AAIR prerequisites: which certifications qualify

Updated September 20, 2026

AAIR has an eligibility gate, but it is the most accommodating of ISACA’s three AI credentials. Where AAISM requires CISM or CISSP specifically, and AAIA requires CISA or an audit designation, AAIR accepts a broad range of risk, security, audit and accounting credentials.

Many people are already eligible without realising it.

What qualifies

ISACA’s own designations:

  • CISA — Certified Information Systems Auditor
  • CISM — Certified Information Security Manager
  • CRISC — Certified in Risk and Information Systems Control
  • CGEIT — Certified in the Governance of Enterprise IT
  • CDPSE — Certified Data Privacy Solutions Engineer

Plus approved external designations, including:

  • CRMP — Certified Risk Management Professional
  • CIA — Certified Internal Auditor
  • CISSP
  • CPA — US, Canadian and Japanese designations
  • CGMA
  • ACCA
  • PMI-RMP — PMI Risk Management Professional
  • and further equivalents on ISACA’s qualification page

Check your specific credential against ISACA’s current list before paying — the recognised set is defined by ISACA and can change. Note also that your qualifying designation must remain active for your AAIR to stand.

Why the broad list makes sense

AAIR is a risk credential, and AI risk lands on a wide range of desks: IT risk, enterprise risk, internal audit, privacy, security and project risk. Rather than insisting on one route in, ISACA has recognised that the people being asked to quantify and treat AI risk come from all of them.

The practical consequence is that AAIR is the most accessible of the three AI credentials for someone who holds a professional designation but not the specific one its siblings demand.

What is expected but not enforced

The questions assume you work in risk. Practically:

  • You are comfortable with likelihood, impact, appetite, threshold and treatment
  • You have maintained a risk register and reported to people above you
  • You can distinguish a risk from an issue, and a control from an intention

You do not need to be technical. No coding, no configuration, no mathematics. The lifecycle domain is the most technical-sounding and is only 21% of the exam.

What it costs

Exam fee — ISACA memberUS$459
Exam fee — non-memberUS$599
Application processing feeUS$50 after passing
Eligibility period after registering6 months to sit
Window to apply after passing5 years

Two clocks. Registering starts a six-month window to sit the exam — register when you are ready to study, not when the idea appeals. Passing starts a five-year window to apply for the credential, with the US$50 fee.

The US$140 member saving covers a meaningful share of ISACA membership, so price it before booking if you are not already a member.

If you hold none of these

The list is long enough that this is less common than for AAISM or AAIA. If you genuinely hold nothing on it:

CRISC is the most natural destination if risk is your field, and it makes you eligible afterwards.

Something ungated. If the goal is AI risk knowledge rather than an ISACA credential, CompTIA SecAI+ has no enforced prerequisite and covers overlapping governance, risk and control material from a security perspective.

Choosing between the three ISACA AI credentials

They divide by role, not by difficulty:

CredentialForGate
AAISMSecurity managersCISM or CISSP
AAIAAuditorsCISA or audit designation
AAIRRisk professionalsBroad list

Pick by what you are accountable for: securing it, assuring it, or quantifying and treating its risk. Holding more than one is possible but the overlap is substantial — most people should pick the one matching their role.

Before you book

  1. Verify your designation is on ISACA’s current list and is active.
  2. Price ISACA membership against the US$140 saving.
  3. Try the free sample questions.
  4. Read the programme management guide — at 42% it is the largest domain, and if that material feels foreign, budget the full six weeks.