AAIR AI risk governance and frameworks

Updated September 20, 2026

AI Risk Governance and Framework Integration is worth 37% of AAIR — around 33 of the 90 questions. ISACA splits it into six areas, and the through-line is integration: AI risk governance should extend what the enterprise already has, not sit beside it as a parallel structure.

AI models, frameworks, strategies and use cases

Working literacy, not technical depth:

  • Training versus inference, and why behaviour derives from data rather than written logic
  • Why outputs are probabilistic, so “acceptable” is a threshold not a binary
  • That use cases carry very different risk profiles — an internal drafting assistant and a credit decisioning model are not comparable

The practical skill is classifying a use case by risk, because almost everything downstream is proportionate to that classification.

Organisational processes and alignment

AI risk that lives in its own committee, register and process fails. This area is about connecting it to what exists: the enterprise risk framework, the existing register, established appetite statements, and current approval paths.

A scenario describing a standalone AI risk process disconnected from enterprise risk management is describing a weakness.

Ownership, oversight and accountability

ISACA cares about this more than almost anything, and it recurs across all three of its AI credentials:

  • A named accountable individual, not “the AI team” or “IT”
  • Oversight with genuine authority to intervene, including to stop a deployment
  • Evidence that oversight actually operates — records of reviews, and of decisions to override

The distinction to hold: a policy requiring oversight demonstrates intent; records of reviews demonstrate operation. Exam answers reward the second.

Policies, procedures and organisational training

What an AI policy set contains — acceptable use, model approval, data use in training, third-party model use, human oversight requirements — and who needs training on it. Note that training is named explicitly: a policy nobody has been trained on is a partial control.

And the sequencing rule that appears repeatedly in ISACA questions: inventory before policy. A policy written without knowing what is in use will not fit what is in use.

You are not expected to recite legislation. You are expected to know the consistent shape of what regulators ask for:

  • An inventory, classified by risk
  • Impact assessment before deployment, proportionate to that risk
  • Human oversight of consequential decisions
  • Documentation of data sources, limitations and testing
  • Transparency toward affected people
  • Records sufficient for later audit

Plus legal questions specific to AI: whether training data was lawfully obtained and for what purpose, what rights exist in model outputs, and where liability sits when a third-party model causes harm.

Trustworthiness, ethical and societal implications

Named explicitly by ISACA, including ESG — and this has no equivalent in most general risk credentials. Treat these as things that get evidenced:

ConcernWhat demonstrates it
FairnessBias testing across affected groups, before and after deployment
ExplainabilityExplanations to affected people, and an appeal route
Societal and ESG impactImpact assessment covering wider effects, not just enterprise risk
TrustworthinessDocumented limitations, honestly stated

Sample questions

Question 1. An enterprise has created a separate AI risk committee with its own register, appetite statement and reporting line, independent of enterprise risk management. Which is the MOST significant concern?

  • A. The committee may not meet frequently enough
  • B. The committee may be too small to be effective
  • C. A parallel structure means AI risk is not integrated with enterprise risk, producing inconsistent appetite and blind spots
  • D. The committee’s name does not reflect its scope
Show answer

Answer: C

AI risk governance that runs parallel to enterprise risk management produces inconsistent appetite and prevents AI risk being weighed against other enterprise risks, which is why integration is the objective. Meeting frequency, committee size and naming are administrative matters by comparison.

Question 2. An organisation's AI policy requires human oversight of all consequential decisions. The risk practitioner wants to assess whether the control operates. Which evidence is BEST?

  • A. Records of oversight reviews, including evidence of overrides
  • B. The approved policy document stating the requirement
  • C. A training completion report showing staff read the policy
  • D. The vendor’s description of the system’s oversight features
Show answer

Answer: A

Records of reviews, including instances where a reviewer actually overrode the system, demonstrate that oversight operates rather than merely being required. The policy states intent, a training completion report shows awareness, and the vendor’s description addresses capability rather than your operation.

Question 3. A business unit wants to deploy an AI system that will influence loan approvals. Which should the risk practitioner establish FIRST?

  • A. The model’s reported accuracy on the vendor’s benchmark
  • B. The hosting cost over three years
  • C. The vendor’s market share among comparable lenders
  • D. The risk classification of the use case, which determines the governance required
Show answer

Answer: D

Classifying the use case by risk determines the proportionate governance that follows, and a decision affecting individuals’ access to credit sits at the higher end. Model accuracy, hosting cost and vendor market share are inputs to later decisions but none of them determines the governance the deployment requires.

What to practise

Take one AI use case and write six lines: its risk classification, who is accountable, which existing enterprise process it plugs into, what policy applies, what regulators would expect, and what ethical or societal impact it carries. Those six lines are this domain, and the exercise transfers directly to the programme management domain.