CertClue
Courses · Security
GRC Analyst / Junior IT Auditor

GRC / IT Audit (Governance, Risk, Compliance)

Learn to do the GRC and IT audit job: map controls, run a walkthrough, rate a risk, sample and test evidence, and write a finding a busy executive can act on.
5 hrs taught · 5 to 9 hrs applied 7 modules 28 lessons 5 portfolio artifacts Completion certificate Updated August 2026
Created by the CertClue team
What you'll build

Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.

  • Evidence request listA tracked list of every piece of evidence requested for the engagement: what, from whom, when, and whether it was sufficient once reviewed.
  • Control mapping matrixOne row per control in scope: objective, activity, type, owner, frequency, evidence source and testing approach.
  • Risk register entryA single risk, rated for likelihood and impact with the reasoning behind each rating, existing controls, and a residual rating and treatment plan.
  • Audit finding memoCondition, criteria, cause, effect and a specific recommendation, written so a busy executive can act on it in one read.
  • Remediation trackerEvery agreed fix, followed to independently validated closure rather than a self reported status update.

What you'll learn

Fundamentals, kept short
The role decoded
A day in the role
The recurring calendar
Live simulation · a worked audit week
Artifacts · what you leave the week with
Handoff

Course content · 7 modules, 28 lessons

Sign up to unlock every lesson - the titles below show exactly what is inside.

The model underneath every GRC and IT audit job: what a control is, who is checking what and why, what risk actually means as arithmetic, what counts as evidence, and the lifecycle an audit moves through. Enough theory to function, not the course.

What GRC and IT audit actually are
What a control actually is
The three lines model
Risk: likelihood times impact, and why that is a starting point
Evidence and sampling: what "sufficient" actually means
The audit lifecycle, and what frameworks are actually for

Requirements

  • No prior experience in this field is required to start.
  • A computer with a reliable internet connection.
  • Comfortable using a web browser - no software to install.

Description

Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for grc analyst / junior it auditor.

Who this course is for

Anyone aiming to become a grc analyst / junior it auditor, including career changers with no background in it yet. This is the entry rung of a realistic ladder:

entry
GRC Analyst

Tracks controls against a framework, gathers evidence for audits, and flags gaps to the team.

Control trackingEvidence gatheringGap analysis
mid
IT Auditor

Runs full control testing cycles, writes audit findings, and works directly with process owners on remediation.

Control testingAudit reportingRemediation tracking
senior
Senior GRC / Audit Lead

Owns the audit program across the org, and advises leadership on risk posture.

Program ownershipRisk advisoryLeadership reporting

Where it leads

This course prepares you for the ISACA CISA role or credential path. Named for preparation only - no partnership or endorsement is implied.

Reviews

No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.

Sign in to leave a review.

Students also explore