AIAC-03 · Financial track
AI Assurance for Financial Institutions
For risk, compliance, and audit professionals in regulated financial services, covering model risk, agentic AI oversight, and supervisory expectations for AI deployment.
- Reference
- AIAC-03
- Level
- Practitioner
- Examination
- 3.5 hours
- Delivery
- Remote, proctored
- Credential
- Valid 3 years
§ 1 — Intended candidates
Who this certification is for
Second- and third-line professionals in banks, insurers, and asset managers: model risk, operational risk, compliance, and internal audit.
- Prerequisites
- Recommended: three or more years in a risk, compliance, or audit function within a regulated financial institution.
- Status
- In development · First cohort October 2026
§ 2 — Examination domains
What the examination covers
Domain weightings are published with the full syllabus ahead of the first cohort.
- 01
Model risk and AI
Where established model risk management practice extends to AI systems and where it leaves gaps — particularly for foundation models.
- 02
Agentic AI oversight
Controls for systems that take actions rather than produce outputs: authorization boundaries, audit trails, and reversibility.
- 03
Third-party AI risk
Assessing vendor and foundation-model dependencies, including concentration risk and limited-visibility assessment techniques.
- 04
Supervisory expectations
Reading and applying published financial-sector AI risk management guidance in the jurisdictions where candidates operate.
- 05
Reporting and governance
Reporting AI risk to committees and boards in terms that support a decision rather than describe a technology.
§ 3 — Assessment
How candidates are assessed
Scenario-based examination set in a regulated financial services context, including a model inventory judgement, a risk profile, and a committee-level reporting summary.
Successful candidates receive a credential with a unique identifier that any employer can check against the public record. See credential verification.
Curriculum mapping indicates alignment of learning content with published frameworks. It does not constitute endorsement by, or certification under, any standards organization or regulator.
§ 4 — Further reading
Background reading
- AI assurance vs AI audit vs AI risk assessment: the differences that matter
Three terms used interchangeably that mean different things, have different outputs, and require different independence. A practitioner-level distinction.