CRISC Exam Study Guide 2026: Updated Domains and Risk-Decision Practice

A current CRISC study plan for governance, risk assessment, response and reporting, technology and security, and decision-focused practice.

CertGuru Editorial Team · Published 2026-07-20 · Reviewed 2026-07-20 · 10 min read

What does the CRISC exam cover in 2026?

The Certified in Risk and Information Systems Control (CRISC) exam measures how well you connect enterprise governance, IT risk assessment, risk response, controls, reporting, technology, and security. A useful CRISC study guide for 2026 therefore needs more than security terminology. It should train you to reason from business objectives, risk ownership, stakeholder decisions, and evidence.

ISACA's current outline lists 150 questions across four job-practice domains:

  • Governance: 26%;
  • Risk Assessment: 22%;
  • Risk Response and Reporting: 32%; and
  • Technology and Security: 20%.

Risk Response and Reporting has the largest weighting, but the domains operate together. A scenario may begin with a technology change, require a risk assessment, lead to a treatment recommendation, and finish with metrics for decision-makers.

How to study each CRISC domain

Domain 1: Governance

Learn how strategy, objectives, organizational structure, culture, policies, resilience, and asset management shape risk decisions. Be able to distinguish risk appetite from risk tolerance and connect both to the enterprise risk-management framework.

The exam perspective is not simply “reduce every risk.” Organizations take risk to create value. The better response is the one aligned to objectives, authority, legal and contractual obligations, and an approved risk process.

Domain 2: Risk Assessment

Study risk events, threat modelling, vulnerabilities, scenarios, business impact analysis, risk registers, analysis methods, and inherent versus residual risk. Practise writing a scenario with an asset or objective, threat, vulnerability, event, likelihood, and business impact.

Do not treat a vulnerability score as a complete risk assessment. Context determines whether a technical weakness creates material enterprise risk.

Domain 3: Risk Response and Reporting

Cover risk response options, risk and control ownership, vendor and supply-chain risk, issues and exceptions, control design, implementation, testing, action plans, and reporting. Know the distinct purpose of key risk indicators, key control indicators, and key performance indicators.

Questions often turn on decision rights. A risk practitioner may assess, advise, monitor, validate, and report, while the appropriate business owner accepts a risk. Watch for answers that bypass the owner or implement a control before requirements and causes are understood.

Domain 4: Technology and Security

Connect architecture, operations, emerging technology, data lifecycle, systems development, security principles, and control environments to risk. Technical detail matters when it changes likelihood, impact, control effectiveness, or resilience. It should support a risk conclusion rather than replace one.

ISACA now explicitly discusses emerging technology and AI risk in its CRISC material. Focus on how new technology changes governance, data, third-party exposure, monitoring, and risk scenarios—not on memorising one product.

A six-week CRISC preparation plan

Week 1: establish the enterprise-risk model

Download the current outline and build a glossary for objective, asset, threat, vulnerability, event, likelihood, impact, inherent risk, control, residual risk, appetite, tolerance, owner, and treatment. Take a diagnostic and map every miss to a domain.

Week 2: governance and risk ownership

Trace decisions from strategy through policies, appetite, roles, and reporting. Practise identifying who provides information, who recommends action, who owns a control, and who accepts risk.

Week 3: assessment and scenarios

Write risk scenarios for a cloud migration, critical supplier, privileged account, ransomware event, and AI-enabled process. Compare qualitative and quantitative analysis and state what additional evidence would make each assessment defensible.

Week 4: response and control design

For each scenario, evaluate avoidance, mitigation, transfer or sharing, and acceptance. Select controls based on requirements and root causes. Then define how design and operating effectiveness would be tested.

Week 5: monitoring and reporting

Create a small dashboard containing a KRI, KCI, KPI, threshold, owner, reporting audience, and escalation rule. Practise explaining trends without hiding uncertainty behind a single heat-map colour.

Week 6: timed CRISC practice tests

Complete a full 150-question simulation. Review all incorrect and uncertain answers, then group them by reasoning fault: wrong owner, premature action, weak evidence, control-versus-risk confusion, or poor stakeholder communication.

A decision sequence for CRISC scenario questions

When several choices appear plausible, use this order:

  1. Identify the business objective and affected stakeholder.
  2. Determine the material risk and available evidence.
  3. Confirm ownership, authority, appetite, and policy.
  4. Locate the scenario in the risk lifecycle.
  5. Choose the action that supports an informed decision at that stage.
  6. Preserve monitoring, reporting, and accountability.

Words such as first, best, most important, and greatest matter. A technically strong control may still be premature if assessment, ownership, or requirements are missing.

CRISC exam and certification are not the same step

Passing the exam does not by itself complete the CRISC certification. ISACA also requires an application, qualifying experience, adherence to its ethics requirements, and ongoing continuing professional education. Check the current experience rules and application window directly with ISACA before planning your credential path.

CRISC knowledge is relevant to IT risk, governance, security assurance, controls, resilience, third-party risk, and technology oversight. The credential can support those career conversations, but it does not guarantee a particular role or outcome.

After reviewing the official outline, use the CertGuru CRISC mock exam for a domain baseline. Compare the management perspective in the CISM 2026 exam guide and the assurance perspective in the CISA preparation guide. Use the mock-exam review guide to convert scores into a correction plan.

CertGuru is independent and is not affiliated with or endorsed by ISACA.

Authoritative references

ISACA may revise objectives, policies, fees, and certification requirements. Confirm the current official information before registering.

Related preparation paths