GRC PROFESSIONAL CERTIFICATION (GRCP™)

Become a versatile professional who integrates governance, strategy, performance, risk, compliance, ethics, security, privacy, and audit to achieve Principled Performance.

The GRC Professional (GRCP) certification demonstrates that you have the understanding and skills to apply GRC in your organization.

Learn How To Get GRCP

Become a versatile professional who integrates governance, strategy, performance, risk, compliance, ethics, security, privacy, and audit to achieve Principled Performance. The GRC Professional (GRCP) certification demonstrates that you have the understanding and skills to apply GRC in your organization.

Get an all access pass Log in Read more

This certification is your current focus. If you want to change your focus, remove your focus from this certification and pick another one to focus on.

I no longer want to focus on this.


More info about this certification

GRC Professional (GRCP™) Certification is your current focus. Go to your program dashboard for more information on resources and examination.

Go to program dashboard

My certifications

Loading...

Download my certificate

Loading...

Download my certificate


CPE and maintenance information

Become a versatile professional who integrates governance, strategy, performance, risk, compliance, ethics, security, privacy, and audit to achieve Principled Performance. The GRC Professional (GRCP) certification demonstrates that you have the understanding and skills to apply GRC in your organization.

Set / Remove Focus Show me alternatives


Back

Set / Remove Focus


Back

Set / Remove Focus

Globally Recognized GRC Certification

Get certified by the global nonprofit that invented GRC 20 years ago


What is the GRCP?

The GRC Professional (GRCP) certification validates that you understand and can apply GRC in your organization. It ensures that you have the versatile skill set to integrate and advise on governance, strategy, performance, risk, compliance, ethics, internal control, security, privacy, and audit activities.


GRCP Candidate Handbook

The GRC Professional (GRCP) Candidate Handbook is your definitive resource for all things GRCP certification. This Handbook provides comprehensive insights into certification eligibility, exam details, and the certification renewal process. It also features a valuable set of sample questions to enhance your preparation for the GRCP exam. Whether you're a prospective candidate or currently pursuing GRCP certification, this Handbook is your roadmap to success for the GRCP (GRC Professional) Certification.

Download the Handbook Today


What does the GRCP Cover?

The GRCP is based on the essential body of knowledge used daily by GRC Professionals. With the help of hundreds of experts, this body of knowledge was identified, analyzed, and documented in the GRC Capability Model.

We recommend using these resources to prepare for the GRCP Exam (all of these are available on the GRCP Focus page that helps guide you through the process of getting certified)

  • GRC Capability Model ("Red Book") - contains the essential body of knowledge
  • GRC Fundamentals - is a self-study online course provided to deepen your understanding of the GRC Capability Model
  • GRC Fundamentals LIVE - is offered by our global training partners to provide localized language, more context, and implementation examples.

While the exam does not require course attendance, 94% of people who pass on the first attempt report that a course helped them pass.

Benefits of certification from the creators of GRC

GRCP comes from the organization and community that created GRC over 20 years ago. You are learning from and getting certified by THE authoritative source!


Unique Benefits of GRCP

Rather than just focusing on a single discipline, GRCP integrates multiple disciplines and helps you become a versatile professional.

GRCP allows you to integrate governance, strategy, performance, risk, compliance, ethics, security, internal controls, and audit.

  • Integration. Integrate your work with business operations.
  • Versatility. Cut across the critical disciplines to be more effective.
  • Communication. Communicate with diverse audiences.
  • Compensation. Obtain new jobs and accelerate your career.

Learn how to get GRCP


Is GRCP right for me?

GRCP is perfect for anyone who works in - governance, strategy, performance, risk, compliance, ethics, internal control, security, continuity, audit, assurance, or IT. GRCP helps to integrate what you do with the other departments and disciplines, including mainline business operations.

Our certifications are open and accessible to all professionals. We accept candidates from diverse cultural, educational, and professional backgrounds. We do not require specific experience or educational degrees to apply.


When should I get GRCP?

GRCP is a versatile certification aimed to serve versatile needs for professionals in all stages of their careers. Professionals can use the GRCP in several scenarios:

  • Starter. Some professionals use the GRCP as a starting point for their careers. By understanding and applying GRC capabilities, you get the full breadth of governance, strategy, risk, compliance, security, and audit, in any organization. You will gain traction ahead of your peers no matter what role you are in today – and it also gives you a well-rounded and versatile foundation to grow into other roles in other disciplines over time!
  • Enhancer. Some professionals use the GRCP to enhance an existing certification in risk, compliance, security, or audit. For example, a risk manager may have a certification in quantitative risk management – GRCP helps to integrate risk concepts with business operations as well as governance, strategy, compliance, security, and audit. An audit manager may have a certification in internal audit – GRCP helps to integrate audit concepts with business operations as well as governance, strategy, risk, compliance, and security. All of this makes you well-rounded and versatile.
  • Capstone. Some professionals use the GRCP as a capstone “on top of” a collection of existing certifications. GRCP uniquely integrates the many disciplines of governance, strategy, risk, compliance, security, and audit. Professionals with one or more certifications in those disciplines find value in how GRCP cohesively pulls everything together into a framework and methodology.

GRCP is for new and experienced professionals


New Professionals

GRCP is the perfect way to start your career. By understanding and applying all critical disciplines, you have a broad foundation to build a career in any GRC role. GRCP helps you understand the inner workings within and between other departments, including how they operate, think, and what they need to succeed.


Experienced Professionals

GRCP is the perfect way to enhance existing certifications and to upgrade skills in areas where you lack experience. You may already have a certification from one of the many associations. However, most of these associations focus on a SINGLE discipline. GRCP helps to make you more VERSATILE and well-rounded.

What are you waiting for?

Purchase an All Access Pass to access the GRCP and all of our other certifications.

Purchase All Access Pass

100 questions over 120 minutes

What is on the GRCP Exam?

Correctly answer 70 of the 100 questions to pass!

The GRCP certification exam assesses your knowledge and ability to apply the GRC Capability Model. The exam content is weighted as follows:

  • 30% GRC Key Concepts
    • Understand key concepts associated with Reliably Achieving Objectives
    • Reliably Addressing Uncertainty
    • Reliably Acting with Integrity
    • Understand key concepts associated with the Lines of Accountability™ and Integrated Action & Control Model™
    • Understand key concepts associated with measuring the GRC Capability Model
  • 70% GRC Capability Model Details
    • Understand components, elements, and practices
    • Understand key actions and controls
    • Understand design and implementation considerations
    • Details are grouped by components (adds up to 70%)
    • Learn Component: 15%
    • Align Component: 20%
    • Perform Component: 25%
    • Review Component: 10%

Note: The GRCP certification exam is based on a blueprint that serves as a competency model for GRC professionals. This blueprint was developed through an extensive job analysis and research involving over 1,000 GRC professionals who analyzed over 200 skills to determine their significance in the field of GRC.

Additionally, certified GRC professionals (holders of the GRCP™ credential) periodically update the GRC Capability Model and the GRC Professional Exam to reflect relevant changes in GRC disciplines and practices.


  • Principles, outcomes, and key terms. Prove that you can communicate across disciplines using a common and unambiguous vocabulary.
  • Core components, practices, and activities. Demonstrate understanding of the components and elements of the GRC Capability model.
  • Relationship of GRC to disciplines. Discuss how GRC incorporates the governance, management, and audit of strategy, performance, risk, and compliance.

Learn how to get GRCP


How do I get the GRCP Certification?

All of our certifications use a similar streamlined process. We pride ourselves on simplicity and accessibility. All of our exams are online and available at any time. No need to schedule! We include everything you need as part of your All Access Pass. To be clear, everything is included for no additional fees.

1. Get All Access Pass

Our All Access Pass provides everything you need to prepare for the GRCP and all of our other certification exams. One fee for education, preparation, certification, and maintenance.

Everything is included for no additional fees.

2. Prepare for GRCP

Study the essential body of knowledge contained in the GRC Capability Model (“Red Book”) and attend GRC Fundamentals to learn how to apply it.

We offer GRC Fundamentals via self-study or by attending an in-person course delivered by one of our authorized partners (a great choice if you want localized language and additional examples).

Our self-study programs are delivered in English and often subtitled in English, Spanish, Arabic, and Bahasa (our GRC Fundamentals course is being updated and will have subtitles soon). Need another language? Let us know.

Essential body of knowledge and self-study are included for no additional fees.

3. Apply for GRCP

Our certifications are open and accessible to all professionals. We accept candidates from diverse cultural, educational, and professional backgrounds.

We do not require specific experience or educational degrees to apply.

Just complete a simple form at the beginning of the exam to update your information and agree to the code of conduct.

Application is included for no additional fees.

4. Earn the GRCP (Pass!)

Access the online exam anywhere and anytime.

The exam is limited to two hours (120 minutes) to answer 100 questions. Correctly answer 70 questions to pass. Exams are "open book," which means that you may use Google and other resources while taking an exam.

You can retake an exam up to six times per year to pass it.

All retakes are included for no additional fees.

5. Maintain the GRCP

Participate in the streamlined Unified Certification Maintenance program to maintain your certification. All continuing education is automatically tracked and administered under this unified program. Whenever you watch a video or attend an event on our website, it is automatically tracked and counted toward your certifications as appropriate.

DOUBLE CREDIT!

One CPE credit may track to multiple certifications. For example, a course on “Risk Assessments” counts toward all certifications that use Risk Assessment skills.

All maintenance and CPEs are included for no additional fees.

6. BONUS! Add More Certifications

Apply to gain additional certifications. We add new certifications regularly.

All certifications are included for no additional fees.

How long is my certificate valid?

A streamlined approach to gain and maintain your certification.

We use continuing education requirements to ensure that you stay current with new developments in GRC. You can review the other requirements to maintain your GRCP certification.

When a certificate is awarded, it is awarded for a full year starting on the day you passed the exam.

Your first full year has no CPE requirement (because you spent at least 8 hours preparing for and taking the exam).

Starting your second year, you must earn at least eight (8) credits of continuing education related to the certification topic annually.

When a certificate renews, it renews for a full year. Automatic renewal on the day of certificate expiration happens if both of these conditions are true: a) Member has an active AAP and b) CPE requirement has been met (if applicable).

If the expiration date passes and you do not meet both conditions, you have a grace period of 90 days to fulfill both requirements. After the grace period is over, your certification gets deleted from our records, and certificates are no longer available for display.

How to get the GRCP

What are you waiting for?

Purchase an All Access Pass to get access to the GRCP and all of our other certifications.

Purchase All Access Pass

Get started now!

As an All Access Pass holder you have access to all OCEG certifications.

Focus on this certification

FAQ about Preparing for GRCP

How long does it take to prepare for GRCP?

Preparation time varies based on your experience. People who pass the exam report anywhere from 2 hours to 40 hours of preparation before the exam.

This wide range is explained by the differences in background. If you are more experienced in governance, strategy, risk, compliance, ethics, security, or audit, then less time may be required to prepare vs. someone who is new to GRC.


How long does it take to prepare for GRCP?

The essential body of knowledge for the GRCP is contained in the open-source GRC Capability Model (“Red Book”). We recommend that you:

  • Carefully study the GRC Capability Model
  • Attend online self-study GRC Fundamentals course
  • Attend in-person GRC Fundamentals LIVE! course
  • Practice exam questions

How do I get GRCP Training?

We offer GRC Fundamentals via self-study or by attending an in-person course delivered by one of our authorized partners. Training partners are a great choice if you want the training delivered in your native language and want additional context and examples for applying the concepts. Our self-study programs are delivered in English and subtitled in English, Spanish, Arabic, and Bahasa.


What does it cost to get GRCP training?

All of our self-study preparation courses are included for no additional fees.

This means that GRC Fundamentals is part of your All Access Pass.

Our global training partners charge separate fees for in-person experiences delivered in the localized language. These experiences also provide additional context and examples so that you understand how to implement solutions.

FAQ about the GRCP Exam

How do I schedule the GRCP Exam?

All of our exams are online and available at any time. No need to schedule!


How do I apply for the GRCP exam?

Applying for GRCP is simple! If you are already an OCEG member, we have most of the information necessary. Just complete a simple form at the beginning of the exam to update your information and agree to the code of conduct.

As a reminder, our certifications are open and accessible to all professionals. We accept candidates from diverse cultural, educational, and professional backgrounds. We do not require specific experience or educational degrees to apply.


How difficult is the GRCP Exam?

Most people who pass the exam report that they carefully studied the GRC Capability Model and completed the GRC Fundamentals course.

Those who fail tend to pass on a subsequent attempt if they study and complete GRC Fundamentals or attend a training course with an OCEG training partner.

In other words ... STUDY and WATCH the videos or attend a class if you want to pass the exam.


What is on the GRCP Exam?

The GRCP certification exam covers both awareness (definitions, terms, and lists) and the application of concepts and knowledge of the GRC Capability Model. The exam breaks out as follows:

  • 15% General Knowledge
    • Understand key terms and definitions related to GRC
    • Understand key principles and business drivers behind GRC
    • Understand the benefits of integrating GRC
    • Understand how GRC relates to other disciplines/professions
  • 85% GRC Capability Model Details
    • Understand components, elements, and practices
    • Understand key actions and controls
    • Understand design and implementation considerations

How was the GRCP Exam developed?

GRCP topics and questions were determined by conducting an extensive job analysis of over 500 GRC Professionals. Participants in the job analysis were asked to analyze over 200 skills and determine their significance to a GRC professional, executive, or auditor. The job analysis and other research yielded a blueprint that serves as a competency model for the GRCP.

We update the GRC Capability model and GRC Professional Exam periodically to reflect important and relevant changes in GRC disciplines and practices.


How many questions are on the GRCP Exam?

There are 100 scored questions and up to 15 unscored questions on the exam. We calculate your final score on the 100 scored questions. Scored questions have gone through a rigorous validation process.

The unscored questions are used to introduce and validate new questions without affecting your score. However, the unscored items are not labeled – so make sure you answer each question as if it counts!

All questions are multiple choice.


How do I pass the GRCP Exam?

You have 2 hours to complete the exam. You must correctly answer 70 of the 100 scored items.


Is the GRCP Exam "open book" like the real world?

Yes! The GRCP Exam is open-book, which means that you may use Google and other resources while taking the exam.

We believe that the exam process should reflect modern reality and user experiences. In your job, you use Google and online resources daily. You should be able to use these resources when you learn and when you take the exam.

However, don't be fooled! The exam is challenging even with the help of these resources.


When do I find out if I passed the GRCP?

You get your result immediately after taking the exam. If you pass, your certificate is immediately available for sharing and printing.


What happens if I fail the GRCP and how many times can I take the exam?

You may retake the exam up to six (6) times per year. Almost everyone is able to accomplish this goal. We believe that certification should be part of the learning process and help reinforce understanding and not just be a point-in-time proof of memorized knowledge.

Consider being fully prepared each time that you attempt the exam. Our database of questions is extensive, so it is unlikely that you will see the same questions each time that you attempt the exam.

FAQ about Maintaining GRCP

How long is my certificate valid?

When a certificate is awarded, it is awarded for a full year starting on the day you passed the exam.

Your first full year has no CPE requirement (because you spent at least 8 hours preparing for and taking the exam).

Starting your second year, you must earn at least eight (8) credits of continuing education related to the certification topic annually.

When a certificate renews, it renews for a full year. Automatic renewal on the day of certificate expiration happens if both of these conditions are true: a) Member has an active AAP and b) CPE requirement has been met (if applicable).

If the expiration date passes and you do not meet both conditions, you have a grace period of 90 days to fulfill the requirements (

Under Construction New! Generate your own 90s page here! Under Construction