ISACA · AAIR
Validates expertise in managing AI-related risks across three practice areas: AI risk governance and framework integration, AI risk program management, and AI lifecycle risk management, covering AI vulnerability evaluation, impact assessment, and risk lifecycle navigation.
Practice Questions
598
≈ 3 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Sep 2026
This AAIR practice exam follows how ISACA weights the real Advanced in AI Risk exam. AI Risk Program Management is the heaviest domain at 42 percent, AI Risk Governance and Framework Integration carries 37 percent, and AI Life Cycle Risk Management the remaining 21 percent, so the 598-question bank gives each domain matching depth across vulnerability evaluation, impact assessment, and risk lifecycle judgment.
On test day you get 90 questions and 150 minutes through PSI, at an authorized test center or online proctored (remote proctoring is not offered in India, mainland China, or Hong Kong), and you need a scaled 450 on ISACA's 200-to-800 range, which is weighted by question difficulty rather than a straight percentage. AAIR is an advanced credential, not an entry point: you must already hold one of roughly 25 qualifying designations, including ISACA's CISA, CISM, CRISC, CGEIT, or CDPSE, or an accepted equivalent like CISSP or CIA. Registration costs $459 for ISACA members and $599 for non-members, opens a six-month window to sit the exam, and lets you schedule up to 90 days in advance. After passing, you have five years to apply for certification, which adds a $50 processing fee, then 10 CPE hours a year (30 per three-year cycle) and a $45 member or $85 non-member annual fee to keep it active.
ISACA launched AAIR on April 15, 2026, making it the newest of the three advanced AI credentials, after AAIA for audit and AAISM for security management. Because the question pool is that fresh, scenario judgment matters more than memorized definitions, and the hardest items ask you to weigh governance, life cycle, and program-management concerns against each other in realistic organizational settings. Start with the 30 free questions to benchmark yourself, then work through the full 598-question bank in short timed sessions until your accuracy holds steady across all three domains.
The ISACA Advanced in AI Risk (AAIR™) certification is an AI-focused IT risk management credential designed to validate advanced expertise in identifying, evaluating, and managing risks that arise from artificial intelligence adoption within organizations. It covers three core practice areas: AI Risk Governance and Framework Integration, AI Risk Program Management, and AI Life Cycle Risk Management. Together, these domains address the full spectrum of AI risk—from establishing governance structures and embedding AI risk into enterprise frameworks, to executing risk programs, evaluating AI-specific vulnerabilities, conducting impact assessments, and navigating risk throughout the AI development and deployment lifecycle.
The AAIR credential is part of ISACA's suite of Advanced AI certifications, alongside the Advanced in AI Audit (AAIA) and Advanced in AI Security Management (AAISM). Unlike these related credentials, AAIR specifically equips professionals to work cross-functionally, recommend risk responses, and guide senior management in safeguarding organizations from financial, reputational, and operational harms associated with AI integration. The certification is currently in beta, with a full launch anticipated for Q2 2026.
AAIR is intended for experienced IT risk and advisory professionals who already hold a recognized risk or security certification and are seeking to extend their expertise into AI-specific risk management. Eligible professionals must hold at least one active credential from the following: CISA, CISM, CRISC, CGEIT, CDPSE (ISACA credentials), or CRMP, CRMA, CGRC, CISSP, CERP, CRCM, or PMI-RMP (global designations). Because the program does not cover foundational IT risk concepts, it is best suited for mid-to-senior-level practitioners who already operate in risk management, compliance, governance, or advisory roles and need structured knowledge to address AI's unique risk profile.
Typical candidates include IT Risk Managers, Enterprise Risk Officers, AI Governance Leads, Chief Risk Officers, and Compliance Managers working in industries where AI adoption is accelerating—such as financial services, healthcare, technology, and government. It is also relevant for consultants who advise organizations on responsible AI adoption and integration strategies.
Candidates must hold at least one active qualifying credential at the time of application. Accepted ISACA credentials include CISA, CISM, CRISC, CGEIT, and CDPSE. Globally recognized designations that also qualify include CRMP, CRMA, CGRC, CISSP, CERP, CRCM, and PMI-RMP. These prerequisites are non-negotiable, as the AAIR program is explicitly designed to build on existing foundational IT risk knowledge rather than introduce it.
Beyond holding a qualifying credential, candidates should have practical professional experience working in IT risk management, AI governance, compliance, or a closely related advisory function. Familiarity with enterprise risk frameworks (such as COBIT, NIST, or ISO 31000), AI concepts including machine learning and generative AI models, and cross-functional risk communication will help candidates engage effectively with the curriculum and exam content.
The AAIR exam consists of scenario-based multiple-choice questions delivered in a proctored setting. The exam duration is 150 minutes. Scoring uses a scaled scoring model with a maximum score of 800 points, and the passing score is 450 out of 800—consistent with the scoring methodology used across ISACA's Advanced AI certification suite. The exact number of scored questions has not been published by ISACA as of the time of writing, as the certification is currently completing its beta phase ahead of a full Q2 2026 launch.
ISACA's Advanced AI exams are delivered online with remote proctoring available. Exam fees are estimated at approximately USD 575 for ISACA members and USD 760 for non-members, with an additional USD 50 application fee and annual maintenance fees of USD 45 (members) and USD 85 (non-members). Candidates are advised to check the official ISACA credentialing page for confirmed question counts, delivery options, and final pricing once the exam officially launches.
As organizations across industries accelerate AI adoption, demand for professionals who can rigorously manage AI-related risks is growing rapidly. AAIR holders are positioned for roles such as AI Risk Manager, Enterprise AI Governance Lead, Chief Risk Officer, AI Compliance Manager, and senior risk consultant specializing in responsible AI. These roles are emerging in regulated industries—including financial services, healthcare, and government—where AI governance requirements are being codified through regulations such as the EU AI Act and U.S. executive orders on AI.
Salary data for AI risk professionals in the United States ranges from approximately USD 90,000 to over USD 210,000 annually, depending on role, industry, and geography. ISACA-certified professionals have historically commanded a salary premium of 10–20% over non-certified peers, according to the Robert Half Salary Guide and Global Knowledge IT Skills and Salary Report. AAIR complements existing ISACA credentials—particularly CRISC—by adding a specialized AI risk layer that distinguishes holders in a market where general IT risk expertise is common but AI-specific risk governance skills remain scarce.
5 sample questions with answers and explanations. The full bank has 598 questions, enough for 3 full-length practice exams.
Preview — answers shown1. Contoso Education develops an AI-powered student performance prediction system. Under NIST AI RMF, which characteristic serves as the foundation for all other trustworthy AI characteristics? (Select one!)
Explanation
NIST AI RMF explicitly identifies Valid and Reliable as the foundational characteristic for all other trustworthy AI characteristics. Validation confirms requirements for specific intended use are fulfilled, while reliability means consistent performance without failure. Without validity and reliability, other characteristics cannot be meaningfully assessed—an invalid model cannot be safe, secure, or fair. Safe addresses preventing harm. Secure and Resilient protects against attacks and maintains function under stress. Accountable and Transparent is described as a vertical element cutting across all characteristics but is not the foundation.
2. An attacker queries a production ML model repeatedly with carefully crafted inputs to infer whether specific individuals' data was included in the training dataset. Which privacy attack is being executed? (Select one!)
Explanation
Membership inference attacks determine whether specific data points were included in the training dataset by analyzing model responses to queries. Attackers exploit model overfitting to training data, observing higher confidence on training examples versus unseen data. This threatens individual privacy by revealing training set participation. Model inversion reconstructs training data features from model outputs, attempting to recreate original inputs rather than determine membership. Model extraction steals model parameters, architecture, or functionality through repeated queries without focusing on training data membership. Property inference extracts global properties about the training dataset rather than individual membership. The scenario describes membership determination characteristic of membership inference attacks.
3. According to NIST AI RMF MEASURE 2.11, an organization must evaluate and document which trustworthy AI characteristic specifically addresses systematic differences in outcomes across demographic groups? (Select one!)
Explanation
MEASURE 2.11 specifically addresses fairness and bias evaluation, requiring that fairness metrics be evaluated and results documented to identify systematic differences in outcomes across demographic groups. Fair with Harmful Bias Managed directly addresses equality and equity by managing harmful bias and discrimination. Valid and Reliable focuses on accuracy and consistency. Safe addresses prevention of harm to life, health, property, or environment. Explainable and Interpretable addresses transparency of decision-making mechanisms.
4. An AI risk manager conducts risk identification for a supply chain optimization AI system. According to comprehensive AI risk taxonomies, which risk category encompasses system downtime, latency issues, compatibility problems, and key person dependencies? (Select one!)
Explanation
Operational risks encompass availability (system downtime), performance (latency and throughput issues), integration (compatibility problems), scalability challenges, and key person risk (over-reliance on specific individuals). These risks affect the operational functioning of AI systems in production environments. Model risk relates to accuracy, drift, bias, robustness, and explainability of predictions. Data risk covers quality, privacy, poisoning, provenance, and representativeness issues. Ethical risk addresses fairness, discrimination, transparency, accountability, and human autonomy concerns.
5. Northwind Traders is implementing ISO/IEC 42001 and must prepare documentation before market placement. Which document must justify which Annex A controls are included or excluded from their AI management system? (Select one!)
Explanation
ISO 42001 requires organizations to document a Statement of Applicability that justifies which of the 38 Annex A controls are included and which are excluded based on the organization's context and risk assessment. This is a mandatory requirement under Clause 6 Planning. AI System Impact Assessment evaluates potential impacts but does not justify control selection. Technical Documentation describes the system itself. Risk Treatment Plan addresses how risks are managed but does not justify control applicability.
ISACA runs a zero-tolerance policy on exam fraud. If you sit the AAIR exam using memorized or leaked questions and ISACA's forensic review flags the pattern, your result gets nullified and the certification itself can be permanently revoked, not just the score. Because AAIR only launched in April 2026, ISACA is watching its first cohorts of test-takers closely for exactly this kind of abuse.
The honest path costs nothing to start: 598 AAIR practice questions on CertCompanion, 30 free, each with an explanation of the AI risk reasoning ISACA is actually testing, not just the letter answer. You walk out of the real exam able to explain your reasoning to an employer, which a memorized dump can never give you.
US $459 for ISACA members and $599 for non-members, plus a $50 application processing fee when you apply for certification after passing. Registration opens a six-month eligibility window to take the exam, and you can schedule up to 90 days in advance.
90 questions in 150 minutes. The exam is computer-based, delivered through PSI at an authorized test center or via remote proctoring (remote proctoring is not available in India, mainland China, or Hong Kong).
450 on ISACA's 200-to-800 scaled range. Scoring is weighted by question difficulty, so 450 does not translate to a fixed percentage of correct answers.
You must already hold one of roughly 25 qualifying designations. ISACA credentials that qualify include CISA, CISM, CRISC, CGEIT, and CDPSE; accepted global certifications include CISSP, CIA, PMI-RMP, and several accounting designations like CPA and ACCA. AAIR is designed as an advanced follow-on, not a first certification.
Three domains: AI Risk Program Management (42%), AI Risk Governance and Framework Integration (37%), and AI Life Cycle Risk Management (21%).
ISACA launched AAIR on April 15, 2026, with registration, the AAIR Review Manual, the official questions database, and the online review course available from day one. It is the newest of ISACA's three advanced AI certifications.
All three are ISACA advanced AI credentials with the same prerequisite model, but they target different roles: AAIA extends audit skills (built for CISA holders), AAISM covers AI security management (CISM territory), and AAIR focuses on AI risk governance, risk programs, and lifecycle risk, the natural next step for CRISC and risk professionals.
Report at least 10 CPE hours a year and 30 over each three-year cycle, follow ISACA's Code of Professional Ethics, and pay the annual maintenance fee of $45 for members or $85 for non-members, due by 1 January each year.
ISACA publishes the AAIR Review Manual in digital and print formats, plus an official questions, answers, and explanations database and an online review course. Many candidates pair those with a larger practice bank to pressure-test readiness before booking.
No. Dumps recycle unverified, often outdated content, and using leaked exam material violates ISACA's exam candidate agreement. Realistic practice questions with explanations build the scenario judgment the AAIR exam actually tests.
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
Blockchain Fundamentals Certificate
Blockchain-Fund · 599 questions
$17.99
One-time access to this exam