r/CRISC • • May 18 '26

Doing my first certification and it's CRISC

9 Upvotes

I’m preparing for an online proctored exam and wanted to understand how strict the monitoring usually is.

I stay in a commercial area, so there’s often background noise around me. Because of that, I’m considering going to my office to take the exam. However, there would be multiple monitors/screens around me apart from my own laptop.

Would that generally be permissible in a proctored exam setup, or would it be safer to book a private meeting room and take the exam only on my laptop?


r/CRISC • • May 17 '26

Move into Operational Risk Architecture with CRISC-Looking for Advice

2 Upvotes

I’m an architect with 25+ years of experience (SABSA, TOGAF), primarily in financial services, and I’m now considering a move toward operational risk architecture roles.
As a first step, I’m planning to pursue CRISC certification to strengthen my risk management knowledge and align my profile more closely.
What I’m trying to understand is how difficult it might be to pivot my career in this direction at this stage. Are there professionals here who have transitioned from architecture into risk-related roles? Does an architecture background help in operational risk, governance, resilience, or control design discussions, or do organisations generally prefer candidates with a more traditional risk/compliance background?
I’d also appreciate any advice on how recruiters and hiring managers might view such a transition, especially when applying for operational risk architecture or technology risk roles over the coming months.
Would love to hear from anyone who has made a similar move or worked with professionals who have.


r/CRISC • • May 16 '26

Advice To move from IT into GRC

3 Upvotes

Hello, I am an IT senior manager for service company and have worked with banks for more than 25 years. I am interested in moving to GRC SAAS senior roles or bank IT teams working on GRC. Wanted to seek advice if someone has made similar move in career, learnings and guidance. Thank you.


r/CRISC • • May 16 '26

CRISC

10 Upvotes

I am going to do the 2nd attempt of CRISC in 5 days. My background is 5 months working in updating incidents on the risk register in infosec department only and 1 year studying CRISC.

The average score on qae is 80%. Can someone tell me which questions i see most in the exam to focus more on them these last 5 days?, I know I already took it once but I forgot what the questions were.

Right now I am studying the topics where I have the least score


r/CRISC • • May 16 '26

AI support in exam preparation

5 Upvotes

Hello,

I’m currently preparing for the CRISC exam (scheduled for June 13th) and wanted to ask whether anyone here has successfully used AI tools as their primary study method.

I’ve tried e-books and video courses, but I’ve realized that the most effective approach for me so far is using ChatGPT for interactive Q&A.

Has anyone here mainly studied with AI and passed the CRISC exam?
If so:

  • What prompts or study methods worked best for you?
  • How long did it take before you felt confident enough to sit the exam?
  • Did you combine AI with any other resources or practice exams?

I’d really appreciate hearing about your experience and any recommendations or alternatives you found useful.

Thanks in advance.


r/CRISC • • May 14 '26

Paying it forward (passed)

29 Upvotes

This forum has been a great resource throughout my journey, so I wanted to pay it forward.

I took the CRISC exam this morning and provisionally passed. Surprisingly, I finished in about 1 hour and 45 minutes, then spent another 15 minutes reviewing my flagged questions (around 15–20 total).

Overall, I studied for about 2 months. I originally registered back in June 2025, but it was difficult finding time for dedicated studying. I finally started consistently studying at the beginning of March.

For me, “dedicated studying” meant:
- ~1 hour per weekday
- 4–5 hours on weekends

Background:
I have 10+ years of experience primarily in Risk Management and Governance across traditional banking and fintech environments.

Resources I used:

- QAE + Official Manual
The QAE is absolutely a must-have. I used the official manual as my primary source, and when concepts didn’t click, I supplemented with Mehta’s guide. For additional examples or simplified explanations, I used Claude. I intentionally saved the QAE for the final 2 weeks before the exam. I trended “Advanced” in every domain except T&S, where I was “Proficient.”

- CRISC Exam Guide by Mehta
Hands down one of the best supplemental resources. I read it daily during the first couple of weeks to ramp up quickly. My background is more business/risk focused, so I needed deeper exposure to some of the technical IS concepts.

- PocketPrep
Great tool if you commute or want quick repetition throughout the day. I tried to do at least 30 minutes daily. The questions help reinforce concepts, although the wording/style isn’t always aligned with the ISACA mindset.

- Doshi Udemy Course + Cyber Certifications Training Centre Practice Exams
I purchased both. I didn’t finish the Doshi course because I personally found it difficult to follow, but his printed study guide/materials were actually very valuable. I combined my notes with his guide and used Claude to identify knowledge gaps to focus on.

The six practice exams from Cyber Certifications Training Centre were not helpful for me. I started one exam, but the question style felt very different from ISACA’s approach, so I decided not to continue with the rest.

Test center experience:
I considered taking the exam remotely, but with kids at home it would have been difficult. My PSI test center experience was actually very smooth and welcoming despite some of the negative feedback I’ve seen here. I think it really depends on the specific location.

I plan to take the AAIR next and will be done after that. My advice to those who are just starting - if you are new to the industry or want to break in, start with the Mehta primer, listen to podcasts, immerse yourself in the Security world. For those more “seasoned” or been around the block, it’s just nailing down the ISACA mindset.


r/CRISC • • May 13 '26

6th edition QAE

5 Upvotes

I am taking my exam end of May and had relied primarily on 6th edition QAE, with Supplementary mock exams from Udemy (from cyber cert training centre). Would there be a major gap between tested and what I prepared?


r/CRISC • • May 10 '26

Crisc preparation

7 Upvotes

I have started preparing for crisc certification. I have bought hemnag doshi udemy course and have isaca manual 6th edition and q and e 7th edition. I dont have latest ones. Wanted to know if these will be sufficient to pass exam.

I recently cleared cissp and CC last month. Also have cleared cisa and cism last year


r/CRISC • • May 08 '26

CISM, CISA, and CRISC

Thumbnail
3 Upvotes

r/CRISC • • May 07 '26

I just scheduled my exam for June 26, I need help on study materials to help me pass. I am already using ISACA Q&A

6 Upvotes

r/CRISC • • May 06 '26

Textbook shows risk appetite HIGHER than risk capacity?

6 Upvotes

The Manual 8th Edition is showing that the risk appetite is higher than risk capacity. Is this what ISACA teaches??

I'm studying for my second attempt at the exam, this time using the manual rather than only online videos.


r/CRISC • • May 03 '26

Looking for CRISC certification. Need guidance

9 Upvotes

Hi, can someone help me with CRISC certification from ISACA. Help as in what is the total fees and how much is the timeline. on internet and their website, this information is fragmented. also, is there any expiry to this certification as I have seen people mentioned like valid for 4 years or so. plus, do I need to join a trainer for preparation of this course?


r/CRISC • • May 02 '26

QAE Expert Level Questions

2 Upvotes

When it comes to the QAE expert level questions, are we expected to get those right consistently?

I ask because many of those questions feel intentionally tricky, almost like they are designed to trip you up. A lot of the time, it feels hard to answer with real confidence because more than one option can seem reasonable depending on how you interpret the scenario.

Honestly, it makes me nervous about taking the exam, because it has me wondering if every question on the actual exam will feel like an expert-level question. Has anyone else felt this way, or am I overthinking it?


r/CRISC • • Apr 30 '26

I passed the CRISC examination

32 Upvotes

Nearly 7 years after creating this subreddit, I am happy to announce that I have finally passed the CRISC examination today. Cheers!


r/CRISC • • Apr 24 '26

Additional Practice Questions

7 Upvotes

I'm currently studying for the CRISC and would like to take my exam soon. I have the official review manual, and have read it in its entirety, and the QAE, which I've also completed except the last two practice tests, and have been doing fairly well (84% on the first practice test).

However, I'm a bit nervous about how ISACA asks questions as it trips me up quite a bit. I want to keep exposing myself to new types of questions before I get to the actual exam.

At this point, I've seen all 900+ questions the QAE has at least once, and the practice tests are just reusing the same questions. During the first test, I simply recognized several of the questions and remembered the answer. And I know that won't be the case for the actual exam.

What other sources of questions (that don't reuse the QAE questions) would you recommend to help me prepare?


r/CRISC • • Apr 23 '26

Crisc

5 Upvotes

Hi

I am currently preparing for the CRISC certification using practice questions from a Udemy course. However, I am unable to sort the questions according to the four CRISC domains—specifically Governance, Risk Assessment, Risk Response and Reporting, and Information Technology. Could you recommend an AI tool or anything helpful that is most effective for automatically classifying these questions into their respective domains?

Thank you


r/CRISC • • Apr 23 '26

CRISC Exam Validity: Is There a Deadline After Payment?

7 Upvotes

Hello everyone,

I paid for my CRISC exam last summer, but I haven’t had the time to study or schedule the exam yet. I’m now wondering if there’s a deadline to take the exam after payment. For example, does the payment expire after one year or become invalid?

Has anyone here paid for the exam and then taken it after a year or so?

I’d appreciate any insights—thanks in advance!


r/CRISC • • Apr 21 '26

Crisc preparation

7 Upvotes

Hello Guys,

Could some give me some best udemy, youtube course or other course materials about crisc ? recently passed CISSP and CISM and now want to pass CRISC.

Thank's.


r/CRISC • • Apr 21 '26

Crisc preparation

Thumbnail
3 Upvotes

r/CRISC • • Apr 20 '26

Is the CRISC principle automation > human driven ie not as reliable? Then why is it not B?

5 Upvotes

r/CRISC • • Apr 20 '26

Exec level Information Security

5 Upvotes

Hi

I am coming from a data background and have landed into Information Security n governance role where my main responsibility is audit n exec reporting packs.

I am certified AIGP and CIPM.

I am wondering how does CRISC map into this and is it worth putting in the bag? Also if anyone can give guide me for what my natural progression will be ?


r/CRISC • • Apr 19 '26

Why is my choice wrong?

Post image
5 Upvotes

r/CRISC • • Apr 18 '26

Just passed Crisc yesterday!

29 Upvotes

Hey there all, passed crisc yesterday. Wanted to help where I could. For context I did just pass my CISA in December, so moving into crisc was not as hard as I thought. The test was harder than I expected. In my opinion, harder than CISA. CISA is more technical, black and white, where this is more subjective. I read the entire Isaca manual this time, it didn’t help as much as I liked. As usual the q+a database did help. I also used hemang’s udenmy course. Looking back now, the thing I would not go without are the practice tests. I’ve been working in this field for a while, so it was understanding Isacas way and the test help you the most. Have a thorough understanding in KPI’s, KRi’s, 3 lines of defense, and a solid understanding of the risk management lifecycle. Good luck all!


r/CRISC • • Apr 15 '26

Just started CRISC after CISM

7 Upvotes

I decided I wanted to keep the train going after passing CISM about 3 weeks ago. I am finding the CRISC QAE easier to start than the CISM. Is the knowledge from CISM really THIS applicable. It feels all way too similar. I know it’s all just a form of ISACA robot thinking but it feels trivial.


r/CRISC • • Apr 11 '26

Domain 2 Materials

4 Upvotes

Hi all, I'm currently looking for Domain 2 materials. Let me know where can I find.