I recently passed ISACA’s Advanced in AI Risk (AAIR) exam. For those considering the certification, I’ll briefly explain what it covers and share four lessons from my preparation that may be useful for other candidates. This blog post is also intended for managers, who may be asked to support AAIR training for team members. Understanding the business case and potential return on investment can help justify funding or workload adjustment requests.
What is the AAIR, and how does it compare with the AIGP?
AAIR is part of ISACA’s new suite of AI-focused certifications and focuses on a practitioner’s ability to manage AI-related risk. ISACA members may already be familiar with those offerings, and how they compare. For those who want a direct comparison, ISACA has published useful guidance.
Some business and legal professionals may be more familiar with the Artificial Intelligence Governance Professional (AIGP) certification, administered by the International Association of Privacy Professionals (IAPP), than the AAIR. Since both relate to GRC (Governance, Risk Management, Compliance), they may wonder how the two relate – do they compete or complement? The answer matters for practitioners and managers making time and financial budgeting decisions. My answer: I found them complementary with little duplication. AIGP provides a broad foundation in AI governance, while AAIR is an advanced credential emphasizing applied risk practice.
A quick-and-rough exam comparison may help. Many AIGP questions test the practitioner’s knowledge of AI-focused laws, regulations and broad governance principles. By contrast, virtually all of the AAIR questions on my exam tested for applied judgment: each question posed a realistic scenario and problem. Candidates needed to decide the most appropriate response – whether technical, governance, risk or business-oriented. Both address different, yet essential, dimensions of becoming an effective AI practitioner.
Professionals thinking of pursuing both should also decide on a progression strategy. AIGP can be broadly pursued, including by those new to the field. This fits its status as a foundational certification. By contrast, the “Advanced” in AAIR aptly describes the level of technical knowledge and risk-management acumen needed to pass. AAIR also has more substantial prerequisites: applicants must hold a CISM, CISSP, or other qualifying certification to apply. This signals (correctly in my view) that ISACA sees AI risk management as an extension of established security and IT management principles, instead of something entirely new.
Preparing for the Exam
I spent about 40–50 hours preparing. For anyone considering the AAIR, four preparation lessons stood out:
1. Learn the concepts, not just the vocabulary.
I used ISACA’s study manual and official AI glossary to establish the foundation of my training. But in order to pass a certification exam testing for applied judgment, it would not be enough to simply memorize definitions and rules; I needed to understand how technical concepts – model drift, training data, validation, inference, precision and recall, among others – connected to risk and governance decisions. How I developed that understanding leads to the next lesson.
2. Consider using GenAI as a study coach.
I used Generative AI (GenAI) extensively as a study coach – not to give me answers, but to translate technical concepts, such as those above, into real-world business and governance implications.
For example, ISACA’s official glossary provides a highly technical definition of “Gradient Descent,” an important AI concept. I asked my AI coach for a simpler explanation and, importantly, to clarify why a business leader should care. Rinse-and-repeat that process for other highly technical terms. Building out my AI governance glossary became a foundational part of my study.

I also requested physical-world examples of AI concepts, comparisons among related concepts, and explanations connecting technical issues back to governance and risk management. Used this way, GenAI became an effective interactive guide.
3. Use practice questions as a learning tool, not just an assessment tool.
For me, ISACA’s Questions, Answers & Explanations (QAE) practice exam database was even more useful than the study manual. When I missed a question, I focused on understanding the principles behind the answer rather than memorizing the correct choice. Another QAE practice tip: I answered 70% of the questions open-book, and without a time limit, to help me learn. I took the remaining 30% under test conditions. Using practice exams as both a learning and diagnostic tool helped me better understand AI and build a framework I could apply to unfamiliar questions.
Coincidentally – and for a bit of AI training trivia – the risk of simply memorizing test answers isn’t confined to humans. Look up “overfitting” in an AI glossary and you’ll find out AI sometimes also “trains to pass the test.”
4. Don’t overlook the fundamentals of GRC.
Sixteen-plus years working across cybersecurity, national security, privacy and AI have convinced me of one thing: the principles of governance, risk management, and compliance (GRC) are foundational across these disciplines. My prior CISM and CISSP preparation served me well as I developed a mental framework for tackling AI. The need to clarify risk ownership, implement controls, execute on incident response and make enterprise-level risk tradeoffs all reappeared in this exam. AI may introduce new risks and technical considerations, but the underlying governance principles to meet them still apply. Or to put it another way: “same wine, different glass.”
One unexpected challenge was real-world experience. Sometimes I would read a question, imagine how the situation might actually unfold inside an organization and unconsciously add facts that weren’t part of the exam. Incident response questions were a recurring example. I had to remind myself to answer the question presented – not the more complex scenario unfurling in my head.
AAIR is Worth the Effort
Was seeking the certification worth the effort? For me, the answer is “yes.” I’ve worked with AI-related issues since 2018, but I still found the process highly valuable. It crystallized connections among AI technology, cybersecurity, governance and risk management that I had previously understood on a more instinctive basis. Preparing for the exam acted like a “forcing agent” to help me understand how AI functions within an organization – and to use that knowledge to build out usable solutions to a variety of scenarios.
Similarly, if I were wearing my former manager’s cap, I would support a team member’s decision to seek this credential. Assuming sufficient organizational resources, I would view the training as a worthwhile investment in my team’s organizational and enterprise-level AI risk management capability.
The Takeaway
My primary takeaway is that AAIR requires examtakers to apply judgment across technical, security, governance and business issues.
That ultimately made the preparation worthwhile. Even after working with AI for several years, the process gave me a more integrated way of thinking about how AI systems are designed, deployed, governed and evaluated. Several “aha!” moments that emerged while studying may ultimately become practical guidance I write for business, security and legal professionals navigating AI.
For managers, strengthening organizational judgment may be a useful way to view the return on investment from supporting a colleague’s pursuit of AAIR. The value goes beyond simply enabling one person to earn another certification. According to recent ISACA surveys, organizations have identified major governance gaps in their use of AI. Developing team members who can more effectively connect technical AI issues to security, governance, risk and business decisions can help bridge those gaps.
Finally, everyone learns differently. I value self-study; others may benefit more from a structured boot camp or another approach. Whatever method you choose, I hope these lessons help with your own AI learning journey.
For me, the final, and most important, lesson is simple: the goal isn’t just learning more about AI risk. It’s about exercising better judgment over that risk.
About the author: Robert Kang is a governance consultant and adjunct faculty at the University of Southern California Viterbi School of Engineering and at Loyola Law School, Los Angeles. His focus includes cybersecurity, national security and emerging technologies. Prior to that, Professor Kang served in executive and staff roles at major U.S. organizations in the technology and critical infrastructure industries. He is a licensed attorney and maintains the following certifications: CISM, AAIR, CISSP, AIGP, and CIPP/US.