AI Training Critical as Governance Challenges Grow

Written by

AI is rapidly becoming embedded in enterprise operations, yet many organizations still lack the skills and governance frameworks needed to manage the technology effectively.

In response, training and certification body ISACA plans to launch an AI governance certification, currently accepting applications in beta phase, in early 2027. This will complete a series of AI-focused credentials designed to help professionals manage the technology securely and responsibly.

Previous ISACA research highlighted a significant AI governance gap, with only 32% of digital trust professionals believing their organizations adequately address AI risks such as privacy, bias and security, despite widespread workplace adoption.

ISACA’s rollout of its AI-related certifications includes Advanced in AI Audit (AAIA), Advanced in AI Security Management (AAISM) and Advanced in AI Risk (AAIR).

This comes at a time when 54% of organizations are involved in onboarding or implementing AI solutions, up from 46% in 2024, according to ISACA’s State of Cybersecurity 2026 report.

“The governance certification is important in terms of providing an umbrella around the operations of professions from cyber to audit to risk. We’re trying the help individuals in controlling and governing AI rather than having AI on the loose,” said Chris Dimitriadis, chief global strategy officer at ISACA, during a media roundtable at ISACA’s Europe conference in Munich, Germany on 8 October.

AI Skills Gap Remains a Major Challenge

Dimitriadis said uptake of the ISACA-provided AI trainings had been positive, especially in AI-forward regions like Europe, the US and Asia.

However, ISACA’s own 2025 AI Pulse Poll, which surveyed over 3000 digital trust professionals, found that within organizations, 32% said there is no AI training provided to any employees. 

Dimitriadis said, “The message we’re trying to convey is that we need more AI training, specialized AI training across the domain, whether you’re an auditor, if you’re a cyber professional, a risk manager, project manager or IT manager dealing with governance of AI technology, we need more AI training. We need this to be holistic and well rounded with soft skills in order for them to be successful in their job.”

From its 2026 research, ISACA has concluded that AI is set to dominate most of the technical and orchestration tasks. Professionals will therefore focus on tasks that require context and intuition, as well as communication. These include governance, AI configuration and monitoring, and final decision making.

Threat detection and response alongside identity and access management represented the most important security skill needed, citied in ISACA’s State of Cybersecurity report.

Also highlighted were vulnerability management, data security and incident response skills.

What’s Hot on Infosecurity Magazine?