Domain · 31%

AI Risk Management

This domain tests whether you can identify risks that are specific to AI systems, assess them credibly, and fold them into an organization's existing risk program rather than managing AI risk in a silo. It's weighted 31% of the exam.

What it covers

Risk categories this domain focuses on

  • Data and model risk: data quality, provenance, and bias that can quietly skew AI outputs.
  • Drift and change: AI systems can behave differently over time as they learn or as inputs shift.
  • Explainability gaps: decisions that are hard to fully explain create risk in regulated or high-stakes contexts.
  • Third-party and vendor AI: risk introduced by AI tools and models an organization doesn't build itself.

The bigger picture

AI risk belongs in enterprise risk, not beside it

A recurring theme in this domain is integration: AI-specific risks still need to be scored, prioritized, and reported using the same enterprise risk management processes an organization already runs, not tracked separately where they're easy to lose track of. This domain tests that connective tissue as much as it tests AI-specific risk knowledge on its own.

See how risk translates into technical controls →

Questions

Risk Management domain, answered

How is AI risk different from traditional IT risk?

AI systems can behave differently as they learn from new data, produce decisions that are hard to fully explain, and introduce risks like bias or drift that don't map cleanly onto traditional IT risk categories.

Does this domain overlap with Governance?

They're closely related, but Governance focuses on structures and accountability, while Risk Management focuses on identifying, assessing, and prioritizing specific risks and getting them into the enterprise risk program.

Ready to prep for AAISM™?

Certifi360 targets your gaps from minute one: 177 exam-style questions with rationale, 102 concepts, 115 flashcards, a 13-section cram sheet, and full timed exam simulations across all three weighted domains.