Most CRISC candidates do not fail for lack of intelligence. They fail for lack of structure — and because they study the wrong way for this particular exam. CRISC is not a recall test. It is a judgment test dressed up as multiple choice, and 90 days is enough time to build that judgment if you spend the hours where the exam spends its weight.
The one mindset shift that decides your result
Before any schedule: understand what ISACA is testing. Every CRISC question with a BEST or FIRST in it has a logic, and that logic is the ISACA worldview — business objectives come first, accountability flows upward, and evidence beats assumption every time.
You can delegate responsibility. You can never delegate accountability. Internalise that one sentence and an entire category of exam questions resolves itself.
When you practice, never just check whether you got a question right. Read the rationale for every option, including the ones you ruled out instantly. The distractors are where ISACA teaches you its logic — each wrong answer is wrong for a reason that will reappear, slightly disguised, on exam day.
Match your hours to the domain weights
The exam outline tells you exactly where the marks are. Study time should follow it, not your comfort zone.
| Domain | Weight | Study window |
|---|---|---|
| 1 · Governance | 26% | Weeks 1–2 |
| 2 · IT Risk Assessment | 20% | Weeks 3–4 |
| 3 · Risk Response & Reporting | 32% | Weeks 5–7 |
| 4 · Information Technology & Security | 22% | Weeks 8–10 |
| Mock exams & weak-area review | — | Weeks 11–13 |
Notice that Domain 3 — the heaviest — gets three weeks. Most self-built plans do the opposite: candidates linger in Domain 1 because governance concepts feel readable, then sprint through risk response. The exam punishes that.
Weeks 1–2 · Governance
Your goal is to think like the board thinks. Work through organisational governance versus risk governance, the three lines of defense, risk appetite versus tolerance versus capacity, and the structure of policies, standards and procedures.
The trap in this domain is treating terms as interchangeable. Appetite is the amount of risk the organisation is willing to take; tolerance is the acceptable deviation around that; capacity is the maximum it can absorb. Exam questions are built on candidates blurring these.
End week 2 with 50 practice questions in open-book mode. Score doesn't matter yet — rationale absorption does.
Weeks 3–4 · IT Risk Assessment
This is the analytical core: threat and vulnerability identification, risk scenarios, likelihood and impact, inherent versus residual risk, and the quantitative basics — SLE, ARO, ALE. Don't over-invest in the formulas; CRISC asks fewer pure-calculation questions than candidates expect. What it asks constantly is sequence: identify before you assess, assess before you respond.
Build five risk scenarios from your own workplace this fortnight. Real scenarios make the abstract concrete, and CRISC scenario questions read exactly like incidents you've lived through.
Weeks 5–7 · Risk Response and Reporting
Three weeks, because a third of your exam lives here. Master the four response options — accept, avoid, transfer, mitigate — and, more importantly, when each is appropriate relative to appetite and cost. Then control design: key risk indicators versus key performance indicators versus key control indicators, control ownership, and what makes a KRI actually useful (leading, measurable, tied to a threshold that triggers action).
The reporting half is underrated. Who receives what, at what level of aggregation, and what the risk register must capture for a decision-maker to act — these produce reliable marks. If a question asks what to do after assessing a risk that exceeds appetite, the answer almost always routes through the risk owner, not around them.
Weeks 8–10 · IT and Security
The most technical domain, and the one where security-background candidates relax too early. ISACA tests these topics through a risk lens, not an operations lens: the question is rarely "how does this control work" and nearly always "which control addresses this risk best given the context." Cover SDLC and emerging tech risk, IAM concepts, security awareness, BCP/DRP relationships (RTO, RPO, and who sets them), and control testing.
Weeks 11–13 · Mock exams and triage
Now switch from learning to calibrating.
- Sit a full 150-question, 4-hour mock in week 11 under real conditions — timed, closed-book, no pauses.
- Triage by domain. Anything under 60% gets a dedicated review day; re-read rationales, not chapters.
- Sit a second full mock in week 12. You're looking for 75%+ consistently before you book with confidence.
- The final week is light: error-log review, one short daily question set, and rest. Cramming in the last 72 hours measurably hurts judgment-based exams.
Pacing, burnout and the exam itself
Ninety minutes a day, six days a week, beats four-hour weekend marathons — spaced repetition is how rationale-logic sticks. Keep one full rest day. On exam day you have 96 seconds per question; flag anything that takes more than two minutes and move. Unanswered questions score zero, while an educated elimination usually gets you to a coin flip between two options — and the ISACA worldview breaks the tie: the answer that assesses first, respects accountability, and serves the business objective wins.
Pass mark is 450 on an 800-point scale. With weighted effort and rationale-first practice, 90 days is not just enough — it's comfortable.