The 4 CRISC Domains Explained (2025 Exam Weights)

The 4 CRISC domains and their official exam weights: 26, 22, 32, and 20 percent

There are four CRISC domains: Governance (26%), Risk Assessment (22%), Risk Response and Reporting (32%), and Technology and Security (20%). Those weights come from the ISACA CRISC Exam Content Outline effective 2025, which has been live since November 3, 2025. If you are sitting the exam now, that is the blueprint your paper is built from.

The number that should shape your plan: Domain 3 is 32% by itself, roughly 48 of the 150 questions. Domains 1 and 3 together are 58%, near 87 questions. This post walks each domain in turn, covering what it actually contains, what the exam tends to ask about it, and the one trap that catches most people there.

What are the CRISC domains and their weights?

Domain Name Weight Approx. questions
1 Governance 26% 39
2 Risk Assessment 22% 33
3 Risk Response and Reporting 32% 48
4 Technology and Security 20% 30

The question counts are approximate. The exam is 150 multiple-choice items in 4 hours, some of them unscored pretest items that ISACA does not identify, so treat the column as a planning tool rather than an exact count. Scoring is scaled from 200 to 800 with 450 to pass. For the full picture of format, fees, and eligibility, start with what the CRISC exam is.

One framing point before the tour. Every CRISC question is written from the risk practitioner's seat, and that seat is not the engineer's, the auditor's, or the executive's. You identify risk, analyze it, recommend a response, monitor it, and report it. You do not own it, approve it, or fix it yourself. That lens settles more questions than any single definition.

Domain 1: Governance (26%)

Domain 1 is the frame every other domain works inside, and it splits in two. Organizational governance (1A) covers strategy, goals and objectives, organizational structure with roles and responsibilities, culture and ethics, the policy and standards hierarchy, business processes and resilience including business continuity and disaster recovery planning, and organizational asset management. Risk governance (1B) covers enterprise risk management, the lines of defense model, the enterprise risk profile, risk appetite and risk tolerance, and the risk frameworks plus the legal, regulatory, and contractual requirements that turn into compliance risk.

What the exam asks here is mostly who is accountable and against what threshold. Expect stems where a control has failed and nobody is clearly assigned to it, or where residual risk has drifted past a threshold and you have to say what the practitioner recommends. Appetite and tolerance carry more question weight than their page count suggests: appetite is the board-level statement of how much risk the enterprise will take, tolerance is the measurable threshold that operationalizes it for a specific process.

The trap: the second line of defense does not own the risks it oversees. When a question asks who is accountable for a privacy or fraud risk, the answer is the first-line business process owner, not the compliance or risk function that monitors them. Internal audit, the third line, assures and does not operate controls. Keep those three lines separate and a whole family of questions becomes mechanical.

Domain 2: Risk Assessment (22%)

Domain 2 is the analytical engine, and it is also split. Risk identification (2A) covers risk events, threat modeling, vulnerability management, and risk scenario development and evaluation. Risk analysis (2B) covers risk assessment concepts and standards, business impact analysis, the risk register, risk analysis methodologies both qualitative and quantitative, and the difference between inherent and residual risk.

The exam is precise about vocabulary here, and answer options often differ by exactly one term. A threat is not a risk. A vulnerability is not a risk. Risk needs a threat, a vulnerability, and an asset the enterprise cares about losing. Scenario questions test the same discipline in longer form: a complete risk scenario names a threat source, an event, an affected asset, and a business impact, and a scenario missing one of those is incomplete rather than merely weak. On the quantitative side, know single loss expectancy and annualized loss expectancy well enough to compute them, and know that a qualitative rating is the appropriate output when the data will not support a dollar figure.

The trap: inherent risk does not drive the response. Residual risk does. Inherent risk is a planning reference that shows how much work your controls are doing. The decision to accept, mitigate, transfer, or avoid is made by comparing residual risk to tolerance, and a stem that hands you a high inherent number and a residual number inside tolerance is usually testing exactly that.

Domain 3: Risk Response and Reporting (32%)

Domain 3 is the largest domain by a clear margin and covers three sub-areas rather than two. Risk response (3A) covers the four response options, risk and control ownership, vendor and supply-chain risk management, and the management of issues, findings, exceptions, and exemptions. Control design and implementation (3B) covers control frameworks, types, and standards, then the design, selection, implementation, and analysis of controls, then control testing methodologies. Risk monitoring and reporting (3C) covers risk action plans, the collection, aggregation, analysis, and validation of data, risk and control metrics, monitoring techniques, reporting formats such as heatmaps, scorecards, and dashboards, and the monitoring and reporting of emerging risks.

That is a lot of surface for one domain, which is part of why it carries a third of the paper. The exam asks you to pick a response and defend the sequence: which option fits this residual risk at this cost, who signs the acceptance, what goes into the action plan, how completion gets validated rather than self-declared. Metrics questions are their own reliable cluster. A key risk indicator signals exposure and is most useful when it is leading rather than lagging. A key control indicator measures whether one specific control is working. A key performance indicator measures process performance. The exam tests that boundary directly and often.

The trap: transfer does not move accountability. Buying insurance or writing an indemnification clause into a vendor contract moves the financial consequence and nothing else. The enterprise keeps the risk ownership, the governance accountability, and the regulatory responsibility. The same logic runs through the vendor sub-area: outsourcing the process never outsources the risk. When an option says a risk was eliminated because it was transferred, it is wrong.

If you want the answer pattern rather than the syllabus, our CRISC study guide teaches all four domains from the practitioner's decision lens and then drills them with four full-length 150-question exams where every option is explained, including why the attractive wrong one loses.

Domain 4: Technology and Security (20%)

Domain 4 is the smallest weight and the one candidates most often misread as a technical exam inside the exam. Technology principles (4A) runs to seven sub-areas: technology roadmaps and enterprise architecture, operations management covering change, assets, DevOps, problems, and incidents, the system development life cycle, data lifecycle management, portfolio and project management including Agile, technology resilience and disaster response and recovery, and emerging technologies. Information security principles (4B) has three: security concepts, frameworks, and standards, security and risk awareness and training, and data privacy and data protection principles.

The depth expected is literacy, not engineering. You need to know that a delayed migration extends an exposure window, that DevOps moves the control points into the pipeline instead of removing the need for them, that recovery time objective and recovery point objective are set by business need and not by what the backup system happens to support, and that awareness training is a control with a measurable effect rather than an annual formality.

The trap: treating security as a discipline sitting beside risk management instead of a control set serving it. When a stem hands you a security finding, the credited answer evaluates likelihood and impact and recommends a response against appetite. It does not harden the system. The neighboring trap is privacy versus security: security protects data from unauthorized access, privacy governs whether the use of personal data is lawful and appropriate, and a question about retaining personal data past its stated purpose is a privacy question no matter how well the database is encrypted.

What changed in the effective-2025 outline?

Two percentage points moved. Domain 2 went from 20% to 22% and Domain 4 went from 22% to 20% against the prior outline. The domain names and the four-domain structure were kept.

For a study plan, that is a rounding error: three questions moved from Technology and Security to Risk Assessment. It matters for one reason only, which is that a study product built to the older outline is teaching the older blueprint, so check what your material is written to before you trust its weighting. How hard the CRISC exam is covers the parts of the difficulty story that the weights do not explain.

Is there a pass mark for each domain?

No. You get one scaled score between 200 and 800, and 450 is the pass. The domain-level percentages printed on your score report are informational only. There is no per-domain minimum, and no way to fail on one domain while clearing the total.

That has a practical consequence people miss. A weak domain is only expensive in proportion to its weight, so being shaky on Technology and Security costs you at most 20% of the paper while being shaky on Risk Response and Reporting exposes you on almost a third of it. Points are fungible. Spend your hours where they buy the most of them.

How should the weights shape your study time?

Split them by weight, not by chapter. Reading front to back at an even pace gives every domain the same share, which is the wrong answer four times over. Our 12-week CRISC study plan turns these percentages into an hour budget against a calendar.

Here is the opinion about order. Domain 3 is where the hours belong, and it repays being worked early rather than saved for last, and not only because it is the biggest. Its questions depend on vocabulary the other domains define, so working through response options, ownership, control testing, and metrics early surfaces every gap you have in Domains 1 and 2 while you still have time to fill them. The exception is small and worth respecting: read the risk appetite, risk tolerance, and ownership sections of Domain 1 before you start Domain 3, because half of Domain 3's answers turn on a threshold or an accountable role that Domain 1 defines.

Domain 4 goes last, and it goes quickly if you have worked in IT. Twenty percent is real money, but most of it is recognition rather than recall, and the risk lens you built in Domains 2 and 3 carries most of the load. The practice question walkthrough shows what the ranking looks like item by item.

One last thing to check before you plan anything: the CRISC experience requirement has no waivers or substitutions, unlike some other ISACA credentials. You can sit the exam first and apply later, but it is worth knowing where you stand before you book.

FAQ

How many questions are in each CRISC domain?

The exam is 150 multiple-choice questions, so the weights work out to roughly 39 questions on Governance, 33 on Risk Assessment, 48 on Risk Response and Reporting, and 30 on Technology and Security. ISACA also includes unscored pretest items that are not identified on the paper, so treat those numbers as planning estimates rather than an exact count.

Which CRISC domain should I study first?

Domain 1, briefly, then Domain 3 at length. Governance defines appetite, tolerance, and risk ownership, and half of Domain 3's credited answers turn on one of those three. Once that vocabulary is settled, Risk Response and Reporting is where the hours belong, because at 32% it is the largest domain and it holds the finest distinctions on the paper: response options against appetite, control design versus operating effectiveness, and the boundary between key risk indicators and key control indicators.

Do I need to pass each CRISC domain separately?

No. CRISC is scored as one scaled result from 200 to 800 with 450 to pass, and the domain-level figures on your score report are informational only. There is no per-domain pass mark, so a weak domain costs you only its share of the questions.

Did the CRISC domains change in 2025?

The four domains kept their structure and their count. The weights shifted by two points: Risk Assessment went from 20% to 22% and Technology and Security went from 22% to 20%. Two of the names also changed, with Domain 2 moving from IT Risk Assessment to Risk Assessment and Domain 4 from Information Technology and Security to Technology and Security, so older material can look right and be labeled wrong. The effective-2025 outline has been live since November 3, 2025, so check that any study material you buy is written to it.


Looking for a plain-English CRISC guide? ISACA CRISC: Simply Certified Study Guide covers all four domains at their 26/22/32/20 weights, with four full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CRISC and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.