CORCI logo
Focused certification exam prep
Start practice

CORCI Exam Domains 2026: Complete Guide to All 13 Content Areas

TL;DR
  • The 13 content areas are editorial preparation headings, not official scored domains or a published exam blueprint.
  • McAfee Institute's CORCI curriculum centers on six published learning objectives, from ORC foundations to legal fundamentals and surveillance.
  • The standalone CORCI exam page lists a three-hour limit, online proctoring, one attempt and a one-year exam license.
  • Official domain weights, question count and pass rate are unverified, so ignore any source quoting them as fact.

How to Read the 13 Content Areas

Candidates searching for the "CORCI exam domains" usually expect a tidy table of percentages: Domain 1 is 20%, Domain 2 is 15%, and so on. For the Certified Organized Retail Crime Investigator credential from McAfee Institute, that table does not exist in any public source we could verify. What does exist is a curriculum narrative and six published learning objectives, and the thirteen areas in this guide are organized directly from the topics those materials name.

Think of the 13 headings as a study map rather than an exam blueprint. They are unweighted, they are not official module titles, and they do not claim to be exhaustive. The issuer advertises 21 modules, but the public course page does not expose their complete titles or lesson contents, so we do not pretend to reproduce them. Your actual coursework will contain material beyond this map, and that coursework is the authoritative source.

Why this distinction matters: A study plan built on invented weights can send you to over-prepare a "heavy" domain that the real assessment barely touches. Treat every area below as potentially testable, and let your official course sections tell you where the emphasis lies.

If you are still orienting yourself to the credential, start with What Is CORCI Certification? and What Does CORCI Stand For?. Once you are ready to test yourself against these topics, our CORCI practice test site lets you drill them in question form.

What the Issuer Actually Publishes

Before diving into each area, it helps to separate what is confirmed from what is not. The table below reflects the current public issuer material reviewed for this guide.

ItemStatus
Credential authorityMcAfee Institute
Published learning objectivesSix, covering ORC foundations, cyber investigation and evidence collection, auction and online-fraud investigation, social-media and OSINT investigation, booster and fencing operations, and legal fundamentals and surveillance
Program size21 modules advertised; 40 hours of instruction and 35 CPE credits described
Standalone exam formatThree-hour time limit, online proctoring, one attempt, one-year exam license
Passing thresholdAt least 70% on course sections and on the final online exam
Official domain weightsUnverified
Question count and scored/unscored splitUnverified
Pass rateUnverified

Note that the 40 hours and 35 CPE credits describe the training program, not the exam timer or the number of questions. Mixing those figures up is one of the most common errors in online discussion of this credential. For the threshold itself, see CORCI Passing Score 2026, and for the data question, CORCI Pass Rate 2026: What the Data Shows.

One more clarification: McAfee Institute also offers an Associate designation, A|CORCI. Its current associate policy describes the same training curriculum and the same proctored certification examination, with professional experience distinguishing the status. Progression from associate to professional does not require retraining or retesting. So the content areas below apply to both; you are not preparing for two separate exams.

Domains 1-3: Structures and the Intelligence Foundation

The first three areas build the conceptual frame that every later investigative technique hangs on. If the first learning objective, ORC foundations, includes "fraud schemes, operational structures and business impact," then these are the topics you should be able to explain in your own words.

Domain 1: Organized-Retail-Crime Structures

This is the foundation. You need to distinguish organized retail crime from opportunistic shoplifting and understand how groups are arranged to move stolen merchandise at scale.

  • Operational structures: how roles are divided among participants, from those who steal to those who move and monetize goods
  • Fraud schemes that overlap with theft, and how they differ in evidence and charging posture
  • Business impact: why losses extend beyond the cost of merchandise, and how that framing supports referrals and case priority
  • How individual incidents link into a pattern worth an investigator's time

Domain 2: Open-Source Intelligence (OSINT)

OSINT appears directly in the learning objectives, tied to gathering evidence and building cases. Expect scenario questions about what information is legitimately collectible from public sources and how it feeds an investigation.

  • Identifying public sources that can reveal people, relationships and activity
  • Distinguishing a lead from corroborated evidence
  • Documenting what you found, where, and when, so it survives scrutiny later

Domain 3: The Intelligence Cycle

The intelligence cycle gives your work a repeatable shape: defining what you need to know, collecting, processing, analyzing and disseminating. Candidates who understand the cycle can reason through unfamiliar scenarios by asking which stage they are in.

  • Direction and requirements: starting from a question, not a pile of data
  • Collection versus analysis, and why they should not blur together
  • Producing something a decision-maker can act on

Because the cycle is the connective tissue, it pays to learn it early. Our CORCI Study Guide walks through how to fold these concepts into a first-attempt plan.

Domains 4-6: Privacy, Cyber and Auction Fraud

This cluster covers the digital side of the work. The published objectives name "evidence from auctions and social media to identify perpetrators and networks," plus "tracking and identifying criminal operations" in auction and online-fraud investigation. Privacy sits alongside them because collection power and collection limits travel together.

Domain 4: Privacy

Privacy is a candidate's guardrail. Even when information is technically reachable, an investigator must know what is appropriate to collect, how to handle it, and where authorization or legal process becomes necessary.

  • The difference between what is publicly visible and what requires lawful process
  • Handling personal information responsibly during an investigation
  • How privacy missteps can undermine an otherwise strong case

Domain 5: Cyber Investigations

The cyber objective centers on evidence collection. Questions here lean toward how digital evidence is identified, preserved and attributed to a person or network.

  • Recognizing digital traces that connect an online identity to a real-world actor
  • Preserving evidence so its integrity can be demonstrated
  • Mapping networks rather than isolated accounts

Domain 6: Auction Fraud

Stolen goods frequently surface on online marketplaces and auction platforms, which makes listings a rich evidence source. This area is about tracking and identifying the criminal operations behind those listings.

  • Reading listing behavior, seller patterns and item volume for signs of a fencing outlet
  • Linking an online seller to the upstream theft activity
  • Preserving listing evidence before it disappears
Connecting the cluster: Auction evidence, cyber attribution and privacy limits are rarely tested in isolation. A realistic scenario might ask how you would build a case from a suspicious seller account while staying within appropriate collection boundaries. Practice thinking across all three at once.

Domains 7-8: Social Media and Deception Analysis

The fourth learning objective ties social media directly to OSINT, "gathering evidence and building cases." Social platforms often reveal associations, locations, and boasts that other sources never will. Deception analysis is the skill of weighing what you gather and what suspects say.

Domain 7: Social-Media Research

Social media research turns scattered posts into case-relevant intelligence. The emphasis is on structured collection and on connecting online presence to the individuals and groups under investigation.

  • Identifying accounts, associations and patterns that reveal group membership
  • Capturing content in a way that preserves context and provenance
  • Avoiding assumptions: an account that looks relevant still needs corroboration

Domain 8: Deception Analysis

Investigators encounter false statements, fabricated identities and staged narratives. This area focuses on recognizing and testing deception rather than trusting surface claims.

  • Spotting inconsistencies between statements, documents and observable facts
  • Treating behavioral cues as prompts for verification, not proof
  • Recognizing fabricated or borrowed online identities

These two areas reward a skeptical habit of mind. If you can articulate why a lead is only a lead, you will be better positioned for scenario-style items than someone who has memorized terms.

Domains 9-11: Boosters, Fencing and Surveillance

The fifth objective asks candidates to "detect and investigate" booster and fencing operational tactics, and the sixth pairs surveillance with legal fundamentals. Together these areas connect the online evidence trail to the physical world of stores, vehicles and storage locations.

Domain 9: Booster Operations

Boosters are the individuals who steal merchandise, often to order. Understanding their methods helps investigators recognize patterns across incidents.

  • Common tactics and how they present in loss data and video
  • How boosters fit into the larger structure from Domain 1
  • Linking repeated incidents to the same actors or crews

Domain 10: Fencing Operations

Fences convert stolen goods into cash. Disrupting fencing is often the most effective way to reduce theft, because it removes the market the boosters depend on.

  • How fencing operations acquire, store and resell goods
  • Indicators that a seller or business is moving stolen merchandise
  • Tracing the path from theft to resale, including online channels from Domain 6

Domain 11: Surveillance

Surveillance generates evidence, but it also generates legal exposure when done carelessly. The published objective pairs it with compliance, so expect both technique and constraint in your study.

  • Purposes and methods of observation in an ORC context
  • Documentation that supports later prosecution
  • Staying within legal and policy limits while gathering evidence

Domains 12-13: Legal Fundamentals and Case Development

The final two areas are where everything converges. The sixth learning objective covers "compliance and effective evidence gathering," and case development is where an investigator turns collected material into something a prosecutor or internal decision-maker can use.

Domain 12: Legal Fundamentals

This area establishes the legal boundaries around every other technique. You are not being asked to practice law, but you must understand what makes evidence usable and what makes it vulnerable.

  • Compliance requirements that govern collection and handling
  • What makes evidence admissible or open to challenge
  • How the line between private-sector investigators and law enforcement affects what you can do

Domain 13: Professional ORC Case Development

Case development is the capstone. It asks whether you can assemble structure, intelligence, digital evidence, surveillance and legal compliance into a coherent package.

  • Organizing evidence so the story of the operation is clear
  • Showing links between individuals, incidents and the broader network
  • Preparing material that supports referral, recovery or prosecution

Key Takeaway

Domain 13 is not a separate body of facts so much as a test of whether Domains 1 through 12 work together. Revisit it last, and use it to find the gaps in everything you studied before it.

For a sense of where this skill set leads professionally, see CORCI Jobs and the CORCI Salary Guide. Neither the credential nor any agency listing guarantees employment or endorsement, so treat career value as something you build, not something the certificate delivers on its own.

Sequencing the 13 Areas in Your Prep

Since the exam is a single timed assessment with no verified weights, the sensible approach is to move from foundations to application rather than to cram by guesswork. This is the one place where we get tactical about study structure, and it is deliberately tied to the domain order above. The cycle in Domain 3 and the legal limits in Domain 12 act as bookends.

Week 1

Foundations

  • Domain 1 (structures) and Domain 3 (intelligence cycle) so later topics have a frame
  • Skim Domain 12 now to understand the boundaries you will keep hitting
Week 2

Digital collection

  • Domains 2, 4, 5, 6 and 7 together, since OSINT, privacy, cyber, auction and social media evidence overlap heavily
  • Practice explaining how a single suspect could be traced across all five
Week 3

Physical operations and analysis

  • Domains 8, 9, 10 and 11: deception, boosters, fencing and surveillance
  • Connect each back to the online evidence from Week 2
Week 4

Integration and review

  • Full pass through Domain 12 and Domain 13 with the whole picture in mind
  • Timed practice on the practice test site to rehearse working across a three-hour sitting

Adjust the pace to your own background. An experienced loss-prevention investigator may move quickly through Domains 1, 9 and 10 and slow down on OSINT and legal fundamentals; someone from a cyber background will likely do the opposite. For a read on relative difficulty, see How Hard Is the CORCI Exam?, and for a condensed reference, the CORCI Cheat Sheet.

Exam Logistics That Shape Your Preparation

Several verified logistics should influence how you study.

  • One attempt. The standalone exam page describes a single attempt within a one-year exam license. That raises the stakes of readiness and argues against sitting the exam to "see what it's like."
  • Three hours, online proctoring. You will work under identity checks and monitoring from your own location, so rehearse in conditions that resemble that setup.
  • 70% threshold. Board certification requires at least 70% on course sections and on the final online exam, plus eligibility documentation and payment of all fees. That is a passing threshold, not an observed pass rate.
  • Eligibility paths. The current professional program lists a bachelor's degree or higher plus one year, an associate degree plus three years, or a high-school diploma or equivalent plus five years of relevant investigative or intelligence work. Details are in CORCI Requirements.
  • Cost. The current standalone exam offer is USD 450, and the full training bundle is USD 1397. Payment plans, study materials and tuition are not additional universal exam fees. See CORCI Certification Cost for the breakdown.
License is not renewal: The one-year exam license is a booking and access period. It is not a verified certification-renewal cycle, and current renewal requirements and fees were not verified from the reviewed sources. Confirm renewal expectations directly with McAfee Institute before you plan around them.

Finally, remember what a question bank can and cannot do. Practice questions, including ours, are editorial preparation. They do not replace the training, identity checks, eligibility review, proctoring or the issuer's own assessment. Use them to find weak spots across the 13 areas, then return to your official course material to close the gaps. Scheduling questions are covered in CORCI Exam Dates, and the bigger value question in Is the CORCI Certification Worth It?

Frequently Asked Questions

Are the 13 domains official CORCI exam domains?

No. They are editorial preparation headings organized from topics named in the official curriculum narrative. They are not official module titles or scored domains, and the issuer has not published an exam blueprint or weights.

How many questions are on the CORCI exam?

The current question count and scored/unscored split are unverified. The standalone exam page publishes a three-hour time limit, online proctoring, one attempt and a one-year exam license. Ignore older figures that circulate in brochures or forums.

What score do I need to pass?

The current published board-certification policy requires at least 70% on course sections and on the final online examination, along with eligibility documentation and payment of all fees. This is a passing threshold, not an observed pass rate.

Is the Associate designation a different exam?

No. McAfee Institute's associate policy describes the same training curriculum and proctored examination, with experience distinguishing professional status. Moving from associate to professional does not require retraining or retesting.

Do the 40 hours and 35 CPE credits describe the exam?

No. Those figures describe the training program. They are not an exam timer or a question count. The standalone exam page lists a three-hour limit.

Ready to pass your CORCI exam?

Put this into practice with free CORCI questions across every exam domain.