Log In

Don't have an account? Sign up now

Lost Password?

Sign Up

Password will be generated and sent to your email address.

CRISC — Certified in Risk and Information Systems Control

IT Risk & Governance · Professional Certification

CRISC — Certified in Risk and Information Systems Control

The only credential focused specifically on enterprise IT risk and control — highly valued by Jamaica’s banks, insurers, and regulators. The bridge between IT and enterprise risk management.

J$5MAvg Annual Salary
6–12 moTime to Qualify
~100CRISCs in Jamaica
↑↑ HighDemand Level

Key Facts

Awarding BodyISACA
Exam150 questions, 4 hours
PrerequisitesMinimum 3 years combined experience in IS risk management and IS control across at least 2 of 4 CRISC domains
RenewalEvery 3 years — 120 CPE hours (20 minimum per year)
RecognitionGlobal — the only credential focused specifically on enterprise IT risk and control; highly valued by banks, insurers, and regulators
Jamaica Context: BOJ IT risk management guidelines and FSC operational risk requirements create strong demand. CRISC holders are sought by Jamaica’s financial sector to bridge IT and risk management; international banks operating in Jamaica (Scotiabank, Citi) require CRISC for senior IT risk roles.

Salary in Jamaica

J$3.5M – J$16M+

Typical annual salary range for CRISC certified professionals in Jamaica

Avg J$5M
Entry J$3.5MCRO J$16M+

Salary by Role

IT Risk AnalystJ$3.5M–J$4.5M
CRISC IT Risk ManagerJ$5M–J$7.5M
GRC ConsultantJ$5.5M–J$9M
Enterprise Risk ManagerJ$6.5M–J$10M
Chief Risk OfficerJ$10M–J$16M+

Demand by Sector

Banking & Finance92%
Consulting / Advisory85%
Insurance80%
Telecoms75%
Government70%

Stand out with a professional CV

Highlight your CRISC certification to Jamaica’s financial sector employers

Build Your CV →

Career Pathway

1
IT / Risk DegreeComputer Science, Management Information Systems, or Risk Management foundation
2
IT Audit or Risk Analyst RoleBuild the IS risk management and control experience required for eligibility
3
3 Years IS Risk ExperienceAcross at least 2 of the 4 CRISC domains
4
CRISC ExamPass with 450+/800 — study using ISACA’s Review Manual and QAE
5
IT Risk ManagerJ$5M–J$7.5M — lead IT risk and governance programmes
6
ERM Lead / CROJ$10M–J$16M+ — enterprise risk and board-level reporting

Key Skills Gained

IT Risk Assessment94%
Risk Monitoring90%
Control Design88%
Regulatory Compliance88%
Business Impact Analysis85%
Board Reporting80%

Top Jamaican Employers Hiring CRISC Professionals

Bank of Jamaica
Scotiabank Jamaica
NCB Financial Group
Sagicor
FSC Jamaica
Citibank Jamaica
Deloitte Risk Advisory
KPMG Risk Consulting
Guardian Life
JN Group

Ready to apply for IT risk roles?

Get a CV tailored for GRC and risk management positions in Jamaica

Get Your CV →

How to Obtain CRISC

1
Gain IS risk management experience
Build 3 years of experience in IS risk management or IS control across CRISC domains — IT risk identification, assessment, response, and monitoring
2
Register with ISACA
Create an account at isaca.org — ISACA membership reduces exam fees and gives access to study resources
3
Study with ISACA resources
Use the CRISC Review Manual and practise with ISACA’s Question, Answer & Explanation (QAE) database
4
Sit the exam
Book at a Kryterion/PSSI centre or online proctored — 150 questions over 4 hours
5
Pass with 450+/800 and verify experience
Submit your work experience verification to ISACA within 5 years of passing the exam
6
Maintain with 120 CPE hours
Earn 120 CPE hours every 3 years (20 per year minimum) — ISACA Caribbean chapter events and BOJ/FSC risk workshops all count
7
Stack with CISA or CISSP
CISA and CRISC together cover audit and risk — a highly marketable combination in Jamaica’s regulated financial sector

Continuing Professional Development

CRISC requires 120 CPE hours per 3-year cycle (minimum 20 per year). The ISACA Caribbean chapter, BOJ and FSC risk management workshops, ISACA webinars, and approved risk management courses all count. Many Jamaican CRISC holders combine their CPD with CISA or CISM maintenance — the ISACA CPE framework covers all ISACA credentials simultaneously, making dual or triple ISACA certification highly efficient.

Frequently Asked Questions

How does CRISC differ from CISA?
CISA focuses on auditing information systems; CRISC focuses on identifying, managing, and controlling IT risk — more aligned with risk management and enterprise governance roles. Many Jamaican financial sector professionals hold both.
Is CRISC harder than CISA?
Both are challenging ISACA exams. CRISC requires fewer years of experience but the content is more strategic and enterprise-focused. Candidates with hands-on risk management experience typically find CRISC more intuitive than those from a pure IT background.
Do banks in Jamaica specifically ask for CRISC?
Yes — Jamaica’s top banks and the BOJ itself increasingly list CRISC as preferred or required for senior IT risk and GRC roles. International banks operating in Jamaica (Scotiabank, Citi) often mandate it at the manager level and above.

Related Certifications

Ready to get CRISC certified?

Join Jamaica’s top IT risk and governance professionals at the highest salary tier

Build Your CV All Certifications