Skip to main content
AI & Machine LearningQuantum Computing

ISACA Bolsters AI Governance with New Certification Amid Skills Gap

Professionals gather around a table with laptops and notepads in a conference room with natural daylight.

"The governance certification is important in terms of providing an umbrella around the operations of professions from cyber to audit to risk. We’re trying the help individuals in controlling and governing AI rather than having AI on the loose," said Chris Dimitriadis during a media roundtable at ISACA’s Europe conference in Munich, Germany on 8 October.

ISACA to launch an AI governance certification in early 2027

Training and certification body ISACA plans to introduce an AI governance certification, with applications already being accepted in a beta phase and a full launch scheduled for early 2027. ISACA characterizes this credential as the capstone to a suite of AI-focused certifications designed to help professionals manage AI "securely and responsibly." The organization framed the new governance credential as an "umbrella" that spans the operational needs of multiple professions involved with AI.

Built on an existing set of AI credentials: AAIA, AAISM and AAIR

ISACA’s rollout of AI-related certifications is not starting from scratch. The charity and professional body has already introduced three advanced credentials that it describes as part of the same ecosystem:

  • Advanced in AI Audit (AAIA)
  • Advanced in AI Security Management (AAISM)
  • Advanced in AI Risk (AAIR)

The governance certification is presented as completing that series, signaling an intent to cover auditing, security management, risk and overall governance for AI systems.

Concrete gaps in training and governance persist

ISACA’s own surveys and research underline why the new credential is being pushed. Earlier research cited by ISACA found that only 32% of digital trust professionals believe their organizations adequately address AI risks such as privacy, bias and security, despite widespread workplace adoption of the technology. Separately, ISACA’s 2025 AI Pulse Poll — which surveyed over 3,000 digital trust professionals — found that within organizations 32% reported there is no AI training provided to any employees.

Those twin findings form the immediate rationale for ISACA’s attention to training: a large minority of practitioners perceive governance shortfalls, and roughly one-third of organizations provide no AI training at all, according to ISACA’s published figures.

Adoption is rising while skills priorities shift

Adoption of AI in enterprise operations is growing. ISACA’s State of Cybersecurity 2026 report found that 54% of organizations are involved in onboarding or implementing AI solutions, up from 46% in 2024. Alongside that deployment trend, ISACA’s 2026 research concluded that AI is set to take over "most of the technical and orchestration tasks," leaving human professionals to focus on roles requiring context, intuition and communication — namely governance, AI configuration and monitoring, and final decision-making.

The State of Cybersecurity 2026 report also identifies specific security skills that respondents flagged as most important: threat detection and response and identity and access management ranked at the top. Vulnerability management, data security and incident response were also highlighted as critical capabilities as organizations integrate AI technologies.

What this means for auditors, cyber professionals, and project/IT managers

  • Auditors and risk managers: ISACA positions the governance certification as an organizing layer that ties auditing, risk assessment and broader governance together. The credential is intended to help these professionals shape and verify controls around AI systems.
  • Cyber and IT professionals: With ISACA’s research indicating that technical orchestration will increasingly be automated, security teams should expect a stronger emphasis on threat detection and response, identity and access management, vulnerability management, data security and incident response when securing AI-enabled operations.
  • Project managers and IT managers: Chris Dimitriadis emphasized the need for "specialized AI training across the domain" for those who manage or govern AI projects, calling for holistic curricula that include soft skills to enable effective communication and decision-making in AI deployments.

ISACA reports positive uptake of its AI trainings to date, particularly in regions it described as "AI-forward" — Europe, the US and Asia. Yet the dual findings — rising adoption and persistent training gaps — present a simple, measurable test for the coming year: will the governance certification and existing credentials reduce the share of organizations that either lack AI training or judge their governance inadequate?

The early-2027 timeline for the new governance credential sets a clear next milestone. Between now and then, organizations and practitioners will be watching whether enrollment expands beyond current uptake, and whether the credential helps close the specific shortfalls ISACA’s research identified: training coverage for employees and confidence that privacy, bias and security risks are being addressed.

Original story