RIMS · RIMS-CRMP
The RIMS-CRMP is the only ANSI-accredited, competency-based risk management credential in the world, validating a professional's ability to analyze organizational models, design risk strategies, and implement risk processes. It demonstrates achievement of risk management knowledge, performance ability, and commitment to ethical standards.
Practice Questions
807
≈ 5 practice exams
Duration
120 minutes
Passing Score
71%
Difficulty
ProfessionalLast Updated
Jun 2026
This RIMS CRMP practice exam helps you review enterprise risk management concepts including risk governance, assessment, analysis, response, communication, monitoring, and integration with strategic decision-making. The questions mirror how the real exam is weighted, with implementing the risk process (32%) and designing organizational risk strategies (26%) carrying the most marks, so your practice time goes where the exam actually rewards it.
Use explanations to connect each scenario to risk appetite, stakeholder communication, controls, and organizational objectives. The certification rewards applied judgment, so repeated practice should focus on why a response supports the broader risk management process. The exam itself is 120 multiple-choice questions (100 scored) in two hours, with a 71% pass mark, so steady accuracy matters more than speed.
The RIMS-Certified Risk Management Professional (RIMS-CRMP) is the world's only ANSI National Accreditation Board (ANAB)-accredited, competency-based risk management credential, holding accreditation under ISO/IEC 17024:2012. Administered by RIMS (the Risk and Insurance Management Society), this certification validates a professional's demonstrated ability to analyze organizational models, design enterprise risk strategies, implement risk processes, build organizational risk competency, and support strategic decision-making. Its ISO/IEC 17024 accreditation means the credential meets rigorous international standards for personnel certification, setting it apart from every other risk management designation worldwide.
The RIMS-CRMP is a performance-based credential that goes beyond knowledge testing to assess a candidate's practical ability to apply risk management concepts within real organizational contexts. The exam spans five domains drawn from a comprehensive job task analysis, covering the full lifecycle of enterprise risk management. With more than 1,300 credential holders across 60 countries, RIMS-CRMP is recognized internationally across industries including financial services, insurance, healthcare, government, and technology.
The RIMS-CRMP is designed for mid-to-senior-level risk management professionals who are actively working in or transitioning into enterprise risk management roles. Ideal candidates include Risk Managers, Chief Risk Officers, Risk Analysts, Compliance Officers, Internal Auditors, and operational managers with significant risk oversight responsibilities. Professionals working in industries with complex risk environments — such as banking, insurance, healthcare, government, and energy — will find this credential particularly relevant.
Candidates who benefit most are those seeking to formalize their risk management expertise, move into leadership positions, or differentiate themselves in a competitive job market. The credential is also pursued by professionals advising boards and executives on risk strategy, as the exam directly tests the skills required to design and champion risk frameworks at the organizational level.
RIMS-CRMP candidates must meet one of two educational and experience pathways: a bachelor's degree or higher in risk management combined with at least one year of full-time professional experience in risk management, or a bachelor's degree or higher in any non-risk management field combined with at least three years of full-time risk management work experience. Relevant internship experience may count toward the required work experience hours. RIMS membership is not required to apply or sit for the exam.
While there are no mandatory preparatory courses, candidates are strongly encouraged to review the official RIMS-CRMP Examination Blueprint (particularly page 9), download the RIMS-CRMP Study Guide, and familiarize themselves with the ten recommended reference materials. These include ISO 31000:2018 (Risk Management — Guidelines), foundational enterprise risk management frameworks, and RIMS Executive Reports on risk committee governance. A working knowledge of ERM principles, organizational strategy, and risk process implementation is assumed.
The RIMS-CRMP exam consists of 120 multiple-choice questions, of which 100 are scored and 20 are unscored pretest questions embedded throughout. Candidates cannot distinguish pretest from scored questions during the exam. The total time allotted is 120 minutes (2 hours), making pacing critical. The exam is delivered as a computer-based test (CBT) and is available year-round either at Pearson VUE testing centers located globally or remotely via the OnVUE online proctoring platform from a candidate's home or office.
Candidates are monitored by a certified proctor via webcam and microphone when testing remotely. Once an application is approved, candidates have a four-month window to schedule and sit for the exam. Results are reported on a pass/fail basis, with a minimum passing score of 71% on the 100 scored questions. Candidates who do not pass may retake the exam upon payment of a retest fee. The resulting credential is valid for two years and requires continuing education for recertification.
According to RIMS, full-time risk professionals who hold the RIMS-CRMP credential earn $16,000 more annually than their non-certified peers, making it one of the most financially impactful credentials in the risk management field. The certification prepares holders for senior roles including Risk Manager, Enterprise Risk Director, Vice President of Risk, and Chief Risk Officer, as well as advisory roles supporting C-suite and board-level risk governance. Industries with the highest demand for RIMS-CRMP holders include financial services, insurance, healthcare, energy, and government.
As the only ISO/IEC 17024-accredited risk management credential in the world, the RIMS-CRMP carries a level of international recognition and credibility that distinguishes it from non-accredited designations such as the PMI-RMP or CRISC, which are scoped to project or IT risk rather than enterprise-wide risk strategy. With a global community of over 1,300 certified professionals across 60 countries, the credential is recognized by multinational employers and government agencies alike, including the U.S. Department of Defense through the Navy COOL program.
5 sample questions with answers and explanations. The full bank has 807 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A real estate investment trust is implementing Domain C4 (Evaluate Risk) and must establish risk evaluation criteria aligned with organizational risk appetite. According to ISO 31000:2018, what is the relationship between risk criteria and risk appetite? (Select one!)
Explanation
ISO 31000:2018 uses the term risk criteria to refer to the terms of reference against which the significance of risk is evaluated. Risk appetite, defined in ISO Guide 73 and ISO 31073 as the amount and type of risk an organization is willing to pursue or retain, is a related but distinct concept. Risk criteria provide the measurement framework for evaluation, while risk appetite expresses the organization's willingness to take risk. They are not identical or interchangeable terms—criteria are evaluative standards while appetite is a strategic position. Risk appetite applies broadly across all risk categories, not just financial risks. ISO 31000 does not replace risk appetite but rather uses risk criteria as a complementary concept in the risk evaluation process.
2. A manufacturing organization is implementing ISO 31000:2018 and needs to establish the context for its risk management process. The risk professional is gathering information about governance structure, strategic objectives, organizational culture, capabilities, resources, policies, and information systems. Which type of context is the professional establishing? (Select one!)
Explanation
Internal context encompasses governance structure, strategic objectives, organizational culture, capabilities, resources, policies, and information systems. Establishing internal context helps the organization understand its risk management environment from within. External context includes political, legal, regulatory, economic, competitive, social, cultural, technological, and natural environment factors. Risk criteria are the terms of reference for evaluating risk significance, not a context category. Regulatory context is a component of external context, not a separate category.
3. Fabrikam Technology is developing a risk strategy approach under Domain B2. The CEO has asked the risk manager to explain the difference between a top-down and bottom-up approach to risk management and recommend which approach the organization should adopt. What should the risk manager recommend? (Select one!)
Explanation
An integrated approach combining top-down and bottom-up risk identification is recommended because it captures risks at all organizational levels. Top-down identification ensures strategic, emerging, and enterprise-level risks are captured through the perspective of senior leadership who understand the broader business context. Bottom-up identification ensures operational, process-level, and emerging frontline risks are captured by those closest to daily operations. Connecting these through a consistent framework enables portfolio-level risk aggregation and prioritization. A purely top-down approach misses operational risks that are only visible at the frontline. A purely bottom-up approach may fail to identify strategic and systemic risks. Outsourcing risk identification entirely eliminates the organizational learning and risk culture development that are essential to sustainable risk management.
4. Tailspin Consulting is advising a client on the NIST Cybersecurity Framework 2.0 and needs to explain the key changes from the previous version. The client specifically wants to know about the new function added in version 2.0. Which function was added in NIST CSF 2.0, and what is its primary purpose? (Select one!)
Explanation
Govern is the new function added in NIST Cybersecurity Framework 2.0, bringing the total from five functions to six. The Govern function establishes the organizational context for cybersecurity risk management, including strategy, policy, roles and responsibilities, and oversight mechanisms. It reflects the growing recognition that effective cybersecurity requires governance-level engagement, not just technical controls. Detect was part of the original NIST CSF 1.0 framework and focuses on identifying cybersecurity events through continuous monitoring. Recover was also in the original framework, addressing restoration of services after incidents. Respond was included in the initial version covering incident response activities. The six functions in NIST CSF 2.0 are: Govern, Identify, Protect, Detect, Respond, and Recover.
5. Northwind Technologies has experienced a data center outage and is activating its business continuity plan. The organization has determined that the Maximum Tolerable Downtime for its core trading platform is 8 hours, and the Work Recovery Time required to verify data integrity and restore full functionality is 3 hours. What is the maximum Recovery Time Objective that the IT team can target while still meeting the MTD requirement? (Select one!)
Explanation
The critical formula for business continuity metrics is MTD = RTO + WRT, which means RTO = MTD - WRT. With an MTD of 8 hours and WRT of 3 hours, the maximum RTO is 8 - 3 = 5 hours. The RTO must always be less than the MTD because work recovery activities still need to occur after system restoration before full functionality is achieved. Setting RTO equal to MTD at 8 hours would leave no time for work recovery activities, causing the organization to exceed its Maximum Tolerable Downtime. Setting RTO equal to WRT at 3 hours would be unnecessarily aggressive and potentially costly, though it would meet the requirement. Adding MTD plus WRT (11 hours) misapplies the formula and would far exceed the maximum tolerable period.
You qualify with a risk management bachelor degree plus 1 year of experience, a non-risk bachelor degree plus 3 years, or 6 years of risk management experience with no degree. Final-year students can test but are certified only after finishing the degree and gaining 1 year of experience.
It is $375 for RIMS members and $525 for non-members, each including a $100 non-refundable application fee. Student rates are lower.
There are 120 multiple-choice questions (100 scored plus 20 unscored pretest) in a 2-hour computer-based test, taken at a Pearson VUE center or online via OnVUE.
You need 71% or higher. Only the 100 scored questions count toward your result.
Analyzing the organizational model (16%), designing organizational risk strategies (26%), implementing the risk process (32%), developing organizational risk competency (16%), and supporting decision making (10%).
Recertify every 2 years by earning 50 recertification points, 35 of which must be in professional development, and paying $150 for members or $200 for non-members.
No. Membership is not required, but non-members pay a higher exam fee.
It is a vendor-neutral, ANAB/ISO 17024-accredited enterprise risk management credential recognized internationally, which supports its value for ERM career advancement.
$17.99
One-time access to this exam