RIMS · CRMP-FED
The RIMS-CRMP-FED validates risk management competencies specifically within the United States Federal Government environment, covering enterprise risk management implementation, reporting, and alignment with OMB, GAO, and NIST standards. It is developed in cooperation with the Association for Federal Enterprise Risk Management (AFERM) and builds upon the core RIMS-CRMP credential.
Practice Questions
850
≈ 5 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
SpecialtyLast Updated
Feb 2026
Use this CRMP-FED practice exam to prepare for RIMS-Certified Risk Management Professional—Federal (CRMP-FED) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 850 questions for RIMS CRMP-FED, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Understanding the Federal Government ERM Environment, ERM Implementation in the Federal Government, ERM Reporting in the Federal Government, OMB, GAO, and NIST Standards Alignment, and Federal Stakeholder Engagement and Communication. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The RIMS-Certified Risk Management Professional—Federal (CRMP-FED) is a specialized credential developed by RIMS in cooperation with the Association for Federal Enterprise Risk Management (AFERM) that validates risk management competencies specifically within the United States Federal Government environment. It is the only credential of its kind designed to confirm expertise in enterprise risk management (ERM) as practiced under federal frameworks, including alignment with OMB Circular A-123, OMB Circular A-11 Part 6, GAO standards, and NIST guidance. The RIMS-CRMP holds ANSI National Accreditation Board (ANAB) accreditation under ISO/IEC 17024:2012, making it the only risk management certification in the world with this accredited status.
The CRMP-FED is structured as an add-on to the core RIMS-CRMP credential and cannot be earned independently. Candidates take a single three-hour combined exam that tests both core risk management competencies and federal-government-specific knowledge—covering areas such as ERM implementation within federal agencies, internal controls integration, stakeholder engagement, and ERM reporting requirements. The credential is valid for two years and requires ongoing recertification to maintain.
This certification is designed for risk management professionals working within or directly supporting United States Federal Government agencies who wish to validate their specialized knowledge of federal ERM frameworks and practices. Typical candidates include agency risk officers, enterprise risk managers, internal auditors, compliance officers, and program managers embedded in civilian or defense federal organizations.
The credential is also well-suited for contractors, consultants, and advisors who regularly support federal agencies on ERM implementation, reporting, and governance. RIMS membership is not required to pursue the CRMP-FED, and RIMS-CRMP holders seeking to differentiate themselves in a government-focused career path will find it a natural and recognized next step.
Candidates must first earn or simultaneously qualify for the core RIMS-CRMP credential before sitting for the FED portion of the exam. This means satisfying one of three eligibility pathways: (1) a bachelor's degree or global equivalent in risk management plus one year of full-time risk management work experience; (2) a bachelor's degree or global equivalent in any non-risk management field plus three years of full-time risk management work experience; or (3) six years of full-time risk management experience with no degree requirement. All degrees must be from accredited institutions.
Applicants must submit a formal application with supporting documentation (official transcripts or registrar letters, employment verification), pay the applicable fee, and receive an authorization-to-test email from the RIMS-CRMP Certification Department before scheduling the exam. If a candidate has already passed the core RIMS-CRMP, they need only demonstrate eligibility for and pass the FED portion. The six-month testing window must be honored, or the examination fee is forfeited.
The CRMP-FED is delivered as a single combined, computer-based exam totaling three hours. The full exam consists of 170 items: 100 scored RIMS-CRMP core questions, 20 unscored pretest (pilot) questions embedded in the core section, and 50 scored FED-specific questions answered in a dedicated one-hour block. The exam is available year-round and administered either at a Pearson VUE testing center (in the US, Canada, and internationally) or via remote proctoring through Pearson VUE's OnVUE platform from a candidate's home or office. Candidates choosing remote proctoring must check in 30 minutes before their scheduled start time.
A passing score requires achieving 71% or higher on the overall exam. Results are provided as pass/fail. Candidates who do not pass must reapply within the guidelines set by the RIMS-CRMP Certification Department. The CRMP-FED credential, once earned, is valid for two years, after which recertification is required.
Earning the CRMP-FED signals to federal hiring managers, Inspector General offices, and agency leadership that a professional has validated expertise in the specific risk management frameworks, regulations, and reporting obligations unique to the federal government. It is recognized by the Navy, Army, and Marine Corps COOL programs, making it eligible for military tuition assistance funding and a valued credential for transitioning service members entering federal civilian risk roles. According to RIMS data, full-time risk professionals holding the RIMS-CRMP credential earn approximately $16,000 more annually than non-certified peers—a premium that the specialized CRMP-FED designation is positioned to reinforce within the federal pay and hiring ecosystem.
The credential is relevant to positions such as Agency Risk Officer, Senior Advisor for Enterprise Risk, ERM Program Manager, Internal Controls Officer, and strategic planning roles across civilian and defense agencies. As OMB continues to enforce ERM requirements under Circular A-123 and federal agencies mature their risk programs, demand for credentialed professionals who can demonstrate knowledge of federal-specific standards—rather than general private-sector ERM—continues to grow. The ANAB accreditation under ISO/IEC 17024:2012 adds a layer of independent validation that supports portability and credibility of the credential across agencies.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 5 full-length practice exams.
Preview — answers shown1. Northwind Federal Agency's Information Security team is implementing general controls for its financial management information system. The CISO needs to ensure that general controls cover all required areas as specified in the GAO Green Book. Which combination of areas must general controls address for information systems? (Select two!)
Multiple correct answersExplanation
The GAO Green Book specifies that general controls for information systems must address several key areas, including security management encompassing the CIA triad (confidentiality, integrity, and availability) and logical and physical access controls. General controls apply to all or a large segment of an entity's information systems and also include configuration management, segregation of duties within IT, and contingency planning. Marketing automation, revenue forecasting algorithms, and employee satisfaction surveys are operational or administrative functions, not general control categories for information systems as defined by the Green Book. General controls provide the foundation upon which application-level controls operate effectively.
2. Contoso Federal Agency is conducting a root cause analysis after a significant control failure in its procurement process. The investigation team wants to use a structured technique that visually maps potential causes across multiple categories such as people, processes, technology, and environment. Which risk identification technique should the team use? (Select one!)
Explanation
The Fishbone (Ishikawa) Diagram is a root cause analysis technique that visually organizes potential causes of a problem into categories such as people, processes, technology, and environment. It helps teams systematically trace a control failure back to its underlying causes. Monte Carlo simulation is a quantitative technique for modeling probability distributions through random iterations, not root cause analysis. Decision tree analysis is used for evaluating alternatives through graphical models with decision nodes and chance nodes, not for identifying causes. PESTEL analysis examines external macro-environmental factors (Political, Economic, Social, Technological, Environmental, Legal) rather than specific internal control failures.
3. Litware Federal Agency is using the NISTIR 8286 series to integrate cybersecurity risk management with enterprise risk management. The CISO needs to explain the three-tier enterprise hierarchy described in NISTIR 8286 to the Risk Management Council. Which hierarchy accurately represents the NISTIR 8286 model from highest to lowest? (Select one!)
Explanation
NISTIR 8286 Rev. 1 establishes a three-tier enterprise hierarchy for integrating cybersecurity and enterprise risk management: Level 1 (Enterprise) addresses strategic governance and enterprise-wide risk considerations, Level 2 (Mission/Business Process) focuses on business processes, security architecture, and resource allocation, and Level 3 (Information Systems) deals with specific system controls, categorization, and continuous monitoring. This hierarchy aligns with NIST SP 800-39's three-tier model and enables risk aggregation from system-level cybersecurity risk registers up to enterprise risk registers. The inverted hierarchy (systems at top) would contradict the top-down governance approach. The strategic/tactical/technical and governance/assessment/control options do not represent the NISTIR 8286 structure.
4. Northwind Federal Agency's program manager is proposing to implement a new automated system for processing benefit payments. The system would replace manual reviews currently performed by three separate employees who handle authorization, recording, and custody of payments respectively. The proposed automated system would consolidate these functions into a single workflow managed by one system administrator. What internal control concern does this consolidation raise? (Select one!)
Explanation
Consolidating authorization, recording, and custody functions into a single role or workflow managed by one individual eliminates segregation of duties, which is a fundamental internal control principle under GAO Green Book Principle 3. Segregation of duties requires that custody of assets, accounting/recording of transactions, and authorization of transactions be performed by different individuals to prevent and detect errors or fraud. While FISMA security requirements are important for any federal information system, the primary internal control concern with this specific consolidation is the loss of segregation of duties. Automated controls are actually considered more reliable than manual controls with less susceptibility to human error, not less reliable. The system administrator's role does not warrant Senior Management Council membership, which is a governance body with different composition requirements.
5. Contoso Federal Agency is coordinating its ERM activities with federal planning processes. The risk management team needs to ensure the agency's risk profile is properly synchronized with the required federal review processes. According to OMB Circular A-123, by when must agencies submit their risk profiles coordinated with Strategic Reviews? (Select one!)
Explanation
OMB Circular A-123 requires agencies to update their risk profiles annually, coordinated with Strategic Reviews that are submitted to OMB by June. This timing ensures that risk information is current and can inform the strategic review discussions conducted through FedSTAT, where agencies discuss performance and risk with OMB. December 31 aligns with the calendar year rather than the federal planning cycle. September 30 is the fiscal year end, which is when financial reporting occurs but not when risk profiles are submitted. March 15 is not the specified deadline; the budget submission process follows a different timeline that begins earlier in the fiscal year.
$17.99
One-time access to this exam