Study Guide

CSE-06 Senior Management Test: A Governance-Lens Study Plan

Study plan for the SAC senior management level test (CSE-06): map decision rights across governance layers, drill scenarios, and track readiness with a rubric.

Updated September 202611 min readStudy Guide证券考试题库
证E

Prepared by

证券考试题库 Editorial Team

Study guide editorial team

These guides use AI-assisted research and drafting. Sources are linked so you can check the evidence. Automated checks do not represent review by a credentialed subject expert. Contact us to report a correction.

Prepare for CSE-06 with a governance lens rather than as a larger staff exam. For every rule you study, record who formulates it, who approves it, who executes it, who monitors it, and who must be informed. The two worked scenarios below show how a plausible but wrong answer comes from fixing a single transaction, while the better answer fixes the system and its reporting line. Finish with the mapping exercise and readiness rubric to locate your weak layers.

Separating Executive Accountability from Line Duties in Governance Items

Anchor every rule you study to an owner: which body sets policy, which role a named officer must hold, and where an incident must be reported. Map decision rights before memorizing rule text.

Use the three lines of defense as your base map. The first line is the business line, which owns its own risks and controls; the second line comprises compliance and risk management functions, which set standards and monitor the first line; the third line is internal audit, which provides independent assurance to the board. Senior management sits above the first line and carries firm-level responsibility for the whole arrangement. Use this contrast when you study: a staff-level framing asks what a rule requires; a management-level framing asks who must ensure it, who reports upward, and to whom.

Convert this into a study technique. As you read any rule, annotate its verbs: formulate, approve, execute, supervise, report. Then build a decision-rights table for each topic — for example, who approves the compliance policy versus who drafts it, and whether the compliance officer reports to the board or to the president. If you cannot fill in a row, that is a specific gap, not a vague feeling of unreadiness, and it tells you exactly which rule text to reread.

  • First line: business and branch management execute controls daily and own residual risk.
  • Second line: compliance and risk functions set standards, monitor, and report independently.
  • Third line: internal audit evaluates the effectiveness of the first two lines for the board.
  • Senior management: allocates resources, approves policies within board mandates, and answers for system failures.
DecisionTypical owner to mapCommonly confused with
Approving the overall risk appetiteBoard or its dedicated committeeSenior management, which implements and cascades it
Drafting and maintaining compliance proceduresCompliance departmentBusiness departments, which execute them
Day-to-day client suitability checksFront-line sales and branch managementThe compliance function, which oversees the system
Independent assurance over all of the aboveInternal auditCompliance, which is part of the second line

Tracing the Compliance Management System's Structure and Reporting Lines

Compliance material rewards studying structure as much as duties: the compliance officer's standing, the department's independence, and the upward path of compliance reports. Learn the system's parts and trace information flow through them.

Model the compliance management system as four linked parts: the firm-wide compliance policy, the compliance department, a compliance officer positioned within senior management, and compliance liaison arrangements in business departments and branches. The concept that distinguishes a management-level answer is independence: the compliance function needs a reporting line and working conditions that let it escalate problems without business interference. Contrast compliance with risk management so you do not merge them: compliance asks whether conduct conforms to rules and internal standards, while risk management measures and limits quantified exposures. Write this boundary down as an explicit distinction in your notes.

Drill with a trace exercise rather than rereading. Pick one flow — for example, how a compliance finding at a branch travels to the compliance department, to the compliance officer, and to the board or its duly empowered body — and write the path from memory. Then pick a second flow, such as how a new business product receives a compliance review before launch. If your written path skips a node or invents an extra approval, reread that specific part of the system description. Ten minutes of tracing per flow teaches more than an hour of passive reading because errors in the map expose gaps precisely.

Linking Comprehensive Risk Management to Capital and Risk Indicators

Risk topics combine a governance cascade with balance-sheet constraints: the board sets risk appetite, management cascades limits, and regulatory capital and risk control indicators constrain the whole. Learn the cascade first, then the indicator categories.

The comprehensive risk management framework has a clear chain of ownership. The board approves the risk appetite statement and overall risk management policy; senior management implements them by setting limits, allocating resources, and chairing management-level risk committees; risk functions measure exposures against those limits; and business lines operate within them. Study risk by category — market, credit, liquidity, operational, and reputational — and note that each category needs a named limit owner and an escalation trigger. When you answer risk questions, train yourself to name the cascade step, not just the risk type.

Layer capital regulation on top of this cascade. The net capital and risk control indicator regime translates risk into balance-sheet language: a firm must hold sufficient net capital relative to its businesses, and specific indicators constrain concentrations and leverage in principle. You do not need to compute thresholds to be prepared at this level; you need to know that breaches of such indicators trigger reporting and corrective obligations that end at senior management and the board. Build a one-page map: each risk category, its limit owner, the related indicator family, and the escalation path. Reproduce it from memory at the end of each study cycle.

Deciding Suitability Problems in Brokerage and Wealth Management Scenarios

Practice suitability problems as firm-wide failures rather than single bad sales. Diagnose which system component broke — assessment, product matching, escalation, or oversight — and prefer the option that repairs the system.

Scenario one. A branch manager notices that a retired client, whose risk assessment says conservative, was sold a high-commission structured product. The branch has a signed confirmation form. The branch manager plans to note the case and retrain the individual salesperson. That is the plausible mistake: it treats suitability as an isolated conduct problem. The better decision is to treat it as a system signal — check whether the client's risk assessment was current, whether the product-matching rule was applied before the sale, why the mismatch was not escalated, and whether branch-level monitoring detected it — and to fix the matching and escalation process firm-wide if it is weak. It matters because the firm's suitability obligation is systemic: forms do not discharge it if the process behind them failed.

When answering such items, run a four-point system check in order: is the investor assessment valid and updated; does the product match the assessed profile; was the mismatch documented and escalated; and is there management-level monitoring over the whole flow. The option that strengthens one of these four points for all clients is the one to prefer over an option that addresses one transaction. Also distinguish suitability from mere disclosure: telling the client about risks does not substitute for matching the product to their profile in the first place.

Operating Information Walls Between Investment Banking and Asset Management

Treat cross-division conflict problems as exercises in operationalizing separation: restricted lists, information isolation, and compliance escalation — not informal discretion between division heads.

Scenario two. An investment banking team holds non-public information about an issuer whose bonds are held by funds the firm's asset management division manages. A portfolio manager asks a friend in investment banking about the issuer's outlook. The division head plans to remind both informally to be careful and leaves trading unchanged. That is the mistake: informal reminders do not create a record, do not restrict trading, and blur the wall. The better decision is to invoke the firm's information isolation arrangements — place the issuer on a restricted list, stop the informal channel, route any legitimate cross-division contact through compliance, and document the episode. It matters because the wall only functions as an auditable system; undocumented discretion is precisely the gap the wall exists to close.

Train this pattern with named mechanisms so your answer always contains one: restricted and watch lists, physical or logical separation of information, controlled cross-division communication through compliance, and record-keeping of contacts with issuers. Notice how the scenario differs from the suitability one: there the failure was in the client-facing control chain; here it is between internal divisions. If you can state, for any conflict scenario, which mechanism was missing and who was responsible for maintaining it, you are reasoning at management level. Practice by writing three lines per scenario: the mechanism, its owner, and the escalation step that was skipped.

Assigning Fintech and Information Security Duties at Management Level

Map technology rules to governance: management owns IT governance, data security policy, and outsourcing accountability, while technical teams implement. Attach each rule to an accountable owner and a control artifact.

Learn three named concepts and keep them distinct. IT governance means management sets the framework for system planning, development, operation, and change control, and remains answerable for it. Data security management means classifying data, controlling access, and protecting client information across its lifecycle. Outsourcing accountability means that delegating a system or process to a vendor does not delegate responsibility: management must perform due diligence, contract for control and audit rights, and monitor the vendor. The same logic extends to arrangements such as external access to trading information systems, which in principle require meeting regulatory and self-regulatory requirements rather than informal connection.

Study method: for each technology-related rule you read, write two items — the accountable owner at governance level and the control artifact that evidences compliance, such as an approved policy, an access review record, a change approval log, or a vendor assessment report. When you practice, deliberately invent shortcut cases — skipping vendor due diligence or delaying a security review for a new app feature — and train your reflex to identify which artifact is missing and which owner must enforce it. This converts a vague topic into a checklist you can reconstruct under pressure.

A Six-Week Sequence with a Readiness Rubric and Mapping Exercise

Rotate the syllabus by governance theme instead of reading linearly, close each cycle by writing decision-rights maps from memory, and score yourself against the rubric below. Treat scores as learning milestones only, not pass predictions.

Suggested adaptable sequence. Weeks one and two: laws, rules, and professional ethics, plus the three lines of defense and the compliance management system; end by writing the decision-rights table for both from memory. Week three: comprehensive risk management and the capital and risk indicator layer; end by reproducing your one-page risk map. Week four: brokerage and wealth management supervision; drill two suitability scenarios using the four-point system check. Week five: investment banking and asset management rules; drill two conflict and information-wall scenarios. Week six: fintech, information security, and a full review of all your maps and scenario notes. If a week's map has gaps, extend that week rather than moving on.

Exercise and rubric. Once per cycle, sit down with a blank page and produce three artifacts: the decision-rights table for one topic, the compliance reporting path, and the risk cascade with indicator families. Score each artifact from zero to three: zero means you cannot start; one means fragments without owners; two means owners and flows present with minor gaps; three means complete, correct, and reproducible in under ten minutes. Readiness checks: you can state which body approves risk appetite and which officer leads compliance; you can run the four-point suitability check on an unfamiliar scenario in writing; and you can name the wall mechanism, its owner, and the skipped escalation step for any conflict scenario. Self-check scores indicate study progress only.

Rubric item0–1 indicates2–3 indicates
Decision-rights table for a topicRule fragments without owners; reread the rule and remapOwners, flows, and reporting lines complete; move to the next topic
Compliance reporting path from memoryMissing or invented nodes; retrace the flow section by sectionFull path drawn correctly and quickly; test a second flow
Risk cascade with indicator familiesRisk types listed without limit owners or indicatorsEach category linked to a limit owner, indicator family, and escalation path
Scenario handling (suitability or conflict)Fixes one transaction or person instead of the systemNames the failed system component, the mechanism, and the owner

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for 一般高级管理人员水平评价测试.

How should I adapt staff-level securities study notes for a senior management test?
Staff-level notes emphasize what a rule requires; for this level, rework them so every rule is attached to an owner — who formulates, approves, executes, monitors, and reports. Build decision-rights tables rather than rereading the same text.
Do I need to memorize specific numerical thresholds for capital and risk control indicators?
At the governance level, the essential knowledge is the framework: that net capital and risk control indicators constrain businesses and that breaches carry reporting and corrective obligations. Verify the current administrative details and any thresholds directly with the issuer rather than relying on secondary summaries.
Can I rely on generic compliance-management material from other jurisdictions?
Concepts like the three lines of defense travel well, but specifics — the compliance management system's structure, reporting lines, and self-regulatory requirements — are jurisdiction-specific. Anchor your notes to the Chinese securities framework and the association's rules rather than imported material.
How should I use the two scenarios when practicing on my own?
After reading each scenario, write three lines before checking anything: the failed system component, the mechanism that should have operated, and the owner responsible for it. Compare with the model reasoning, then repeat with a self-invented variation a week later.
Where should I confirm administrative details such as registration and scheduling?
Treat all administrative matters — registration windows, scheduling, and result inquiries — as outside the scope of study notes. The China Securities Industry Association's website is the issuing source for the test's official administrative information.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.