AAIR prerequisites: which certifications qualify
AAIR has an eligibility gate, but it is the most accommodating of ISACA’s three AI credentials. Where AAISM requires CISM or CISSP specifically, and AAIA requires CISA or an audit designation, AAIR accepts a broad range of risk, security, audit and accounting credentials.
Many people are already eligible without realising it.
What qualifies
ISACA’s own designations:
- CISA — Certified Information Systems Auditor
- CISM — Certified Information Security Manager
- CRISC — Certified in Risk and Information Systems Control
- CGEIT — Certified in the Governance of Enterprise IT
- CDPSE — Certified Data Privacy Solutions Engineer
Plus approved external designations, including:
- CRMP — Certified Risk Management Professional
- CIA — Certified Internal Auditor
- CISSP
- CPA — US, Canadian and Japanese designations
- CGMA
- ACCA
- PMI-RMP — PMI Risk Management Professional
- and further equivalents on ISACA’s qualification page
Check your specific credential against ISACA’s current list before paying — the recognised set is defined by ISACA and can change. Note also that your qualifying designation must remain active for your AAIR to stand.
Why the broad list makes sense
AAIR is a risk credential, and AI risk lands on a wide range of desks: IT risk, enterprise risk, internal audit, privacy, security and project risk. Rather than insisting on one route in, ISACA has recognised that the people being asked to quantify and treat AI risk come from all of them.
The practical consequence is that AAIR is the most accessible of the three AI credentials for someone who holds a professional designation but not the specific one its siblings demand.
What is expected but not enforced
The questions assume you work in risk. Practically:
- You are comfortable with likelihood, impact, appetite, threshold and treatment
- You have maintained a risk register and reported to people above you
- You can distinguish a risk from an issue, and a control from an intention
You do not need to be technical. No coding, no configuration, no mathematics. The lifecycle domain is the most technical-sounding and is only 21% of the exam.
What it costs
| Exam fee — ISACA member | US$459 |
| Exam fee — non-member | US$599 |
| Application processing fee | US$50 after passing |
| Eligibility period after registering | 6 months to sit |
| Window to apply after passing | 5 years |
Two clocks. Registering starts a six-month window to sit the exam — register when you are ready to study, not when the idea appeals. Passing starts a five-year window to apply for the credential, with the US$50 fee.
The US$140 member saving covers a meaningful share of ISACA membership, so price it before booking if you are not already a member.
If you hold none of these
The list is long enough that this is less common than for AAISM or AAIA. If you genuinely hold nothing on it:
CRISC is the most natural destination if risk is your field, and it makes you eligible afterwards.
Something ungated. If the goal is AI risk knowledge rather than an ISACA credential, CompTIA SecAI+ has no enforced prerequisite and covers overlapping governance, risk and control material from a security perspective.
Choosing between the three ISACA AI credentials
They divide by role, not by difficulty:
| Credential | For | Gate |
|---|---|---|
| AAISM | Security managers | CISM or CISSP |
| AAIA | Auditors | CISA or audit designation |
| AAIR | Risk professionals | Broad list |
Pick by what you are accountable for: securing it, assuring it, or quantifying and treating its risk. Holding more than one is possible but the overlap is substantial — most people should pick the one matching their role.
Before you book
- Verify your designation is on ISACA’s current list and is active.
- Price ISACA membership against the US$140 saving.
- Try the free sample questions.
- Read the programme management guide — at 42% it is the largest domain, and if that material feels foreign, budget the full six weeks.