Certification12 min read

ISACA Launched a Global AI Risk Certification. Not One Domain Is Caribbean.

By Adrian Dunkley·Aug 17, 2026
TLDR
  • ISACA launched three new credentials on 15 April 2026: Advanced in AI Risk (AAIR), Advanced in AI Audit (AAIA), and Advanced in AI Security Management (AAISM), each gated behind one of 25 prerequisite certifications and priced at $459 to $649 once membership and application fees are counted.
  • The AAIR syllabus covers three practice domains: AI risk governance and framework integration, AI lifecycle risk management, and AI risk program management. None names a specific jurisdiction, a specific data protection statute, or the Caribbean.
  • ISACA's own 2026 AI Pulse Poll, surveying 681 digital trust professionals across Europe in February 2026, found 59% do not know how quickly their organisation could halt an AI system during an incident, and only 21% could do so within 30 minutes.
  • PwC's 2026 Caribbean Corporate Governance Survey of 154 directors found only 6% believe their board spends enough time on AI oversight and just 29% strongly agree management has the skills to execute an AI strategy, even though 62% say their AI investments are already paying off.
  • A global process certification and a regionally grounded one test different things. CAIRMC's position: pursue AAIR for the programme-management discipline it teaches, then pair it with a regionally specific credential such as CAIRMC's own QAIRP track before treating either as sufficient by itself.
An empty modern boardroom with a long table and chairs, representing the governance and board-level review that AI risk certification is meant to support

Photo via Unsplash

ISACA certified its first cohort of AI risk professionals against a global body of knowledge in April 2026. Not one of the three practice domains on that exam names a Caribbean data protection act, a CARICOM instrument, or the EU AI Act's reach into Caribbean exporters. For a region assembling its own AI risk workforce largely from scratch, that gap is the actual story.

ISACA, the global professional association behind CISA, CISM, and CRISC, launched the Advanced in AI Risk (AAIR) certification on 15 April 2026 alongside two companion credentials, Advanced in AI Audit (AAIA) and Advanced in AI Security Management (AAISM). AAIR tests three practice areas: AI risk governance and framework integration, AI lifecycle risk management, and AI risk program management, all built around global standards rather than any single jurisdiction's law. A Caribbean risk officer who holds only AAIR is certified in the discipline of AI risk management. They have not been tested on the regulatory environment they actually work inside.

This article sets out what ISACA built, what it deliberately left out, what the confidence numbers on both sides of that gap actually say, and what a Caribbean risk function should do with a credential that is genuinely useful and genuinely incomplete at the same time.

What ISACA Actually Launched

AAIR did not arrive alone. ISACA released three advanced credentials on the same day, each aimed at a different professional lane inside AI governance: AAIR for risk professionals, AAIA for auditors, and AAISM for security management practitioners. All three sit above ISACA's existing certification stack rather than beside it. Candidates cannot sit the AAIR exam directly. They must first hold one of 25 recognised prerequisite designations, among them CISA, CISM, CRISC, CGEIT, CDPSE, CISSP, CRMA, CGRC, and a run of accountancy credentials including the US CPA and ACCA. ISACA CEO Erik Prusch framed the timing plainly at launch: "AI is moving faster than many organizations are prepared for, and IT risk professionals are on the front lines."

The exam itself costs $459 for ISACA members and $599 for non-members, plus a $50 application processing fee, and is delivered through computer-based testing at PSI centres worldwide or by remote proctoring, with in-person testing required in a small number of jurisdictions. The three domains break down as follows: AI risk governance and framework integration asks candidates to evaluate how an organisation structures AI oversight and maps it to a chosen framework; AI lifecycle risk management covers identifying and assessing risk from design through deployment and retirement; AI risk program management covers building and running the operational programme that keeps the first two functions alive day to day.

Read against ISO/IEC 42001:2023, the NIST AI Risk Management Framework, and COSO Enterprise Risk Management, the three domains map cleanly. What they do not map to is a jurisdiction. No domain description names the EU AI Act's specific risk tiers, no domain names the General Data Protection Regulation, and no domain names a single Caribbean data protection statute. That is not a criticism of ISACA's design choice. A global membership organisation serving IT risk professionals in more than 180 countries has good reason to build a syllabus that travels, and a credential built around jurisdiction-agnostic practice areas is more durable than one rewritten every time a new AI law passes somewhere. The consequence, whether intended or not, is that AAIR certifies competence in the discipline without certifying knowledge of the law a Caribbean holder will actually have to apply it against.

The Confidence Gap the Certification Answers

ISACA's own research explains why it built AAIR when it did. The organisation's 2026 AI Pulse Poll, fielded 6 to 22 February 2026 across 681 digital trust professionals in Europe and published in May, found a governance picture considerably shakier than the pace of AI adoption around it. Fifty-nine percent of respondents said they do not know how quickly their organisation could halt an AI system if it needed to be shut down during a security incident, and only 21% said they could do so within 30 minutes. Fewer than 42% expressed confidence in their organisation's ability to investigate and explain a serious AI incident to leadership or regulators, and just 11% said they were completely confident. A third of organisations, 33%, do not require employees to disclose when AI was used in a work product. On accountability, 20% did not know who bears ultimate responsibility if an AI system causes harm, and only 38% identified the board or executive level as the answer.

Those numbers come from European respondents, not Caribbean ones, and should be read as exactly that: evidence of a governance gap in a mature, heavily regulated market, not a claim about the Caribbean. The reason they matter here is structural rather than geographic. If digital trust professionals in a jurisdiction with the EU AI Act, GDPR, and years of ISO 42001 adoption already in force are this uncertain about their own AI shutdown authority and incident accountability, a credential built to close that gap has an obvious market. It also has an obvious limit: closing a governance-maturity gap and closing a jurisdiction-knowledge gap are two different projects, and AAIR was built to do the first.

The Caribbean's Own Confidence Numbers

The Caribbean has its own version of this survey, and it tells a related but distinct story. PwC's 2026 Caribbean Corporate Governance Survey polled 154 board directors between November 2025 and January 2026 across the Bahamas, Barbados, Grenada, Jamaica, Saint Lucia, and Trinidad and Tobago, adding Bermuda to the panel for the first time. Sixty-two percent of directors said their organisation's investments in AI and generative AI are already yielding positive results, evidence that adoption is real rather than aspirational. Set against that, only 6% believe their board spends enough time understanding the impact of AI, and just 29% strongly agree that management has the skills needed to execute an AI strategy.

Read the two surveys together and a pattern holds across both jurisdictions, even though the specific numbers differ and the samples are not comparable in size or method. Adoption is running ahead of governance capability almost everywhere AI risk research has looked in 2026, in a market with a mature global credential newly available and in a market that does not yet have one built for it. The Caribbean gap is not smaller because the region is behind. It is, if anything, sharper, because a Caribbean director sits on a board making AI-dependent decisions inside a regulatory environment considerably less settled than Europe's, with fewer local benchmarks to check the board's own judgement against.

Three Certification Profiles, Compared

An institution deciding where to spend training budget is really choosing between three different things a credential can test: general process discipline, technical standard conformance, and regional regulatory fluency. No single credential on the market currently does all three at once.

Attribute ISACA AAIR ISO/IEC 42001 Lead Auditor CAIRMC QAIRP / CCARP
What it tests AI risk governance, lifecycle risk, and programme management, jurisdiction-agnostic Audit competence against the ISO/IEC 42001:2023 management system standard AI risk assessment, EU AI Act mapping, and Caribbean Data Protection Act integration
Entry requirement One of 25 prerequisite certifications, including CISA, CISM, CRISC or a recognised accountancy designation Typically an ISO management system auditor background; varies by training provider None; the Professional tier assumes the Associate tier or equivalent working knowledge
Named jurisdictions None None beyond the standard itself EU AI Act, GDPR, Jamaica, Barbados, and Trinidad and Tobago data protection statutes
What it signals to a counterparty Recognised global process competence, useful to overseas insurers, auditors and regulators Ability to run or lead a conformance audit against a specific certifiable standard Working fluency in the regulatory instruments that actually govern a Caribbean deployment
Cost, approximate $459 to $649 including application fee, membership-dependent Varies by training provider, commonly several hundred to over a thousand US dollars $120 to $680 depending on tier

None of the three columns is redundant with the other two. An institution that stops at one has bought process discipline, or standard conformance, or regional fluency, and is missing the other pair.

Why "Global" Does Not Mean "Complete"

The gap AAIR leaves is not cosmetic once a Caribbean institution starts using the credential to staff an actual risk function. ISO/IEC 42001:2023, built on the same high-level structure as ISO 27001 and ISO 9001, requires an organisation to determine and evidence the competence of the people performing work under its AI management system, under the standard's competence clause. A certificate that teaches lifecycle risk management in the abstract does not, on its own, evidence that the certificate holder can competently assess whether a specific deployment complies with Jamaica's Data Protection Act 2020, a statute with its own registration and breach-notification requirements that AAIR's syllabus never mentions.

The NIST AI Risk Management Framework makes the same point from a different angle. Its GOVERN function includes a subcategory, GOVERN 2.2, requiring that personnel receive AI risk management training consistent with the policies and procedures they are actually expected to follow. A generic global syllabus satisfies the letter of that requirement. It does not satisfy the spirit of it for an institution operating under CARICOM's patchwork of data protection statutes, where Trinidad and Tobago's 2011 law remains substantially unproclaimed, Barbados' 2019 Act sets its own registration regime, and the EU AI Act reaches back into any Caribbean exporter serving EU customers regardless of where the exporter is incorporated. COSO's Enterprise Risk Management framework treats this as a governance and culture question rather than a training checkbox: an organisation's risk capability is only as strong as the specific context its people have been trained to recognise, and a credential that never names that context leaves a documented hole in the control.

None of this is an argument against AAIR. It is an argument against treating any single certification, global or regional, as a complete answer. StarApple AI's own study of board-level AI training across Caribbean organisations found governance stand-up time falling from 11 to 15 months down to roughly six once structured training was in place, alongside a measurable rise in board data literacy. That result came from training built around the region's own regulatory reality, not a generic global syllabus, which is precisely the layer AAIR was never designed to provide.

The Complementary Play, Not Either/Or

The practical answer for a Caribbean risk function is to stack credentials deliberately rather than pick one and stop. AAIR, or its companion AAIA and AAISM tracks, gives a risk, audit, or security professional a globally recognised baseline that an overseas reinsurer, a foreign auditor, or a cross-border regulator will immediately understand, because ISACA's brand and exam rigour are already established currency in those rooms. That recognition has real value for a Caribbean institution negotiating a reinsurance treaty or responding to a group-level audit from a foreign parent.

What it does not do is tell a compliance officer which Caribbean statute applies to a specific deployment, at what risk tier CAIRMC's own Caribbean AI Risk Taxonomy would classify it, or which of the region's data protection authorities expects notification first. That is the layer CAIRMC's CARA methodology and QAIRP certification track are built to supply, with the EU AI Act deep dive and Caribbean Data Protection Act integration content named directly in the certification's own curriculum. Pair a global process credential with a regionally grounded one, and staff both against the same risk register, rather than treating either as a finish line. An institution that certifies its risk lead in AAIR and stops has bought process fluency without regional fluency. An institution that does the reverse has bought regional fluency that an overseas counterparty may not recognise on sight. Doing both costs a fraction of either credential's price difference and closes both gaps at once.

For boards specifically, the PwC numbers point to where the first investment should land. A director who does not believe the board spends enough time on AI oversight is unlikely to be reassured by a risk officer's certificate alone; the board itself needs enough literacy to ask the right question of that officer. Structured board-level training, delivered against the region's own regulatory environment rather than translated from a foreign template, is the intervention that moves the 6% and 29% figures, not a credential held three organisational layers below the board table.

Frequently Asked Questions

What is ISACA's AAIR certification?

Advanced in AI Risk (AAIR) is a credential ISACA launched on 15 April 2026, covering three practice domains: AI risk governance and framework integration, AI lifecycle risk management, and AI risk program management. Candidates must already hold one of 25 recognised prerequisite certifications, such as CISA, CISM, or CRISC, before sitting the exam.

Does AAIR cover any Caribbean-specific regulation?

No. The AAIR syllabus is built around global practice areas and does not name the EU AI Act's specific risk tiers, GDPR, or any Caribbean data protection statute. It certifies competence in the discipline of AI risk management rather than knowledge of a specific jurisdiction's law.

How much does the AAIR exam cost?

The exam itself costs $459 for ISACA members and $599 for non-members, plus a $50 application processing fee. It is delivered by computer-based testing at PSI centres worldwide or through remote proctoring, subject to country-specific restrictions.

What did ISACA's 2026 AI Pulse Poll find?

Surveying 681 digital trust professionals across Europe in February 2026, the poll found 59% did not know how quickly their organisation could halt an AI system during an incident, only 21% could do so within 30 minutes, and fewer than 42% expressed confidence in investigating and explaining a serious AI incident to leadership or regulators.

What does PwC's 2026 Caribbean Corporate Governance Survey say about AI oversight?

Polling 154 directors across the Bahamas, Barbados, Grenada, Jamaica, Saint Lucia, Trinidad and Tobago, and Bermuda between November 2025 and January 2026, the survey found only 6% of directors believe their board spends enough time on AI oversight and just 29% strongly agree that management has the skills to execute an AI strategy, even though 62% report positive returns from their AI investments already.

Should a Caribbean risk professional pursue AAIR or a CAIRMC certification instead?

Both, staffed against the same risk register rather than treated as substitutes. AAIR supplies globally recognised process discipline that overseas counterparties, auditors, and reinsurers already understand. CAIRMC's CARA methodology and QAIRP certification supply the EU AI Act mapping and Caribbean Data Protection Act content AAIR's syllabus does not cover.

What are ISACA's other two new AI credentials?

Advanced in AI Audit (AAIA), aimed at auditors assessing AI systems and controls, and Advanced in AI Security Management (AAISM), aimed at security management practitioners. Both launched alongside AAIR on 15 April 2026 and follow the same prerequisite-gated structure.

Why does a competence gap in a certification matter for ISO 42001 compliance?

ISO/IEC 42001:2023 requires an organisation to determine and evidence the competence of people performing work under its AI management system. A certification that never addresses the specific regulatory environment a person operates in leaves that evidence incomplete for an institution seeking or maintaining ISO 42001 certification in a Caribbean jurisdiction.

Related reading across the Caribbean AI network

This article sits alongside ongoing coverage of AI governance, risk, and company-building across the region. For related perspectives:

Sources and References
  • ISACA: "ISACA Launches Advanced in AI Risk (AAIR) Certification to Equip IT Risk Professionals," press release, 15 April 2026
  • ISACA: 2026 AI Pulse Poll, 681 digital trust professionals across Europe, fielded 6-22 February 2026, published May 2026
  • ISACA: "New ISACA Research Reveals AI Blind Spot at the Heart of Enterprise Risk," press release, 2026
  • PwC: Caribbean Corporate Governance Survey 2026, 154 directors, the Bahamas, Barbados, Grenada, Jamaica, Saint Lucia, Trinidad and Tobago, and Bermuda, November 2025 to January 2026
  • ISO: ISO/IEC 42001:2023, Artificial Intelligence Management Systems
  • NIST: AI Risk Management Framework (AI RMF 1.0), GOVERN function
  • StarApple AI: Board-Level AI Training Study, 2026, starappleai.org
  • Caribbean AI Risk Management Council: CARA methodology and QAIRP certification, caribbeanairisk.com