Skip to main content
v2026.11,858 entries · CC-BY 4.0

Direct comparison

AIGP vs ISACA AAIA vs AAISM: AI Governance Certs

IAPP AIGP, ISACA AAIA and ISACA AAISM compared on issuer, prerequisites, domains, fees and best-fit seat — and why none certifies your organisation.

Written and maintained by CASRAI Editorial Board

Last updated

Ask CASRAI · free to try

Ask about AIGP vs ISACA AAIA vs AAISM: AI Governance Certs

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

How do IAPP AIGP, ISACA AAIA, ISACA AAISM compare side by side?

The table below compares IAPP AIGP, ISACA AAIA, ISACA AAISM across 9 procurement-relevant dimensions, from issuing body through best-fit seat.

Side-by-side comparison

DimensionIAPP AIGPISACA AAIAISACA AAISM
Issuing bodyThe IAPP, which describes itself as “a policy neutral, not-for-profit association founded in 2000” whose mission is to “define, promote and improve the professions of privacy, AI governance and digital responsibility globally.”ISACA. The credential is marketed as “The World’s First Advanced AI Audit Certification.” That is ISACA’s own positioning claim, not an independent finding.ISACA. Published in full as “ISACA Advanced in AI Security Management (AAISM)” — the security-management counterpart to AAIA, issued by the same body.
Who it is forThe person who builds and runs the AI governance programme: policy, principles, applicable law, and the risk-management work across the AI life cycle.The auditor who tests somebody else’s AI governance — the person writing the findings, not the person writing the policy.The security manager who owns AI-related security risk: policy implementation, controls, and assurance in AI security domains. ISACA aims it at experienced IT professionals already holding CISM or CISSP.
PrerequisitesNone published on IAPP’s AIGP certification page. This is the open-entry credential of the three — a policy analyst, a compliance officer or a lawyer can sit it without first holding an audit or security certification.Gated. ISACA requires an active CISA, or — for candidates in IT audit or advisory roles — one of a named list of equivalent designations: CIA, US CPA, ACCA, FCCA, Canadian CPA, Australian CPA/FCPA, Japanese CPA, ICAEW ACA/FCA, CNA, CA ANZ/FCA, or Hong Kong CPA/FCPA.Gated, but on a different axis: an active CISM or CISSP, plus experience in security or advisory roles and some expertise assessing, implementing and maintaining AI systems. A CISA does not get you in here; a CISM does.
Domains coveredIAPP’s certification page states coverage rather than named domains: foundational knowledge of AI systems, their use cases and impacts, and responsible AI principles; how current and emerging laws apply to AI systems and how major frameworks are capable of being responsibly governed; and the AI life cycle, the context in which AI risks are managed, and the implementation of responsible AI governance. The full domain breakdown is published separately in the free AIGP Body of Knowledge and Exam Blueprint.Three named domains: AI Governance and Risk; AI Operations; AI Auditing Tools and Techniques. The third is what distinguishes it — it is the testing tradecraft, not the governance design.Three named domains: AI Governance and Program Management; AI Risk Management; AI Technologies and Controls. Note the overlap with AAIA on governance and risk, and the divergence on the third domain — controls rather than audit technique.
What it does NOT coverIt does not confer audit competence or security-engineering competence, and it does not make its holder independent of the programme they run. An AIGP who wrote the policy is not an independent reviewer of that policy.It is a credential in auditing AI, not in building or securing AI. It also does not, by itself, establish organisational independence — an in-house auditor with an AAIA is still an in-house auditor.It is security management, not legal or policy analysis, and not audit. A security manager credentialed here is still the first line being tested, not the person testing it.
Relationship to ISO/IEC 42001 certificationNone, and the distinction matters. AIGP certifies a person. ISO/IEC 42001 certifies an organisation’s AI management system through an accredited certification body. Employing AIGP holders does not put your organisation anywhere on the 42001 path.Also a personal credential, not an organisational one. An AAIA holder may well be the person running your internal readiness work ahead of a 42001 audit, but the credential itself certifies only them.Same: personal. None of these three is an accreditation of an organisation, and none is a licence to practise — there is no regulator withdrawing any of them.
Published feeNot stated on the IAPP’s AIGP certification page, which directs candidates to purchase the exam through the IAPP store. We are not quoting a figure we did not see published on the credential page.US$459 for ISACA members, US$599 for non-members, with a six-month eligibility window from registration in which to take the exam.US$459 for ISACA members, US$599 for non-members, with the same six-month eligibility window — as published on ISACA’s AAISM credential page, not inferred from AAIA.
Free study materialSubstantial and free: the AIGP Body of Knowledge and Exam Blueprint, an AIGP Study Guide covering exam format and sample questions, and the Certification Candidate Handbook with testing policies and procedures. You can scope the whole syllabus before spending anything.ISACA publishes the domain structure and eligibility rules openly; study materials and review courses are sold separately. Budget beyond the exam fee.Same pattern — domains and eligibility are published, preparation material is a separate purchase.
Best-fit seatThe AI governance lead, the responsible-AI programme manager, the privacy or compliance officer picking up AI, the policy counsel. In a university: the research-compliance officer, the IRB administrator handling AI-in-research protocols, the research-security officer.Internal audit, and specifically an internal audit shop that already holds CISAs — the prerequisite makes the decision for you. If your auditors hold CISAs today, AAIA is the cheapest credible step to auditing AI; if they do not, it is a two-certification journey.The CISO’s team — whoever owns AI security risk day to day. In a university, that is typically the information-security office rather than research administration.

Common questions

Common questions about IAPP AIGP vs ISACA AAIA vs ISACA AAISM

Does any of these certify our organisation?

+

No. All three certify an individual. The credential that applies to an organisation is ISO/IEC 42001, which certifies an AI management system through an accredited certification body — a different object entirely, with its own path, timeline and Annex A controls. Employing certified people is not the same as being a certified organisation, and no amount of AIGP, AAIA or AAISM holders on staff changes your organisation’s certification status.

Can someone without a CISA sit the AAIA?

+

Only through ISACA’s named equivalents, and only in the right role. ISACA requires an active CISA, or — for candidates focused on IT audit or advisory work — one of a specific list including CIA, US CPA, ACCA, FCCA, Canadian CPA, Australian CPA/FCPA, Japanese CPA, ICAEW ACA/FCA, CNA, CA ANZ/FCA and Hong Kong CPA/FCPA. A governance or policy professional with none of those cannot sit AAIA, which is exactly why AIGP and AAIA are not alternatives to each other.

Which is the industry standard, and what are the pass rates?

+

We are not going to tell you, because neither is published in a form we can verify. None of these three is an industry standard in any formal sense — there is no accreditation body designating one, and none of them is a licence. Pass rates, holder counts and salary uplift figures circulate widely for all three; we found none of them published by the issuing bodies, so this page asserts none. Treat any source that does quote them as owing you a citation.

We are a university. Who should we credential for AI oversight?

+

Split it by seat rather than buying one credential for everyone. Research-compliance staff, IRB administrators dealing with AI in human-subjects protocols, research-security and export-control officers, and sponsored-programs staff writing AI terms into subawards are all doing governance work, and AIGP is the open-entry credential that fits them — none of them will hold a CISA. Your internal audit shop is the opposite case: if it already holds CISAs, the AAIA prerequisite is already satisfied and the step to auditing AI systems is short. University research computing and the information-security office are the AAISM constituency. The decisive question is not which credential is best but which prerequisite your people already hold.

Does a certified evaluator satisfy an independence requirement?

+

No, and the two are different kinds of fact. A credential attests that an individual passed an exam covering a published body of knowledge. Independence is a relationship question — who pays the evaluator, what else they sell the developer, who employs them. CASRAI’s NIKOLAI dictionary keeps these apart: its N8 element, Evaluator Independence and Conflict of Interest, records “a record of declared financial, organisational and personal relationships between an evaluator and the developer being evaluated, and the independence test applied to clear the evaluator for the engagement.” No credential maps to that element, and none of the three on this page attempts to. NIKOLAI is CASRAI’s own independent, unendorsed dictionary, and every crosswalk row on that element is a shadow mapping — CASRAI’s own reading of a published document. No organisation has filed a Mapping Declaration for it, and no lab, evaluator or regulator named on a shadow row has declared, endorsed or been consulted on it.

Can one person hold more than one of these?

+

Yes, and in a small team that is often the practical route — but be honest about what it does to independence. The same person holding AIGP and AAIA can design the governance programme and audit it, and holding both credentials does not make that arrangement independent. The credentials are cumulative; the separation of duties is not.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

AI policy question? Get an answer citing the framework.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.