
This course contains the use of artificial intelligence.
CRISC (Certified in Risk and Information Systems Control) is ISACA's leading credential for IT risk practitioners — the natural complement to CISM and CISA for anyone who identifies, assesses, and responds to IT risk on behalf of the business. This course, built and taught by Aseem Mankotia, walks through all four domains of the current CRISC exam content outline — Governance (26%), IT Risk Assessment (20%), Risk Response and Reporting (32%), and Information Technology and Security (22%) — with a strict focus on the risk-judgment mindset the exam actually rewards: aligning decisions to risk appetite and tolerance, identifying the correct risk or control owner, prioritizing by likelihood and impact, and choosing the response that addresses the root risk rather than a symptom. Before you enroll, know what full certification requires: the exam itself is 150 multiple-choice questions across 4 hours, scored on a 200-800 scale with a minimum score of 450 out of 800, at an approximate cost of USD 575 for non-members or USD 460 for ISACA members (confirm current pricing on ISACA's site). Certification also requires at least three years of verified IT risk management and IS control experience — no substitutions or waivers — plus ongoing CPE maintenance, so this course is one part of a longer professional path, not a substitute for it.
Every chapter is scenario- and judgment-based rather than a rote definitions dump: you'll work through enterprise-style situations covering the three lines model, risk appetite versus tolerance, the risk register and risk scenarios, inherent versus residual risk, quantitative and qualitative analysis, control design and ownership, third-party risk, KRIs and KCIs, control testing, and risk reporting to stakeholders and the board — the exact areas ISACA weights most heavily, with Domain 3 (Risk Response and Reporting) and Domain 1 (Governance) given proportionally more chapter time because they carry the most exam weight. Domain 4's technology and security content is taught at the depth a risk practitioner needs to evaluate and respond to risk, not as hands-on engineering, keeping the course squarely aligned to what the exam tests.
The course closes with a full 150-question exam simulation walkthrough, complete with a 4-hour time-management plan and reasoning for every answer choice, so you finish with a clear, practiced approach to the real exam-day experience. Please verify the current CRISC exam content outline, format, fees, and experience requirements on ISACA's official CRISC page before scheduling your exam — this course anchors to that outline but ISACA updates it periodically.
AI content disclosure: This course was produced with the assistance of artificial intelligence tools. Lecture narration is AI-voice generated, and lecture scripts, slides, and practice questions were drafted with AI assistance, then reviewed and curated by the instructor for technical accuracy and alignment with the official CRISC exam guide.