ABA · CERP
The ABA CERP validates expertise in enterprise risk management for banking professionals, covering risk governance, credit risk, financial risk, and non-financial risk management frameworks. It is designed for experienced risk management practitioners in the U.S. banking industry.
Practice Questions
749
≈ 4 practice exams
Duration
240 minutes
Passing Score
500/800
Difficulty
ProfessionalLast Updated
Oct 2026
The 2026 CERP outline covers board and senior-management oversight (8%), policies, procedures, and limits (12%), management information systems (11%), the control framework (7%), risk identification (15%), risk measurement and evaluation (13%), risk response (18%), and risk monitoring (16%). The emphasis is enterprise risk management in U.S. banking, not a generic risk-management syllabus.
CERP contains 200 multiple-choice questions in four hours, including a small number of unscored items. ABA reports scores from 200 to 800 and requires 500 to pass. Candidates also need qualifying U.S.-based banking experience: either a bachelor's degree plus five years in banking with three years in enterprise risk, or seven years in banking with five years in enterprise risk.
Use these 749 questions to rehearse how governance, appetite, limits, data, controls, measurement, response, and monitoring connect. Study at board, business-line, and independent-risk-function levels, because many plausible answers describe a useful activity while only one assigns it to the right owner at the right point in the risk-management cycle.
The ABA Certified Enterprise Risk Professional (CERP) validates enterprise risk management in the U.S. banking industry. The 2026 outline follows the full risk cycle from governance, policies, information, and controls through identification, measurement, response, and monitoring.
Its eight weighted domains are Board and Senior Management Oversight 8%, Policies, Procedures, and Limits 12%, Management Information Systems 11%, Control Framework 7%, Risk Identification 15%, Risk Measurement and Evaluation 13%, Risk Responses 18%, and Risk Monitoring 16%.
The CERP is designed for experienced risk management professionals working within U.S. banking institutions. Target roles include Chief Risk Officers, enterprise risk managers, credit risk analysts, operational risk officers, financial risk managers, and compliance officers who have significant risk oversight responsibilities. The certification is appropriate for mid-to-senior level professionals who are either currently managing risk functions or seeking to formalize and advance their enterprise risk expertise.
Given the eligibility requirements, candidates are expected to have substantial hands-on experience in the field—making this credential most suitable for seasoned practitioners rather than early-career professionals. It is particularly valuable for those seeking leadership roles within bank risk departments or those looking to distinguish themselves in a competitive hiring environment.
The ABA specifies experience-based eligibility pathways rather than mandatory formal education requirements. Candidates with a bachelor's degree must have at least five years of experience in the banking industry, of which a minimum of three years must be in a risk management role or a closely related function. Candidates without a degree must have at least seven years of banking industry experience, with at least five years in risk management or a closely related role.
All experience must be U.S.-based, as the CERP is anchored to U.S. banking laws, regulations, and supervisory frameworks. While no specific prior certifications are required, familiarity with ABA training programs and a strong working knowledge of bank regulatory requirements, credit risk analysis, financial risk measurement, and operational risk frameworks is strongly recommended before sitting for the exam.
CERP contains 200 multiple-choice questions and allows four hours. ABA says a small number of unscored questions are included. Results use a 200-800 scaled score, with 500 required to pass.
The exam is offered during published 30-day testing windows at approved sites or by live remote proctoring. After an unsuccessful attempt, ABA requires a 90-day wait, and candidates must pass within three years of their first attempt.
CERP demonstrates enterprise-risk knowledge tailored to U.S. banking, including the connections among board oversight, risk appetite, policies, data, controls, measurement, response, and monitoring. It is relevant to enterprise risk, operational risk, governance, controls, and risk-leadership roles in banks and related institutions.
Maintaining the credential requires 60 continuing-education credits during each three-year cycle, the annual renewal fee, and continued adherence to ABA's professional ethics requirements.
5 sample questions with answers and explanations. The full bank has 749 questions, enough for 4 full-length practice exams.
Preview — answers shown1. Fabrikam Financial's capital planning team is calculating the institution's effective minimum CET1 requirement. The bank is designated as a G-SIB with a surcharge of 2.5% and has a Stress Capital Buffer of 3.0%. What is the bank's effective minimum CET1 requirement? (Select one!)
Explanation
The effective minimum CET1 requirement is calculated by summing the Basel III minimum CET1 of 4.5%, plus the Stress Capital Buffer, plus the G-SIB surcharge. For this bank: 4.5% (CET1 minimum) + 3.0% (SCB, which replaces the fixed 2.5% Capital Conservation Buffer for large banks) + 2.5% (G-SIB surcharge) = 10.0%. The SCB is the greater of the peak-to-trough CET1 decline under the severely adverse scenario plus four quarters of planned dividends, or a floor of 2.5%. In this case, the SCB of 3.0% exceeds the 2.5% floor. If the bank's CET1 ratio falls below this 10.0% effective minimum, automatic restrictions on capital distributions (dividends and share buybacks) are triggered.
2. Litware Bank's risk management team is implementing the NIST Cybersecurity Framework 2.0, released in 2024, as part of its updated cybersecurity risk management program. Which core function was newly added in NIST CSF 2.0 that was not present in the original framework? (Select one!)
Explanation
NIST Cybersecurity Framework 2.0, released in 2024, added Govern as a new sixth core function. The original NIST CSF included five core functions: Identify, Protect, Detect, Respond, and Recover. The Govern function addresses the organizational context, risk management strategy, and cybersecurity supply chain risk management at a governance level. Detect, Respond, and Recover were all part of the original framework. The addition of Govern reflects the growing recognition that cybersecurity requires organizational governance integration, not just technical controls.
3. Fabrikam Bank's IT risk team is transitioning from the FFIEC Cybersecurity Assessment Tool to the NIST Cybersecurity Framework 2.0 following the CAT sunset. Which core function was newly added in NIST CSF 2.0 that was not present in the original five-function framework? (Select one!)
Explanation
NIST Cybersecurity Framework 2.0, released in 2024, added Govern as a sixth core function. The original five functions were Identify, Protect, Detect, Respond, and Recover. The Govern function addresses organizational context, risk management strategy, cybersecurity supply chain risk management, roles and responsibilities, and policy. Detect, Recover, and Respond were all part of the original NIST CSF version 1.0/1.1 and were not new additions in version 2.0.
4. Contoso Bank's credit risk team is calculating the expected loss for a $25 million commercial real estate loan. The borrower has a probability of default of 3%, and the senior secured loan has a loss given default of 35%. What is the expected loss for this exposure? (Select one!)
Explanation
Expected Loss is calculated as PD x LGD x EAD. For this loan: 0.03 x 0.35 x $25,000,000 = $262,500. The formula EL = PD x LGD x EAD is the foundational credit risk calculation. The other amounts result from common calculation errors: $87,500 incorrectly uses only PD x EAD without LGD adjustment, $750,000 uses an incorrect 3% applied to the full exposure, and $875,000 results from multiplying LGD x EAD without applying the probability of default.
5. Tailspin Bank's risk management committee is evaluating the institution's Non-Maturity Deposit modeling approach for interest rate risk measurement. Under BCBS guidance on IRRBB, what is the maximum behavioral repricing maturity that can be assigned to non-maturity deposits? (Select one!)
Explanation
The Basel Committee on Banking Supervision caps the maximum behavioral repricing maturity for non-maturity deposits at 5 years for IRRBB measurement purposes. Non-maturity deposits have no contractual maturity, requiring banks to model behavioral assumptions for the core (stable) versus volatile portions and the rate at which deposit rates pass through market rate changes. The 5-year cap prevents banks from assigning excessively long repricing maturities to these deposits, which would artificially reduce measured duration gap and understate interest rate risk. This constraint ensures conservatism in EVE calculations and prevents manipulation of behavioral assumptions.
The CERP exam has 200 multiple-choice questions, including a small number of unscored items, and allows four hours.
ABA reports scores on a 200-800 scale and requires 500 to pass.
Risk Responses is 18%, Risk Monitoring 16%, Risk Identification 15%, and Risk Measurement and Evaluation 13%; the remaining four domains total 38%.
ABA requires U.S.-based banking experience: a bachelor's plus five years in banking with three in enterprise risk, or seven years in banking with five in enterprise risk.
ABA requires a 90-day wait after an unsuccessful attempt, and candidates must pass within three years of the first attempt.
CERP holders must complete 60 continuing-education credits in each three-year cycle, pay the annual renewal fee, and follow ABA's ethics requirements.
Certified Financial Marketing Professional (CFMP)
CFMP · 750 questions
Certified Regulatory Compliance Manager (CRCM)
CRCM · 700 questions
Certified Trust and Fiduciary Advisor (CTFA)
CTFA · 699 questions
Certified AML and Fraud Professional (CAFP)
CAFP · 750 questions
Certified IRA Services Professional (CISP)
CISP · 700 questions
$17.99
One-time access to this exam