Skip to content

Level III Core · Guidance for Standard VII: Responsibilities as a CFA Institute Member or CFA Candidate

Confidential Program Information: Standard VII(A) Guidance

Updated 8 October 2026 · Fact-checked

Standard VII(A) says members and candidates must not engage in conduct that compromises the reputation or integrity of CFA Institute or the CFA designation, or the integrity, validity or security of CFA Institute programs. To solve a question, find the conduct and test whether it compromises the integrity, validity or security of the programs. Disclosing confidential content and breaking exam rules are examples, not the whole standard. Then name the violation and the fix.

Understand Guidance for VII(A): Confidential Program Information

Standard VII(A) is titled Conduct as Participants in CFA Institute Programs. It protects the CFA Program itself. The standard has two linked aims: protect the reputation and integrity of CFA Institute and the designation, and protect the integrity, validity and security of the programs. Hold both ideas in mind.

The guidance in the Standards of Practice Handbook is organised under three headings. First, Confidential Program Information: content that CFA Institute does not make public, such as exam questions, answers, and what topics or question formats were or were not tested. Second, Additional CFA Program Restrictions: the rules and candidate instructions you accept when you register and sit the exam, such as limits on devices and conduct in the exam room. Third, Expressing an Opinion: what you may say about the program without revealing protected content.

These headings give the main examples. The test in the standard itself is wider: does the conduct compromise the integrity, validity or security of the programs, or the reputation or integrity of CFA Institute or the designation?

Think of it as fairness to every candidate. If someone learns questions in advance, or shares them afterwards, the exam stops measuring skill equally. The standard applies to members and candidates alike. It covers all CFA Institute programs, not only the exam, and includes things like grading, the Practical Skills Module and any other program content.

Exam security and program integrity are close but not identical. Exam security is about protecting the content and the exam room: no unauthorized devices, no copying, no sharing of questions. Program integrity is the wider idea that the process and the designation stay credible. Cheating, helping others cheat, or leaking content harms both. Exam questions often test whether you can spot which behaviours cross the line.

The standard does not stop you from discussing the program. You may give opinions about the program in general, such as saying the curriculum is hard or that a topic area is covered. You may not reveal specific questions or answers, or disclose which specific material was or was not tested. A candidate who has sat the exam can say it was difficult. The same candidate cannot say that a named topic did not appear.

Key rules to remember

Core rule of VII(A)
Conduct that compromises the integrity, validity or security of CFA Institute programs = violation
Applies to members and candidates in every CFA Institute program, not only the exam.
Confidential Program Information
Do not disclose specific questions, answers, or which specific material was or was not tested
Applies during and after the exam, in any setting, including social media and study groups.
Additional CFA Program Restrictions
Do not break the exam conduct rules, e.g. unauthorized devices, copying, or helping others
Includes bringing or using a device that is not allowed, and any attempt to gain unfair advantage.
Expressing an Opinion
General opinions about the program are allowed if no confidential content is revealed
For example, you may say the exam was hard. You may not say a named topic was absent.
Scope
Standard VII(A) is about conduct in the programs; Standard VII(B) is about how you refer to CFA Institute, the designation and the program
Do not mix them up. Misusing the CFA name or candidacy status is VII(B).

How to solve Guidance for VII(A): Confidential Program Information questions

Use this method for any VII(A) item set or essay question. Apply the official text and keep your answer short and exact.

  1. 1Identify who acts: a member or a candidate. The standard covers both.
  2. 2Identify the conduct: sharing content, using a device, helping someone, or giving an opinion.
  3. 3Ask whether the conduct compromises the integrity, validity or security of the programs, or the reputation or integrity of CFA Institute or the designation.
  4. 4Check the common examples: is confidential program information revealed, such as specific questions, answers, or what was or was not tested?
  5. 5Check whether an exam rule was broken, such as an unauthorized device or copying, even if no content was shared.
  6. 6If the behaviour is only a general opinion about the program with no protected content, conclude it is permitted.
  7. 7State the verdict with the standard name: violated or not violated VII(A).
  8. 8Give the corrective action if asked, such as stop sharing, remove the post, and not repeat the conduct.
  9. 9Check the command word. Use one clear reason per point to earn the points without extra text.

Quickest way: Content-or-rule test

When to use it: Use when you have little time on a multiple-choice item about candidate or member conduct.

  1. Ask: does the action reveal specific exam content or what was tested? If yes, violation.
  2. Ask: does it break an exam rule or help someone else break one? If yes, violation.
  3. Ask: does it otherwise compromise the integrity, validity or security of the programs? If yes, violation.
  4. If it is only a general view on difficulty or the program, it is permitted.
  5. Choose the option that names the exact violation, not a vague or related standard.

Common mistakes in Guidance for VII(A): Confidential Program Information

  • Saying candidates can never talk about the exam after sitting it.

    Students over-learn the confidentiality rule and ignore the opinion allowance.

    Fix: Remember that general opinions are allowed. Specific questions, answers, and what was or was not tested are not.

  • Thinking that saying a topic was not tested is harmless.

    It feels like a general comment, not a leak.

    Fix: Disclosing which specific material was or was not tested reveals confidential program information, so it is a violation.

  • Treating VII(A) as applying only to candidates.

    The exam setting makes it feel like a candidate rule.

    Fix: The standard covers both members and candidates, so a charterholder who leaks content also violates it.

  • Assuming a violation needs content to be shared.

    Students focus on leaks and forget the exam rules.

    Fix: Using an unauthorized device or breaking exam rules is a violation even if nothing is shared.

  • Confusing VII(A) with VII(B).

    Both sit under Standard VII and both involve CFA Institute.

    Fix: VII(A) is conduct as a participant in the programs, including confidentiality. VII(B) is Reference to CFA Institute, the CFA Designation, and the CFA Program, which covers how you refer to them and to your candidacy.

  • Naming the wrong standard, such as Standard III(E), for exam leaks.

    The word confidential triggers the client confidentiality standard.

    Fix: III(E) protects client information. Exam content falls under VII(A).

Worked examples

Example 1

After sitting the exam, a candidate posts in an online forum: The exam was very tough, but I was glad the curriculum was well structured. Did the candidate violate Standard VII(A)?

Show the solution
  1. Identify the conduct: a post giving a general opinion about the exam and curriculum.
  2. Test for confidential content: no specific question, answer, or statement of what was or was not tested is given.
  3. Test for rule breach: no exam rule is broken by the comment.
  4. Apply the permission: general opinions about the program are allowed.

Answer: No violation. The post is a general opinion and reveals no confidential program information.

Example 2

A candidate tells a colleague who will sit the exam next window that the exam had no questions on a particular topic, so the colleague can skip it. Did the candidate violate Standard VII(A)? What should the candidate do?

Show the solution
  1. Identify the conduct: telling another candidate which specific topic was not tested.
  2. Test for confidential content: what was or was not tested is confidential program information.
  3. Note that the disclosure gives the colleague an unfair advantage and harms the integrity and validity of the program.
  4. Conclude that the candidate violated VII(A).
  5. Corrective action: stop sharing such information, ask the colleague not to rely on it, and avoid repeating the conduct.

Answer: Yes, the candidate violated Standard VII(A) by disclosing confidential program information. The candidate should stop and not repeat the disclosure.

Exam tips

  • Look for the trigger words: specific questions, answers, what was tested, unauthorized device, helping others.
  • When the scenario is a vague comment such as hard or fair, expect the answer to be no violation.
  • In an essay, name the standard, state the verdict, then give one reason tied to the integrity, validity or security of the programs, such as confidential content or an exam rule.
  • Do not pick Standard III(E) for exam content. Pick VII(A).
  • Read the command word. If it says recommend or state action, give the corrective step and stop.

Guidance for VII(A): Confidential Program Information in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Guidance for VII(A): Confidential Program Information: frequently asked questions

Can CFA Level III candidates discuss exam questions after the exam?

No. You may not disclose specific questions, answers, or what was or was not tested. You may give general opinions, such as that the exam was difficult, if they reveal no protected content.

What is the difference between exam security and program integrity?

Exam security is about protecting exam content and conduct, such as devices and copying. Program integrity is wider and covers the credibility of the programs and the designation. Cheating or leaking content harms both.

How do I report CFA exam cheating by others?

The Code and Standards do not impose a specific duty to report under VII(A). To report suspected misconduct, check the current CFA Institute website or contact CFA Institute directly for the reporting channels.

Does Standard VII(A) apply to charterholders as well as candidates?

Yes. It applies to both members and candidates and covers all CFA Institute programs.