,

The CRMA: Is the Risk Management Assurance Credential Worth It?

The Certification in Risk Management Assurance is the IIA’s specialist credential for one question boards increasingly ask their auditors: is our risk management actually working? It has always been a niche credential, overshadowed by the CIA, and for four years it was also a hard one to reach, because from 2021 it required an active CIA before you could apply. In July 2025 the IIA removed that prerequisite. The CRMA is now a standalone certification with its own eligibility rules, one exam and a modest fee, which reopens a question many auditors had stopped asking: is it worth it?

The answer depends on who you are and what you want the letters to do. This guide explains what the CRMA certifies, how it has changed, what the exam tests topic by topic, who can sit it now, what it costs to earn and keep, how the market actually recognizes it, and who gains most from it. It ends with a short test for deciding. The facts are those the IIA published as of September 2026; the judgments about value are ours, and we say where they are.

In this guide

What the CRMA certifies

The IIA describes the CRMA as validating expertise in risk management, governance and internal control, and the organizational knowledge needed to provide risk management assurance to audit committees and executive management. In practice that means three capabilities. First, knowing internal audit’s role in risk management: which assurance and advisory services the function should offer, what competencies they need, and how to coordinate with other assurance providers. Second, evaluating risk governance: frameworks, risk culture, the integration of risk management into strategy and performance, and the organization’s response to emerging risks. Third, and above all, giving assurance over risk management itself: assessing management’s risk identification and assessment, building a risk-based plan from an organizationwide risk assessment, evaluating risk management at every level, and telling the board what the function concludes.

That last capability is what distinguishes it. The CIA certifies the whole of internal audit, of which risk is one part. The CRMA certifies depth in one engagement type that has grown in importance as boards have built enterprise risk management programs and asked internal audit to tell them whether those programs work. The IIA’s position on internal audit’s role in ERM has always been careful about the line between giving assurance on risk management and running it, and the CRMA syllabus is built on that line: it examines the assurance and advisory roles, not the job of the risk manager.

How the credential has changed

The CRMA has been rebuilt twice, and much of what is written about it online describes a version that no longer exists. The table sets out the changes the IIA has published.

DateChangeWhat it meant
2011The CRMA introducedBy the eve of the 2021 revision, candidates passed CIA Part 1 and a separate 100-question CRMA exam and needed two years of internal audit experience
2018 to 2021The Certification in Control Self-Assessment retiredNew CCSA applications closed at the end of 2018 and final testing ended in June 2021; control self-assessment now appears in the CRMA syllabus
1 April 2021Revised CRMA program effectiveAn active CIA became a prerequisite; experience rose to five years of internal audit or risk management; the syllabus moved from four areas to three, with risk management assurance at 55 percent
1 October 2021Revised exam launchedThe exam grew from 100 questions in 120 minutes to 125 questions in 150 minutes
15 July 2025CIA prerequisite removedThe CRMA became a standalone certification with education-based experience rules
1 April 2026Delayed scoringCRMA results, like CIA results, are released within about three weeks rather than at the test center
September 2026Current programOne exam of 120 questions in 150 minutes, a two-year program window, and a syllabus that the IIA says is supported by the 2017 Standards

By the time of the 2021 revision, the IIA said nearly 17,000 professionals had earned the CRMA since its introduction. The 2021 changes made it a credential for experienced CIAs only, which narrowed the candidate pool; the 2025 change reversed the prerequisite while keeping the three-section syllabus. The practical effect is that a risk management professional in the second line, or an auditor without the CIA, can now earn an IIA credential centred on risk assurance without passing the three CIA parts first.

The exam and the syllabus, topic by topic

The CRMA exam has 120 questions in 150 minutes, 75 seconds a question, and is sat at a Pearson VUE test center. The syllabus has three sections and 26 topics. The weights are unusual: more than half the exam is the third section, risk management assurance, so a candidate who prepares evenly across the syllabus is under-preparing for most of the marks.

Section and weightSubsectionsWhat the topics ask you to doWhere a CIA has met it
1. Internal audit roles and responsibilities, 20 percentRoles and competencies (three topics); coordination (three topics)Choose the right assurance and consulting services on risk management; determine the competencies needed; evaluate independence; recommend or improve an organizationwide risk strategy; coordinate with other assurance providers and decide when to rely on them; build a risk assurance mapPart 1 foundations, including assurance versus advisory services and the Three Lines Model; Part 3 coordination with other providers
2. Risk management governance, 25 percentGovernance, risk management and control frameworks (three topics); risk management integration (three topics)Evaluate governance structures and frameworks; assess risk governance and risk culture, including tone at the top; evaluate how risk management is integrated into objectives, strategy and performance; evaluate the response to emerging risks; examine integrated risk reportingPart 1 governance, risk management and control, which covers culture, risk appetite and tolerance and control frameworks
3. Risk management assurance, 55 percentRisk management approach (two topics); assurance processes (nine topics); communication (three topics)Evaluate risk assessment approaches, including control self-assessment, continuous monitoring and maturity models; select analytics; evaluate management’s risk identification; run an organizationwide risk assessment and build the risk-based plan; manage engagements; evaluate risk management at every level; assess risk in systems development, data privacy, cybersecurity and IT controls; evaluate risk registers and monitoring; manage engagement reporting; escalate unacceptable risk acceptance; report on risk management’s effectivenessPart 2 planning and evidence; Part 3 plan and results, including communicating risk acceptance

Three features of the syllabus stand out. The first is the organizationwide view: several topics ask you to synthesize the results of many engagements, other assurance providers’ work and management’s remediation into an overall opinion on risk management, which the CIA touches but does not examine in depth. The second is technology: the assurance section includes topics on risk in the systems development lifecycle and on data privacy, cybersecurity, IT controls and information security, so a candidate without IT audit experience should budget time for the privacy, development lifecycle and cybersecurity assessment material. The third is escalation: topic 3.C.2 asks you to evaluate management’s responses on key risks and communicate to the board when management has accepted a level of risk that may be unacceptable, which is the subject of our risk acceptance guide.

The topics are written as verbs, and the verbs tell you the depth. Most begin with evaluate, assess, analyze or examine, which means scenario questions that ask for a judgment about adequacy, not recall of a definition. A question on 2.A.3, for example, is less likely to ask what tone at the top means than to describe a board that approves a risk appetite statement but never discusses breaches of it, and ask what the auditor should conclude about risk governance. Practise with that in mind: the risk appetite guide, the RCSA process guide and the risk register guide on this site are written around the judgments the exam asks for.

The 2017 Standards caveat

One fact about the current CRMA deserves attention before you register: the IIA states that the CRMA exam is supported by the 2017 Standards, the International Standards for the Professional Practice of Internal Auditing that the Global Internal Audit Standards replaced on 9 January 2025. The CIA moved to the new Standards with its 2025 syllabus; the CRMA, as of September 2026, had not.

For most of the syllabus this matters less than it sounds, because risk governance, risk assessment and assurance over risk management are the same work under either framework. It matters in three places. The vocabulary differs: the 2017 Standards speak of the “internal audit activity” and of “consulting” services, where the Global Internal Audit Standards speak of the internal audit function and “advisory” services, and the CRMA syllabus uses the older terms. The structure differs: the 2017 Standards were numbered attribute and performance standards, from 1000 to 2600, while the new Standards are organized into five domains, fifteen principles and 52 standards. And some requirements moved or changed, which the IPPF to GIAS mapping sets out standard by standard.

The practical advice is simple. Study the CRMA content in the 2017 Standards’ language, because that is the language of the exam, and practise in the Global Internal Audit Standards’ language, because that is the language of your work. Check the CRMA syllabus page before you register: if the IIA updates the exam to the new Standards, the study plan changes with it. The history of the IIA’s Standards explains how the two frameworks relate.

Who can sit it now

Since the prerequisite was removed, the CRMA’s eligibility follows the same education-and-experience pattern as the CIA, with a shorter program window. The table sets out the routes the IIA published.

RouteExperience requiredCan you sit before completing it?
Master’s degree or higherOne yearYes
Bachelor’s degreeTwo yearsYes
Active Internal Audit Practitioner designationFive years, two of them in the last three; one year with a master’s, two with a bachelor’sCheck the IIA’s rules for your combination
No degreeFive years, two of them in the last threeNo; the experience comes first
Qualifying experienceInternal audit, quality assurance, risk management, audit or assessment disciplines, compliance, external audit and internal controlNot applicable
Program windowTwo years from acceptance into the programNot applicable

Two points follow. Risk management experience qualifies, which is what makes the CRMA newly accessible to second-line professionals: a risk manager with a bachelor’s degree and two years in the role now meets the same bar as an internal auditor. And the two-year window is shorter than the CIA’s three, but with one exam rather than three, it is rarely the constraint. As with the CIA, residents of the UK, Ireland and South Africa must be IIA members to apply.

Cost, time and maintenance

The CRMA is inexpensive by certification standards, which is one reason the “is it worth it” question has a lower bar than for most credentials.

ItemIIA membersNon-members
Application$100$220
Exam$465$610
Total to earn, first-time pass$565$830
Study materialThe IIA offers a study guide, practice questions, an on-demand preparation course and an interactive demo examAs for members, at non-member prices
Annual CPE, practising20 hours, including 2 of ethics20 hours, including 2 of ethics
Annual CPE, non-practising10 hours10 hours
Renewal deadline31 December, by attestation in CCMS31 December, by attestation in CCMS
Annual renewal fee$20 ($40 in the grace period)$120 ($240 in the grace period)

For a CIA, the extra cost of keeping the CRMA is small: its renewal fee, $20 a year for members, and no additional CPE. The IIA’s renewal policy lets hours earned for the CRMA count toward the CIA’s requirement, and its own example is a practising CIA and CRMA who completes 40 hours of training in internal audit and risk management assurance and satisfies both. A CIA who already reports forty hours, some of them on risk, needs no extra CPE to keep the CRMA; the CIA CPE guide covers how to log them.

Study time depends almost entirely on what you already know. A practising CIA who has run enterprise risk assessments and built a risk-based plan has met most of the syllabus in the CIA’s 2025 syllabus and in daily work; the gaps are usually the organizationwide synthesis topics, the IT topics and the 2017 vocabulary. A second-line risk professional without audit experience faces the opposite gaps: the assurance process, engagement management and audit reporting. Either way the exam is one sitting, so the preparation is weeks rather than the months the CIA takes.

The honest market picture

Here is the part the course marketing leaves out. The CRMA is a small credential. The IIA reported nearly 17,000 holders by 2021, against more than 220,000 CIAs today, and a credential held by that few people is one that many recruiters, and some hiring managers, will not recognize. In our reading of the market it is seldom a stated requirement for a role. Its value lies mostly inside the internal audit world, where chief audit executives and audit committees know what it means, rather than in the risk management world, where hiring managers tend to look for risk credentials from risk bodies.

That does not make it worthless; it makes it a signal rather than a key. On a CIA’s profile, the CRMA says that this auditor has gone deeper on risk management assurance than the CIA requires, which is a useful differentiator for roles that lead enterprise risk assessments, report on ERM to a board risk committee, or sit in heavily regulated sectors where risk management assurance is a regular engagement. On its own, without the CIA, it says that the holder understands internal audit’s view of risk, which is useful for a risk professional who works closely with internal audit, but it is not a substitute for the CIA in an audit career.

Two further cautions. Because the syllabus is still supported by the 2017 Standards, a hiring manager reading closely may prefer evidence that you know the Global Internal Audit Standards, which the CIA now provides. And because the credential has been rebuilt twice, older CRMAs, those earned before 2021, certified a somewhat different syllabus. None of this is a reason not to take it, but it is a reason to take it for the right purpose.

If you hold it, present it so the signal lands. List it after the CIA rather than before, and pair it on the profile or CV with the risk engagements it supports: the enterprise risk assessment you led, the ERM review you delivered to the board, the risk assurance map you built. A reader who does not know the letters will understand the work, and a reader who does know them will see that the credential and the experience point the same way. In an interview, the useful sentence is not what the CRMA is but what it lets you do: give an independent opinion on whether risk management works.

Who gains, and who should skip it

ProfileOur verdictWhy
CIA who leads or wants to lead enterprise risk assessments and ERM assuranceWorth itLow cost, free maintenance alongside the CIA, and a clear signal of depth in the engagement type the role centres on
Audit manager aiming at chief audit executive in a regulated sectorWorth consideringBoards in banking, insurance and energy ask for opinions on risk management; the CRMA shows preparation for giving one
Second-line risk professional who works closely with internal auditWorth considering nowSince July 2025 you can earn it without the CIA, and it builds a shared vocabulary with the third line; weigh it against risk credentials from risk bodies
Internal auditor without the CIACIA firstThe CIA is the credential the career runs on; the CRMA is a complement, not a substitute
Auditor planning to move into ERM or the chief risk officer’s teamMaybeIt helps you talk about assurance, but risk teams hire for risk management skills; a risk body’s credential may carry more weight there
IT auditorUsually skipThe CISA or CRISC signals more in technology risk roles
Candidate hoping it will substitute for experienceSkipNo credential does; the experience requirement applies here too

The pattern is that the CRMA is most valuable as a second credential for someone whose job already includes risk management assurance, and least valuable as a first credential for someone hoping it will open doors on its own. The certification roadmap by career stage places it where it usually belongs: after the CIA, for auditors moving into senior roles with a risk focus.

The CRMA among other risk credentials

Auditors weighing the CRMA often have another risk credential in mind. The credentials below certify different things, and the right one depends on the kind of risk work you do. We describe what each is for, not its current requirements; check each body’s site before committing.

CredentialBodyWhat it certifiesBest for
CRMAIIAAssurance and advisory work on risk management and governance, from internal audit’s standpointAuditors who give opinions on risk management; risk professionals who work with the third line
CIAIIAThe whole of internal audit, including the fraud, governance, risk and control topicsEvery internal auditor, as the base credential
CRISCISACAIT risk management and information systems controlTechnology risk and IT audit professionals
FRMGARPFinancial risk management: market, credit, liquidity and operational risk, with a quantitative emphasisRisk professionals in banks, asset managers and trading firms
PRMPRMIAProfessional risk management with a financial focusFinancial risk professionals
RIMS-CRMPRIMSEnterprise risk management practiceRisk managers in corporate and public-sector ERM programs
IRM qualificationsInstitute of Risk Management (UK)Enterprise risk management, through certificate and diploma levelsRisk professionals seeking a broad, internationally recognized ERM qualification

The CRMA’s distinctive position is the assurance standpoint. The other credentials certify how to manage risk; the CRMA certifies how to give an independent opinion on whether it is managed well. For an internal auditor, that is the more relevant skill. For a risk manager, it is a complementary one, which is why the removal of the CIA prerequisite matters most to the second line.

What CRMA-level work looks like

The clearest way to judge whether the CRMA fits your career is to look at the engagement it prepares you for: an assurance review of the organization’s risk management program, delivered as an opinion to the audit committee or the board risk committee. Few internal audit functions run one every year, but most regulated organizations expect one on a cycle, and the syllabus reads like its work program. The table sets out the areas such a review covers, the evidence that shows the program working and the gaps auditors most often find.

AreaWhat the auditor testsEvidence that it worksCommon gap
Governance and oversightWho owns risk management, how the board oversees it, how roles divide across the three linesA board or committee charter that assigns risk oversight; minutes that show challenge, not just receipt of reportsOversight on paper, with risk reports noted rather than discussed
Risk appetiteWhether appetite is defined, cascaded into limits and used in decisionsMetrics with thresholds, breaches reported and acted on, appetite cited in strategic decisionsA statement approved once and never linked to limits or decisions
Identification and assessmentHow risks are identified, assessed and refreshed, including emerging risksA consistent method, calibrated scales, a regular refresh, and evidence that new risks enter the registerA register that has not changed in two years while the business has
Responses and controlsWhether each key risk has an owner, a response and controls that are designed and operatingNamed owners, action plans with dates, and links from key risks to tested controlsResponses described as intentions, with no link to any control
Monitoring and reportingWhether key risk indicators, reporting and escalation give leaders what they need to actIndicators with triggers, reports that show movement over time, escalations with outcomesReports that show the same heat map every quarter
CultureWhether people raise risks, and whether leaders reward or punish itSurvey results, speak-up data, examples of bad news travelling up quicklyNo evidence either way, which is itself a finding
IntegrationWhether risk informs strategy setting, planning and performance managementRisk discussed in strategy papers and budget decisions, not in a separate annual exerciseRisk management running beside the business rather than inside it

The hard part of the engagement is the opinion. Topic 3.C.3 asks candidates to formulate and deliver communications on the effectiveness of risk management at multiple levels and organizationwide, and topic 3.B.6 asks them to bring together the results of many engagements, the work of other assurance providers and management’s remediation to support that overall assessment. In practice that means a conclusion the board can use, such as “risk management is effective at the process level and in two of three business units; organizationwide integration with strategy setting is not yet effective”, supported by the evidence in each row above and a clear statement of what was not covered. Auditors who have written that paragraph for a board will find the CRMA’s assurance section familiar. Auditors who have not will find that preparing for the exam is also preparing for the engagement, which is the strongest argument for the credential.

The same logic applies to the advisory side. Topic 1.B.1 asks candidates to recommend establishing an organizationwide risk strategy or improving the existing one, and topic 1.B.3 to help management build a risk assurance map. Both are advisory roles internal audit can take on with safeguards, and both are common requests in organizations whose risk programs are young. Knowing where advice ends and ownership begins, and documenting the safeguards when the function helps build what it will later audit, is what the roles section tests and what the independence and objectivity requirements require.

How to prepare

Preparation follows the weights. Spend roughly half your time on the risk management assurance section, a quarter on governance and a fifth on roles and coordination, and weight within the assurance section toward the topics you do least at work. The IIA’s own study guide, practice questions, on-demand preparation course and interactive demo exam are the materials written to this syllabus; the demo exam is worth taking early, to learn the question style before you study.

Beyond the IIA’s materials, the best preparation is doing the work the syllabus describes, on paper if not in your job. Build an organizationwide risk assessment and a risk-based plan from it, using the risk assessment playbook and the audit plan template. Draft a risk assurance map for an organization you know, listing each key risk, the first- and second-line activities that manage it and the assurance providers that cover it; topic 1.B.3 asks for exactly that. Evaluate a risk register against the criteria in the risk register guide. Write a one-page opinion on a risk management process’s effectiveness, the communication topic 3.C.3 describes. And re-read the Three Lines Model and COSO’s seventeen principles, because the frameworks topics assume both.

If you areYour likely gapsWhere to put the time
A practising CIAOrganizationwide synthesis, IT topics, 2017 vocabularyTopics 3.B.5, 3.B.6 and 3.C.3; 3.B.7 and 3.B.8; the 2017 Standards’ terms
A second-line risk professionalThe assurance process, engagement management, audit reporting, independenceTopics 1.A.3, 3.B.3, 3.B.4 and 3.C.1; the IIA’s view of assurance versus advisory work
An IT auditorRisk governance and culture, ERM frameworksSection 2 in full; the risk management frameworks toolkit
An external auditorInternal audit’s roles, coordination and the risk-based planSection 1 in full; topics 3.B.2 and 3.B.3

Is it worth it for you? A five-minute test

Answer four questions honestly. Do you give, or want to give, an opinion on risk management to senior management or the board? Does your employer, sector or regulator care about risk management assurance as a distinct engagement? Do you already hold, or plan to hold, the CIA, so that the CRMA is additive rather than a substitute? And is the cost, under $600 for a member who passes first time, small relative to what you would spend on anything else that signals the same depth?

Three or four yes answers: take it, probably within a year of passing the CIA while the Part 1 governance and risk material is fresh. One or two: it is a reasonable choice but not a priority; the CIA, the CISA or the CFE may do more for your specific path. None: skip it, and spend the time on the risk engagements themselves, which will do more for your reputation than the letters. Whatever the answer, the CIA remains the base; the CIA exam guide and the CIA Study Planner are where to start if you do not hold it yet.

Questions auditors ask about the CRMA

Do I still need the CIA to earn the CRMA?

No. The IIA removed the CIA prerequisite on 15 July 2025. The CRMA now has its own education and experience routes, and risk management experience counts.

Does the CRMA count toward the CIA?

Not as exam credit: passing the CRMA does not exempt you from any CIA part. The link runs through maintenance instead, since CPE hours earned for the CRMA can count toward the CIA’s annual requirement.

Is the CRMA based on the new Global Internal Audit Standards?

As of September 2026 the IIA stated that the CRMA exam is supported by the 2017 Standards. Study the exam in that language and check the syllabus page before you register, in case it has been updated.

What happened to the CCSA, CGAP and CFSA?

The IIA retired all three: new applications closed at the end of 2018 and final testing ended in June 2021. Control self-assessment now sits within the CRMA syllabus, and holders of the retired credentials can keep them through annual renewal. Our guide to the IIA’s specialty and retired credentials covers what holders should do.

Can I take the CRMA online?

The CRMA is delivered at Pearson VUE test centers. The IIA ended online proctoring for its exams in May 2025, so plan for a test-center appointment, and book it early, because seats fill weeks ahead in many cities.

Should I take the CRMA or the CIA first?

For an internal auditor, the CIA first: it is the base credential of the career and the one that examines the Global Internal Audit Standards. For a second-line risk professional who does not plan an audit career, the CRMA can now come first, or alone, since the CIA is no longer required.

Will employers pay for it?

Many will, especially under a policy that already funds the CIA, and at under $600 for members it is an easier request than most credentials. Frame the request around the risk engagements you lead or will lead, not around the letters.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading