ISACA launches AAIR certification for AI risk and governance

ISACA introduces the AAIR certification, aimed at equipping professionals to govern AI effectively amidst rising adoption and risks.

  • Monday, 27th April 2026 Posted 2 weeks ago in by Sophie Milburn

ISACA, a global organisation focused on digital trust, has introduced the Advanced in AI Risk (AAIR) certification. The credential is aimed at professionals working in audit, risk, security, privacy, and compliance, with a focus on developing skills for governing AI systems.

The launch comes amid differing levels of AI adoption and preparedness across European organisations. According to ISACA’s 2026 AI Pulse Poll, 59% of digital trust professionals are unsure about their organisation’s ability to shut down an AI system during a security incident. These results indicate gaps in operational readiness and accountability for AI systems.

AI risk is increasingly being treated as a business and governance issue rather than solely a technical one, with attention at board level. The absence of established governance structures may create regulatory and reputational risks, particularly in light of the forthcoming EU AI Act, which introduces requirements for oversight and accountability.

ISACA’s findings highlight gaps in governance practices. For example, 33% of organisations do not require employees to disclose AI usage, while 38% assign responsibility for AI risk to a board or executive-level role. This suggests variability in how organisations manage oversight of AI activity.

The AAIR certification is designed for experienced IT risk professionals looking to build expertise in AI governance. It covers areas such as governance framework integration, lifecycle risk management, and risk programme management, with an emphasis on assessing AI-related risks and communicating them to stakeholders and regulators.

To be eligible, candidates must already hold one of 25 specified certifications, including CISA, CISM, or CRISC. Supporting materials such as an online review course and a review manual are available for preparation.

Overall, as AI becomes more embedded in business processes, certifications like AAIR are positioned to support the development of governance and risk management capabilities needed to address associated challenges.

Sophos' latest report highlights the escalating identity security challenges, with high breach rates and costly recoveries.
Black Kite and Sayari have partnered to combine cyber risk data with corporate and supply chain intelligence for third-party risk management.
AHEAD expands its European presence through an acquisition, a senior appointment, and new facilities to support its international operations.
SonicWall has introduced the NSv XS, a subscription-based virtual firewall designed for small and distributed environments, offering enhanced...
By integrating the Alteryx One platform, the Marine Conservation Society has enhanced its data processing, driving meaningful environmental...

State of the channel 2026: navigating the AI era

Posted 4 days ago by Sophie Milburn
The latest GTIA report reveals AI's dominant role in the future of IT service provision across the UK and Ireland.
63% report operational downtime while manual IT/OT coordination continues to slow response.

Integris expands global reach with acquisition

Posted 1 week ago by Sophie Milburn
Integris has acquired First Focus to expand its MSP footprint and broaden services for SMB customers.