Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA

ISACA Advanced in AI Risk

The ISACA Advanced in AI Risk (AAIR) certification empowers experienced IT risk professionals to lead on AI risk. It validates your ability to assess and manage AI-related risks across the enterprise, integrate AI risk into governance frameworks, and guide management through the evolving AI regulatory landscape. Earning AAIR positions you to turn AI risk into a strategic leadership capability.

Exam formatComputer-based
DeliveryPSI
Free questions507

Content last reviewed 30 July 2026 · Up to date

The certification

What ISACA Advanced in AI Risk proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

3domains
16objectives
133concepts
US $459exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The ISACA Advanced in AI Risk (AAIR) certification is a practice-driven credential designed for experienced IT risk professionals. It expands and applies your existing expertise to the unique challenges of artificial intelligence, equipping you to confidently assess and manage AI risk across the enterprise. The program focuses on three key practice areas: AI Risk Governance and Framework Integration, AI Life Cycle Risk Management, and AI Risk Program Management.

By earning AAIR, you demonstrate the strategic skills needed to guide management in addressing AI-related risks, safeguarding your organization from potential financial and reputational harm. The certification validates your ability to work cross-functionally, recommend responses to AI risk, and develop a deep understanding of AI technologies and their challenges. It is a globally recognized credential that showcases your existing risk expertise while preparing you for the future of AI.

AAIR is built on ISACA's trusted expertise in risk and information systems control, providing a rigorous and relevant credential for professionals who want to lead in the AI era. The certification proves to employers that you can add immediate and lasting value to the enterprise by turning AI risk into a leadership capability.

Who it’s for

This certification is for experienced IT risk professionals who hold a qualifying designation such as CISA, CISM, CRISC, CGEIT, CDPSE, or another recognized global designation. It is designed for those who want to specialize in AI risk management and lead their organizations through the complexities of AI adoption. The ideal candidate has proven experience in IT risk or advisory roles and is ready to apply that expertise to the unique challenges of AI. This includes professionals who assess, implement, maintain, or audit AI systems and want to validate their skills in managing AI-related risks and opportunities.

Recommended experience

Candidates should have proven experience in IT risk or advisory roles, as the credential is designed to enhance the expertise of certified IT risk professionals. Active holders of CISA, CISM, CRISC, CGEIT, CDPSE, or other recognized certifications; Proven experience in IT risk or advisory roles; Experience working cross-functionally to address IT risk

The syllabus

What you’ll learn

Every domain and objective ISACA measures, with the weight they carry on the exam.

The official ISACA exam outline · checked 30 July 2026 · See the source

AI Risk Governance and Framework Integration
  • AI Models, Frameworks, Strategies, and Use Cases
  • AI Organizational Processes and Alignment
  • AI Ownership, Oversight, and Accountability
  • AI Policies, Procedures, and Organizational Training
  • AI Regulatory Compliance and Legal Considerations
  • AI Trustworthiness, Ethical and Societal Implications (e.g., ESG)
6 objectives · 174 free questions · 37 pages
AI Life Cycle Risk Management
  • AI Design, Development/Procurement, and Documentation
  • AI Model Training, Testing, and Validation
  • AI Implementation, Maintenance, and Decommissioning
  • AI Data and Asset Management
4 objectives · 140 free questions · 30 pages
AI Risk Program Management
  • AI Risk Scenario Identification and Assessment (e.g., threats, vulnerabilities, and attacks)
  • AI Risk Treatment Strategies
  • AI Controls Management (e.g., Evaluation, Selection, Validation)
  • AI Risk Metrics, Monitoring, and Reporting
  • AI Supply Chain Risk Management (e.g., third party resources)
  • AI Incident Response, BIA, Business Continuity, and Disaster Recovery
6 objectives · 193 free questions · 42 pages
On the day

The exam itself

Everything ISACA publishes about sitting it, and nothing we inferred.

Prerequisites

Hold one of the following ISACA certifications: CISA, CISM, CRISC, CGEIT, or CDPSE.

CertificationISACA Advanced in AI Risk
Exam formatComputer-based
Questions90 questions
DeliveryPSI
PricingUS $459
After you pass

Where this credential goes next

The path ISACA lays out, how the credential is kept, and where to book.

Step-by-step path to ISACA Advanced in AI Risk

PrerequisiteHold one of the following ISACA certifications: CISA, CISM, CRISC, CGEIT, or CDPSE.
ISACA Advanced in AI Risk badgeCredential earnedISACA Advanced in AI Risk Certification
Renewal and maintenance

ISACA certifications require renewal through earning CPE credits. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISACA

Exam registration

Register for the exam through PSI, ISACA’s authorized testing partner.

Schedule your exam

Visit the official ISACA certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does AAIR relate to other ISACA AI certifications like AAIA and AAISM?

AAIR is part of ISACA's Advanced in AI series, alongside AAIA (Advanced in AI Audit) and AAISM (Advanced in AI Security Management). While AAIA focuses on AI auditing and AAISM on AI security management, AAIR is specifically designed for IT risk professionals to manage AI-related risks.

Do I need to earn a lower-tier ISACA certification before taking the AAIR exam?

Yes. To qualify for AAIR, you must already hold one of the qualifying designations listed by ISACA, such as CISA, CISM, CRISC, CGEIT, CDPSE, or another recognized global designation. This is a mandatory prerequisite.

How do I schedule my AAIR exam?

After registering and paying the exam fee, log in to your ISACA Account, click 'Certification & CPE Management', then 'Schedule Your Exam' or 'Visit Exam Website'. You will be taken to the PSI dashboard to schedule your exam. Appointments are available up to 90 days in advance.

What are the requirements for online proctored testing?

Online proctored exams are available, but residents of India, Mainland China, and Hong Kong cannot use live remote proctoring and must take the exam at a testing center. You must check system compatibility before registering.

What is the retake policy for the AAIR exam?

The official source does not specify a retake policy for the AAIR exam. Please refer to the ISACA Terms of Use for Exams for detailed information on retake policies.

Is there a hands-on or lab component in the AAIR exam?

The official source does not mention a hands-on or lab component. The exam consists of 90 questions covering three domains.

How soon will I receive my exam results?

The official source does not specify the timeline for receiving exam results. Please refer to the Exam Candidate Guide for details.

What job roles does the AAIR certification map to?

AAIR is designed for experienced IT risk professionals, including those in IT risk or advisory roles, who want to specialize in AI risk management. It is for professionals who assess, implement, maintain, or audit AI systems.

Can I recertify by passing a different ISACA exam?

ISACA certifications require renewal through earning CPE credits. The official source does not specify whether passing a different exam can renew the AAIR certification.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 507 questions, free, no account needed.