Learn as you go
Choose an answer, reveal the key, and review available explanations, citations and candidate context.
25 questions free
Start guided practiceEnterprise IT risk in practice: governance structures, risk assessment methodology, response and reporting, and the technology and security knowledge needed to evaluate controls.
ISACA does not publish numeric exam codes — CRISC is the common abbreviation.
Certified in Risk and Information Systems Control is ISACA's professional-level governance, risk & compliance certification, referred to across the industry by the shorthand CRISC. The exam runs for 4 hours and presents up to 150 questions, with a pass mark of 450 / 800 (scaled). It costs US$760 at the standard rate.
ISACA publishes the syllabus as 4 weighted domains. Risk Response and Reporting carries the most weight at 32%, and the three largest domains together account for roughly 80% of the scored content — worth knowing before you decide where study time goes.
Confirm these details on the official ISACA page before booking — vendors adjust format and pricing without notice.
Some forms include unscored trial questions
Standard rate, before local taxes
The published exam guide for CRISC, in the vendor's own order.
01Governance
26%02IT Risk Assessment
20%03Risk Response and Reporting
32%04Information Technology and Security
22%Three years of IT risk management and control experience.
Professional level — Advanced credentials covering design, scale and trade-off decisions.
Preview 25 supported questions before unlocking the 1,448-question CRISC bank.
Community-contributedCompiled from publicly posted community exam discussions. Contributed by third parties rather than written here, so accuracy varies and most items carry no explanation. Progress and bookmarks stay in this browser.
Answer support: 591 explanations, 1,428 questions with candidate context and 10 questions with direct citations. Bank updated .
Choose an answer, reveal the key, and review available explanations, citations and candidate context.
25 questions free
Start guided practiceKeep answers hidden on the clock and review every miss only after you finish the public sample.
Free sample mock
Open timed mockWant the complete 1,448-question bank?
One Exam Pass unlocks this selected bank for 12 months with no renewal.
Compiled from exam discussions posted publicly by other people on ExamTopics. Copyright in each contribution rests with its original author; it is reproduced here for study. Not verified by us — most items carry no explanation. To request removal, see our content policy.
ISACA lists up to 150 questions, to be completed in 4 hours. Question counts can vary slightly between exam forms, and unscored trial questions are sometimes included.
450 / 800 (scaled). Confirm the current figure on the official exam page before booking, as vendors adjust cut scores when an exam form is refreshed.
The standard price is US$760. Local pricing, taxes and any retake policy vary by region, so check the official page for the figure that applies to you.
Three years of IT risk management and control experience.
The exam guide covers Governance, IT Risk Assessment, Risk Response and Reporting and Information Technology and Security. The full weighted breakdown is listed above.
Yes — this exam has 1448 practice questions available here, each with the correct answer marked. They are community-contributed, compiled from exam discussions posted publicly by other people rather than written here, and most do not carry an explanation.