Artificial intelligence is moving from experimental projects into everyday business operations. Organizations now use AI for customer service, cybersecurity, financial analysis, software development, fraud detection, decision support, and many other business processes. As adoption grows, however, so does the difficulty of understanding and controlling AI-related risk.
The ISACA AAIR Certification, formally known as ISACA Advanced in AI Riskâ„¢ (AAIRâ„¢), was created for professionals who need to evaluate these risks from an enterprise perspective. Rather than focusing only on how AI models work technically, AAIR examines how organizations govern AI, evaluate risk throughout the AI lifecycle, implement controls, manage third parties, respond to incidents, and communicate AI risk to management.
For experienced IT risk and governance professionals, this makes AAIR particularly interesting. AI does not eliminate traditional risk management principles, but it introduces new variables such as model drift, algorithmic bias, training-data quality, external foundation models, explainability, human oversight, and rapidly changing regulatory expectations.
If you are actively preparing for the exam, our ISACA AAIR Advanced in AI Risk course can be used alongside official ISACA materials to organize your review of the major exam domains and AI risk concepts.
This guide explains what the AAIR certification covers, who should consider it, the technologies and risk concepts behind the exam, and how to build an effective preparation strategy.
What Is the ISACA Advanced in AI Risk (AAIR) Certification?
AAIR is an advanced professional certification focused on identifying, assessing, governing, treating, and monitoring artificial intelligence risk within an enterprise.
It is important to understand the word advanced in the certification name. AAIR is not designed as an introductory artificial intelligence credential for someone with no professional risk background. ISACA positions the certification as an extension of existing expertise in areas such as IT risk, governance, assurance, cybersecurity, compliance, and enterprise risk management.
In practical terms, an AAIR-certified professional should be able to participate in questions such as:
- Should the organization approve a proposed AI use case?
- What risks could an AI model introduce to customers or business operations?
- Who is accountable for an AI system and its decisions?
- How should AI risk be incorporated into the enterprise risk register?
- What controls are appropriate for high-risk AI applications?
- How should model drift or unexpected behavior be detected?
- What happens if a third-party AI provider changes its model?
- How should AI incidents be integrated into incident response and business continuity processes?
- How should management measure and report AI risk?
That enterprise perspective is one of the main differences between AAIR and a purely technical AI or machine learning certification.
AAIR Exam Overview
According to current ISACA exam information, the AAIR examination contains 90 multiple-choice questions and allows candidates 150 minutes to complete the exam.
| Exam Item | AAIR Details |
|---|---|
| Certification | ISACA Advanced in AI Risk (AAIR) |
| Exam Questions | 90 multiple-choice questions |
| Exam Duration | 2.5 hours / 150 minutes |
| Domain 1 | AI Risk Governance and Framework Integration – 37% |
| Domain 2 | AI Life Cycle Risk Management – 21% |
| Domain 3 | AI Risk Program Management – 42% |
| Exam Languages | English, Spanish, and Chinese; candidates should confirm current availability with ISACA |
| Current Member Exam Fee | US$459 |
| Current Nonmember Exam Fee | US$599 |
| Testing Provider | PSI testing centers and remote proctoring where available |
| Exam Eligibility Period | Six months after registration |
| ISACA Passing Score | 450 or higher on ISACA’s 200–800 scaled scoring system |
Exam fees, testing policies, accepted certifications, languages, and scheduling rules can change. Candidates should always check the current ISACA AAIR page and Candidate Guide before registering.
Before beginning a study schedule, it can also help to review a structured AAIR exam preparation resource so that your practice is aligned with the relative weighting of each domain.
Who Is Eligible for the AAIR Certification?
One detail beginners need to pay particular attention to is eligibility. Unlike many entry-level AI certificates, AAIR requires candidates to already hold an approved professional designation.
The current AAIR Candidate Guide recognizes a range of qualifying credentials. These include major ISACA certifications such as CISA, CISM, CGEIT, CRISC, and CDPSE, as well as selected credentials from other professional organizations, including certain accounting, audit, cybersecurity, risk, and compliance certifications.
The accepted list is broader than only ISACA credentials and may be updated over time. Therefore, someone considering the AAIR exam should verify their exact certification against ISACA’s latest eligibility list rather than assuming that professional experience by itself is sufficient.
This prerequisite tells us quite a lot about the intended level of the certification: AAIR assumes that the candidate already understands basic risk and governance concepts and is now learning how to apply them specifically to artificial intelligence.
AAIR Exam Domains Explained
The ISACA AAIR exam is divided into three domains. The weighting is significant because almost half of the exam is concentrated on AI risk program management.
Domain 1: AI Risk Governance and Framework Integration – 37%
This domain connects artificial intelligence with enterprise governance. A company cannot manage AI effectively by treating every model as an isolated technology project. AI needs ownership, accountability, policies, risk thresholds, oversight structures, and alignment with the organization’s broader objectives.
Topics include:
- AI models, frameworks, strategies, and business use cases
- Organizational processes and business alignment
- AI ownership and accountability
- Governance roles and oversight responsibilities
- AI policies and procedures
- Employee awareness and training
- Legal and regulatory considerations
- AI trustworthiness
- Ethical and societal implications
A candidate should understand that governance is more than creating an AI policy document. Effective governance defines who can approve AI use, who accepts residual risk, how exceptions are handled, how performance is reviewed, and how AI objectives remain aligned with business strategy.
Domain 2: AI Life Cycle Risk Management – 21%
AI risk changes throughout the life of a system. The risks present while selecting a model may be very different from those that emerge after the system has operated for a year.
This domain therefore examines risk from initial design through retirement.
- AI design and development
- AI procurement and third-party solutions
- Model and system documentation
- Model training
- Testing and validation
- Implementation and deployment
- Maintenance and ongoing monitoring
- AI system decommissioning
- Data and AI asset management
Lifecycle thinking is especially important with AI because models are not necessarily static. Data distributions change, business environments change, vendors update their models, and user behavior can evolve. A model that met its risk requirements at deployment may not remain acceptable indefinitely.
Domain 3: AI Risk Program Management – 42%
This is the largest AAIR exam domain and is arguably where traditional risk-management skills and AI-specific knowledge meet most directly.
The domain includes:
- AI risk scenario identification
- Threat and vulnerability assessment
- AI risk assessment
- Risk treatment strategies
- AI control selection and evaluation
- Control validation
- Risk metrics and key risk indicators
- Continuous monitoring and management reporting
- AI supply chain and third-party risk
- AI incident response
- Business impact analysis
- Business continuity and disaster recovery considerations
For exam preparation, candidates should spend significant time learning how to move from identifying a technical AI problem to expressing that problem as an enterprise risk scenario and then selecting an appropriate treatment. Because this is the highest-weighted area, it should also receive substantial attention when working through AAIR study materials and practice questions.
Technical AI Concepts AAIR Candidates Should Understand
AAIR is a risk certification rather than a machine learning engineering exam, so candidates are not expected to spend the exam writing Python code or training neural networks. At the same time, effective AI risk management requires enough technical understanding to recognize where risk originates.
Model Drift and Data Drift
A machine learning model is generally trained using historical data. If real-world data later changes substantially, model performance can deteriorate. This is commonly discussed through concepts such as data drift and model drift.
From a risk perspective, the important question is not simply whether drift exists. A risk professional needs to determine how drift is detected, what thresholds trigger investigation, who receives alerts, and whether a model should be restricted or removed from production when performance falls outside acceptable limits.
Bias and Fairness
Training data can contain historical patterns that produce unfair outcomes when used by automated systems. Bias may also enter through model design, feature selection, data collection, or the way users interact with a system.
AAIR candidates should therefore think beyond the model itself and consider governance, testing, documentation, human review, monitoring, and escalation procedures.
Explainability and Transparency
Some AI systems produce outputs that are difficult for users or management to explain. This may create significant risk when AI influences lending, hiring, healthcare, financial decisions, cybersecurity responses, or other high-impact processes.
The appropriate degree of explainability depends on the use case, affected stakeholders, legal environment, and consequences of an incorrect decision.
Generative AI and Hallucination Risk
Large language models can generate convincing responses that are incomplete or incorrect. When organizations use generative AI for customer support, research, coding, legal analysis, or internal decision support, unreliable output can become a business risk rather than simply a technical limitation.
Controls may include grounding, restricted use cases, output validation, human review, monitoring, approved data sources, and clear accountability for decisions based on AI-generated information.
Prompt Injection and AI Security Threats
Generative AI applications introduce attack scenarios that traditional web applications were not originally designed to handle. Prompt injection, sensitive information disclosure, malicious model inputs, poisoned data, adversarial manipulation, and insecure integration with external tools are examples of risks that may need to be evaluated.
AAIR does not turn a risk professional into a penetration tester, but candidates should understand how technical vulnerabilities can translate into confidentiality, integrity, availability, financial, compliance, or reputational risk.
Third-Party and AI Supply Chain Risk
Many enterprises do not build their own foundation models. They consume AI through cloud services, APIs, embedded software, SaaS platforms, open-source models, or specialized vendors.
This creates questions about:
- Data ownership and permitted data use
- Intellectual property
- Service availability
- Model changes made by vendors
- Subprocessors and downstream suppliers
- Security responsibilities
- Contractual protections
- Exit strategies
- Model and software provenance
For many organizations, third-party AI risk may ultimately be more important than the risk associated with internally developed models.
AI Risk Frameworks Worth Understanding
AAIR candidates should be comfortable with the idea of integrating AI risk into established enterprise risk frameworks rather than creating a completely independent process for every AI initiative.
NIST AI Risk Management Framework
The NIST Artificial Intelligence Risk Management Framework (AI RMF) is one of the most useful public resources for studying structured AI risk management. Its core is organized around four functions:
- Govern – establish policies, responsibilities, processes, and organizational culture for AI risk.
- Map – understand the AI system, context, stakeholders, intended use, and potential impacts.
- Measure – analyze and evaluate AI risks using appropriate metrics and testing.
- Manage – prioritize risks, implement treatments, monitor outcomes, and respond to changing conditions.
These concepts fit naturally with the governance, lifecycle, assessment, monitoring, and treatment topics covered by AAIR.
ISO/IEC 42001
ISO/IEC 42001 defines requirements for an Artificial Intelligence Management System, often abbreviated as AIMS. It provides organizations with a structured management-system approach for establishing, implementing, maintaining, and continually improving responsible AI governance.
For AAIR students, the value is not necessarily memorizing every clause. It is understanding how AI risk management can be embedded into repeatable organizational processes rather than handled as a collection of one-time technical assessments.
How Is AAIR Different from CRISC, AAIA, and AAISM?
ISACA now has several credentials that touch artificial intelligence, governance, audit, security, and risk. Their objectives overlap in places, but they are not interchangeable.
| Certification | Main Focus | Best Fit |
|---|---|---|
| CRISC | Enterprise IT risk management and information systems controls | IT risk and control professionals |
| AAIR | AI-specific enterprise risk governance and management | Risk, GRC, advisory, and governance professionals responsible for AI risk |
| AAIA | Auditing and assuring AI systems and AI-related processes | IT auditors and assurance professionals |
| AAISM | Managing AI security programs, threats, technologies, and controls | Information security managers and AI security leaders |
A useful way to think about the difference is that AAIR asks how AI risk should be identified and managed, while AAIA concentrates more heavily on assurance and auditing, and AAISM approaches AI from the security-management perspective.
Is the ISACA AAIR Certification Worth It?
The value of AAIR depends heavily on your current role.
For an experienced risk, GRC, audit, cybersecurity, or governance professional who is increasingly being asked to review artificial intelligence initiatives, the certification has a clear practical purpose. It provides a structured way to extend existing professional skills into an area that many organizations are still learning how to govern.
Potential roles that can benefit from AAIR knowledge include:
- AI Risk Manager
- Technology Risk Manager
- Enterprise Risk Professional
- AI Governance Specialist
- GRC Manager
- Technology Risk Consultant
- Responsible AI Program Manager
- Third-Party Risk Manager
- Compliance and Governance Professional
- Cybersecurity Risk Leader
AAIR is less compelling as someone’s first IT certification. Students and early-career professionals who do not yet meet the eligibility requirements may get more value initially from developing foundations in information security, risk management, governance, privacy, cloud computing, and basic AI technologies.
In that situation, AAIR can still be useful as a longer-term career target. Candidates who already meet the eligibility requirements can begin building a structured preparation plan with an ISACA Advanced in AI Risk exam course and then reinforce that knowledge with official documentation and framework references.
How to Prepare for the AAIR Exam
The most effective AAIR preparation should combine technical understanding with risk-management judgment. Simply memorizing definitions is unlikely to be enough for scenario-based questions that ask for the best, most appropriate, or first action.
1. Start With the Official Exam Content Outline
Use the domain percentages to decide how much time to invest in each topic. Domain 3 represents 42% of the exam, so AI risk assessment, treatment, controls, monitoring, third-party risk, and incident management deserve substantial attention.
2. Build an AI Technology Foundation
You do not need to become a data scientist, but make sure you understand terms such as training data, inference, machine learning models, large language models, model validation, drift, hallucination, bias, explainability, adversarial attacks, and human oversight.
3. Think in Terms of Risk Scenarios
When studying an AI problem, ask:
- What asset or business objective is affected?
- What threat or failure could occur?
- What vulnerability or weakness enables it?
- What would the business impact be?
- How likely is the scenario?
- Does the exposure exceed risk appetite?
- Which treatment strategy is most appropriate?
- What residual risk remains?
- Who should accept that residual risk?
This method makes technical AI concepts much easier to connect with traditional enterprise risk management.
4. Study AI Governance as an Enterprise Process
Do not assume every AI problem should be solved by deploying another technical control. Questions involving accountability, policy, risk appetite, executive oversight, business ownership, regulatory obligations, or organizational strategy may require governance solutions first.
5. Use Scenario-Based Practice Questions
ISACA examinations are known for testing professional judgment. Several answers may look reasonable, but one is usually the best response based on governance, risk ownership, business objectives, and the sequence in which actions should occur.
When reviewing AAIR practice questions, spend as much time understanding why the incorrect options are weaker as you spend memorizing the correct answer. This makes practice much more useful than simply counting how many questions you answered correctly.
6. Review Authoritative AI Risk Resources
Resources such as the NIST AI RMF and ISO/IEC 42001 can help candidates understand how AI governance and risk management work outside the exam syllabus. This broader understanding becomes especially useful when answering unfamiliar scenarios.
A Practical Six-Week AAIR Study Plan
| Week | Main Study Focus |
|---|---|
| Week 1 | Review the AAIR exam outline and build foundations in AI models, machine learning, generative AI, and AI terminology. |
| Week 2 | Study Domain 1: governance frameworks, organizational alignment, ownership, policies, accountability, ethics, and regulatory considerations. |
| Week 3 | Study Domain 2: AI design, procurement, training, testing, validation, implementation, monitoring, data management, and decommissioning. |
| Week 4 | Begin Domain 3: AI risk scenarios, assessments, treatment strategies, controls, risk appetite, and residual risk. |
| Week 5 | Complete Domain 3 with monitoring, metrics, reporting, supply chain risk, incident response, BIA, BCP, and disaster recovery. |
| Week 6 | Complete practice questions, revisit weak domains, review frameworks, and practice time management under exam conditions. |
Candidates with less exposure to AI technologies may want to extend this schedule. Experienced CRISC, GRC, or enterprise risk professionals may move faster through general risk topics but should avoid underestimating the AI lifecycle and technical-risk sections.
A useful approach during the final two weeks is to combine official resources with a dedicated AAIR certification preparation course, especially when you need additional repetition in weaker domains.
Common Mistakes When Preparing for AAIR
Focusing Only on Generative AI
ChatGPT and other generative AI platforms receive enormous attention, but AAIR addresses AI risk much more broadly. Candidates should understand machine learning and enterprise AI systems beyond large language models.
Treating Every AI Risk as a Cybersecurity Risk
Security is important, but AI also introduces legal, privacy, operational, ethical, financial, safety, reputational, and governance risks. A strong AAIR candidate considers the complete enterprise impact.
Ignoring Risk Ownership
Technical teams can assess and recommend controls, but risk decisions ultimately need appropriate business ownership and accountability. Understanding this distinction is essential in enterprise risk management.
Ignoring the AI Supply Chain
Modern AI systems often depend on cloud services, external datasets, open-source libraries, commercial APIs, foundation models, and multiple vendors. A risk assessment that looks only at internally controlled components is incomplete.
Memorizing Without Understanding the Sequence
ISACA-style questions often depend on knowing what should happen first. Risk identification normally comes before treatment, business requirements influence control selection, and management decisions should be based on properly assessed risk rather than assumptions.
Does AAIR Require Programming Knowledge?
No advanced programming background is normally necessary to understand the AAIR exam domains. The certification is designed for risk professionals rather than AI developers.
However, candidates should be technically literate enough to communicate with data scientists, cybersecurity teams, architects, legal professionals, model owners, and business stakeholders.
Understanding what model training, validation, inference, APIs, data pipelines, model drift, and generative AI systems actually do makes it much easier to identify meaningful risk rather than relying on abstract terminology.
Frequently Asked Questions About ISACA AAIR
What does AAIR stand for?
AAIR stands for Advanced in AI Risk, an ISACA certification focused on artificial intelligence risk governance, lifecycle risk management, and enterprise AI risk programs.
How many questions are on the AAIR exam?
The current AAIR exam contains 90 multiple-choice questions.
How long is the AAIR exam?
Candidates currently receive 150 minutes, or 2.5 hours, to complete the examination.
Is AAIR suitable for beginners?
AAIR can be studied by anyone interested in AI risk, but the certification itself is designed for experienced professionals and requires an approved qualifying professional designation. Complete beginners should usually develop foundational risk, security, governance, and AI knowledge first.
Is AAIR the same as CRISC?
No. CRISC addresses IT and enterprise technology risk more broadly. AAIR builds on established risk-management principles and applies them specifically to artificial intelligence systems, governance, lifecycle management, and AI-specific risk scenarios.
Does AAIR focus only on generative AI?
No. Generative AI is relevant, but the AAIR syllabus covers the wider field of enterprise artificial intelligence, including AI models, data, lifecycle management, risk frameworks, governance, monitoring, controls, supply chains, and incident management.
Is the ISACA AAIR Certification worth earning?
For professionals already responsible for technology risk, GRC, AI governance, enterprise risk, compliance, or advisory work, AAIR can provide a useful specialization as organizations formalize their AI governance and risk-management programs. Its value is much stronger when combined with existing professional risk experience.
Where can I find additional AAIR exam preparation resources?
In addition to ISACA’s official exam content outline and candidate materials, you can review our AAIR Advanced in AI Risk preparation page for additional study support and exam-focused resources.
Final Thoughts
The rapid adoption of artificial intelligence is changing the job of the technology risk professional. Traditional risk principles still matter, but AI adds difficult questions involving model behavior, data quality, explainability, bias, third-party models, human oversight, lifecycle monitoring, and emerging regulation.
The ISACA AAIR Certification is designed around that intersection between established enterprise risk management and modern artificial intelligence.
For professionals who already have a strong foundation in IT risk or governance, AAIR provides a structured path for developing deeper AI risk expertise. For students and early-career professionals, the certification can serve as a useful roadmap showing which governance, security, risk, and AI skills will become increasingly important as enterprise AI adoption grows.
The key to preparing effectively is not to treat AAIR as a vocabulary exam. Learn how AI systems behave, understand where their risks originate, and then practice connecting those risks to business objectives, governance responsibilities, risk appetite, controls, monitoring, and management decisions.
If AAIR is your next certification goal, combine the official ISACA materials with structured review, scenario-based practice, and a dedicated ISACA AAIR exam preparation course to identify weak areas and build confidence before the exam.
External References and Further Reading
- ISACA – Advanced in AI Risk (AAIR) Official Certification Page
- ISACA – AAIR Exam Content Outline
- ISACA – Official Exam Candidate Guides
- NIST – Artificial Intelligence Risk Management Framework (AI RMF)
- NIST – AI RMF Generative Artificial Intelligence ProfileISO – ISO/IEC 42001 Artificial Intelligence Management Systems

