ABA · CERP
The ABA CERP validates expertise in enterprise risk management for banking professionals, covering risk governance, credit risk, financial risk, and non-financial risk management frameworks. It is designed for experienced risk management practitioners in the U.S. banking industry.
Practice Questions
749
≈ 4 practice exams
Duration
240 minutes
Passing Score
Pass/Fail
Difficulty
ProfessionalLast Updated
Mar 2026
Use this CERP practice exam to prepare for Certified Enterprise Risk Professional (CERP) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 749 questions for ABA CERP, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Risk Governance and Management, Elements of a Risk Management Structure, Credit Risk, Financial Risk, and Non-Financial Risk. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified Enterprise Risk Professional (CERP) is a professional-level certification offered by the American Bankers Association (ABA), designed exclusively for risk management practitioners in the U.S. banking industry. It validates comprehensive expertise across the full spectrum of enterprise risk management, including risk governance, credit risk, financial risk, non-financial risk, and operational risk management frameworks. The designation demonstrates that a holder possesses both the knowledge and applied judgment necessary to manage complex risks across a banking organization.
The CERP is grounded in U.S. banking laws, regulations, and supervisory expectations, making it uniquely relevant for professionals operating within domestic financial institutions. The exam assesses not only theoretical knowledge of risk domains but also the practical application of risk identification, measurement, evaluation, mitigation, and monitoring within real-world banking scenarios. Candidates are expected to demonstrate proficiency across eight content domains that collectively span the enterprise risk management lifecycle.
The CERP is designed for experienced risk management professionals working within U.S. banking institutions. Target roles include Chief Risk Officers, enterprise risk managers, credit risk analysts, operational risk officers, financial risk managers, and compliance officers who have significant risk oversight responsibilities. The certification is appropriate for mid-to-senior level professionals who are either currently managing risk functions or seeking to formalize and advance their enterprise risk expertise.
Given the eligibility requirements, candidates are expected to have substantial hands-on experience in the field—making this credential most suitable for seasoned practitioners rather than early-career professionals. It is particularly valuable for those seeking leadership roles within bank risk departments or those looking to distinguish themselves in a competitive hiring environment.
The ABA specifies experience-based eligibility pathways rather than mandatory formal education requirements. Candidates with a bachelor's degree must have at least five years of experience in the banking industry, of which a minimum of three years must be in a risk management role or a closely related function. Candidates without a degree must have at least seven years of banking industry experience, with at least five years in risk management or a closely related role.
All experience must be U.S.-based, as the CERP is anchored to U.S. banking laws, regulations, and supervisory frameworks. While no specific prior certifications are required, familiarity with ABA training programs and a strong working knowledge of bank regulatory requirements, credit risk analysis, financial risk measurement, and operational risk frameworks is strongly recommended before sitting for the exam.
The CERP exam consists of 200 multiple-choice questions, which may include scenario-based and case-study style questions that test applied knowledge rather than rote recall. Candidates are allotted 240 minutes (four hours) to complete the exam. The exam is delivered through Meazure Learning's testing infrastructure and can be taken either at an authorized U.S. test center or remotely via the ProctorU live remote proctoring (LRP) platform, provided the candidate meets the technical requirements for a remote session.
Scoring is reported on a pass/fail basis. The exam fee is $775 USD. Testing windows are offered multiple times per year, with application deadlines approximately eight weeks prior to the start of each window. Candidates must submit a completed application and satisfy the eligibility requirements before being approved to register for a specific exam window.
Earning the CERP positions banking professionals for senior risk management roles, including enterprise risk officer, Chief Risk Officer, and risk governance leadership positions within commercial banks, community banks, and financial holding companies. The credential signals to employers that the holder meets the ABA's rigorous experience and competency standards for enterprise-level risk oversight—a differentiator in competitive hiring for risk leadership roles regulated under U.S. supervisory frameworks.
As regulatory scrutiny of bank risk management continues to intensify following post-2008 and post-2023 bank failure episodes, demand for credentialed enterprise risk professionals in U.S. banking has grown. The CERP is specifically recognized within the domestic banking sector and complements other risk credentials such as the FRM (Financial Risk Manager) or PRM (Professional Risk Manager), while being uniquely tailored to the operational and regulatory realities of U.S.-chartered financial institutions.
5 sample questions with answers and explanations. The full bank has 749 questions, enough for 4 full-length practice exams.
Preview — answers shown1. Adatum Bank's board risk committee has requested a comprehensive review of the institution's risk governance framework following recent regulatory feedback. The examiners noted that the bank's risk appetite statement lacks proper cascading into operational limits. Which combination of actions should the bank take to address this deficiency? (Select two!)
Multiple correct answersExplanation
A properly functioning Risk Appetite Framework requires board-level qualitative statements that are translated into quantitative risk tolerance thresholds for each business line, creating a clear cascade from strategic appetite to operational limits. Equally important are well-defined escalation protocols that specify actions, responsibilities, and timelines when thresholds are approached or breached, as outlined in the FSB Principles for an Effective Risk Appetite Framework. Allowing business lines to set their own appetite without board alignment undermines the top-down governance structure. Eliminating tolerance thresholds removes the operational mechanism for monitoring adherence to appetite. While consultants may assist, the framework must be owned and driven internally by the board and senior management.
2. Fabrikam Financial's operational risk team is conducting a scenario analysis workshop to assess low-frequency, high-severity events such as a major cyber breach or systemic fraud. The team is concerned about cognitive biases that could compromise the quality of expert judgments. Which two cognitive biases pose the greatest threat to the integrity of operational risk scenario analysis workshops? (Select two!)
Multiple correct answersExplanation
Anchoring bias and groupthink are two of the most significant cognitive biases affecting operational risk scenario analysis workshops. Anchoring occurs when workshop participants fixate on initial estimates or reference points and insufficiently adjust their subsequent judgments, leading to biased loss severity or frequency estimates. Groupthink occurs when the social dynamics of the workshop suppress dissenting views and critical evaluation, resulting in artificially narrow loss distributions that underestimate tail risk. These biases are explicitly recognized in operational risk management literature as key threats to scenario analysis quality. Diversification bias relates to portfolio theory, not scenario workshops. Survivorship bias is more relevant to statistical sampling than expert workshops. Confirmation bias regarding VaR models is a model risk concern, not a scenario analysis issue.
3. Fabrikam Financial's board risk committee is reviewing the institution's risk appetite framework. The committee chair asks the CRO to explain the precise hierarchy among risk capacity, risk appetite, and risk tolerance. Which statement correctly describes the relationship? (Select one!)
Explanation
The correct hierarchy is Capacity > Appetite > Tolerance. Risk capacity represents the maximum risk an organization can absorb before threatening financial viability, regulatory standing, or operational integrity — it is an objective, quantitative outer boundary based on capital, liquidity, and solvency constraints. Risk appetite is the broad, board-level statement of the amount and type of risk the organization willingly pursues or retains to achieve strategic objectives. Risk tolerance is the specific, tactical-level acceptable variation around appetite for particular risks, quantified through KRIs and thresholds. Risk appetite and capacity are distinct concepts and not interchangeable. Risk tolerance is not about regulatory minimums but about operational boundaries within the appetite. Business units do not determine capacity — it is driven by the institution's overall financial and regulatory constraints.
4. Litware Financial's risk committee is evaluating a proposed new lending product that would enter a market segment with elevated default rates but strong risk-adjusted returns. Under the COSO ERM 2017 framework, the committee decides to proceed with the product launch while implementing enhanced monitoring controls. Which combination of risk responses does this decision represent? (Select two!)
Multiple correct answersExplanation
This decision combines two COSO 2017 risk responses. Pursuing the risk reflects the committee's deliberate decision to accept increased risk exposure to capture the strategic opportunity of strong risk-adjusted returns in a new market segment. Reducing the risk reflects the implementation of enhanced monitoring controls to decrease the likelihood or impact of adverse outcomes. Accepting risk without modification would mean no additional controls are implemented, which contradicts the enhanced monitoring requirement. Avoiding the risk would mean declining to enter the market entirely. Sharing the risk through reinsurance is not described in the scenario.
5. Adatum Bank's model risk management team is building a comprehensive model inventory as required under SR 11-7. The chief risk officer wants to ensure the inventory meets all supervisory expectations. Which three elements must be included in the model inventory for each model? (Select three!)
Multiple correct answersExplanation
Under SR 11-7, a comprehensive model inventory must document each model's purpose, ownership, and current validation status to ensure accountability and tracking. Risk tier classification based on materiality, complexity, and usage determines the intensity of validation and oversight applied. The last validation date and outstanding findings enable management to monitor compliance with validation schedules and remediation timelines. Complete source code storage is a development function, not an inventory requirement. Revenue attribution is a business performance metric unrelated to model risk governance. While developer identity may be documented, the inventory requirement focuses on the model's risk profile, validation status, and governance attributes rather than detailed personnel verification records.
Certified Regulatory Compliance Manager (CRCM)
CRCM · 700 questions
Certified Trust and Fiduciary Advisor (CTFA)
CTFA · 699 questions
Certified AML and Fraud Professional (CAFP)
CAFP · 750 questions
Certified Financial Marketing Professional (CFMP)
CFMP · 750 questions
Certified IRA Services Professional (CISP)
CISP · 700 questions
$17.99
One-time access to this exam