RIMS · RIMS-CRMP
The RIMS-CRMP is the only ANSI-accredited, competency-based risk management credential in the world, validating a professional's ability to analyze organizational models, design risk strategies, and implement risk processes. It demonstrates achievement of risk management knowledge, performance ability, and commitment to ethical standards.
Practice Questions
807
≈ 5 practice exams
Duration
120 minutes
Passing Score
71%
Difficulty
ProfessionalLast Updated
Jun 2026
This RIMS CRMP practice exam helps you review enterprise risk management concepts including risk governance, assessment, analysis, response, communication, monitoring, and integration with strategic decision-making. The questions mirror how the real exam is weighted, with implementing the risk process (32%) and designing organizational risk strategies (26%) carrying the most marks, so your practice time goes where the exam actually rewards it.
Use explanations to connect each scenario to risk appetite, stakeholder communication, controls, and organizational objectives. The certification rewards applied judgment, so repeated practice should focus on why a response supports the broader risk management process. The exam itself is 120 multiple-choice questions (100 scored) in two hours, with a 71% pass mark, so steady accuracy matters more than speed.
The RIMS-Certified Risk Management Professional (RIMS-CRMP) is the world's only ANSI National Accreditation Board (ANAB)-accredited, competency-based risk management credential, holding accreditation under ISO/IEC 17024:2012. Administered by RIMS (the Risk and Insurance Management Society), this certification validates a professional's demonstrated ability to analyze organizational models, design enterprise risk strategies, implement risk processes, build organizational risk competency, and support strategic decision-making. Its ISO/IEC 17024 accreditation means the credential meets rigorous international standards for personnel certification, setting it apart from every other risk management designation worldwide.
The RIMS-CRMP is a performance-based credential that goes beyond knowledge testing to assess a candidate's practical ability to apply risk management concepts within real organizational contexts. The exam spans five domains drawn from a comprehensive job task analysis, covering the full lifecycle of enterprise risk management. With more than 1,300 credential holders across 60 countries, RIMS-CRMP is recognized internationally across industries including financial services, insurance, healthcare, government, and technology.
The RIMS-CRMP is designed for mid-to-senior-level risk management professionals who are actively working in or transitioning into enterprise risk management roles. Ideal candidates include Risk Managers, Chief Risk Officers, Risk Analysts, Compliance Officers, Internal Auditors, and operational managers with significant risk oversight responsibilities. Professionals working in industries with complex risk environments — such as banking, insurance, healthcare, government, and energy — will find this credential particularly relevant.
Candidates who benefit most are those seeking to formalize their risk management expertise, move into leadership positions, or differentiate themselves in a competitive job market. The credential is also pursued by professionals advising boards and executives on risk strategy, as the exam directly tests the skills required to design and champion risk frameworks at the organizational level.
RIMS-CRMP candidates must meet one of two educational and experience pathways: a bachelor's degree or higher in risk management combined with at least one year of full-time professional experience in risk management, or a bachelor's degree or higher in any non-risk management field combined with at least three years of full-time risk management work experience. Relevant internship experience may count toward the required work experience hours. RIMS membership is not required to apply or sit for the exam.
While there are no mandatory preparatory courses, candidates are strongly encouraged to review the official RIMS-CRMP Examination Blueprint (particularly page 9), download the RIMS-CRMP Study Guide, and familiarize themselves with the ten recommended reference materials. These include ISO 31000:2018 (Risk Management — Guidelines), foundational enterprise risk management frameworks, and RIMS Executive Reports on risk committee governance. A working knowledge of ERM principles, organizational strategy, and risk process implementation is assumed.
The RIMS-CRMP exam consists of 120 multiple-choice questions, of which 100 are scored and 20 are unscored pretest questions embedded throughout. Candidates cannot distinguish pretest from scored questions during the exam. The total time allotted is 120 minutes (2 hours), making pacing critical. The exam is delivered as a computer-based test (CBT) and is available year-round either at Pearson VUE testing centers located globally or remotely via the OnVUE online proctoring platform from a candidate's home or office.
Candidates are monitored by a certified proctor via webcam and microphone when testing remotely. Once an application is approved, candidates have a four-month window to schedule and sit for the exam. Results are reported on a pass/fail basis, with a minimum passing score of 71% on the 100 scored questions. Candidates who do not pass may retake the exam upon payment of a retest fee. The resulting credential is valid for two years and requires continuing education for recertification.
According to RIMS, full-time risk professionals who hold the RIMS-CRMP credential earn $16,000 more annually than their non-certified peers, making it one of the most financially impactful credentials in the risk management field. The certification prepares holders for senior roles including Risk Manager, Enterprise Risk Director, Vice President of Risk, and Chief Risk Officer, as well as advisory roles supporting C-suite and board-level risk governance. Industries with the highest demand for RIMS-CRMP holders include financial services, insurance, healthcare, energy, and government.
As the only ISO/IEC 17024-accredited risk management credential in the world, the RIMS-CRMP carries a level of international recognition and credibility that distinguishes it from non-accredited designations such as the PMI-RMP or CRISC, which are scoped to project or IT risk rather than enterprise-wide risk strategy. With a global community of over 1,300 certified professionals across 60 countries, the credential is recognized by multinational employers and government agencies alike, including the U.S. Department of Defense through the Navy COOL program.
5 sample questions with answers and explanations. The full bank has 807 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A company is implementing the NIST Cybersecurity Framework 2.0 released in 2024. Which core function was newly added in version 2.0 that was not present in the previous version? (Select one!)
Explanation
GOVERN is the new sixth core function added in NIST CSF 2.0 released in February 2024. This function addresses cybersecurity risk management strategy, expectations, policy, and oversight at the organizational level. The original NIST CSF 1.0 and 1.1 contained five functions: Identify, Protect, Detect, Respond, and Recover. The addition of GOVERN emphasizes the importance of governance and risk management strategy in cybersecurity programs, aligning with enterprise risk management principles.
2. An organization has completed risk analysis and now needs to evaluate the identified risks. According to the RIMS-CRMP framework, against which criterion should the professional evaluate analyzed risks? (Select one!)
Explanation
According to RIMS-CRMP guidance, once risks have been analyzed, they should be evaluated against the organization's risk appetite. Risk appetite represents the amount and type of risk the organization is willing to accept in pursuit of objectives and serves as the primary reference point for evaluation. Risk capacity is the maximum risk that can be absorbed. Risk tolerance represents acceptable variation around specific objectives. Risk thresholds are specific trigger points within tolerance bands.
3. A risk professional is implementing COSO ERM 2017 and needs to address risks arising from the organization's chosen strategy. Which type of risk is the professional considering? (Select one!)
Explanation
COSO ERM 2017 identifies three types of strategy-related risks: Risk TO strategy refers to risks that could impair execution of the chosen strategy. Risk FROM strategy refers to risks that arise from the chosen strategy itself. Strategy ALIGNMENT risk is the possibility that the strategy does not align with mission, vision, and values. In this scenario, the professional is addressing risks arising from the chosen strategy, which is risk FROM strategy.
4. An airline is implementing NIST Cybersecurity Framework 2.0 under Domain B4 (Design Risk Management Framework) and must structure their cybersecurity governance approach. Which core function was newly added in the CSF 2.0 update released in 2024? (Select one!)
Explanation
GOVERN was added as the sixth core function in NIST CSF 2.0 released in 2024, emphasizing cybersecurity strategy, policy, and oversight at the organizational level. This addition recognizes that effective cybersecurity requires strong governance foundations. The other five functions from CSF 1.1 remain: IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER. IDENTIFY has been part of CSF since the original 2014 version. PROTECT was also in the original framework. RECOVER has been included since the beginning as the final function addressing resilience and restoration capabilities. The addition of GOVERN reflects the evolution of cybersecurity from a technical discipline to an enterprise governance concern.
5. Northwind Retail is implementing the NIST Cybersecurity Framework 2.0 to strengthen its cybersecurity posture. The CISO needs to explain the key change introduced in version 2.0 compared to the original framework. Which function was newly added in NIST CSF 2.0? (Select one!)
Explanation
NIST Cybersecurity Framework 2.0, released in 2024, added the Govern function as a new sixth core function. Govern addresses cybersecurity strategy, policy, and oversight at the organizational level, emphasizing that cybersecurity risk management is a governance concern. The original NIST CSF 1.0/1.1 had five functions: Identify, Protect, Detect, Respond, and Recover. Identify, Protect, and Recover were all part of the original framework and are not new additions.
You qualify with a risk management bachelor degree plus 1 year of experience, a non-risk bachelor degree plus 3 years, or 6 years of risk management experience with no degree. Final-year students can test but are certified only after finishing the degree and gaining 1 year of experience.
It is $375 for RIMS members and $525 for non-members, each including a $100 non-refundable application fee. Student rates are lower.
There are 120 multiple-choice questions (100 scored plus 20 unscored pretest) in a 2-hour computer-based test, taken at a Pearson VUE center or online via OnVUE.
You need 71% or higher. Only the 100 scored questions count toward your result.
Analyzing the organizational model (16%), designing organizational risk strategies (26%), implementing the risk process (32%), developing organizational risk competency (16%), and supporting decision making (10%).
Recertify every 2 years by earning 50 recertification points, 35 of which must be in professional development, and paying $150 for members or $200 for non-members.
No. Membership is not required, but non-members pay a higher exam fee.
It is a vendor-neutral, ANAB/ISO 17024-accredited enterprise risk management credential recognized internationally, which supports its value for ERM career advancement.
$17.99
One-time access to this exam