an asset side (a position cannot be sold promptly at a reasonable price) and a funding side (the firm cannot meet payments when due). Operational risk concerns losses from inadequate or failed processes, people, systems or external events. One incident can engage several categories, so identify the actual cause and consequence before choosi…
Unlock all Focus Learn
Open every chapter’s key areas, pitfalls, exam traps and key numbers.
3. Cyber Security
As cyber threats become more sophisticated, regulators are placing greater emphasis on IT security and data protection. You should understand the principles of the General Data Protection Regulation (GDPR), the role of the Chief Information Security Officer (CISO), and common cyber threats like phishing, ransomware, and DDoS attacks.
Preparation Strategies
Start with the Official Workbook
The CISI Edition 26 workbook is the primary study source for the current Version 22 syllabus. Read it alongside the learning objectives, noting key definitions, controls, regulatory bodies and the BIC × ILM relationship.
Practice with Realistic Mock Exams
Use timed practice to identify weak areas and get comfortable with the question format. The course has four original 50-question mocks and a fifth mixed review paper drawn from those questions.
Utilise Flashcards for Key Terms
Operational risk involves a lot of terminology and acronyms (e.g., KRI, RCSA, BCBS). Flashcards are an excellent tool for rapid recall and spaced repetition. Ensure you are familiar with all definitions, as the exam often uses precise language.
Conclusion
Passing the CISI Operational Risk exam requires a solid understanding of both the theoretical frameworks and the practical applications of risk management. By dedicating sufficient time to study, utilizing mock exams, and focusing on the core syllabus areas, you will be well on your way to achieving this valuable certification.
Frequently Asked Questions
1 What is the CISI Operational Risk exam format?
The Version 22 syllabus specifies 50 multiple-choice questions in 60 minutes. The public syllabus does not publish a pass mark; this course uses 70% as its practice target.
2 Is the Operational Risk exam suitable for beginners?
While it covers advanced concepts like Basel III and risk modelling, it is a Level 3 qualification and accessible for practitioners looking to formalise their knowledge.
3 How long should I study for the CISI Operational Risk exam?
Study time depends on prior experience. Work through all seven chapters, then use timed practice and answer explanations to find weak areas.
4 What are the core topics covered in the syllabus?
Key areas include the regulatory environment (Basel frameworks, FCA guidelines), risk identification and assessment, cyber risk, and enterprise risk management (ERM).
Keep learning
Related Insights
Top 5 Operational Risk Scenarios in Finance (CISI Guide)
Master operational risk management for the CISI exams by exploring the top 5 real-world failure scenarios, from cyber attacks to rogue trading.
CISI Operational Risk Mock Exams & Free Sample Questions (2026)
Prepare for the CISI Operational Risk exam with 250 practice questions across five mock exams and free sample questions aligned to Edition 26.
GARP FRM Part II Operational Risk and Resilience Study Guide
Study FRM Part II Operational Risk and Resilience through governance, controls, cyber risk, third parties, model risk, stress testing, capital and Basel reforms.
Ready to Prepare for Your Exam?
Prepare with syllabus-aligned study tools, realistic practice and course-grounded AI support.
Explore Courses