RIMS · CRMP-FED
The RIMS-CRMP-FED validates risk management competencies specifically within the United States Federal Government environment, covering enterprise risk management implementation, reporting, and alignment with OMB, GAO, and NIST standards. It is developed in cooperation with the Association for Federal Enterprise Risk Management (AFERM) and builds upon the core RIMS-CRMP credential.
Practice Questions
850
≈ 5 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
SpecialtyLast Updated
Sep 2026
RIMS publishes an official examination blueprint for the FED-specific portion, and the weighting is lopsided in a way many candidates don't expect: Understanding the Federal Government ERM Environment carries 50% of the FED section, ERM Implementation in the Federal Government carries 40%, and ERM Reporting in the Federal Government is just 10%. That first domain covers identifying sources of government oversight and reporting (GAO, OIG, and internal reports), assessing key stakeholders, aligning ERM with internal controls, analyzing federal ERM initiatives against OMB, GAO, and NIST standards, and distinguishing between overlapping federal reporting requirements. The Implementation domain tests coordination with oversight bodies and partners across Federal, State, Local, Tribal, and Territorial lines, engagement with internal and external risk communities of practice, building top-down and bottom-up communication strategies, and aligning resources to an agency's risk appetite. The much smaller Reporting domain covers preparing both internal and external reports to federal requirements. That FED section, though, only sits atop the 120-question core RIMS-CRMP block that makes up the other two-thirds of the combined exam. This 850-question bank is built to match that full split, with the heaviest rep count on environment-and-stakeholder scenarios rather than the smaller reporting domain, so you're not over-drilling the 10% slice at the expense of the 50%.
The RIMS-CRMP-FED isn't a standalone test. It's delivered as one combined, computer-based exam: 120 questions in the first two hours cover the core RIMS-CRMP curriculum (100 scored plus 20 unscored pretest items mixed in without being flagged, so you can't tell which ones don't count), then a dedicated one-hour block adds 50 scored FED-specific questions, for 170 questions and three hours total. You can sit for it at a Pearson VUE test center in the US, Canada, or internationally, or remotely through Pearson's OnVUE proctoring from your own home or office, with a 30-minute check-in required before a remote start to verify your ID and workspace. The exam is offered year-round rather than in fixed testing windows once you're authorized. A passing score of 71% or higher is required across the combined result, which comes back as a simple pass or fail with no domain-by-domain proficiency breakdown published to candidates, unlike some other professional credentials that report per-domain performance.
You cannot earn CRMP-FED independently — it's an add-on that requires passing (or simultaneously qualifying for) the core RIMS-CRMP, through one of three pathways: a risk management degree plus one year of full-time risk management experience, a non-risk-management degree plus three years, or six years of experience with no degree at all, all from accredited institutions. That's the key difference from the base RIMS-CRMP: the general credential validates enterprise risk management competency for any industry, while CRMP-FED requires the same core plus a federal-specific blueprint aimed squarely at agency risk officers, internal auditors, and the consultants and contractors who support them. The combined exam costs $500 for RIMS members and $650 for non-members, both figures including a non-refundable $100 application fee; a failed attempt can be retaken for $400 or $500. The credential runs on a two-year cycle requiring 50 recertification points, at least 35 from continuing education, plus a renewal fee and adherence to RIMS's Code of Ethics. Start with the 30 free questions, then work the full 850-question bank so the federal-specific reporting chains and oversight-body scenarios are second nature before test day.
The RIMS-Certified Risk Management Professional—Federal (RIMS-CRMP-FED) is a specialized add-on credential that RIMS developed in cooperation with the Association for Federal Enterprise Risk Management (AFERM) to validate enterprise risk management (ERM) competency specifically within the U.S. Federal Government environment. It layers a federal-specific content section on top of the core RIMS-CRMP, RIMS's flagship risk management credential, which holds ANSI National Accreditation Board (ANAB) accreditation under ISO/IEC 17024:2012. The FED-specific portion is governed by an official RIMS examination blueprint with three duties-and-tasks domains: Understanding the Federal Government ERM Environment (50%), ERM Implementation in the Federal Government (40%), and ERM Reporting in the Federal Government (10%).
The FED section tests concrete federal tasks: identifying sources of government oversight and reporting such as GAO and OIG output, aligning ERM with internal controls, analyzing agency ERM initiatives against OMB, GAO, and NIST standards, coordinating with stakeholders across Federal, State, Local, Tribal, and Territorial lines, engaging internal and external risk communities of practice, and preparing both internal and external reports to satisfy federal reporting obligations. It cannot be earned on its own — candidates sit one combined exam that tests the core RIMS-CRMP curriculum and the FED-specific curriculum together, and the FED credential is only awarded once both portions are passed.
This certification targets risk management professionals working in or directly supporting United States Federal Government agencies who want to formally validate federal-specific ERM knowledge. Typical candidates include agency risk officers, ERM program managers, internal auditors, compliance and internal-controls staff, and program managers embedded in civilian or defense agencies who deal directly with OMB, GAO, and NIST-aligned reporting requirements.
It also suits contractors, consultants, and advisory-firm staff who regularly support federal agencies on ERM implementation, governance, and reporting, since the exam tests coordination with oversight bodies and cross-government stakeholders that consultants routinely navigate. RIMS membership is not required to apply, though members pay a lower exam fee. Existing RIMS-CRMP holders looking to specialize into a government-focused career path will find CRMP-FED a natural next step rather than a separate certification track.
Because CRMP-FED is an add-on, candidates must meet the core RIMS-CRMP eligibility criteria through one of three pathways: (1) a bachelor's degree or global equivalent in risk management plus one year of full-time risk management work experience; (2) a bachelor's degree or global equivalent in a non-risk-management field plus three years of full-time risk management work experience; or (3) six years of full-time risk management work experience with no degree required. All degrees must come from accredited or globally equivalent institutions, and RIMS defines qualifying experience as occupational work applying frameworks, tools, or solutions that support risk-informed decision-making, including program design, risk financing, executive advising, or leading a risk management practice.
Applicants submit a formal application with supporting documentation (transcripts or registrar letters, employment verification) and pay the combined exam fee before receiving authorization to schedule. Candidates must also agree to uphold the RIMS-CRMP Code of Ethics. There is no separate FED-only application or fee tier; the eligibility review and payment cover the full combined RIMS-CRMP/CRMP-FED exam in one pass.
The RIMS-CRMP-FED is one combined, computer-based exam totaling three hours and 170 questions. The first two hours cover the core RIMS-CRMP curriculum: 120 questions, of which 100 are scored and 20 are unscored pretest items seeded in without being identified to the candidate. A dedicated one-hour block then adds 50 scored FED-specific questions, weighted 50% Understanding the Federal Government ERM Environment, 40% ERM Implementation in the Federal Government, and 10% ERM Reporting in the Federal Government per RIMS's official blueprint. The exam is available year-round at Pearson VUE testing centers in the US, Canada, and internationally, or through Pearson's OnVUE remote-proctoring platform, which requires a 30-minute check-in before the scheduled start.
A combined score of 71% or higher is required to pass; RIMS reports a simple pass/fail result without a public per-domain breakdown. Candidates who do not pass may retake the exam for $400 (members) or $500 (non-members) within RIMS's reapplication guidelines. Once earned, the RIMS-CRMP-FED credential is valid for two years, after which recertification requires 50 points (at least 35 from continuing education activities) plus a renewal fee of $150 for members or $200 for non-members.
Earning RIMS-CRMP-FED signals to federal hiring managers, Inspector General offices, and agency leadership that a candidate has validated expertise in the specific oversight structures, frameworks, and reporting obligations of federal ERM, not just general private-sector risk management. It is recognized by Army COOL, giving transitioning service members and federal employees a credential path tied to tuition-assistance and credentialing-opportunity programs. Because the credential requires passing the ANAB-accredited core RIMS-CRMP first, it also carries that broader risk management program's third-party validation into a government-specific niche.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 5 full-length practice exams.
Preview — answers shown1. Adatum Agency is implementing the NIST Cybersecurity Framework (CSF) 2.0 and needs to understand the newly added core function. Which function was introduced in CSF 2.0 that was not present in version 1.1? (Select one!)
Explanation
The Govern (GV) function is the new addition in NIST Cybersecurity Framework 2.0, addressing risk management strategy, expectations, and policy at the organizational level. CSF 1.1 contained five core functions: Identify, Protect, Detect, Respond, and Recover. The addition of Govern reflects the growing recognition that cybersecurity risk management requires organizational governance, strategy, and policy oversight as a distinct function. Detect, Recover, and Respond were all part of the original CSF 1.1 framework and carried forward into version 2.0.
2. Woodgrove Federal Agency is implementing the NIST Cybersecurity Framework 2.0 to strengthen its cybersecurity posture. The agency's CISO notes that CSF 2.0 introduced a new core function not present in previous versions. Which function was newly added in CSF 2.0? (Select one!)
Explanation
The GOVERN function is the new addition in NIST Cybersecurity Framework 2.0, expanding the framework from five to six core functions. GOVERN addresses risk management strategy, expectations, and policy, establishing the organizational context for cybersecurity risk management decisions. It emphasizes that cybersecurity governance should align with and support broader enterprise governance. Identify was part of the original CSF and focuses on understanding current cybersecurity risks. Protect was part of the original CSF and addresses safeguards including identity management, access control, and data security. Respond was part of the original CSF and covers incident management, analysis, and mitigation.
3. Woodgrove Federal Agency's Chief Information Officer is briefing the Risk Management Council on the NIST Cybersecurity Framework (CSF) 2.0. A council member asks what distinguishes CSF 2.0 from the previous version. Which core function was newly introduced in CSF 2.0? (Select one!)
Explanation
The GOVERN function is the newly introduced core function in NIST Cybersecurity Framework 2.0. It addresses risk management strategy, expectations, and policy at the organizational level, recognizing that governance is foundational to effective cybersecurity risk management. Identify was part of the original CSF 1.0 framework, covering the understanding of current cybersecurity risks. Protect was also in CSF 1.0, covering safeguards such as identity management and access control. Respond was included in the original framework, addressing incident management, analysis, and mitigation.
4. Contoso Federal Agency's charge card program manager needs to submit statistical reports on the agency's purchase, travel, and fleet card usage. According to OMB Circular A-123, Appendix B, within how many days of the fiscal year end must these reports be submitted to GSA? (Select one!)
Explanation
OMB Circular A-123, Appendix B requires agencies to submit statistical reporting on government charge card programs to GSA and the agency's Charge Card Coordinator/Manager (CCCM) within 90 days of the fiscal year end. This includes data on purchase cards, travel cards, fleet cards, and integrated cards as part of the Charge Card Management Plan requirements. The 30-day and 60-day timeframes are too short for the comprehensive statistical reporting required. The 120-day timeframe exceeds the actual requirement established in the appendix.
5. Northwind Federal Agency is developing its Cybersecurity Risk Management program and wants to align with the NIST Cybersecurity Framework (CSF) 2.0. The agency's CISO notes that CSF 2.0 introduced a new core function that was not present in CSF 1.1. Which function was newly added in CSF 2.0? (Select one!)
Explanation
The GOVERN function is the new addition in NIST Cybersecurity Framework 2.0. It establishes and monitors the organization's cybersecurity risk management strategy, expectations, and policy. CSF 1.1 had five functions: Identify, Protect, Detect, Respond, and Recover. The GOVERN function was added to emphasize the importance of organizational governance in managing cybersecurity risk, reflecting the growing recognition that cybersecurity is an enterprise-level concern requiring leadership direction. Detect, Respond, and Recover were all present in the original CSF 1.1 framework.
170 total, delivered as one combined three-hour exam: 120 questions (100 scored core RIMS-CRMP plus 20 unscored pretest items) in the first two hours, then 50 scored FED-specific questions in a dedicated one-hour block.
71% or higher on the combined exam. RIMS reports results as pass or fail without publishing a per-domain breakdown to candidates.
RIMS's published fee is $500 for members and $650 for non-members, both including a non-refundable $100 application fee. A retake costs $400 for members or $500 for non-members. Confirm current pricing on rims.org before applying.
Per RIMS's official examination blueprint: Understanding the Federal Government ERM Environment is 50%, ERM Implementation in the Federal Government is 40%, and ERM Reporting in the Federal Government is 10%.
No. CRMP-FED is an add-on credential — you must pass or simultaneously qualify for the core RIMS-CRMP eligibility and content within the same combined exam sitting; it is not offered as a separate, independent certification.
One of three pathways, all requiring RIMS-CRMP eligibility: a bachelor's degree (or higher) in risk management plus one year of full-time risk management experience; a bachelor's degree in another field plus three years of experience; or six years of full-time risk management experience with no degree required.
$17.99
One-time access to this exam