Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Domain 1 — Governance (26%)Preview
More in this section
16 more key points in Pro version
9 more common mistakes in Pro version
5 more exam tips in Pro version
49 more related questions in Pro version
Summary
CRISC governance is about aligning IT risk with business strategy, objectives, accountability, and stakeholder expectations. Governance sets direction; management executes. Policies define intended direction, standards define required implementation. Risk owners are accountable for risk decisions, control owners manage controls, oversight monitors, and independent assurance validates. Risk registers feed the enterprise risk profile. Risk appetite expresses willingness to take risk; tolerance defines acceptable variation around that appetite. Always connect governance decisions back to business objectives, legal/regulatory requirements, resilience, and validated stakeholder reporting.
Key Points
Governance = strategic alignment, direction, accountability, and oversight.
Common Mistakes
Treating governance as day-to-day technical execution.
Exam Tips
Start with the business objective, not the technology.
Section 2Domain 2 — Risk Assessment (22%)Preview
More in this section
16 more key points in Pro version
9 more common mistakes in Pro version
5 more exam tips in Pro version
41 more related questions in Pro version
Summary
Risk assessment identifies what could go wrong, why, how likely it is, and what business impact could result. Threats, vulnerabilities, assets, and consequences combine into meaningful risk scenarios. Use a defined methodology and standard, then assess likelihood and impact. BIA focuses on critical business processes, impact consequences, dependencies, and recovery priorities. The risk register records assessed risks and supports the enterprise risk profile. Qualitative analysis fits limited data; quantitative analysis fits stronger measurable data. Inherent risk is before controls; residual risk is what remains after controls.
Key Points
Risk event = potential occurrence that could affect objectives or operations.
Common Mistakes
Confusing threat with vulnerability.
Exam Tips
Assessment asks: what can happen, how likely, and what is the impact?
Section 3Domain 3 — Risk Response and Reporting (32%)Preview
More in this section
18 more key points in Pro version
11 more common mistakes in Pro version
6 more exam tips in Pro version
61 more related questions in Pro version
Summary
This is the largest CRISC domain. Once assessed risk is compared with appetite/tolerance, select and manage an appropriate response with accountable ownership, concrete actions, monitoring, validation, and reporting. Risk owners make risk decisions; control owners design, implement, and maintain controls. Vendor and supply-chain risks require assessment, treatment, monitoring, and reporting. Issues, findings, exceptions, and exemptions follow governed processes. Control testing validates both design and operating effectiveness using evidence suited to the control. Risk action plans need an owner, action, target date, resources, and validation criteria. KRIs measure risk exposure, KCIs measure control effectiveness, and KPIs measure performance. Reports must use validated information and be tailored to stakeholder needs.
Key Points
Compare assessed risk to appetite/tolerance before selecting a response.
Common Mistakes
Confusing risk owner with control owner.
Exam Tips
Domain 3 is often about the NEXT management action after assessment.
Section 4Domain 4 — Technology and Security (20%)Preview
More in this section
17 more key points in Pro version
11 more common mistakes in Pro version
6 more exam tips in Pro version
37 more related questions in Pro version
Summary
Technology and security questions are still risk-management questions. Align technology principles, roadmaps, architecture, operations, development, projects, resilience, emerging technology, security, awareness, privacy, and data protection with business and risk objectives. Integrate controls across the SDLC rather than bolting them on at the end. Manage risk throughout the full data lifecycle. Technology resilience is proactive continuity capability; recovery is restoration after disruption. New technology should be evaluated for threats, vulnerabilities, opportunities, dependencies, and control impact. Awareness must be role-based and measured for effectiveness. Privacy and protection should be integrated into governance and lifecycle decisions.
Key Points
Technology decisions should align with business and risk objectives.
Common Mistakes
Choosing technology based only on features.
Exam Tips
Technology is the context; risk alignment is the decision criterion.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.