The Certification in Risk Management Assurance is the IIA’s specialist credential for one question boards increasingly ask their auditors: is our risk management actually working? It has always been a niche credential, overshadowed by the CIA, and for four years it was also a hard one to reach, because from 2021 it required an active CIA before you could apply. In July 2025 the IIA removed that prerequisite. The CRMA is now a standalone certification with its own eligibility rules, one exam and a modest fee, which reopens a question many auditors had stopped asking: is it worth it?
The answer depends on who you are and what you want the letters to do. This guide explains what the CRMA certifies, how it has changed, what the exam tests topic by topic, who can sit it now, what it costs to earn and keep, how the market actually recognizes it, and who gains most from it. It ends with a short test for deciding. The facts are those the IIA published as of September 2026; the judgments about value are ours, and we say where they are.
In this guide
- What the CRMA certifies
- How the credential has changed
- The exam and the syllabus, topic by topic
- The 2017 Standards caveat
- Who can sit it now
- Cost, time and maintenance
- The honest market picture
- Who gains, and who should skip it
- The CRMA among other risk credentials
- What CRMA-level work looks like
- How to prepare
- Is it worth it for you? A five-minute test
- Questions auditors ask about the CRMA
- Related guides
What the CRMA certifies
The IIA describes the CRMA as validating expertise in risk management, governance and internal control, and the organizational knowledge needed to provide risk management assurance to audit committees and executive management. In practice that means three capabilities. First, knowing internal audit’s role in risk management: which assurance and advisory services the function should offer, what competencies they need, and how to coordinate with other assurance providers. Second, evaluating risk governance: frameworks, risk culture, the integration of risk management into strategy and performance, and the organization’s response to emerging risks. Third, and above all, giving assurance over risk management itself: assessing management’s risk identification and assessment, building a risk-based plan from an organizationwide risk assessment, evaluating risk management at every level, and telling the board what the function concludes.
That last capability is what distinguishes it. The CIA certifies the whole of internal audit, of which risk is one part. The CRMA certifies depth in one engagement type that has grown in importance as boards have built enterprise risk management programs and asked internal audit to tell them whether those programs work. The IIA’s position on internal audit’s role in ERM has always been careful about the line between giving assurance on risk management and running it, and the CRMA syllabus is built on that line: it examines the assurance and advisory roles, not the job of the risk manager.
How the credential has changed
The CRMA has been rebuilt twice, and much of what is written about it online describes a version that no longer exists. The table sets out the changes the IIA has published.
| Date | Change | What it meant |
|---|---|---|
| 2011 | The CRMA introduced | By the eve of the 2021 revision, candidates passed CIA Part 1 and a separate 100-question CRMA exam and needed two years of internal audit experience |
| 2018 to 2021 | The Certification in Control Self-Assessment retired | New CCSA applications closed at the end of 2018 and final testing ended in June 2021; control self-assessment now appears in the CRMA syllabus |
| 1 April 2021 | Revised CRMA program effective | An active CIA became a prerequisite; experience rose to five years of internal audit or risk management; the syllabus moved from four areas to three, with risk management assurance at 55 percent |
| 1 October 2021 | Revised exam launched | The exam grew from 100 questions in 120 minutes to 125 questions in 150 minutes |
| 15 July 2025 | CIA prerequisite removed | The CRMA became a standalone certification with education-based experience rules |
| 1 April 2026 | Delayed scoring | CRMA results, like CIA results, are released within about three weeks rather than at the test center |
| September 2026 | Current program | One exam of 120 questions in 150 minutes, a two-year program window, and a syllabus that the IIA says is supported by the 2017 Standards |
By the time of the 2021 revision, the IIA said nearly 17,000 professionals had earned the CRMA since its introduction. The 2021 changes made it a credential for experienced CIAs only, which narrowed the candidate pool; the 2025 change reversed the prerequisite while keeping the three-section syllabus. The practical effect is that a risk management professional in the second line, or an auditor without the CIA, can now earn an IIA credential centred on risk assurance without passing the three CIA parts first.
The exam and the syllabus, topic by topic
The CRMA exam has 120 questions in 150 minutes, 75 seconds a question, and is sat at a Pearson VUE test center. The syllabus has three sections and 26 topics. The weights are unusual: more than half the exam is the third section, risk management assurance, so a candidate who prepares evenly across the syllabus is under-preparing for most of the marks.
| Section and weight | Subsections | What the topics ask you to do | Where a CIA has met it |
|---|---|---|---|
| 1. Internal audit roles and responsibilities, 20 percent | Roles and competencies (three topics); coordination (three topics) | Choose the right assurance and consulting services on risk management; determine the competencies needed; evaluate independence; recommend or improve an organizationwide risk strategy; coordinate with other assurance providers and decide when to rely on them; build a risk assurance map | Part 1 foundations, including assurance versus advisory services and the Three Lines Model; Part 3 coordination with other providers |
| 2. Risk management governance, 25 percent | Governance, risk management and control frameworks (three topics); risk management integration (three topics) | Evaluate governance structures and frameworks; assess risk governance and risk culture, including tone at the top; evaluate how risk management is integrated into objectives, strategy and performance; evaluate the response to emerging risks; examine integrated risk reporting | Part 1 governance, risk management and control, which covers culture, risk appetite and tolerance and control frameworks |
| 3. Risk management assurance, 55 percent | Risk management approach (two topics); assurance processes (nine topics); communication (three topics) | Evaluate risk assessment approaches, including control self-assessment, continuous monitoring and maturity models; select analytics; evaluate management’s risk identification; run an organizationwide risk assessment and build the risk-based plan; manage engagements; evaluate risk management at every level; assess risk in systems development, data privacy, cybersecurity and IT controls; evaluate risk registers and monitoring; manage engagement reporting; escalate unacceptable risk acceptance; report on risk management’s effectiveness | Part 2 planning and evidence; Part 3 plan and results, including communicating risk acceptance |
Three features of the syllabus stand out. The first is the organizationwide view: several topics ask you to synthesize the results of many engagements, other assurance providers’ work and management’s remediation into an overall opinion on risk management, which the CIA touches but does not examine in depth. The second is technology: the assurance section includes topics on risk in the systems development lifecycle and on data privacy, cybersecurity, IT controls and information security, so a candidate without IT audit experience should budget time for the privacy, development lifecycle and cybersecurity assessment material. The third is escalation: topic 3.C.2 asks you to evaluate management’s responses on key risks and communicate to the board when management has accepted a level of risk that may be unacceptable, which is the subject of our risk acceptance guide.
The topics are written as verbs, and the verbs tell you the depth. Most begin with evaluate, assess, analyze or examine, which means scenario questions that ask for a judgment about adequacy, not recall of a definition. A question on 2.A.3, for example, is less likely to ask what tone at the top means than to describe a board that approves a risk appetite statement but never discusses breaches of it, and ask what the auditor should conclude about risk governance. Practise with that in mind: the risk appetite guide, the RCSA process guide and the risk register guide on this site are written around the judgments the exam asks for.
The 2017 Standards caveat
One fact about the current CRMA deserves attention before you register: the IIA states that the CRMA exam is supported by the 2017 Standards, the International Standards for the Professional Practice of Internal Auditing that the Global Internal Audit Standards replaced on 9 January 2025. The CIA moved to the new Standards with its 2025 syllabus; the CRMA, as of September 2026, had not.
For most of the syllabus this matters less than it sounds, because risk governance, risk assessment and assurance over risk management are the same work under either framework. It matters in three places. The vocabulary differs: the 2017 Standards speak of the “internal audit activity” and of “consulting” services, where the Global Internal Audit Standards speak of the internal audit function and “advisory” services, and the CRMA syllabus uses the older terms. The structure differs: the 2017 Standards were numbered attribute and performance standards, from 1000 to 2600, while the new Standards are organized into five domains, fifteen principles and 52 standards. And some requirements moved or changed, which the IPPF to GIAS mapping sets out standard by standard.
The practical advice is simple. Study the CRMA content in the 2017 Standards’ language, because that is the language of the exam, and practise in the Global Internal Audit Standards’ language, because that is the language of your work. Check the CRMA syllabus page before you register: if the IIA updates the exam to the new Standards, the study plan changes with it. The history of the IIA’s Standards explains how the two frameworks relate.
Who can sit it now
Since the prerequisite was removed, the CRMA’s eligibility follows the same education-and-experience pattern as the CIA, with a shorter program window. The table sets out the routes the IIA published.
| Route | Experience required | Can you sit before completing it? |
|---|---|---|
| Master’s degree or higher | One year | Yes |
| Bachelor’s degree | Two years | Yes |
| Active Internal Audit Practitioner designation | Five years, two of them in the last three; one year with a master’s, two with a bachelor’s | Check the IIA’s rules for your combination |
| No degree | Five years, two of them in the last three | No; the experience comes first |
| Qualifying experience | Internal audit, quality assurance, risk management, audit or assessment disciplines, compliance, external audit and internal control | Not applicable |
| Program window | Two years from acceptance into the program | Not applicable |
Two points follow. Risk management experience qualifies, which is what makes the CRMA newly accessible to second-line professionals: a risk manager with a bachelor’s degree and two years in the role now meets the same bar as an internal auditor. And the two-year window is shorter than the CIA’s three, but with one exam rather than three, it is rarely the constraint. As with the CIA, residents of the UK, Ireland and South Africa must be IIA members to apply.
Cost, time and maintenance
The CRMA is inexpensive by certification standards, which is one reason the “is it worth it” question has a lower bar than for most credentials.
| Item | IIA members | Non-members |
|---|---|---|
| Application | $100 | $220 |
| Exam | $465 | $610 |
| Total to earn, first-time pass | $565 | $830 |
| Study material | The IIA offers a study guide, practice questions, an on-demand preparation course and an interactive demo exam | As for members, at non-member prices |
| Annual CPE, practising | 20 hours, including 2 of ethics | 20 hours, including 2 of ethics |
| Annual CPE, non-practising | 10 hours | 10 hours |
| Renewal deadline | 31 December, by attestation in CCMS | 31 December, by attestation in CCMS |
| Annual renewal fee | $20 ($40 in the grace period) | $120 ($240 in the grace period) |
For a CIA, the extra cost of keeping the CRMA is small: its renewal fee, $20 a year for members, and no additional CPE. The IIA’s renewal policy lets hours earned for the CRMA count toward the CIA’s requirement, and its own example is a practising CIA and CRMA who completes 40 hours of training in internal audit and risk management assurance and satisfies both. A CIA who already reports forty hours, some of them on risk, needs no extra CPE to keep the CRMA; the CIA CPE guide covers how to log them.
Study time depends almost entirely on what you already know. A practising CIA who has run enterprise risk assessments and built a risk-based plan has met most of the syllabus in the CIA’s 2025 syllabus and in daily work; the gaps are usually the organizationwide synthesis topics, the IT topics and the 2017 vocabulary. A second-line risk professional without audit experience faces the opposite gaps: the assurance process, engagement management and audit reporting. Either way the exam is one sitting, so the preparation is weeks rather than the months the CIA takes.
The honest market picture
Here is the part the course marketing leaves out. The CRMA is a small credential. The IIA reported nearly 17,000 holders by 2021, against more than 220,000 CIAs today, and a credential held by that few people is one that many recruiters, and some hiring managers, will not recognize. In our reading of the market it is seldom a stated requirement for a role. Its value lies mostly inside the internal audit world, where chief audit executives and audit committees know what it means, rather than in the risk management world, where hiring managers tend to look for risk credentials from risk bodies.
That does not make it worthless; it makes it a signal rather than a key. On a CIA’s profile, the CRMA says that this auditor has gone deeper on risk management assurance than the CIA requires, which is a useful differentiator for roles that lead enterprise risk assessments, report on ERM to a board risk committee, or sit in heavily regulated sectors where risk management assurance is a regular engagement. On its own, without the CIA, it says that the holder understands internal audit’s view of risk, which is useful for a risk professional who works closely with internal audit, but it is not a substitute for the CIA in an audit career.
Two further cautions. Because the syllabus is still supported by the 2017 Standards, a hiring manager reading closely may prefer evidence that you know the Global Internal Audit Standards, which the CIA now provides. And because the credential has been rebuilt twice, older CRMAs, those earned before 2021, certified a somewhat different syllabus. None of this is a reason not to take it, but it is a reason to take it for the right purpose.
If you hold it, present it so the signal lands. List it after the CIA rather than before, and pair it on the profile or CV with the risk engagements it supports: the enterprise risk assessment you led, the ERM review you delivered to the board, the risk assurance map you built. A reader who does not know the letters will understand the work, and a reader who does know them will see that the credential and the experience point the same way. In an interview, the useful sentence is not what the CRMA is but what it lets you do: give an independent opinion on whether risk management works.
Who gains, and who should skip it
| Profile | Our verdict | Why |
|---|---|---|
| CIA who leads or wants to lead enterprise risk assessments and ERM assurance | Worth it | Low cost, free maintenance alongside the CIA, and a clear signal of depth in the engagement type the role centres on |
| Audit manager aiming at chief audit executive in a regulated sector | Worth considering | Boards in banking, insurance and energy ask for opinions on risk management; the CRMA shows preparation for giving one |
| Second-line risk professional who works closely with internal audit | Worth considering now | Since July 2025 you can earn it without the CIA, and it builds a shared vocabulary with the third line; weigh it against risk credentials from risk bodies |
| Internal auditor without the CIA | CIA first | The CIA is the credential the career runs on; the CRMA is a complement, not a substitute |
| Auditor planning to move into ERM or the chief risk officer’s team | Maybe | It helps you talk about assurance, but risk teams hire for risk management skills; a risk body’s credential may carry more weight there |
| IT auditor | Usually skip | The CISA or CRISC signals more in technology risk roles |
| Candidate hoping it will substitute for experience | Skip | No credential does; the experience requirement applies here too |
The pattern is that the CRMA is most valuable as a second credential for someone whose job already includes risk management assurance, and least valuable as a first credential for someone hoping it will open doors on its own. The certification roadmap by career stage places it where it usually belongs: after the CIA, for auditors moving into senior roles with a risk focus.
The CRMA among other risk credentials
Auditors weighing the CRMA often have another risk credential in mind. The credentials below certify different things, and the right one depends on the kind of risk work you do. We describe what each is for, not its current requirements; check each body’s site before committing.
| Credential | Body | What it certifies | Best for |
|---|---|---|---|
| CRMA | IIA | Assurance and advisory work on risk management and governance, from internal audit’s standpoint | Auditors who give opinions on risk management; risk professionals who work with the third line |
| CIA | IIA | The whole of internal audit, including the fraud, governance, risk and control topics | Every internal auditor, as the base credential |
| CRISC | ISACA | IT risk management and information systems control | Technology risk and IT audit professionals |
| FRM | GARP | Financial risk management: market, credit, liquidity and operational risk, with a quantitative emphasis | Risk professionals in banks, asset managers and trading firms |
| PRM | PRMIA | Professional risk management with a financial focus | Financial risk professionals |
| RIMS-CRMP | RIMS | Enterprise risk management practice | Risk managers in corporate and public-sector ERM programs |
| IRM qualifications | Institute of Risk Management (UK) | Enterprise risk management, through certificate and diploma levels | Risk professionals seeking a broad, internationally recognized ERM qualification |
The CRMA’s distinctive position is the assurance standpoint. The other credentials certify how to manage risk; the CRMA certifies how to give an independent opinion on whether it is managed well. For an internal auditor, that is the more relevant skill. For a risk manager, it is a complementary one, which is why the removal of the CIA prerequisite matters most to the second line.
What CRMA-level work looks like
The clearest way to judge whether the CRMA fits your career is to look at the engagement it prepares you for: an assurance review of the organization’s risk management program, delivered as an opinion to the audit committee or the board risk committee. Few internal audit functions run one every year, but most regulated organizations expect one on a cycle, and the syllabus reads like its work program. The table sets out the areas such a review covers, the evidence that shows the program working and the gaps auditors most often find.
| Area | What the auditor tests | Evidence that it works | Common gap |
|---|---|---|---|
| Governance and oversight | Who owns risk management, how the board oversees it, how roles divide across the three lines | A board or committee charter that assigns risk oversight; minutes that show challenge, not just receipt of reports | Oversight on paper, with risk reports noted rather than discussed |
| Risk appetite | Whether appetite is defined, cascaded into limits and used in decisions | Metrics with thresholds, breaches reported and acted on, appetite cited in strategic decisions | A statement approved once and never linked to limits or decisions |
| Identification and assessment | How risks are identified, assessed and refreshed, including emerging risks | A consistent method, calibrated scales, a regular refresh, and evidence that new risks enter the register | A register that has not changed in two years while the business has |
| Responses and controls | Whether each key risk has an owner, a response and controls that are designed and operating | Named owners, action plans with dates, and links from key risks to tested controls | Responses described as intentions, with no link to any control |
| Monitoring and reporting | Whether key risk indicators, reporting and escalation give leaders what they need to act | Indicators with triggers, reports that show movement over time, escalations with outcomes | Reports that show the same heat map every quarter |
| Culture | Whether people raise risks, and whether leaders reward or punish it | Survey results, speak-up data, examples of bad news travelling up quickly | No evidence either way, which is itself a finding |
| Integration | Whether risk informs strategy setting, planning and performance management | Risk discussed in strategy papers and budget decisions, not in a separate annual exercise | Risk management running beside the business rather than inside it |
The hard part of the engagement is the opinion. Topic 3.C.3 asks candidates to formulate and deliver communications on the effectiveness of risk management at multiple levels and organizationwide, and topic 3.B.6 asks them to bring together the results of many engagements, the work of other assurance providers and management’s remediation to support that overall assessment. In practice that means a conclusion the board can use, such as “risk management is effective at the process level and in two of three business units; organizationwide integration with strategy setting is not yet effective”, supported by the evidence in each row above and a clear statement of what was not covered. Auditors who have written that paragraph for a board will find the CRMA’s assurance section familiar. Auditors who have not will find that preparing for the exam is also preparing for the engagement, which is the strongest argument for the credential.
The same logic applies to the advisory side. Topic 1.B.1 asks candidates to recommend establishing an organizationwide risk strategy or improving the existing one, and topic 1.B.3 to help management build a risk assurance map. Both are advisory roles internal audit can take on with safeguards, and both are common requests in organizations whose risk programs are young. Knowing where advice ends and ownership begins, and documenting the safeguards when the function helps build what it will later audit, is what the roles section tests and what the independence and objectivity requirements require.
How to prepare
Preparation follows the weights. Spend roughly half your time on the risk management assurance section, a quarter on governance and a fifth on roles and coordination, and weight within the assurance section toward the topics you do least at work. The IIA’s own study guide, practice questions, on-demand preparation course and interactive demo exam are the materials written to this syllabus; the demo exam is worth taking early, to learn the question style before you study.
Beyond the IIA’s materials, the best preparation is doing the work the syllabus describes, on paper if not in your job. Build an organizationwide risk assessment and a risk-based plan from it, using the risk assessment playbook and the audit plan template. Draft a risk assurance map for an organization you know, listing each key risk, the first- and second-line activities that manage it and the assurance providers that cover it; topic 1.B.3 asks for exactly that. Evaluate a risk register against the criteria in the risk register guide. Write a one-page opinion on a risk management process’s effectiveness, the communication topic 3.C.3 describes. And re-read the Three Lines Model and COSO’s seventeen principles, because the frameworks topics assume both.
| If you are | Your likely gaps | Where to put the time |
|---|---|---|
| A practising CIA | Organizationwide synthesis, IT topics, 2017 vocabulary | Topics 3.B.5, 3.B.6 and 3.C.3; 3.B.7 and 3.B.8; the 2017 Standards’ terms |
| A second-line risk professional | The assurance process, engagement management, audit reporting, independence | Topics 1.A.3, 3.B.3, 3.B.4 and 3.C.1; the IIA’s view of assurance versus advisory work |
| An IT auditor | Risk governance and culture, ERM frameworks | Section 2 in full; the risk management frameworks toolkit |
| An external auditor | Internal audit’s roles, coordination and the risk-based plan | Section 1 in full; topics 3.B.2 and 3.B.3 |
Is it worth it for you? A five-minute test
Answer four questions honestly. Do you give, or want to give, an opinion on risk management to senior management or the board? Does your employer, sector or regulator care about risk management assurance as a distinct engagement? Do you already hold, or plan to hold, the CIA, so that the CRMA is additive rather than a substitute? And is the cost, under $600 for a member who passes first time, small relative to what you would spend on anything else that signals the same depth?
Three or four yes answers: take it, probably within a year of passing the CIA while the Part 1 governance and risk material is fresh. One or two: it is a reasonable choice but not a priority; the CIA, the CISA or the CFE may do more for your specific path. None: skip it, and spend the time on the risk engagements themselves, which will do more for your reputation than the letters. Whatever the answer, the CIA remains the base; the CIA exam guide and the CIA Study Planner are where to start if you do not hold it yet.
Questions auditors ask about the CRMA
Do I still need the CIA to earn the CRMA?
No. The IIA removed the CIA prerequisite on 15 July 2025. The CRMA now has its own education and experience routes, and risk management experience counts.
Does the CRMA count toward the CIA?
Not as exam credit: passing the CRMA does not exempt you from any CIA part. The link runs through maintenance instead, since CPE hours earned for the CRMA can count toward the CIA’s annual requirement.
Is the CRMA based on the new Global Internal Audit Standards?
As of September 2026 the IIA stated that the CRMA exam is supported by the 2017 Standards. Study the exam in that language and check the syllabus page before you register, in case it has been updated.
What happened to the CCSA, CGAP and CFSA?
The IIA retired all three: new applications closed at the end of 2018 and final testing ended in June 2021. Control self-assessment now sits within the CRMA syllabus, and holders of the retired credentials can keep them through annual renewal. Our guide to the IIA’s specialty and retired credentials covers what holders should do.
Can I take the CRMA online?
The CRMA is delivered at Pearson VUE test centers. The IIA ended online proctoring for its exams in May 2025, so plan for a test-center appointment, and book it early, because seats fill weeks ahead in many cities.
Should I take the CRMA or the CIA first?
For an internal auditor, the CIA first: it is the base credential of the career and the one that examines the Global Internal Audit Standards. For a second-line risk professional who does not plan an audit career, the CRMA can now come first, or alone, since the CIA is no longer required.
Will employers pay for it?
Many will, especially under a policy that already funds the CIA, and at under $600 for members it is an easier request than most credentials. Frame the request around the risk engagements you lead or will lead, not around the letters.
Related guides
- The CIA exam, explained — the base credential, with study plans.
- The IIA’s specialty and retired credentials — CGAP, CFSA, CCSA and what holders should do.
- A certification roadmap by career stage — where the CRMA fits.
- Internal audit’s role in ERM — the assurance line the CRMA is built on.
- The annual risk assessment playbook — the organizationwide assessment the syllabus examines.
- Risk appetite statements — what auditors test in them.
- The RCSA process — control self-assessment in practice.
- Risk acceptance by management — the escalation topic 3.C.2 tests.
- IPPF to GIAS mapping — the 2017 Standards against the new ones.
- CIA vs CFE — the other common specialist pairing.
- IAP vs CIA — the IIA’s entry designation and the route to the CIA.
- Internal audit certifications compared — every credential on one page.
Leave a Reply