About the certification


The Certified GRC Professional is a certification designed for professionals seeking to validate their comprehensive knowledge of governance, risk management, and compliance, based on ISO/IEC 38500, ISO 31000, and ISO 37301.

This exam covers key topics from ISO/IEC 38500, ISO 31000, and ISO 37301, including governance principles, risk management processes, compliance management systems, organizational accountability, and control mechanisms. It validates your comprehensive knowledge of how to establish, implement, and maintain effective governance, risk management, and compliance practices within an organizational context, in accordance with widely recognized international standards and best practices.

The Certified GRC Professional certification exam is an online, closed-book, and remotely-proctored exam. This exam consists of 60 multiple-choice questions. The passing score is 70%. Candidates will have 60 minutes to complete the exam. The exam is available in English and Portuguese. Validate your GRC knowledge and advance your career. Purchase your exam voucher now!




What’s Included When You Purchase an Exam Voucher


  • Self-Paced Study Guide – A comprehensive resource designed to help you prepare at your own pace.

  • Practice Test – Includes questions similar in style and difficulty to the actual exam, so you know exactly what to expect.

  • Two Free Retakes – If you don’t pass on your first attempt, you’ll have two additional opportunities at no extra cost.

Exam details


Exam code

ITC-206

Launch date

March 10, 2026

Exam description

The Certified GRC Professional exam validates the candidate's knowledge of GRC.

Current version

v1 (March 10, 2026)

Exam format

Multiple choice; computer-based; closed book (online proctored exam)

Number of questions

60 questions

Passing score

70% (42 out of 60)

Exam duration

60 minutes

Level

Advanced

Languages

English and Portuguese

Exam description

This exam covers key topics from ISO/IEC 38500, ISO 31000, and ISO 37301, including governance principles, risk management processes, compliance management systems, organizational accountability, and control mechanisms. It validates your comprehensive knowledge of how to establish, implement, and maintain effective governance, risk management, and compliance practices within an organizational context, in accordance with widely recognized international standards and best practices.

RECOMMENDED HOURS OF STUDY

32 hours

BLOOM'S TAXONOMY

Level 2 (Understanding), Level 3 (Applying), Level 4 (Analyzing), and Level 5 (Evaluating)

Recommended reading

• ISO/IEC 38500:2024 Information technology — Governance of IT for the organization
• ISO 31000:2018 Risk management — Guidelines
• ISO 37301:2021 Compliance management systems — Requirements with guidance for use

Prerequisites

There are no prerequisites for this certification program.

Recommended experience

Six months of work experience in GRC

Validity period

Lifetime

Exam Content Outline


   Domains Weight

1. ISO/IEC 38500

30%

2. ISO 31000

40%

3. ISO 37301

30%

   Total

100%

How to get certified


1

Browse our certification programs and choose your certification.

2

Discover the exam objectives and prepare for your exam.

3

Register for your online proctored exam.

4

Take your online proctored exam in the comfort of your home or office.

5

Congratulations! You are certified!

Frequently Asked Questions


  • After purchasing an exam voucher, how much time do I have to take the exam?

    After purchasing an exam voucher, candidates will have 180 days to take the exam.

  • Does the exam voucher include a retake?

    The exam voucher includes 2 retakes in case the candidate fails the first attempt.

  • Are there any prerequisites to take the exams?

    There are no prerequisites to take the exams. ITCERTS recommends that candidates have at least six months of work experience in the area that the certification exam covers.

  • What is the exam retake policy?

    If a candidate does not achieve a passing score on the first attempt, there is no waiting period between the first and the second attempt. If a candidate does not achieve a passing score on the second attempt, the candidate must wait at least 7 days before retaking the exam for a third time. A candidate may not take a given exam any more than three times per year (12 months).

  • How do I register for an Online Proctored Exam?

    Visit the Online Proctored Exam registration page to find complete instructions.

  • Are there any mandatory training to take an exam?

    Training is recommended as part of your certification preparation, but it is not mandatory.

  • Which languages are the exams available in?

    Our exams are currently available in English and Portuguese.

  • Where can I take the exams?

    Exams are delivered online (Online Proctored Exams) and can be taken from anywhere in the world.

  • Do the ITCERTS certifications expire?

    ITCERTS certifications are considered good-for-life and do not expire.

  • How can a potential employer verify my certifications?

    Your employer can verify your certification on our certification verification page. Your certification number will be needed in order to process the verification.

Subscribe

Subscribe


Subscribe to our newsletter