Free Practice Questions for IIA CRMA
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Explore More IIA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
Key Facts: IIA CRMA Exam
100 Qs
Exam Questions
2-hour time limit
600/750
Passing Score
IIA scaled scoring
5 Domains
2024 Standards
15 Principles, effective Jan 2025
5 + 20
COSO ERM 2017
Components and principles
8 Principles
ISO 31000:2018
Risk management standard
3 Lines
IIA Model (2020)
Replaced 'Lines of Defense'
CRMA is a 100-question, 2-hour add-on credential for internal auditors who provide assurance and advisory over risk management. The 2026 prep aligns with the 2024 Global Internal Audit Standards (effective 9 January 2025), COSO ERM 2017 (5 components, 20 principles), ISO 31000:2018, and the IIA Three Lines Model (2020). CRMA is delivered by Pearson VUE (test centers or OnVUE online proctoring) and uses the IIA's 250-750 scaled scoring with 600 to pass.
Sample IIA CRMA Practice Questions
Try these sample questions to review concepts for the IIA CRMA exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Under the 2024 Global Internal Audit Standards, who has primary accountability for ensuring an organization has an effective risk management framework?
2The IIA's Three Lines Model (2020) replaced the Three Lines of Defense. Which statement best describes a key change introduced by the new model?
3How many components are in the COSO ERM 2017 'Enterprise Risk Management — Integrating with Strategy and Performance' framework?
4ISO 31000:2018 defines risk as the:
5An audit committee is reviewing the company's risk appetite statement. Which characteristic is MOST important for the statement to be useful in governance?
6Which of the following BEST illustrates the 'tone at the top' driving risk culture?
7Per the IIA Three Lines Model, which group is responsible for designing and overseeing the risk management framework, including policies and risk monitoring?
8An organization's board has set a risk tolerance of 'no more than $5M aggregate operational loss per quarter.' This is BEST described as:
9A CAE is asked by the CFO to take direct responsibility for managing a newly identified compliance risk because 'audit knows it best.' What is the MOST appropriate response under the 2024 Global Internal Audit Standards?
10Which COSO ERM 2017 component most directly addresses how an entity identifies, assesses, and prioritizes risks that could affect achievement of strategy?
About the IIA CRMA Exam
The IIA's Certification in Risk Management Assurance (CRMA) validates an internal auditor's ability to provide assurance over the risk management processes that protect organizational value. Content covers organizational governance related to risk management (~25%), principles of risk management processes (~25%), assurance role of internal audit (~20%), consulting role of the internal auditor (~15%), and other specialized risk areas (~15%) including BCM, fraud, third-party, ESG, and IT/cyber risk.
Exam sponsor: The Institute of Internal Auditors (IIA) / Pearson VUE. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Questions
100 questions
Time Limit
2 hours
Passing Score
600/750 (scaled)
Reported exam pass rate: Not publicly disclosed. IIA does not release CRMA-specific pass rates Exam sponsor website
Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
Organizational Governance Related to Risk Management
Board oversight, risk culture, Three Lines Model (2020), COSO ERM 2017, ISO 31000:2018, audit charter, risk appetite/tolerance
Principles of Risk Management Processes
Risk identification, assessment (inherent/residual/velocity), response, monitoring, communication, KRIs, scenario/stress testing, NIST CSF/RMF
Assurance Role of Internal Audit
2024 Global Internal Audit Standards, assurance mapping, evidence, sampling, follow-up, overall opinions on risk management
Consulting Role of the Internal Auditor
Facilitation, advisory engagements, independence safeguards, communication of significant matters, competency
Specialized Risk Areas
Fraud risk (triangle/diamond), third-party/TPRM, BCM/ISO 22301, ESG (IFRS S2/CSRD), IT/cyber, AML, privacy, AI risk, operational resilience
Preparing for the IIA CRMA Exam
What You Need to Know
- Passing score: 600/750 (scaled)
- Exam length: 100 questions
- Time limit: 2 hours
- Exam / certification fees: Per IIA member/non-member fee schedule Official sources
Using Our Practice Resources
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
IIA CRMA: Suggested Study Strategy
Frequently Asked Questions
How many questions are on the CRMA exam and how long is it?
The CRMA exam is 100 multiple-choice questions delivered in a 2-hour window through Pearson VUE (test centers or OnVUE online proctoring). The IIA reports results on a 250-750 scaled scoring basis with 600 required to pass.
What are the CRMA exam domains?
The CRMA covers five content areas: organizational governance related to risk management (~25%), principles of risk management processes (~25%), assurance role of internal audit (~20%), consulting role of the internal auditor (~15%), and other specialized risk areas (~15%) such as BCM, fraud, third-party, ESG, and IT/cyber risk.
What standards does the CRMA reference?
Modern CRMA prep should align with the 2024 Global Internal Audit Standards (effective 9 January 2025, replacing the 2017 IPPF), COSO ERM 2017 (5 components, 20 principles), ISO 31000:2018 (8 principles), the IIA Three Lines Model (2020), NIST CSF 2.0, and ISO 22301:2019 for business continuity.
Who is eligible to take the CRMA?
The CRMA is available to active CIAs and to candidates who meet the IIA's CRMA-specific eligibility. Candidates apply through the IIA's CCMS portal and schedule the exam with Pearson VUE. Verify current eligibility on the IIA's CRMA certification page.
How is the CRMA different from the CIA or CRISC?
CIA is the foundational internal audit credential (three parts). CRMA is an IIA add-on focused specifically on risk management assurance and consulting. CRISC (ISACA) addresses risk and information systems control with a stronger IT focus. Many internal auditors hold CIA + CRMA, while CRISC is often pursued by IT-risk professionals.
How long should I study for the CRMA?
Most candidates plan 60-100 hours of study, depending on internal audit experience. Focus on the 2024 Global Internal Audit Standards (5 Domains, 15 Principles), COSO ERM 2017, ISO 31000:2018, the Three Lines Model, and applied scenarios across BCM, fraud, third-party, ESG, and IT/cyber assurance.