Certified in Risk and Information Systems Control Practice Exams

CRISC
⭐ Most popularAdvancedProfessionalIT Risk Manager

ISACA's credential for IT risk management professionals. Validates the ability to govern risk, identify and assess IT risk, design and implement risk responses and controls, and report on risk using indicators that support business decisions.

240
minutes
70%
passing score
$760
exam fee

Start preparing today

5 flashcard sets · 5 learning tests · 2 timed exams · 150-question bank

Start Free Practice →

Overview

What this certification is and how the exam works.

The CRISC (Certified in Risk and Information Systems Control) is ISACA's credential for professionals who identify and manage enterprise IT risk and implement information systems controls. It covers four domains: Governance (26%); IT Risk Assessment (22%); Risk Response and Reporting (32%); and Information Technology and Security (20%). The exam is 150 items in 4 hours, scored on a 200–800 scale with 450 required to pass. Candidates need three years of cumulative experience in IT risk management and control across at least two of the four domains, one of which must be Domain 1 or Domain 2, with no experience waivers available.

Why should I take the exam?

What this credential does for your career.

  • 1The leading credential specifically for IT risk management, distinct from audit (CISA) and security management (CISM)
  • 2Proves you can translate technical exposure into business risk language that executives and boards act on
  • 3Consistently ranked among the highest-paying IT certifications, and widely requested for risk and GRC roles
  • 4Aligns with enterprise risk frameworks and the COBIT and Risk IT bodies of knowledge used across regulated industries

Skills measured

What you need to know to pass this exam.

  • Align IT risk management with enterprise governance, strategy, culture, and the three lines of defense
  • Establish and apply risk appetite, tolerance, and capacity so treatment decisions are consistent and defensible
  • Identify IT risk through scenario development, threat and vulnerability analysis, and control deficiency review
  • Analyze and evaluate risk using qualitative and quantitative methods, including inherent and residual risk
  • Maintain a risk register with defined risk owners, treatment plans, and tracked issues and exceptions
  • Select risk responses — mitigate, transfer, avoid, or accept — and justify them against appetite and cost
  • Design, implement, and test controls, evaluating both design adequacy and operating effectiveness
  • Monitor risk and controls using KRIs, KPIs, and KCIs with defined thresholds and escalation triggers
  • Report risk to stakeholders using heat maps, dashboards, and scorecards tailored to the audience
  • Assess risk arising from technology and security practices: architecture, operations, data lifecycle, and emerging technology

Prerequisites

Credentials required before you can earn this certification.

🔑
Three years cumulative experience in IT risk management and information systems control
Experience must span at least two of the four domains, including Domain 1 or Domain 2. No experience substitutions or waivers are available; the exam may be passed first and experience submitted within five years

About our CRISC practice exams

Our Certified in Risk and Information Systems Control CRISC question bank holds 150 exam-style questions with a written explanation on every answer, mapped to the four exam domains published for CRISC, covering Governance, IT Risk Assessment, Risk Response and Reporting and Information Technology and Security.

Alongside the bank there are two full-length timed exams at the real 240-minute limit and 70% pass mark, plus five topic-based learning tests for working a single domain at a time. Randomised mock exams are dealt on demand from the full 150-question pool, so you never run out of fresh papers.

Questions
150
Exam domains
4
Timed exams
2
Pass mark
70%

How our practice content is created

Practice questions are independently developed using the official ISACA CRISC exam guide and ISACA documentation. Each question is checked for alignment with the current exam objectives and reviewed for technical accuracy before publication.

The CRISC bank cites 1 distinct ISACA documentation page, and every question links the source it was written against — so you can check any answer at first hand.

Official CRISC exam guide

ISACA is a trademark of its respective owner. This is an independent study resource and is not affiliated with, endorsed by, or authorised by ISACA.

Related certifications

Credentials that pair well with this exam or come next on the path.

Official resources

Provider documentation and study material for this exam.

Start Free Practice →

5 flashcard sets · 5 learning tests · 2 timed exams · 150-question bank