Skip to main content
ITS-0146ExpertCurrent Intake
XCRISC

Xcademia Risk and IS Control Practitioner

5-Day Instructor-Led Programme

The XCRISC Certification Programme is the practitioner standard for IT risk managers and information systems control professionals who identify, assess, respond to, and monitor enterprise IT risk across financial services, enterprise, and regulated sector environments. Assessed on Day 5 through a supervised enterprise risk assessment and IS control design exercise. No 150-question MCQ exam. No annual CPE requirement.

Duration

5 Days

Price

$5,620

Xcademia Risk and IS Control Practitioner
Duration
5 Days
Complete in 5 days
Learning Style
Mentor-led, practical and scenario-based
Guided walkthroughs, real-world examples, and applied skills for the workplace.

Course Overview

CRISC is the most respected credential for IT risk management professionals with over 46,000 holders globally. It is heavily weighted toward financial services and enterprise risk functions where connecting IT risk to business impact is a daily requirement. The CRISC exam is 150 multiple choice questions across four domains, but the real work is applying risk frameworks to complex business scenarios, designing IS controls, and reporting risk in board-level language. XCRISC builds this applied capability.

Across five instructor-led days, XCRISC covers all four CRISC domains as updated by the November 2025 ISACA CRISC job practice revision: IT Risk Identification, IT Risk Assessment, Risk Response and Mitigation, and Risk Control Monitoring and Reporting. The November 2025 update introduced AI risk assessment and AI data governance into the CRISC job practice, and XCRISC covers this in depth. Every domain is applied to realistic enterprise and financial services risk scenarios.

On Day 5, participants conduct a supervised enterprise risk assessment for a simulated organisation and design IS controls to address identified risks. A senior IT risk practitioner assesses risk identification, assessment methodology, control design, and reporting quality. XCRISC certificate and Practitioner Assessment Report issued. Aligned with ISACA CRISC four domains (November 2025 revision), ISO 31000, NIST RMF, COBIT 2019, FAIR methodology, ISO 27005, DORA Articles 6 to 16, and Federal Reserve SR 11-7 for model risk.

Hands-On Learning

Hands-on risk register development, FAIR quantitative risk modelling, IS control design exercises, control testing methodology design, and a supervised enterprise risk assessment and control design exercise on Day 5.

Mentor-Led Sessions

Mentor-led sessions from experienced IT risk professionals examining real risk decisions, control selection trade-offs, board risk reporting formats, and the difference between theoretical risk frameworks and real enterprise risk management.

Career-Ready Skills

Identify, assess, and respond to IT risks across enterprise environments, design effective IS controls, monitor control effectiveness, and report risk to executive and board audiences in quantitative and business-aligned language.

Learning Outcomes

Apply CRISC job practice domain methodology updated to the November 2025 revision to identify, assess, and respond to IT risks across enterprise and financial services environments

Design IS controls aligned to COBIT 2019, ISO 27001, and risk treatment decisions including compensating controls for constrained environments

Conduct quantitative IT risk assessments using FAIR methodology to produce board-level financial risk quantification for investment and insurance decisions

Develop Key Risk Indicators and control monitoring frameworks to provide continuous assurance over IS control effectiveness

Integrate AI risk assessment into enterprise IT risk programmes aligned to the November 2025 ISACA CRISC update and SR 11-7 model risk principles

Report IT risk to board and executive audiences using FAIR-quantified scenarios, regulatory formats, and risk heat maps

Prerequisites

1

Minimum 3 years of IT risk management or information systems control experience

2

Working knowledge of at least one risk framework: ISO 31000, NIST RMF, COBIT, or enterprise risk management methodology

3

Understanding of IT governance concepts and audit or assurance fundamentals

Detailed Syllabus

Organized by professional domains with comprehensive coverage

Topics Covered:
  • IT risk taxonomy for enterprise: operational, strategic, compliance, and financial risk categories
  • Risk scenario development methodology: historical loss data, threat intelligence, and emerging technology risk
  • AI risk identification: NIST AI RMF integration, algorithmic bias, model poisoning, and AI supply chain risk (CRISC 2025 update)
  • Third-party and supply chain risk identification: concentration risk, ICT dependency mapping, and fourth-party exposure
  • Risk register design and governance: ownership model, escalation triggers, and board-level risk appetite alignment
Stage 5Final Capstone

Xcademia Risk and IS Control Practitioner — Capstone Project

On Day 5, participants receive a simulated enterprise scenario in which IT risk assessments are overdue, AI systems have been deployed without governance, and a regulatory audit is imminent. They must conduct a structured IT risk assessment, design IS controls for the top-priority risks, build a Key Risk Indicator dashboard, and produce a board-level risk report. The senior practitioner assesses risk identification quality, FAIR methodology application, control design, and reporting format throughout.

Assessed by a senior Xcademia practitioner

Framework Alignment

This course is mapped directly onto the standards your organisation already answers to. No invented frameworks, no proprietary jargon.

  • ISACA CRISC (4 domains)

    Global

    All four CRISC job practice domains updated to November 2025 ISACA revision including AI risk assessment

  • ISO 31000

    Global

    Risk management principles and framework: primary risk methodology reference throughout all domains

  • FAIR (Open FAIR)

    Global

    Factor Analysis of Information Risk: quantitative risk modelling throughout from fundamentals to Monte Carlo

  • COBIT 2019

    Global

    Governance and management objectives for IS controls: control selection and monitoring methodology

  • NIST RMF

    Global

    Risk Management Framework: federal and enterprise risk assessment methodology integration throughout

  • DORA Articles 6 to 16

    Global

    ICT risk management requirements for EU financial entities: regulatory IT risk domain alignment

  • Federal Reserve SR 11-7

    Global

    Model risk management guidance: AI and commercial model risk in AI risk module

  • ISO 27005

    Global

    Information security risk management standard: detailed assessment methodology aligned to ISO 27001

Skills You'll Gain

Master these in-demand skills through hands-on practice

CRISC 4 domainsFAIR quantitative risk methodologyIS control design and testingKRI and KCI developmentControl monitoring frameworksDORA ICT risk managementNIS2 risk management obligationsAI risk assessmentBoard-level risk reportingThree Lines of Defence modelSR 11-7 model risk managementSupply chain and third-party risk

Career Progression

A clear view of the roles this programme supports, what typically comes next, and where learners progress over time

IT Risk ManagerEnterprise Risk AnalystGRC Analyst / ManagerInformation Systems AuditorRisk and Compliance ManagerFinancial Services Risk Professional
Flexible Delivery Options

Ways to Learn

Choose the learning format that works best for you and your team

Book Now

Live Online

Instructor-Led Training

Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.

5 Days
Small cohorts
  • Live instructor interaction (real-time)
  • Trainer-led walkthroughs and real examples
  • Guided resources and session notes provided
  • Structured Q&A and practical discussion

Price per person

$5,620+ VAT

Group enrolments and early planning options available.

All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.

Premium Training Option

Prefer a Faster, Personalised Route into IT?

Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.

Personalised Xcademia Risk and IS Control Practitioner learning plan
Tailored to your pace and goals
Live 1-to-1 sessions
With an experienced mentor
Real-world troubleshooting
Practice, not just exam theory
Flexible scheduling
To fit around work, study, or family

"Many learners choose 1-to-1 when they want understanding, not memorisation."

Exam & Certification Information

Everything you need to know about the certification exams

Xcademia Certification Programme

Xcademia Certification Programme

On successful completion of Xcademia Risk and IS Control Practitioner, learners are assessed on the final day through a supervised practitioner scenario. Three outcomes are possible, Certificate Awarded, Certificate Deferred, or Not Awarded. The Practitioner Assessment Report and certificate are issued together. Verified at xcademia.com/verify.

Certificate Awarded

Assessed competent on the final day.

Certificate Deferred

Resit available on a future cohort.

Not Awarded

Attendance record issued. Reassessment possible.

Frequently Asked Questions

Everything you need to know about this course

CRISC is a 150 MCQ exam. Beyond the $760 exam, CRISC holders pay annual fees and 120 CPE credits every 3 years. XCRISC is 5 instructor-led days covering all four CRISC domains updated to the November 2025 revision, assessed on Day 5 through a supervised enterprise risk assessment and IS control design exercise. One price. No annual fees. The Practitioner Assessment Report documents risk management and control design capability.

Share:

Ready to Start Your Learning Journey?

Take the next step in your professional development

Digital certificate upon completion
Comprehensive course materials
Expert instructor support
Flexible learning options