Certified IT Governance Professional
CITGP® can also strengthen governance competency for professionals working in cybersecurity, cloud, data, AI, information systems, project management, procurement, finance, and internal audit.
- Credential
- Certified IT Governance Professional
- Certification Designation
- CITGP®
- Certification Level
- Professional
- Certification Body
- International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
- Program Category
- IT Governance, Technology Risk, Compliance & Enterprise Technology Management
- Delivery Format
- Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
- Recommended Training Duration
- 40–60 Hours
- Certification Examination
- Proctored, competency-based examination with multiple-choice and scenario-based questions
- Alternative Assessment Pathway
- Applied IT Governance Capstone for eligible candidates in approved instructor-led pathways
- Credential Renewal Cycle
- 3 Years
Align. Govern. Control. Measure. Assure. Lead.
What You Will Learn
Master the core areas of it governance.
Policies, Standards & Controls
IT Risk Identification & Assessment
Compliance & Regulatory Requirements
Control Testing, Audit & Assurance
IT Service & Process Governance
Data Governance & Information Management
Governance Reporting & Documentation
Become an IT Governance professional the market trusts.
Certification Designation: CITGP®
Certification Level: Professional
Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category: IT Governance, Technology Risk, Compliance & Enterprise Technology Management
Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Professional level — Three-year certification cycle with continuing professional education
Recommended Training Duration: 40–60 Hours
Certification Examination: Proctored, competency-based examination with multiple-choice and scenario-based questions
Alternative Assessment Pathway: Applied IT Governance Capstone for eligible candidates in approved instructor-led pathways
Credential Renewal Cycle: 3 Years
Who Should Earn CITGP®?
CITGP® is designed for professionals and aspiring professionals such as:
CITGP® can also strengthen governance competency for professionals working in cybersecurity, cloud, data, AI, information systems, project management, procurement, finance, and internal audit.
- IT Governance Analyst
- IT Risk Analyst
- Technology Risk Analyst
- Governance, Risk and Compliance Analyst
- IT Compliance Analyst
- IT Controls Analyst
- Internal Controls Professional
- IT Auditor
- Technology Auditor
- Cybersecurity Governance Analyst
- Information Security Governance Analyst
- IT Service Management Professional
- IT Project Governance Analyst
- Technology Portfolio Analyst
- Vendor Risk Analyst
- Third-Party Risk Analyst
- Privacy and Compliance Professional
- IT Business Analyst
- IT Operations Analyst
- Technology Consultant
- Information Systems Professional
CITGP® Body of Knowledge — Eight Modules
Module 1 — IT Governance Foundations and Accountability
1.1 Governance, Management, and Enterprise Oversight
1.2 Stakeholders, Responsibilities, and Accountability
1.3 Governance Structures and Decision Rights
1.4 Policies, Standards, Principles, and Authority
1.5 Governance Culture, Ethics, and Professional Responsibility
Module 2 — Strategy Alignment and Technology Value
2.1 Enterprise Strategy and Technology Alignment
2.2 Technology Objectives, Capabilities, and Roadmaps
2.3 Business Cases and Value Propositions
2.4 Benefits Realization and Stakeholder Outcomes
2.5 Strategic Prioritization and Technology Performance
Module 3 — IT Risk, Controls, Compliance, and Assurance
3.1 Technology Risk Identification and Assessment
3.2 Internal Controls and Control Design
3.3 Regulatory, Contractual, and Policy Requirements
3.4 Control Testing, Evidence, Audit, and Assurance
3.5 Findings, Remediation, Exceptions, and Risk Acceptance
Module 4 — Cybersecurity, Privacy, Data, and Resilience Governance
4.1 Cybersecurity Governance and Enterprise Risk
4.2 Privacy, Data Protection, and Information Governance
4.3 Identity, Access, and Information-Control Governance
4.4 Business Continuity, Disaster Recovery, and Resilience
4.5 Incident Governance, Lessons Learned, and Improvement
Module 5 — Investment, Portfolio, Project, and Architecture Governance
5.1 IT Investment and Portfolio Governance
5.2 Business Cases, Prioritization, and Funding Decisions
5.3 Project and Program Governance
5.4 Enterprise Architecture and Technology Standards
5.5 Benefits, Post-Implementation Review, and Value Realization
Module 6 — Service, Vendor, Sourcing, and Third-Party Governance
6.1 IT Service Governance and Service-Level Principles
6.2 Vendor Selection and Due Diligence
6.3 Contracts, SLAs, and Performance Obligations
6.4 Outsourcing, Cloud, and Third-Party Risk
6.5 Provider Monitoring, Dependency, Exit, and Continual Improvement
Module 7 — Performance, Metrics, Monitoring, and Improvement
7.1 Governance KPIs, KRIs, and Outcome Measures
7.2 Risk, Compliance, and Control Dashboards
7.3 Service, Investment, and Benefits Measurement
7.4 Governance Reporting and Stakeholder Communication
7.5 Maturity Assessment and Continual Improvement
Module 8 — AI Governance, Ethics, and Emerging Technology
8.1 AI Governance and Accountability
8.2 Data, Privacy, Ethics, and Responsible Technology Use
8.3 Human Oversight, Transparency, and AI Risk
8.4 Cloud, Automation, IoT, and Emerging Technology Governance
8.5 Innovation Governance and Future Technology Readiness
CITGP® Course Learning Outcomes
Upon successful completion, participants will be able to:
1. Apply IT Governance Principles
Distinguish governance from management and apply roles, decision rights, accountability, policies, and governance structures.
2. Evaluate Strategic Alignment and Technology Value
Connect technology objectives, investments, portfolios, projects, and services with organizational strategy and stakeholder outcomes.
3. Assess Technology Risk, Controls, and Compliance
Evaluate risk, control design, control evidence, policies, compliance requirements, deficiencies, and assurance needs.
4. Apply Cybersecurity, Data, Privacy, and Resilience Governance
Evaluate governance requirements relating to information security, privacy, data, continuity, recovery, and resilience.
5. Support Technology Investment and Portfolio Governance
Evaluate business cases, projects, architecture decisions, investment priorities, benefits, and transformation initiatives.
6. Evaluate Service Providers and Third Parties
Interpret contracts, service levels, sourcing arrangements, third-party dependencies, provider risks, and performance.
7. Measure and Communicate Governance Performance
Interpret KPIs, KRIs, dashboards, audit findings, control results, and governance measures.
8. Evaluate AI and Emerging-Technology Governance
Assess AI, automation, cloud, and emerging technology using appropriate accountability, risk, ethical, and oversight principles.
CITGP® Certification Testing Outcomes — Skills & Competencies Tested
CITGP® evaluates the candidate's ability to apply IT governance knowledge and judgment to real-world organizational scenarios.
Governance Foundations
Interpret governance roles, responsibilities, structures, accountability, policies, and decision authority.
Strategy and Value
Evaluate alignment between enterprise strategy, technology objectives, investments, and expected benefits.
Risk and Controls
Identify technology risks, evaluate controls, interpret deficiencies, and recommend appropriate responses.
Compliance and Assurance
Interpret regulatory, policy, audit, evidence, control-testing, and assurance situations.
Cybersecurity and Resilience
Evaluate cybersecurity governance, privacy, data, continuity, recovery, and resilience requirements.
Investment and Portfolio Governance
Analyze business cases, projects, technology investments, architecture decisions, priorities, and benefit realization.
Vendor and Service Governance
Evaluate sourcing, contracts, SLAs, provider performance, outsourcing, and third-party risk.
AI and Emerging Governance
Evaluate AI accountability, automation, data use, human oversight, ethical concerns, and emerging technology risk.
CITGP® Competency Standard
Understand → Assess → Prioritize → Apply → Monitor → Report → Assure → Improve
CITGP®–IBACTP® IT Governance Competency Model
The CITGP® competency model consists of eight integrated professional dimensions.
1. IT Governance Foundations, Principles, and Accountability
Understand governance concepts, the distinction between governance and management, stakeholder expectations, roles, decision rights, authority, accountability, policies, and governance structures.
Competency Objective
Understand who should make technology decisions, how accountability should be established, and how governance supports enterprise objectives.
2. Strategy Alignment and Technology Value
Evaluate how technology capabilities, investments, portfolios, and priorities support enterprise strategy and stakeholder needs.
Relevant areas include:
- Strategic alignment
- Technology objectives
- Business cases
- Benefits
- Value realization
- Portfolio priorities
- Stakeholder needs
- Technology roadmaps
Competency Objective
Connect technology activities and investments to measurable organizational outcomes.
3. IT Risk, Controls, Compliance, and Assurance
Identify and evaluate technology risk, control objectives, policy requirements, regulatory considerations, control evidence, compliance, and assurance activities.
Competency Objective
Support responsible technology decisions by understanding risk, controls, obligations, and assurance requirements.
4. Cybersecurity, Privacy, Data, and Resilience Governance
Apply governance principles to cybersecurity, information protection, privacy, data, continuity, disaster recovery, and resilience.
Competency Objective
Connect information and cybersecurity risks with organizational governance and business resilience.
5. Investment, Portfolio, Project, and Architecture Governance
Evaluate technology investments, business cases, projects, programs, portfolios, architecture decisions, and change initiatives.
Competency Objective
Support disciplined technology investment and transformation decisions.
6. Service, Vendor, and Third-Party Governance
Evaluate IT services, sourcing, vendors, outsourcing, cloud providers, service levels, contracts, dependencies, third-party risk, and provider performance.
Competency Objective
Support effective governance of internally and externally delivered technology services.
7. Performance, Metrics, Monitoring, and Continual Improvement
Interpret KPIs, KRIs, service levels, benefits measures, risk indicators, audit findings, dashboards, and governance-performance information.
Competency Objective
Translate governance data into meaningful information for oversight and improvement.
8. AI Governance, Ethics, and Emerging Technology
Evaluate governance implications of AI, automation, cloud, digital platforms, IoT, data-driven systems, and other emerging technologies.
Competency Objective
Apply governance principles to emerging technologies while maintaining accountability, human oversight, ethics, and risk awareness.
What Is CITGP®?
The Certified IT Governance Professional (CITGP®) validates professional competency in understanding, applying, assessing, monitoring, and improving governance practices relating to enterprise information and technology.
CITGP® develops a broad governance perspective that connects:
Strategy + Technology + Risk + Controls + Investment + Performance + Assurance
It prepares professionals to evaluate not only whether a technology works, but whether it is:
- Properly governed
- Aligned with strategy
- Appropriately controlled
- Within acceptable risk
- Performing as expected
- Delivering value
- Supported by reliable evidence
What Does CITGP® Cover?
IT Governance Principles
Candidates develop understanding of:
- Governance concepts
- Enterprise governance
- Technology governance
- Governance versus management
- Stakeholder needs
- Accountability
- Oversight
- Decision authority
- Governance objectives
- Professional responsibilities
Recommended Prerequisites and Eligibility
CITGP® is positioned at the professional level.
Candidates benefit from familiarity with:
Advanced governance experience is not required to begin the training pathway.
- Information technology
- Information systems
- IT management
- Risk management
- Cybersecurity
- Business processes
- Policies and controls
- Compliance
- Project management
- Service management
- Audit concepts
- Organizational governance
Policies, Standards, and Principles
Candidates learn how organizations establish expectations through:
CITGP® emphasizes understanding the relationship between these documents and practical technology governance.
- Policies
- Standards
- Procedures
- Guidelines
- Architecture principles
- Control requirements
- Security requirements
- Exceptions
Certification Overview
Align Technology. Strengthen Controls. Measure Performance. Support Better Decisions.
The Certified IT Governance Professional (CITGP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency in applying governance principles to enterprise information and technology.
CITGP® prepares professionals to understand how organizations make technology decisions, assign accountability, manage risk, establish controls, monitor performance, govern investment, oversee third parties, and ensure that information and technology support enterprise objectives responsibly.
The certification is designed for professionals who contribute to governance by analyzing information, assessing risk, evaluating controls, monitoring performance, supporting audits and assurance activities, documenting decisions, and communicating governance information to stakeholders.
CITGP® addresses the reality that technology governance now extends far beyond traditional IT oversight. Modern governance must consider cloud, cybersecurity, data, privacy, artificial intelligence, digital transformation, third-party services, continuity, resilience, and enterprise risk.
The certification therefore integrates:
IT Governance + Strategy Alignment + Risk + Controls + Compliance + Investment + Performance + Service Management + Cybersecurity Governance + Data Governance + Vendors + AI Governance + Assurance
CITGP® Professional Objective
Understand Governance Requirements → Assess Technology Decisions → Apply Controls → Monitor Performance → Report Risk → Support Assurance → Improve Governance
Why CITGP®?
Technology Decisions Are Enterprise Decisions
Technology decisions increasingly affect every major part of an organization.
A cloud migration may influence:
An artificial-intelligence implementation may affect:
A cybersecurity investment may affect:
An outsourcing decision may affect:
Technology decisions are therefore rarely “IT-only” decisions.
They are increasingly:
- Technology cost
- Cybersecurity exposure
- Data residency
- Privacy
- Regulatory obligations
- Vendor dependency
- Business continuity
- Service availability
- Architecture
- Long-term technology strategy
- Business processes
- Sensitive information
- Intellectual property
- Automated decisions
- Workforce practices
- Ethics
- Accountability
- Security
- Privacy
- Regulatory compliance
- Enterprise risk
- Regulatory exposure
- Customer confidence
- Service availability
- Incident-response capability
- Recovery
- Business resilience
- Cost
- Service quality
- Data access
- Security
- Concentration risk
- Contractual obligations
- Business continuity
- Organizational capability
Business Decisions + Risk Decisions + Investment Decisions + Governance Decisions
CITGP® prepares professionals to connect:
Technology → Risk → Control → Performance → Enterprise Value
Governance Helps Organizations Ask Better Questions
Technology governance does not exist to prevent organizations from innovating.
Its purpose is to ensure that important technology decisions are made with appropriate:
A governance professional may therefore ask:
CITGP® develops competency in answering these questions.
- Direction
- Accountability
- Evidence
- Risk awareness
- Controls
- Oversight
- Performance measurement
- Assurance
- Why are we making this technology investment?
- Which business objective does it support?
- Who owns the decision?
- Who owns the risk?
- What controls are required?
- What evidence demonstrates compliance?
- What could go wrong?
- Are responsibilities clear?
- How will performance be measured?
- Who should receive the results?
- What should happen if performance is unacceptable?
- Is the expected value being realized?
IT Governance Is More Than IT Management
IT governance and IT management are closely connected, but they serve different purposes.
- IT Management Asks:
- IT Governance Asks:
“How should technology services and resources be planned, built, operated, supported, and improved?”
Management focuses on execution.
Examples include:
- Implementing systems
- Operating infrastructure
- Managing projects
- Delivering IT services
- Supporting users
- Resolving incidents
- Managing vendors
- Maintaining applications
“Who should make technology decisions, what outcomes should be achieved, what risks are acceptable, how should performance be monitored, and how should accountability be demonstrated?”
Governance focuses on direction, oversight, accountability, and evaluation.
Examples include:
CITGP® develops professionals who understand how governance and management work together without confusing their respective roles.
- Who approves major investments?
- Which risks require executive acceptance?
- What standards must be followed?
- Who is accountable for cybersecurity?
- What evidence demonstrates control effectiveness?
- Which KPIs should leadership monitor?
- How should benefits be measured?
- When should a governance issue be escalated?
Governance Connects Strategy and Execution
A strong governance environment creates a continuous connection between enterprise direction and technology execution.
Enterprise Strategy
- What does the organization want to achieve?
- Technology Strategy
- What technology capabilities are required to support those objectives?
- Governance
- Who decides, what principles apply, what controls are required, and what risks are acceptable?
- Management
- How are technology capabilities implemented, operated, and supported?
- Measurement
- Are the expected outcomes actually being achieved?
- Assurance
- Can leadership trust the controls, evidence, reports, and results?
- Improvement
What should change based on performance, risk, audit, incidents, or emerging technology?
CITGP® prepares professionals to contribute throughout this lifecycle.
IT Governance Creates Accountability
One of the most important functions of governance is ensuring that technology decisions have clear ownership.
Weak governance often produces questions such as:
CITGP® develops professionals who understand how governance structures reduce this ambiguity.
The progression becomes:
Authority → Responsibility → Accountability → Evidence → Oversight
- Who approved this system?
- Who owns this risk?
- Who authorized this exception?
- Who is accountable for the vendor?
- Who monitors performance?
- Who confirms the control works?
- Who reports significant issues?
- Who decides whether remediation is sufficient?
IT Governance Connects Technology to Enterprise Risk
A technical weakness matters because of what it could mean for the organization.
For example:
Technical Condition
A critical application runs on unsupported infrastructure.
↓
Technology Risk
The environment may be vulnerable to failure or compromise.
↓
Business Exposure
A critical business service may become unavailable.
↓
Governance Question
Who owns the risk, what remediation is required, and is temporary acceptance appropriate?
CITGP® develops the ability to connect technical conditions with broader governance and enterprise-risk decisions.
Controls Are Not the Same as Governance
Controls are important, but governance is broader than control implementation.
A control may require:
Governance determines:
CITGP® prepares professionals to understand this broader context.
- MFA
- Encryption
- Backup
- Approval
- Logging
- Segregation of duties
- Access review
- Why the control is required
- Which systems it applies to
- Who owns it
- Who evaluates its effectiveness
- What happens when it fails
- Who can approve an exception
- How results are reported
Performance Is Part of Governance
Technology governance cannot focus only on risk and compliance.
Organizations also need to know whether technology is producing expected value.
Governance professionals may monitor:
Effective governance therefore asks two questions:
- Service availability
- Technology costs
- Investment performance
- Project outcomes
- Security exposure
- Vendor performance
- Customer satisfaction
- Benefits realization
- Recovery capability
- Technology maturity
- Is technology producing the outcomes the organization expected?
Are we managing technology responsibly?
and:
Assurance Builds Confidence
Senior leadership cannot personally inspect every system, project, contract, control, or technology decision.
They depend on trustworthy information.
Assurance activities help determine whether:
CITGP® prepares professionals to support these assurance activities through evidence, analysis, documentation, testing support, remediation tracking, and reporting.
- Controls are designed appropriately
- Controls operate effectively
- Policies are followed
- Risks are accurately reported
- Compliance obligations are addressed
- Governance processes are functioning
- Management information can be trusted
Governance Structures and Decision Rights
CITGP® addresses:
The central question is:
- Governance committees
- Steering committees
- Roles
- Responsibilities
- Decision authority
- Escalation
- Delegation
- Accountability
- Reporting relationships
- Governance charters
- Who has authority to decide—and who is accountable for the result?
Technology Strategy Alignment
Technology investments should support organizational objectives.
CITGP® addresses:
The progression becomes:
Enterprise Objective → Technology Capability → Investment → Outcome
- Enterprise strategy
- Technology strategy
- Strategic alignment
- Technology roadmaps
- Capability planning
- Business priorities
- Stakeholder requirements
- Performance outcomes
IT Risk Management
Candidates develop competency in:
The objective is to understand how technology risk contributes to enterprise risk.
- Risk identification
- Risk analysis
- Likelihood
- Impact
- Inherent risk
- Controls
- Residual risk
- Risk treatment
- Risk acceptance
- Escalation
- Monitoring
Internal Controls
CITGP® addresses:
Professionals learn that a documented control is not automatically an effective control.
The question becomes:
- Control objectives
- Preventive controls
- Detective controls
- Corrective controls
- Manual controls
- Automated controls
- Control ownership
- Control evidence
- Control testing
- Deficiencies
- “Can we demonstrate that the control operates as intended?”
Compliance
Technology governance frequently supports compliance with:
CITGP® develops the ability to distinguish between:
- Laws
- Regulations
- Contracts
- Internal policies
- Industry requirements
- Customer commitments
- Privacy obligations
- Security requirements
- Requirement → Control → Evidence → Compliance Determination
Technology Investment Governance
CITGP® addresses how organizations evaluate technology investments.
Relevant areas include:
The goal is not simply:
- Business cases
- Cost
- Benefits
- Risk
- Strategic alignment
- Alternatives
- Funding
- Prioritization
- Expected outcomes
- Benefits realization
“Can we afford this technology?”
but:
“Does the investment produce sufficient strategic and operational value for the cost and risk?”
Portfolio Governance
Organizations may have hundreds of technology initiatives competing for resources.
CITGP® introduces:
- Portfolio prioritization
- Strategic alignment
- Resource constraints
- Risk
- Dependencies
- Benefits
- Project status
- Portfolio performance
- Investment balance
- Governance oversight
Project and Program Governance
CITGP® addresses governance of:
Governance helps determine whether projects remain aligned with their intended business purpose.
- Scope
- Business cases
- Sponsorship
- Decision authority
- Milestones
- Risk
- Issues
- Changes
- Benefits
- Post-implementation review
Architecture Governance
Architecture decisions affect:
CITGP® addresses:
- Cost
- Integration
- Security
- Scalability
- Technical debt
- Supportability
- Resilience
- Architecture standards
- Design principles
- Technology standards
- Exceptions
- Architecture review
- Legacy technology
- Modernization
- Technology lifecycle
Cybersecurity Governance
Cybersecurity is a major component of enterprise technology governance.
CITGP® addresses:
The governance question is not simply:
- Security accountability
- Security policies
- Risk
- Security controls
- Incident oversight
- Vulnerability management
- Identity
- Third-party security
- Cyber resilience
- Security metrics
“Are security tools installed?”
It is:
“Is cybersecurity risk being governed appropriately and reported to the right decision-makers?”
Data Governance
Data governance addresses how information is:
Relevant concepts include:
-
01
Owned
Classified
-
02
Used
Protected
-
03
Shared
Retained
-
04
Deleted
Monitored
-
05
Data ownership
Data stewardship
-
06
Data quality
Classification
-
07
Access
Retention
-
08
Lifecycle
Accountability
Privacy Governance
CITGP® develops awareness of:
- Personal information
- Data collection
- Data minimization
- Appropriate use
- Consent concepts
- Retention
- Access
- Disclosure
- Privacy risk
- Governance responsibilities
Vendor and Third-Party Governance
Organizations increasingly depend on:
CITGP® addresses:
The governance progression becomes:
Select → Contract → Monitor → Assure → Improve or Exit
- Cloud providers
- SaaS companies
- Managed service providers
- Technology vendors
- Outsourcing partners
- Consultants
- Software suppliers
- Due diligence
- Contracts
- Service levels
- Security
- Privacy
- Risk
- Performance
- Monitoring
- Dependency
- Exit planning
IT Service Governance
Technology governance also applies to ongoing service delivery.
Candidates develop competency involving:
- Service ownership
- Service levels
- Availability
- Capacity
- Incidents
- Problems
- Changes
- User experience
- Service performance
- Continual improvement
Performance Measurement
CITGP® addresses:
KPIs
Measures of performance.
KRIs
Measures of risk.
KCIs
Measures indicating whether controls are operating as expected.
Professionals learn to distinguish between:
Activity Metrics
and:
Outcome Metrics
For example:
“10,000 tickets closed” is an activity measure.
“Critical-service availability improved from 98.5% to 99.9%” is closer to an outcome measure.
Audit and Assurance
CITGP® introduces professionals to:
CITGP® is not solely an IT audit credential, but assurance is an important governance capability.
- Audit objectives
- Audit evidence
- Control testing
- Findings
- Management responses
- Remediation
- Issue tracking
- Independent assurance
- Follow-up
- Closure
Business Continuity and Resilience Governance
Governance professionals need to understand whether critical technology can withstand and recover from disruption.
CITGP® addresses:
-
01
Business impact
Critical services
-
02
Continuity
Disaster recovery
-
03
Backup
Recovery objectives
-
04
Testing
Dependencies
-
05
Incident governance
Resilience improvement
AI Governance
Artificial intelligence creates new governance questions.
Organizations must consider:
CITGP® introduces professionals to responsible AI-governance principles across the AI lifecycle.
- Who owns AI systems?
- Which uses are permitted?
- What data is used?
- Are outputs reliable?
- Can decisions be explained?
- Is human oversight required?
- Are privacy requirements satisfied?
- Are security risks addressed?
- How are models monitored?
- Who is accountable when AI produces an inappropriate outcome?
Emerging Technology Governance
CITGP® applies governance concepts to technologies such as:
The objective is not to predict every technology.
It is to develop governance principles that remain useful as technologies evolve.
- Cloud
- Automation
- IoT
- Edge computing
- Digital platforms
- Blockchain
- Generative AI
- Autonomous technologies
Ethics and Professional Responsibility
Governance professionals frequently work with sensitive information involving:
CITGP® therefore emphasizes:
- Risk
- Audits
- Controls
- Compliance
- Incidents
- Executive decisions
- Employee activity
- Vendors
- Security weaknesses
- Integrity
- Confidentiality
- Objectivity
- Evidence-based reporting
- Professional judgment
- Conflict-of-interest awareness
- Responsible technology use
Continual Governance Improvement
Governance models must evolve as:
CITGP® therefore incorporates a continual improvement cycle:
Assess → Identify Gaps → Prioritize → Improve → Monitor → Reassess
- Business strategy changes
- Technology changes
- New threats emerge
- Regulations evolve
- Vendors change
- Incidents occur
- AI adoption expands
CITGP® Governance Lifecycle
CITGP® connects governance activities into an integrated professional lifecycle:
Enterprise Objective → Technology Decision → Risk Assessment → Control → Performance → Assurance → Reporting → Improvement
This helps professionals understand governance as a continuous decision and oversight process rather than a compliance exercise performed once per year.
What Makes CITGP® Different?
CITGP® develops competency across several important professional transitions.
From Technology Activity to Business Outcome
“The IT team completed the project.”
becomes:
“Did the project produce the intended business value?”
From Risk Identification to Risk Governance
“We found the risk.”
becomes:
“Who owns it, what is the treatment, and who can accept the residual exposure?”
From Control Documentation to Control Effectiveness
“The policy says we perform access reviews.”
becomes:
“Can we demonstrate that access reviews occur effectively and produce appropriate remediation?”
From Vendor Management to Vendor Governance
“The provider signed the contract.”
becomes:
“Is the provider meeting security, performance, resilience, and contractual expectations?”
From Metrics to Decision Support
“Here are 50 dashboard metrics.”
becomes:
“Here are the measures leadership needs to make a decision.”
From Compliance to Responsible Governance
“Are we compliant?”
becomes:
“Are we making responsible, controlled, risk-informed technology decisions that support enterprise objectives?”
CITGP® Professional Value Proposition
CITGP® integrates:
Governance + Strategy + Risk + Controls + Compliance + Investment + Cybersecurity + Data + Vendors + Performance + Assurance + AI
Its central professional objective is:
Understand the Requirement → Evaluate the Decision → Assess the Risk → Apply the Control → Measure the Outcome → Support Assurance → Improve Governance
CITGP® Professional Identity
A CITGP® professional should be capable of asking:
That is the professional capability CITGP® is designed to develop and validate.
CITGP® — Align Technology. Govern Risk. Strengthen Accountability. Support Better Enterprise Decisions.
- What business objective does this technology support?
- Who owns the decision?
- Who owns the risk?
- What governance structure applies?
- What controls are required?
- Is the control effective?
- What evidence supports the conclusion?
- Is the investment delivering value?
- Are vendors meeting expectations?
- Are cybersecurity responsibilities clear?
- Is data being governed appropriately?
- Are critical services resilient?
- Which KPI or KRI actually matters?
- What should leadership know?
- How should this issue be escalated?
- Is AI being used responsibly?
- What should be improved?
CITGP® Professional Progression
Understand → Assess → Apply → Monitor → Measure → Report → Assure → Improve
Tools, Technologies, and Governance Applications
CITGP® remains vendor-neutral while addressing categories of tools professionals may encounter.
Governance, Risk, and Compliance
GRC Platforms • Risk Registers • Control Libraries • Compliance Systems • Policy-Management Platforms
Service and Asset Management
ITSM • CMDB • Asset Management • Service Catalogs • SLA Platforms
Portfolio and Investment
Project Portfolio Management • Business Case Tools • Financial Dashboards • Benefits Tracking
Audit and Assurance
Audit Management • Evidence Repositories • Control Testing • Issue Tracking
Cybersecurity Governance
Security Dashboards • Vulnerability Reports • SIEM Governance Metrics • Identity Reports • Risk Platforms
Data and Privacy
Data Inventories • Classification Tools • Privacy Platforms • Information-Governance Systems
AI Governance
AI Inventories • Model Registers • Risk Assessments • AI Control Monitoring • Responsible-AI Documentation
The focus is:
Governance Requirement → Evidence → Analysis → Decision → Monitoring → Improvement
rather than proficiency with one commercial platform.
Employment Outlook — CITGP® & CITGM®
Growing Demand for Professionals Who Can Connect Technology, Risk, Governance, Compliance, and Enterprise Value
Technology governance is becoming increasingly important as organizations expand their reliance on cloud computing, cybersecurity, artificial intelligence, data, digital platforms, outsourcing, automation, and third-party technology ecosystems.
There is no single U.S. Bureau of Labor Statistics occupational category called “IT Governance Professional” or “IT Governance Manager.” IT-governance responsibilities are distributed across several occupations, including computer and information systems managers, information security analysts, computer systems analysts, management analysts, compliance officers, auditors, technology-risk professionals, and governance, risk, and compliance specialists.
For that reason, the employment outlook for CITGP® and CITGM® is best understood by examining these closely aligned occupational groups.
CITGP® Employment Outlook
- Certified IT Governance Professional (CITGP®)
Govern Risk. Strengthen Controls. Support Better Technology Decisions.
CITGP® competencies align with a growing range of professional roles involving:
IT Governance • Technology Risk • GRC • Cybersecurity Governance • Compliance • IT Controls • Assurance • IT Audit • Vendor Risk • Information Systems • Technology Consulting
The broader U.S. labor market supporting these competencies shows strong demand, particularly where governance intersects with cybersecurity and technology transformation.
U.S. Occupational Outlook — CITGP®-Aligned Careers
*The accountants-and-auditors category is broader than IT audit but provides a relevant benchmark for professionals whose governance careers involve technology audit and assurance. (Bureau of Labor Statistics)
For comparison, BLS projects total U.S. employment across all occupations to grow approximately 3.1% from 2024 to 2034. Computer and mathematical occupations overall are projected to grow 10.1%, while management occupations are projected to grow 6.1%. (Bureau of Labor Statistics)
| Relevant Occupation | 2024 Employment | 2034 Projected Employment | Growth | New Jobs | Annual Openings | 2024 Median Salary |
|---|---|---|---|---|---|---|
| Information Security Analysts | 182,800 | 234,900 | 29% | 52,100 | 16,000 | $124,910 |
| Computer Systems Analysts | 521,100 | 566,500 | 9% | 45,500 | 34,200 | $103,790 |
| Management Analysts | 1,075,100 | 1,169,700 | 9% | 94,500 | 98,100 | $101,190 |
| Compliance Officers | 418,000 | 430,300 | 3% | 12,300 | 33,300 | $78,420 |
| Accountants & Auditors* | 1,579,800 | 1,652,600 | 5% | 72,800 | 124,200 | $81,680 |
Information Security and Cyber Governance Outlook
One of the strongest employment indicators relevant to CITGP® is cybersecurity.
BLS projects employment for Information Security Analysts to increase from approximately 182,800 positions in 2024 to 234,900 in 2034.
That represents:
29% Projected Growth
and approximately:
52,100 Additional Jobs
with about:
16,000 Openings Per Year
on average over the decade. (Bureau of Labor Statistics)
This is particularly important for CITGP® because modern cybersecurity increasingly requires governance of:
BLS specifically notes that growth is being supported by increasing cyberattacks, expanding cybersecurity requirements, e-commerce, and greater adoption of artificial intelligence. (Bureau of Labor Statistics)
- Cyber risk
- Security controls
- Policy
- Identity
- Third parties
- Cloud security
- Vulnerability exposure
- Incident oversight
- Compliance
- Executive reporting
Computer Systems Analysis Outlook
Information systems and technology analysis are another important foundation for IT-governance careers.
BLS projects Computer Systems Analysts to grow from:
521,100 jobs in 2024
to:
566,500 jobs by 2034.
That represents:
9% Growth
approximately:
45,500 Additional Positions
and:
34,200 Openings Per Year
on average. (Bureau of Labor Statistics)
BLS notes that continued organizational reliance on IT—including artificial intelligence—is expected to support demand for systems analysts. This aligns with CITGP® responsibilities involving technology evaluation, business alignment, architecture governance, investment analysis, and control assessment. (Bureau of Labor Statistics)
Management and Technology Consulting Outlook
IT-governance professionals may also work in technology consulting, risk advisory, internal consulting, transformation, and governance-improvement roles.
BLS projects employment for Management Analysts to grow by approximately:
9% from 2024–2034
from approximately 1.075 million to 1.170 million positions.
Approximately:
98,100 openings per year
are projected over the decade. (Bureau of Labor Statistics)
BLS expects demand for consulting services to continue as organizations seek to improve efficiency and control costs, with specialized consulting—including information-technology consulting—contributing to demand. (Bureau of Labor Statistics)
Compliance Career Outlook
Governance and compliance frequently overlap.
BLS projects approximately:
33,300 Compliance Officer Openings Annually
through 2034.
Employment is projected to grow approximately 3%, from 418,000 positions in 2024 to 430,300 by 2034. (Bureau of Labor Statistics)
BLS identifies ongoing regulatory complexity as a key driver of demand, with organizations requiring professionals who can interpret requirements and help reduce the costs and risks of noncompliance. (Bureau of Labor Statistics)
For CITGP® professionals, this aligns with competencies involving:
Policy • Technology Controls • Regulatory Requirements • Evidence • Assurance • Risk • Remediation
IT Audit and Assurance Outlook
IT governance also intersects with audit and assurance.
Although BLS does not maintain a separate national category for IT Auditors, its broader accountants-and-auditors occupation provides an indication of assurance-related employment.
Employment is projected to increase from:
1.58 million positions in 2024
to approximately:
1.65 million by 2034,
representing:
5% Growth
and approximately:
124,200 openings annually. (Bureau of Labor Statistics)
Technology is expected to automate some routine audit tasks while increasing the importance of analytical and advisory activities. This may increase the relative value of professionals capable of understanding automated controls, cloud environments, cybersecurity evidence, data, AI, and technology risk. (Bureau of Labor Statistics)
CITGP® Salary Outlook
Governance, Risk & Compliance Analyst — Current U.S. Benchmark
Because the BLS does not publish a separate occupation for “IT Governance Analyst,” current market compensation data provide an additional benchmark.
As of July 1, 2026, Salary.com reported an average U.S. salary for a Governance, Risk and Compliance Analyst of approximately:
$100,913 Per Year
or approximately:
$49 Per Hour. (Salary)
The reported salary distribution was:
Percentile
Annual Salary
10th Percentile
$88,908
25th Percentile
$94,629
Average
$100,913
75th Percentile
$108,783
90th Percentile
$115,948
(Salary)
GRC Analyst Salary by Geography
Salary.com's July 2026 estimates show meaningful geographic differences for Governance, Risk and Compliance Analysts.
Examples include:
These are market estimates rather than BLS wage statistics. (Salary)
| Location | Estimated Average Salary |
|---|---|
| District of Columbia | $111,731 |
| California | $111,307 |
| Massachusetts | $109,824 |
| Washington | $109,420 |
| New Jersey | $109,380 |
| New York | $107,281 |
| Maryland | $104,051 |
| Illinois | $102,861 |
| Texas | $98,431 |
| North Carolina | $95,898 |
| South Carolina | $94,555 |
Official 2025 BLS Salary Benchmarks — CITGP®-Aligned Roles
The latest BLS Occupational Employment and Wage Statistics released for May 2025 provide useful national mean-wage benchmarks.
(Bureau of Labor Statistics)
These occupational categories are broader than IT governance specifically, but together they illustrate the compensation environment surrounding governance, technology risk, cybersecurity, systems analysis, audit, and compliance.
| Occupation | Employment | Mean Hourly Wage | Mean Annual Wage |
|---|---|---|---|
| Information Security Analysts | 190,650 | $63.71 | $132,510 |
| Computer Systems Analysts | 519,530 | $55.10 | $114,610 |
| Management Analysts | 898,280 | $54.71 | $113,790 |
| Accountants & Auditors | 1,449,500 | $45.56 | $94,750 |
| Compliance Officers | 417,070 | $42.50 | $88,400 |
Potential Careers for CITGP® Professionals
CITGP® competencies may support professional development toward positions such as:
- IT Governance Analyst
- Technology Governance Analyst
- Governance, Risk and Compliance Analyst
- IT Risk Analyst
- Technology Risk Analyst
- Cybersecurity Governance Analyst
- Information Security Governance Analyst
- IT Controls Analyst
- Technology Controls Analyst
- IT Compliance Analyst
- Technology Compliance Analyst
- IT Audit Analyst
- IT Auditor
- Technology Assurance Analyst
- Third-Party Risk Analyst
- Vendor Risk Analyst
- Cloud Governance Analyst
- Data Governance Analyst
- AI Governance Analyst
- Technology Portfolio Analyst
- IT Service Governance Analyst
- Information Systems Analyst
- Technology Consultant
- Risk Advisory Consultant
High-Value CITGP® Skill Combinations
Governance professionals can become particularly valuable when governance competency is combined with specialized expertise.
IT Governance + Cybersecurity
This combination is supported by the 29% projected growth in employment of information security analysts. (Bureau of Labor Statistics)
IT Governance + Cloud
Organizations increasingly need professionals capable of governing cloud security, cost, architecture, data, third parties, resilience, and shared-responsibility models.
IT Governance + Risk & Compliance
Risk and compliance professionals help translate technical activities into enterprise-control and regulatory requirements.
IT Governance + Data & Privacy
Growing dependence on data creates additional demand for professionals capable of governing data ownership, access, quality, privacy, retention, and use.
IT Governance + AI
AI introduces new governance requirements involving model ownership, human oversight, privacy, data quality, security, explainability, accountability, third-party risk, and monitoring.
CITGP® Employment Outlook Summary
29%
Projected growth for Information Security Analysts, 2024–2034. (Bureau of Labor Statistics)
52,100
Projected additional Information Security Analyst positions. (Bureau of Labor Statistics)
9%
Projected growth for Computer Systems Analysts. (Bureau of Labor Statistics)
34,200
Projected annual Computer Systems Analyst openings. (Bureau of Labor Statistics)
9%
Projected growth for Management Analysts. (Bureau of Labor Statistics)
98,100
Projected annual Management Analyst openings. (Bureau of Labor Statistics)
$100,913
July 2026 market-average salary estimate for U.S. Governance, Risk and Compliance Analysts. (Salary)
$132,510
May 2025 BLS mean annual wage for Information Security Analysts. (Bureau of Labor Statistics)
$114,610
May 2025 BLS mean annual wage for Computer Systems Analysts. (Bureau of Labor Statistics)
Flexible CITGP® Certification Assessment
Option 1 — CITGP® Certification Examination
100 Questions
90 Minutes
Multiple-Choice + Scenario-Based Questions
Closed Book
Secure Online Proctoring or Approved Testing Center
Recommended Passing Score: 70%
Assessment emphasizes:
Governance • Strategy • Risk • Controls • Compliance • Investment • Vendors • Performance • Assurance • AI Governance
Option 2 — Applied IT Governance Capstone
Eligible candidates in an approved instructor-led pathway may demonstrate competency through the CITGP® Applied IT Governance Capstone.
The Capstone may integrate:
Enterprise Requirement → Governance Assessment → Risk & Controls → Investment Decision → Performance Monitoring → Governance Recommendation
- CITGP®
- CITGM®
- From IT Governance Practice to Enterprise Technology Governance Leadership
CITGP® Certification Value Proposition
CITGP® integrates:
Governance + Strategy + Risk + Controls + Compliance + Cybersecurity + Investment + Vendors + Performance + Assurance + AI
Its central professional objective is:
Understand Governance → Evaluate Risk → Apply Controls → Monitor Performance → Support Assurance → Improve Technology Decision-Making
Exam & Certification Details
Everything you need to plan your sitting.
CITGP-100
Exam code for the Professional-level IT Governance credential.
100 questions (maximum)
Multiple choice, completed in 120 minutes.
700 out of 1000
Passing score. Delivered in English.
Recommended experience
A minimum of two years of experience in it governance or a closely related technology discipline.
Where you sit it
IBACTP® approved testing centers and online proctored delivery
Staying certified
Three-year certification cycle with continuing professional education
Four ways to enroll. One credential.
Every route leads to the same CITGP® examination and the same designation.
Your Certification Pathway
Start as a Professional. Advance as a Leader.
Ready to certify as a CITGP®?
Self-Paced Learning
Exam fee only, with complimentary course materials provided — $400 USD.
Virtual Instructor-Led Training
4 days, 2 hours daily online. All course materials + Exam — $1,200 USD.
Bootcamps & Intensives
10 days, 2 hours daily. All course materials + Exam — $1,800 USD.
Corporate Training
Certify a whole team on a schedule that suits your organization. Fees negotiable.
Take the next step in IT Governance
Apply, choose your preparation route and book your examination with an approved provider.