Audit, risk management, privacy and security leadership certifications.
Governance credentials sit at the management layer: control frameworks, audit evidence, risk registers, privacy engineering and the reporting lines that make security programmes accountable.
These exams reward the ability to distinguish between a control, a risk and an issue, and to pick the response a governing body would actually endorse.
A vendor-specific security primer: zero trust concepts, Microsoft Entra identity capabilities, the Defender product family and Purview compliance tooling.
Open the exam guideFilter by practice availability, provider, level or exam code to narrow the list.
15 exams
The most widely recognised senior security certification: eight domains spanning risk management, asset and architecture security, networks, identity, testing, operations and software security.
The benchmark IT audit credential: the audit process itself, IT governance and management, systems acquisition and development, operations and resilience, and protection of information assets.
A vendor-specific security primer: zero trust concepts, Microsoft Entra identity capabilities, the Defender product family and Purview compliance tooling.
Security management rather than security engineering: governance, risk management, building and running a security programme, and managing incidents at an organisational level.
Enterprise IT risk in practice: governance structures, risk assessment methodology, response and reporting, and the technology and security knowledge needed to evaluate controls.
The Microsoft security architect exam: designing zero trust strategy, security operations, identity and compliance capabilities, and security for infrastructure, applications and data.
Protecting data with Microsoft Purview: sensitivity labelling, data loss prevention, lifecycle management, insider risk and the investigations that follow an alert.
CompTIA’s most advanced security certification, formerly CASP+: enterprise security architecture and engineering, governance and risk, and running security operations at scale.
Technical privacy implementation: privacy governance and programme structure, privacy architecture across infrastructure and applications, and managing the data lifecycle.
The authorisation and risk management credential, formerly CAP: building a risk management programme, selecting and implementing controls, assessment, authorisation and continuous monitoring.
Specialist project risk management: risk strategy and planning, identification, qualitative and quantitative analysis, response planning, and monitoring risk through delivery.
Enterprise IT governance at executive level: governance frameworks and structures, resource management, benefits realisation, and optimising risk across the IT portfolio.
Implementing ServiceNow Risk and Compliance: policy and control frameworks, risk assessment and scoring, audit management, and the continuous monitoring that supports them.
An executive security credential: governance and risk, controls and audit management, security programme management, core competencies, and the financial and vendor side of security leadership.
An advanced audit credential aimed at AI systems: governance and risk frameworks for AI, auditing models and data pipelines, and reporting on AI assurance.
How many exams each provider contributes here.
Where each exam sits, so you can plan a progression rather than a single jump.
15 exams from 7 vendors are tagged to Governance, Risk & Compliance. Exams appear in this category when it is either their primary focus or a substantial secondary one.
Microsoft Security, Compliance, and Identity Fundamentals (SC-900) is the most common entry point. A vendor-specific security primer: zero trust concepts, Microsoft Entra identity capabilities, the Defender product family and Purview compliance tooling.
ISC2 Certified Information Systems Security Professional, Certified Information Systems Auditor and Microsoft Security, Compliance, and Identity Fundamentals (SC-900) are the most frequently pursued in this category.