ISACA (Information Systems Audit and Control Association)
Audit, risk, security management and governance credentials used widely in regulated industries and internal audit functions.
ISACA credentials sit at the governance layer rather than the technical one. They are common requirements for internal audit, risk and security management roles, particularly in banking, insurance and public sector organisations.
All the flagship exams share a format: 150 multiple-choice questions over four hours, scored on a 200–800 scale with 450 as the pass mark. That scale is not a percentage, so a "450" is not 56% correct.
Every credential requires verified professional experience in addition to the exam, and is maintained through continuing professional education credits and an annual fee.
Professional4
Advanced credentials covering design, scale and trade-off decisions.
Expert2
The highest tier, usually requiring a prerequisite certification.
Filter by practice availability, category, level or exam code. Retired exams are hidden by default.
6 exams
The benchmark IT audit credential: the audit process itself, IT governance and management, systems acquisition and development, operations and resilience, and protection of information assets.
Security management rather than security engineering: governance, risk management, building and running a security programme, and managing incidents at an organisational level.
Enterprise IT risk in practice: governance structures, risk assessment methodology, response and reporting, and the technology and security knowledge needed to evaluate controls.
Technical privacy implementation: privacy governance and programme structure, privacy architecture across infrastructure and applications, and managing the data lifecycle.
Enterprise IT governance at executive level: governance frameworks and structures, resource management, benefits realisation, and optimising risk across the IT portfolio.
An advanced audit credential aimed at AI systems: governance and risk frameworks for AI, auditing models and data pipelines, and reporting on AI assurance.
How the ISACA ladder is structured, from entry point to the top tier.
Advanced credentials covering design, scale and trade-off decisions.
The highest tier, usually requiring a prerequisite certification.
ISACA exams with an available question bank. Each bank shows its source, licence and answer-support coverage.
Categories and topics that run through the ISACA catalog.
This directory currently lists 6 ISACA exams across 2 levels (Professional and Expert). ISACA adds and retires exams regularly, so treat this as a working map rather than a permanent one.
The best-known active options in this directory include Certified Information Systems Auditor, Certified Information Security Manager and Certified in Risk and Information Systems Control. Compare their levels, syllabus domains and role focus before choosing one.
Yes — 6 ISACA exams have 4,864 practice questions in total. 2,381 questions currently carry an explanation. Every bank is labelled with its source and licence; 6 community-contributed banks are available.
15 categories · browse by technology · all providers