100+ Free CIMA P3 Risk Management Practice Questions
Prepare for the CIMA Strategic Level P3: Risk Management exam with instant access — no signup required.
Loading practice questions...
Explore More AICPA and CIMA Credentials
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: CIMA P3 Risk Management Exam
90 min
Objective Test Duration
AICPA & CIMA Exam Information
~60
Objective Test Questions
AICPA & CIMA
4 x 25%
Equally Weighted Syllabus Areas
Strategic Level Blueprint 2026-2027
100/150
Scaled Score to Pass
AICPA & CIMA
On demand
Booking Availability
AICPA & CIMA / Pearson VUE
Strategic
CGMA Qualification Level
CGMA Professional Qualification
CIMA P3: Risk Management is a 90-minute, on-demand computer-based objective test sat at Pearson VUE or via online proctoring, typically containing around 60 questions in MCQ, multiple-response, number-entry and drag-and-drop formats. The 2026-2027 Strategic blueprint splits the syllabus into four equally weighted areas: Enterprise risk (25%), Strategic risk (25%), Internal controls to manage risk (25%) and Cyber risk and management control (25%). Each CIMA objective test is marked on a 0-150 scaled score with 100 required to pass. CIMA does not publish a single global P3 fee; assessment fees are confirmed by region at booking.
Sample CIMA P3 Risk Management Practice Questions
Try these sample questions to test your CIMA P3 Risk Management exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1In enterprise risk management (ERM), what most clearly distinguishes the ERM approach from traditional 'silo' risk management?
2Under the COSO Enterprise Risk Management framework (2017), 'Enterprise Risk Management — Integrating with Strategy and Performance', what are the five interrelated components?
3A company defines the amount and type of risk it is willing to accept in pursuit of its objectives. This concept is best described as the organisation's:
4The 'TARA' framework classifies risk responses. What does each letter represent?
5On a likelihood/impact risk map, which combination would normally indicate a risk that should be AVOIDED or the activity exited entirely?
6Which statement correctly describes 'gross (inherent) risk' versus 'net (residual) risk'?
7A manufacturer faces a possible loss of £4,000,000 from a plant fire with an estimated probability of 0.05. What is the expected value of this risk?
8Within ISO 31000:2018, which is identified as one of the core PRINCIPLES of effective risk management?
9Who holds ultimate responsibility for an organisation's risk management and the setting of risk appetite?
10A risk register typically records, for each risk, all of the following EXCEPT:
About the CIMA P3 Risk Management Exam
CIMA P3 Risk Management is a Strategic-level objective test in the CGMA Professional Qualification. It examines who is responsible for managing risk, how risk management links to strategy, how organisations design internal controls, and how they manage cyber risk, across four equally weighted syllabus areas.
Assessment
Question count not published by the exam provider
Time Limit
90 minutes
Passing Score
Scaled score of 100 on a 0-150 scale
Exam Fee
Region-specific assessment fee confirmed at booking; CIMA does not publish a single global P3 fee (AICPA & CIMA / Pearson VUE)
CIMA P3 Risk Management Exam Content Outline
Enterprise risk
Risk management process and frameworks (COSO ERM, ISO 31000), risk appetite and tolerance, the TARA responses, risk identification, quantifying risk (expected value, standard deviation, VaR), risk registers, three lines of defence, and risk-financing including insurance and captives.
Strategic risk
Sources of strategic risk, PESTEL and Porter's analysis, reputational and political/country risk, ESG and climate risk, acquisition and concentration risk, and managing financial risks such as currency, interest-rate, credit and commodity exposures using internal and external hedging.
Internal controls to manage risk
COSO internal control framework, control types (preventive, detective, corrective, directive), segregation of duties, internal and external audit, audit committees, corporate governance codes, fraud risk and the fraud triangle, control limitations, and assurance over outsourced functions.
Cyber risk and management control
The CIA triad and information security, cyber-attack types (ransomware, phishing, DDoS), access controls and least privilege, GDPR and data protection, COBIT and ISO 27001, defence in depth, incident response, cloud and spreadsheet risk, and cyber governance at board level.
How to Pass the CIMA P3 Risk Management Exam
What You Need to Know
- Passing score: Scaled score of 100 on a 0-150 scale
- Assessment: Question count not published by the exam provider
- Time limit: 90 minutes
- Exam fee: Region-specific assessment fee confirmed at booking; CIMA does not publish a single global P3 fee
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
CIMA P3 Risk Management Study Tips from Top Performers
Frequently Asked Questions
How many questions are on the CIMA P3 exam?
CIMA does not publish a fixed number, but the P3 objective test typically contains around 60 questions to be answered in 90 minutes. Question types include multiple-choice, multiple-response, number-entry and drag-and-drop.
What is the CIMA P3 syllabus and how is it weighted?
Under the CGMA Strategic level blueprint 2026-2027, P3 is split into four equally weighted areas: Enterprise risk (25%), Strategic risk (25%), Internal controls to manage risk (25%), and Cyber risk and management control (25%).
What score do I need to pass CIMA P3?
CIMA objective tests are marked on a scaled score from 0 to 150, and a scaled score of 100 is required to pass. The scaled score is not the same as a simple percentage of questions correct.
Is CIMA P3 available on demand?
Yes. P3 is a computer-based objective test available on demand throughout the year. It can be sat at a Pearson VUE test centre or remotely through online proctoring once you have booked through your CIMA account.
How long is the CIMA P3 exam?
The P3 objective test lasts 90 minutes. Candidates should manage their time across the objective test questions, leaving a little time to review flagged answers before submitting.
What frameworks should I know for CIMA P3?
Key frameworks include COSO ERM (2017) and ISO 31000 for risk management, the COSO internal control framework and the three lines of defence for controls, and COBIT, ISO 27001 and the CIA triad for cyber risk and information security.
Do I need work experience to sit CIMA P3?
No work experience is required to sit the P3 objective test. However, three years of relevant practical experience is required, alongside passing the exams, to gain the CGMA designation and full CIMA membership.
How much does CIMA P3 cost?
CIMA does not publish a single global P3 fee. The objective test assessment fee varies by region and is confirmed when you book through your CIMA account and Pearson VUE, in addition to your annual student subscription.