
110 slides on key exam focus areas.
Certifications propelled my career in internal audit and risk management, from CMA and CIA to CRM, CFSA, CSA, and IIA leadership across banks and brands.
Explore the CRMA exam strategy, including format, timing, and language considerations, and compare pass rates before and after the 2021 syllabus expansion.
Plan the CRM A exam with 2–3 months of revision and hundreds of practice questions, focusing on new questions across all parts before testing at Pearson VUE centers or online.
Explore what this CRMA lecture covers and does not, and contrast awareness versus proficiency in CIA and CRM, with recommended review areas.
Explore internal audits and governance of risk management, then assurance over risk management, with practical risk assessments, risk and control self-assessments, monitoring, and maturity models.
Explore the internal audit function's role in managing organizational risks and how enterprise risk management emphasizes goals, uncertainty, and opportunities.
Enterprise risk management applies risk management across the entire organization to identify events that could hinder goals and objectives, from shareholder returns to reputation and sustainable practices.
Contrast risk management with enterprise risk management, showing risk management as mitigating risks and being risk averse, while ERM is organization-wide, strategy-driven, and interrelates risks.
Explore the three core components of enterprise risk management: board oversight, management implementation, and internal audit, all aligned to risk appetite and COSO frameworks.
Mastering erm documentation by linking policy and risk appetite statements to strategic risk registers and guidelines, clarifying entity and department risk structures and controls.
Explore the COSO enterprise risk management model and its integration with strategy and performance, learn how to identify the portfolio view, and recognize how CRM questions test precise model knowledge.
Explore the coso helix’s five components—governance and culture, strategy and objective setting, performance, review and revision, information, communication and reporting—and map 20 steps to a portfolio view of risks.
Explore risk management maturity as a benchmarking framework that measures how fully an organization implements risk management measures, using a CMMI-based model and noting other maturity models.
Trace how risk management matured from ad hoc firefighting to an optimized, policy-driven program with documentation, policies, KPIs, KRIs, contingency plans, and board-led risk culture.
Strengthen risk culture and integrate risk into decision making and rewards through the risk management maturity model, and enhance governance, management training, and improve risk aggregation, reporting, and cybersecurity.
See how risk information ownership matures from internal audit in the initial stage to a shared, policy-driven process across functions. Aligns risk appetite, ratings, and reporting for strategic decisions.
Learn how to apply risk management maturity models to conduct internal audits, assess organizational maturity across initial, managed, and defined stages, and tailor governance, reporting, and risk understanding to departments.
Maintain objectivity through functional independence from management, adherence to standards and ethics, and avoidance of appearance of conflicts of interest, with disciplined procedures, supervision, and safeguards to ensure unbiased reporting.
Examine threats to objectivity in internal auditing, including self-interest, self-review, advocacy, familiarity, intimidation, and lack of proficiency. Learn how independence supports objective work and guard against these threats.
Explore threats to internal audit independence and objectivity, emphasizing the mandate, board accountability, access to resources, and freedom from management interference in reporting results.
Internal audit operates across a continuum from auditing risk management to providing data and insights that actively support risk processes, while never assuming risk ownership and always upholding standards.
Explore IIA standard 2120 on internal audit's role in risk management, evaluating governance, operations, and information systems, considering fraud risk, and integrating consulting insights into assurance engagements.
Explore the COSO ERM fan to understand internal audit roles in risk management, including core duties, assurance on the risk management process, safeguards, and prohibitions.
Identify legitimate internal audit roles with safeguards that facilitate risk identification and cross-department coordination, while avoiding risk ownership or prescribing controls, to support enterprise risk management development and board approval.
Explore forbidden internal audit roles in ERM, such as setting risk appetite, imposing risk management processes, providing management assurance, and deciding or implementing risk responses.
Examine internal audit's role in enterprise risk management, including assurance on risk processes and developing the erm framework, while noting prohibited actions like risk response decisions.
Internal auditors coordinate with internal and external assurance and consulting providers under IIA standard 205 on coordination and reliance, sharing information to reduce duplication and leverage others' controls.
Share plans, data, and findings to enhance risk management, coordinate with assurance providers for broader coverage with fewer resources, and rely on solid controls to avoid duplicating tests.
Explore how continuous monitoring, embedded modules, and proper information systems enable real-time detection of control failures, supported by proper data warehousing, flow of information, and reporting of risks.
Analyze risk measurement methods, including risk exposure, expected loss, sensitivity analysis, stress testing, and key risk indicators to assess changes in risk and resilience.
Understand the three lines of defence model in banking: first line risk owners, second line oversight, and third line assurance, with board governance, risk appetite, and strict or blended separations.
Describe risk assurance mapping using first, second, and third lines of defense to visualize risk owners, controls, inherent risk ratings, and audit coverage across risk categories.
Explore a typical board governance model for risk, detailing the audit and risk committees, the chief audit executive, and the chief risk officer's role in enterprise risk management oversight.
Evaluate board and risk committee processes to strengthen risk management governance. Provide insight to the board, benchmark practices, address new risks, and ensure timely reporting.
Internal audit must assess governance processes across strategic and operational decision making, risk management, ethics, accountability, and performance management, within three years, coordinating reporting with the board and assurance providers.
Explore COSO's enterprise risk management cube, linking internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring to align with organizational goals.
Explore how the external environment—political, economic, social, technological, environmental, and legal factors—shapes risk management, and contrast it with the internal environment and the board’s control environment.
Define your organization's risk appetite and acceptable risk to set clear risk-taking boundaries, quantify risk types and amounts, and align risk communication, culture, and planning with strategy.
Examine how a risk appetite statement guides investment choices, prohibiting tobacco, marijuana, and online gambling, and set acceptable risks such as interest rate, credit, liquidity, currency, and basis risk.
Evaluate an organization's risk capacity using Sobel and Reding's capability criteria, balancing readiness, agility, controllability, monitoring, and maturity to enhance resilience and risk response.
Explore risk evaluation measures, including risk appetite, risk level, risk severity, risk capacity, and risk tolerance, with graphical insights into boundaries of acceptable risk as an exam focus area.
Explore how risk levels align with risk appetite, tolerance, and capacity using volatility, value at risk, and portfolio examples, with insights from an internal auditor on opportunity cost and reporting.
Identify and balance risks across the organization by mapping the risk universe, defining a target risk profile, and aligning with risk appetite to compare with actual risk profile for equilibrium.
Identify risk universe as all risks affecting objectives, including new security, strategic, economic profitability, systemic risk, regulatory change, and new operational risks, then map to the audit universe to plan.
Illustrate how likelihood and impact map to risk levels, defining risk appetite, target risk profile, and risk tolerance, with cash thresholds guiding acceptable and unacceptable risks.
Identify the main functions of controls—directive, preventive, detective, and corrective—and see how guidelines, training, incentives, access restrictions, approvals, maintenance, reconciliations, exception reports, and audits mitigate risks.
Develop and monitor lead indicators and controls for emerging risks, tracing triggers, root causes, intermediate events, risk events, and consequences across a risk timeline.
explain audit risk as the residual undetected risk after inherent, control, and detection risks, and relate it to material misstatement and subsequent events in financial statements.
Explore key risk management frameworks, including COSO, ISO 31000, COBIT, GATE, and the NIST risk management framework, to guide enterprise governance and IT risk management across organizations.
Explore the COSO ERM framework roles, from the board’s oversight and risk appetite to management execution, the risk officer, internal audit, finance, and the three lines of defense.
Apply ISO 31000 risk management principles to create value by integrating risk reporting into decision making across the organization, using structured, unambiguous processes and top-down, bottom-up communication.
Compare COSO ERM and ISO 31000 components, showing they match; map internal environment and objective setting to ISO chapters, and identify risk evaluation as COSO's risk assessment.
Explore the COSO internal control cube, its five components and the three control objectives—operations, reporting, and compliance—and see how risk assessment informs control activities, information and communication, and monitoring.
Explore how the risk culture framework from the institute of risk management shapes risk management by linking personal attitudes toward risk, personal ethics, group behavior, and organizational culture, and recruitment.
Explore the McKinsey 7S model, detailing seven elements—structure, systems, style, staff, skills, strategy, shared values—and distinguish hard elements from soft ones, guided by leadership and risk culture.
Internal audit must assess emerging risks, given high uncertainty, to ensure coverage of significant risks that affect objectives and balance positive risk with negative risk.
Assess emerging risks from a breakthrough in manufacturing technology and expansion into new markets, and explore how ERP adoption and enhanced planning reduce uncertainty toward pure risk.
Identify risks through workshops and face-to-face interviews with frontline staff, applying a bottom-up approach to surface risks to objective achievement, including control self-assessment.
Identify and discuss process risks through a bottom-up brainstorming session where operational staff and internal auditors collaborate on CRSA to map inputs to outputs and improve risk responses.
Assess processes to identify single points of failure, bottlenecks, and redundancy gaps, contrasting slack with overreliance on a single system such as online payments for business continuity.
Explore scenario planning using decision trees and sensitivity analysis to assess a bank's capital adequacy under Basel II across scenarios like recession and rising interest rates, highlighting organizational vulnerability.
Benchmarking risk management involves comparing practices to standards such as ISO 31000 and COSO, identifying gaps, and using internal policies to assure compliance and improvements.
Explore risk assessment techniques with a risk event map that plots incidents by impact and likelihood, helping auditors identify the most impactful and likely events.
Define likelihood and impact through a formal policy that standardizes definitions across the organization, aligning high risk with board-level oversight and low risk with operational-level management, including reputational risks.
Explore six steps to assessing risk management, from understanding the organization context and gathering information to establishing scopes, allocating resources, performing the audit, and reporting results.
Gather board and risk committee minutes, charters, terms of reference, and risk policies to identify risks early, support decision making, and inform regulatory reporting through risk assessments and inventories.
Identify and evaluate risks via a risk inventory, map significant risks on a likelihood-impact graph, and examine process controls with workflows, flowcharts, and escalation procedures.
Establish the scope and objectives for risk management using external criteria such as laws and regulations and internal criteria like risk policies and procedures, and incorporate best practices.
Define data analytics for internal audit by gathering and analyzing data to extract insights that inform decision making, with emphasis on big data, artificial intelligence, and automated processes.
Explore how internal audit and risk management add value by identifying and evaluating risks, and predict future risks through four data analytics types: descriptive, diagnostic, predictive, and prescriptive.
Describe and summarize data to understand what is going on and what has happened. Aggregate data from multiple sources, compute averages, and present descriptive findings for management and auditors.
Explore predictive data analytics, using forecasts and interdependencies to predict future performance and trends, with machine learning, statistical models, and applications like dynamic pricing and seasonal sales.
Explore prescriptive analytics, a subcategory of predictive analytics, that recommends actions by analyzing data and showing the implications of different decisions in contexts like commodities or weather.
Explore how a T function graph of daily network access incident tickets over a month illustrates descriptive data analytics, showing the data as it is rather than predicting or prescribing.
Explore prescriptive data analytics that anticipate exceptions and automatically adapt processes to prevent them, moving beyond predictive, diagnostic, and descriptive insights.
Ratio estimation uses a representative sample to extrapolate insight applicable to a whole population, a practice internal auditors often use with attribute data.
Analyze proportional analysis using ratios such as costs to sales and apply trend analysis to explain data changes. Consider embedded audit modules and software that automate testing of correlations.
Benford's law explains that leading digits in real data follow a predictable pattern and can reveal falsified invoices in accounting and sales data.
Explore statistical process control with a bell curve, set upper and lower control limits, identify out-of-control items, and assess when outliers exaggerate averages amid natural variation.
Understand the process elements approach to risk management, starting with risk communication and context, then identifying, assessing, prioritizing, and treating risks while monitoring and improving the process.
Apply the process elements approach to gather evidence by interviewing staff across the organization about risk communication, enabling the internal auditor to assess structured and ongoing risk management communication.
Identify the most useful evidence for transparency and inclusiveness in risk management under the key principles approach, comparing benchmarks, policies, interviews, and committee observations.
Apply the fishbone (Ishikawa) diagram to map the risk event's effect and its causes and sub-causes, including reporting delays, unclear deadlines, automation gaps, and missing templates.
Learn the five whys method for root cause analysis by repeatedly asking why to drill down to the underlying cause, with examples like staff shortages and hiring the wrong person.
Explore root cause analysis using logic trees to hierarchically break down an environmental impact into emissions sources—from production and supply chain to staff travel—identifying high-impact actions to reduce pollution.
Failure modes and effects analysis (FMEA) is a systematic, proactive method to identify root causes and failures, assess their impact, and prioritize risks using cross-functional teams and probability-based ratings.
Explore the system development life cycle from planning and analyzing requirements to design, programming, testing, and deployment, including building from scratch or purchasing with customization and user acceptance testing.
Explore how internal audit can influence deployment design or software selection, embed security controls in development policies, and align acceptance criteria with the initial project objectives.
Explore the waterfall method in the SDLC, with non-overlapping stages and sign-offs at each phase, balancing control with potential inflexibility and longer deadlines.
Explore the spiral method for the systems development life cycle, an iterative and flexible approach that develops objectives, identifies and assesses risks, tests solutions, and applies lessons to future projects.
Overlap planning, analysis, and design to accelerate the SDLC by running steps in parallel, with alpha and beta testing and multiple prototypes tested in parallel.
Adopt agile methods that emphasize continuous iteration through sprints, with development and testing simultaneous, and prioritize customer collaboration and working software over heavy documentation and plans.
Learn four main qualities of persuasive internal audit information: sufficient, proper, reliable, and relevant and useful information to support observations and objectives.
Explore the 2210 and 2300 standards, and learn how internal auditors identify, analyze, evaluate, and document sufficient, factual, adequate, reliable, and relevant information to meet objectives.
Explore primary and direct audit evidence, secondary evidence, corroborative evidence, analytical evidence, and testimonial evidence, with examples like signed contracts, notarized documents, invoices, interviews, and payroll analyses.
Explore types of audit evidence, focusing on circumstantial evidence and how circumstances relate to intermediate facts, with examples like contracts and witness statements.
Apply IIA standard 2600 on communicating the acceptance of risk, guiding internal audit from senior management discussions to board escalation when risk exceeds the board's risk appetite.
We are glad to bring you a course on the Certification in Risk Management Assurance (CRMA), a certification from the Institute of Internal Auditors (IIA).
We really think this is the best course in the world on the CRMA, despite having a Udemy price.
This course will give you all that you need to cover the study parts of the new CRMA syllabus. It is intended for either:
1. Those who want to learn more about risk management.
2. Those who want to learn how to audit risk management.
3. Those who want to pass the CRMA certification exam.
It includes 40 exclusive practice questions, plus further questions explained during the course.
It includes 110 pages of slides on key exam areas.
It is taught by Adrian Resag, an experienced Chief Audit Executive and Head of Risk Management who has also been teaching for nearly 2 decades.
You will learn:
All you need to know to pass the CRMA exam.
The basics (and intermediate knowledge) of risk management.
What you need to know to perform proper audits of risk management.
The course covers:
CRMA Introduction and Exam Strategy
Introduction to the CRMA, what strategies to use for the exam, what types of questions can be asked and what topics are covered in the CRMA.
Internal Audit's Role in Risk Management
Understand the role of an internal audit function in the management of an organization’s risks.
The Governance of Risk Management
Learn how to apply governance structures and frameworks over the management of risks in an organization.
Know how to assess the governance framework in place.
Assurance over Risk Management Learn how to perform risk assessments
Know different measures for evaluating risks, how risk and control self-assessments are performed.
Know how the monitoring of risks and the risk management system should be performed.
Know how to use risk management maturity models in your organization.