Course overview
thinQtank® Learning is offering a unique instructor-led training camp that gives students the knowledge and skills needed to govern IT risk inside a real organizational structure — identifying and analyzing risk honestly, choosing a response and designing the controls that carry it, and then monitoring and reporting in terms a board will act on rather than merely acknowledge.
This course also helps students prepare to take the ISACA CRISC exam. It is built on the exam content outline that took effect on 3 NOVEMBER 2025, when ISACA revised the CRISC job practice: Risk Assessment rose from 20% to 22% and Technology and Security fell from 22% to 20%. Material still quoting the older split is a year out of date.
What's included
14 itemsthinQtank® Learning Accelerated Custom Exam Study Guide for the CRISC exam
Exam delivery in classroom with 98% success
Custom and focused exam preparation software and materials
Course specific thinQtank® Learning publications to promote a fun and exciting learning
Membership to the thinQtank® Learning University Online
WE DO NOT "TEACH THE TEST" - Students will receive valuable examples and discussion
Receive all reading material and study guides when you register
All courses taught by certified instructors
Additional hours of remote lab access across risk scenarios, controls and metrics
Custom video recordings with even more in-depth learning of course topics
Customized practice exam software
Digital courseware
Retake any or all portions of the course as many times as you like in person or live on-line for 24 months
Six months mentoring access to our engineers after completing the course
What you'll be able to do
16 objectives- Understand the organizational structures, policies and accountability that govern IT risk
- Apply enterprise risk management, the three lines of defense and a risk framework
- Establish and use risk appetite and risk tolerance rather than merely quoting them
- Identify risk events, model threats and manage vulnerabilities
- Develop risk scenarios that a business owner recognizes as real
- Perform risk analysis, including business impact analysis and quantitative methods
- Build and maintain a risk register that is used rather than filed
- Choose among risk response options, and assign genuine risk ownership
- Manage third-party, vendor and supply chain risk
- Handle exceptions and issues without quietly accepting risk by default
- Design, implement and test information systems controls
- Define key risk, key control and key performance indicators, and know the difference
- Monitor risk and report it in terms leadership can act on
- Apply technology principles: architecture, the development lifecycle, the data lifecycle and resilience
- Apply information security principles, awareness training and data privacy
- Assess the risk that emerging technology introduces before it is deployed
The exam
Risk Response and Reporting32%
Governance26%
Risk Assessment22%
Technology and Security20%
- ISACA CRISC — Certified in Risk and Information Systems Control
- Based on the exam content outline effective 3 November 2025
- 150 multiple-choice questions
- Four hours to complete
- Scaled score of 450 or better, on a scale of 200 to 800
- Three years of professional experience across at least two of the four domains, gained within the ten years preceding the application, is required to CERTIFY. You may sit the exam first and have five years to apply
- Certification is maintained with 120 CPE hours per three-year reporting period, a minimum of 20 in any year. A US$50 application processing fee applies separately
- CRISC Voucher — an exam voucher is available through thinQtank for $760 USD, which is the ISACA non-member exam price at list. Ask when you register and we will add it to your enrollment
Who it's for, and what you need first
Target Audience
- Risk and compliance managers, directors and consultants
- IT audit managers and consultants moving from auditing controls to designing them
- Security managers accountable for risk rather than only for technology
- Business analysts and project managers who own risk on what they deliver
- Anyone holding CISA or CISM and specializing into risk next
- Service members, veterans and military spouses using AF COOL, Army Credentialing Assistance, MyCAA or VET TEC 2.0
Prerequisites
- Three years of professional experience across at least two of the four CRISC domains, gained within the ten years before you apply
- THE EXAM IS NOT GATED BEHIND IT. Sit and pass the exam first if you like — you then have five years to submit the certification application
- Working familiarity with a risk or control framework makes the course land faster
How it's delivered
Instructor-Led Training
Immersive Live-Online Training
On-Site and Custom Delivery
Training Camp Format
This course is delivered as an instructor-led training camp, with the exam sat in the classroom as part of the camp. Camps are scheduled by cohort, and the balance of lecture and hands-on lab work is set to suit the group and the delivery method. Contact us for the schedule covering your dates.
Dates and locations
24 scheduledGuaranteed to run means the class goes ahead whatever the enrollment.
Prices shown are MSRP. Qualified military personnel funding through Air Force COOL, Army Credentialing Assistance, MyCAA or VET TEC 2.0 pay a flat $1,500 per class, whatever the listed price. Everyone else — call 855-868-4467 about group pricing, discounts and current promotions.