AAIR vs CRISC: how they differ
CRISC and AAIR are not competing credentials. CRISC is one of the designations that makes you eligible for AAIR, and the two are designed to stack.
The useful comparison is therefore about content: what does AAIR add to a risk professional who already holds CRISC?
The relationship
| CRISC | AAIR | |
|---|---|---|
| Position | ISACA’s IT risk credential | AI specialisation on top |
| Eligibility | Work experience in IT risk | A recognised designation, CRISC included |
| Subject | IT risk and control | AI risk specifically |
| Largest domain | Varies by CRISC’s structure | AI Risk Program Management (42%) |
| Questions | Longer paper | 90 |
CRISC establishes that you can identify, assess, respond to and monitor IT risk, and that you understand controls. AAIR asks whether you can do that when the asset behaves probabilistically, derives its logic from data, changes without a deployment, and depends on a supply chain you cannot inspect.
What transfers completely
Your method. Risk identification, assessment, thresholds, treatment, controls evaluation and selection, metrics, monitoring and reporting — all of it. That is the architecture of AAIR’s largest domain, and you already have it.
The question style transfers too. If you are used to ISACA’s BEST/FIRST/MOST framing and the advise-the-business perspective, that is a genuine head start over candidates meeting it fresh.
What is genuinely new
A different threat catalogue. Poisoning, backdoors, model extraction, inversion, evasion, prompt injection — and crucially, which lifecycle stage each targets. A threat against training data is not mitigated by anything you do at the endpoint.
Risk that moves without anyone acting. Drift. Traditional IT risk changes when something changes. An AI system’s risk profile shifts as the world diverges from its training data, with no deployment and no incident. Periodic reassessment stops being good practice and becomes a necessary control.
Thresholds as measurements. “Secure” is not a threshold for a model. Accuracy, fairness disparity and groundedness are. Expressing AI risk appetite quantitatively is a real adjustment.
A supply chain you cannot inspect. Pretrained models, third-party datasets, model APIs. Due diligence on a model provider is not vendor assessment as you know it, and the change management problem is severe: a provider can update a hosted model and alter your production behaviour without notice.
Governance content at 37%. AI models and frameworks, organisational alignment, ownership and accountability, policies and training, regulatory compliance and legal considerations, and trustworthiness, ethics and societal implications including ESG. That last area has no CRISC equivalent at all.
Decommissioning. Retiring an AI system raises questions retiring an application does not — what happens to the model, the training data, and the decisions it already made.
How much new study for a CRISC holder?
Four to six weeks, and the allocation is counterintuitive.
Do not spend it on the lifecycle domain because it sounds technical — that is only 21%. Spend it on what is different about AI inside the risk disciplines you already know. Read the programme management domain not as new material but as a familiar checklist where every item has an AI-specific twist.
Which if you hold neither?
If you are choosing a first credential, CRISC. It is broader, more widely recognised, and it makes you eligible for AAIR afterwards. AAIR on its own is not available to you anyway.
If AI risk is already your job and you hold a different qualifying designation — CISM, CISA, CISSP, PMI-RMP and others all count — you can go straight to AAIR without CRISC.
The sibling credentials
ISACA has three AI credentials and they divide by role, not by level:
- AAISM — security management, gated on CISM or CISSP
- AAIA — audit, gated on CISA or an equivalent audit designation
- AAIR — risk, with the broadest eligibility of the three
They overlap in subject matter and differ in perspective. Pick by what you are accountable for: securing it, assuring it, or quantifying and treating its risk.