
Master AI risk reasoning across three domains—AI risk governance and framework integration, AI lifecycle risk management, and AI risk program management—through scenario-based questions, capstones, and integrated practice exams.
Leave a quick review to help professionals decide the value of the material and to refine explanations; connect on LinkedIn to discuss certification strategy and exam prep.
Distinguish risk appetite from risk tolerance, connect them to governance with KRIs and escalation thresholds, and outline treatment decisions.
Define five AI governance roles with clear accountability, separating the AI owner from the model owner and establishing an independent AI risk officer, guided by a responsibility assignment matrix.
Master the three lines of defense for AI governance—first line operators, second line independent risk oversight, and third line audit assurance—preserving independence under speed and pressure.
Explore governance program design by comparing centralized, federated, and hybrid models, including center of excellence and embedded governance roles, their accountability, escalation paths, and prerequisites for successful AI governance.
Govern establishes the RMF framework for AI risk by defining risk posture, six subcategories, and an accountability structure, ensuring board-approved risk tolerance, roles, and policies guide map, measure, and manage.
Manage enables AI risk governance by applying four treatment options—avoid, mitigate, transfer, or accept—with authority, reassessment triggers, and links to change management, response and recovery, risk communication, and the RMF.
Treat AI change as a risk discipline by mapping ADCAR phases to residual risk categories and assessing model updates, prompts, data refreshes, and vendor changes for drift and regulatory exposure.
Explain how the ai deployment pipeline uses KRIs and gate criteria to help risk officers govern model promotion, AB rollout, and full deployment, with drift, test coverage, HITL, and rollback.
Explore how the six-tier AI policy hierarchy translates board risk appetite into concrete controls, from charter to work instruction, and test its completeness, version history, and risk register implications.
Learn to design AUP content by linking prohibited use categories to the risk register, applying the four-tier data sensitivity model, and managing exceptions with auditable decisions.
Design a cross-jurisdictional AI program anchored in OECD principles and G7 Hiroshima, building a unified evidence trail to meet the strictest applicable standards across UK, Singapore, Canada, and China.
Explore the iterative article IX risk management system, covering risk identification, mitigation, and residual risk, with Annex IV documentation and the self-assessment or notified body paths.
Identify provider and deployer roles under the EU AI Act, map GPAI and model obligations, timelines, and article 99 penalties and thresholds to risk registers.
Assess fairness and transparency failures by diagnosing three causal pathways, apply elimination by design, monitoring, and human review override, and set residual risk thresholds to prevent disparate impact.
Align accountability with operational oversight to prevent diffusion of ownership and escalation gaps, reducing automation bias and residual harm in AI deployments.
This course contains the use of artificial intelligence. However, every lecture recording involves me reading the scripts, and I am fully involved in scripting and production. Be careful buying courses with instructors that don't appear in person. AI courses are becoming quite common on learning platforms.
This course is a complete, structured study program for the ISACA Advanced in AI Risk (AAIR) exam. Built domain by domain against the official exam blueprint, it covers every topic area you need to understand before sitting for the exam. Each lesson is a narrated video that explains how concepts connect to each other and to real-world practice — not just what the definition is, but how a practitioner applies it.
D1 — AI Risk Governance and Framework Integration (37% of the exam) — covers evaluate risk related to ai models/solutions including design, suitability, algorithms, training, drift, and ai life cycle., evaluate ai use cases based on the organization's risk appetite., leverage ai to support the risk management program (e.g., risk profile, reporting, evaluation, risk models, and analysis)., facilitate the integration of ai risk management into an enterprise risk management framework and risk programs., integrate ai risk considerations into existing governance programs., monitor and test organizational processes to identify ai risks., integrate ai-related risk considerations into the change management process., develop and implement an ai risk management framework, including roles and accountability, ai risk policies and procedures, and acceptable risk tolerance levels., assess human oversight controls at critical decision points for risk and ai impact., collaborate with stakeholders to develop and integrate ai risk concepts into enterprise-wide awareness training., assess compliance with applicable ai-related regulations, laws, frameworks, standards, and guidelines., advise on ai-related risk within contracts and service agreements, including data usage and intellectual property., collaborate with stakeholders to address ai trustworthiness and impacts including ethics, bias, privacy, safety, and environmental, social, and governance (esg) implications.. You will understand how each of these areas is tested on the exam and how they connect to real-world practice.
D2 — AI Life Cycle Risk Management (21% of the exam) — covers . You will understand how each of these areas is tested on the exam and how they connect to real-world practice.
D3 — AI Risk Program Management (42% of the exam) — covers conduct risk assessments to identify and classify risks associated with ai., conduct and/or evaluate threat and vulnerability assessments on ai projects/programs., continuously assess and monitor the risk landscape for emerging ai risk., develop and recommend risk treatment strategies for identified ai risks., evaluate controls to manage ai-related risk within the organization's risk tolerance., integrate ai risk considerations into existing risk register and control taxonomies., capture ai risk considerations in enterprise risk metrics and reporting (e.g., board, management, operations)., evaluate ai risk as part of supply chain risk management., collaborate with stakeholders to integrate ai risk scenarios into the enterprise incident management program., incorporate ai-related risk considerations into incident response, bias, the bcp, and drp.. You will understand how each of these areas is tested on the exam and how they connect to real-world practice.
Every domain includes practice questions designed to mirror the style and difficulty of AAIR exam scenarios, covering not just recall but application and analysis. The course closes with full-length practice exams with detailed answer explanations, so you can measure your readiness and focus your remaining study time where it matters most.
Major topics covered: evaluate risk related to ai models/solutions including design, suitability, algorithms, training, drift, and ai life cycle., evaluate ai use cases based on the organization's risk appetite., leverage ai to support the risk management program (e.g., risk profile, reporting, evaluation, risk models, and analysis)., facilitate the integration of ai risk management into an enterprise risk management framework and risk programs., integrate ai risk considerations into existing governance programs., monitor and test organizational processes to identify ai risks., integrate ai-related risk considerations into the change management process., develop and implement an ai risk management framework, including roles and accountability, ai risk policies and procedures, and acceptable risk tolerance levels., assess human oversight controls at critical decision points for risk and ai impact., collaborate with stakeholders to develop and integrate ai risk concepts into enterprise-wide awareness training., assess compliance with applicable ai-related regulations, laws, frameworks, standards, and guidelines., advise on ai-related risk within contracts and service agreements, including data usage and intellectual property., collaborate with stakeholders to address ai trustworthiness and impacts including ethics, bias, privacy, safety, and environmental, social, and governance (esg) implications., conduct risk assessments to identify and classify risks associated with ai., conduct and/or evaluate threat and vulnerability assessments on ai projects/programs., continuously assess and monitor the risk landscape for emerging ai risk., develop and recommend risk treatment strategies for identified ai risks., evaluate controls to manage ai-related risk within the organization's risk tolerance., integrate ai risk considerations into existing risk register and control taxonomies., capture ai risk considerations in enterprise risk metrics and reporting (e.g., board, management, operations)., evaluate ai risk as part of supply chain risk management., collaborate with stakeholders to integrate ai risk scenarios into the enterprise incident management program., incorporate ai-related risk considerations into incident response, bias, the bcp, and drp., AAIR exam prep 2026.