CRMA: Certification in Risk Management Assurance from The IIA
Table of Contents
- 1. What Is CRMA?
- 2. CRMA at a Glance
- 3. Who Awards and Oversees the Credential?
- 4. When and Why Was the Credential Created?
- 5. Who Pursues the Credential, and Where Is It Used?
- 6. What Knowledge and Skills Does It Cover?
- 7. What Are the Eligibility Requirements?
- 8. How Do You Earn the Credential?
- 9. How Long Does It Take, and How Do Candidates Prepare?
- 10. How Much Does the Credential Cost?
- 11. How Do Holders Maintain the Credential?
- 12. What Is Its Professional Value, and What Are Its Limitations?
- 13. What Should Employers and Clients Infer from It?
- 14. How Does It Compare with Related Credentials?
- 15. How Can You Verify the Credential and Use Its Letters Correctly?
- 16. Frequently Asked Questions
- 17. Official Resources and Recent Changes
1. What Is CRMA?
CRMA stands for Certification in Risk Management Assurance, a professional certification awarded by The Institute of Internal Auditors (The IIA). It recognizes knowledge relevant to evaluating organizational risk management and providing assurance to boards, audit committees, and executive management. It is a specialist audit and risk credential, not a government-issued professional license.
The current route combines an examination with verified qualifying experience. Education determines the experience requirement. Candidates no longer need to hold the Certified Internal Auditor (CIA) credential first.
Seeing CRMA after someone’s name should indicate that the person satisfied an IIA-approved qualification route and, if currently active, maintains the designation. It should not be treated as proof that the holder has successfully led a particular risk transformation, understands a specific industry, or can deliver an assignment without further evaluation. The IIA’s own competency guidance cautions against automatically translating certification into a particular level of practical proficiency.
2. CRMA at a Glance
Full name: Certification in Risk Management Assurance.
Abbreviation: CRMA.
Credential type: Individual professional certification.
Awarding organization: The Institute of Internal Auditors.
Official website: The IIA’s CRMA credential page.
First introduced: 2011, initially including an experience-recognition route; examination-based awards followed in 2013.
Current status: Active and available to new candidates.
Professional focus: Internal audit responsibilities, risk governance, and risk management assurance.
Intended career stage: Professionals with relevant experience, including auditors developing a risk-assurance specialty.
Geographic scope: International program; the examination is offered in English.
Main eligibility requirement: Generally one, two, or five years of qualifying experience, depending on education and entry route.
Assessment: One 120-question examination lasting 150 minutes.
Indicative initial cost: September 2026 U.S. application and first-attempt examination fees total US$565 for existing members or US$830 for nonmembers, excluding preparation and membership dues.
Maintenance: Annual renewal; practicing holders normally complete 20 continuing professional education hours, including two ethics hours.
Verification: The IIA’s voluntary Certification Registry, supplemented by issuer confirmation where necessary.
3. Who Awards and Oversees the Credential?
The IIA owns and awards CRMA. Its Professional Certifications Board governs the certification programs, while the Exam Development Committee supports examination content. These responsibilities are distinct from those of the International Internal Audit Standards Board, which develops professional standards.
Applications, documentation, examination registration, and certification records are managed through the Certification Candidate Management System, usually called CCMS. Pearson VUE delivers the examination at authorized test centers. National Institutes may handle local administration, pricing, or related arrangements. Neither a testing appointment nor enrollment with a preparation provider constitutes an award of the credential.
The IIA’s Disciplinary and Oversight program has authority over certification holders, including CRMAs. Its procedures provide notice of allegations, an opportunity to respond, and an appeal mechanism. These are professional credentialing and disciplinary arrangements, not governmental licensing powers.
4. When and Why Was the Credential Created?
CRMA was introduced to recognize a specific professional capability: assessing whether an organization manages risk effectively, rather than simply identifying individual control failures. Its original materials emphasized assurance, strategic risk, and communication with management and audit committees.
- 2011: The IIA introduced CRMA as a specialist qualification for internal auditors and other risk-assurance professionals.
- 2012 to 2013: An initial Professional Experience Recognition route allowed qualifying professionals to earn the designation through documented education, existing credentials, and experience. This preceded the examination route introduced in 2013. Consequently, not every longstanding holder earned CRMA by passing an examination.
- 2021: Revised program applications began April 1, and the revised examination launched October 1. That version required an active CIA and five years of experience, while expanding the assessment’s depth and question formats. Those prerequisites are historical, not today’s universal rules.
- 2025: The IIA removed the CIA prerequisite, opening the program to candidates qualifying through education and experience without first earning CIA.
5. Who Pursues the Credential, and Where Is It Used?
The most natural candidates are internal auditors, audit managers, risk-assurance specialists, and professionals in risk, compliance, controls, or quality-assurance functions who want a stronger assurance perspective. The distinguishing interest is not merely managing risk, but evaluating the reliability of the organization’s risk-management arrangements.
Documented professional use crosses sectors. The IIA’s committee biographies identify CRMA holders working in banking, manufacturing, healthcare, and higher education. Public-sector audit reports also display the designation. These examples demonstrate use in those settings, not a measured rate of adoption across each industry.
For an enterprise risk management review, a relevant contribution would be examining whether significant risks are identified, assigned to accountable owners, monitored, and reported appropriately. The important distinction is between advising management and independently assuring management’s work. The IIA’s governance guidance calls for safeguards when internal audit takes on responsibilities associated with management.
CRMA is generally an optional professional qualification, although an employer may request or prefer it. For example, Texas Board of Criminal Justice internal-audit job descriptions list CRMA among several preferred credentials. That is an employer preference for particular positions, not a general legal requirement to work in risk management.
6. What Knowledge and Skills Does It Cover?
The published syllabus has three weighted domains: Internal Audit Roles and Responsibilities, 20%; Risk Management Governance, 25%; and Risk Management Assurance, 55%. Within them, six practical knowledge areas are especially useful for understanding the credential.
- Roles and independence: Distinguishing assurance from consulting, identifying capability needs, and recognizing threats to audit independence.
- Assurance coordination: Mapping coverage and deciding whether work by other assurance providers can be relied upon.
- Governance and culture: Evaluating oversight, organizational behavior, and the use of risk and control frameworks.
- Risk integration: Assessing how risk management connects with strategy, performance, operations, and emerging risks.
- Assessment and testing: Evaluating risk-identification processes, selecting analytical techniques, prioritizing engagements, and assessing controls, including technology-related controls.
- Communication: Reporting conclusions, assessing management responses, and escalating potentially unacceptable risk acceptance.
Applied capabilities
Illustrative assignments include challenging the completeness of a manufacturer’s enterprise risk register, examining gaps between a bank’s compliance monitoring and internal audit coverage, or preparing a board-level assessment of risk-management effectiveness. These are applications of the syllabus, not tasks that every holder has necessarily performed.
A useful work product should connect its conclusion to evidence. For example, an assurance map should show not only which team covers a risk, but whether that coverage is sufficiently current, independent, and reliable to support reliance.
Boundaries
Coverage of cybersecurity, analytics, or system-development controls does not establish specialist engineering or software expertise. Likewise, knowledge of governance does not prove boardroom judgment or implementation success. Evaluate those capabilities separately rather than treating examination coverage as observed job performance.
7. What Are the Eligibility Requirements?
The current program uses education-based and experience-based routes:
- Master’s degree or equivalent or higher: One year of qualifying experience.
- Bachelor’s degree or equivalent: Two years of qualifying experience.
- Active Internal Audit Practitioner designation: Five years if the candidate does not qualify for a shorter degree-based route.
- Without a university degree: An experience-based route is available for candidates with a high-school diploma, associate degree, GCE, A-level, or equivalent, together with five years of qualifying experience.
For the five-year routes, two of the required years must fall within the previous three years. An IAP holder who also has a qualifying degree can use the corresponding shorter experience requirement.
Accepted experience includes internal audit, quality assurance, risk management, audit or assessment disciplines, compliance, external audit, and internal control. Candidates should document their actual duties and dates, rather than assume that a job title alone establishes eligibility.
Applicants provide valid government-issued photo identification and applicable education evidence. The IIA accepts documents such as a degree, official transcript, university confirmation, or an appropriate degree-level evaluation. Degree and active-IAP candidates may take the examination before completing the experience requirement, but examination success alone does not confer certification. The program normally allows two years from acceptance to complete its requirements.
No prescribed preparation course is mandatory. U.S. candidates can apply without IIA membership; candidates residing in the United Kingdom, Republic of Ireland, or South Africa must be members under the published regional rules. Candidates must also accept the program’s confidentiality and ethical conditions.
8. How Do You Earn the Credential?
Apply and obtain approval
Create or access a CCMS account, select CRMA, pay the application fee, and submit the required documentation. Application payment does not itself mean admission. The IIA gives applicants 90 days after payment is processed to complete the application process; otherwise, the application expires.
Register and schedule
Once approved, register and pay for the examination through CCMS, then schedule with Pearson VUE. Examination authorization normally lasts 180 days or until the program expires, whichever comes first. This scheduling window is separate from the overall two-year CRMA completion period.
Take the examination
The current examination has 120 questions and a 150-minute time limit. It is offered in English and taken at an authorized test center. It is a closed-book assessment, not a take-home project or workplace observation.
Potential question formats extend beyond conventional multiple choice. The IIA’s examination guidance describes multiple-response questions, matching, ordering, categorization, fill-in-the-blank selections, hot spots, and scenario-based item sets. Candidates should use the official interactive demonstration rather than assume every item has one selectable answer.
Receive the result and, if necessary, retake
The IIA uses scaled scoring, with 600 as the passing score on its 250-to-750 reporting scale. This is not equivalent to answering 80% correctly. Effective April 1, 2026, candidates receive a single official result within three weeks; an immediate unofficial result is no longer provided.
A failed examination can be retaken after at least 30 days, with a new registration and fee. The published limit is eight attempts within a certification program. Candidates must still finish within their applicable program window.
Complete experience verification and receive the award
Complete the CCMS proof-of-experience process and obtain the IIA’s confirmation that all requirements are satisfied. The designation normally appears in the account within 7 to 14 business days after completion. Only then should the candidate represent themselves as certified.
9. How Long Does It Take, and How Do Candidates Prepare?
Prerequisite-building time: The required professional experience can take one, two, or five years to accumulate. That is distinct from examination preparation. Applicants should check how much experience they already have before starting a time-limited program.
Preparation time: The IIA does not prescribe a universal study-hour requirement. Its official reference page describes CRMA as a self-study examination and allows candidates to choose their preparation method. References include COSO materials, ISO 31000, and guidance on risk appetite, culture, and analytics.
Official resources: Candidates can use the syllabus, interactive question demonstration, CRMA Study Guide and Practice Questions, and an IIA preparation course. These are preparation options, not alternative routes to certification.
A sensible study plan starts with a syllabus-based gap assessment, then practices applying principles to unfamiliar scenarios. Experienced auditors should still test their understanding of independence, reliance, governance, and risk escalation rather than rely only on their employer’s procedures.
Administrative time: Allow for application review, appointment availability, the three-week results window, and final experience verification.
10. How Much Does the Credential Cost?
As of September 25, 2026, published U.S. fees in U.S. dollars are:
- Application: US$100 for members; US$220 for nonmembers.
- Examination: US$465 for members; US$610 for nonmembers.
- First-attempt total: US$565 for an existing member or US$830 for a nonmember.
These totals exclude membership, preparation materials, courses, travel, taxes, and repeat attempts. Standard individual IIA membership is listed at US$290 annually. Someone newly joining at that rate would therefore pay US$855 for membership plus the application and first examination, not US$565. Other membership categories and employer group arrangements may cost less.
Additional charges: A retake requires another examination registration. Rescheduling or cancellation costs US$75 per occurrence. A 75-day examination-registration extension costs US$100, while a one-time 12-month program extension costs US$275. These are separate provisions, not automatic additions to the initial fee.
Ongoing costs: The published active-status renewal schedule lists US$20 for members and US$120 for nonmembers. However, annual certification renewal is included in membership for North American members with active designations. Continuing education may create additional costs, depending on the learning activities selected.
Fees can differ under National Institute arrangements. Confirm local pricing and applicable taxes before payment; published application and examination fees are nonrefundable and nontransferable.
11. How Do Holders Maintain the Credential?
CRMA requires annual maintenance, not simply a one-time award. Practicing holders normally complete 20 continuing professional education hours annually. Nonpracticing holders complete 10. Both categories include two hours of ethics training within their total. Approved retired holders are exempt from renewal requirements while genuinely retired.
Holders annually attest to the applicable requirements, review professional standards, report their conformance or nonconformance, and make the required ethics and criminal-conviction declarations. They must retain supporting CPE records for at least three years and provide them if selected for audit. A certification record is therefore not an independent finding that every engagement conforms to the Standards.
Renewal generally opens October 1 and closes December 31. For newly certified individuals, the initial renewal period ends December 31 of the following year. Someone certified during 2026 would normally first renew by December 31, 2027.
Failure to renew moves an active designation into Grace status. Despite the name, this does not authorize continued use of CRMA after the holder’s name. Remaining in Grace for more than 24 months leads to revocation. Restoring a revoked CRMA requires reapplication, the required fees, and passing the examination again.
Ethics violations can also lead to disciplinary action. Employers should distinguish active, nonpracticing, retired, Grace, and revoked circumstances rather than treat an old certificate as evidence of present good standing.
12. What Is Its Professional Value, and What Are Its Limitations?
CRMA can make a professional’s risk-assurance knowledge easier to recognize. It provides a structured basis for discussing governance, assurance coverage, management responses, and reporting to senior stakeholders. Its value is strongest when those subjects are central to the proposed role.
Employer treatment varies. Texas Board of Criminal Justice job descriptions include CRMA among preferred qualifications. A Sanad internal-audit management posting, by contrast, requires CIA and treats CRMA as an additional valued credential, alongside other qualifications and substantial experience. These examples show why CRMA should not be assumed to replace another credential specified in a job requirement.
For a professional considering the investment, the relevant question is whether the knowledge addresses a recurring work need. Reviewing enterprise risk management, coordinating assurance, and communicating risk conclusions are a closer fit than a role primarily concerned with actuarial modeling, technical security testing, or insurance placement. This is a subject-matter comparison, not a ranking of professions.
A material limitation is the examination’s standards basis. The IIA states that CRMA remains supported by the 2017 Standards, although the Global Internal Audit Standards became effective for professional practice on January 9, 2025. Passing CRMA therefore does not, by itself, demonstrate mastery of every current professional requirement.
Employers should assess compensation and responsibility against demonstrated work, industry knowledge, location, and role requirements, rather than assume a fixed salary premium from the letters alone.
13. What Should Employers and Clients Infer from It?
What it establishes: A verified current holder satisfied the IIA award route applicable to that person and maintains the relevant status. The modern route includes examination and experience requirements. Early Professional Experience Recognition awards mean that an employer should not infer that every holder passed today’s examination or previously held CIA.
What it does not establish: CRMA does not independently demonstrate industry expertise, project scale, leadership, stakeholder influence, implementation capability, or the quality of a particular consulting firm. The IIA’s competency framework explicitly leaves practical proficiency assessment to professional judgment.
Where it may matter: Consider it supporting evidence when staffing risk-governance reviews, assurance coordination, or internal controls assessment. Match the individual’s actual experience to the workstream rather than assuming the credential qualifies them to lead the entire assignment.
Evidence to request: Ask for nonconfidential or redacted examples of assessment criteria, an assurance map, testing documentation, and a management or board report. Establish what the person personally performed, what evidence supported the conclusion, and what changed afterward.
Three questions to assess applied competence
- How would you test whether management’s risk register is complete rather than merely well documented? A useful answer connects risks to objectives, independently challenges assumptions, and uses evidence beyond management’s existing list.
- You helped design a risk-assessment process and are now asked to assure it. What independence safeguards would you require? Look for recognition of self-review threats, disclosure, clear responsibilities, and appropriately independent review.
- When would you rely on compliance testing, and what would you report if its coverage were insufficient? A useful answer examines competence, objectivity, scope, evidence quality, and the communication of remaining assurance gaps.
14. How Does It Compare with Related Credentials?
These credentials address overlapping work but different professional questions. None should be selected solely because its abbreviation contains “risk” or “audit.”
- CIA, Certified Internal Auditor: The IIA’s broader internal-audit certification covers internal audit fundamentals, engagements, and management of the function. Its standard route has three examination parts and education-dependent experience requirements. CIA is a complement to CRMA and may be the broader starting point for an internal-audit career. It is no longer a CRMA prerequisite.
- CRISC, Certified in Risk and Information Systems Control: ISACA’s certification emphasizes technology-related risk, controls, governance, and reporting. It requires one examination and at least three years of relevant experience across at least two of its four domains. It can complement CRMA where the assignment centers on information systems rather than enterprise-wide audit assurance.
- RIMS-CRMP, RIMS-Certified Risk Management Professional: This credential addresses the broader practice of risk management. Experience requirements generally range from one year with a risk-management degree to three years with another qualifying degree or six years without one. It has a separate examination. It is an alternative to consider for managing risk programs, rather than primarily providing independent assurance over them.
All three operate internationally as professional certifications. Their usefulness depends on the assignment and employer requirements; they do not create a universal progression ladder or automatically award one another.
15. How Can You Verify the Credential and Use Its Letters Correctly?
Start with The IIA’s Certification Registry. Ask the individual for the name used in their certification record and certificate ID; country of residence can help distinguish similar names. Registry information includes the holder’s name, certificate ID, status, and country.
Participation is voluntary. A missing result is therefore not conclusive evidence of a false claim. Ask the holder to confirm their listing or provide current issuer-generated evidence, and seek IIA confirmation where the hiring decision requires stronger assurance. Do not confuse an original award certificate or badge screenshot with current status.
For a holder authorized to use the designation, a conventional presentation is Jordan Lee, CRMA. When spelling it out, use “Certification in Risk Management Assurance,” not an invented expansion such as “Certified Risk Management Auditor.” Active holders may display the letters after their names.
Applicants, course participants, and people who have passed the examination but not completed all requirements should not present themselves as CRMAs. Grace and revoked holders may not display the designation as current. Approved nonpracticing and retired categories have different maintenance rules; ask for the actual status when evaluating someone for active professional work.
16. Frequently Asked Questions
Do I need CIA before pursuing CRMA?
No. The IIA removed the CIA prerequisite in 2025. Current candidates qualify through the applicable education and experience route. Older materials describing an active CIA as mandatory refer to a previous version of the program.
Can I earn CRMA without a bachelor’s degree?
Yes. The program provides a five-year qualifying-experience route, with two of those years within the previous three years. An associate degree or high-school qualification does not reduce that requirement to the two years applicable to a bachelor’s degree.
Does completing a CRMA preparation course make me certified?
No. Preparation courses and study materials support learning but do not replace the examination, experience verification, or award process. The IIA does not require a prescribed course, so self-study candidates can pursue the same credential.
Can I take the CRMA examination from home?
No under the current delivery policy. The IIA discontinued online testing on May 27, 2025. Candidates must use an authorized Pearson VUE test center. Older descriptions of remote CRMA testing should not be used for scheduling decisions.
If I hold both CIA and CRMA, must I complete 60 CPE hours?
Not necessarily. Relevant learning can satisfy both credentials. For example, 40 hours covering internal auditing and risk management assurance can meet the practicing CIA requirement while also satisfying CRMA’s 20-hour requirement, provided all applicable conditions are met.
17. Official Resources and Recent Changes
Official resources available: The IIA provides a candidate handbook, examination syllabus, question-format demonstration, preparation references, study materials, renewal policy, registry, and CCMS support. Candidates should distinguish program administration, examination preparation, and current professional-practice guidance.
Recent material changes: The CIA prerequisite was removed in 2025. Remote testing ended May 27, 2025. Since April 1, 2026, CRMA results have been issued as a single official result within three weeks rather than an immediate unofficial result. These are current rules, not pending changes.
Examination and practice distinction: The CRMA examination remains supported by the 2017 Standards. The IIA currently states that it has no plans to update the examination. Professional assignments nevertheless need to address the applicable current Standards, not simply the examination’s reference base.
This profile is an independent Umbrex reference and is not issued or endorsed by the credential owner unless an explicit relationship is stated.