Advanced in AI Risk - AAIR
Exam General Information
Review the exam status, fees, eligibility, structure, delivery, scheduling, venue, retake, and renewal rules before studying.
Official Scope and Verification
This lesson is mapped to the verified Advanced in AI Risk - AAIR outline. Official sources and public status were rechecked on 2026-07-13. Provider pages remain authoritative for late-breaking blueprint, availability, scheduling, price, language, delivery, and retake changes.
Current ISACA AAIR certification with official domain percentages, subtopics, and other skills tested.
Official Objective Map
| Domain or objective area | Published weight | Key objective groups | Official source |
|---|---|---|---|
| AI Risk Governance and Framework Integration | 37% | AI Models, Frameworks, Strategies, and Use Cases; AI Organizational Processes and Alignment; AI Ownership, Oversight, and Accountability; AI Policies, Procedures, and Organizational Training; AI Regulatory Compliance and Legal Considerations; AI Trustworthiness, Ethical and Societal Implications | ISACA official AAIR exam content outline |
| AI Life Cycle Risk Management | 21% | AI Design, Development/Procurement, and Documentation; AI Model Training, Testing, and Validation; AI Implementation, Maintenance, and Decommissioning; AI Data and Asset Management | ISACA official AAIR exam content outline |
| AI Risk Program Management | 42% | AI Risk Scenario Identification and Assessment; AI Risk Treatment Strategies; AI Controls Management; AI Risk Metrics, Monitoring, and Reporting; AI Supply Chain Risk Management; AI Incident Response, BIA, Business Continuity, and Disaster Recovery | ISACA official AAIR exam content outline |
| Other Skills Tested | Published without a scored percentage | Evaluate risk related to AI models and solutions including design, suitability, algorithms, training, drift, and AI life cycle; Facilitate integration of AI risk management into an enterprise risk management framework and risk programs; Develop and implement an AI risk management framework, including roles, accountability, policies, procedures, and risk tolerance; Conduct risk assessments to identify and classify risks associated with AI; Develop and recommend risk treatment strategies for identified AI risks; Assess compliance with applicable AI-related regulations, laws, frameworks, standards, and guidelines; Integrate AI risk considerations into existing governance programs; Integrate AI risk considerations into existing risk register and control taxonomies; Evaluate AI use cases based on the organization's risk appetite; Monitor and test organizational processes to identify AI risks; Collaborate with stakeholders to develop and integrate AI risk concepts into enterprise-wide awareness training; Capture AI risk considerations in enterprise risk metrics and reporting, including board, management, and operations reporting; Conduct or evaluate threat and vulnerability assessments on AI projects and programs; Collaborate with stakeholders to integrate AI risk scenarios into the enterprise incident management program; Continuously assess and monitor the risk landscape for emerging AI risk; Evaluate controls to manage AI-related risk within the organization's risk tolerance; Advise on AI-related risk within contracts and service agreements, including data usage and intellectual property; Evaluate AI risk as part of supply chain risk management; Collaborate with stakeholders to address AI trustworthiness and impacts including ethics, bias, privacy, safety, and environmental, social, and governance implications; Leverage AI to support the risk management program, including risk profile, reporting, evaluation, risk models, and analysis; Integrate AI-related risk considerations into the change management process; Incorporate AI-related risk considerations into incident response, BIAs, the BCP, and DRP; Assess human oversight controls at critical decision points for risk and AI impact | ISACA official AAIR exam content outline |
Authoritative Sources for This Scope
- ISACA official AAIR exam content outline - Official source; accessed 2026-07-13.
Exam General Information At A Glance
This is the administrative starting point for Advanced in AI Risk - AAIR. The information was reviewed on July 14, 2026. Providers and testing vendors can change prices, appointment inventory, delivery methods, languages, identity rules, and retake terms, so follow the official links below and recheck the checkout screen before paying.
| Planning item | Current guidance |
|---|---|
| Credential and current status | Current in the local verified catalog. |
| Exam or assessment code | No separate public exam code is stated in the local verified title; register by the full credential name. |
| Who should take it | Candidates whose role and experience match the official exam page and objective guide. |
| Requirements and prerequisites | Active CRISC or another qualified advanced risk designation is required; verify the exact accepted-designation list before paying. |
| When to take it | Registration is continuous. After payment, eligibility lasts six months; appointments may be scheduled as early as 48 hours after payment and are displayed up to 90 days ahead. |
| Registration and scheduling | Register from the exact ISACA credential page and schedule through ISACA's current remote-proctor or test-center partner. |
| Where to take it / exam venues | PSI live remote proctoring or an authorized PSI test center. AAIA is test-center-only for residents of India, mainland China, and Hong Kong under the current page. |
| Fee and payment | USD 459 for ISACA members or USD 599 for non-members. Registration creates a six-month eligibility period; the separate certification application fee is USD 50 after passing. |
| Duration and exam structure | 90 multiple-choice questions in 150 minutes. |
| Scoring, results, and passing rule | The provider does not publish a fixed raw passing percentage for this track in the public materials reviewed. Follow the current pass/fail or scaled-score rule in the candidate guide and score report. |
| Languages and accommodations | Choose only a language shown in the registration flow. Request accommodations through the provider or testing vendor before booking; approval may take time. |
| Identification, check-in, and equipment | Use an accepted, unexpired government ID whose name matches the registration profile. For online delivery, run the system test and prepare a private, compliant room; test centers supply their own equipment. |
| Cancellation and rescheduling | Reschedule without penalty at least 48 hours before the appointment and within the six-month eligibility period. |
| Retake rule and repeat fees | After the first failed ISACA attempt, wait 30 days; after the second and third failures, wait 90 days. A maximum of four attempts is allowed in a rolling 12-month period, and each retake requires a new fee. |
| Validity, expiration, and renewal | Maintain the qualifying base credential and the advanced AI credential, report the required AI-domain CPE, pay annual maintenance fees, and follow the ISACA ethics and audit rules. |
What To Verify Before You Pay Or Enroll
- The credential is still available in your country, and the exam code matches this course.
- The final checkout amount, currency, tax, voucher, membership discount, bundle, and refund terms are acceptable.
- Your chosen online or test-center appointment is available on the date you need; a provider offering an exam does not guarantee a seat at every venue.
- Your legal name matches the accepted identification, and any accommodation request has been approved before scheduling.
- You understand the exact attempt, waiting-period, cancellation, rescheduling, no-show, expiration, and renewal rules shown by the provider.
Official Registration And Policy Sources
- ISACA Credentialing - Official ISACA credential catalog.
- ISACA Advanced in AI Audit - Official AAIA credential page.
- ISACA Advanced in AI Risk - Official AAIR credential page.
- ISACA Advanced in AI Security Management - Official AAISM credential page.
Start here if you are learning on your own. This module turns Advanced in AI Risk - AAIR into a concrete study route: what the credential is for, what you need before you begin, where to verify cost and retake rules, and how to practice without getting lost in product trivia or stale third-party claims.
Administrative facts were reviewed for this course build on July 14, 2026. Fees, retake rules, testing vendors, beta status, language availability, delivery format, and renewal rules can change, so use the official ISACA links below as the final source before you pay or schedule.
What This Credential Measures
Advanced in AI Risk - AAIR belongs in the AI audit, AI risk, AI security management, and assurance practices area. In practical terms, it asks whether you can recognize the right AI concept, choose an appropriate provider capability or governance action, and explain why a tempting alternative does not fit the scenario.
Local catalog summary: Current verified credential track. Current ISACA AAIR certification with official domain percentages, subtopics, and other skills tested.
- Best audience: governance, risk, audit, privacy, and security professionals responsible for trustworthy AI.
- Exam mindset: look for role or learner goal, data source, risk level, required effort, and outcome words before choosing an answer or completing a task.
- Not enough by itself: memorizing product names. You need to know when the product, workflow, or control is appropriate.
Track-Specific Study Focus
- Read the exact credential title first. Many AI credentials are role-based, so the same AI concept can be tested differently for an engineer, architect, auditor, business leader, teacher, or administrator.
- Translate every objective into a real scenario with a user, data source, risk constraint, and expected output.
- Separate durable AI principles from provider product names so you can still reason when a product name changes.
- Use an AI system inventory, risk classification, control mapping, evidence collection, and monitoring plan.
- Connect AI risks to data protection, transparency, accountability, vendor management, incident response, and change control.
- Study NIST AI RMF and OWASP GenAI Security as general references, then map them to the credential provider objectives.
What You Need To Get Started
- Official preparation source. Download or bookmark the official exam guide, course page, exam topics, or credential outline before using third-party notes.
- AI vocabulary. Be comfortable with AI, ML, GenAI, model, prompt, token, embedding, inference, grounding, RAG, fine-tuning, hallucination, bias, evaluation, and human oversight.
- Credential vocabulary. Build a short glossary for the ISACA product names, roles, concepts, policies, and artifacts that appear in the credential. For each one, write what problem it solves and when it is not enough.
- Security basics. Know identity, least privilege, privacy, data classification, and why AI prompts and outputs need appropriate protection for the people and setting involved.
- Practice environment. Use official labs, free tiers, sandboxes, demos, or documentation walkthroughs only where they help you understand a scenario. Do not spend money on cloud resources without a budget limit.
- Error notebook. Track every missed practice item by writing the requirement word that changed the answer, not just the correct option.
Cost, Retake Rules, And Registration Checks
Do not assume that the fee or retake rule you saw in an old blog post still applies. Before paying for Advanced in AI Risk - AAIR, open the official ISACA credential page and confirm the current checkout amount, taxes, vouchers, attempt rules, waiting period after a failed attempt, cancellation or reschedule window, online-proctor rules, ID requirements, expiration period, and renewal process. Where a public official page does not list a fixed price, treat the testing vendor checkout or provider portal as the authoritative price source.
| Question to verify | Where to check | Why it matters |
|---|---|---|
| How much does it cost? | Official credential page or testing-vendor checkout. | The public price may vary by country, membership, voucher, bundle, tax, or beta program. |
| What happens if I fail? | Retake policy, exam terms, testing-vendor rules, or credential FAQ. | Some programs require a waiting period, charge again, limit attempts, or treat beta exams differently. |
| Can I reschedule or cancel? | Scheduling confirmation, testing-vendor policy, or provider exam policy. | Missing the allowed window can forfeit the fee even when you were otherwise ready. |
| What exam format and identification rules apply? | Official exam page and appointment confirmation. | Delivery, allowed materials, check-in, and identification requirements are provider-specific. |
| How long is it valid? | Certification renewal or continuing education page. | You may need renewal assessments, continuing education, membership, or a recertification exam. |
How To Study The Official Objectives
- Convert each objective into a question. If the guide says "identify", ask: "Given this scenario, what should I identify?"
- Build one example per objective. Use a simple workplace case, not an abstract definition.
- Separate concept from tool. First decide whether the question is about data, model behavior, governance, implementation, or operations. Then choose the tool.
- Practice adjacent choices together. Mix similar options so you can explain why the second-best answer is not best.
- Review weak topics twice. Re-read the official page, write a one-paragraph explanation, and answer a mixed quiz before marking the topic complete.
Example: Reading A Scenario
Scenario: An organization deploys an AI decision aid. The governance answer should identify owner, purpose, data, risk level, controls, evidence, monitoring, and appeal or review path.
Reasoning: Identify the role, business outcome, data source, operational constraint, and risk level. Then apply this lens: Select the audit, risk, or security management action that produces evidence and reduces AI system risk.
Common trap: Treating governance as a policy document instead of operational controls with evidence.
Self-Study Cadence
- Pass 1 - orient. Read the official page, this general-information module, and the five other modules in this six-module course. Write the top objectives from memory.
- Pass 2 - map. Create a two-column map: scenario cue on the left, correct concept or provider capability on the right.
- Pass 3 - drill. Use flashcards and quizzes. Do not mark an answer "known" until you can reject at least two distractors.
- Pass 4 - simulate. Do timed mixed sets. Practice flagging uncertain questions, making the best available choice, and moving on.
- Pass 5 - remediate. Spend the last review cycle only on missed topics, policy details, and confusing service pairs.
Official Links
- ISACA Credentialing - Official ISACA credential catalog.
- ISACA Advanced in AI Audit - Official AAIA credential page.
- ISACA Advanced in AI Risk - Official AAIR credential page.
- ISACA Advanced in AI Security Management - Official AAISM credential page.