CRISC exam domains
The CRISC exam is weighted across 4 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.
| Exam domain | Exam weight | Practice |
|---|---|---|
| Governance | 26% | Practice this topic |
| Risk Assessment | 22% | Practice this topic |
| Risk Response and Reporting | 32% | Practice this topic |
| Technology and Security | 20% | Practice this topic |
Sample CRISC questions
A sample of the CRISC questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.
- A mid-sized financial services firm has just acquired a smaller fintech company that operated with an informal, spreadsheet-based approach to risk tra…View question
- A manufacturing company recently redesigned its procurement process to speed up vendor onboarding, allowing purchasing managers to approve new supplie…View question
- A newly appointed CRISC-certified risk practitioner reviews the enterprise risk register and finds that many identified risks are documented in techni…View question
- A newly appointed CRISC-certified risk practitioner reviews the information security department's annual goals. The goals emphasize maximizing the num…View question
- A risk practitioner is conducting a risk assessment for a customer-facing e-commerce platform. During the initial data-gathering phase, the practition…View question
- A risk analyst is assessing the likelihood of a targeted intrusion against a customer-facing payment portal. Historical internal incident data is spar…View question
- A risk practitioner is conducting a business impact analysis (BIA) for an order-processing application. Business owners assert the system is 'mission…View question
- During a business impact analysis for an order-processing application, the business owner asserts that the application must be recovered within one ho…View question
- A risk practitioner is supporting a business impact analysis (BIA) for a mid-sized insurer. Two applications are being evaluated: a claims-processing…View question
- A financial services firm is deploying a smart contract on a public blockchain to automate loan disbursements. During a pre-deployment risk review, a…View question
Key CRISC terms
Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the CRISC exam.
CRISC frequently asked questions
What is the CRISC certification?+
CRISC is widely regarded as a leading certification for IT risk management and is common in job listings for risk and control professionals.
It emphasizes the full risk lifecycle — identification, assessment, response, and monitoring — so success rewards risk judgment rather than tool-specific skills.
What topics are on the CRISC exam?+
The CRISC exam is organised into four weighted domains. The percentages below are ISACA’s official weightings for the current exam content outline, so bias your study toward the heaviest domain — Risk Response and Reporting is the largest, followed by Governance.
Governance (26%)
Covers organizational strategy and structure, culture, policies and standards, and risk governance — enterprise risk management, the risk management framework, three lines of defense, risk appetite/tolerance/capacity, and legal, regulatory, and ethical requirements.
Risk Assessment (22%)
Covers risk events and threat modeling, the threat landscape, vulnerability and control-deficiency analysis, assessment concepts and frameworks, the risk register, quantitative and qualitative analysis, business impact analysis, and inherent versus residual risk.
Risk Response and Reporting (32%)
The largest domain. Covers risk response options (accept, mitigate, transfer, avoid) and their selection, control design and ownership, third-party risk, control monitoring, issues and exceptions management, emerging risk, KRIs and KPIs, and risk reporting to stakeholders.
Technology and Security (20%)
Covers enterprise architecture, IT operations and project management, disaster recovery and data lifecycle management, the SDLC, emerging technologies and their risk, information security concepts and frameworks, awareness programs, and data privacy principles.
Is the CRISC hard?+
CRISC is challenging because it demands risk-based judgment: you must choose the best response for a given risk relative to the organization’s appetite, not the most technical control.
The four domains span the whole IT risk lifecycle, and the heavy weighting on risk response and reporting rewards practical risk-management experience.
How many questions are on the CRISC exam and how long is it?+
The CRISC exam consists of 150 multiple-choice questions to be completed in 4 hours (240 minutes).
Our full-length practice mock uses a 100-question, 180-minute session so you can rehearse pacing and risk-based reasoning across all four domains before test day.
What score do you need to pass the CRISC?+
ISACA scores CRISC on a scaled range of 200 to 800, and you need a scaled score of 450 to pass. Your raw performance is converted to this scaled score, and there is no penalty for guessing, so answer everything. Our practice mock uses a 70% threshold as a study checkpoint; aim comfortably beyond it before test day.
How much does the CRISC exam cost?+
The CRISC exam fee is set by ISACA and differs for members and non-members — check the ISACA site for current pricing. Certification also requires meeting the work-experience requirement and paying annual maintenance fees with continuing professional education (CPE). Everything on this hub is free.
Who should take the CRISC?+
CRISC is aimed at risk professionals, control practitioners, and IT and business managers who manage IT risk.
ISACA requires three years of experience in IT risk management and information systems control to certify, with no experience waivers. You can pass the exam first and claim the experience within five years.
What jobs and salaries can the CRISC lead to?+
CRISC maps to roles such as IT risk manager, risk and control analyst, compliance manager, and information security risk officer.
How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. CRISC is best viewed as validation of IT risk-management competence.
How long does it take to study for the CRISC?+
Experienced candidates often need two to three months of steady study, focused on the risk-based mindset the exam rewards.
Review every explanation, including for questions you answered correctly, because CRISC distractors are built from plausible but sub-optimal risk choices. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.
How should you prepare for the CRISC?+
Study the four domains above, giving the heaviest weight to Risk Response and Reporting, then drill scenario questions domain by domain. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.
When you can reason to the best risk response comfortably, move to full-length timed mocks. Use the glossary to keep concepts like risk appetite, inherent versus residual risk, KRIs, and the three lines of defense straight, and aim to score consistently above the checkpoint before you book.
Can you take the CRISC exam online?+
Yes. ISACA offers CRISC through remote online proctoring as well as at in-person test centers, so you can choose the option that suits you. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.
If you do not pass, ISACA lets you retake the exam, with a limited number of attempts allowed per rolling twelve-month period — check the current policy before rebooking.
What certification should you take after the CRISC?+
After CRISC, common next steps include ISACA’s CISM for security management or CISA for audit, depending on your focus.
For many, the real next step is owning an enterprise IT risk program. Pairing CRISC with hands-on risk management is what turns the certificate into a career.