IBACTP® — International Board of AI, Cybersecurity & Technology Professionals
CITGP®

Certified IT Governance Professional

CITGP® can also strengthen governance competency for professionals working in cybersecurity, cloud, data, AI, information systems, project management, procurement, finance, and internal audit.

Credential
Certified IT Governance Professional
Certification Designation
CITGP®
Certification Level
Professional
Certification Body
International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
Program Category
IT Governance, Technology Risk, Compliance & Enterprise Technology Management
Delivery Format
Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning
Recommended Training Duration
40–60 Hours
Certification Examination
Proctored, competency-based examination with multiple-choice and scenario-based questions
Alternative Assessment Pathway
Applied IT Governance Capstone for eligible candidates in approved instructor-led pathways
Credential Renewal Cycle
3 Years
A corporate boardroom set for a meeting
IT Governance
CITGP® Certified IT Governance Professional badge

Align. Govern. Control. Measure. Assure. Lead.

Professional Level For practitioners, specialists, analysts and engineers
Vendor-Neutral Skills and knowledge that apply across platforms and tools
Global Recognition Recognized internationally across industries and regions
Digital Credential Shareable, verifiable credential and certificate

What You Will Learn

Master the core areas of it governance.

IT Governance Foundations & Frameworks

Policies, Standards & Controls

IT Risk Identification & Assessment

Compliance & Regulatory Requirements

Control Testing, Audit & Assurance

IT Service & Process Governance

Data Governance & Information Management

Governance Reporting & Documentation

About the credential

Become an IT Governance professional the market trusts.

Certification Designation: CITGP®

Certification Level: Professional

Certification Body: International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)

Program Category: IT Governance, Technology Risk, Compliance & Enterprise Technology Management

Delivery Format: Instructor-Led, Virtual Instructor-Led, Self-Paced, or Blended Learning

A corporate boardroom set for a meeting

Professional level — Three-year certification cycle with continuing professional education

Recommended Training Duration: 40–60 Hours

Certification Examination: Proctored, competency-based examination with multiple-choice and scenario-based questions

Alternative Assessment Pathway: Applied IT Governance Capstone for eligible candidates in approved instructor-led pathways

Credential Renewal Cycle: 3 Years

A corporate boardroom set for a meeting
CITGP®

Who Should Earn CITGP®?

CITGP® is designed for professionals and aspiring professionals such as:

CITGP® can also strengthen governance competency for professionals working in cybersecurity, cloud, data, AI, information systems, project management, procurement, finance, and internal audit.

  • IT Governance Analyst
  • IT Risk Analyst
  • Technology Risk Analyst
  • Governance, Risk and Compliance Analyst
  • IT Compliance Analyst
  • IT Controls Analyst
  • Internal Controls Professional
  • IT Auditor
  • Technology Auditor
  • Cybersecurity Governance Analyst
  • Information Security Governance Analyst
  • IT Service Management Professional
  • IT Project Governance Analyst
  • Technology Portfolio Analyst
  • Vendor Risk Analyst
  • Third-Party Risk Analyst
  • Privacy and Compliance Professional
  • IT Business Analyst
  • IT Operations Analyst
  • Technology Consultant
  • Information Systems Professional
Curriculum

CITGP® Body of Knowledge — Eight Modules

Learning outcomes

CITGP® Course Learning Outcomes

Upon successful completion, participants will be able to:

1. Apply IT Governance Principles

Distinguish governance from management and apply roles, decision rights, accountability, policies, and governance structures.

2. Evaluate Strategic Alignment and Technology Value

Connect technology objectives, investments, portfolios, projects, and services with organizational strategy and stakeholder outcomes.

3. Assess Technology Risk, Controls, and Compliance

Evaluate risk, control design, control evidence, policies, compliance requirements, deficiencies, and assurance needs.

4. Apply Cybersecurity, Data, Privacy, and Resilience Governance

Evaluate governance requirements relating to information security, privacy, data, continuity, recovery, and resilience.

5. Support Technology Investment and Portfolio Governance

Evaluate business cases, projects, architecture decisions, investment priorities, benefits, and transformation initiatives.

6. Evaluate Service Providers and Third Parties

Interpret contracts, service levels, sourcing arrangements, third-party dependencies, provider risks, and performance.

7. Measure and Communicate Governance Performance

Interpret KPIs, KRIs, dashboards, audit findings, control results, and governance measures.

8. Evaluate AI and Emerging-Technology Governance

Assess AI, automation, cloud, and emerging technology using appropriate accountability, risk, ethical, and oversight principles.

What is assessed

CITGP® Certification Testing Outcomes — Skills & Competencies Tested

CITGP® evaluates the candidate's ability to apply IT governance knowledge and judgment to real-world organizational scenarios.

CITGP®

CITGP®–IBACTP® IT Governance Competency Model

The CITGP® competency model consists of eight integrated professional dimensions.

1. IT Governance Foundations, Principles, and Accountability

Understand governance concepts, the distinction between governance and management, stakeholder expectations, roles, decision rights, authority, accountability, policies, and governance structures.

Competency Objective

Understand who should make technology decisions, how accountability should be established, and how governance supports enterprise objectives.

2. Strategy Alignment and Technology Value

Evaluate how technology capabilities, investments, portfolios, and priorities support enterprise strategy and stakeholder needs.

Relevant areas include:

  • Strategic alignment
  • Technology objectives
  • Business cases
  • Benefits
  • Value realization
  • Portfolio priorities
  • Stakeholder needs
  • Technology roadmaps

Competency Objective

Connect technology activities and investments to measurable organizational outcomes.

3. IT Risk, Controls, Compliance, and Assurance

Identify and evaluate technology risk, control objectives, policy requirements, regulatory considerations, control evidence, compliance, and assurance activities.

Competency Objective

Support responsible technology decisions by understanding risk, controls, obligations, and assurance requirements.

4. Cybersecurity, Privacy, Data, and Resilience Governance

Apply governance principles to cybersecurity, information protection, privacy, data, continuity, disaster recovery, and resilience.

Competency Objective

Connect information and cybersecurity risks with organizational governance and business resilience.

5. Investment, Portfolio, Project, and Architecture Governance

Evaluate technology investments, business cases, projects, programs, portfolios, architecture decisions, and change initiatives.

Competency Objective

Support disciplined technology investment and transformation decisions.

6. Service, Vendor, and Third-Party Governance

Evaluate IT services, sourcing, vendors, outsourcing, cloud providers, service levels, contracts, dependencies, third-party risk, and provider performance.

Competency Objective

Support effective governance of internally and externally delivered technology services.

7. Performance, Metrics, Monitoring, and Continual Improvement

Interpret KPIs, KRIs, service levels, benefits measures, risk indicators, audit findings, dashboards, and governance-performance information.

Competency Objective

Translate governance data into meaningful information for oversight and improvement.

8. AI Governance, Ethics, and Emerging Technology

Evaluate governance implications of AI, automation, cloud, digital platforms, IoT, data-driven systems, and other emerging technologies.

Competency Objective

Apply governance principles to emerging technologies while maintaining accountability, human oversight, ethics, and risk awareness.

What it validates

What Is CITGP®?

The Certified IT Governance Professional (CITGP®) validates professional competency in understanding, applying, assessing, monitoring, and improving governance practices relating to enterprise information and technology.

CITGP® develops a broad governance perspective that connects:

Strategy + Technology + Risk + Controls + Investment + Performance + Assurance

It prepares professionals to evaluate not only whether a technology works, but whether it is:

  • Properly governed
  • Aligned with strategy
  • Appropriately controlled
  • Within acceptable risk
  • Performing as expected
  • Delivering value
  • Supported by reliable evidence
CITGP®

What Does CITGP® Cover?

IT Governance Principles

Candidates develop understanding of:

  • Governance concepts
  • Enterprise governance
  • Technology governance
  • Governance versus management
  • Stakeholder needs
  • Accountability
  • Oversight
  • Decision authority
  • Governance objectives
  • Professional responsibilities
CITGP®

Recommended Prerequisites and Eligibility

CITGP® is positioned at the professional level.

Candidates benefit from familiarity with:

Advanced governance experience is not required to begin the training pathway.

  • Information technology
  • Information systems
  • IT management
  • Risk management
  • Cybersecurity
  • Business processes
  • Policies and controls
  • Compliance
  • Project management
  • Service management
  • Audit concepts
  • Organizational governance
CITGP®

Policies, Standards, and Principles

Candidates learn how organizations establish expectations through:

CITGP® emphasizes understanding the relationship between these documents and practical technology governance.

  • Policies
  • Standards
  • Procedures
  • Guidelines
  • Architecture principles
  • Control requirements
  • Security requirements
  • Exceptions
CITGP®

Certification Overview

Align Technology. Strengthen Controls. Measure Performance. Support Better Decisions.

The Certified IT Governance Professional (CITGP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency in applying governance principles to enterprise information and technology.

CITGP® prepares professionals to understand how organizations make technology decisions, assign accountability, manage risk, establish controls, monitor performance, govern investment, oversee third parties, and ensure that information and technology support enterprise objectives responsibly.

The certification is designed for professionals who contribute to governance by analyzing information, assessing risk, evaluating controls, monitoring performance, supporting audits and assurance activities, documenting decisions, and communicating governance information to stakeholders.

CITGP® addresses the reality that technology governance now extends far beyond traditional IT oversight. Modern governance must consider cloud, cybersecurity, data, privacy, artificial intelligence, digital transformation, third-party services, continuity, resilience, and enterprise risk.

The certification therefore integrates:

IT Governance + Strategy Alignment + Risk + Controls + Compliance + Investment + Performance + Service Management + Cybersecurity Governance + Data Governance + Vendors + AI Governance + Assurance

CITGP® Professional Objective

Understand Governance Requirements → Assess Technology Decisions → Apply Controls → Monitor Performance → Report Risk → Support Assurance → Improve Governance

CITGP®

Why CITGP®?

Technology Decisions Are Enterprise Decisions

Technology decisions increasingly affect every major part of an organization.

A cloud migration may influence:

An artificial-intelligence implementation may affect:

A cybersecurity investment may affect:

An outsourcing decision may affect:

Technology decisions are therefore rarely “IT-only” decisions.

They are increasingly:

  • Technology cost
  • Cybersecurity exposure
  • Data residency
  • Privacy
  • Regulatory obligations
  • Vendor dependency
  • Business continuity
  • Service availability
  • Architecture
  • Long-term technology strategy
  • Business processes
  • Sensitive information
  • Intellectual property
  • Automated decisions
  • Workforce practices
  • Ethics
  • Accountability
  • Security
  • Privacy
  • Regulatory compliance
  • Enterprise risk
  • Regulatory exposure
  • Customer confidence
  • Service availability
  • Incident-response capability
  • Recovery
  • Business resilience
  • Cost
  • Service quality
  • Data access
  • Security
  • Concentration risk
  • Contractual obligations
  • Business continuity
  • Organizational capability

Business Decisions + Risk Decisions + Investment Decisions + Governance Decisions

CITGP® prepares professionals to connect:

Technology → Risk → Control → Performance → Enterprise Value

CITGP®

Governance Helps Organizations Ask Better Questions

Technology governance does not exist to prevent organizations from innovating.

Its purpose is to ensure that important technology decisions are made with appropriate:

A governance professional may therefore ask:

CITGP® develops competency in answering these questions.

  • Direction
  • Accountability
  • Evidence
  • Risk awareness
  • Controls
  • Oversight
  • Performance measurement
  • Assurance
  • Why are we making this technology investment?
  • Which business objective does it support?
  • Who owns the decision?
  • Who owns the risk?
  • What controls are required?
  • What evidence demonstrates compliance?
  • What could go wrong?
  • Are responsibilities clear?
  • How will performance be measured?
  • Who should receive the results?
  • What should happen if performance is unacceptable?
  • Is the expected value being realized?
CITGP®

IT Governance Is More Than IT Management

IT governance and IT management are closely connected, but they serve different purposes.

  • IT Management Asks:
  • IT Governance Asks:

“How should technology services and resources be planned, built, operated, supported, and improved?”

Management focuses on execution.

Examples include:

  • Implementing systems
  • Operating infrastructure
  • Managing projects
  • Delivering IT services
  • Supporting users
  • Resolving incidents
  • Managing vendors
  • Maintaining applications

“Who should make technology decisions, what outcomes should be achieved, what risks are acceptable, how should performance be monitored, and how should accountability be demonstrated?”

Governance focuses on direction, oversight, accountability, and evaluation.

Examples include:

CITGP® develops professionals who understand how governance and management work together without confusing their respective roles.

  • Who approves major investments?
  • Which risks require executive acceptance?
  • What standards must be followed?
  • Who is accountable for cybersecurity?
  • What evidence demonstrates control effectiveness?
  • Which KPIs should leadership monitor?
  • How should benefits be measured?
  • When should a governance issue be escalated?
CITGP®

Governance Connects Strategy and Execution

A strong governance environment creates a continuous connection between enterprise direction and technology execution.

Enterprise Strategy

  1. What does the organization want to achieve?
  2. Technology Strategy
  3. What technology capabilities are required to support those objectives?
  4. Governance
  5. Who decides, what principles apply, what controls are required, and what risks are acceptable?
  6. Management
  7. How are technology capabilities implemented, operated, and supported?
  8. Measurement
  9. Are the expected outcomes actually being achieved?
  10. Assurance
  11. Can leadership trust the controls, evidence, reports, and results?
  12. Improvement

What should change based on performance, risk, audit, incidents, or emerging technology?

CITGP® prepares professionals to contribute throughout this lifecycle.

CITGP®

IT Governance Creates Accountability

One of the most important functions of governance is ensuring that technology decisions have clear ownership.

Weak governance often produces questions such as:

CITGP® develops professionals who understand how governance structures reduce this ambiguity.

The progression becomes:

Authority → Responsibility → Accountability → Evidence → Oversight

  • Who approved this system?
  • Who owns this risk?
  • Who authorized this exception?
  • Who is accountable for the vendor?
  • Who monitors performance?
  • Who confirms the control works?
  • Who reports significant issues?
  • Who decides whether remediation is sufficient?
CITGP®

IT Governance Connects Technology to Enterprise Risk

A technical weakness matters because of what it could mean for the organization.

For example:

Technical Condition

A critical application runs on unsupported infrastructure.

Technology Risk

The environment may be vulnerable to failure or compromise.

Business Exposure

A critical business service may become unavailable.

Governance Question

Who owns the risk, what remediation is required, and is temporary acceptance appropriate?

CITGP® develops the ability to connect technical conditions with broader governance and enterprise-risk decisions.

CITGP®

Controls Are Not the Same as Governance

Controls are important, but governance is broader than control implementation.

A control may require:

Governance determines:

CITGP® prepares professionals to understand this broader context.

  • MFA
  • Encryption
  • Backup
  • Approval
  • Logging
  • Segregation of duties
  • Access review
  • Why the control is required
  • Which systems it applies to
  • Who owns it
  • Who evaluates its effectiveness
  • What happens when it fails
  • Who can approve an exception
  • How results are reported
CITGP®

Performance Is Part of Governance

Technology governance cannot focus only on risk and compliance.

Organizations also need to know whether technology is producing expected value.

Governance professionals may monitor:

Effective governance therefore asks two questions:

  • Service availability
  • Technology costs
  • Investment performance
  • Project outcomes
  • Security exposure
  • Vendor performance
  • Customer satisfaction
  • Benefits realization
  • Recovery capability
  • Technology maturity
  • Is technology producing the outcomes the organization expected?

Are we managing technology responsibly?

and:

CITGP®

Assurance Builds Confidence

Senior leadership cannot personally inspect every system, project, contract, control, or technology decision.

They depend on trustworthy information.

Assurance activities help determine whether:

CITGP® prepares professionals to support these assurance activities through evidence, analysis, documentation, testing support, remediation tracking, and reporting.

  • Controls are designed appropriately
  • Controls operate effectively
  • Policies are followed
  • Risks are accurately reported
  • Compliance obligations are addressed
  • Governance processes are functioning
  • Management information can be trusted
CITGP®

Governance Structures and Decision Rights

CITGP® addresses:

The central question is:

  • Governance committees
  • Steering committees
  • Roles
  • Responsibilities
  • Decision authority
  • Escalation
  • Delegation
  • Accountability
  • Reporting relationships
  • Governance charters
  • Who has authority to decide—and who is accountable for the result?
CITGP®

Technology Strategy Alignment

Technology investments should support organizational objectives.

CITGP® addresses:

The progression becomes:

Enterprise Objective → Technology Capability → Investment → Outcome

  • Enterprise strategy
  • Technology strategy
  • Strategic alignment
  • Technology roadmaps
  • Capability planning
  • Business priorities
  • Stakeholder requirements
  • Performance outcomes
CITGP®

IT Risk Management

Candidates develop competency in:

The objective is to understand how technology risk contributes to enterprise risk.

  • Risk identification
  • Risk analysis
  • Likelihood
  • Impact
  • Inherent risk
  • Controls
  • Residual risk
  • Risk treatment
  • Risk acceptance
  • Escalation
  • Monitoring
CITGP®

Internal Controls

CITGP® addresses:

Professionals learn that a documented control is not automatically an effective control.

The question becomes:

  • Control objectives
  • Preventive controls
  • Detective controls
  • Corrective controls
  • Manual controls
  • Automated controls
  • Control ownership
  • Control evidence
  • Control testing
  • Deficiencies
  • “Can we demonstrate that the control operates as intended?”
CITGP®

Compliance

Technology governance frequently supports compliance with:

CITGP® develops the ability to distinguish between:

  • Laws
  • Regulations
  • Contracts
  • Internal policies
  • Industry requirements
  • Customer commitments
  • Privacy obligations
  • Security requirements
  • Requirement → Control → Evidence → Compliance Determination
CITGP®

Technology Investment Governance

CITGP® addresses how organizations evaluate technology investments.

Relevant areas include:

The goal is not simply:

  • Business cases
  • Cost
  • Benefits
  • Risk
  • Strategic alignment
  • Alternatives
  • Funding
  • Prioritization
  • Expected outcomes
  • Benefits realization

“Can we afford this technology?”

but:

“Does the investment produce sufficient strategic and operational value for the cost and risk?”

CITGP®

Portfolio Governance

Organizations may have hundreds of technology initiatives competing for resources.

CITGP® introduces:

  • Portfolio prioritization
  • Strategic alignment
  • Resource constraints
  • Risk
  • Dependencies
  • Benefits
  • Project status
  • Portfolio performance
  • Investment balance
  • Governance oversight
CITGP®

Project and Program Governance

CITGP® addresses governance of:

Governance helps determine whether projects remain aligned with their intended business purpose.

  • Scope
  • Business cases
  • Sponsorship
  • Decision authority
  • Milestones
  • Risk
  • Issues
  • Changes
  • Benefits
  • Post-implementation review
CITGP®

Architecture Governance

Architecture decisions affect:

CITGP® addresses:

  • Cost
  • Integration
  • Security
  • Scalability
  • Technical debt
  • Supportability
  • Resilience
  • Architecture standards
  • Design principles
  • Technology standards
  • Exceptions
  • Architecture review
  • Legacy technology
  • Modernization
  • Technology lifecycle
CITGP®

Cybersecurity Governance

Cybersecurity is a major component of enterprise technology governance.

CITGP® addresses:

The governance question is not simply:

  • Security accountability
  • Security policies
  • Risk
  • Security controls
  • Incident oversight
  • Vulnerability management
  • Identity
  • Third-party security
  • Cyber resilience
  • Security metrics

“Are security tools installed?”

It is:

“Is cybersecurity risk being governed appropriately and reported to the right decision-makers?”

CITGP®

Data Governance

Data governance addresses how information is:

Relevant concepts include:

  1. 01

    Owned

    Classified

  2. 02

    Used

    Protected

  3. 03

    Shared

    Retained

  4. 04

    Deleted

    Monitored

  5. 05

    Data ownership

    Data stewardship

  6. 06

    Data quality

    Classification

  7. 07

    Access

    Retention

  8. 08

    Lifecycle

    Accountability

CITGP®

Privacy Governance

CITGP® develops awareness of:

  • Personal information
  • Data collection
  • Data minimization
  • Appropriate use
  • Consent concepts
  • Retention
  • Access
  • Disclosure
  • Privacy risk
  • Governance responsibilities
CITGP®

Vendor and Third-Party Governance

Organizations increasingly depend on:

CITGP® addresses:

The governance progression becomes:

Select → Contract → Monitor → Assure → Improve or Exit

  • Cloud providers
  • SaaS companies
  • Managed service providers
  • Technology vendors
  • Outsourcing partners
  • Consultants
  • Software suppliers
  • Due diligence
  • Contracts
  • Service levels
  • Security
  • Privacy
  • Risk
  • Performance
  • Monitoring
  • Dependency
  • Exit planning
CITGP®

IT Service Governance

Technology governance also applies to ongoing service delivery.

Candidates develop competency involving:

  • Service ownership
  • Service levels
  • Availability
  • Capacity
  • Incidents
  • Problems
  • Changes
  • User experience
  • Service performance
  • Continual improvement
CITGP®

Performance Measurement

CITGP® addresses:

KPIs

Measures of performance.

KRIs

Measures of risk.

KCIs

Measures indicating whether controls are operating as expected.

Professionals learn to distinguish between:

Activity Metrics

and:

Outcome Metrics

For example:

“10,000 tickets closed” is an activity measure.

“Critical-service availability improved from 98.5% to 99.9%” is closer to an outcome measure.

CITGP®

Audit and Assurance

CITGP® introduces professionals to:

CITGP® is not solely an IT audit credential, but assurance is an important governance capability.

  • Audit objectives
  • Audit evidence
  • Control testing
  • Findings
  • Management responses
  • Remediation
  • Issue tracking
  • Independent assurance
  • Follow-up
  • Closure
CITGP®

Business Continuity and Resilience Governance

Governance professionals need to understand whether critical technology can withstand and recover from disruption.

CITGP® addresses:

  1. 01

    Business impact

    Critical services

  2. 02

    Continuity

    Disaster recovery

  3. 03

    Backup

    Recovery objectives

  4. 04

    Testing

    Dependencies

  5. 05

    Incident governance

    Resilience improvement

CITGP®

AI Governance

Artificial intelligence creates new governance questions.

Organizations must consider:

CITGP® introduces professionals to responsible AI-governance principles across the AI lifecycle.

  • Who owns AI systems?
  • Which uses are permitted?
  • What data is used?
  • Are outputs reliable?
  • Can decisions be explained?
  • Is human oversight required?
  • Are privacy requirements satisfied?
  • Are security risks addressed?
  • How are models monitored?
  • Who is accountable when AI produces an inappropriate outcome?
CITGP®

Emerging Technology Governance

CITGP® applies governance concepts to technologies such as:

The objective is not to predict every technology.

It is to develop governance principles that remain useful as technologies evolve.

  • Cloud
  • Automation
  • IoT
  • Edge computing
  • Digital platforms
  • Blockchain
  • Generative AI
  • Autonomous technologies
CITGP®

Ethics and Professional Responsibility

Governance professionals frequently work with sensitive information involving:

CITGP® therefore emphasizes:

  • Risk
  • Audits
  • Controls
  • Compliance
  • Incidents
  • Executive decisions
  • Employee activity
  • Vendors
  • Security weaknesses
  • Integrity
  • Confidentiality
  • Objectivity
  • Evidence-based reporting
  • Professional judgment
  • Conflict-of-interest awareness
  • Responsible technology use
CITGP®

Continual Governance Improvement

Governance models must evolve as:

CITGP® therefore incorporates a continual improvement cycle:

Assess → Identify Gaps → Prioritize → Improve → Monitor → Reassess

  • Business strategy changes
  • Technology changes
  • New threats emerge
  • Regulations evolve
  • Vendors change
  • Incidents occur
  • AI adoption expands
CITGP®

CITGP® Governance Lifecycle

CITGP® connects governance activities into an integrated professional lifecycle:

Enterprise Objective → Technology Decision → Risk Assessment → Control → Performance → Assurance → Reporting → Improvement

This helps professionals understand governance as a continuous decision and oversight process rather than a compliance exercise performed once per year.

CITGP®

What Makes CITGP® Different?

CITGP® develops competency across several important professional transitions.

From Technology Activity to Business Outcome

“The IT team completed the project.”

becomes:

“Did the project produce the intended business value?”

From Risk Identification to Risk Governance

“We found the risk.”

becomes:

“Who owns it, what is the treatment, and who can accept the residual exposure?”

From Control Documentation to Control Effectiveness

“The policy says we perform access reviews.”

becomes:

“Can we demonstrate that access reviews occur effectively and produce appropriate remediation?”

From Vendor Management to Vendor Governance

“The provider signed the contract.”

becomes:

“Is the provider meeting security, performance, resilience, and contractual expectations?”

From Metrics to Decision Support

“Here are 50 dashboard metrics.”

becomes:

“Here are the measures leadership needs to make a decision.”

From Compliance to Responsible Governance

“Are we compliant?”

becomes:

“Are we making responsible, controlled, risk-informed technology decisions that support enterprise objectives?”

CITGP®

CITGP® Professional Value Proposition

CITGP® integrates:

Governance + Strategy + Risk + Controls + Compliance + Investment + Cybersecurity + Data + Vendors + Performance + Assurance + AI

Its central professional objective is:

Understand the Requirement → Evaluate the Decision → Assess the Risk → Apply the Control → Measure the Outcome → Support Assurance → Improve Governance

CITGP®

CITGP® Professional Identity

A CITGP® professional should be capable of asking:

That is the professional capability CITGP® is designed to develop and validate.

CITGP® — Align Technology. Govern Risk. Strengthen Accountability. Support Better Enterprise Decisions.

  • What business objective does this technology support?
  • Who owns the decision?
  • Who owns the risk?
  • What governance structure applies?
  • What controls are required?
  • Is the control effective?
  • What evidence supports the conclusion?
  • Is the investment delivering value?
  • Are vendors meeting expectations?
  • Are cybersecurity responsibilities clear?
  • Is data being governed appropriately?
  • Are critical services resilient?
  • Which KPI or KRI actually matters?
  • What should leadership know?
  • How should this issue be escalated?
  • Is AI being used responsibly?
  • What should be improved?
CITGP®

CITGP® Professional Progression

Understand → Assess → Apply → Monitor → Measure → Report → Assure → Improve

CITGP®

Tools, Technologies, and Governance Applications

CITGP® remains vendor-neutral while addressing categories of tools professionals may encounter.

Governance, Risk, and Compliance

GRC Platforms • Risk Registers • Control Libraries • Compliance Systems • Policy-Management Platforms

Service and Asset Management

ITSM • CMDB • Asset Management • Service Catalogs • SLA Platforms

Portfolio and Investment

Project Portfolio Management • Business Case Tools • Financial Dashboards • Benefits Tracking

Audit and Assurance

Audit Management • Evidence Repositories • Control Testing • Issue Tracking

Cybersecurity Governance

Security Dashboards • Vulnerability Reports • SIEM Governance Metrics • Identity Reports • Risk Platforms

Data and Privacy

Data Inventories • Classification Tools • Privacy Platforms • Information-Governance Systems

AI Governance

AI Inventories • Model Registers • Risk Assessments • AI Control Monitoring • Responsible-AI Documentation

The focus is:

Governance Requirement → Evidence → Analysis → Decision → Monitoring → Improvement

rather than proficiency with one commercial platform.

CITGP®

Employment Outlook — CITGP® & CITGM®

Growing Demand for Professionals Who Can Connect Technology, Risk, Governance, Compliance, and Enterprise Value

Technology governance is becoming increasingly important as organizations expand their reliance on cloud computing, cybersecurity, artificial intelligence, data, digital platforms, outsourcing, automation, and third-party technology ecosystems.

There is no single U.S. Bureau of Labor Statistics occupational category called “IT Governance Professional” or “IT Governance Manager.” IT-governance responsibilities are distributed across several occupations, including computer and information systems managers, information security analysts, computer systems analysts, management analysts, compliance officers, auditors, technology-risk professionals, and governance, risk, and compliance specialists.

For that reason, the employment outlook for CITGP® and CITGM® is best understood by examining these closely aligned occupational groups.

CITGP®

CITGP® Employment Outlook

  • Certified IT Governance Professional (CITGP®)

Govern Risk. Strengthen Controls. Support Better Technology Decisions.

CITGP® competencies align with a growing range of professional roles involving:

IT Governance • Technology Risk • GRC • Cybersecurity Governance • Compliance • IT Controls • Assurance • IT Audit • Vendor Risk • Information Systems • Technology Consulting

The broader U.S. labor market supporting these competencies shows strong demand, particularly where governance intersects with cybersecurity and technology transformation.

CITGP®

U.S. Occupational Outlook — CITGP®-Aligned Careers

*The accountants-and-auditors category is broader than IT audit but provides a relevant benchmark for professionals whose governance careers involve technology audit and assurance. (Bureau of Labor Statistics)

For comparison, BLS projects total U.S. employment across all occupations to grow approximately 3.1% from 2024 to 2034. Computer and mathematical occupations overall are projected to grow 10.1%, while management occupations are projected to grow 6.1%. (Bureau of Labor Statistics)

Relevant Occupation2024 Employment2034 Projected EmploymentGrowthNew JobsAnnual Openings2024 Median Salary
Information Security Analysts 182,800 234,900 29% 52,100 16,000 $124,910
Computer Systems Analysts 521,100 566,500 9% 45,500 34,200 $103,790
Management Analysts 1,075,100 1,169,700 9% 94,500 98,100 $101,190
Compliance Officers 418,000 430,300 3% 12,300 33,300 $78,420
Accountants & Auditors* 1,579,800 1,652,600 5% 72,800 124,200 $81,680
CITGP®

Information Security and Cyber Governance Outlook

One of the strongest employment indicators relevant to CITGP® is cybersecurity.

BLS projects employment for Information Security Analysts to increase from approximately 182,800 positions in 2024 to 234,900 in 2034.

That represents:

29% Projected Growth

and approximately:

52,100 Additional Jobs

with about:

16,000 Openings Per Year

on average over the decade. (Bureau of Labor Statistics)

This is particularly important for CITGP® because modern cybersecurity increasingly requires governance of:

BLS specifically notes that growth is being supported by increasing cyberattacks, expanding cybersecurity requirements, e-commerce, and greater adoption of artificial intelligence. (Bureau of Labor Statistics)

  • Cyber risk
  • Security controls
  • Policy
  • Identity
  • Third parties
  • Cloud security
  • Vulnerability exposure
  • Incident oversight
  • Compliance
  • Executive reporting
CITGP®

Computer Systems Analysis Outlook

Information systems and technology analysis are another important foundation for IT-governance careers.

BLS projects Computer Systems Analysts to grow from:

521,100 jobs in 2024

to:

566,500 jobs by 2034.

That represents:

9% Growth

approximately:

45,500 Additional Positions

and:

34,200 Openings Per Year

on average. (Bureau of Labor Statistics)

BLS notes that continued organizational reliance on IT—including artificial intelligence—is expected to support demand for systems analysts. This aligns with CITGP® responsibilities involving technology evaluation, business alignment, architecture governance, investment analysis, and control assessment. (Bureau of Labor Statistics)

CITGP®

Management and Technology Consulting Outlook

IT-governance professionals may also work in technology consulting, risk advisory, internal consulting, transformation, and governance-improvement roles.

BLS projects employment for Management Analysts to grow by approximately:

9% from 2024–2034

from approximately 1.075 million to 1.170 million positions.

Approximately:

98,100 openings per year

are projected over the decade. (Bureau of Labor Statistics)

BLS expects demand for consulting services to continue as organizations seek to improve efficiency and control costs, with specialized consulting—including information-technology consulting—contributing to demand. (Bureau of Labor Statistics)

CITGP®

Compliance Career Outlook

Governance and compliance frequently overlap.

BLS projects approximately:

CITGP®

33,300 Compliance Officer Openings Annually

through 2034.

Employment is projected to grow approximately 3%, from 418,000 positions in 2024 to 430,300 by 2034. (Bureau of Labor Statistics)

BLS identifies ongoing regulatory complexity as a key driver of demand, with organizations requiring professionals who can interpret requirements and help reduce the costs and risks of noncompliance. (Bureau of Labor Statistics)

For CITGP® professionals, this aligns with competencies involving:

Policy • Technology Controls • Regulatory Requirements • Evidence • Assurance • Risk • Remediation

CITGP®

IT Audit and Assurance Outlook

IT governance also intersects with audit and assurance.

Although BLS does not maintain a separate national category for IT Auditors, its broader accountants-and-auditors occupation provides an indication of assurance-related employment.

Employment is projected to increase from:

1.58 million positions in 2024

to approximately:

1.65 million by 2034,

representing:

5% Growth

and approximately:

CITGP®

124,200 openings annually. (Bureau of Labor Statistics)

Technology is expected to automate some routine audit tasks while increasing the importance of analytical and advisory activities. This may increase the relative value of professionals capable of understanding automated controls, cloud environments, cybersecurity evidence, data, AI, and technology risk. (Bureau of Labor Statistics)

CITGP®

CITGP® Salary Outlook

Governance, Risk & Compliance Analyst — Current U.S. Benchmark

Because the BLS does not publish a separate occupation for “IT Governance Analyst,” current market compensation data provide an additional benchmark.

As of July 1, 2026, Salary.com reported an average U.S. salary for a Governance, Risk and Compliance Analyst of approximately:

$100,913 Per Year

or approximately:

$49 Per Hour. (Salary)

The reported salary distribution was:

Percentile

Annual Salary

10th Percentile

$88,908

25th Percentile

$94,629

Average

$100,913

75th Percentile

$108,783

90th Percentile

$115,948

(Salary)

CITGP®

GRC Analyst Salary by Geography

Salary.com's July 2026 estimates show meaningful geographic differences for Governance, Risk and Compliance Analysts.

Examples include:

These are market estimates rather than BLS wage statistics. (Salary)

LocationEstimated Average Salary
District of Columbia $111,731
California $111,307
Massachusetts $109,824
Washington $109,420
New Jersey $109,380
New York $107,281
Maryland $104,051
Illinois $102,861
Texas $98,431
North Carolina $95,898
South Carolina $94,555
CITGP®

Official 2025 BLS Salary Benchmarks — CITGP®-Aligned Roles

The latest BLS Occupational Employment and Wage Statistics released for May 2025 provide useful national mean-wage benchmarks.

(Bureau of Labor Statistics)

These occupational categories are broader than IT governance specifically, but together they illustrate the compensation environment surrounding governance, technology risk, cybersecurity, systems analysis, audit, and compliance.

OccupationEmploymentMean Hourly WageMean Annual Wage
Information Security Analysts 190,650 $63.71 $132,510
Computer Systems Analysts 519,530 $55.10 $114,610
Management Analysts 898,280 $54.71 $113,790
Accountants & Auditors 1,449,500 $45.56 $94,750
Compliance Officers 417,070 $42.50 $88,400
CITGP®

Potential Careers for CITGP® Professionals

CITGP® competencies may support professional development toward positions such as:

  • IT Governance Analyst
  • Technology Governance Analyst
  • Governance, Risk and Compliance Analyst
  • IT Risk Analyst
  • Technology Risk Analyst
  • Cybersecurity Governance Analyst
  • Information Security Governance Analyst
  • IT Controls Analyst
  • Technology Controls Analyst
  • IT Compliance Analyst
  • Technology Compliance Analyst
  • IT Audit Analyst
  • IT Auditor
  • Technology Assurance Analyst
  • Third-Party Risk Analyst
  • Vendor Risk Analyst
  • Cloud Governance Analyst
  • Data Governance Analyst
  • AI Governance Analyst
  • Technology Portfolio Analyst
  • IT Service Governance Analyst
  • Information Systems Analyst
  • Technology Consultant
  • Risk Advisory Consultant
CITGP®

High-Value CITGP® Skill Combinations

Governance professionals can become particularly valuable when governance competency is combined with specialized expertise.

IT Governance + Cybersecurity

This combination is supported by the 29% projected growth in employment of information security analysts. (Bureau of Labor Statistics)

IT Governance + Cloud

Organizations increasingly need professionals capable of governing cloud security, cost, architecture, data, third parties, resilience, and shared-responsibility models.

IT Governance + Risk & Compliance

Risk and compliance professionals help translate technical activities into enterprise-control and regulatory requirements.

IT Governance + Data & Privacy

Growing dependence on data creates additional demand for professionals capable of governing data ownership, access, quality, privacy, retention, and use.

IT Governance + AI

AI introduces new governance requirements involving model ownership, human oversight, privacy, data quality, security, explainability, accountability, third-party risk, and monitoring.

CITGP®

CITGP® Employment Outlook Summary

29%

Projected growth for Information Security Analysts, 2024–2034. (Bureau of Labor Statistics)

52,100

Projected additional Information Security Analyst positions. (Bureau of Labor Statistics)

9%

Projected growth for Computer Systems Analysts. (Bureau of Labor Statistics)

34,200

Projected annual Computer Systems Analyst openings. (Bureau of Labor Statistics)

9%

Projected growth for Management Analysts. (Bureau of Labor Statistics)

98,100

Projected annual Management Analyst openings. (Bureau of Labor Statistics)

$100,913

July 2026 market-average salary estimate for U.S. Governance, Risk and Compliance Analysts. (Salary)

$132,510

May 2025 BLS mean annual wage for Information Security Analysts. (Bureau of Labor Statistics)

$114,610

May 2025 BLS mean annual wage for Computer Systems Analysts. (Bureau of Labor Statistics)

CITGP®

Flexible CITGP® Certification Assessment

Option 1 — CITGP® Certification Examination

100 Questions

90 Minutes

Multiple-Choice + Scenario-Based Questions

Closed Book

Secure Online Proctoring or Approved Testing Center

Recommended Passing Score: 70%

Assessment emphasizes:

Governance • Strategy • Risk • Controls • Compliance • Investment • Vendors • Performance • Assurance • AI Governance

Option 2 — Applied IT Governance Capstone

Eligible candidates in an approved instructor-led pathway may demonstrate competency through the CITGP® Applied IT Governance Capstone.

The Capstone may integrate:

Enterprise Requirement → Governance Assessment → Risk & Controls → Investment Decision → Performance Monitoring → Governance Recommendation

CITGP®
  • CITGP®
  • CITGM®
  • From IT Governance Practice to Enterprise Technology Governance Leadership
CITGP®

CITGP® Certification Value Proposition

CITGP® integrates:

Governance + Strategy + Risk + Controls + Compliance + Cybersecurity + Investment + Vendors + Performance + Assurance + AI

Its central professional objective is:

Understand Governance → Evaluate Risk → Apply Controls → Monitor Performance → Support Assurance → Improve Technology Decision-Making

The examination

Exam & Certification Details

Everything you need to plan your sitting.

CITGP-100

Exam code for the Professional-level IT Governance credential.

100 questions (maximum)

Multiple choice, completed in 120 minutes.

700 out of 1000

Passing score. Delivered in English.

Recommended experience

A minimum of two years of experience in it governance or a closely related technology discipline.

Where you sit it

IBACTP® approved testing centers and online proctored delivery

Staying certified

Three-year certification cycle with continuing professional education

Choose your route

Four ways to enroll. One credential.

Every route leads to the same CITGP® examination and the same designation.

Option 1

Self-Paced Learning

Self-study
$400 USD
  • Exam fee only
  • Complimentary course materials provided
Option 2

Virtual Instructor-Led Training

4 days
$1,200 USD
  • 4 days, 2 hours daily online
  • Includes all course materials + Exam
Select a Date and Purchase
Option 3

Bootcamps & Intensives

10 days
$1,800 USD
  • 10 days, 2 hours daily
  • Includes all course materials + Exam
Select a Date and Purchase
Option 4

Corporate Training

Your schedule
Fees negotiable
  • Certify a whole team on a schedule that suits your organization
  • Fees depend on the team's size / number
Request a Team Quote
28+ Certifications
14 Technology Disciplines
Global Recognition
Industry Validated
Your Career Our Mission