Governance, Risk, and Compliance
GRC standards address how an organization is directed, how it identifies and treats risk, and how it demonstrates that it plays by the rules. This domain covers risk management with ISO 31000, anti-bribery with ISO 37001, compliance management with ISO 37301, organizational governance with ISO 37000, and IT governance with ISO/IEC 38500. These credentials are frequently required for roles in regulated industries and for organizations bidding on public sector contracts.
Courses
18
Standards
5
Languages
10
From
€299
Who this is for
- Risk managers and heads of enterprise risk
- Compliance officers and ethics function leads
- Internal auditors covering governance and compliance
- Board advisors and executives accountable for governance frameworks
Standards in this category
Credential levels available
Not sure which level fits your role, or what experience a designation requires? See the full certification-criteria reference →
All governance, risk, and compliance courses€299–€850
ISO/IEC 38500
Lead IT Corporate Governance Manager
EN, FR
2 exam attempts includedISO/IEC 38500
IT Corporate Governance Manager
EN
2 exam attempts includedISO/IEC 38500
IT Corporate Governance Foundation
EN
2 exam attempts includedISO 37301
Lead Implementer
EN, UA, ES +1 more
2 exam attempts includedISO 37301
Lead Auditor
EN, ES, KO +1 more
2 exam attempts includedISO 37301
Foundation
EN, UA, ES +3 more
2 exam attempts includedISO 37001
Transition
EN, UA, ES
2 exam attempts includedISO 37001
Lead Implementer
EN, UA, ES +3 more
2 exam attempts includedISO 37001
Lead Implementer
EN
2 exam attempts includedISO 37001
Lead Auditor
EN, UA, ES +5 more
2 exam attempts includedISO 37001
Lead Auditor
EN
2 exam attempts includedISO 37001
Foundation
EN, ES, DE +2 more
2 exam attempts includedISO 37000
Corporate Governance Manager
EN, FR
2 exam attempts includedISO 37000
Corporate Governance Lead Manager
EN
2 exam attempts includedISO 31000
Risk Manager
EN, UA, ES +3 more
2 exam attempts includedISO 31000
Risk Manager
EN
2 exam attempts includedISO 31000
Lead Risk Manager
EN, KO, DE +1 more
2 exam attempts includedISO 31000
Foundation
EN
2 exam attempts includedFrequently asked questions
What is the difference between ISO 37001 and ISO 37301?
ISO 37001 is specifically an anti-bribery management system — it targets one risk in depth. ISO 37301 is a general compliance management system covering an organization’s full range of compliance obligations, of which bribery is one. Organizations with broad regulatory exposure usually want 37301; those addressing a specific bribery risk or contractual requirement often start with 37001.
Can an organization be certified against ISO 31000?
No. ISO 31000 is a guidance standard for risk management, not a requirements standard, so organizations are not certified against it. Individuals can still hold a PECB personal certification demonstrating their competence in applying it — which is what these courses lead to.
Which course suits someone new to risk management?
The Foundation level introduces risk management principles and terminology without assuming prior experience. Risk Manager and Lead Risk Manager build on that toward designing and leading a risk management programme.
What does ISO/IEC 38500 cover?
ISO/IEC 38500 is the standard for corporate governance of information technology. It addresses how boards and executives direct and oversee IT — accountability, strategy, acquisition, performance, conformance and human behaviour — rather than how IT is run day to day.
Are these credentials recognized internationally?
Yes. PECB is an accredited certification body and its personal certifications are recognized worldwide. Courses in this category are delivered in English and, for several standards, in additional languages.