ISACA spent the last fourteen months quietly building out an entire second layer of certifications, all aimed at one problem: nobody’s flagship credential from five years ago actually tests whether you can govern, audit, or secure an AI system. Advanced in AI Audit (AAIA) arrived first in 2025, Advanced in AI Security Management (AAISM) followed a few months later, and Advanced in AI Risk (AAIR) only opened for registration on April 15, 2026. If you already hold a CISA, CISM, CRISC, or CISSP and you’re wondering whether adding one of these three to your existing ISACA certification is worth the money, the honest answer depends entirely on what your job actually looks like day to day, not on which acronym sounds most impressive on LinkedIn.

Here’s what each one actually tests, what it costs once you add up the parts nobody puts in the headline price, and which of the three fits which career track.

Why ISACA Built Three Separate AI Certifications Instead of One

Most vendors chasing the AI skills gap have shipped a single generalist credential. CompTIA did it with SecAI+. ISACA took a different route entirely: rather than one broad AI certification, it built three narrow ones, each designed as a specialty extension that only opens up once you already hold a specific flagship credential.

  • AAIA (Advanced in AI Audit): launched in 2025, requires an active CISA or a qualifying audit designation
  • AAISM (Advanced in AI Security Management): launched August 19, 2025, requires an active CISM or CISSP
  • AAIR (Advanced in AI Risk): opened for registration April 15, 2026, requires one of roughly 25 qualifying risk or governance credentials

The logic is straightforward once you see it laid out. ISACA isn’t trying to teach AI from scratch to people with no security or audit background. It’s assuming you already understand the assurance lifecycle, or a security program, or a risk framework, and layering AI-specific knowledge on top of a foundation you’re expected to already have. That’s a meaningfully different bet than a certification meant to stand alone, and it changes who should actually consider each one. ISACA CEO Erik Prusch put the underlying pressure bluntly in the announcement launching AAIR: “AI is moving faster than many organizations are prepared for, and IT risk professionals are on the front lines,” a framing that applies just as well to the audit and security management tracks.

AAIA, AAISM, and AAIR at a Glance

Before going deep on each one, here’s how the three stack up side by side on the details that actually determine which applies to you.

Certification Prerequisite Exam Format Member Cost Launched
AAIA Active CISA, or CIA/CPA with IT audit focus 90 questions, 150 minutes, pass 450/800 $459 2025
AAISM Active CISM or CISSP 90 questions, three domains $459 August 2025
AAIR One of ~25 risk/governance credentials plus 2+ years IT risk experience 90 questions, 150 minutes, pass 450/800 $459 April 2026

Non-members pay $599 for any of the three, plus a $50 application fee once you pass. The exam fee is only part of the real cost, which is a point worth coming back to after looking at each certification individually.

ISACA Advanced in AI Audit (AAIA): Built for Auditors, Not Generalists

AAIA was ISACA’s first move into AI-specific credentialing, positioned as the first advanced audit certification built specifically around evaluating AI systems rather than general IT controls.

Who Actually Qualifies for AAIA

The gate is narrower than it first appears. A CISA covers everyone automatically, but ISACA also opened the door to CIA holders and several CPA variants, provided the role focus is IT audit or IT advisory work, not general accounting.

  • Certified Information Systems Auditor (CISA), any active holder
  • Certified Internal Auditor (CIA), with IT audit or advisory role focus
  • US CPA, Canadian CPA, Australian CPA/FCPA, ACCA/FCCA, or Japanese CPA, each with the same IT audit or advisory role requirement

If your CISA lapses, so does your eligibility to maintain AAIA, since ISACA ties the two together rather than letting the AI credential stand independently.

What the AAIA Exam Tests and What It Costs

The exam runs 90 multiple-choice questions across 150 minutes, scored on a 200 to 800 scale with 450 required to pass. Content splits across three weighted domains covering AI governance and risk, AI operations, and AI auditing tools and techniques, essentially asking whether you can walk into an organization’s AI deployment and actually assess whether its controls hold up. DirectCertify’s own AAIA practice question set runs 275 questions built around that same three-domain structure, useful for candidates who want repetition beyond ISACA’s own review manual.

ISACA Advanced in AI Security Management (AAISM): Built for People Who Already Own AI Risk

AAISM sits on the security management side of the fence. ISACA markets it as the first AI-centric credential aimed specifically at reinforcing an enterprise’s security posture against AI-specific threats, rather than general application security.

Who Actually Qualifies for AAISM

This one is stricter than AAIA. ISACA’s own AAISM credentialing page states plainly that candidates cannot certify without an active CISM or CISSP, with no exceptions carved out for adjacent designations the way AAIA allows for CIA and CPA holders.

What the AAISM Exam Tests and What It Costs

The exam covers 90 questions across three domains: AI Governance and Program Management (roughly 30 percent), AI Risk Management (roughly 30 percent), and AI Technologies and Controls (the largest slice at roughly 38 percent). That weighting tells you something practical about the exam itself: more than a third of it is technical, covering how AI systems and their controls actually work, not just policy and governance theory. DirectCertify carries a 255-question AAISM practice set mapped to the same three domains for candidates coming from a management background who want more reps on the technical third.

ISACA Advanced in AI Risk (AAIR): The Newest of the Three

AAIR is the newest credential in the lineup by a wide margin, and it’s the one with the least real-world track record so far since candidates only started registering in mid-April 2026.

Who Actually Qualifies for AAIR

Eligibility is the broadest of the three on paper, covering roughly 25 prerequisite credentials rather than just one or two. Named options in ISACA’s own launch materials include CISA, CISM, CRISC, CGEIT, CDPSE, CRMP, CRMA, CGRC, CISSP, CERP, and CRCM. Beyond holding one of those, candidates also need two or more documented years in an IT risk or advisory role, a requirement neither AAIA nor AAISM imposes as explicitly.

What the AAIR Exam Tests and What It Costs

Structurally it mirrors AAIA almost exactly: 90 questions, 150 minutes, scored 200 to 800 with 450 to pass. The three domains are AI Risk Governance and Framework Integration, AI Lifecycle Risk Management, and AI Risk Program Management, and the content pulls directly from named frameworks candidates are expected to already recognize, including the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, the OWASP LLM Top 10, and MITRE ATLAS. That’s a heavier real-world framework load than either AAIA or AAISM lists explicitly, reflecting how fragmented AI risk governance still is across regions and standards bodies.

Why Being First Through the Door Carries Its Own Risk

Registering for a certification that’s barely a few months old cuts both ways. On one hand, holding AAIR right now signals you moved early on a credential ISACA CEO Erik Prusch has publicly tied to a specific talent gap. On the other, there’s no multi-year track record yet showing how employers weight it against a more established credential like CRISC alone, and ISACA itself has flagged 2026 as a year it expects to keep refining AI-related content across its whole portfolio. Candidates comfortable being early adopters should register now; candidates who want to see two or three hiring cycles of data first have a reasonable case for waiting.

The Real Cost of Stacking a Specialty Credential on Your Flagship Cert

Every write-up of these three certifications leads with the $459 member exam fee, which understates what you’re actually signing up for. The full cost stack looks like this for any of the three:

  1. Exam fee: $459 for members, $599 for non-members
  2. Application processing fee: $50, charged after you pass
  3. Annual maintenance fee: somewhere between $20 and $35 a year depending on membership status, on top of whatever you already pay to maintain the prerequisite credential
  4. Continuing education: a minimum of 10 CPE hours per year and 30 hours across a three-year cycle, stacked on top of whatever CPE load your CISA, CISM, or CRISC already requires
  5. The prerequisite itself, if you don’t already hold it, which for CISA or CISM alone runs a comparable exam fee before you’re even eligible to sit for the AI-specific add-on

None of that makes the credentials bad value. It does mean the true annual cost of holding, say, AAISM on top of an active CISM is closer to two overlapping maintenance obligations than a single one-time exam fee, which is worth budgeting for honestly before registering.

Which of the Three Should You Actually Pursue

The decision genuinely comes down to which ISACA certification you already hold and what your role looks like this year, not which credential has the most buzz.

You’re an Auditor Who Holds a CISA

AAIA is built for exactly this position. If part of your job is walking into a business unit and assessing whether its AI deployment has real controls around bias, data provenance, and model governance, this is the credential that maps directly to that work rather than forcing you to translate general IT audit skills on the fly.

You Manage a Security Program and Hold CISM or CISSP

AAISM fits security leaders who are already accountable for an enterprise’s overall security posture and now need to fold AI-specific threats, from model poisoning to prompt injection, into that existing program rather than treating AI security as someone else’s problem. Readers weighing AAISM against a broader security certification path may also want our breakdown of CompTIA’s newer SecAI+ credential, which takes the generalist route AAISM deliberately avoids.

You Work in Risk and Hold CRISC or a Related Credential

AAIR is the newest and least proven of the three, but it’s also the one built specifically for people whose job title already includes the word “risk.” If you’re the person in the room responsible for AI risk registers, vendor AI assessments, or board-level AI risk reporting, this credential tracks your actual scope of work more closely than either of the other two. Our earlier look at what CRISC covers is worth revisiting first if it’s been a while since you last touched the base credential AAIR builds on.

Is Any of This Worth It in 2026

The market signal behind all three credentials is stronger than the certifications’ own short track records suggest. Foote Partners’ Q1 2026 “Hot List,” which tracks pay premium growth across 663 industry IT certifications, included only 17 total, and three of those seventeen were ISACA credentials: CISA, CRISC, and CGEIT. CISA and CGEIT specifically posted cash pay premium growth in the 11 to 20 percent range over the second half of 2025, a period that lines up almost exactly with when AAIA and AAISM launched.

On the job market side, ZipRecruiter’s current listings for AI Risk Manager roles put average pay at $111,556 a year nationally, and roles requiring the broader AI Risk Management Framework skill set average $96,047, with most positions falling between $72,500 and $115,500. Senior AI risk positions at larger financial institutions reportedly reach $245,000, reflecting how much of the current demand is concentrated in regulated industries already required to document AI governance.

A few forces are driving that demand beyond general cybersecurity hiring growth:

  • Financial services firms facing new regulatory pressure to document AI risk controls, a sector ISACA’s own pay premium research flags as commanding a 15 to 25 percent salary premium for AI risk work specifically
  • Enterprises adopting AI systems faster than they’re building governance around them, the exact gap AAIR was designed to close
  • A widening split between generalist security roles and AI-specific security and audit functions, mirrored in how ISACA structured these three certifications as separate tracks rather than one combined credential

None of that guarantees a raise or a promotion just for passing an exam. It does mean the underlying skill set maps to a genuinely tight labor market right now, which is a more durable reason to pursue one of these than the novelty of holding a brand-new acronym.

Before You Register for AAIA, AAISM, or AAIR

A few practical checks are worth doing before paying the exam fee on any of the three:

  • Confirm your prerequisite credential is currently active, not lapsed, since all three certifications are contingent on it staying that way
  • Check ISACA’s exam content outline directly for the credential you’re targeting, since 2026 updates are already expected to fold in newer EU AI Act and NIST AI RMF guidance
  • Budget the full cost stack, not just the headline exam fee, especially the recurring CPE and maintenance obligations layered on top of your existing credential
  • If you’re considering AAIR specifically, weigh the early-adopter tradeoff honestly given how new the credential still is

Worth being direct about here: DirectCertify is an independent certification prep provider and has no affiliation with, endorsement from, or sponsorship by ISACA. Exam content outlines, prerequisites, and pricing are ISACA’s to set and change, so confirm anything time-sensitive directly on ISACA’s own credentialing pages before you register.

AAIR, AAIA, and AAISM: Quick Answers

Can I hold more than one of AAIA, AAISM, and AAIR at the same time?
Yes, nothing prevents holding all three if you qualify for each one’s prerequisite. In practice most candidates pursue whichever single credential matches their current role, since each carries its own separate exam fee and ongoing maintenance obligation.
What happens to my AI certification if my underlying CISA, CISM, or CRISC lapses?
Since AAIA, AAISM, and AAIR are structured as extensions of an active flagship credential, letting the prerequisite lapse puts the specialty certification’s standing at risk as well. Keeping the base credential current is part of maintaining any of the three.
Is AAIR too new to be worth pursuing right now?
It depends on your tolerance for being an early adopter. Registration only opened April 15, 2026, so there is no multi-year hiring data yet showing how employers weigh it. The underlying skill set it tests, AI risk governance mapped to frameworks like NIST AI RMF and the EU AI Act, is in real demand regardless of the credential’s age.
Do these certifications actually pay more, or is that just marketing?
There is real data behind the demand, though it points to the underlying skill set rather than the brand-new credentials themselves. CISA and CGEIT posted 11 to 20 percent pay premium growth in the second half of 2025, and AI risk management roles broadly average over $96,000 a year nationally as of mid-2026.
Which one should someone with a CRISC but no audit or security management background pick?
AAIR is the only one of the three built around a CRISC-style prerequisite path, since AAIA requires an audit credential like CISA and AAISM requires CISM or CISSP. A CRISC holder without those other credentials would need to earn one of them first to qualify for AAIA or AAISM.