Study Guide

CSE-07 Senior Management Test: Deciding Like an Executive

Prepare for the SAC CSE-07 senior management test by practicing executive decisions across compliance, risk, governance, integrity and incident handling.

Updated September 20268 min readStudy Guide证券考试题库
证E

Prepared by

证券考试题库 Editorial Team

Study guide editorial team

These guides use AI-assisted research and drafting. Sources are linked so you can check the evidence. Automated checks do not represent review by a credentialed subject expert. Contact us to report a correction.

Study this exam by converting every rule into an executive decision: who owns the duty, what triggers action, what gets escalated, and what is documented. Two worked scenarios, a three-function comparison table, and a five-point self-check rubric make that conversion concrete.

Role positioning: why rule recall alone does not produce the right answer

The core difficulty is role positioning: senior-management scenarios ask which duty is engaged, who must act, and what should be escalated — three judgments that a memorized rule summary cannot supply on its own.

In operational-level securities tests, knowing what a rule says is usually enough. Here, a question may describe a board meeting, a business-line proposal, or an internal dispute and ask how the senior manager should respond. You must first map the situation onto a governance role: are you deciding, supervising, or reporting? That mapping changes the correct response even when the underlying rule text is identical in both versions of the scenario.

Train this by rewriting every rule you study as a decision sentence: who owns it, what triggers action, and what follows if it is ignored. Then compare two phrasings of the same rule — one addressed to front-line staff, one addressed to management. The management version emphasizes oversight, resourcing, and accountability rather than execution. Collect these pairs as flashcards so the executive framing becomes automatic.

Mapping the rule hierarchy: national law, CSRC rules, SAC self-regulatory rules

Chinese securities rules form tiers: national statutes, CSRC regulations and rules, then SAC self-regulatory rules. Identifying the tier a duty comes from tells you its force and how a scenario expects it to be applied.

Study each syllabus domain top-down. National securities law sets baseline prohibitions and investor-protection duties. CSRC departmental rules add operational requirements for governance, compliance systems, and risk management. SAC self-regulatory rules — which the association publishes as compiled collections on its website — fill in implementation detail, from professional conduct and reputation management to training and specific business standards.

The trap is that scenario facts may cite a self-regulatory standard while the decisive duty sits in a higher tier. Practice tagging every fact in a practice question to its tier. When two requirements appear to conflict, the higher tier prevails; when both bind, the executive answer follows the stricter one. Keep a one-page tier map per domain listing one anchor rule at each level so you can locate any new fact quickly.

Compliance and internal control: the three lines of defense in practice

The three-lines model assigns first-line control ownership to business units, second-line oversight to compliance and risk functions, and third-line assurance to internal audit. Senior-management questions test whether these lines stay independent and resourced.

The named concept to master is compliance independence: the compliance head's position, reporting access to the board, and protection from casual removal or override. A scenario in which a business head 'directs' or 'manages' compliance output is signaling a broken control structure — the executive response restores the reporting line rather than negotiating around it. Internal control, meanwhile, is the whole environment: authorization limits, information isolation between sensitive functions, record-keeping, and accountability mechanisms.

Watch for the proportionality cue. A scenario describing rapid business expansion with unchanged control staffing or unchanged systems is inviting the executive answer of scaling controls with the business — before an incident, not after. Contrast this with a stable business where the same request would be routine maintenance; recognizing which situation you are in is part of the judgment being tested.

Risk management, compliance, and internal audit: three functions, three questions

These functions share vocabulary but differ in the question they ask, their position in the three lines, and their outputs. Distinguishing them tells you whom a scenario expects you to instruct first.

Risk management asks whether an exposure can be borne within stated tolerance, and it produces risk tolerance statements, limits, monitoring, and the early-warning indicators named in the syllabus's risk-domain theme. Compliance asks whether an action is permitted, and it produces reviews, violation handling, and advisory opinions. Internal audit asks whether controls actually worked, and it produces findings on past periods with rectification tracking.

In a scenario where a new product both carries market exposure and touches a client-suitability boundary, an executive sequence emerges: hold the launch pending compliance sign-off, size exposure through risk limits, and schedule audit coverage. The table below contrasts the three functions so you can label each scenario actor correctly before deciding.

DimensionRisk managementComplianceInternal audit
Core questionCan we bear this exposure?Is this action permitted?Did controls work as designed?
Line of defenseSecond lineSecond lineThird line
Typical outputsRisk tolerance, limits, early-warning indicatorsReviews, violation handling, adviceAudit findings, rectification tracking
Senior-manager actionSet tolerance, review limit breachesGuarantee independence and resourcingEnsure scope, independence, follow-up

Worked scenario 1: escalating a compliance objection to a revenue plan

When a revenue-critical plan collides with a compliance objection, the senior-manager answer preserves the compliance function's independence, documents the dispute, and resolves it through the proper governance channel.

Scenario: the retail brokerage head proposes a promotional sales campaign; the compliance department flags a client-suitability problem and asks to narrow the target group. The plausible mistake is the chief executive telling compliance to 'note the risk but let it proceed' — treating compliance sign-off as a checkbox. That dissolves second-line independence and concentrates personal accountability on the decision-maker who overrode it.

The better decision has three steps: require compliance to state its objection in writing; convene the appropriate management decision body; and choose among narrowing the campaign, redesigning it, or abandoning it, recording the chosen option and its owner. This matters because the documented process is what demonstrates discharge of a senior manager's duty — a senior manager may still decide, but only through a channel that respects the compliance line, and the record is the evidence.

Worked scenario 2: a mis-selling allegation goes viral

Incident questions test sequence: assess facts, protect clients first, report through the required chain, preserve evidence, and make public communication consistent with the filed report — not public relations first.

Scenario: social media posts allege that a branch misled elderly clients into high-risk products. The plausible mistake is the branch manager drafting a public denial before verifying facts and before any internal report. That sequence risks contradicting later findings, undermining regulatory credibility, and delaying remedy for affected investors — compounding the original problem with a communication failure.

The better decision runs: freeze the implicated sales process; verify client files, suitability records, and recordings; remedy verified harms under the firm's investor-protection framework; report internally and to the regulator within the applicable reporting timelines; and align any public statement with verified facts and the report already filed. The ordering — clients, evidence, report, then communication — is the logic the syllabus's incident-handling and investor-protection themes describe.

A four-week sequence, a five-point rubric, and readiness checks

Build a four-week loop: map the rule hierarchy, study each syllabus domain by writing executive decisions, score them against a rubric, then finish with mixed timed scenarios and flashcard review of named concepts.

Suggested sequence, adaptable to your calendar: Week 1 — build the tier map and the governance-role chart from the sections above. Weeks 2–3 — cover one syllabus domain every few days: read its named concepts, then write a five-sentence executive decision for a self-made conflict scenario. Week 4 — mixed scenarios and flashcards for terms such as three lines of defense, risk tolerance, information isolation, and integrity commitments.

Practical exercise: take any domain, invent a scenario with a genuine conflict, and write a decision memo. Self-check rubric — score two points per element, as learning milestones rather than pass predictions: (1) names the engaged duty; (2) separates who decides from who reports; (3) states the escalation or reporting path; (4) addresses client or investor impact; (5) specifies documentation. Eight or more points across two different domains suggests scenario fluency; below six, revisit that domain's governance structure before moving on.

Concrete readiness checks: work through the list below and only count yourself ready when every item is true from memory. For question volume, use a practice bank such as the site's free practice set, scoring your written rationales — not just your answers — against the rubric.

  • You can draw the three lines of defense and place compliance, risk, and internal audit without notes.
  • You can state the difference between risk tolerance and risk limits in one sentence.
  • Given an incident scenario, your first three actions protect clients and evidence before any communication.
  • Your rule-hierarchy map covers national law, CSRC rules, and SAC self-regulatory rules with one anchor example each.
  • You score eight or more on the rubric for decision memos from two different syllabus domains.

References and further reading

Use these references to explore the concepts and check the latest information from the relevant organizations.

Continue your preparation

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for 专项高级管理人员水平评价测试.

Is this test the same as the general practitioner-level securities tests?
No. This is a senior-management-focused level evaluation test: its syllabus domains center on governance, compliance and internal control systems, risk oversight, regulation, integrity, and incident handling rather than operational business knowledge. Do not prepare for it using only general qualification materials.
Do I need to memorize exact rule article numbers?
Anchor rules by name and by tier — national law, CSRC rules, SAC self-regulatory rules — because recognizing which duty and which tier applies is what drives the decision. Precise numbering adds little value when writing an executive decision; the tier map does the locating work.
How does the integrity and clean-conduct domain differ from compliance?
Integrity rules target specific conduct: bribery, improper benefits, and conflicts in dealings with clients and counterparties. Compliance is the broader system ensuring all activity follows applicable rules. Scenarios can combine both — for example, an improper-benefit allegation handled through the compliance escalation channel.
What should I actually study from first?
Start with the rule hierarchy anchored in publicly available national securities law, CSRC rules, and the SAC's compiled self-regulatory rules, then add scenario practice on top. The SAC website publishes rule compilations and test announcements; pair that with written decision exercises and a question bank.
Where are the registration dates, format, and results?
Administrative details — schedules, registration, admission tickets, and results — are published by the Securities Association of China. Check the SAC website's candidate services section for current arrangements rather than relying on secondary summaries.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.