CRISC Exam Format and Time Management
CRISC is a computer-based exam with 150 multiple-choice questions and four hours (240 minutes) of testing time.
- That averages 96 seconds per question, including review.
- ISACA's public format describes multiple-choice items and does not identify a CAT, live lab, or performance task.
- Practise selecting the best risk-management action from a scenario and its stated facts.
On this page9 sections
- Published CRISC exam format
- What CRISC questions ask you to reason about
- A pacing plan for four hours
- Original worked question: risk assessment before control selection
- Question technique for close answer choices
- Pretest items and unanswered questions
- Test center and remote delivery
- Practise with the current outline
- Make a four-hour plan that protects decision quality The exam presents 150 multiple-choice questions in 240 minutes. Dividing time evenly gives 96 seconds per question, but that figure is a planning average, not a limit on each item. A short definitional question may take less time, while a scenario that asks you to choose the best response can need careful reading. Leave time to inspect unanswered items and confirm that every response is recorded before submitting. A candidate might divide the session into four blocks of 60 minutes, each containing about 37 or 38 questions. At each checkpoint, notice whether the pace is drifting. If the candidate has answered 30 questions in the first hour, roughly 210 remain in the remaining three hours, so the pace must increase modestly. If the candidate is ahead, use the time to read carefully rather than speeding through easy items and creating careless errors. Do not spend several minutes debating an item after identifying the governing decision. Determine what the question asks, such as the risk owner's next action, the purpose of an assessment, or the measure that informs a response. Eliminate options that skip a necessary step or assign authority to the wrong role. If two options remain, compare which one addresses the stated objective with the least unsupported assumption. Work a scenario through the decision chain Consider a business unit that reports a new critical vendor dependency. The first task is to understand the risk scenario: what could happen, which asset or objective could be affected, and how the current controls change likelihood or impact. A question asking for the next risk-management step may favor assessment before selecting a new control. Choosing a control too early can treat a risk that has not been defined. Now suppose the assessment shows that an outage could interrupt a regulated service, and a recovery test misses the approved target. The candidate should distinguish the evidence from the decision. The test result is evidence of a gap. The responsible owner must evaluate treatment options, assign accountability, and decide whether residual risk is acceptable within authority. A technician can explain technical options but should not silently accept business exposure. Finally, choose a metric that tells management whether the treatment works. Counting how many policies were distributed may show activity, but it does not show whether recovery performance improved. Repeated recovery-test success against the target, with exceptions tracked to closure, is closer to the stated decision. Read the stem carefully: the best metric is tied to the objective, not simply easy to count. When a test contains pretest items, they look like ordinary questions and the candidate cannot identify them. Treat every item as important and answer it consistently. An unanswered item has no demonstrated response, so do not leave items blank while spending time polishing one difficult choice. Time management is part of making sure the knowledge you have can be recorded. After a timed practice session, review decisions as well as accuracy. Note whether you misread the requested role, chose a response before assessing the risk, or picked a metric unrelated to the objective. The correction should match the error. More memorization will not fix a recurring role-boundary mistake, and faster reading will not fix a weak understanding of risk treatment.
Published CRISC exam format
The 2026 ISACA Candidate Guide lists 150 multiple-choice questions and a four-hour, or 240-minute, exam. It is administered by computer at authorized PSI test centers or remotely where available. The exam is fixed length in the published guide. ISACA's public format does not identify CRISC as a computerized adaptive test and does not list a hands-on lab or performance task.
| Detail | CRISC format |
|---|---|
| Questions | 150 |
| Item style | Multiple choice; scenarios test applied risk judgment |
| Time | Four hours or 240 minutes |
| Average pace | 96 seconds per question if evenly divided |
| Delivery | Authorized PSI center or remote proctoring where offered |
| CAT | Not identified in the official public description |
| Hands-on labs | Not identified in the official public description |
The 96-second average is arithmetic, not an official time limit for each item. Some questions are shorter and some include more context to interpret. You need a pace that lets you read the requested decision and compare answers without leaving many questions for the end. Follow the current candidate guide and on-screen rules for navigation, flagging, breaks, and submitting responses.
What CRISC questions ask you to reason about
A CRISC scenario may describe a business service, a technology project, a control gap, a risk assessment, or a reporting problem. The question asks for the most appropriate action or conclusion. The candidate needs to identify the objective, risk scenario, owner, evidence, and stage of the risk process. A technically possible safeguard may be premature if the scenario first requires assessment or an authorized decision.
Read the final sentence first and note words such as first, best, most important, or next. Those words define the task. Then read the scenario for relevant facts: who owns the process, what has been assessed, what controls exist, what is unknown, and what decision is needed. Do not fill in a missing risk tolerance, contract term, or incident result from your own assumptions.
Identify the actor expected to act. A CRISC professional can analyze and advise, while the business risk owner makes acceptance decisions within delegated authority. The control owner operates or monitors a safeguard. Questions sometimes tempt the candidate to assign a decision to the wrong role. Ask whether the choice respects ownership and governance.
A pacing plan for four hours
Use approximate checkpoints to track progress: around 38 questions after one hour, 75 after two hours, 112 after three hours, and all 150 before time expires. These estimates divide the total evenly and are not official ISACA targets. If you are far behind, reduce rereading and make a reasoned selection. If you are ahead, use the time for flagged questions and review.
| Elapsed time | Approximate progress | Check |
|---|---|---|
| 60 minutes | 38 items | Is the pace sustainable? |
| 120 minutes | 75 items | Have you reached about halfway? |
| 180 minutes | 112 items | Protect time to complete all questions |
| 240 minutes | 150 items | Submit within the allowed time and review if available |
If the exam interface allows you to flag items, use that feature for questions that deserve a second look. Do not leave every uncertain question unanswered. Select the best supported choice, mark it, and continue. Return only if time permits. A simple reason for your choice can help on review: owner, evidence, criteria, then action.
Avoid spending several minutes searching for a perfect answer when the prompt does not contain enough information for certainty. Eliminate options that skip the risk process, hide an issue, or act beyond authority. Compare the remaining answers using the qualifier. A defensible choice is better than losing several later questions to one ambiguous item.
Original worked question: risk assessment before control selection
A company plans to connect a new logistics application to its inventory system. The project team reports that a new access-control tool will be installed, but no one has identified which inventory data the application can change or who owns the risk. The sponsor asks the CRISC professional to approve the control plan. What should happen first? A. Approve the plan because access control is the main concern. B. Define the business process and risk scenario, identify ownership and assessment criteria, then evaluate controls against the exposure. C. Reject the project until every possible threat is eliminated. D. Record that the risk has been transferred to the software vendor.
Best answer: B. The organization first needs to understand the process, scenario, owner, and criteria so it can assess whether the proposed control is appropriate. Approving a tool before knowing the risk can leave important exposures unaddressed. No organization can eliminate every possible threat, so C is unrealistic. A vendor relationship does not automatically transfer all accountability.
Question technique for close answer choices
When two choices both seem useful, compare their sequence and purpose. Does one establish facts while the other makes an unsupported assumption? Does one involve the owner while the other lets the risk analyst accept exposure? Does one measure residual risk while the other counts a control's existence? The better answer normally addresses the scenario's actual decision at the right management level.
Do not treat words like risk register, dashboard, or control framework as magic answers. A register can document a risk but does not itself treat it. A dashboard can communicate status but does not prove data quality. A control framework can guide design but does not determine whether a particular control is proportionate. Look for the action that connects analysis to ownership and follow-up.
Pretest items and unanswered questions
ISACA's Candidate Guide says exams include scored questions and pretest questions that are not used to calculate the score. It does not identify which questions are pretest, so treat every CRISC item as though it counts. The guide does not list a CRISC-specific pretest item count in the summary. Do not spend time trying to guess which item might be experimental.
The guide states that the number of correctly answered scored items determines the result and that there is no penalty for an incorrect answer. Answer every item. If you are unsure, eliminate choices, select the most supportable one, and move on. An empty response cannot improve your score.
Test center and remote delivery
Before booking, determine whether a nearby authorized PSI center or remote proctor appointment is available. For remote testing, run the provider's compatibility check on the device and network you plan to use. A company laptop may need IT approval or may restrict secure testing software. Review the room and equipment rules, and remove prohibited materials from the space.
For a center appointment, verify the address and leave travel time for check-in. For either option, confirm the exact time zone, language, government ID, and account name. The candidate guide says late arrival or a missed appointment may forfeit the fee. Logistics are not part of risk knowledge, but they can determine whether you actually sit the exam.
Practise with the current outline
Use the 2025 CRISC outline: Governance 26 percent, Risk Assessment 22 percent, Risk Response and Reporting 32 percent, and Technology and Security 20 percent. Build practice across all four areas. A set focused only on control frameworks will not show whether you can assess a scenario, choose treatment, assign ownership, or communicate residual risk.
For each practice question, explain the best answer and each distractor. Label misses by cause: knowledge, wrong owner, skipped assessment, premature control, weak reporting, unsupported assumption, or rushed reading. Use fresh scenarios to check whether the reasoning changes, not only whether you remember the prior key. Practice results are diagnostic and do not convert directly to ISACA's scaled score.
- Identify the requested action and qualifier before selecting an answer.
- Separate known facts from assumptions.
- Locate risk and control ownership.
- Choose the action that matches the current process stage.
- Use pacing checkpoints and answer every item.
- Use the Candidate Guide for break, navigation, and delivery rules.
Make a four-hour plan that protects decision quality The exam presents 150 multiple-choice questions in 240 minutes. Dividing time evenly gives 96 seconds per question, but that figure is a planning average, not a limit on each item. A short definitional question may take less time, while a scenario that asks you to choose the best response can need careful reading. Leave time to inspect unanswered items and confirm that every response is recorded before submitting. A candidate might divide the session into four blocks of 60 minutes, each containing about 37 or 38 questions. At each checkpoint, notice whether the pace is drifting. If the candidate has answered 30 questions in the first hour, roughly 210 remain in the remaining three hours, so the pace must increase modestly. If the candidate is ahead, use the time to read carefully rather than speeding through easy items and creating careless errors. Do not spend several minutes debating an item after identifying the governing decision. Determine what the question asks, such as the risk owner's next action, the purpose of an assessment, or the measure that informs a response. Eliminate options that skip a necessary step or assign authority to the wrong role. If two options remain, compare which one addresses the stated objective with the least unsupported assumption. Work a scenario through the decision chain Consider a business unit that reports a new critical vendor dependency. The first task is to understand the risk scenario: what could happen, which asset or objective could be affected, and how the current controls change likelihood or impact. A question asking for the next risk-management step may favor assessment before selecting a new control. Choosing a control too early can treat a risk that has not been defined. Now suppose the assessment shows that an outage could interrupt a regulated service, and a recovery test misses the approved target. The candidate should distinguish the evidence from the decision. The test result is evidence of a gap. The responsible owner must evaluate treatment options, assign accountability, and decide whether residual risk is acceptable within authority. A technician can explain technical options but should not silently accept business exposure. Finally, choose a metric that tells management whether the treatment works. Counting how many policies were distributed may show activity, but it does not show whether recovery performance improved. Repeated recovery-test success against the target, with exceptions tracked to closure, is closer to the stated decision. Read the stem carefully: the best metric is tied to the objective, not simply easy to count. When a test contains pretest items, they look like ordinary questions and the candidate cannot identify them. Treat every item as important and answer it consistently. An unanswered item has no demonstrated response, so do not leave items blank while spending time polishing one difficult choice. Time management is part of making sure the knowledge you have can be recorded. After a timed practice session, review decisions as well as accuracy. Note whether you misread the requested role, chose a response before assessing the risk, or picked a metric unrelated to the objective. The correction should match the error. More memorization will not fix a recurring role-boundary mistake, and faster reading will not fix a weak understanding of risk treatment.
Make a four-hour plan that protects decision quality The exam presents 150 multiple-choice questions in 240 minutes. Dividing time evenly gives 96 seconds per question, but that figure is a planning average, not a limit on each item. A short definitional question may take less time, while a scenario that asks you to choose the best response can need careful reading. Leave time to inspect unanswered items and confirm that every response is recorded before submitting. A candidate might divide the session into four blocks of 60 minutes, each containing about 37 or 38 questions. At each checkpoint, notice whether the pace is drifting. If the candidate has answered 30 questions in the first hour, roughly 210 remain in the remaining three hours, so the pace must increase modestly. If the candidate is ahead, use the time to read carefully rather than speeding through easy items and creating careless errors. Do not spend several minutes debating an item after identifying the governing decision. Determine what the question asks, such as the risk owner's next action, the purpose of an assessment, or the measure that informs a response. Eliminate options that skip a necessary step or assign authority to the wrong role. If two options remain, compare which one addresses the stated objective with the least unsupported assumption. Work a scenario through the decision chain Consider a business unit that reports a new critical vendor dependency. The first task is to understand the risk scenario: what could happen, which asset or objective could be affected, and how the current controls change likelihood or impact. A question asking for the next risk-management step may favor assessment before selecting a new control. Choosing a control too early can treat a risk that has not been defined. Now suppose the assessment shows that an outage could interrupt a regulated service, and a recovery test misses the approved target. The candidate should distinguish the evidence from the decision. The test result is evidence of a gap. The responsible owner must evaluate treatment options, assign accountability, and decide whether residual risk is acceptable within authority. A technician can explain technical options but should not silently accept business exposure. Finally, choose a metric that tells management whether the treatment works. Counting how many policies were distributed may show activity, but it does not show whether recovery performance improved. Repeated recovery-test success against the target, with exceptions tracked to closure, is closer to the stated decision. Read the stem carefully: the best metric is tied to the objective, not simply easy to count. When a test contains pretest items, they look like ordinary questions and the candidate cannot identify them. Treat every item as important and answer it consistently. An unanswered item has no demonstrated response, so do not leave items blank while spending time polishing one difficult choice. Time management is part of making sure the knowledge you have can be recorded. After a timed practice session, review decisions as well as accuracy. Note whether you misread the requested role, chose a response before assessing the risk, or picked a metric unrelated to the objective. The correction should match the error. More memorization will not fix a recurring role-boundary mistake, and faster reading will not fix a weak understanding of risk treatment.
Common questions
How many questions are on the CRISC exam?
CRISC has 150 multiple-choice questions.
How long is the CRISC exam?
Four hours, or 240 minutes. Dividing evenly gives an average of 96 seconds per question, which is a pacing guide rather than an official item limit.
Is CRISC a CAT exam?
The current public ISACA format does not identify CRISC as computerized adaptive testing; the candidate guide lists a fixed 150-question exam.
Does CRISC include hands-on labs?
ISACA's public CRISC format identifies multiple-choice questions and does not list a lab or performance task.
Are some CRISC questions unscored?
ISACA says exams include pretest questions that do not count, but does not identify them or publish a CRISC-specific count in the guide summary.