Live CRISC Training for IT Risk & GRC Professionals Across South Africa
Prepare for the ISACA Certified in Risk and Information Systems Control (CRISC) exam through 32+ hours of guided learning for professionals across South Africa. Choose nationwide in-person, live online, hybrid, self-paced or corporate preparation with recordings, an AI-powered LMS, mind maps, study notes, question practice, mock exams and structured doubt support.
EduDelphi provides independent CRISC exam preparation. ISACA administers the official exam and awards CRISC certification when its requirements are met.
CRISC Course in South Africa: What You Are Planning For
A clear view of the learning system, official examination and eventual certification route before you choose a delivery option.
| Course detail | Current reference |
|---|---|
| Credential | Certified in Risk and Information Systems Control (CRISC) |
| Credential body | ISACA |
| EduDelphi role | Independent CRISC exam preparation, revision support and route guidance |
| Delivery | Nationwide in-person, live online, hybrid, self-paced and corporate learning |
| Guided learning | 32+ hours with recordings, AI LMS, notes, mind maps, practice and doubt support |
| Official exam | 150 multiple-choice questions across four job-practice domains |
| Testing | PSI testing centre or remote proctoring where ISACA currently makes it available |
| Official fees | Separate ISACA fees in USD; EduDelphi tuition quoted separately in ZAR |
What Is CRISC Certification?
CRISC stands for Certified in Risk and Information Systems Control. It is ISACA’s credential for professionals who identify, assess, respond to and report on technology risk while connecting controls to business objectives.
CRISC is most relevant when risk ownership, governance, controls, resilience or technology assurance are part of your responsibilities. It is not a generic cyber-technical qualification.
Provider and credential body: EduDelphi supports preparation. ISACA controls exam registration, testing, certification applications, experience review and the CRISC designation.

Who Should Take a CRISC Course in South Africa?
CRISC is a strong fit when you need to turn technology-risk information into clear ownership, control and reporting decisions.
IT risk & GRC professionals
Risk analysts, GRC specialists and control professionals who assess technology risk and support risk treatment.
Audit & assurance teams
Internal audit, technology-assurance and advisory professionals who evaluate controls, evidence and remediation.
Security & technology leaders
Security, IT, resilience and governance professionals developing stronger business-risk and control judgement.
Choose a different route when it fits better: CISA is more audit-centred, CISM is built for security-management leadership and CISSP is wider security-domain coverage.
Keep Teaching, Revision & Risk Practice in One CRISC Study System
The programme is designed to keep structured learning, question practice and revision accessible around a working schedule.
Live expert-led learning
Trainer-led sessions connecting the CRISC domains to risk ownership, control decisions and business impact.
Recordings & reinforcement
Revisit difficult concepts and keep study continuity when professional commitments interrupt a planned session.
AI-powered LMS
Bring notes, mind maps, infographics and revision resources into one organised study environment.
Question practice & mocks
Use question sets, targeted drills, revision activities and mock exams to identify weaker domain areas.
Case-based judgement
Work through risk, controls, reporting and remediation scenarios instead of relying only on definition recall.
Exam-route guidance
Plan the separate ISACA registration, PSI scheduling, official costs and eventual certification journey with clarity.
CRISC Exam Syllabus: Four Current ISACA Domains
The CRISC examination covers four job-practice domains. Preparation is mapped to the official outline applicable to your intended exam administration.
Official outline verified August 2026.
1. Governance — 26%
- Enterprise governance, organisational structures and risk culture.
- Risk management, policies, standards and accountability.
- Metrics, monitoring and reporting to management and stakeholders.
2. Risk Assessment — 22%
- Risk identification, analysis, likelihood and impact assessment.
- Threats, vulnerabilities, controls and risk scenarios.
- Risk registers, assessment methods and risk prioritisation.
3. Risk Response and Reporting — 32%
- Risk-treatment options, response planning and control selection.
- Control design, implementation, testing and monitoring.
- Risk communication, escalation, reporting and remediation tracking.
4. Technology and Security — 20%
- Technology architecture, security concepts and data protection.
- Resilience, change, operations, third parties and emerging technology risk.
- Applying technical context to business-risk and control decisions.
Technology Risk & Governance in South Africa
CRISC develops practical technology-risk and control capability for professionals working alongside South Africa’s governance, privacy and financial-sector expectations.
| Local context | Why it matters to CRISC learners |
|---|---|
| POPIA security safeguards | Reasonable technical and organisational measures, security risk and data protection. |
| Joint Standard 1 of 2023 | IT governance and risk-management requirements for applicable financial institutions. |
| Joint Standard 2 of 2024 | Cybersecurity and cyber-resilience requirements for specified financial institutions. |
| King V | Current South African corporate-governance context, including board-level governance and risk oversight. |
POPIA section 19 addresses appropriate technical and organisational safeguards. Joint Standard 1 of 2023 became effective on 15 November 2024, Joint Standard 2 of 2024 on 1 June 2025, and King V applies to financial years beginning on or after 1 January 2026.
Important distinction: CRISC develops technology-risk and control capability; it does not by itself establish compliance with POPIA, King V or financial-sector regulatory requirements.
CRISC Exam Format, Eligibility & Certification Route
You can sit the CRISC exam before meeting the full experience requirement. Passing the examination is one step toward ISACA certification.
Register with ISACA
Registration is continuous. Payment establishes the current ISACA exam-eligibility period.
Prepare and schedule
Book through PSI at an authorised test centre or through remote proctoring where available. Appointments may be scheduled from 48 hours after payment, subject to availability.
Pass the CRISC exam
Complete the computer-based 150-question examination within the four-hour appointment.
Apply for certification
Submit your ISACA certification application after meeting the experience and professional-ethics requirements.
ISACA currently requires three or more years of qualifying professional experience across at least two CRISC domains. Experience must be within the 10 years before application, and candidates have five years after passing to apply.
Plan Your CRISC Budget in ZAR & Official ISACA Costs
Your total plan has two separate parts: EduDelphi CRISC training in ZAR and official ISACA registration/certification costs in USD.
EduDelphi training fees
Request current ZAR pricing for nationwide classroom, live online, hybrid, self-paced, individual or corporate delivery. We will explain the study system, delivery choice and available instalment options.
Official ISACA costs
US$575 current member exam fee
US$760 current non-member exam fee
US$50 CRISC certification application fee
Official ISACA fees are separate from EduDelphi tuition and can change. Confirm current pricing directly with ISACA before payment.
CRISC Training in Johannesburg, Cape Town, Pretoria & Durban
Choose the learning format that works around your current role without losing structure or access to guided support.
Live online
South Africa-time sessions for professionals nationwide, supported by recordings and revision resources.
Self-paced support
LMS-led reinforcement, notes, recordings, practice resources and scheduled guidance.
Classroom / hybrid
Instructor-led physical or hybrid delivery can be planned nationwide for suitable groups and locations.
Corporate cohorts
Private CRISC preparation for technology risk, audit, security, governance and controls teams.
Johannesburg / Sandton / Midrand
Banking, financial services, consulting, GRC and technology-risk teams.
Pretoria / Centurion
Public sector, audit, governance, technology and assurance professionals.
Cape Town
Financial services, technology, privacy, SaaS and risk professionals.
Durban / KwaZulu-Natal
Enterprise, financial-services, industrial and technology-risk teams.
Live online and corporate delivery also supports learners elsewhere in South Africa. EduDelphi is an independent provider; candidates may also explore the ISACA South Africa Chapter community directly.

Practise the Risk Decision, Not Just the Definition
EduDelphi uses scenario discussion to help CRISC learners practise risk reasoning, control choices, ownership and reporting decisions.
South Africa Technology-Risk Case: Critical Third-Party Failure
A South African financial-services organisation relies on an outsourced platform provider. A control failure exposes customer information and affects service availability. Operations wants immediate restoration while technology risk, privacy, security and senior management need to understand residual risk, control effectiveness, regulatory implications and escalation.
What learners work through
Business objective → risk owner → inherent and residual risk → control gap → response → KRIs → escalation → management report.
Why this matters: this exercises vendor and supply-chain risk, control ownership, KRIs/KCIs/KPIs and risk reporting from the current CRISC outline. The aim is disciplined risk reasoning, not a memorised legal answer.

Build a Stronger Technology-Risk Narrative in South Africa
CRISC knowledge can strengthen how you contribute to risk assessment, control design, governance, third-party oversight, resilience and remediation reporting.
It can be relevant to IT risk analysts, GRC specialists, technology risk managers, internal auditors, security-governance professionals, control owners and advisory teams.
CRISC does not guarantee employment, promotion or salary. Outcomes also depend on experience, employer needs, industry context and the responsibilities you can demonstrate.
Banking & financial servicesFintech & paymentsTelecom & enterpriseAudit & advisoryTechnology governance
Learn with a CRISC and Governance Practitioner
Kashif Akhtar
CISA · CISM · CRISC · CDPSE · PMP · CSCP
Kashif connects IT governance, audit, risk, security and controls to the decisions CRISC candidates need to make under examination and workplace pressure.
Faculty perspective: good CRISC answers begin with the business objective, the risk owner and the evidence. Only then should you choose the control, response or report that seems most familiar.
Corporate CRISC Training for South African Teams
Private CRISC preparation can be planned for technology risk, GRC, audit, security, resilience and controls teams across South Africa, paced around your priorities and intended exam timing.
EduDelphi has delivered professional learning for teams associated with recognised organisations across sectors. These are organisation-level training relationships, not CRISC endorsement or ISACA affiliation.








CRISC, CISA, CISM or CISSP?
Choose according to the work you want to own, rather than whichever certification title is most familiar.
| Route | Primary focus | Usually best when |
|---|---|---|
| CRISC | IT risk, controls, response and reporting | You need focused capability in technology risk and control decisions. |
| CISA | IT audit, assurance and control evaluation | Technology assurance and audit work are central to your role. |
| CISM | Security governance, programmes and incidents | You are moving toward security-management responsibility. |
| CISSP | Broad information-security technical and managerial knowledge | You need wide security-domain coverage alongside technical depth. |
CRISC Course & Certification Questions
Is this the official CRISC certification from ISACA?
EduDelphi provides independent CRISC training and exam preparation. ISACA administers the official exam, reviews certification applications and awards the CRISC designation when its requirements are met.
Can I take the CRISC exam before meeting the experience requirement?
Yes. ISACA states that the CRISC exam is open to interested candidates. Full certification requires qualifying professional experience, but candidates have five years from passing the exam to apply.
What experience is required for CRISC certification?
ISACA currently requires three or more years of relevant professional experience across at least two CRISC domains. Experience must be gained within the 10 years before the certification application.
How many questions are on the CRISC exam?
The current CRISC examination has 150 multiple-choice questions and a four-hour appointment. ISACA uses a scaled score, with 450 as the current passing score.
Can I take CRISC from home in South Africa?
ISACA currently provides PSI test-centre and remote-proctoring routes where available. Check live availability and system requirements through ISACA when scheduling.
How quickly can I schedule CRISC after registering?
ISACA states that candidates can schedule an appointment as early as 48 hours after paying the exam registration fee, subject to PSI availability. Exam appointments are generally displayed up to 90 days ahead. ISACA currently permits rescheduling without penalty when it is completed at least 48 hours before the appointment and within the eligibility period.
What are CRISC course fees in South Africa?
EduDelphi fees are quoted in ZAR based on your delivery route. Official ISACA exam and certification fees are separate USD costs. Request a current, written breakdown before enrolling.
Is CRISC better than CISA?
Neither is universally better. CRISC is more concentrated on technology risk and controls; CISA is more focused on IT audit and assurance. Your current responsibilities should decide the route.
Is self-paced CRISC preparation available?
Yes. Self-paced reinforcement can combine recordings, the AI-powered LMS, study notes, mind maps, practice resources and scheduled guidance.
How do I maintain CRISC after certification?
CRISC holders currently need at least 20 CPE hours each year and 120 CPE hours over three years. ISACA currently lists an annual CRISC maintenance fee of US$45 for members and US$85 for non-members.
Can companies arrange corporate CRISC training?
Yes. Private CRISC cohorts can be planned nationwide for technology-risk, GRC, audit, security, resilience and controls teams.
Get CRISC Fees, Syllabus & South Africa Batch Options
Share your role, city and preferred learning format. We will send current ZAR course-fee guidance, delivery options, the CRISC syllabus and a clear view of separate ISACA exam costs.





















