Corporate Business Alliance

CBA-CRP · Management · Professional level

CBA Certified Compliance & Risk Professional

Award requires3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee

The CBA Certified Compliance & Risk Professional (CBA-CRP) validates the ability to build and run a complete compliance programme: assessing risk, writing policies and controls, monitoring, handling investigations, and reporting to leadership. Jurisdiction-neutral and concept-focused.

Level
Professional
Domains
5weighted
Questions
75
Time limit
115minutes

The CBA Certified Compliance & Risk Professional (CBA-CRP) certifies the working cycle of a compliance programme: identifying and scoring compliance risks, translating risk appetite into policies and controls, understanding financial crime and data-protection obligations at a conceptual level, running monitoring and testing, handling the early stages of an internal investigation, and reporting findings to leadership. The syllabus is jurisdiction-neutral: it teaches the concepts and structures that recur across legal systems rather than the law of any one country, and it is not legal advice.

The examination is an online assessment built around workplace scenarios: a risk register that needs scoring, a policy with a gap, a transaction pattern that warrants escalation, a whistleblowing report to triage. The techniques in the syllabus can be practised in Excel or Google Sheets, for risk registers, control matrices and simple monitoring dashboards, without specialist software. Where the syllabus covers automated and AI-assisted monitoring, it teaches concepts such as alert tuning, false positives and human review rather than any single vendor's product.

The path to the credential

Awarded on the examination, 6 assessed workbooks of applied work and 3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee, with a signed undertaking to the Code of Professional Conduct.

  1. 01Prepare

    Study to the published standard with CBA’s study material, or prepare in your own way. The examination is the same whichever route you take. Routes to preparation

  2. 02Enrol

    Enrolling for the examination gives a voucher for one sitting, valid for 12 months.

  3. 03Sit the examination

    75 questions in 115 minutes, taken online and drawn to the published domain weightings. The specimen paper

  4. 04Complete the applied work

    6 assessed workbooks, marked against a published tolerance.

  5. 05Evidence your experience

    Declare 3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee, and sign the undertaking to the Code of Professional Conduct. The Code

  6. 06Award

    The credential is awarded at Professional level and entered in the public register, and the holder may use the CBA-CRP designation.

  7. 07Maintain

    Renew every 3 years against evidenced continuing professional development. CPD and renewal

Exam blueprint

Every paper is assembled to these weightings, which are published in full and fixed for the life of the scheme version.

Assessment domains and their percentage weighting of the CBA-CRP exam
Domain

Compliance Risk Assessment20%

  • Identify sources of compliance obligation and translate them into an inventory of organisational risks
  • Calculate inherent and residual risk scores using likelihood and impact scales, and justify the scale design
  • Distinguish inherent risk, residual risk, risk appetite and risk tolerance in practical scenarios
  • Prioritise risks for treatment and select an appropriate treatment response (accept, mitigate, transfer, avoid)
  • Evaluate the quality of a risk register entry and identify missing or defective elements
  • Interpret changes in an organisation's risk profile triggered by new products, markets, suppliers or technology

Programme Governance, Policies and Controls22%

  • Select an appropriate governance structure for a compliance programme given organisational size and risk profile
  • Distinguish the responsibilities of operational management, compliance functions and independent assurance within a layered defence model
  • Evaluate a draft policy against criteria of clarity, scope, ownership, proportionality and enforceability
  • Differentiate preventive, detective and corrective controls and match control types to identified risks
  • Design a training and communication approach that targets the right audiences with the right depth
  • Assess whether a described programme element is proportionate to the organisation's size and risk exposure

Financial Crime and Data Protection Fundamentals20%

  • Explain the three-stage model of money laundering and identify the stage illustrated by a described transaction pattern
  • Distinguish customer due diligence, enhanced due diligence and ongoing monitoring, and select the appropriate level for a given customer profile
  • Identify red flags for money laundering, bribery and sanctions exposure in workplace scenarios
  • Interpret core data-protection concepts including personal data, lawful processing purposes, data minimisation and retention
  • Select the correct first response when a possible data breach or suspicious activity is discovered
  • Evaluate third-party relationships for financial crime and data-protection risk at a conceptual level

Monitoring, Testing and Investigations22%

  • Distinguish continuous monitoring, periodic testing and independent review, and select which is appropriate for a given assurance need
  • Design a risk-based monitoring plan including sample selection, frequency and pass criteria
  • Interpret monitoring results to distinguish an isolated error from a control weakness or systemic failure
  • Evaluate alert-based monitoring output, including tuning thresholds and managing false positives, whether rule-based or AI-assisted
  • Select sound practice for the intake, triage and initial handling of a whistleblowing report or suspected breach
  • Apply core investigation principles: preserving evidence, maintaining confidentiality, fairness to subjects and documenting steps

Reporting, Culture and Improvement16%

  • Select metrics and key risk indicators that give leadership a faithful picture of compliance performance
  • Construct a management report from raw programme data, choosing appropriate structure, emphasis and visualisation
  • Interpret indicators of compliance culture, including speak-up data, and diagnose likely cultural weaknesses from a scenario
  • Distinguish activity metrics from outcome metrics and evaluate a dashboard for balance between them
  • Evaluate lessons-learned and programme review processes and select improvements after an incident or audit finding
Total100%

Specimen examination paper

Twelve examination items, with the answer and a rationale for every option. None of them will appear on a live paper.

Open the specimen paper

The study material

The full contents of the study material: every chapter and lesson, how long each takes, and where the assessed workbooks fall. One complete lesson is free to read, with no account.

Contents of the study material

What you will be able to do

  • Design and populate a compliance risk assessment, scoring likelihood and impact and prioritising risks against a stated risk appetite
  • Draft the core elements of a compliance programme: governance structure, policy framework, controls and training aligned to identified risks
  • Explain the purpose and typical mechanics of anti-money-laundering and data-protection regimes at a conceptual, jurisdiction-neutral level
  • Plan and execute monitoring and testing activity, interpret the results and distinguish control weaknesses from isolated errors
  • Triage reports of suspected misconduct and apply sound practice in the opening stages of an internal investigation
  • Build management reporting on compliance performance using accessible tools such as Excel or Google Sheets
  • Assess the health of an organisation's compliance culture and select realistic interventions to strengthen it

Who this is for

Early-career compliance and risk staff
Analysts, officers and coordinators in compliance, risk, audit or legal support roles who want a structured, recognised foundation covering the whole programme cycle rather than one narrow speciality.
Operations and finance professionals moving into compliance
Professionals in operations, finance, HR or customer onboarding who already apply controls day to day and want to formalise that experience into a dedicated compliance and risk career path.
Managers accountable for compliance in smaller organisations
Owners, general managers and department heads in SMEs, startups and regional firms who carry compliance responsibility without a large specialist team and need to build a proportionate programme themselves.

Other certifications

CBA-AIM

CBA Certified AI-Driven Management Professional

CBA-AIM certifies that a manager can judge what current AI can and cannot do, select and scope viable use cases, lead adoption across a team, redesign workflows around AI assistance, and apply proportionate governance and risk controls at manager level.

View certification
CBA-COM

CBA Certified Operations Manager

Certifies competence in process design, capacity and quality management, lean improvement, performance measurement and the leadership of operational teams and small change projects.

View certification
CBA-CPM

CBA Certified Procurement & Supply Manager

A certification in end-to-end procurement and supply management, covering sourcing strategy, tendering and supplier selection, contract and relationship management, negotiation, inventory and logistics fundamentals, and ethical, sustainable procurement practice.

View certification