AAIR certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
AI Risk Governance And Framework Integration
The “AI Risk Governance And Framework Integration” objective treats objectives, assigned accountability, risk significance, reliability of support, sequence of action, and judgments the evidence can sustain as an end-to-end responsibility. Preparation is successful when the candidate can assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case. It leads into “AI Life Cycle Risk Management” in the published outline.
Question notes
Prepare “AI Risk Governance And Framework Integration” within the credential's wider flow, since several answers may sound reasonable until the responsible role and objective are identified. A defensible response accounts for a weak factual basis, ambiguous accountability, unsupported conclusions, or action taken against a secondary issue rather than the source of risk. Its support should include a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Use the numeric section weight for relative priority, not as a promise about assessment inventory.
Preparation tips
Rehearse “AI Risk Governance And Framework Integration” under a realistic constraint. Use this exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Then test unreliable support, unclear ownership, conclusions reached too early, or action taken against a secondary issue rather than the underlying risk. Decide what must change by inspecting a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Identify the evidence that would reveal this mistake when handling “AI Life Cycle Risk Management”.
AI Life Cycle Risk Management
Within AAIR — ISACA Advanced in AI Risk, “AI Life Cycle Risk Management” examines objectives, responsible parties, risk significance, evidence quality, sequence of action, and defensible conclusions. Candidates must assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case. In the published sequence, it follows “AI Risk Governance And Framework Integration” and precedes “AI Risk Program Management”.
Question notes
For “AI Life Cycle Risk Management,” the assessment context matters: several answers may sound reasonable until the responsible role and objective are identified. Failure mode to test: a weak factual basis, ambiguous accountability, unsupported conclusions, or a response disconnected from the source of risk. Verification should include a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Section metadata communicates relative emphasis without supporting an inferred question total.
Preparation tips
Make preparation for “AI Life Cycle Risk Management” observable. Practical exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Ask a reviewer to test for poor supporting information, uncertain decision rights, findings beyond the evidence, or an intervention focused on what is visible instead of the source of risk. Give the reviewer traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Review the final proof from the perspective of later work in “AI Risk Program Management”.
AI Risk Program Management
In the AAIR — ISACA Advanced in AI Risk outline, “AI Risk Program Management” brings together objectives, responsible parties, risk significance, evidence quality, sequence of action, and judgments the evidence can sustain. The practical standard is to establish decision ownership, determine the necessary evidence, and choose the action appropriate to that stage of the case. It draws on work established in “AI Life Cycle Risk Management”.
Question notes
Question or task wording for “AI Risk Program Management” may hide its decisive constraint because question context may require separating management ownership from independent assurance responsibility. Required negative check: unverified inputs, unclear responsibility, judgment before analysis is complete, or a remedy that changes the symptom while leaving the underlying risk. Supporting evidence: traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Section metadata carries the published emphasis; assessment composition can still vary within that boundary.
Preparation tips
Keep a short decision journal for “AI Risk Program Management.” Complete this exercise: Write a short case, identify the responsible role and evidence needed, compare plausible responses, and justify which action comes first. Record whether you detected or prevented a weak factual basis, ambiguous accountability, unsupported conclusions, or an intervention focused on what is visible instead of the risk driving the case. Attach a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Use evidence from “AI Life Cycle Risk Management” as an input to the final review.
