ISACA · AAIR
Validates expertise in managing AI-related risks across three practice areas: AI risk governance and framework integration, AI risk program management, and AI lifecycle risk management, covering AI vulnerability evaluation, impact assessment, and risk lifecycle navigation.
Practice Questions
598
≈ 3 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Feb 2026
This AAIR practice exam follows how ISACA weights the real Advanced in AI Risk exam. AI Risk Program Management is the heaviest domain at 42 percent, AI Risk Governance and Framework Integration carries 37 percent, and AI Life Cycle Risk Management the remaining 21 percent, so the 598-question bank gives each domain matching depth across vulnerability evaluation, impact assessment, and risk lifecycle judgment.
On test day you get 90 questions and 150 minutes through PSI, at an authorized test center or online proctored, and you need a scaled 450 on ISACA's 200-to-800 range, which is weighted by question difficulty rather than a straight percentage. AAIR is an advanced credential, not an entry point: certification requires an existing qualifying credential such as CISA, CISM, CRISC, CGEIT, CDPSE, or an accepted equivalent like CISSP. Registration costs $459 for ISACA members and $599 for non-members and opens a six-month window to sit the exam.
Because the exam only launched in 2025, scenario judgment matters more than memorized definitions, and the hardest questions ask you to weigh governance, life cycle, and program-management concerns against each other in realistic organizational settings. Start with the 30 free questions to benchmark yourself, then work through the full 598-question bank in short timed sessions until your accuracy holds steady across all three domains.
The ISACA Advanced in AI Risk (AAIR™) certification is an AI-focused IT risk management credential designed to validate advanced expertise in identifying, evaluating, and managing risks that arise from artificial intelligence adoption within organizations. It covers three core practice areas: AI Risk Governance and Framework Integration, AI Risk Program Management, and AI Life Cycle Risk Management. Together, these domains address the full spectrum of AI risk—from establishing governance structures and embedding AI risk into enterprise frameworks, to executing risk programs, evaluating AI-specific vulnerabilities, conducting impact assessments, and navigating risk throughout the AI development and deployment lifecycle.
The AAIR credential is part of ISACA's suite of Advanced AI certifications, alongside the Advanced in AI Audit (AAIA) and Advanced in AI Security Management (AAISM). Unlike these related credentials, AAIR specifically equips professionals to work cross-functionally, recommend risk responses, and guide senior management in safeguarding organizations from financial, reputational, and operational harms associated with AI integration. The certification is currently in beta, with a full launch anticipated for Q2 2026.
AAIR is intended for experienced IT risk and advisory professionals who already hold a recognized risk or security certification and are seeking to extend their expertise into AI-specific risk management. Eligible professionals must hold at least one active credential from the following: CISA, CISM, CRISC, CGEIT, CDPSE (ISACA credentials), or CRMP, CRMA, CGRC, CISSP, CERP, CRCM, or PMI-RMP (global designations). Because the program does not cover foundational IT risk concepts, it is best suited for mid-to-senior-level practitioners who already operate in risk management, compliance, governance, or advisory roles and need structured knowledge to address AI's unique risk profile.
Typical candidates include IT Risk Managers, Enterprise Risk Officers, AI Governance Leads, Chief Risk Officers, and Compliance Managers working in industries where AI adoption is accelerating—such as financial services, healthcare, technology, and government. It is also relevant for consultants who advise organizations on responsible AI adoption and integration strategies.
Candidates must hold at least one active qualifying credential at the time of application. Accepted ISACA credentials include CISA, CISM, CRISC, CGEIT, and CDPSE. Globally recognized designations that also qualify include CRMP, CRMA, CGRC, CISSP, CERP, CRCM, and PMI-RMP. These prerequisites are non-negotiable, as the AAIR program is explicitly designed to build on existing foundational IT risk knowledge rather than introduce it.
Beyond holding a qualifying credential, candidates should have practical professional experience working in IT risk management, AI governance, compliance, or a closely related advisory function. Familiarity with enterprise risk frameworks (such as COBIT, NIST, or ISO 31000), AI concepts including machine learning and generative AI models, and cross-functional risk communication will help candidates engage effectively with the curriculum and exam content.
The AAIR exam consists of scenario-based multiple-choice questions delivered in a proctored setting. The exam duration is 150 minutes. Scoring uses a scaled scoring model with a maximum score of 800 points, and the passing score is 450 out of 800—consistent with the scoring methodology used across ISACA's Advanced AI certification suite. The exact number of scored questions has not been published by ISACA as of the time of writing, as the certification is currently completing its beta phase ahead of a full Q2 2026 launch.
ISACA's Advanced AI exams are delivered online with remote proctoring available. Exam fees are estimated at approximately USD 575 for ISACA members and USD 760 for non-members, with an additional USD 50 application fee and annual maintenance fees of USD 45 (members) and USD 85 (non-members). Candidates are advised to check the official ISACA credentialing page for confirmed question counts, delivery options, and final pricing once the exam officially launches.
As organizations across industries accelerate AI adoption, demand for professionals who can rigorously manage AI-related risks is growing rapidly. AAIR holders are positioned for roles such as AI Risk Manager, Enterprise AI Governance Lead, Chief Risk Officer, AI Compliance Manager, and senior risk consultant specializing in responsible AI. These roles are emerging in regulated industries—including financial services, healthcare, and government—where AI governance requirements are being codified through regulations such as the EU AI Act and U.S. executive orders on AI.
Salary data for AI risk professionals in the United States ranges from approximately USD 90,000 to over USD 210,000 annually, depending on role, industry, and geography. ISACA-certified professionals have historically commanded a salary premium of 10–20% over non-certified peers, according to the Robert Half Salary Guide and Global Knowledge IT Skills and Salary Report. AAIR complements existing ISACA credentials—particularly CRISC—by adding a specialized AI risk layer that distinguishes holders in a market where general IT risk expertise is common but AI-specific risk governance skills remain scarce.
5 sample questions with answers and explanations. The full bank has 598 questions, enough for 3 full-length practice exams.
Preview — answers shown1. An insurance company implements NIST AI RMF MANAGE 3.2 for their claims processing system that uses a pre-trained natural language processing model from a third-party vendor. Which monitoring activity is specifically required for pre-trained models? (Select one!)
Explanation
NIST AI RMF MANAGE 3.2 explicitly requires that pre-trained models are monitored as part of regular AI system monitoring. Organizations deploying third-party pre-trained models remain accountable for system performance and trustworthiness. Pre-trained models can experience drift, adversarial vulnerabilities, or unexpected behaviors in deployment contexts differing from training environments. Organizations cannot delegate accountability by claiming vendor responsibility. Initial validation without ongoing monitoring fails to detect post-deployment issues. Monitoring must track performance metrics, fairness characteristics, security posture, and alignment with intended use.
2. A multinational corporation implements NIST AI RMF GOVERN 6.1 policies to address third-party AI risks. The policy must cover intellectual property concerns when using third-party foundation models. Which risk should be prioritized in the policy documentation? (Select one!)
Explanation
NIST AI RMF GOVERN 6.1 specifically requires policies to address third-party AI risks including intellectual property infringement. Copyright infringement from training data represents a significant legal and reputational risk as many foundation models may have been trained on copyrighted materials without proper licensing. Latency issues are operational concerns not related to intellectual property. Version control conflicts are technical management issues. User interface incompatibility is an integration challenge unrelated to the intellectual property risks that GOVERN 6.1 explicitly addresses.
3. An organization implements NIST AI RMF MAP 2.2 to document knowledge limits and human oversight requirements. The system is a medical diagnostic AI that identifies potential cancerous lesions in radiology images. Which information should be prioritized in the documentation to meet this sub-category requirement? (Select one!)
Explanation
MAP 2.2 requires documenting knowledge limits and human oversight to provide sufficient information for risk-based decisions. For medical diagnostic AI, this means clearly defining scenarios where the system's reliability decreases and mandating human expert review. Knowledge limits might include image quality thresholds, rare condition detection, or edge cases. Computational requirements relate to infrastructure planning rather than knowledge limits. Source code locations address technical management but not operational boundaries. Marketing materials focus on capabilities rather than limitations and oversight needs required for safe deployment.
4. Cygnus Pharmaceuticals discovers their clinical trial recruitment AI exhibits statistically significant disparate impact against candidates over age 50, with the unprivileged group receiving positive outcomes at 65 percent of the rate of younger candidates. The ethics board evaluates whether this violates fairness standards. According to the Four-Fifths Rule, does this ratio indicate potential discrimination? (Select one!)
Explanation
The Four-Fifths Rule states that if the unprivileged group receives positive outcomes at less than 80 percent of the rate of the privileged group, this indicates potential disparate impact requiring further investigation. A ratio of 0.65 falls below the 0.8 threshold, suggesting potential discrimination that must be evaluated and justified. There is no 0.5 threshold in fairness metrics—the standard is 0.8. Ratios below 1.0 do not automatically indicate discrimination since some disparity may be statistically justified. While the Four-Fifths Rule originated in employment law, it is widely applied across AI fairness evaluation including healthcare, lending, and other domains where protected characteristics matter.
5. A data science team discovers that training data for their hiring AI contains historical biases from past discriminatory practices. Which bias type from NIST's taxonomy is present at this stage? (Select one!)
Explanation
NIST identifies systemic bias as being present in datasets, organizational norms, and society, including historical inequities reflected in training data. This is a data collection stage bias where the dataset captures past discriminatory practices. Computational bias arises from statistical issues like non-representative samples during model development. Human-cognitive bias involves how individuals interpret AI outputs. Algorithmic bias occurs during model development when design choices reinforce existing biases. The historical discrimination in training data is systemic bias at the data collection stage.
ISACA runs a zero-tolerance policy on exam fraud. If you sit the AAIR exam using memorized or leaked questions and ISACA's forensic review flags the pattern, your result gets nullified and the certification itself can be permanently revoked, not just the score. Because AAIR is still a newer credential, ISACA is watching its early cohort of test-takers closely for exactly this kind of abuse.
The honest path costs nothing to start: 598 AAIR practice questions on CertCompanion, 30 free, each with an explanation of the AI risk reasoning ISACA is actually testing, not just the letter answer. You walk out of the real exam able to explain your reasoning to an employer, which a memorized dump can never give you.
US $459 for ISACA members and $599 for non-members, plus a $50 application processing fee when you apply for certification after passing. Registration opens a six-month eligibility window to take the exam.
90 questions in 150 minutes. The exam is computer-based, delivered through PSI at an authorized test center or via remote proctoring.
450 on ISACA's 200-to-800 scaled range. Scoring is weighted by question difficulty, so 450 does not translate to a fixed percentage of correct answers.
You must already hold a qualifying credential such as CISA, CISM, CRISC, CGEIT, or CDPSE, or an accepted global certification like CISSP or CIA. AAIR is designed as an advanced follow-on, not a first certification.
Three domains: AI Risk Program Management (42%), AI Risk Governance and Framework Integration (37%), and AI Life Cycle Risk Management (21%).
ISACA publishes the AAIR Review Manual in digital and print formats, plus an official questions, answers, and explanations database with a 200+ question pool. Many candidates pair those with a larger practice bank to pressure-test readiness before booking.
No. Dumps recycle unverified, often outdated content, and using leaked exam material violates ISACA's exam candidate agreement. Realistic practice questions with explanations build the scenario judgment the AAIR exam actually tests.
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
Blockchain Fundamentals Certificate
Blockchain-Fund · 599 questions
$17.99
One-time access to this exam