CBA Standard · Management
Compliance & Risk Professional
The CBA Standard for Compliance & Risk Professional states what competent practice in the discipline consists of: the domains of the work, their relative weight, and the learning objectives a competent practitioner meets in each.
- Version
- 7.1
- Domains
- 5weighted
- Learning objectives
- 29
- Published
- 2026
1Compliance Risk Assessment
20%2Programme Governance, Policies and Controls
22%3Financial Crime and Data Protection Fundamentals
20%4Monitoring, Testing and Investigations
22%5Reporting, Culture and Improvement
16%
Show as a table
| Domain | Objectives | Weighting |
|---|---|---|
| 1. Compliance Risk Assessment | 6 | 20% |
| 2. Programme Governance, Policies and Controls | 6 | 22% |
| 3. Financial Crime and Data Protection Fundamentals | 6 | 20% |
| 4. Monitoring, Testing and Investigations | 6 | 22% |
| 5. Reporting, Culture and Improvement | 5 | 16% |
Domains and learning objectives
A domain’s weighting is its share of the discipline, and the share of the examination paper drawn from that domain. The study material and the examination questions are written to the objectives.
Domain 1
Compliance Risk Assessment
20%
- 1.1Identify sources of compliance obligation and translate them into an inventory of organisational risks
- 1.2Calculate inherent and residual risk scores using likelihood and impact scales, and justify the scale design
- 1.3Distinguish inherent risk, residual risk, risk appetite and risk tolerance in practical scenarios
- 1.4Prioritise risks for treatment and select an appropriate treatment response (accept, mitigate, transfer, avoid)
- 1.5Evaluate the quality of a risk register entry and identify missing or defective elements
- 1.6Interpret changes in an organisation's risk profile triggered by new products, markets, suppliers or technology
Domain 2
Programme Governance, Policies and Controls
22%
- 2.1Select an appropriate governance structure for a compliance programme given organisational size and risk profile
- 2.2Distinguish the responsibilities of operational management, compliance functions and independent assurance within a layered defence model
- 2.3Evaluate a draft policy against criteria of clarity, scope, ownership, proportionality and enforceability
- 2.4Differentiate preventive, detective and corrective controls and match control types to identified risks
- 2.5Design a training and communication approach that targets the right audiences with the right depth
- 2.6Assess whether a described programme element is proportionate to the organisation's size and risk exposure
Domain 3
Financial Crime and Data Protection Fundamentals
20%
- 3.1Explain the three-stage model of money laundering and identify the stage illustrated by a described transaction pattern
- 3.2Distinguish customer due diligence, enhanced due diligence and ongoing monitoring, and select the appropriate level for a given customer profile
- 3.3Identify red flags for money laundering, bribery and sanctions exposure in workplace scenarios
- 3.4Interpret core data-protection concepts including personal data, lawful processing purposes, data minimisation and retention
- 3.5Select the correct first response when a possible data breach or suspicious activity is discovered
- 3.6Evaluate third-party relationships for financial crime and data-protection risk at a conceptual level
Domain 4
Monitoring, Testing and Investigations
22%
- 4.1Distinguish continuous monitoring, periodic testing and independent review, and select which is appropriate for a given assurance need
- 4.2Design a risk-based monitoring plan including sample selection, frequency and pass criteria
- 4.3Interpret monitoring results to distinguish an isolated error from a control weakness or systemic failure
- 4.4Evaluate alert-based monitoring output, including tuning thresholds and managing false positives, whether rule-based or AI-assisted
- 4.5Select sound practice for the intake, triage and initial handling of a whistleblowing report or suspected breach
- 4.6Apply core investigation principles: preserving evidence, maintaining confidentiality, fairness to subjects and documenting steps
Domain 5
Reporting, Culture and Improvement
16%
- 5.1Select metrics and key risk indicators that give leadership a faithful picture of compliance performance
- 5.2Construct a management report from raw programme data, choosing appropriate structure, emphasis and visualisation
- 5.3Interpret indicators of compliance culture, including speak-up data, and diagnose likely cultural weaknesses from a scenario
- 5.4Distinguish activity metrics from outcome metrics and evaluate a dashboard for balance between them
- 5.5Evaluate lessons-learned and programme review processes and select improvements after an incident or audit finding
Competence at award
What a holder of the CBA-CRP credential has demonstrated, at Professional level.
- Design and populate a compliance risk assessment, scoring likelihood and impact and prioritising risks against a stated risk appetite
- Draft the core elements of a compliance programme: governance structure, policy framework, controls and training aligned to identified risks
- Explain the purpose and typical mechanics of anti-money-laundering and data-protection regimes at a conceptual, jurisdiction-neutral level
- Plan and execute monitoring and testing activity, interpret the results and distinguish control weaknesses from isolated errors
- Triage reports of suspected misconduct and apply sound practice in the opening stages of an internal investigation
- Build management reporting on compliance performance using accessible tools such as Excel or Google Sheets
- Assess the health of an organisation's compliance culture and select realistic interventions to strengthen it
Study material
CBA publishes study material written objective by objective to this standard. Its contents are open to read, and one lesson is published in full.
