Corporate Business Alliance

Self-assessment · Management

Compliance & Risk Professional

Rate yourself against each learning objective in the CBA Standard for Compliance & Risk Professional. Your profile builds as you go, domain by domain, weighted as the standard is.

Standard
Version 7.1
Domains
5
Objectives
29to rate
The scale
0
Not yet. This is new to me.
1
Aware. I know what it is, but have not applied it.
2
With guidance. I can apply it with guidance or a reference to hand.
3
Independently. I apply it in my work without guidance.
4
Can guide others. I could teach it, or review someone else’s work on it.
  1. Domain 1Compliance Risk Assessment

    20% of the standard
    1.1Identify sources of compliance obligation and translate them into an inventory of organisational risks
    1.2Calculate inherent and residual risk scores using likelihood and impact scales, and justify the scale design
    1.3Distinguish inherent risk, residual risk, risk appetite and risk tolerance in practical scenarios
    1.4Prioritise risks for treatment and select an appropriate treatment response (accept, mitigate, transfer, avoid)
    1.5Evaluate the quality of a risk register entry and identify missing or defective elements
    1.6Interpret changes in an organisation's risk profile triggered by new products, markets, suppliers or technology
  2. Domain 2Programme Governance, Policies and Controls

    22% of the standard
    2.1Select an appropriate governance structure for a compliance programme given organisational size and risk profile
    2.2Distinguish the responsibilities of operational management, compliance functions and independent assurance within a layered defence model
    2.3Evaluate a draft policy against criteria of clarity, scope, ownership, proportionality and enforceability
    2.4Differentiate preventive, detective and corrective controls and match control types to identified risks
    2.5Design a training and communication approach that targets the right audiences with the right depth
    2.6Assess whether a described programme element is proportionate to the organisation's size and risk exposure
  3. Domain 3Financial Crime and Data Protection Fundamentals

    20% of the standard
    3.1Explain the three-stage model of money laundering and identify the stage illustrated by a described transaction pattern
    3.2Distinguish customer due diligence, enhanced due diligence and ongoing monitoring, and select the appropriate level for a given customer profile
    3.3Identify red flags for money laundering, bribery and sanctions exposure in workplace scenarios
    3.4Interpret core data-protection concepts including personal data, lawful processing purposes, data minimisation and retention
    3.5Select the correct first response when a possible data breach or suspicious activity is discovered
    3.6Evaluate third-party relationships for financial crime and data-protection risk at a conceptual level
  4. Domain 4Monitoring, Testing and Investigations

    22% of the standard
    4.1Distinguish continuous monitoring, periodic testing and independent review, and select which is appropriate for a given assurance need
    4.2Design a risk-based monitoring plan including sample selection, frequency and pass criteria
    4.3Interpret monitoring results to distinguish an isolated error from a control weakness or systemic failure
    4.4Evaluate alert-based monitoring output, including tuning thresholds and managing false positives, whether rule-based or AI-assisted
    4.5Select sound practice for the intake, triage and initial handling of a whistleblowing report or suspected breach
    4.6Apply core investigation principles: preserving evidence, maintaining confidentiality, fairness to subjects and documenting steps
  5. Domain 5Reporting, Culture and Improvement

    16% of the standard
    5.1Select metrics and key risk indicators that give leadership a faithful picture of compliance performance
    5.2Construct a management report from raw programme data, choosing appropriate structure, emphasis and visualisation
    5.3Interpret indicators of compliance culture, including speak-up data, and diagnose likely cultural weaknesses from a scenario
    5.4Distinguish activity metrics from outcome metrics and evaluate a dashboard for balance between them
    5.5Evaluate lessons-learned and programme review processes and select improvements after an incident or audit finding

Developing against the standard