VERGLEICHE
AAIR or PECB LAIRM? AI risk as an add-on tier or as a standalone credential
AI risk management is the youngest discipline in the certification market, and ISACA and PECB occupy it with fundamentally different models: on one side an add-on tier for holders of an ISACA certification that is still in its beta phase, on the other a standalone, accredited lead certification built around the EU AI Act and the NIST AI RMF. The comparison, with the numbers and the access model.
By Daniel Thomas HeesselLast updated: July 30, 20266 min read
"AAIR or PECB LAIRM" is the question asked by risk and GRC professionals who want to document AI risk management with a certification for the first time. The honest answer: before comparing content, you have to compare the access model. The two certify the same young discipline, but along fundamentally different paths: as an extension of an existing profile or as a standalone credential.
AI risk management has only just emerged as a certifiable discipline; both programmes are young, and one of them is not even finished yet. That is exactly why a close look pays off: whoever decides now is deciding on the model, not on an established market standard.
What the two stand for
The AAIR (Advanced in AI Risk) is the risk specialisation of ISACA's Advanced series. It is aimed at people who already hold an active ISACA certification such as CISA, CISM or CRISC, and adds AI risk to that profile: AI risk governance, AI risk program management, and risk management across the AI lifecycle. According to ISACA, the programme has been running in a beta phase since April 2026.
The PECB LAIRM (PECB Certified Lead AI Risk Manager) is a standalone personnel certification accredited under ISO/IEC 17024. It attests to building and operating an AI risk management programme, drawing on several frameworks, including the NIST AI RMF and the EU AI Act. Access is tiered: the exam is open to everyone, and the levels from Provisional up to Senior Lead Manager grow with documented professional experience and project hours.
The numbers in direct comparison
| Provider | ISACA | PECB |
|---|---|---|
| Acquisition cost (exam, EUR) | €551 | €920 |
| Total cost over 5 years (EUR)i | €8,643 | €13,472 |
| Prerequisites | Active CISA, CISM, CRISC, CGEIT, CDPSE or equivalent | No formal prerequisite to sit the exam. Certification is tiered: Provisional Manager with no experience; Manager needs 2 years of professional experience (1 year in AI risk management) and 200 hours of project activities; Lead Manager needs 5 years (2 years in AI risk management) and 300 hours; Senior Lead Manager needs 10 years (7 years in AI risk management) and 1,000 hours. Plus signing the PECB Code of Ethics. |
| Exam format | In beta, details pending | Scenario-based exam across five domains (AI risk principles, governance, identification, evaluation/treatment/monitoring, organizational learning), open-book, about 3 hours, 70 percent passing score. |
| Validity | 3 years | 3 years |
| CPE effort | 20 hrs/year | 30 hrs/year |
| CertMap scoreHow we score → | 5 / 12Market strength 2/6 Substance3/6 | 7 / 12Market strength 3/6 Substance4/6 |
Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.
Two patterns stand out in the table before content even enters the discussion:
- Access separates the two more sharply than the subject matter. The AAIR is out of reach without an active ISACA certification or an equivalent; it is an add-on, not an entry point. The LAIRM has no admission hurdle for the exam; how much the certification says is governed by the tiered levels through documented experience and project hours.
- Two cost models, not simply two prices. With ISACA the exam is cheaper, and the annual fee covers all three Advanced certifications of the series together; in return, the running costs of the required base certification always come on top. With PECB the entry is more expensive and the annual fee is charged per certification, but nothing else is attached. How CertMap calculates such running costs is explained in the cost methodology.
In terms of content, both occupy the same field, with different frames of reference: the AAIR stays within the ISACA programme and its governance language, while the LAIRM works along external frameworks such as the NIST AI RMF and the EU AI Act.
Same discipline, two access models. The AAIR extends an existing ISACA profile, the LAIRM stands on its own.
Prerequisites: base certification versus tier model
The two regulate access in fundamentally different ways:
- AAIR: Requires an active ISACA certification or an equivalent (CISA, CISM, CRISC, CGEIT or CDPSE). Without that history, there is no path to the AAIR.
- PECB LAIRM: No formal prerequisite for exam admission. The certification level depends on experience: from Provisional Manager without any experience requirement up to Senior Lead Manager with years of practice and documented project hours; the full Lead level requires five years of professional experience, two of them in AI risk management.
In practice this means: anyone who does not yet hold a certification cannot start with the AAIR. The path then leads either through an ISACA base certification first, or directly to PECB.
The exams
Here the field's youth shows: according to ISACA, the AAIR exam is still in its beta phase, and binding details on the final exam format are outstanding. The LAIRM exam, by contrast, is established: case-based across five domains, open book, around three hours, with a passing threshold of 70 percent. Both exams are currently offered exclusively in English; neither of the two has a German exam variant.
Our assessment
What our rating says: Both certifications are young and sit in the midfield of the CertMap rating, with the LAIRM ahead of the AAIR. The gap arises mainly from market recognition and practical evidence: the AAIR is so new that it is still in its beta phase and practically not yet visible in the market, while the LAIRM, as an accredited certification with an established exam procedure, already has a firmer foundation. This is a statement about maturity and adoption, not about the substantive quality of the programmes. How the rating axes are constructed is explained in the rating methodology.
The decision becomes easier when approached from your own starting point:
- If you already maintain an ISACA profile (CISA, CISM, CRISC), the AAIR is the natural addition: the annual fee of the Advanced series is low, and the continuing education hours can be earned within the same ecosystem. The price is the dependence on the base certification and the vagueness of the beta phase.
- If you need a standalone AI risk credential without an ISACA history, for instance in consulting on EU AI Act implementation, the LAIRM is the right choice: accredited, with an established exam format, aligned with the frameworks that clients and supervisory authorities work with.
- If you do not want to wait for the beta to mature, you effectively have only one choice: the LAIRM is finished today, the AAIR is not.
In a few years this picture may shift, once the AAIR leaves the beta and ISACA's reach kicks in behind it. But anyone deciding today should start from today's state.
Frequently asked questions
Can I take the AAIR without an ISACA certification?
No. The AAIR requires an active ISACA certification or an equivalent (CISA, CISM, CRISC, CGEIT or CDPSE). Anyone who does not hold one must first earn a base certification, or go directly for a standalone credential such as the PECB LAIRM.
Is the PECB Lead AI Risk Manager tied to an ISO standard?
No. Unlike PECB's ISO/IEC 42001 schemes, the LAIRM is a PECB-owned scheme that integrates several frameworks, including the NIST AI RMF and the EU AI Act. The certification itself is accredited under ISO/IEC 17024.
Are the exams available in German?
No. Both exams are currently offered only in English. Anyone looking for a German-language exam will, at present, not find one in the AI risk space at either provider.
Read next:AAISM or PECB 42001 Lead Implementer? Running the programme or building the management system →TCO Methodology in Portfolio Mode →