- Exam Format Overview
- Domain 1: Standards, Policies, and Procedures
- Domain 2: Program Oversight and Governance
- Domain 3: Communication, Education, and Training
- Domain 4: Monitoring, Auditing, and Internal Reporting
- Domain 5: Investigation, Discipline, and Incentives
- Domain 6: Risk Assessment
- How the Domains Show Up in Questions
- Mapping a Study Timeline to the Domains
- Who Hires for This Domain Knowledge
- FAQ
- The CCEP-I exam covers six domains, and Investigation and Responses, Discipline and Incentives is the largest.
- The exam has 115 multiple-choice questions (100 scored, 15 unscored) in a 2 hour 30 minute session.
- Fees are $350 for SCCE/HCCA members and $450 for non-members; membership is not required to sit for the exam.
- Passing is set using the Angoff method, not a fixed raw score cutoff.
Exam Format Overview
Before drilling into each content area, it helps to understand how the Compliance Certification Board (CCB) structures the CCEP-I exam itself. According to the CCB's 2025 candidate handbook, the exam consists of 115 multiple-choice questions - 100 scored and 15 unscored pretest items that don't count toward your result but are indistinguishable from scored questions during the test. Candidates get 2 hours and 30 minutes for the credential-specific exam-day section, and the test is closed book, meaning no notes, reference materials, or outside resources are permitted at the workstation.
The six domains you'll see below come directly from the CCB's official content outline and form the blueprint every question is written against. If you want a deeper walkthrough of how to prepare across all six areas, our CCEP-I Study Guide 2026 pairs well with this domain breakdown.
Domain 1: Standards, Policies, and Procedures
This domain focuses on the written backbone of a compliance and ethics program: codes of conduct, policy hierarchies, and procedural documentation. Candidates need to understand how organizations draft, review, distribute, and update standards so they remain enforceable and defensible.
Standards, Policies, and Procedures
Expect questions on how policies get created, approved, communicated, and revised over time.
- Elements of an effective code of conduct
- Policy lifecycle management and version control
- Alignment between policies and applicable laws or industry standards
- Accessibility and cultural adaptation of written standards across a global organization
Domain 2: Compliance and Ethics Program Oversight and Governance
This area tests your understanding of how a program is structured at the organizational level - reporting lines, board involvement, and the allocation of authority and resources. Questions often probe the relationship between the compliance officer, senior leadership, and the board or governing body.
Program Oversight and Governance
Candidates should be comfortable with the structural elements that give a compliance program authority and independence.
- Roles and independence of the compliance officer
- Board and senior management oversight duties
- Resource allocation and program authority
- Governance documentation and reporting cadence
If you're still confirming whether this credential fits your career path, our overview of What Is CCEP-I Certification? explains the governance-heavy nature of the role in plain terms.
Domain 3: Communication, Education, and Training
Programs live or die by whether employees actually understand the rules. This domain covers how organizations design, deliver, and measure the effectiveness of training and communication efforts.
Communication, Education, and Training
Expect scenario questions asking you to identify the right training approach for a given audience or risk area.
- Needs assessment for training content
- Delivery methods for different audiences (executives, frontline staff, third parties)
- Measuring training effectiveness and retention
- Communicating policy changes and program updates
Domain 4: Monitoring, Auditing, and Internal Reporting Systems
This domain covers the ongoing verification activities that confirm a program is working as intended, plus the reporting channels employees use to raise concerns.
Monitoring, Auditing, and Internal Reporting Systems
Candidates should be able to distinguish monitoring from auditing and know how reporting hotlines fit into the overall structure.
- Differences between monitoring activities and formal audits
- Designing and maintaining confidential reporting channels
- Non-retaliation protections tied to internal reporting
- Using audit findings to strengthen program design
Domain 5: Investigation and Responses, Discipline and Incentives
This is the largest domain on the exam, and it deserves the most study time of the six. It covers how organizations investigate reported misconduct, respond to substantiated findings, apply discipline consistently, and use incentives to reinforce good behavior.
Investigation and Responses, Discipline and Incentives
Because this domain carries the most weight, candidates should expect the highest concentration of scenario-based items here.
- Steps in a fair and defensible internal investigation
- Documentation standards and chain-of-custody considerations
- Consistent application of discipline across similar violations
- Designing incentive structures that reward ethical conduct
- Root-cause analysis following a substantiated finding
Key Takeaway
Since Investigation and Responses, Discipline and Incentives is the largest domain, allocate more of your practice-question time here than any other single area, and revisit it again in your final review week.
Domain 6: Risk Assessment
The final domain covers how organizations identify, prioritize, and respond to compliance risks. This includes both the methodology of conducting a risk assessment and how findings feed back into the rest of the program - policies, training, monitoring, and investigations all trace back to risk assessment results.
Risk Assessment
Expect questions connecting risk assessment outputs to decisions made elsewhere in the program.
- Risk identification and categorization methods
- Prioritizing risks by likelihood and impact
- Using risk assessment results to shape training and monitoring priorities
- Periodic re-assessment as the organization or regulatory landscape changes
How the Domains Show Up in Questions
The CCEP-I exam draws all 100 scored questions (plus 15 unscored pretest items you can't identify during the test) from the six domains above. Rather than memorizing isolated facts, most items ask you to apply domain knowledge to a workplace situation - for example, identifying the appropriate discipline response under Domain 5, or selecting the correct escalation path under Domain 4. Because the test is closed book and delivered in a single 2 hour 30 minute window, pacing matters as much as content knowledge.
For a full breakdown of how the passing standard interacts with these domains, see our companion piece on the CCEP-I Passing Score, and if you're weighing overall difficulty before you commit to a testing date, How Hard Is the CCEP-I Exam? walks through the format in more depth.
| Domain | Core Focus |
|---|---|
| 1. Standards, Policies, and Procedures | Written codes, policy lifecycle, procedural documentation |
| 2. Program Oversight and Governance | Reporting lines, board oversight, program authority |
| 3. Communication, Education, and Training | Training design, delivery, and effectiveness measurement |
| 4. Monitoring, Auditing, and Internal Reporting Systems | Ongoing verification and confidential reporting channels |
| 5. Investigation and Responses, Discipline and Incentives | Investigations, discipline consistency, incentive design (largest domain) |
| 6. Risk Assessment | Risk identification, prioritization, and program feedback loops |
Mapping a Study Timeline to the Domains
A domain-aware schedule beats generic review because it puts your limited hours where the exam puts its weight. The timeline below is one reasonable way to sequence six weeks of preparation, front-loading the largest domain and closing with a mixed-domain review.
Standards, Policies, and Procedures + Governance
- Review code-of-conduct elements and policy lifecycle concepts
- Study reporting lines and board oversight structures
Communication, Education, and Training
- Work through training-delivery scenario questions
- Review effectiveness-measurement approaches
Monitoring, Auditing, and Internal Reporting
- Compare monitoring versus auditing activities
- Study non-retaliation and hotline design principles
Investigation, Discipline, and Incentives
- Spend extra time here since it is the largest domain
- Practice scenario questions on investigation steps and discipline consistency
Risk Assessment
- Study risk prioritization methods
- Connect risk findings back to training and monitoring decisions
Full-Length Mixed Review
- Take timed practice sets covering all six domains
- Revisit weak areas identified during practice
Our full practice test platform lets you drill each domain individually before combining them into timed, mixed-domain sets that mirror the real 115-question format.
Who Hires for This Domain Knowledge
Because the six domains span policy writing, governance, training, monitoring, investigations, and risk assessment, employers hiring CCEP-I holders tend to be organizations with formal compliance functions - regulated industries, multinational corporations, and organizations managing cross-border regulatory exposure. The breadth of the domains reflects the breadth of the compliance officer role itself: it's not just about knowing the law, but about running the operational machinery that keeps a program functioning day to day.
If you're evaluating whether the credential translates into career or compensation gains, our CCEP-I Salary Guide and ROI analysis dig into that question directly, and CCEP-I Jobs looks at the kinds of roles that typically list this credential as preferred or required.
Frequently Asked Questions
Investigation and Responses, Discipline and Incentives is the largest domain on the exam, so it warrants extra study time relative to the other five domains.
The exam contains 115 multiple-choice questions total: 100 are scored and 15 are unscored pretest items that are not identified during the test.
The credential-specific exam-day section allows 2 hours and 30 minutes. Always confirm your specific booking details when scheduling, since total appointment time at a test center can include check-in procedures.
No. Membership is not required. The 2025 handbook lists exam fees of $350 for SCCE/HCCA members and $450 for non-members.
Delivery options include PSI test centers, remote proctoring, and approved paper-and-pencil exams at qualifying conferences. All formats are closed book. For scheduling windows and deadlines, see our CCEP-I Exam Dates guide.