ISACA AI certification path
Pick the one that matches your existing role: AAIA if you audit, AAIR if you manage risk, AAISM if you manage security. None of the three is an entry-level credential, despite the AI framing — they assume you already work in governance, risk or assurance and are extending into AI.
The three certificates
| Exam | For | Core weighting |
|---|---|---|
| AAIA | Auditors | AI Operations 46%, AI Governance and Risk 33%, AI Auditing Tools and Techniques 21% |
| AAIR | Risk professionals | AI Risk Program Management 42%, AI Risk Governance 37%, AI Life Cycle Risk 21% |
| AAISM | Security managers | AI Technologies and Controls 38%, AI Governance 31%, AI Risk Management 31% |
They are siblings, not a sequence
This is the most common misunderstanding. AAIA, AAIR and AAISM are not three levels of the same thing. They are three professional lenses on the same subject, and the right one is determined by your job title rather than your experience level.
- AAIA asks how you would obtain assurance. The right answer is usually the one an auditor could evidence, not the one that sounds most thorough.
- AAIR asks how you would run an AI risk programme. The right answer usually concerns accountability, escalation and what changes as a result.
- AAISM asks which control removes the mechanism of an attack. The right answer is usually the one a security manager can implement and demonstrate.
Someone who audits AI should take AAIA, not all three. Holding all three signals confusion rather than depth.
Why they are not entry-level
The AI framing makes these look like a way into governance for technical people. They are not.
The questions assume you already know what a risk register is, who owns a risk, what evidence of operating effectiveness looks like, and why a policy document is not a control. AI is the subject matter; governance is the discipline being tested. A developer who understands models perfectly but has never sat in a risk committee will find the reasoning alien.
If you want to move from engineering into governance, these exams are a poor first step. Learn the governance discipline first.
Where they genuinely help
Where these certificates earn their keep is the reverse direction: experienced governance professionals who now have AI systems in scope and no framework for thinking about them.
If you have audited IT for a decade and have just been handed a portfolio of AI systems, AAIA gives you a structured way to approach them — what to inventory, what evidence to ask for, what a significant finding looks like when the system is non-deterministic. That is a real gap, and it is the gap these exams fill.
Choosing between them if your role spans two
Some people genuinely sit across risk and security, or audit and risk. If you have to choose:
- Take the one matching the team you report into, since that is the vocabulary your work product must use.
- If that is still ambiguous, take the one matching what your organisation is worst at, because the study will be most useful.
How long each takes
For someone already working in the relevant discipline: four to six weeks. The AI content is the new part; the governance reasoning should already be familiar. Without that background, these are not four-week exams and no amount of reading substitutes for having done the work.
What to do next
Read the exam format guide for the one matching your role, then take the free 20-question practice test in that section. If the governance reasoning feels foreign rather than the AI content, that is a signal about which gap to close first.
If you are weighing AAISM against a practitioner credential, see AAISM vs SecAI+. The exam changes tracker notes that all three ISACA AI certificates are new.