You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified in Risk and Information Systems Control (CRISC) certification validates your expertise in identifying and managing enterprise IT risk and implementing and maintaining information systems controls. Designed for mid to advanced-career IT professionals focused on IT and cyber risk, CRISC equips you to enhance business resilience, deliver stakeholder value, and address emerging technologies like AI. Earning CRISC demonstrates your ability to optimize risk management across the enterprise and positions you among the top-paying certified professionals worldwide.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Certified in Risk and Information Systems Control (CRISC) certification is ISACA's premier credential for IT risk management professionals. It validates your ability to identify, assess, and manage enterprise IT risk while designing and implementing effective information systems controls. CRISC holders are equipped to take a proactive approach to risk, enhancing business resilience and delivering stakeholder value across the organization.
The CRISC certification focuses on four key domains: Governance, Risk Assessment, Risk Response and Reporting, and Technology and Security. By earning CRISC, you demonstrate mastery of real-world risk management practices, from establishing risk appetite and tolerance to monitoring and reporting on risk and control metrics. As a CRISC, you will be ready to address emerging technologies, including AI risk assessment and general best practices for risk management and mitigation related to AI data governance and ethics.
The CRISC certification is designed for mid to advanced-career IT professionals with a focus on IT and cyber risk and control. It is ideal for risk professionals, IT auditors, compliance officers, and security managers who are responsible for identifying and managing enterprise IT risk and implementing and maintaining information systems controls. If you are looking to gain instant recognition and credibility in the risk management field and boost your career, CRISC can provide the leverage you need to grow. The certification is globally accepted and recognized, and it is required for many organizations and government agencies.
ISACA recommends that candidates have at least three years of work experience in at least three of the four CRISC domains, with at least one year of experience in at least one of the domains. However, this experience is not a prerequisite to take the exam; it is required to apply for certification after passing the exam. Experience in IT risk management, including risk identification, assessment, and response; Experience in implementing and maintaining information systems controls; Experience in governance of enterprise IT, including risk appetite and tolerance; Experience in technology and security, including security concepts and frameworks
Every domain and objective ISACA measures, with the weight they carry on the exam.
The official ISACA exam outline · checked 30 July 2026 · See the source
Everything ISACA publishes about sitting it, and nothing we inferred.
At least three years of work experience in at least three of the four CRISC domains, with at least one year of experience in at least one of the domains.
The path ISACA lays out, how the credential is kept, and where to book.
Step-by-step path to Certified in Risk and Information Systems Control
CRISC certification must be maintained annually by earning and reporting Continuing Professional Education (CPE) credits. The annual CPE requirement is 20 credits, with a minimum of 120 CPE credits over a three-year period. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.
Register for the exam through PSI, ISACA’s authorized testing partner.
Schedule your examVisit the official ISACA certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksCRISC and CISA are separate certifications. CRISC focuses on IT risk management and information systems control, while CISA focuses on information systems auditing. They are not replacements for each other, but they complement each other for professionals in risk and audit roles.
No. There are no mandatory prerequisites to take the CRISC exam. However, to earn the CRISC certification, you must meet the work experience requirements and adhere to ISACA's Code of Professional Ethics and CPE policy.
After registering and paying the exam fee, you can schedule your exam through the PSI dashboard. You can reschedule anytime without penalty during your eligibility period if done at least 48 hours before your scheduled appointment.
You must present a valid government-issued photo ID that matches the name on your ISACA account. For remote proctoring, additional requirements may apply as outlined in the Remote Proctoring Guide.
ISACA has a zero-tolerance policy for fraudulent test-taking activities. Candidates involved in fraudulent activities will be subject to score nullification and/or certification revocation. Specific retake policies are detailed in the Terms of Use – 16. Exams.
No. The CRISC exam is a computer-based multiple-choice exam. It does not include hands-on labs or performance-based tasks.
ISACA does not publish a specific timeline for score reporting. Candidates are advised to refer to the Exam Candidate Guide for details on score availability and reporting.
CRISC is designed for IT risk management professionals, including risk managers, IT auditors, compliance officers, and security managers who are responsible for identifying and managing enterprise IT risk and implementing information systems controls.
No. CRISC certification must be maintained by earning CPE credits. Passing another ISACA exam does not automatically renew CRISC, but it may contribute to your CPE requirements.
The CRISC exam is administered at authorized PSI testing centers globally and as a remotely proctored exam. Availability may vary by region, and candidates should verify PSI test site availability before registering.
Every domain, every objective, and every concept ISACA measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISACA exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
27 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 20 objectives, 155 concepts written under them, and free questions against every one. When ISACA changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.