We operate a certification scheme, so treat this with appropriate suspicion. What follows is written to be checkable: every eligibility claim comes from the issuing body’s own page, and there are three sections below where the honest recommendation is a credential that is not ours.
The market splits into four categories that are routinely confused, and choosing across categories rather than within them is the expensive mistake.
1. Audit credentials
ISACA AAIA — Advanced in AI Audit. The strongest credential available for auditing AI, aimed at experienced IT auditors. Three domains: AI governance and risk, AI operations, and AI auditing tools and techniques.
The decisive feature is eligibility. AAIA requires a qualifying designation — CISA qualifies automatically, and CIA, US/Canadian CPA, ACCA, ICAEW, and several other accounting designations qualify where the holder works in an IT audit or advisory role. ISACA’s own guidance to those who do not qualify is to pursue CISA first.
That is a deliberate and defensible gate: it means every AAIA holder has demonstrated audit competence before adding AI to it. It also means the credential is closed to a large population doing AI assurance work today — engineers, data scientists, model risk specialists, compliance staff — who will never hold CISA.
Take AAIA if you are a practising IT auditor with CISA, CIA or an accounting designation. In that situation it is the better credential and we would tell you so.
2. Governance and policy credentials
IAPP AIGP — AI Governance Professional. Launched in 2023, the first major credential built around AI governance, and IAPP’s distribution among privacy and legal professionals is unmatched. No prerequisites: no degree, no minimum experience.
AIGP’s centre of gravity is policy, law, and programme design — what a governance framework should contain, how regulation maps onto it, how a programme is structured. It is comparatively light on producing technical evidence.
Take AIGP if you are a privacy professional, in-house counsel, or building a governance programme rather than evaluating systems. If your deliverable is a policy set and a regulatory map, it is a better fit than anything we offer.
ISACA AAIR — Advanced in AI Risk is the closest credential to a general AI risk practitioner qualification. Three domains: AI risk governance and framework integration, AI lifecycle risk management, and AI risk programme management. Eligibility again requires a qualifying designation — CISA, CISM, CRISC, CGEIT, or CDPSE, or a risk or accounting designation from bodies such as RIMS, IIA, ISC2, or the accounting institutes.
ISACA AAISM — Advanced in AI Security Management covers the security side and is gated behind CISM.
Take AAIR if you are a certified IT risk professional. Take AAISM if you are a practising security manager. Both are strong credentials and neither competes with what we do.
The pattern worth noticing
All three of ISACA’s advanced AI credentials — AAIA, AAISM, AAIR — require an existing designation. That is a coherent strategy: ISACA is extending its certified population into AI, not opening AI assurance to newcomers. It produces holders with genuinely verified underlying competence.
It also means that if you are a data scientist, an engineer, a model risk analyst without CRISC, or a compliance professional without an accounting qualification, ISACA’s AI suite is closed to you today — regardless of how much AI assurance work you actually do.
3. Tool and skill certificates
A large and growing category: Certified ChatGPT Expert, Gemini Professional, prompt engineering certificates, “Certified AI Expert” programmes from commercial training providers. Many carry lifetime access and can be completed in a day.
These certify familiarity with a tool. That is a real thing and sometimes exactly what someone needs. It is not assurance, and the naming convention — “Certified X Expert” — can obscure that the assessment is typically multiple-choice recall rather than applied judgement.
Take one if you want structured familiarity with a specific product. Do not present one as evidence of competence to assess AI risk, because the first person who examines the syllabus will notice.
4. Assurance execution credentials
This is the category we occupy, and it is thin — which is why we exist rather than a claim of superiority.
The gap is specific. ISACA’s suite certifies audit, risk, and security competence, but every credential in it is gated behind an existing designation. AIGP certifies governance literacy without requiring you to evaluate anything. Tool certificates certify neither. Nobody is certifying the ability to take an unfamiliar deployment, produce a defensible risk profile, and stand behind the conclusion — sector by sector, where the regulator, the evidence, and the consequences of failure differ.
The Council’s ten tracks are built around that: a Foundation credential with no prerequisites, five sector credentials, functional credentials in AI audit and board-level governance, and endorsements in agentic oversight and third-party procurement risk.
The honest caveats. We have issued no credentials — first cohorts open October 2026. We have no employer recognition yet, because recognition is earned by holders doing good work, and ours do not exist. ISACA has more than fifty years of institutional weight and IAPP has a privacy profession that grew up around it. If you need a credential a hiring manager already recognises today, take theirs.
Comparison
| Eligibility gate | Centre of gravity | Assessment style | Validity | |
|---|---|---|---|---|
| ISACA AAIA | CISA / CIA / CPA-class designation | Auditing AI systems | Exam | ISACA CPE cycle |
| ISACA AAIR | CISA / CISM / CRISC / CGEIT / CDPSE or risk designation | Managing AI risk programmes | Exam | ISACA CPE cycle |
| ISACA AAISM | CISM | Securing AI systems | Exam | ISACA CPE cycle |
| IAPP AIGP | None | Governance, policy, regulation | Exam | IAPP maintenance |
| Tool certificates | None | Product familiarity | Usually recall | Often lifetime |
| AI Assurance Council | None (Foundation) | Producing assurance evidence, by sector | Scenario-based | 2-year term, revalidation |
What it costs
Almost nobody publishes the total cost of holding one of these, because the headline exam fee is rarely the whole of it. Published rates at the time of writing, in US dollars:
| Membership / yr | Exam, member | Exam, non-member | Other | |
|---|---|---|---|---|
| ISACA (AAIA, AAIR, AAISM) | ~$145 (+ chapter dues) | ~$459 | ~$599 | $50 application; annual maintenance; prerequisite designation must also be held and maintained |
| IAPP (AIGP) | $295 professional | $649 | $799 | Maintenance covered by membership |
| Tool certificates | — | often $100–400 | — | Frequently discounted; usually lifetime |
Two things worth reading off that table.
Membership is priced at roughly one exam’s discount. At both bodies the member saving on a single examination is close to the annual membership fee — $140 against $145 at ISACA, $150 against $295 at IAPP. Membership is not sold as a discount scheme; the discount is the entry point, and the recurring value is standing, CPD, and access.
The prerequisite is the hidden cost. An ISACA AI credential requires holding and maintaining a qualifying designation. If you do not already have CISA or equivalent, the real cost of AAIA includes another examination, another application fee, and another annual maintenance obligation — several times the headline figure, and a year or more of preparation. That is not a criticism of the design; it is the correct number to compare against.
Confirm current pricing with the issuer before deciding. These change, and none of the above includes preparation.
How to actually choose
Answer one question: what will you be asked to produce?
- A signed audit finding → AAIA, and CISA first if you need it.
- An enterprise AI risk programme → AAIR, if you hold a qualifying risk designation.
- A governance framework, or a regulatory gap analysis → AIGP.
- A security control set for AI systems → AAISM.
- Fluency with a specific tool → a tool certificate, and do not overclaim it.
- A defensible risk profile for a deployment in a regulated sector → the gap this Council was built for.
If two of those describe you, take the established one first. Credentials compound; the sequencing rarely matters as much as people think.
A test that applies to any of them
Before paying for any AI certification, ask the issuer three questions:
- Is training required to sit the examination? If preparation is mandatory, you are buying a course with a certificate attached, and the certificate carries whatever independence the seller’s incentives allow.
- Can a third party verify the credential without contacting the holder? If there is no public register, an employer has to take the claim on trust.
- Does it expire? A lifetime credential in a field this unstable is a claim about competence that nobody is checking.
We publish our answers — no, yes, and a fixed two-year term — because those questions are the ones worth asking, and any body unwilling to answer them plainly is telling you something.
Read more about how the Council handles the first of those, given that our operator also sells training, at how we manage that conflict.
Sources: ISACA — AAIA credential and eligibility · ISACA — AAIR · IAPP — AIGP certification · issuer-published exam fees, August 2026