CISI GFC vs CFC vs RFS: Which Compliance Exam Do I Need?
The Chartered Institute for Securities & Investment offers three flagship compliance and risk qualifications: Global Financial Compliance (GFC), Combating Financial Crime (CFC), and Risk in Financial Services (RFS). They overlap in reputation but not in content. If you're targeting a compliance-officer, MLRO, or risk-management role, choosing the right one — or the right combination — matters more than most candidates realise.
The Three Qualifications at a Glance
Before we compare, a quick summary of what each exam actually is.
| Exam | What it covers | Best for | Length |
|---|---|---|---|
| GFC — Global Financial Compliance | The regulatory environment, the compliance function, financial crime, ethics, and governance / risk / compliance (GRC) | Compliance officers, second-line control staff, aspiring MLROs | 100 MCQs · 2 hours · 70% pass |
| CFC — Combating Financial Crime | Deep dive into AML, CTF, sanctions, bribery, fraud, tax evasion, and cybercrime | MLROs, AML analysts, sanctions specialists, KYC leads | 50 MCQs · 1 hour · 70% pass |
| RFS — Risk in Financial Services | Risk management fundamentals — market, credit, operational, liquidity, model, and enterprise risk | Risk officers, ops-risk specialists, enterprise-risk-management staff | 100 MCQs · 2 hours · 70% pass |
What CISI GFC Actually Tests
The Global Financial Compliance (GFC) exam is the compliance officer's baseline qualification. It is the broadest of the three, covering how regulation works internationally and how compliance functions operate day-to-day.
The five chapters are weighted as follows:
- Chapter 1 — International Regulatory Environment (20% of exam): rules-based vs principles-based regulation, extraterritorial reach (GDPR, FATCA, CRS, Basel), MiFID II venues (RM, MTF, SI, OTF), international bodies (BIS, BCBS, IOSCO, FSB, IAIS).
- Chapter 2 — The Compliance Function (24%, the heaviest): three lines of defence, compliance monitoring programmes, the CCO role, SMCR, individual accountability, handling breaches.
- Chapter 3 — Managing the Risk of Financial Crime (20%): overlaps with CFC but at a higher level — AML/CFT, sanctions, bribery, fraud, tax evasion, crypto.
- Chapter 4 — Ethics, Integrity & Fairness (19%): ethical frameworks, fair customer outcomes, vulnerability, fiduciary duty, product governance, Consumer Duty.
- Chapter 5 — Governance, Risk Management & Compliance (17%): overlaps with RFS at a higher level — governance frameworks, risk appetite, operational resilience.
The exam is globally applicable — it does not focus on any one jurisdiction. This makes GFC the most portable of the three across countries and firm types.
What CISI CFC Actually Tests
Combating Financial Crime (CFC) is the deep-dive specialist qualification for anyone whose full-time role touches financial crime. Where GFC gives you a chapter on the topic, CFC gives you a whole exam.
Content includes: an in-depth treatment of money laundering (three stages, typologies), terrorist financing, FATF and the international AML framework, EU MLDs, national implementation, customer due diligence (CDD, EDD, SDD), politically exposed persons, source of funds versus source of wealth, transaction monitoring, SARs and MLRO obligations, the tipping-off offence, sanctions regimes (with US OFAC's extraterritorial reach a major topic), bribery frameworks (UK Bribery Act 2010, US FCPA), fraud typologies, cybercrime, and the criminal / regulatory frameworks around all of the above.
CFC is a shorter exam (50 questions, one hour) but is more technically dense per question. Candidates typically say the difficulty is comparable to GFC despite being half the length.
What CISI RFS Actually Tests
Risk in Financial Services (RFS) is the fundamentals qualification for risk-management professionals — the equivalent of GFC for the risk side of the second line.
Content includes: the definition of risk (ISO 31000, upside and downside), the risk-management framework, risk appetite versus risk capacity versus risk tolerance, the major risk categories (credit, market, liquidity, operational, compliance/conduct, reputational, strategic, model, cyber, climate), operational-risk management (Basel's seven categories), operational resilience (post-2022 regulatory frameworks), Basel III and beyond, Solvency II, corporate governance, board composition and committees, three lines of defence, and enterprise risk management.
RFS is 100 questions in two hours, matching GFC in length. Unlike GFC, however, RFS is aimed at people whose primary function is risk rather than compliance — think Chief Risk Officer's team, market-risk analysts, operational-risk specialists.
The Three Compared Side by Side
| GFC | CFC | RFS | |
|---|---|---|---|
| Primary audience | Compliance officers | MLROs, AML/sanctions specialists | Risk officers, ORM staff |
| Coverage | Broad regulation + compliance | Deep financial-crime specialisation | Broad risk management |
| Number of chapters | 5 | 7 | 7 |
| Exam length | 100 MCQs · 2 hours | 50 MCQs · 1 hour | 100 MCQs · 2 hours |
| Pass mark | 70% | 70% | 70% |
| Jurisdictional focus | Global | Global, with UK/US emphasis | Global |
| Overlap with the others | Covers financial crime + risk at a high level (chapters 3 and 5) | Deep dive on GFC's chapter 3 | Deep dive on GFC's chapter 5 |
| Typical prep time | 4-6 weeks | 3-4 weeks | 4-6 weeks |
| Difficulty (subjective) | Medium | Medium-hard (dense) | Medium |
Which One Should You Take?
If your job title has "Compliance" in it
Start with GFC. It gives you the broad baseline covering law versus regulation, the regulatory bodies, the compliance function itself, and enough financial-crime + risk knowledge to speak the language across both. Once passed, you can specialise into CFC (if your role deepens into financial crime) or RFS (if you move toward enterprise risk).
If your job title has "MLRO", "AML", "KYC" or "Sanctions" in it
CFC is the more direct qualification. Employers in these specific roles will recognise CFC as the technical baseline. However, many firms will also want you to have GFC as the broader compliance credential — in which case taking both in sequence (GFC first, CFC second) is common.
If your job title has "Risk" in it (and not "Compliance")
RFS is the right qualification. Compliance staff and risk staff often work adjacent to each other but the qualifications differ. RFS covers the enterprise-risk-management side that a compliance-focused qualification like GFC only touches on lightly.
If you're a career changer entering financial services
GFC first, then decide based on where you land. GFC is the most broadly applicable of the three and gives you the vocabulary to interview for compliance roles across banks, asset managers, insurers, and fintechs. Once you're in a specific role, you'll know whether CFC or RFS makes sense next.
Can I Take More Than One?
Yes — and in many firms it's expected. Common combinations:
- Compliance Officer Pack: GFC + CFC. Gives you the broad compliance credential plus the financial-crime specialisation. The most popular combination for compliance careers in banking and asset management.
- Risk & Compliance Pack: GFC + CFC + RFS. The full second-line credential set. Overkill for most, but useful if you're in a senior second-line role or moving between compliance and risk teams.
- GFC + RFS. Broad coverage of both compliance and risk — good for anyone in a smaller firm where the second-line function isn't split into separate teams.
The exams don't have prerequisites, so you can take them in any order. Most candidates prefer GFC first (broadest, gives you the framework) then a specialist.
What Career Paths Do These Open?
GFC
Compliance analyst → senior compliance analyst → compliance manager → Chief Compliance Officer. GFC also underpins moves into monitoring, testing, advisory, and regulatory-affairs roles. In some jurisdictions (UAE, Singapore, Hong Kong) it is explicitly recognised by local regulators.
CFC
AML analyst → senior AML analyst → MLRO → Head of Financial Crime. Also useful for sanctions specialists, KYC / onboarding leads, and transaction-monitoring analysts. CFC is often cited as a preferred qualification in job adverts for MLRO and equivalent roles.
RFS
Risk analyst → senior risk analyst → risk manager → Chief Risk Officer. Also useful for operational-risk specialists, resilience professionals, model-risk analysts, and enterprise-risk-management staff. Adjacent to internal audit and second-line testing roles.
How to Prepare
All three exams are 100% multiple-choice, so preparation is straightforward if you follow the standard formula: work through the CISI workbook, use a calibrated question bank to identify weak areas, take timed mock exams, then focus revision on your weakest chapters.
A common pitfall: candidates over-read the workbook and under-practise MCQs. In these exams, familiarity with the question style is worth as much as content knowledge — many questions test the distinction between two nearly identical answer options, which only comes from practising against calibrated questions.
Frequently Asked Questions
Which of the three is easiest?
Difficulty is subjective, but candidates typically report GFC and RFS as slightly easier than CFC, mostly because CFC packs more technical detail into fewer questions. All three are considered fair rather than difficult exams by CISI standards.
Are GFC, CFC and RFS accepted worldwide?
Yes. These are among CISI's most portable qualifications and are recognised by regulators and employers in the UK, EU, UAE, Singapore, Hong Kong, Australia, and many other jurisdictions. Some regulators explicitly list them as qualifying for named roles.
Do I need to be working in compliance to take these exams?
No. There are no prerequisites — anyone can sit them. That said, working knowledge of financial services helps, so if you're a complete beginner, taking the CISI IISI first as a foundation is worth considering.
How much do the exams cost?
CISI exam fees vary by exam and region, but the enrolment fee (including workbook and one exam attempt) is typically in the £200-300 range. Retakes are cheaper. Prep resources like question banks are additional but relatively affordable compared to the exam fee itself.
How long does it take to prepare for GFC, CFC or RFS?
Most candidates report 4-6 weeks of consistent study for GFC or RFS, and 3-4 weeks for CFC (given its shorter exam). Working professionals studying part-time will typically be in the higher end of these ranges. A calibrated question bank shortens preparation because it directs your revision to weak areas rather than making you re-read the whole workbook.
Which exam should I take first — GFC or CFC?
For most people, GFC first. It gives you the broad framework and vocabulary that CFC then deepens in one specific area. Only take CFC first if your role is very specifically financial-crime focused (e.g. you've just been made an MLRO) and you need the specialist credential fast.
Do these exams replace the IISI or ICWIM?
No — they complement them. IISI is entry-level securities and investment knowledge. ICWIM is wealth management specifically. GFC / CFC / RFS are compliance and risk. Depending on your career path, you may need one from each track.
The Bottom Line
The three exams answer three different questions. GFC asks: can you run a compliance function? CFC asks: can you spot and stop financial crime? RFS asks: can you identify and manage enterprise risk? Pick the one that matches your role or ambition, then decide whether to add another as you specialise. If in doubt: GFC first.