I want to start with a confession. When a colleague first forwarded me information about ISACA’s AI certification offerings, my initial reaction was something close to skepticism. Not because I don’t trust ISACA. I’ve been ISACA certified for years and I have enormous respect for what they’ve built in the audit and governance space. My skepticism was more along the lines of: is the industry actually ready for this, or are we just slapping “AI” on things because everyone is slapping “AI” on things right now?
After spending a lot of time with the material, talking to peers in the GRC community, and watching how the conversation around AI governance has evolved over the past two years, I’ve come around. Not uncritically, and not without some nuance, but I’ve genuinely come around.
A Little Context on Why This Moment Is Different
There’s a version of this conversation we’ve had before. Every few years, a new technology emerges and the certification industry races to produce credentials around it before anyone has fully figured out what governance of that technology even looks like. Sometimes those certs age beautifully. Sometimes they end up being cautionary tales about moving faster than the underlying discipline can support.
AI governance feels different to me, and I say that as someone who has been professionally skeptical of buzzword-driven cert launches for a long time. The difference is regulatory pressure. The EU AI Act is real, it has teeth, and it puts meaningful compliance obligations on organizations deploying AI systems across a wide range of risk categories. In the United States, federal agencies have been issuing AI governance guidance at a pace that would have seemed implausible three years ago. Organizations are not asking whether they need an AI governance framework anymore. They’re asking how to build one and who on their team is equipped to lead that work.
That shift from “should we think about this” to “we need someone who can actually do this” is exactly the kind of environment where a well-designed certification from a credible organization lands with real impact.
What ISACA Is Actually Offering and Who It’s Designed For
These are not technical AI certifications. They are not going to teach you to build machine learning models or write Python pipelines. What ISACA has built is a framework for understanding AI from a governance, risk, and audit perspective. That means understanding how AI systems introduce new categories of risk, knowing how to evaluate whether an AI deployment has appropriate controls, and being able to ask the right questions in an audit context.
For people coming from a GRC or audit background, that framing should feel familiar. We’ve been doing this with other technologies for years. AI governance is a new chapter in a book we already know how to read. ISACA has built out multiple levels of engagement here, from foundational certificate programs suitable for people who need AI literacy without deep specialization, to more rigorous offerings aimed at practitioners who will be leading AI governance work. You can find the full current credential offerings on ISACA’s credentialing page.
Where These Credentials Fit in a Crowded Market
Most AI certifications in the current market are either deeply technical or very broad and introductory. What’s been largely missing is a rigorous, governance-focused credential from an organization with established credibility in the enterprise risk and audit space. That’s the gap ISACA is filling. When a CISO or a Chief Audit Executive is staffing an AI governance function, they’re looking for people who understand risk and control frameworks. An ISACA credential signals that in a way that’s immediately legible to the people making those hiring decisions.
I’ve spoken with GRC professionals who worry that adding AI governance to their portfolio feels like scope creep. I’d push back on the framing. AI governance isn’t a detour from the audit and compliance work we already do. It’s an extension of it. The same principles of risk identification, control assessment, and continuous monitoring apply here too.
The Honest Assessment
These credentials are new, and newer credentials carry a specific kind of risk: the market hasn’t fully decided how much weight to give them. The CISA took years to build the recognition it has now. ISACA’s AI offerings won’t have that same immediate recognition on day one. If you’re counting on a credential to open doors right now, the more established ISACA certifications still carry more consistent market recognition.
That said, I think we’re at an inflection point where getting in early actually matters. The organizations building AI governance functions right now are doing it with a small pool of people who have the right combination of skills. Being one of the people who has invested in this space before it becomes a standard job requirement is a different kind of career positioning than waiting until the credential is everywhere. In my experience, being eighteen months early on a professional development decision tends to pay off better than being right on time.
There’s also the learning itself to consider. Working through AI governance frameworks in a structured way, understanding the regulatory environment, and developing vocabulary for the specific risk categories that AI introduces has made me meaningfully better at my job. The cost is reasonable by professional certification standards. If your organization has a professional development budget, this is a straightforward case to make to your manager.
If you’re in audit, compliance, or GRC and you’ve been watching the AI governance conversation from the sidelines, the dust is settling faster than you might think. ISACA has built something that fits the way people in our profession think about risk and control. Take a look at what’s available, be honest with yourself about where AI governance fits in your career goals, and make a deliberate decision. That’s the advice I’d give a colleague over coffee, and it’s the advice I’m giving you now.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
