All Practice Exams

Free Practice Questions for IAI SP9

Exam-style questions and explanations by OpenExamPrep.

✓ No registration✓ No credit card
100+ Questions
100% Free

Loading practice questions...

Exam Review

Key Facts: IAI SP9 Exam

3h 15m

Exam Duration

IAI examination timetable

₹6,000

Examination Fee

IAI exam fee schedule

50%

Pass Mark

IAI Pass Mark Rule (from November 2025)

7

Syllabus Topics

IAI SP9 syllabus 2026

100

Practice Questions

OpenExamPrep

IAI Subject SP9 Enterprise Risk Management is a Specialist Principles subject of the Institute of Actuaries of India, and its 2026 syllabus is based on the syllabus published by the CERA Global Association (version dated January 2024). The official examination is a closed-book, centre-based online written paper of 3 hours 15 minutes; the entry fee is ₹6,000 for India and SAARC candidates and the pass mark is 50%. The published syllabus weightings run from 10% on the ERM process to 20% on risk management tools and techniques, and this practice set follows those weightings. SP9 is the examination requirement for the Chartered Enterprise Risk Actuary (CERA) credential, which also requires attendance at the CERA seminar. The official paper is a descriptive written examination, so these independent English-language multiple-choice questions are a study aid for the same body of knowledge rather than a simulation of the official format, and they do not replace practice at writing full examination answers.

Sample IAI SP9 Practice Questions

Try these sample questions to review concepts for the IAI SP9 exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which of the following best contrasts traditional siloed risk management with Enterprise Risk Management (ERM)?
A.Traditional risk management focuses on individual risk types in isolation to minimize downside variance, whereas ERM coordinates risks holistically to optimize risk-adjusted enterprise value.
B.Traditional risk management aggregates risks across business units using copulas, whereas ERM delegates risk decisions entirely to decentralized operational managers.
C.Traditional risk management evaluates upside opportunities, whereas ERM focuses exclusively on preventing catastrophic financial insolvency.
D.Traditional risk management eliminates operational and market risk, whereas ERM accepts all financial risks without mitigation to maximize equity return.
Explanation: Traditional siloed (or 'stovepipe') risk management treats risk categories (market, credit, insurance, operational) separately within individual business units, primarily aiming to minimize downside risk or ensure localized compliance. In contrast, ERM provides a centralized, strategic, enterprise-wide framework that assesses aggregate risk exposure, correlation, and interdependencies, enabling leadership to optimize the risk-return trade-off and maximize shareholder value.
2In an effective corporate risk governance architecture, which of the following is the primary responsibility of the Board Risk Committee rather than the Audit Committee?
A.Overseeing the integrity of financial statements and the effectiveness of internal financial reporting controls
B.Approving the group risk appetite framework and monitoring the firm's forward-looking aggregate risk profile against appetite
C.Selecting, appointing, and reviewing the independence and performance of the external statutory auditor
D.Reviewing and approving the annual internal audit charter and internal audit work plan
Explanation: The Board Risk Committee is responsible for forward-looking risk oversight: setting and recommending the Risk Appetite Framework (RAF), approving risk policies, and monitoring current and future aggregate exposures against risk capacity and limits. In contrast, the Audit Committee focuses primarily on retrospective assurance: financial reporting integrity, statutory auditor oversight, and the adequacy of internal accounting and financial reporting controls.
3Under the internationally recognized Three Lines of Defence (3LoD) governance model, which operational responsibility belongs exclusively to the First Line of Defence?
A.Designing and implementing risk management frameworks and enterprise limit policies
B.Providing independent, objective assurance to the Board Audit Committee regarding risk governance effectiveness
C.Day-to-day identification, ownership, and direct mitigation of risks arising from commercial transactions and customer operations
D.Challenging the risk profile and conducting independent second-opinion stress testing on underwriting portfolios
Explanation: The First Line of Defence consists of operational and business unit management. They generate risks, own those risks, and are directly responsible for identifying, assessing, controlling, and mitigating risks within their daily operations. The Second Line (Risk Management and Compliance) establishes frameworks, provides oversight, and challenges the First Line. The Third Line (Internal Audit) provides independent assurance to the Board.
4To ensure objective challenge and organizational independence, how should the Chief Risk Officer (CRO) ideally be positioned within a financial institution's governance hierarchy?
A.Reporting directly and solely to the Chief Investment Officer to ensure alignment with asset return targets
B.Embedded as a subordinate unit under the Chief Underwriting Officer to streamline product pricing decisions
C.Reporting to the Head of Internal Audit to merge second- and third-line supervisory activities into a single department
D.Reporting functionally to the Board Risk Committee and administratively to the Chief Executive Officer, without direct commercial revenue-generating targets
Explanation: Best-practice risk governance requires the CRO to have sufficient stature, authority, and independence from revenue-generating business units. This is achieved via a dual-reporting relationship: functional reporting to the Board Risk Committee (enabling direct, unfiltered access to non-executive directors) and administrative reporting to the CEO. The CRO should not have commercial sales or profit targets that would create conflicts of interest.
5Which of the following definitions correctly describes the relationship between Risk Capacity, Risk Appetite, Risk Tolerance, and Risk Limits?
A.Risk Appetite > Risk Capacity > Risk Limits > Risk Tolerance
B.Risk Capacity is the regulatory capital requirement; Risk Appetite is the economic capital; Risk Tolerance is statutory solvency; Risk Limits apply only to non-financial operational risks.
C.Risk Capacity is the maximum risk an entity can sustain; Risk Appetite is the risk it actively chooses to accept; Risk Tolerance is the acceptable operational variance around appetite; Risk Limits are granular operational constraints.
D.Risk Tolerance is the absolute financial boundary beyond which bankruptcy occurs; Risk Capacity is the target equity return established by executive management.
Explanation: Risk Capacity is the absolute maximum quantum of risk a firm can bear before breaching regulatory solvency or facing insolvency. Risk Appetite is the aggregate amount and type of risk the board strategically decides to take on in pursuit of its business goals. Risk Tolerance represents the acceptable variation or margin of error around the appetite targets. Risk Limits are the operationalized, granular quantitative thresholds allocated to desks, business lines, and asset classes.
6An insurer's Board approves the statement: 'The company maintains a 99.5% probability of remaining solvent over a one-year horizon and will not tolerate a rating downgrade below A- from S&P.' In an ERM framework, this is an example of:
A.A high-level Board Risk Appetite Statement
B.A granular operational risk limit
C.A Key Risk Indicator (KRI) operational trigger
D.An internal audit finding recommendation
Explanation: A Risk Appetite Statement (RAS) articulates in qualitative and high-level quantitative terms the aggregate level and types of risk an institution is willing to accept. Solvency confidence intervals (e.g., 99.5% 1-year survival) and target external credit ratings (e.g., minimum S&P A- rating) are classic expressions of board-level risk appetite.
7Which of the following corporate behaviors is the strongest indicator of a deficient or immature 'risk culture' within an insurance enterprise?
A.Business unit managers actively report 'near-miss' operational incidents to the risk team without fear of disciplinary reprisal.
B.Underwriting guidelines require multi-departmental peer reviews for non-standard, large commercial liability contracts.
C.The Chief Risk Officer possesses explicit veto authority over commercial transactions exceeding defined risk tolerance thresholds.
D.Executive performance bonuses are heavily weighted toward short-term gross premium volume with no ex-post risk adjustments or clawback provisions.
Explanation: A deficient risk culture often stems from misaligned remuneration structures where employees are incentivized on short-term volume or accounting profit without adjusting for the cost of capital, downside risk, or tail exposures, and where clawbacks do not exist. In contrast, reporting near-misses, granting the CRO veto power, and enforcing peer review are hallmarks of a mature, healthy risk culture.
8What is the primary role of the Executive Risk Committee (ERC / ERMC) within an insurer's governance framework?
A.Fulfilling the non-executive statutory oversight duties required under company corporate governance legislation
B.Acting as the senior management operational body that monitors enterprise exposures, approves tactical risk allocations, and implements the Board-approved Risk Appetite Framework
C.Performing independent testing of general IT controls and internal financial reporting workflows
D.Representing the interests of policyholders directly in regulatory tribunals
Explanation: The Executive Risk Committee (ERC) is composed of senior operational executives (CEO, CRO, CFO, Chief Actuary, CIO, Business Unit Heads). Its role is executive and managerial: translating the Board's high-level risk appetite into operational limits, reviewing enterprise risk reports, managing capital allocation, and ensuring risk mitigation across lines of business.
9A life insurer decides to cascade its group-level risk appetite down into business unit limits. Which of the following approaches is most theoretically sound and consistent with an ERM perspective?
A.Allocating risk limits strictly proportional to each business unit's gross revenue, ignoring correlation and volatility
B.Setting standalone Value at Risk limits for each business unit such that the arithmetic sum of standalone limits equals total group economic capital
C.Translating aggregate risk appetite into marginal risk contributions and risk-adjusted return hurdles, accounting for diversification benefits and inter-risk correlations
D.Establishing limits solely based on each business unit's historical maximum accounting loss over the preceding two fiscal years
Explanation: Under an ERM framework, cascading risk appetite requires recognizing diversification benefits and marginal risk contributions. Simply adding standalone VaR limits ignores diversification (as sum of VaRs > diversified VaR for non-comonotonic risks) or leaves capital misallocated. Calculating risk-adjusted contributions and RAROC hurdles aligns business unit behavior with group enterprise value optimization.
10Which of the following scenarios represents a breakdown of the Second Line of Defence under the Three Lines of Defence model?
A.The Chief Risk Officer formally rejects a high-risk commercial real estate loan submitted by the lending department.
B.The Board Risk Committee requests an external independent review of the insurer's economic capital internal model.
C.Internal Audit conducts a full review of the actuarial reserving team's stochastic valuation software.
D.Risk management analysts actively write and execute derivative hedging trades on the market trading desk because the trading unit is understaffed.
Explanation: The Second Line of Defence must maintain objectivity and supervisory challenge over the First Line. If risk management personnel take over operational business activities (such as executing derivative transactions), they assume First Line ownership of risk. They can no longer independently monitor, challenge, or report on trades that they themselves initiated, creating an immediate conflict of interest.

About the IAI SP9 Exam

IAI Subject SP9 Enterprise Risk Management prepares actuarial students to design, implement, and oversee holistic enterprise-wide risk management frameworks, combining rigorous qualitative governance with sophisticated quantitative modeling.

Exam sponsor: Institute of Actuaries of India (IAI). The requirements and fees below concern the certification or admission exam, separate from our free practice resources.

Assessment

3 hour 15 minute closed-book centre-based online written paper; answers are typed into the examination platform's text editor and there is no negative marking.

Time Limit

3 hours 15 minutes

Passing Score

50% of total marks under the IAI Pass Mark Rule applicable from the November 2025 session; marks are rounded up to the next whole number and the final pass mark for each subject is confirmed with the results

Exam / Certification Fees

₹6,000 (INR) for India and SAARC candidates

Exam sponsor website

Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.

Official sources

Our practice resources: topics covered

We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.

15%

ERM Concept and Framework

Key principles and concepts of enterprise risk management, how ERM is applied in an organisation, and how external and regulatory risk frameworks influence an organisation's approach, including governance, risk appetite and risk culture.

10%

ERM Process

The risk management cycle from identification through assessment, response and monitoring, its integration into strategy and business planning, and reporting to governance bodies and supervisors.

10%

Risk Categories and Identification

Market, credit, liquidity, insurance, operational, conduct, strategic, reputational and emerging risks, and the qualitative and quantitative techniques used to identify them.

15%

Risk Modelling and Aggregation of Risks

Modelling of individual risks and their dependence, correlation and copulas, aggregation across risk types and business units, and the limitations of the models used.

15%

Risk Measurement and Assessment

Risk measures and their properties, extreme value theory, scenario and stress testing including reverse stress testing, model risk, validation and backtesting, and parameter uncertainty.

20%

Risk Management Tools and Techniques

Risk response and mitigation, asset-liability techniques, reinsurance and insurance-linked securities, hedging, internal controls, business continuity, and the transfer and financing of risk.

15%

Capital Management

Economic and regulatory capital, capital frameworks and solvency regimes, capital allocation methods and their properties, risk-adjusted performance measurement, and capital fungibility within a group.

Preparing for the IAI SP9 Exam

What You Need to Know

  • Passing score: 50% of total marks under the IAI Pass Mark Rule applicable from the November 2025 session; marks are rounded up to the next whole number and the final pass mark for each subject is confirmed with the results
  • Assessment: 3 hour 15 minute closed-book centre-based online written paper; answers are typed into the examination platform's text editor and there is no negative marking.
  • Time limit: 3 hours 15 minutes
  • Exam / certification fees: ₹6,000 (INR) for India and SAARC candidates Official sources

Using Our Practice Resources

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

IAI SP9: Suggested Study Strategy

1Understand why copulas are needed: linear correlation fails during market crashes when joint tail events occur far more frequently than normal distributions predict.
2Be prepared to prove or explain why VaR can penalise diversification in non-elliptical distributions, whereas TVaR preserves sub-additivity.
3Know the difference between the block maxima approach (GEV) and peaks-over-threshold (GPD) in Extreme Value Theory.
4Understand the Three Lines of Defence model: business units own risks (1st line), risk management oversees (2nd line), and internal audit provides independent assurance (3rd line).
5Practice calculating economic capital and applying Euler's theorem to allocate diversification benefits across subsidiary business units.

Frequently Asked Questions

What is the format of the IAI SP9 exam?

SP9 is a closed-book, centre-based online written paper of 3 hours 15 minutes covering ERM frameworks and governance, the risk management process, risk categories, modelling and aggregation, measurement, mitigation tools and capital management. Answers are typed into the examination platform and there is no negative marking.

What is the pass mark for IAI SP9?

Under the IAI Pass Mark Rule applicable from the November 2025 session, a candidate passes an SP or SA series subject by scoring at least 50%, rounded up to the next whole number. IAI confirms the final pass mark when it publishes the results.

How does SP9 relate to the CERA credential?

SP9 is the examination requirement for the Chartered Enterprise Risk Actuary (CERA) credential. The IAI 2026 SP9 syllabus states that it is based on the syllabus published by the CERA Global Association, version dated January 2024, and that an Associate or Fellow can obtain the credential by passing SP9 (or holding an exemption) and attending the CERA seminar.

How is the SP9 syllabus weighted?

ERM concept and framework 15%, ERM process 10%, risk categories and identification 10%, risk modelling and aggregation of risks 15%, risk measurement and assessment 15%, risk management tools and techniques 20%, and capital management 15%. This practice set follows the same proportions.

How do these OpenExamPrep questions relate to the official exam?

They are independent practice questions covering the SP9 topics, including quantitative items on risk measures, copulas, extreme value theory and capital allocation. The official paper is a descriptive written examination, so this set is a study aid for the same body of knowledge rather than a simulation of the official format. OpenExamPrep is not affiliated with the Institute of Actuaries of India or the CERA Global Association.