CRMA certification is The Institute of Internal Auditors’ specialist credential for professionals who evaluate risk governance, risk management processes, assurance, and advisory work. Candidates take one 120-question, 150-minute exam and do not need the CIA designation. Eligibility depends on education and relevant experience, with one year required for master’s holders, two for bachelor’s holders, and five for candidates without a degree. Current total fees are $565 for IIA members and $830 for non-members, excluding preparation, rescheduling, and local tax charges.
The Certification in Risk Management Assurance (CRMA) is awarded by The Institute of Internal Auditors, commonly known as The IIA. It validates a professional’s ability to evaluate risk management processes, assess organizational governance and provide assurance or advice to senior management and audit committees.
The qualification is not limited to employees with “internal auditor” in their job title. Relevant experience may come from:
Internal auditing
Risk management
Compliance
Quality assurance
External auditing
Internal control
Audit and assessment disciplines
The IIA has also removed the previous CIA prerequisite. A candidate may now pursue the CRMA without first earning the Certified Internal Auditor designation.
This makes the credential particularly relevant to internal auditors, risk managers, compliance professionals, governance specialists, control professionals and experienced consultants who regularly assess whether an organization is managing its risks effectively.
CRMA work goes beyond maintaining a risk register or checking whether controls exist. The professional must determine whether risk management supports the organization’s strategy and whether senior decision-makers receive reliable information.
For example, imagine a company expanding into a new country. Management may identify regulatory, cybersecurity, supply-chain and financial risks. A CRMA professional would not simply confirm that these risks were documented. The professional may also assess:
Whether risk appetite was considered before approving the expansion.
Whether the risk assessment included interconnected risks.
Whether the selected responses are realistic and properly funded.
Whether management reporting gives the board a complete view.
Whether internal audit can provide independent assurance without assuming management responsibility.
That ability to connect strategy, governance, risk and assurance is the primary value of the credential.
The CRMA certification requirements depend mainly on the candidate’s education. Candidates can sit for the examination before completing the required experience, but all eligibility conditions must be completed within the two-year program period.
Candidate background
Relevant experience required
Main application evidence
Master’s degree or equivalent
1 year
Degree evidence and valid photo ID
Bachelor’s degree or equivalent
2 years
Degree evidence and valid photo ID
Active IAP holder
Normally 5 years, reduced if an eligible degree is held
Active IAP credential and valid photo ID
No bachelor’s or master’s degree
5 years, including 2 years within the previous 3 years
High school, associate, GCE, A-level or equivalent evidence and valid photo ID
Relevant experience can include internal audit, risk management, compliance, quality assurance, external audit and internal control. Candidates with master’s degrees require one year of qualifying experience, while bachelor’s degree holders require two years. Candidates following the non-degree pathway generally require five years.
Passing the exam does not automatically mean the designation will be issued immediately. The candidate must also complete the experience verification process.
This distinction matters when planning your application. A candidate who has the required education but lacks sufficient experience may take the exam early, but the certification will not be awarded until the experience requirement has been accepted.
The CRMA examination contains 120 questions and provides 150 minutes of testing time. Candidates have two years from program approval to pass the exam and complete the remaining certification requirements. A CIA designation is not required.
Exam feature
Current structure
Number of examinations
One
Questions
120
Testing time
150 minutes
Average time available
75 seconds per question
Program completion period
Two years
CIA prerequisite
Not required
Result timeline
Within three weeks of the exam date
Effective April 1, 2026, CRMA candidates receive one official result within three weeks instead of receiving an immediate unofficial score at the test center.
The limited time per question means candidates should avoid treating the exam as a memory test. Many questions require the test-taker to distinguish between management responsibilities, internal audit assurance work and permitted advisory activities.
The examination covers four domains.
Domain
Exam weighting
Main focus
Organizational governance related to risk management
25–30%
Risk culture, appetite, accountability, stakeholders and strategic alignment
Principles of risk management processes
25–30%
Risk identification, analysis, response, monitoring and reporting
Assurance role of the internal auditor
20–25%
Independent evaluation of key risks and risk management processes
Consulting role of the internal auditor
20–25%
Facilitating, coaching and supporting risk management without owning it
The first two domains represent as much as 60% of the exam, so governance and risk management processes should receive the largest share of study time. However, the assurance and consulting domains frequently create the most difficulty because several answer choices may describe useful actions while only one protects internal audit independence.
A strong candidate knows the difference between helping management and becoming management.
Internal audit may:
Facilitate risk identification.
Coach management on risk responses.
Coordinate risk-related information.
Recommend improvements.
Provide assurance over risk management.
Internal audit should not establish the organization’s risk appetite, accept risks for management, select risk responses or take ownership of the risk management framework.
When two options appear reasonable, the better answer usually preserves management accountability and internal audit independence.
The current CRMA certification cost consists of a separate application fee and examination registration fee.
Fee category
IIA member
Non-member
Application
$100
$220
Examination
$465
$610
Total core fees
$565
$830
The figures do not include membership dues, study resources, local taxes, travel or optional training. The IIA also lists a $75 Pearson VUE cancellation or rescheduling fee, a $100 exam-registration extension and a $275 program-eligibility extension. Pricing can differ outside North America, so international candidates should confirm charges with their National Institute before paying.
Membership reduces the published application and examination costs by a combined $265. However, candidates should compare those savings with the cost of membership in their country rather than assuming that membership will always produce the lowest overall expense.
Candidates frequently search for the CRMA pass rate, but The IIA’s current certification, syllabus and scoring pages do not publish an official global pass-rate percentage.
Unofficial websites may display estimates, but these numbers often lack a stated testing period, candidate population or primary source. They should not be treated as reliable indicators of exam difficulty.
A more useful readiness measure is performance across the four syllabus domains. Before scheduling the exam, a candidate should be able to:
Explain risk appetite, capacity and tolerance.
Connect risk assessment with strategic objectives.
Evaluate risk responses using cost-benefit reasoning.
Separate assurance work from consulting work.
Identify when internal audit independence is threatened.
Answer scenario-based questions within approximately 75 seconds.
The examination is officially described as a self-study exam and does not require a prescribed curriculum. Candidates may select their own preparation method. The IIA identifies references including COSO guidance, ISO 31000, the IPPF, NIST’s Privacy Framework and risk management publications.
Official IIA CRMA study materials include the CRMA Study Guide and Practice Questions, Third Edition. The resource contains the syllabus, key terms and more than 200 practice questions with explanations. The IIA also provides an aligned preparation course.
Candidates considering CRMA training should look for more than recorded lectures. Effective training should include:
Scenario-based questions rather than definition-only quizzes.
Explanations for both correct and incorrect options.
Domain-level performance tracking.
Exercises covering risk appetite and risk culture.
Assurance-versus-consulting decision scenarios.
Timed mock examinations.
Examples involving cybersecurity, third parties and emerging risks.
People searching for CRMA certification online should also distinguish online preparation from examination delivery. Applications and study programs may be managed online, while The IIA directs candidates to secure, computer-based testing through global Pearson VUE test centers.
Study organizational objectives, governance structures, risk culture, stakeholder expectations, risk appetite, capacity and tolerance.
Cover risk identification, analysis, prioritization, responses, mitigation plans, monitoring, reporting and emerging risks.
Practise evaluating risk reporting, key risks and the effectiveness of risk management processes.
Focus on facilitation, coaching and coordination while protecting internal audit independence.
Work through cases combining strategy, governance, cyber risk, third-party risk, compliance and operational disruption.
Complete full mock exams, analyse weak domains and revise the reasoning behind mistakes instead of memorizing answer letters.
A practical target is to spend approximately 55% of study time on governance and risk processes, 30% on assurance and consulting boundaries, and 15% on timed practice and revision.
Active, practising CRMA holders must complete 20 hours of continuing professional education each year and complete annual certification renewal. The renewal requirements also include ethics education and professional compliance attestations.
Before purchasing a course or submitting an application, download the current syllabus, verify your education and experience pathway, calculate the complete cost for your location and complete a timed diagnostic test. That preparation will show whether you need a full CRMA certification online course, targeted domain revision or primarily exam-question practice.