AAIR study resources

Updated September 20, 2026

AAIR is about running an AI risk programme. The exam rewards answers concerning accountability, escalation and what actually changes as a result of an assessment — not technical depth. Experienced risk professionals find the AI content the only new part; people without risk experience find the whole framing unfamiliar, and that is the harder gap.

Start with the official material

ISACA’s study material for the certificate. It is a newer credential with limited third-party coverage, so the official resources carry more weight than usual.

The domain weighting. AI Risk Program Management is 42%, AI Risk Governance and Framework Integration 37%, and AI Life Cycle Risk Management 21%. Two-thirds of the exam is programme and governance; only a fifth is life cycle specifics.

Free material worth reading

  • The NIST AI Risk Management Framework. Directly relevant, free, and structured around exactly the govern-map-measure-manage thinking the exam expects.
  • ISO/IEC 42001, if work gives you access.
  • Your own organisation’s risk framework, genuinely. The exam repeatedly asks how AI risk integrates with existing enterprise risk management rather than running alongside it. Reading how your employer actually does this is directly useful preparation.

The thinking the exam rewards

AAIR consistently prefers answers that:

  • Integrate rather than duplicate. AI risk belongs inside the existing enterprise framework, extending the taxonomy, not in a parallel programme with its own reporting line.
  • Put ownership with the business. The accountable owner of the process, not the team that built the model.
  • Offer real options when appetite is exceeded. Treat, transfer, avoid, or formally accept at the right authority. Quietly lowering the rating is not one.
  • Measure outcomes, not activity. Percentage of the inventory assessed and time to remediate beat counts of assessments completed.
  • Fix causes, not symptoms. If units bypass the process because it is slow, tier the process rather than reissue the mandate.

That last one recurs. The exam has a consistent preference for addressing why a control is being avoided.

Worth paying for

ISACA membership, which generally pays for itself through the reduced exam fee.

A practice test for diagnosis. The free 20-question test here is weighted to the published domains.

What to skip

Technical AI depth. You need to understand why non-determinism and emergent behaviour break conventional assurance assumptions. You do not need to build anything.

Braindumps.

Material aimed at AI engineers. Wrong discipline entirely — that content belongs to exams like AI-103.

A sensible order

  1. Read the syllabus and note that programme management plus governance is nearly 80%.
  2. Work through the official material.
  3. Read the NIST AI RMF.
  4. Map your own employer’s risk process onto it, and find where AI would not fit. This is the most useful hour you will spend.
  5. Take the practice test.

Which ISACA certificate?

AAIR is for risk professionals. Auditors want AAIA; security managers want AAISM. See the ISACA AI certification path for why they are siblings rather than a ladder.