RIMS · CRMP-FED
The RIMS-CRMP-FED validates risk management competencies specifically within the United States Federal Government environment, covering enterprise risk management implementation, reporting, and alignment with OMB, GAO, and NIST standards. It is developed in cooperation with the Association for Federal Enterprise Risk Management (AFERM) and builds upon the core RIMS-CRMP credential.
Practice Questions
850
≈ 5 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
SpecialtyLast Updated
Feb 2026
Use this CRMP-FED practice exam to prepare for RIMS-Certified Risk Management Professional—Federal (CRMP-FED) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 850 questions for RIMS CRMP-FED, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Understanding the Federal Government ERM Environment, ERM Implementation in the Federal Government, ERM Reporting in the Federal Government, OMB, GAO, and NIST Standards Alignment, and Federal Stakeholder Engagement and Communication. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The RIMS-Certified Risk Management Professional—Federal (CRMP-FED) is a specialized credential developed by RIMS in cooperation with the Association for Federal Enterprise Risk Management (AFERM) that validates risk management competencies specifically within the United States Federal Government environment. It is the only credential of its kind designed to confirm expertise in enterprise risk management (ERM) as practiced under federal frameworks, including alignment with OMB Circular A-123, OMB Circular A-11 Part 6, GAO standards, and NIST guidance. The RIMS-CRMP holds ANSI National Accreditation Board (ANAB) accreditation under ISO/IEC 17024:2012, making it the only risk management certification in the world with this accredited status.
The CRMP-FED is structured as an add-on to the core RIMS-CRMP credential and cannot be earned independently. Candidates take a single three-hour combined exam that tests both core risk management competencies and federal-government-specific knowledge—covering areas such as ERM implementation within federal agencies, internal controls integration, stakeholder engagement, and ERM reporting requirements. The credential is valid for two years and requires ongoing recertification to maintain.
This certification is designed for risk management professionals working within or directly supporting United States Federal Government agencies who wish to validate their specialized knowledge of federal ERM frameworks and practices. Typical candidates include agency risk officers, enterprise risk managers, internal auditors, compliance officers, and program managers embedded in civilian or defense federal organizations.
The credential is also well-suited for contractors, consultants, and advisors who regularly support federal agencies on ERM implementation, reporting, and governance. RIMS membership is not required to pursue the CRMP-FED, and RIMS-CRMP holders seeking to differentiate themselves in a government-focused career path will find it a natural and recognized next step.
Candidates must first earn or simultaneously qualify for the core RIMS-CRMP credential before sitting for the FED portion of the exam. This means satisfying one of three eligibility pathways: (1) a bachelor's degree or global equivalent in risk management plus one year of full-time risk management work experience; (2) a bachelor's degree or global equivalent in any non-risk management field plus three years of full-time risk management work experience; or (3) six years of full-time risk management experience with no degree requirement. All degrees must be from accredited institutions.
Applicants must submit a formal application with supporting documentation (official transcripts or registrar letters, employment verification), pay the applicable fee, and receive an authorization-to-test email from the RIMS-CRMP Certification Department before scheduling the exam. If a candidate has already passed the core RIMS-CRMP, they need only demonstrate eligibility for and pass the FED portion. The six-month testing window must be honored, or the examination fee is forfeited.
The CRMP-FED is delivered as a single combined, computer-based exam totaling three hours. The full exam consists of 170 items: 100 scored RIMS-CRMP core questions, 20 unscored pretest (pilot) questions embedded in the core section, and 50 scored FED-specific questions answered in a dedicated one-hour block. The exam is available year-round and administered either at a Pearson VUE testing center (in the US, Canada, and internationally) or via remote proctoring through Pearson VUE's OnVUE platform from a candidate's home or office. Candidates choosing remote proctoring must check in 30 minutes before their scheduled start time.
A passing score requires achieving 71% or higher on the overall exam. Results are provided as pass/fail. Candidates who do not pass must reapply within the guidelines set by the RIMS-CRMP Certification Department. The CRMP-FED credential, once earned, is valid for two years, after which recertification is required.
Earning the CRMP-FED signals to federal hiring managers, Inspector General offices, and agency leadership that a professional has validated expertise in the specific risk management frameworks, regulations, and reporting obligations unique to the federal government. It is recognized by the Navy, Army, and Marine Corps COOL programs, making it eligible for military tuition assistance funding and a valued credential for transitioning service members entering federal civilian risk roles. According to RIMS data, full-time risk professionals holding the RIMS-CRMP credential earn approximately $16,000 more annually than non-certified peers—a premium that the specialized CRMP-FED designation is positioned to reinforce within the federal pay and hiring ecosystem.
The credential is relevant to positions such as Agency Risk Officer, Senior Advisor for Enterprise Risk, ERM Program Manager, Internal Controls Officer, and strategic planning roles across civilian and defense agencies. As OMB continues to enforce ERM requirements under Circular A-123 and federal agencies mature their risk programs, demand for credentialed professionals who can demonstrate knowledge of federal-specific standards—rather than general private-sector ERM—continues to grow. The ANAB accreditation under ISO/IEC 17024:2012 adds a layer of independent validation that supports portability and credibility of the credential across agencies.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 5 full-length practice exams.
Preview — answers shown1. Contoso Federal Agency's Performance Improvement Officer is working to integrate ERM with the agency's strategic planning cycle as required by GPRAMA. The officer needs to ensure risk information feeds into multiple planning processes throughout the fiscal year. Which combination of integration activities correctly aligns ERM with federal planning requirements? (Select two!)
Multiple correct answersExplanation
ERM integration with federal planning requires coordinating risk profiles with Strategic Reviews submitted to OMB by June and discussing them in FedSTAT sessions, as well as aligning risk-based resource allocation with budget formulation to provide justification for funding decisions. Under GPRAMA and OMB guidance, risk profiles inform multiple planning processes including strategic reviews, budget formulation, and quarterly performance reviews. Submitting risk profiles exclusively to the Inspector General would bypass the management-driven integration process. Deferring risk integration until the AFR is published defeats the purpose of proactive risk-informed decision making. Risk profiles must be shared broadly with leadership including the Risk Management Council and Senior Management Council, not limited to the CFO alone.
2. Litware Federal Agency is building its cybersecurity risk management program using the NISTIR 8286 series. The agency needs to understand how cybersecurity risk information flows from individual systems to enterprise-level decision-making. Which two documents in the NISTIR 8286 series address the aggregation of cybersecurity risk from system-level registers to the enterprise risk portfolio? (Select two!)
Multiple correct answersExplanation
NISTIR 8286C Rev. 1 specifically addresses the aggregation of cybersecurity risks from system-level to the enterprise risk portfolio, describing how information recorded in cybersecurity risk registers is integrated as part of a holistic approach for governance oversight. NISTIR 8286 Rev. 1 (the foundational document) establishes the relationship between the Cybersecurity Risk Register (CSRR) and Enterprise Risk Register (ERR) and focuses on rolling up risk measures from lower system and organizational levels to the broader enterprise level. NISTIR 8286A focuses on risk identification and estimation. NISTIR 8286B focuses on prioritizing risks and selecting response options. NISTIR 8286D focuses on business impact analysis for individual IT assets.
3. Adatum Federal Agency's Chief Risk Officer is developing the agency's first formal risk appetite statement. The CRO needs to distinguish between risk appetite, risk tolerance, and risk capacity for the agency's leadership team. Which combination correctly describes these three concepts? (Select one!)
Explanation
Risk appetite is the broad-based amount of risk an organization is willing to accept in pursuit of its mission, established by senior leadership to guide strategy selection. Risk tolerance is the acceptable level of variance relative to specific objectives, established at the program or component level and aligned with risk appetite. Risk capacity is the maximum amount of risk an organization can absorb while remaining viable—a resource-based ceiling. These three concepts operate at different levels: risk appetite provides enterprise-level guidance, risk tolerance sets operational-level bounds, and risk capacity defines the absolute limit. They are not interchangeable, nor are they limited to specific risk categories.
4. Contoso Federal Agency is evaluating its internal controls and discovers that a recently implemented automated system for processing travel reimbursements does not verify that receipts exceed the minimum threshold before approving payments. The control was designed correctly in policy documents but was not properly coded in the application. How should this issue be classified? (Select one!)
Explanation
An implementation deficiency occurs when a control is properly designed but not correctly implemented. In this scenario, the policy documents correctly specify the receipt verification requirement, but the automated system's coding does not match the design specifications. This is distinct from a design deficiency, which would mean the control concept itself is missing or improper. An operating deficiency occurs when a properly implemented control fails to operate as designed over time. While this issue could potentially escalate to a material weakness depending on the dollar amounts involved and the frequency of erroneous payments, the classification of the deficiency type itself is an implementation deficiency.
5. Woodgrove Federal Agency is conducting its annual risk profile update. According to OMB Circular A-123, a federal agency's risk profile must contain seven mandatory components. Which two components specifically address risk exposure at different stages of the control process? (Select two!)
Multiple correct answersExplanation
Inherent risk assessment and residual risk assessment are the two components that specifically address risk exposure at different stages of the control process. Inherent risk assessment evaluates impact and likelihood before any controls are applied, establishing a pre-control baseline. Residual risk assessment measures the remaining exposure after management has implemented control activities. Together, these two assessments enable agencies to understand the effectiveness of their controls by comparing the before and after risk levels. Identification of Objectives defines what the agency seeks to achieve rather than measuring exposure. Proposed risk response category classifies planned future actions. Current risk response documents the chosen strategy but does not itself measure exposure levels.
$17.99
One-time access to this exam