Corporate Business Alliance

CBA-CRP · Study material

Contents

The complete contents of the CBA Certified Compliance & Risk Professional study material: every chapter and lesson, the reading time of each, and where the assessed workbooks fall. One lesson is open to read in full.

Lessons

101

Reading time

5 hours

Workbooks

19

Words

61,497

These figures are counted from the material itself. The reading time assumes a steady pace and no re-reading, and does not include the time spent building the workbooks.

Free, no account

Read a complete lesson

Emerging risk, from Compliance Risk Assessment, as a candidate reads it, slides included.

Read the lesson

Contents

6 chapters, 101 lessons. Lessons marked workbook carry a spreadsheet you build and submit, marked against the published tolerance. The award requires 6 of the 19 completed to that tolerance.

Introduction

1 lesson · 3 min

  1. CBA-CRP Study Guide3 min

01Compliance Risk Assessment

21 lessons · 59 min

  1. What this chapter covers2 min
  2. What the assessment is for2 min
  3. Defining the risk universe, and bounding it6 min
  4. Mapping: the grid behind the registerworkbook2 min
  5. Writing a risk statement that can be scored2 min
  6. Inherent risk, assessed before controls2 min
  7. Scoring in units, not adjectives3 min
  8. Why the five by five grid collapses into amber2 min
  9. Control effectiveness on evidence, not on existence5 min
  10. Correlated controls, and why residual risk multiplication lies2 min
  11. Residual risk, and the difference between a risk and an issueworkbook4 min
  12. Risk appetite that can be breachedworkbook3 min
  13. Aggregation: the risk nobody scored3 min
  14. Refresh: triggers, not the calendarworkbook3 min
  15. Emerging riskFree2 min
  16. From assessment to monitoring plan3 min
  17. Operational load is a risk input3 min
  18. Remediation and the ageing profile2 min
  19. Governance, ownership and writing down the reasoning2 min
  20. Common pitfalls3 min
  21. Chapter summary3 min

02Programme Governance, Policies and Controls

21 lessons · 60 min

  1. What this chapter covers2 min
  2. The seven components, and the joints that fail2 min
  3. Three lines of defence, and what the first line actually owns3 min
  4. Accountability sits with a named person2 min
  5. The board, its committees, and what approval means2 min
  6. The obligation register, and rebuilding the risk input5 min
  7. Mapping controls to obligations, and finding the obligation with no controlworkbook2 min
  8. Policy architecture: four documents, four jobs3 min
  9. Writing a policy somebody can follow and somebody can test2 min
  10. The policy lifecycle, and the nine orphansworkbook3 min
  11. Controls: preventive, detective, correctiveworkbook4 min
  12. Testing what you mapped: monitoring and sampling5 min
  13. The alert queue: a control that has to be fed3 min
  14. Training that changes behaviour rather than recording completion3 min
  15. Records: the evidence that makes everything else provable2 min
  16. Change management: when the rule moves, or the product does3 min
  17. Remediation: the queue that tells you whether any of this worksworkbook3 min
  18. Resourcing: present coverage, not headcount4 min
  19. Reporting: closing the loop back to governance2 min
  20. Common pitfalls2 min
  21. Chapter summary3 min

03Financial Crime and Data Protection Fundamentals

20 lessons · 59 min

  1. What this chapter covers2 min
  2. What the exam is actually testing here2 min
  3. Financial crime as a control system, not a rulebook2 min
  4. The risk-based approach: more scrutiny where the risk is, and the evidence for both halvesworkbook6 min
  5. Customer due diligence: the four questions a file has to answer8 min
  6. Ongoing monitoring and trigger events2 min
  7. Transaction monitoring: rules, thresholds, alerts and the queue nobody can clear7 min
  8. Suspicious activity: recognising it, escalating it, and what followsworkbook2 min
  9. Tipping off and confidentiality2 min
  10. Politically exposed persons2 min
  11. Sanctions screening: name matching, false positives, and the cost of a missworkbook3 min
  12. Data protection principles, and where each one collides with financial crime3 min
  13. Lawful basis for financial crime processing2 min
  14. Data subject rights, and which of them are qualified3 min
  15. Personal data breaches: identification, escalation and notification2 min
  16. Records that satisfy both regimesworkbook2 min
  17. Capacity: what nine people can actually cover3 min
  18. Telling an executive that something cannot be done2 min
  19. Common pitfalls2 min
  20. Chapter summary2 min

04Monitoring, Testing and Investigations

21 lessons · 60 min

  1. What this chapter covers2 min
  2. Monitoring, testing and audit are three different jobs3 min
  3. Building the monitoring plan from the risk assessment, not from habit4 min
  4. Defining the population before you sample it2 min
  5. Coverage: what nine people can actually testworkbook3 min
  6. Sampling: why thirty files a month finds nothing systemicworkbook6 min
  7. Stratified and targeted sampling3 min
  8. Projecting the error rate and costing the delay2 min
  9. Continuous monitoring and automated exception reporting4 min
  10. Designing a test: control, attribute, evidence, pass criterion, sample2 min
  11. Design effectiveness against operating effectivenessworkbook3 min
  12. Recording a finding so that somebody can act on it2 min
  13. Root cause analysis that goes past "human error"2 min
  14. Rating findings consistently2 min
  15. Tracking remediation, and the finding that is closed because it is old3 min
  16. Thematic review2 min
  17. Investigations: scope, independence and controlworkbook4 min
  18. Evidence, interviews and privilege in outline2 min
  19. Whistleblowing and protecting the person who raises the concern3 min
  20. Common pitfalls3 min
  21. Chapter summary3 min

05Reporting, Culture and Improvement

17 lessons · 47 min

  1. What this chapter covers2 min
  2. What a compliance report is for2 min
  3. The four things a board needs from compliance6 min
  4. Writing a conclusion that can be disagreed with3 min
  5. Is the assurance real4 min
  6. The decisions only the board can take2 min
  7. Metrics that mean somethingworkbook5 min
  8. Escalation thresholds agreed in advanceworkbook2 min
  9. Regulatory relationships and communication3 min
  10. Culture: what it is and why a survey will not find it2 min
  11. The indicators that carry signal2 min
  12. Tone from the top, and the far more important tone from the middle2 min
  13. Incentives: the sales target that quietly overrides a policy2 min
  14. Speak-up arrangements and the zero-complaint channelworkbook3 min
  15. Continuous improvement: lessons, horizon and the review that asks the awkward question3 min
  16. Common pitfalls2 min
  17. Chapter summary2 min

What the material is

The study material is written to the discipline’s domains and learning objectives, chapter by chapter, with worked examples and unscored checks in the lessons and assessed workbooks where the level requires applied work. It does not contain a bank of practice questions matching the examination; the specimen paper shows the style and standard of the examination, with a written rationale for every option.