Conference Description
Key Takeaways
- Joint conference from ISACA and The IIA covering governance, risk management, and compliance
- More than 40 sessions delivered by over 50 expert speakers
- Hybrid format with in-person attendance in San Diego and virtual participation options
- Up to 28 CPE credits available for professional certification maintenance
- Designed for IT auditors, risk managers, compliance officers, and information security professionals
Introduction
The ISACA GRC Conference 2026 brings together governance, risk management, and compliance professionals for a comprehensive programme addressing the operational and regulatory challenges facing modern enterprises. Co-hosted by ISACA and The Institute of Internal Auditors (The IIA), the conference serves practitioners responsible for IT audit, internal controls, cybersecurity, and business continuity. With organisations navigating increasingly complex threat landscapes and evolving regulatory frameworks, the event provides timely guidance on aligning risk management practices with strategic business objectives.
About This Event
The 2026 edition of the ISACA GRC Conference offers a hybrid attendance model, enabling participants to join either in person in San Diego or through a virtual platform. This flexibility accommodates professionals with varying schedules and travel constraints while maintaining access to the full educational programme. The conference structure includes general sessions, breakout tracks, and a pre-conference workshop available exclusively to in-person attendees.
With more than 40 sessions scheduled across the event, attendees can tailor their experience to specific areas of professional interest. The programme features contributions from over 50 speakers drawn from practitioner and leadership roles across the GRC discipline. Participants may earn up to 28 continuing professional education credits, supporting certification maintenance requirements for credentials such as CISA, CRISC, CGEIT, and CIA.
Core Discussion Areas
The conference programme spans the foundational pillars of enterprise GRC: governance frameworks, risk assessment methodologies, internal control design, and compliance management. Sessions address both strategic considerations for senior leaders and technical implementation details for practitioners working directly with audit programmes and control environments.
IT audit and information security feature prominently, reflecting the growing interdependence between technology infrastructure and organisational risk posture. As enterprises expand their digital operations, the boundaries between traditional internal audit and IT-focused assurance continue to blur. The conference examines how practitioners can develop integrated approaches that address both financial controls and technology risks within unified frameworks.
Cybersecurity and business continuity sessions explore how organisations can strengthen their resilience against operational disruptions. These topics connect directly to broader governance concerns, as boards and executive teams increasingly expect risk functions to provide clear visibility into cyber threats and recovery capabilities.
Industry Context
The GRC profession operates within an environment of persistent regulatory change and expanding stakeholder expectations. Financial services, healthcare, and critical infrastructure sectors face particularly demanding compliance obligations, while organisations across all industries must demonstrate effective risk oversight to maintain stakeholder confidence. The convergence of IT governance with enterprise risk management has elevated the strategic importance of professionals who can bridge technical and business perspectives.
Professional associations such as ISACA and The IIA play central roles in establishing standards, developing certification programmes, and facilitating knowledge exchange within the GRC community. Their joint sponsorship of this conference reflects the complementary nature of IT audit and internal audit disciplines, both of which contribute to organisational assurance and control effectiveness.
Who Should Attend
The conference serves professionals across the GRC spectrum, including IT auditors, internal auditors, risk managers, compliance officers, and information security managers. Executives with governance responsibilities, such as chief audit executives and chief risk officers, will find strategic content relevant to their oversight functions. The programme accommodates both mid-career practitioners seeking to deepen technical expertise and senior leaders focused on emerging trends and organisational strategy.
Attendees typically represent large enterprises, financial institutions, consulting firms, and public sector organisations where formal GRC programmes are established or under development. The networking opportunities inherent in the hybrid format enable participants to connect with peers facing similar challenges across different industries and regulatory environments.
Practical Value for Practitioners
Beyond educational content, the conference emphasises actionable guidance that participants can apply within their organisations. Sessions draw on real-world experiences and case studies rather than purely theoretical frameworks, providing context for how governance and risk practices function in operational settings. This practical orientation helps attendees translate conference insights into tangible improvements to their audit programmes, risk assessments, and compliance processes.

