CBA-CRP · Study material
Contents
The complete contents of the CBA Certified Compliance & Risk Professional study material: every chapter and lesson, the reading time of each, and where the assessed workbooks fall. One lesson is open to read in full.
Lessons
101
Reading time
5 hours
Workbooks
19
Words
61,497
These figures are counted from the material itself. The reading time assumes a steady pace and no re-reading, and does not include the time spent building the workbooks.
Free, no account
Read a complete lesson
Emerging risk, from Compliance Risk Assessment, as a candidate reads it, slides included.
Read the lessonContents
6 chapters, 101 lessons. Lessons marked workbook carry a spreadsheet you build and submit, marked against the published tolerance. The award requires 6 of the 19 completed to that tolerance.
Introduction
1 lesson · 3 min
- CBA-CRP Study Guide3 min
01Compliance Risk Assessment
21 lessons · 59 min
- What this chapter covers2 min
- What the assessment is for2 min
- Defining the risk universe, and bounding it6 min
- Mapping: the grid behind the registerworkbook2 min
- Writing a risk statement that can be scored2 min
- Inherent risk, assessed before controls2 min
- Scoring in units, not adjectives3 min
- Why the five by five grid collapses into amber2 min
- Control effectiveness on evidence, not on existence5 min
- Correlated controls, and why residual risk multiplication lies2 min
- Residual risk, and the difference between a risk and an issueworkbook4 min
- Risk appetite that can be breachedworkbook3 min
- Aggregation: the risk nobody scored3 min
- Refresh: triggers, not the calendarworkbook3 min
- Emerging riskFree2 min
- From assessment to monitoring plan3 min
- Operational load is a risk input3 min
- Remediation and the ageing profile2 min
- Governance, ownership and writing down the reasoning2 min
- Common pitfalls3 min
- Chapter summary3 min
02Programme Governance, Policies and Controls
21 lessons · 60 min
- What this chapter covers2 min
- The seven components, and the joints that fail2 min
- Three lines of defence, and what the first line actually owns3 min
- Accountability sits with a named person2 min
- The board, its committees, and what approval means2 min
- The obligation register, and rebuilding the risk input5 min
- Mapping controls to obligations, and finding the obligation with no controlworkbook2 min
- Policy architecture: four documents, four jobs3 min
- Writing a policy somebody can follow and somebody can test2 min
- The policy lifecycle, and the nine orphansworkbook3 min
- Controls: preventive, detective, correctiveworkbook4 min
- Testing what you mapped: monitoring and sampling5 min
- The alert queue: a control that has to be fed3 min
- Training that changes behaviour rather than recording completion3 min
- Records: the evidence that makes everything else provable2 min
- Change management: when the rule moves, or the product does3 min
- Remediation: the queue that tells you whether any of this worksworkbook3 min
- Resourcing: present coverage, not headcount4 min
- Reporting: closing the loop back to governance2 min
- Common pitfalls2 min
- Chapter summary3 min
03Financial Crime and Data Protection Fundamentals
20 lessons · 59 min
- What this chapter covers2 min
- What the exam is actually testing here2 min
- Financial crime as a control system, not a rulebook2 min
- The risk-based approach: more scrutiny where the risk is, and the evidence for both halvesworkbook6 min
- Customer due diligence: the four questions a file has to answer8 min
- Ongoing monitoring and trigger events2 min
- Transaction monitoring: rules, thresholds, alerts and the queue nobody can clear7 min
- Suspicious activity: recognising it, escalating it, and what followsworkbook2 min
- Tipping off and confidentiality2 min
- Politically exposed persons2 min
- Sanctions screening: name matching, false positives, and the cost of a missworkbook3 min
- Data protection principles, and where each one collides with financial crime3 min
- Lawful basis for financial crime processing2 min
- Data subject rights, and which of them are qualified3 min
- Personal data breaches: identification, escalation and notification2 min
- Records that satisfy both regimesworkbook2 min
- Capacity: what nine people can actually cover3 min
- Telling an executive that something cannot be done2 min
- Common pitfalls2 min
- Chapter summary2 min
04Monitoring, Testing and Investigations
21 lessons · 60 min
- What this chapter covers2 min
- Monitoring, testing and audit are three different jobs3 min
- Building the monitoring plan from the risk assessment, not from habit4 min
- Defining the population before you sample it2 min
- Coverage: what nine people can actually testworkbook3 min
- Sampling: why thirty files a month finds nothing systemicworkbook6 min
- Stratified and targeted sampling3 min
- Projecting the error rate and costing the delay2 min
- Continuous monitoring and automated exception reporting4 min
- Designing a test: control, attribute, evidence, pass criterion, sample2 min
- Design effectiveness against operating effectivenessworkbook3 min
- Recording a finding so that somebody can act on it2 min
- Root cause analysis that goes past "human error"2 min
- Rating findings consistently2 min
- Tracking remediation, and the finding that is closed because it is old3 min
- Thematic review2 min
- Investigations: scope, independence and controlworkbook4 min
- Evidence, interviews and privilege in outline2 min
- Whistleblowing and protecting the person who raises the concern3 min
- Common pitfalls3 min
- Chapter summary3 min
05Reporting, Culture and Improvement
17 lessons · 47 min
- What this chapter covers2 min
- What a compliance report is for2 min
- The four things a board needs from compliance6 min
- Writing a conclusion that can be disagreed with3 min
- Is the assurance real4 min
- The decisions only the board can take2 min
- Metrics that mean somethingworkbook5 min
- Escalation thresholds agreed in advanceworkbook2 min
- Regulatory relationships and communication3 min
- Culture: what it is and why a survey will not find it2 min
- The indicators that carry signal2 min
- Tone from the top, and the far more important tone from the middle2 min
- Incentives: the sales target that quietly overrides a policy2 min
- Speak-up arrangements and the zero-complaint channelworkbook3 min
- Continuous improvement: lessons, horizon and the review that asks the awkward question3 min
- Common pitfalls2 min
- Chapter summary2 min
What the material is
The study material is written to the discipline’s domains and learning objectives, chapter by chapter, with worked examples and unscored checks in the lessons and assessed workbooks where the level requires applied work. It does not contain a bank of practice questions matching the examination; the specimen paper shows the style and standard of the examination, with a written rationale for every option.
