
CompTIA
Cisco
ISACA & governance
Offense & defense
Current OCEG body of knowledge·Governance & Audit
OCEG GRC Auditor
Develop assurance skills for evaluating governance, risk, compliance, ethics, security, privacy, internal control, and related GRC capabilities.
Choose a preferred plan, then confirm availability with our team.

RSAY completion certificate
Recognize your training achievement
Online or in-person
Explore delivery options below
Professional
Review prerequisites before choosing
6 learning modules
Topics, practice, and learning checks
BUILD SKILLS THAT MATTER
From understanding to application.
A focused learning experience that connects the concepts to decisions you make in real technical work.
Is this the right course for me? ↗What you will be able to do
- Explain integrated GRC concepts, principles, drivers, and relationships.
- Plan an assessment with clear scope, criteria, evidence, roles, and procedures.
- Evaluate design and operating effectiveness across GRC capabilities.
- Document findings, conclusions, limitations, and improvement opportunities.
- Design assurance reports and follow-up activities for different stakeholders.
Who this course is for
Internal and IT auditors · GRC and risk professionals · Compliance and control specialists · Security and privacy assurance professionals
INSIDE THE COURSE
Explore the syllabus.
Open a module to see its focus, a suggested practical activity, and how you will check your understanding. Exam percentages are not allocations of training hours.
Official certification reference ↗Activities are RSAY learning examples, not a promise of vendor-owned lab access. Final materials are confirmed in the cohort guide.
01GRC General Knowledge · 22%
Topics in focus
Core terms, principles, business drivers, integrated GRC benefits, organizational context, and relationships with risk, compliance, security, privacy, control, and audit.
Put it into practice
Connect a business objective, risk, control, and assurance activity in a simple GRC map.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
02Assurance Models & Assessment Design
Topics in focus
Assurance concepts, independence, objectivity, criteria, materiality, evidence quality, confidence, assessment types, and lines of accountability.
Put it into practice
Choose an assessment approach and explain independence and evidence requirements.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
03Planning the Assessment
Topics in focus
Purpose, scope, objectives, stakeholders, capability context, risks, criteria, resources, procedures, sampling, communication, and documentation.
Put it into practice
Write a scoped assessment plan with stakeholders, milestones, and evidence requests.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
04Performing the Assessment · 67% domain
Topics in focus
Gathering and evaluating evidence, interviewing, testing design and operation, analyzing strengths and weaknesses, forming conclusions, quality review, and issue management.
Put it into practice
Evaluate sample control evidence and distinguish design gaps from operating failures.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
05Reporting & Follow-up
Topics in focus
Report structure, audience needs, ratings, findings, recommendations, management responses, action tracking, escalation, and follow-up assurance.
Put it into practice
Draft a finding with impact, owner, action, and a follow-up verification date.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
06GRC Assessment Framework · 11%
Topics in focus
Applying the OCEG GRC Assessment Framework based on assessment scope, including capability evaluation, procedures, documentation, and reporting.
Put it into practice
Compare assessment evidence with framework expectations and identify coverage gaps.
Your learning checkpoint
Submit your reasoning and supporting evidence. Explain the decisions you made, the limitations of your approach, and what you would improve after feedback.
RECOGNIZE YOUR PROGRESS
Your learning. Your achievement.
Receive an RSAY ITC completion certificate when you meet the attendance, activities, and assessment requirements published in your cohort guide.
Completion is not vendor certification
The RSAY certificate records training completion. Vendor certification requires its own exam and applicable eligibility criteria. An exam voucher is not included unless explicitly confirmed in your package.
CERTIFICATION EXAM
Know your next milestone.
- Certification / version
- Current OCEG body of knowledge
- Exam duration
- 120 minutes
- Assessment
- 100 questions
Exam policies can change. Verify current requirements with the certification provider before booking. Training does not guarantee a pass.
Review official requirements ↗MAKE ROOM FOR YOUR NEXT SKILL
Course schedule & pricing
An intensive week, evening sessions, or weekends. Explore a learning rhythm that fits your life.
Example schedules · not open cohorts
Compare three 40-hour plans. Dates, delivery, breaks, venue, and final price must be confirmed by RSAY. Choosing a plan does not book or charge you.
All times: Riyadh · UTC+3
Five-day intensive
Sunday–Thursday · 09:00–17:00
Online or in-person · venue to be confirmed5 × 8 hours = 40 hours
View every session
- 4 Oct 2026 09:00–17:00
- 5 Oct 2026 09:00–17:00
- 6 Oct 2026 09:00–17:00
- 7 Oct 2026 09:00–17:00
- 8 Oct 2026 09:00–17:00
Weekday evenings
Sunday–Wednesday · 18:00–20:00
Online or in-person · venue to be confirmed20 × 2 hours = 40 hours
View every session
- 4 Oct 2026 18:00–20:00
- 5 Oct 2026 18:00–20:00
- 6 Oct 2026 18:00–20:00
- 7 Oct 2026 18:00–20:00
- 11 Oct 2026 18:00–20:00
- 12 Oct 2026 18:00–20:00
- 13 Oct 2026 18:00–20:00
- 14 Oct 2026 18:00–20:00
- 18 Oct 2026 18:00–20:00
- 19 Oct 2026 18:00–20:00
- 20 Oct 2026 18:00–20:00
- 21 Oct 2026 18:00–20:00
- 25 Oct 2026 18:00–20:00
- 26 Oct 2026 18:00–20:00
- 27 Oct 2026 18:00–20:00
- 28 Oct 2026 18:00–20:00
- 1 Nov 2026 18:00–20:00
- 2 Nov 2026 18:00–20:00
- 3 Nov 2026 18:00–20:00
- 4 Nov 2026 18:00–20:00
Five weekends
Friday–Saturday · 09:00–13:00
Online or in-person · venue to be confirmed10 × 4 hours = 40 hours
View every session
- 9 Oct 2026 09:00–13:00
- 10 Oct 2026 09:00–13:00
- 16 Oct 2026 09:00–13:00
- 17 Oct 2026 09:00–13:00
- 23 Oct 2026 09:00–13:00
- 24 Oct 2026 09:00–13:00
- 30 Oct 2026 09:00–13:00
- 31 Oct 2026 09:00–13:00
- 6 Nov 2026 09:00–13:00
- 7 Nov 2026 09:00–13:00
Prerequisites
Review the professional level and intended audience. Relevant networking and operating-system knowledge helps with technical security courses; our team can assess your starting point.
Technical requirements
A computer, current browser, reliable internet, and clear audio. Software, virtual-machine requirements, and lab access are specified before registration is confirmed.
Learning schedule
The cohort guide confirms dates, breaks, live hours, self-study, activities, and assessments. Example plans on this page are illustrative until confirmed.
Measuring progress
Knowledge checks, practical activities, feedback, and a final review connect to learning outcomes. Completion criteria and assessment weights are published in the cohort guide.
Support & accessibility
Tell us about learning support or accessibility needs before enrollment. Our team can clarify attendance, complaints, privacy, and refund policies.