All Practice Exams

100+ Free CISI Operational Risk Practice Questions

Prepare for the CISI Operational Risk (Investment Operations Certificate unit) exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published by CISI Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CISI Operational Risk Exam

70%

Pass Mark

CISI IOC

CBE

Computer-Based MCQ

CISI IOC

On-demand

Exam Availability

CISI IOC

3 units

To Achieve the IOC

CISI IOC

No entry

Formal Requirements

CISI IOC

7

Basel Event Types

Basel Committee

The CISI Operational Risk unit is an on-demand, computer-based multiple-choice examination forming part of the Investment Operations Certificate (IOC), with a 70% pass mark. The syllabus covers operational risk concepts and the Basel definition, risk appetite and the three lines of defence, identifying and assessing risk, risk and control self-assessment (RCSA), key risk indicators (KRIs), loss data and event management including the Basel operational risk event types, process, people, systems and external-event risk, and governance and reporting. CISI sets no formal entry requirements, and three IOC units are needed to earn the certificate.

Sample CISI Operational Risk Practice Questions

Try these sample questions to test your CISI Operational Risk exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which definition of operational risk is used in the Basel framework and adopted across financial services?
A.The risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events
B.The risk that a counterparty fails to meet its contractual obligations
C.The risk of loss arising from movements in market prices
D.The risk that an institution cannot meet payment obligations as they fall due
Explanation: The Basel Committee defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people and systems, or from external events. This definition explicitly includes legal risk but excludes strategic and reputational risk.
2Under the Basel definition of operational risk, which risk type is explicitly INCLUDED?
A.Strategic risk
B.Legal risk
C.Reputational risk
D.Systemic risk
Explanation: The Basel definition of operational risk explicitly includes legal risk but specifically excludes strategic and reputational risk. Legal risk covers exposure to fines, penalties and damages from supervisory actions and private settlements.
3Operational risk is often described as which type of risk in relation to potential reward?
A.A speculative risk offering balanced upside and downside
B.A market risk that can be hedged with derivatives
C.A pure (downside-only) risk with no upside reward
D.A diversifiable risk that disappears in a large portfolio
Explanation: Operational risk is generally a pure or downside risk: a firm gains no reward for taking it, only the prospect of loss. This contrasts with market or credit risk, which are accepted in exchange for expected return.
4The four primary causal categories of operational risk under the Basel definition are people, systems, external events and which other?
A.Markets
B.Counterparties
C.Liquidity
D.Processes
Explanation: The Basel definition identifies four root-cause categories: inadequate or failed internal processes, people, systems, and external events. These four causal buckets underpin most operational risk taxonomies.
5What is the term for the level and type of risk a firm is willing to accept in pursuit of its objectives?
A.Risk appetite
B.Risk velocity
C.Risk inventory
D.Risk transfer
Explanation: Risk appetite is the amount and type of risk an organisation is prepared to seek, accept or tolerate to achieve its strategic objectives. It is typically expressed in a board-approved risk appetite statement with supporting tolerances.
6Within a risk management framework, what does 'risk tolerance' most accurately describe?
A.The total elimination of all operational risk exposures
B.The acceptable variation around the risk appetite, often expressed as specific limits or thresholds
C.The historical average of realised operational losses
D.The capital held against unexpected losses
Explanation: Risk tolerance defines the acceptable level of variation relative to the achievement of objectives, typically translated into quantitative thresholds and limits that operationalise the broader risk appetite statement.
7Which sequence correctly represents the core stages of the operational risk management cycle?
A.Report, assess, transfer, ignore
B.Monitor, eliminate, capitalise, audit
C.Identify, assess, control/mitigate, monitor and report
D.Assess, accept, terminate, restate
Explanation: A typical operational risk management cycle is: identify risks, assess their likelihood and impact, control or mitigate them, then monitor and report on an ongoing basis. The cycle is iterative rather than one-off.
8The 'three lines of defence' model assigns ownership of day-to-day risk and controls primarily to which line?
A.The second line: the risk and compliance functions
B.The third line: internal audit
C.The external auditors as a fourth line
D.The first line: business and operational management who own and manage risk
Explanation: In the three lines of defence model, the first line comprises business and operational management who own risks and operate controls. The second line (risk and compliance) provides oversight and challenge, and the third line (internal audit) gives independent assurance.
9In the three lines of defence model, which function provides independent assurance to the board and audit committee?
A.Internal audit
B.The trading desk
C.The compliance department
D.The finance team
Explanation: Internal audit forms the third line of defence, providing independent and objective assurance over the effectiveness of governance, risk management and internal controls to the board and audit committee.
10What distinguishes 'inherent risk' from 'residual risk'?
A.Inherent risk is always lower than residual risk
B.Inherent risk is the exposure before controls; residual risk is the exposure remaining after controls are applied
C.Inherent risk applies only to credit risk; residual risk only to market risk
D.They are identical terms used interchangeably
Explanation: Inherent (gross) risk is the level of risk before any mitigating controls are applied. Residual (net) risk is what remains after controls operate. The difference reflects the effectiveness of the control environment.

About the CISI Operational Risk Exam

CISI Operational Risk is a technical unit of the Investment Operations Certificate (IOC). It tests the operational risk framework, risk appetite, identification and assessment, risk and control self-assessment, key risk indicators, loss data and event management, process, people and systems risk, and governance and reporting, through an on-demand computer-based multiple-choice exam with a 70% pass mark.

Assessment

Question count not published by the exam provider

Time Limit

Timed computer-based examination; confirm the current duration with CISI

Passing Score

70% pass mark

Exam Fee

Set by CISI per IOC unit; confirm the current Operational Risk unit price in the CISI shop (Chartered Institute for Securities & Investment (CISI))

CISI Operational Risk Exam Content Outline

16%

Operational Risk Concepts and Frameworks

Basel operational risk definition, pure risk, risk appetite and tolerance, the four Ts, inherent versus residual risk, the three lines of defence, enterprise risk management, and the risk management cycle.

14%

Identifying and Assessing Operational Risk

Risk identification techniques, process mapping, risk taxonomies, likelihood and impact mapping, heat maps, expected loss, scenario analysis, risk velocity, and preventive versus detective controls.

14%

Risk and Control Self-Assessment (RCSA)

Purpose, ownership and frequency of RCSA, assessing control design and operating effectiveness, action plans, limitations and bias, and linking self-assessment results to loss data.

13%

Key Risk Indicators (KRIs)

KRI definition and purpose, leading versus lagging indicators, thresholds and escalation, key control indicators, dashboards, recalibration, and alignment of indicators to risk appetite.

15%

Loss Data and Event Management

Internal and external loss data, near misses, collection thresholds, recoveries, root cause analysis, the Basel operational risk event types, and expected versus unexpected loss.

16%

Operational Risk in Processes, People, Systems and External Events

Segregation of duties, dual control, key-person risk, outsourcing and third-party risk, business continuity, cyber and systems risk, model risk, documentation and legal risk, and conduct and compliance failures.

12%

Governance and Reporting of Operational Risk

Board and risk committee accountability, risk culture and tone from the top, risk registers and policies, escalation, regulatory incident reporting, risk dashboards, aggregation, and internal audit assurance.

How to Pass the CISI Operational Risk Exam

What You Need to Know

  • Passing score: 70% pass mark
  • Assessment: Question count not published by the exam provider
  • Time limit: Timed computer-based examination; confirm the current duration with CISI
  • Exam fee: Set by CISI per IOC unit; confirm the current Operational Risk unit price in the CISI shop

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

CISI Operational Risk Study Tips from Top Performers

1Learn the Basel operational risk definition precisely, including that legal risk is in scope but strategic and reputational risk are excluded.
2Memorise the seven Basel operational risk event types and practise classifying example scenarios into the correct type.
3Be able to distinguish RCSA, KRIs and loss data, and explain how each contributes to the operational risk framework.
4Practise telling leading indicators from lagging indicators, and preventive controls from detective controls, with concrete examples.
5Use the three lines of defence model to answer governance questions about who owns, oversees and assures operational risk.
6Sit timed multiple-choice mocks and aim comfortably above the 70% pass mark before booking your on-demand exam.

Frequently Asked Questions

What is the CISI Operational Risk unit?

It is a technical unit of the CISI Investment Operations Certificate (IOC). It can be taken as a standalone award or as one of the three units needed to achieve the IOC, and it gives operations staff a practical understanding of operational risk in financial services.

What is the pass mark for the CISI Operational Risk exam?

The pass mark is 70%, consistent with CISI's IOC technical units. The unit is assessed by a computer-based multiple-choice examination, so candidates should aim for consistent mastery across the whole syllabus.

How is the CISI Operational Risk exam delivered?

It is delivered as an on-demand computer-based examination (CBE) using multiple-choice questions. Candidates can book and sit the exam flexibly through CISI's computer-based testing arrangements rather than on fixed sitting dates.

Are there any entry requirements for the CISI Operational Risk unit?

No. The Investment Operations Certificate, including the Operational Risk unit, has no formal entry requirements and is open to all levels. It suits staff working in, or aspiring to work in, the administration and operations areas of financial services.

What topics does the CISI Operational Risk syllabus cover?

The syllabus covers operational risk concepts and frameworks, identifying and assessing operational risk, risk and control self-assessment, key risk indicators, loss data and event management, operational risk in processes, people, systems and external events, and the governance and reporting of operational risk.

How long does it take to prepare for the CISI Operational Risk unit?

Most candidates allow around 80 to 100 hours per IOC unit, often spread over six to ten weeks of part-time study. The exact time depends on prior experience with risk management concepts such as RCSA, KRIs and the three lines of defence.

How many units do I need for the Investment Operations Certificate?

The IOC is achieved by passing three units chosen from CISI's available selection. The Operational Risk unit can count as one of those three, alongside other technical and introductory units relevant to your role.

Can I retake the CISI Operational Risk exam if I fail?

Yes. Candidates who do not reach the 70% pass mark can rebook and resit the computer-based examination under CISI's standard resit terms. Because it is on-demand, a resit can usually be scheduled without waiting for a fixed exam window.