Governance, Risk, and Compliance

GRC standards address how an organization is directed, how it identifies and treats risk, and how it demonstrates that it plays by the rules. This domain covers risk management with ISO 31000, anti-bribery with ISO 37001, compliance management with ISO 37301, organizational governance with ISO 37000, and IT governance with ISO/IEC 38500. These credentials are frequently required for roles in regulated industries and for organizations bidding on public sector contracts.

Courses

18

Standards

5

Languages

10

From

€299

Who this is for

  • Risk managers and heads of enterprise risk
  • Compliance officers and ethics function leads
  • Internal auditors covering governance and compliance
  • Board advisors and executives accountable for governance frameworks

Standards in this category

ISO 31000ISO 37000ISO 37001ISO 37301ISO/IEC 38500

Credential levels available

Corporate Governance Lead ManagerCorporate Governance ManagerFoundationIT Corporate Governance FoundationIT Corporate Governance ManagerLead AuditorLead IT Corporate Governance ManagerLead ImplementerLead Risk ManagerRisk ManagerTransition

Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →

All governance, risk, and compliance courses€299€850

Self-study

ISO/IEC 38500

Lead IT Corporate Governance Manager

EN, FR

2 exam attempts included
€950€750View course →
Self-study

ISO/IEC 38500

IT Corporate Governance Manager

EN

2 exam attempts included
€790€590View course →
Self-study

ISO/IEC 38500

IT Corporate Governance Foundation

EN

2 exam attempts included
€550€390View course →
Self-study

ISO 37301

Lead Implementer

EN, UA, ES +1 more

2 exam attempts included
€950€750View course →
Self-study

ISO 37301

Lead Auditor

EN, ES, KO +1 more

2 exam attempts included
€950€750View course →
Self-study

ISO 37301

Foundation

EN, UA, ES +3 more

2 exam attempts included
€550€390View course →
Self-study

ISO 37001

Transition

EN, UA, ES

2 exam attempts included
€390€299View course →
Self-study

ISO 37001

Lead Implementer

EN, UA, ES +3 more

2 exam attempts included
€950€750View course →
eLearning

ISO 37001

Lead Implementer

EN

2 exam attempts included
€1,050€850View course →
Self-study

ISO 37001

Lead Auditor

EN, UA, ES +5 more

2 exam attempts included
€950€750View course →
eLearning

ISO 37001

Lead Auditor

EN

2 exam attempts included
€1,050€850View course →
Self-study

ISO 37001

Foundation

EN, ES, DE +2 more

2 exam attempts included
€550€390View course →
Self-study

ISO 37000

Corporate Governance Manager

EN, FR

2 exam attempts included
€790€590View course →
Self-study

ISO 37000

Corporate Governance Lead Manager

EN

2 exam attempts included
€950€750View course →
Self-study

ISO 31000

Risk Manager

EN, UA, ES +3 more

2 exam attempts included
€790€590View course →
eLearning

ISO 31000

Risk Manager

EN

2 exam attempts included
€850€650View course →
Self-study

ISO 31000

Lead Risk Manager

EN, KO, DE +1 more

2 exam attempts included
€950€750View course →
Self-study

ISO 31000

Foundation

EN

2 exam attempts included
€550€390View course →

Frequently asked questions

What is the difference between ISO 37001 and ISO 37301?

ISO 37001 is specifically an anti-bribery management system — it targets one risk in depth. ISO 37301 is a general compliance management system covering an organization’s full range of compliance obligations, of which bribery is one. Organizations with broad regulatory exposure usually want 37301; those addressing a specific bribery risk or contractual requirement often start with 37001.

Can an organization be certified against ISO 31000?

No. ISO 31000 is a guidance standard for risk management, not a requirements standard, so organizations are not certified against it. Individuals can still hold a PECB personal certification demonstrating their competence in applying it — which is what these courses lead to.

Which course suits someone new to risk management?

The Foundation level introduces risk management principles and terminology without assuming prior experience. Risk Manager and Lead Risk Manager build on that toward designing and leading a risk management programme.

What does ISO/IEC 38500 cover?

ISO/IEC 38500 is the standard for corporate governance of information technology. It addresses how boards and executives direct and oversee IT — accountability, strategy, acquisition, performance, conformance and human behaviour — rather than how IT is run day to day.

Are these credentials recognized internationally?

Yes. PECB is an accredited certification body and its personal certifications are recognized worldwide. Courses in this category are delivered in English and, for several standards, in additional languages.