
110 slides on key exam focus areas.
Certifications propelled my career in internal audit and risk management, from CMA and CIA to CRM, CFSA, CSA, and IIA leadership across banks and brands.
Plan the CRM A exam with 2–3 months of revision and hundreds of practice questions, focusing on new questions across all parts before testing at Pearson VUE centers or online.
Explore what this CRMA lecture covers and does not, and contrast awareness versus proficiency in CIA and CRM, with recommended review areas.
Explore internal audits and governance of risk management, then assurance over risk management, with practical risk assessments, risk and control self-assessments, monitoring, and maturity models.
Explore the internal audit function's role in managing organizational risks and how enterprise risk management emphasizes goals, uncertainty, and opportunities.
Enterprise risk management applies risk management across the entire organization to identify events that could hinder goals and objectives, from shareholder returns to reputation and sustainable practices.
Contrast risk management with enterprise risk management, showing risk management as mitigating risks and being risk averse, while ERM is organization-wide, strategy-driven, and interrelates risks.
Explore risk management maturity as a benchmarking framework that measures how fully an organization implements risk management measures, using a CMMI-based model and noting other maturity models.
Strengthen risk culture and integrate risk into decision making and rewards through the risk management maturity model, and enhance governance, management training, and improve risk aggregation, reporting, and cybersecurity.
See how risk information ownership matures from internal audit in the initial stage to a shared, policy-driven process across functions. Aligns risk appetite, ratings, and reporting for strategic decisions.
Learn how to apply risk management maturity models to conduct internal audits, assess organizational maturity across initial, managed, and defined stages, and tailor governance, reporting, and risk understanding to departments.
Maintain objectivity through functional independence from management, adherence to standards and ethics, and avoidance of appearance of conflicts of interest, with disciplined procedures, supervision, and safeguards to ensure unbiased reporting.
Explore threats to internal audit independence and objectivity, emphasizing the mandate, board accountability, access to resources, and freedom from management interference in reporting results.
Explore IIA standard 2120 on internal audit's role in risk management, evaluating governance, operations, and information systems, considering fraud risk, and integrating consulting insights into assurance engagements.
Explore forbidden internal audit roles in ERM, such as setting risk appetite, imposing risk management processes, providing management assurance, and deciding or implementing risk responses.
Examine internal audit's role in enterprise risk management, including assurance on risk processes and developing the erm framework, while noting prohibited actions like risk response decisions.
Share plans, data, and findings to enhance risk management, coordinate with assurance providers for broader coverage with fewer resources, and rely on solid controls to avoid duplicating tests.
Explore a typical board governance model for risk, detailing the audit and risk committees, the chief audit executive, and the chief risk officer's role in enterprise risk management oversight.
Explore COSO's enterprise risk management cube, linking internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring to align with organizational goals.
Define your organization's risk appetite and acceptable risk to set clear risk-taking boundaries, quantify risk types and amounts, and align risk communication, culture, and planning with strategy.
Identify the main functions of controls—directive, preventive, detective, and corrective—and see how guidelines, training, incentives, access restrictions, approvals, maintenance, reconciliations, exception reports, and audits mitigate risks.
Develop and monitor lead indicators and controls for emerging risks, tracing triggers, root causes, intermediate events, risk events, and consequences across a risk timeline.
explain audit risk as the residual undetected risk after inherent, control, and detection risks, and relate it to material misstatement and subsequent events in financial statements.
Apply ISO 31000 risk management principles to create value by integrating risk reporting into decision making across the organization, using structured, unambiguous processes and top-down, bottom-up communication.
Compare COSO ERM and ISO 31000 components, showing they match; map internal environment and objective setting to ISO chapters, and identify risk evaluation as COSO's risk assessment.
Explore the McKinsey 7S model, detailing seven elements—structure, systems, style, staff, skills, strategy, shared values—and distinguish hard elements from soft ones, guided by leadership and risk culture.
Assess emerging risks from a breakthrough in manufacturing technology and expansion into new markets, and explore how ERP adoption and enhanced planning reduce uncertainty toward pure risk.
Identify risks through workshops and face-to-face interviews with frontline staff, applying a bottom-up approach to surface risks to objective achievement, including control self-assessment.
Identify and discuss process risks through a bottom-up brainstorming session where operational staff and internal auditors collaborate on CRSA to map inputs to outputs and improve risk responses.
Explore scenario planning using decision trees and sensitivity analysis to assess a bank's capital adequacy under Basel II across scenarios like recession and rising interest rates, highlighting organizational vulnerability.
Identify and evaluate risks via a risk inventory, map significant risks on a likelihood-impact graph, and examine process controls with workflows, flowcharts, and escalation procedures.
Establish the scope and objectives for risk management using external criteria such as laws and regulations and internal criteria like risk policies and procedures, and incorporate best practices.
Define data analytics for internal audit by gathering and analyzing data to extract insights that inform decision making, with emphasis on big data, artificial intelligence, and automated processes.
Describe and summarize data to understand what is going on and what has happened. Aggregate data from multiple sources, compute averages, and present descriptive findings for management and auditors.
Explore predictive data analytics, using forecasts and interdependencies to predict future performance and trends, with machine learning, statistical models, and applications like dynamic pricing and seasonal sales.
Explore how a T function graph of daily network access incident tickets over a month illustrates descriptive data analytics, showing the data as it is rather than predicting or prescribing.
Explore prescriptive data analytics that anticipate exceptions and automatically adapt processes to prevent them, moving beyond predictive, diagnostic, and descriptive insights.
Explore statistical process control with a bell curve, set upper and lower control limits, identify out-of-control items, and assess when outliers exaggerate averages amid natural variation.
Learn the five whys method for root cause analysis by repeatedly asking why to drill down to the underlying cause, with examples like staff shortages and hiring the wrong person.
Failure modes and effects analysis (FMEA) is a systematic, proactive method to identify root causes and failures, assess their impact, and prioritize risks using cross-functional teams and probability-based ratings.
Explore how internal audit can influence deployment design or software selection, embed security controls in development policies, and align acceptance criteria with the initial project objectives.
Explore the waterfall method in the SDLC, with non-overlapping stages and sign-offs at each phase, balancing control with potential inflexibility and longer deadlines.
We are glad to bring you a course on the Certification in Risk Management Assurance (CRMA), a certification from the Institute of Internal Auditors (IIA).
We really think this is the best course in the world on the CRMA, despite having a Udemy price.
This course will give you all that you need to cover the study parts of the new CRMA syllabus. It is intended for either:
1. Those who want to learn more about risk management.
2. Those who want to learn how to audit risk management.
3. Those who want to pass the CRMA certification exam.
It includes 40 exclusive practice questions, plus further questions explained during the course.
It includes 110 pages of slides on key exam areas.
It is taught by Adrian Resag, an experienced Chief Audit Executive and Head of Risk Management who has also been teaching for nearly 2 decades.
You will learn:
All you need to know to pass the CRMA exam.
The basics (and intermediate knowledge) of risk management.
What you need to know to perform proper audits of risk management.
The course covers:
CRMA Introduction and Exam Strategy
Introduction to the CRMA, what strategies to use for the exam, what types of questions can be asked and what topics are covered in the CRMA.
Internal Audit's Role in Risk Management
Understand the role of an internal audit function in the management of an organization’s risks.
The Governance of Risk Management
Learn how to apply governance structures and frameworks over the management of risks in an organization.
Know how to assess the governance framework in place.
Assurance over Risk Management Learn how to perform risk assessments
Know different measures for evaluating risks, how risk and control self-assessments are performed.
Know how the monitoring of risks and the risk management system should be performed.
Know how to use risk management maturity models in your organization.