Jason Edwards

Certified: The ISACA AAIR Audio Course

Welcome to Certified: The ISACA AAIR Audio Course. If you’re here, you’re probably seeing AI show up everywhere: in products, in internal tools, in vendor roadmaps, and in executive conversations that expect quick answers. I built this course for people who need to evaluate AI systems responsibly, even when they don’t have time to become machine learning specialists. Across these episodes, we’ll translate AI concepts into assurance language you can use: governance, controls, evidence, risk, and accountability. You’ll learn how to ask better questions, how to recognize weak assurances, and how...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 42 — Establish Model Validation: Performance, Robustness, and Generalization Testing (Domain 3) 14.02.2026

Model validation is the process of confirming that an AI system performs its intended function accurately and reliably before it reaches production. This episode explores the three pillars of validation: performance testing against objective metrics, robustness testing to see how the model handles noisy or unexpected inputs, and generalization testing to ensure it works on data it hasn't seen befo...

Episode 41 — Control Training and Tuning: Reproducibility, Versioning, and Provenance Discipline (Domain 3) 14.02.2026

Effective risk management during the training and fine-tuning phases requires rigorous discipline to ensure that AI models are both predictable and auditable. This episode focuses on the necessity of reproducibility, where a model can be recreated exactly using the same data, code, and hyperparameters. For the AAIR exam, candidates must understand the role of versioning—not just for the model code...

Episode 40 — Manage Sensitive Data Risks: PII, PHI, Secrets, and Proprietary Content (Domain 3) 14.02.2026

The use of sensitive data in AI training and inference poses significant security and privacy risks that are central to Domain 3. This episode details the specific hazards of processing Personally Identifiable Information (PII), Protected Health Information (PHI), trade secrets, and proprietary intellectual property. For the AAIR exam, candidates must know how to implement technical mitigations su...

Episode 39 — Detect and Reduce Bias: Representation, Measurement, and Fairness Tradeoffs (Domain 3) 14.02.2026

Detecting and mitigating algorithmic bias is one of the most complex and critical tasks in Domain 3. This episode explores the different types of bias that can enter an AI system, from historical bias in the training data to measurement bias in the model’s evaluation metrics. For the AAIR certification, you must understand the technical methods for detecting bias, such as disparate impact analysis...

Episode 38 — Validate Data Quality Early: Completeness, Accuracy, Labeling, and Lineage (Domain 3) 14.02.2026

Data quality is the most significant determinant of AI model performance and reliability, a key principle of Domain 3. This episode covers the technical aspects of data validation, including checking for completeness, accuracy, and the integrity of data labeling. For the AAIR exam, candidates must understand how poor data quality can lead to "garbage in, garbage out" scenarios where even the most...

Episode 37 — Control Data Collection and Consent: Privacy, Purpose Limits, and Minimization (Domain 3) 14.02.2026

The integrity of an AI system begins with the data used to build it, making data collection and consent a critical focus for Domain 3. This episode explores the legal and ethical requirements for data acquisition, emphasizing the principles of purpose limitation and data minimization. For the AAIR certification, you must understand how to verify that data was collected with appropriate consent and...

Episode 36 — Map the AI Lifecycle Clearly: From Idea to Retirement Without Blind Spots (Domain 3) 14.02.2026

Domain 3 requires a granular understanding of the AI lifecycle, from the initial concept and data acquisition stages through to deployment, maintenance, and eventual decommissioning. This episode provides a comprehensive map of this lifecycle, highlighting the specific risk points inherent in each phase. For the AAIR exam, candidates must be able to identify where different controls are most effec...

Episode 35 — Spaced Retrieval Review: Program Management Decisions and Risk Response Recall (Domain 2) 14.02.2026

Mastering Domain 2 requires a solid grasp of program management mechanics and the ability to choose the correct risk response under exam pressure. This episode utilizes spaced retrieval to reinforce concepts such as the components of an AI risk operating model, the types of risk treatment, and the criteria for escalating AI incidents. We provide rapid-fire scenarios where you must quickly determin...

Episode 34 — Build Evidence for Audits: Artifacts That Prove Control, Not Intentions (Domain 2) 14.02.2026

Auditors require tangible proof of control effectiveness, making the creation of a robust evidence trail a core competency in Domain 2. This episode focuses on the transition from "intention-based" risk management to "evidence-based" compliance, where every control is backed by a verifiable artifact. For the AAIR certification, you must understand what constitutes valid evidence for an AI system,...

Episode 33 — Plan AI Risk Training That Sticks: Who Needs What and Why (Domain 2) 14.02.2026

Training is a vital administrative control in Domain 2, designed to foster a risk-aware culture across the organization. This episode details how to design and deploy AI-specific training programs tailored to different audiences, from executive leadership needing high-level strategic awareness to technical developers requiring deep dives into adversarial defense and bias mitigation. For the AAIR e...

Episode 32 — Make AI Vendor Risk Real: Due Diligence, Contracts, and Ongoing Oversight (Domain 2) 14.02.2026

As organizations increasingly rely on third-party AI services, managing vendor risk becomes a primary focus of Domain 2. This episode covers the end-to-end vendor management process, from conducting initial due diligence on a provider’s security posture and model transparency to drafting specific contractual clauses that protect against intellectual property theft or data breaches. For the AAIR ce...

Episode 31 — Coordinate Across Teams: Legal, Privacy, Security, Data, and Product Alignment (Domain 2) 14.02.2026

Effective AI risk management in Domain 2 requires deep cross-functional coordination, as the risks associated with machine learning often span multiple traditional corporate silos. This episode explains how to build a collaborative environment where legal teams assess regulatory compliance, privacy officers manage data protection, and security professionals defend against adversarial attacks. For...

Episode 30 — Create Escalation Triggers: When AI Risk Must Go to Leadership (Domain 2) 14.02.2026

Knowing when to escalate a technical AI issue to senior leadership is a vital skill that ensures high-stakes risks receive appropriate attention, a focus of Domain 2. This episode details the creation of escalation triggers based on pre-defined thresholds of impact, such as a breach of sensitive data, a significant drop in model accuracy for critical systems, or a legal challenge related to algori...

Episode 29 — Build Ongoing Monitoring: Drift, Performance, Incidents, and Emerging Threats (Domain 2) 14.02.2026

AI risk management does not end at deployment; it requires continuous monitoring to detect the "silent failures" that often plague autonomous systems in Domain 2. This episode explores the critical need for monitoring data and concept drift, where the relationship between input variables and the target output changes over time, leading to a decline in model performance. For the AAIR exam, candidat...

Episode 28 — Define AI Controls and Testing Plans: What to Verify and How Often (Domain 2) 14.02.2026

The effectiveness of any AI risk program rests on the strength of its controls and the rigor of its testing plans, a key area of expertise for Domain 2. This episode defines the difference between preventive, detective, and corrective controls specifically as they apply to AI systems, such as input filters, performance alerts, and automatic failovers. For the AAIR certification, understanding what...

Episode 27 — Manage AI Risk Exceptions Safely: Approvals, Time Limits, and Compensating Controls (Domain 2) 14.02.2026

Exceptions to AI risk policies are sometimes necessary for innovation or emergency situations, but they must be managed with extreme discipline to prevent them from becoming permanent vulnerabilities. This episode focuses on the formal exception management process, including the requirement for senior-level approvals and the implementation of strict time limits or "sunset clauses." For the AAIR ex...

Episode 26 — Choose Risk Treatments Wisely: Avoid, Reduce, Transfer, Accept, or Retire (Domain 2) 14.02.2026

Selecting the appropriate risk treatment is a strategic decision-making process that determines the ultimate trajectory of an AI project in Domain 2. This episode details the five standard risk treatment options: avoiding the risk by canceling a project, reducing it through technical controls, transferring it through insurance or contracts, accepting it when it falls within tolerance, or retiring...

Episode 25 — Build a Living AI Risk Register: Structure, Owners, Updates, and Reporting (Domain 2) 14.02.2026

An AI Risk Register is the central repository for all identified risks, and it must function as a "living" document that evolves alongside the technology it tracks. This episode covers the essential structure of a risk register, including risk descriptions, impact scores, mitigation plans, and the specific individuals assigned as risk owners. For the AAIR exam, understanding how the register links...

Episode 24 — Run AI Risk Assessments Consistently: Methods, Criteria, and Evidence Rules (Domain 2) 14.02.2026

Consistency in running AI risk assessments is paramount to maintaining a defensible and objective risk posture, a core competency tested in Domain 2. This episode explores the methodologies used to evaluate AI systems, including qualitative assessments for ethical concerns and quantitative methods for measuring model performance and error rates. For the AAIR certification, candidates must understa...

Episode 23 — Stand Up an AI Risk Intake Process: Bring New Use Cases Under Control (Domain 2) 14.02.2026

An effective AI risk intake process serves as the "front door" for all AI-related initiatives, ensuring that no model is developed or deployed without a preliminary risk screening. This episode details how to design an intake workflow that captures essential information such as the intended use case, data sources, and potential impact on third parties. For the AAIR exam, candidates should understa...

Episode 22 — Design the AI Risk Operating Model: People, Process, Tools, and Cadence (Domain 2) 14.02.2026

The AI Risk Operating Model represents the functional mechanics of how risk is identified and managed on a day-to-day basis, a critical area of focus for Domain 2. This episode breaks down the four essential components of the model: the people who execute the work, the processes they follow, the tools they use for automation, and the operational cadence that determines the frequency of reviews and...

Episode 21 — Build an AI Risk Program Charter: Scope, Objectives, and Success Measures (Domain 2) 14.02.2026

Establishing a formal AI Risk Program Charter is a foundational step in Domain 2, providing the necessary authorization and structure for all subsequent risk management activities. This document serves as the formal "contract" between the risk team and executive leadership, explicitly defining the program's scope, high-level objectives, and the metrics by which its success will be measured. For th...

Episode 20 — Spaced Retrieval Review: Governance Decisions and Risk Language Rapid Recall (Domain 1) 14.02.2026

Mastering Domain 1 requires the ability to recall and apply key governance concepts under the pressure of the exam environment. This episode uses the "spaced retrieval" method to review critical topics such as the definitions of risk appetite vs. tolerance, the roles within an AI governance charter, and the alignment of AI use cases with organizational strategy. We walk through a series of rapid-f...

Episode 19 — Define AI Risk KRIs: Signals That Warn Before Harm Happens (Domain 2) 14.02.2026

Key Risk Indicators (KRIs) serve as the early warning system for AI failures, and defining them correctly is a critical component of Domain 2. This episode explains the difference between KPIs, which measure performance, and KRIs, which signal changes in the risk environment before an incident occurs. For the AAIR certification, understanding how to select and monitor KRIs—such as a sudden increas...

Episode 18 — Translate AI Risk for Executives: Clear Briefings Without Technical Fog (Domain 1) 14.02.2026

Effective communication with executive leadership requires the ability to translate complex technical AI risks into clear business implications, a skill tested in Domain 1. This episode focuses on the art of executive briefing, emphasizing the need to avoid "technical fog" and focus on strategic outcomes like market share, regulatory fines, and brand reputation. For the AAIR exam, candidates must...

Listen to the Certified: The ISACA AAIR Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.