CRX | October 13-15, 2026 | Up to 17 CPEs | In-person & virtual options available | Register Now!

Customers
Login
Optro's logo

August 3, 2026 13 min read

8 GRC conferences in 2026 worth your time (and your CPE budget)

logo image

Optro staff

Choosing the right governance, risk, and compliance conference in 2026 comes down to more than just travel. It is about where you'll learn the most, earn the CPE credits your certification requires, and return with ideas your team can actually use. Agentic AI is changing how GRC functions operate, which raises the stakes on where you spend your CPE budget this year. This guide compares eight verified 2026 GRC conferences by date, format, location, and CPE, so you can make the case to leadership and book the right room.

Key takeaways

  • Eight verified GRC conferences run from August through November 2026 across U.S., U.K., and virtual formats, each checked against official organizer pages and covering at least two GRC pillars.
  • CPE is highest at the ISACA and IIA GRC Conference (up to 28) and CRX (up to 17 in person, up to 5 virtual), while CRX virtual keynotes, #RISK Expo Europe, and the MetricStream U.S. virtual edition are free to attend.
  • CRX 2026, Optro's flagship hybrid conference, leads the list on specifics: named sponsors, confirmed speakers, verified CPE, and a published agenda focused on transforming risk into opportunity in an agentic AI world.

GRC conferences at a glance (Fall 2026)

Conference

Dates

Location/format

CPE

CRX (Connected Risk Experience)

Oct 13-15 (virtual Oct 14-15)

San Diego, CA; Hybrid

Up to 17 in person; up to 5 virtual

GRC Conference 2026 (ISACA and The IIA)

Aug 17-19

San Diego, CA; Hybrid

Up to 28 CPE

Gartner Enterprise Risk, Audit and Compliance — Americas

Sep 15-16

Grapevine, TX; In person

Up to 10.8 CPE

Gartner Enterprise Risk, Audit and Compliance — EMEA

Sep 28-29

London, U.K.; In person

Up to 7.8 CPE credits or up to 13.2 CPE for those participating in the Senior Leadership Circle program

#RISK Expo Europe 2026

Nov 10-11

London, U.K.; In person, free

Contact conference organizer for CPE information

MBA Compliance and risk management Conference

Sep 27-29

Washington, D.C.; In person

Contact conference organizer for CLE, CPE, CRCM

infosec World 2026

Oct 12-14

Orlando, FL; In person

Contact conference organizer for CPE information

MetricStream GRC Summit — U.S. virtual edition

Nov 4-5

Virtual, free

Contact conference organizer for CPE information

1. CRX (Connected Risk Experience): October 13-15 in San Diego, CA

CRX 2026 is Optro's flagship hybrid conference for audit, risk, compliance, and infosec leaders, designed around a single forward-looking premise: transforming risk into opportunity in an agentic AI world.

The in-person event runs October 13-15 at the Gaylord Pacific Resort in San Diego. Free virtual keynotes are available October 14-15, making CRX one of the most accessible options on this list, regardless of your travel budget.

The 2026 CRX agenda spans agentic AI, enterprise risk management, operational resiliency, cyber risk quantification, and regulatory compliance automation — hitting governance, risk, and compliance pillars in one cohesive program.

Keynotes include a conversation between Richard Chambers and Kieran Taylor on agentic AI, with sessions from industry analysts Michael Rasmussen (GRC 20/20) and Paul McKay (Forrester). Sponsors include Deloitte, EY, Protiviti, KPMG, and Grant Thornton.

For a deeper look at what's on the agenda, see the CRX 2026 agenda and keynote overview. And if you're wondering why CRX replaced Audit and Beyond, this post explains why CRX replaced Audit and Beyond — along with what that rebrand means for the GRC community.

In-person vs. virtual

In-person attendees get the full three-day program, dedicated networking, and access to up to 17 CPE credits through Optro's NASBA-registered program. Virtual attendees access the free keynote sessions on October 14-15 and can earn up to 5 CPE credits.

Pricing and CPEs

In-person registration for CRX 2026 is $2,095 at standard pricing. Virtual keynote access is free, which puts the October 14-15 agentic AI sessions within reach even when travel is not in this year's budget. In-person attendees earn up to 17 CPE credits, and virtual attendees earn up to 5, all through Optro's NASBA-registered program.

Be in the room where GRC decides what comes next
Register for CRX

2. GRC Conference 2026 (ISACA and The IIA) — August 17-19 — San Diego, CA

The GRC Conference 2026 is the 13th annual joint event from ISACA and The IIA — and arguably the most horizontally comprehensive association conference on this list. Running August 17-19 at the Gaylord Pacific Resort and Convention Center in San Diego, this hybrid event brings together governance, risk, audit, cybersecurity, and compliance leaders under one roof.

The program features 50-plus speakers from organizations including Microsoft, PayPal, Mastercard, Intuit, the NBA, Generali, Snowflake, and Protiviti, spread across 40-plus sessions. Topics include enterprise AI governance, vendor risk management, agentic AI in GRC, privacy governance, and cloud security.

CPE potential is up to 28 credits total — 16 at the main conference plus up to 12 through pre- and post-conference workshops. For teams with active CISA, CRISC, or CIA certification requirements, this is a compelling value argument for leadership.

3. Gartner Enterprise Risk, Audit and Compliance — Americas — September 15-16 — Grapevine, TX

The Gartner Enterprise Risk, Audit and Compliance Conference — Americas takes an analyst-led approach, connecting enterprise risk, internal audit, and compliance functions through Gartner's research frameworks and executive peer networks.

Scheduled for September 15-16 in Grapevine, TX, this in-person event covers AI-powered GRC tools, digital audit automation, compliance analytics, and third-party risk management. It suits practitioners who want research-backed guidance on building or maturing their GRC programs, particularly those evaluating new technology.

CPE credits have not been confirmed on the official event page at this time. Reach out to event organizers for more information.

4. Gartner Enterprise Risk, Audit and Compliance — EMEA — September 28-29 — London, U.K.

The Gartner Enterprise Risk, Audit and Compliance Conference — EMEA mirrors the Americas program in structure and content, making it the natural pick for European risk, audit, and compliance leaders who want the same Gartner analyst insight without transatlantic travel.

Running September 28-29 in London, the agenda covers AI governance tools, audit automation, regulatory intelligence, and third-party risk — topics increasingly central to EU-based practitioners navigating the EU AI Act, DORA, NIS2, and expanding ESG obligations.

CPE credits have not been confirmed on the official event page at this time.

5. #RISK Expo Europe 2026 — November 10-11 — London, U.K.

Now in its fifth year, #RISK Expo Europe is Europe's large-scale, free-to-attend GRC and RegTech expo. It runs November 10-11 at ExCeL London, drawing 6,000-plus senior decision-makers, 200-plus speakers, and 120 exhibitors across five content streams: infosec, banking/financial services/insurance, third-party risk management, GRC, and protective security.

The dedicated GRC stream focuses on "unified GRC platforms, breaking risk and compliance silos" and moving from tick-box compliance to risk-led audit and governance — language that maps directly to where the profession is heading. Free registration removes the budget barrier that sidelines many teams from attending European events, making this a strong option for practitioners who want exposure to cross-functional GRC thinking without a conference fee.

CPE credits have not been confirmed at this time (expo-style format, free).

6. MBA Compliance and Risk Management Conference — September 27-29 — Washington, D.C.

If your GRC work sits in the mortgage or residential lending space, the MBA Compliance and Risk Management Conference is the sector-specific pick. Hosted by the Mortgage Bankers Association, this in-person event runs September 27-29 at the Grand Hyatt in Washington, D.C.

The agenda integrates regulatory compliance, credit risk, quality assurance and quality control, underwriting, and fraud prevention — genuine cross-functional GRC coverage within a tightly regulated industry. CPE credits for CPAs and CLE credits for attorneys are confirmed, making this a strong candidate for compliance officers and legal professionals who need structured credits.

Worth noting: the sector-specific scope makes this event most relevant to mortgage compliance and risk teams rather than broad GRC audiences.

7. Infosec World 2026 — October 12-14 — Orlando, FL

In its 31st year, Infosec World 2026 is a cybersecurity-forward event with a dedicated governance, regulation, and compliance track — the reason it qualifies here. Modernizing GRC practices is a named 2026 focus area with a specific session category for governance, regulation, and compliance.

The event runs October 12-14 at the Gaylord Palms in Orlando (with workshops on October 11 and October 15), drawing 2,500-plus attendees across 150-plus sessions and 200-plus speakers. For GRC program leaders who want to stress-test their frameworks against a cybersecurity-native audience, InfoSec World offers a different kind of cross-pollination than traditional GRC association events.

8. MetricStream GRC Summit — U.S. virtual edition — November 4-5 — Virtual

The MetricStream GRC Summit U.S. virtual edition is a free, fully virtual option for U.S.-based GRC, risk, compliance, and cyber leaders who can't travel this year. Running November 4-5 across two half-day sessions, it's part of MetricStream's 14-year-running GRC Summit series and covers AI, risk, compliance, and cybersecurity as integrated themes.

For teams with no travel budget or practitioners who've already used their CPD allowance at an in-person event, this is a low-friction way to stay current on GRC trends before year-end.

How to pick the right GRC event for your team

No single conference fits every practitioner. Here's a practical framework:

By role:

  • Audit, risk, compliance, and infosec leaders wanting breadth: CRX or the ISACA/IIA GRC Conference
  • Enterprise risk and internal audit leaders wanting analyst research: Gartner Americas or EMEA
  • Mortgage compliance officers and legal professionals: MBA Conference
  • GRC program leaders with a strong cyber mandate: InfoSec World

By region:

  • U.S.-based practitioners: CRX, ISACA/IIA, Gartner Americas, MBA, InfoSec World
  • European practitioners: Gartner EMEA, #RISK Expo Europe
  • Anywhere with internet access: CRX virtual keynotes, MetricStream U.S. virtual edition

By CPE need:

  • Highest credits: ISACA/IIA (up to 28)
  • Strong in-person CPE with hybrid option: CRX (up to 17 in person, up to 5 virtual)
  • Legal and accounting CPD: MBA Conference (CLE and CPE)

By budget:

  • Free options: CRX virtual keynotes, #RISK Expo Europe (in person), MetricStream U.S. virtual edition
  • Mid-range: CRX early bird ($1,495 through December 31, 2025)

Follow the risk in 2026

The GRC conferences on this list are where the profession is working out what comes next. Agentic AI, integrated risk frameworks, and evolving regulatory demands are reshaping every function on this list. The practitioners who show up with questions and leave with frameworks will have an edge.

If you're ready to start with the event built specifically for that conversation, register for CRX 2026 — Optro's hybrid conference in San Diego, October 13-15, with free virtual access October 14-15. And if you need to bring leadership along first, the business-case letter is ready when you are.

About the authors

logo image

Optro is the leading AI-powered GRC platform, transforming the way the world’s biggest companies manage risk. More than 50% of the Fortune 500 trust Optro to elevate their audit, risk, and compliance management.

You may also like to read

person at a conference room table with colleagues
GRC

Responsible AI policy: A guide to ethical governance

LEARN MORE
person with glasses smiling
GRC

AI transparency policy: a practical guide for enterprises

LEARN MORE
colleagues reviewing work on a laptop
GRC

AI governance implementation: A practical guide

LEARN MORE

Discover why industry leaders choose Optro

SCHEDULE A DEMO
upward trending chart
confident business professional