Jason Edwards
Certified: The ISACA AAIR Audio Course
Welcome to Certified: The ISACA AAIR Audio Course. If you’re here, you’re probably seeing AI show up everywhere: in products, in internal tools, in vendor roadmaps, and in executive conversations that expect quick answers. I built this course for people who need to evaluate AI systems responsibly, even when they don’t have time to become machine learning specialists. Across these episodes, we’ll translate AI concepts into assurance language you can use: governance, controls, evidence, risk, and accountability. You’ll learn how to ask better questions, how to recognize weak assurances, and how...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 67 — Handle Intellectual Property Risks: Training Data Rights and Output Ownership (Domain 1) 14.02.2026 12:19
Intellectual property (IP) risks in AI represent a "two-way street" involving the data used to train models and the content generated by those models. This episode details the legal hazards of using copyrighted or proprietary data in training sets and the ongoing uncertainty regarding the ownership of AI-generated outputs. For the AAIR exam, candidates must be able to identify these IP boundaries...
Episode 66 — Navigate Regulatory Expectations: How to Stay Aligned Without Overpromising (Domain 1) 14.02.2026 11:56
As global AI regulations evolve, organizations must learn to navigate a complex web of requirements without committing to standards they cannot realistically meet. This episode discusses the current state of AI regulation and how to interpret high-level guidance from bodies like NIST or the EU AI Act in the context of your specific industry. For the AAIR certification, it is vital to understand th...
Episode 65 — Manage Reputation Risk from AI: Trust Events, Public Response, and Recovery (Domain 1) 14.02.2026 12:24
Reputation is an intangible yet critical asset that can be shattered by a single visible AI failure, making its management a key focus of Domain 1. This episode explores the concept of "trust events"—incidents where AI behavior contradicts public expectations or corporate values—and how to plan for a rapid, transparent response. For the AAIR exam, candidates must understand the link between techni...
Episode 64 — Establish AI Risk Metrics Dashboards: What to Track and What to Ignore (Domain 2) 14.02.2026 13:17
A well-designed risk dashboard provides real-time visibility into the health of an organization’s AI ecosystem, but its value depends on selecting the right metrics. This episode explores how to build a dashboard that balances technical telemetry, like model error rates, with program-level metrics, such as the number of outstanding risk assessments. For the AAIR certification, you must understand...
Episode 63 — Write Executive-Ready AI Risk Reports: Clear Findings and Clear Decisions (Domain 1) 14.02.2026 12:43
The impact of a risk professional is often determined by their ability to write reports that lead to decisive action from executive leadership. This episode focuses on the structure of high-impact AI risk reports, emphasizing the need for a "bottom-line-up-front" approach that highlights clear findings and specific requested decisions. For the AAIR exam, candidates should know how to synthesize co...
Episode 62 — Design Control Libraries for AI: Reusable Patterns Across Use Cases (Domain 2) 14.02.2026 12:42
Efficiency in Domain 2 is achieved by moving away from bespoke control design for every project and toward a centralized library of reusable control patterns. This episode details how to build a control library that covers common AI risks like data leakage, model drift, and unauthorized access, allowing teams to "plug and play" verified mitigations. For the AAIR certification, you must understand...
Episode 61 — Prioritize AI Risks for Action: Triage Methods That Avoid Analysis Paralysis (Domain 2) 14.02.2026 13:36
Efficient risk management requires a disciplined approach to triage, ensuring that the most critical AI vulnerabilities are addressed before resources are spent on low-impact issues. This episode explores various prioritization frameworks, such as the Eisenhower Matrix or risk-ranking heat maps, adapted specifically for the speed of AI development. For the AAIR exam, candidates must understand how...
Episode 60 — Quantify AI Risk When Possible: Likelihood, Impact, and Confidence Ranges (Domain 2) 14.02.2026 17:05
While qualitative assessments are useful for ethics, many AI risks can and should be quantified to provide more precise guidance for decision-makers in Domain 2. This episode covers the methods for quantifying risk by estimating the likelihood of an AI failure and the range of its potential financial impact. For the AAIR certification, you must understand how to use statistical distributions and "...
Episode 59 — Build Strong AI Risk Narratives: Scenario Thinking Without Guesswork (Domain 1) 14.02.2026 18:08
AI risk narratives are essential for making abstract technical threats understandable to business leaders, but they must be based on evidence rather than speculation. This episode teaches you how to construct realistic, data-driven risk scenarios that illustrate the potential business impact of an AI failure. For the AAIR exam, candidates should know how to use "scenario thinking" to explore "what...
Episode 58 — Spaced Retrieval Review: Lifecycle Risk Scenarios and Control Choices Rapid Recall (Domain 3) 14.02.2026 23:00
Success in Domain 3 requires the ability to instantly link a specific stage of the AI lifecycle to its most relevant risks and controls. This episode utilizes the spaced retrieval method to drill you on rapid recall for scenarios involving data poisoning, model drift, adversarial inputs, and retirement procedures. We present a series of fast-paced "if-then" questions: If you detect a performance d...
Episode 57 — Retire AI Systems Safely: Data Deletion, Archiving, and Lifecycle Closure (Domain 3) 14.02.2026 17:46
The final stage of the AI lifecycle, retirement, is often overlooked but carries significant risks regarding data privacy and intellectual property. This episode explores the procedures for safe decommissioning, including the secure deletion of training data that is no longer needed and the archiving of model weights for historical or regulatory reference. For the AAIR exam, candidates must unders...
Episode 56 — Validate Third-Party Models: Assumptions, Limits, and Hidden Dependencies (Domain 3) 14.02.2026 19:02
When using AI models developed by external vendors, the risk management challenge shifts from internal process control to external validation. This episode focuses on how to verify third-party models by probing their underlying assumptions, performance limits, and hidden dependencies on specific software libraries or data streams. For the AAIR certification, you must know how to ask the right ques...
Episode 55 — Control Retraining and Updates: Governance Gates and Regression Testing (Domain 3) 14.02.2026 18:46
The lifecycle of an AI model is iterative, but retraining a model on new data introduces the risk of "regression," where previously corrected errors reappear or new biases are introduced. This episode details the governance gates that must be passed before a retrained model is allowed back into production. For the AAIR exam, candidates must understand the importance of regression testing, which ve...
Episode 54 — Build Fallbacks and Fail-Safes: What Happens When AI Must Stop (Domain 3) 14.02.2026 20:20
Every mission-critical AI system must have a robust "Plan B" to ensure business continuity if the model fails or behaves unpredictably. This episode explores the design of fallbacks, such as reverting to a traditional rule-based system, and fail-safes, which are automated triggers that halt a process before harm can occur. For the AAIR certification, understanding how to define these trigger point...
Episode 53 — Manage Human Oversight: Approvals, Overrides, and Accountability Under Pressure (Domain 3) 14.02.2026 17:44
The concept of "human-in-the-loop" is a vital safety mechanism in high-stakes AI systems, yet it introduces its own set of risks if not managed properly. This episode focuses on the design of effective human oversight, including the formal process for approving AI-generated decisions and the authority to override the model when it produces an obviously incorrect result. For the AAIR exam, candidat...
Episode 52 — Handle AI Incidents Well: Triage, Containment, Communication, and Recovery (Domain 2) 14.02.2026 19:45
AI-related incidents require a specialized response plan that differs from traditional IT security because the failure might be behavioral rather than technical. This episode details the AI incident response lifecycle, starting with triage to determine the severity and nature of the failure—be it a security breach, a safety violation, or an ethical lapse. For the AAIR certification, you must under...
Episode 51 — Monitor Drift in Production: Data Shift, Concept Shift, and Silent Degradation (Domain 3) 14.02.2026 17:37
Maintaining the integrity of an AI system after deployment requires a sophisticated approach to monitoring "drift," which is the gradual decline in a model's predictive power due to changing environmental conditions. This episode explores the two primary forms of drift: data shift, where the statistical distribution of input data changes, and concept shift, where the actual relationship between in...
Episode 50 — Deploy Safely: Change Management, Rollback Plans, and Guardrail Monitoring (Domain 3) 14.02.2026 15:58
The deployment phase is the most critical transition in the AI lifecycle, requiring a structured approach to change management to prevent service disruptions. This episode details the steps for a safe deployment, including the use of "canary releases" or "blue-green" deployments to test the new model in a limited capacity before a full rollout. For the AAIR certification, candidates must know how...
Episode 49 — Control Access and Least Privilege: Who Can Use, Train, and Deploy Models (Domain 3) 14.02.2026 16:41
Access control is a fundamental administrative and technical requirement for maintaining the security of the AI lifecycle in Domain 3. This episode focuses on the implementation of Role-Based Access Control (RBAC) to ensure that only authorized personnel can access training data, modify model architectures, or trigger a production deployment. For the AAIR exam, candidates should understand the pri...
Episode 48 — Secure AI Interfaces: APIs, Plugins, Agents, and Permission Boundaries (Domain 3) 14.02.2026 19:12
The points where AI systems interact with other software—APIs, plugins, and autonomous agents—are often the most vulnerable to security breaches. This episode covers the necessity of establishing strict permission boundaries and "least privilege" access for AI interfaces to prevent unauthorized data access or system manipulation. For the AAIR certification, you must understand the risks of "confus...
Episode 47 — Reduce Model Inversion and Leakage: Privacy Attacks and Practical Mitigations (Domain 3) 14.02.2026 19:44
Model inversion and membership inference attacks are privacy-focused threats where an attacker attempts to extract sensitive training data or determine if a specific individual's data was used in the model. This episode details these "leakage" risks, which are particularly dangerous when models are trained on PII or proprietary information. For the AAIR exam, candidates must know how to apply miti...
Episode 46 — Prevent Data Poisoning: Supply Chain Controls for Training Data Integrity (Domain 3) 14.02.2026 16:55
Data poisoning is a long-term threat where an attacker corrupts the training data to create "backdoors" or systemic biases in the resulting model, a key concern in Domain 3. This episode explores the supply chain risks associated with training data, emphasizing the need for strict controls over data sources and ingestion pipelines. For the AAIR certification, you must understand how to verify the...
Episode 45 — Protect Against Adversarial Inputs: Evasion, Prompt Injection, and Abuse Patterns (Domain 3) 14.02.2026 18:13
Adversarial attacks represent a unique class of security threats where small, often invisible changes to inputs can cause an AI model to misbehave. This episode focuses on the mechanics of evasion attacks, where an attacker bypasses a classifier, and prompt injection, where an attacker hijacks a large language model's instructions to perform unauthorized actions. For the AAIR exam, candidates must...
Episode 44 — Understand Explainability Options: When You Need It and What Works (Domain 3) 14.02.2026 19:52
Explainability is the degree to which a human can understand the cause of a decision made by an AI system, a critical requirement for high-stakes environments in Domain 3. This episode distinguishes between "black box" models like deep neural networks and "white box" models like decision trees, explaining the trade-offs between complexity and transparency. For the AAIR certification, you must unde...
Episode 43 — Test for Safety Failures: Hallucinations, Toxicity, and Unsafe Recommendations (Domain 3) 14.02.2026 17:56
Safety testing is a non-negotiable step in Domain 3, particularly for generative models and autonomous systems that interact directly with humans. This episode examines the detection and mitigation of safety failures such as hallucinations, where the AI generates plausible but false information, and toxicity, where the output is harmful, biased, or inappropriate. For the AAIR exam, candidates must...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.