ISACA AAIA Explained: Inside the Advanced in AI Audit Certification
As organizations deploy AI into critical processes, someone has to assure that those systems are governed, monitored, and controlled. That's the gap ISACA's Advanced in AI Audit (AAIA) credential is built to fill — and it's one of the first certifications focused squarely on auditing AI.
This guide covers what the exam asks of you rather than how it looks on paper: what each domain means in practice, why one of them carries nearly half the marks, how the AAIA sits alongside CISA, and how to prepare accordingly.
AAIA exam format at a glance
- Issuer: ISACA
- Questions: 90 multiple-choice
- Duration: 150 minutes
- Scoring: scaled score 200–800
- Passing score: 450
- Delivery: computer-based
That works out to 100 seconds per question — enough time to read a scenario carefully once, but not enough to reconstruct a control framework from first principles while the clock runs.
It's an advanced credential
The "Advanced" in AAIA is meaningful. This isn't an entry point — it's designed for experienced auditors and assurance professionals who already understand audit fundamentals and now need to apply them to AI systems, models, and governance. That expectation is also formal, not just cultural: ISACA requires AAIA candidates to hold an active CISA, or another qualified designation such as CIA, US CPA, ACCA/FCCA, Canadian CPA, Australian CPA/FCPA or the Japanese CPA. If you hold none of them, you cannot register for the AAIA yet.
For preparation, "advanced" has a specific consequence: the exam does not stop to teach you the fundamentals it stands on. It assumes you can already scope an engagement, distinguish a control objective from a control activity, judge whether evidence is sufficient, and write a finding that survives management review. What it tests is those instincts applied to a system that behaves probabilistically and changes after you sign off.
That join is where candidates struggle, and it cuts both ways. Auditors who know controls but have never interrogated a model pipeline lose marks on the operational half of the exam. Data and ML practitioners who know the pipeline intimately lose marks on framing failure as a control weakness, evidencing it, and reporting it to people who will never look at a confusion matrix. Preparing well means finding which side you're on and closing the other.
The three AAIA domains
The exam concentrates heavily on operations:
| Domain | Weight |
|---|---|
| AI Governance and Risk | 33% |
| AI Operations | 46% |
| AI Auditing Tools and Techniques | 21% |
AI Governance and Risk
At 33%, this domain covers who is accountable for an AI system and how that accountability is evidenced: ownership and approval gates before a model reaches production, risk assessment methods adapted to probabilistic outputs, the ethical and regulatory duties that attach to an automated decision, the exposure carried in by models bought rather than built, and whether any of it should sit outside the governance structures the organization already runs.
The useful mental shift is that the audit question is almost never "is there an AI policy?" It's whether the policy binds the people who actually ship models. A model inventory is the clearest example: an organization that cannot enumerate the models running in its processes cannot govern them, and the gap is rarely malicious — it's a team that wired a vendor API into a workflow without anyone treating it as a system.
Vendor risk deserves separate attention because it inverts the usual evidence path. When the model is consumed as a hosted service, you cannot inspect weights, training data, or evaluation results. Assurance shifts onto contractual terms, provider attestations, and the monitoring you run over your own inputs and outputs. Regulatory obligations, meanwhile, differ by jurisdiction and are still moving, so the durable skill is mapping an obligation to a named control owner rather than reciting any particular rulebook.
AI Operations
At 46% this is the largest domain, and it begins where most audit programmes stop: the day the model goes live. It reaches across the pipeline feeding a production model, the metrics that show whether it still works, the process governing its next version, and what happens when it fails in front of customers. Lineage, monitoring, drift, versioning, and incident handling all sit here, but the through-line is narrower than that list — whether anyone would notice, and act, if a live model quietly stopped doing its job.
That makes the monitoring thresholds themselves a control worth testing: who reviews them, how often, what value triggers a retrain, and whether that retrain travels the same approval path as the original release. Retraining is a change, and organizations routinely fail to treat it as one.
Version control matters for a reason auditors recognize immediately: reproducibility. Reconstructing a decision the system made six months ago needs the model version, the input values as they stood at that moment, and the surrounding code. Plenty of teams can produce two of the three. Incident response is the other high-yield area — when a model starts producing harmful or plainly wrong output, is there a rollback path, a human override, a kill switch, and a defined notification chain? And underneath all of it, data quality and lineage, because unreliable inputs do not announce themselves. They become confident, well-formatted, wrong outputs.
AI Auditing Tools and Techniques
At 21% this is the smallest domain and the most practical — the how of the engagement rather than the what. Everything the other two domains say should be controlled has to be evidenced, tested, and written up: deciding what counts as proof from a system that will not give the same answer twice, choosing what to sample and how much, testing for bias, explaining an output well enough to challenge it, and landing all of that in documentation a committee can act on.
Evidence from a non-deterministic system behaves differently from evidence from a ledger. A screenshot of one output proves very little; what stands up is testing across a population — re-running held-out data, comparing observed behavior against documented expectations, and examining distributions rather than instances. Sampling follows the same logic. You are sampling decisions, and the sample only means something if it reaches the subgroups and edge cases where failure concentrates rather than the comfortable middle of the distribution.
Bias testing is where judgment shows. Comparing outcome rates across groups is arithmetic; deciding what fairness should mean for a particular use case, and documenting why that definition was chosen, is the audit work. Explainability splits the same way — global explanations tell you what drives the model overall, local ones tell you why a specific decision came out as it did, and a finding usually needs one specifically rather than whichever the team already produces.
Why AI Operations is nearly half the exam
A conventional application audit can lean on a point-in-time assessment. The system changes when somebody changes it, so a controls review plus a change-management sample covers most of the risk. AI breaks that assumption. The same deployed model, untouched, can drift out of tolerance because the world it was trained on moved — and the retrained replacement that fixes it may never pass through the gates the original did.
That is why governance sign-off is the beginning of the assurance obligation rather than the end of it, and why the largest body of testable control activity sits after deployment. It also matches where control failures actually turn up in practice: monitoring specified but never implemented, thresholds set once and never revisited, retraining outside change control, no rollback path, no owner watching the dashboards that were built for exactly this purpose.
The study consequence is direct: this is the half of the exam to protect when time runs short. Candidates who arrive from a governance or risk background often feel comfortable after covering frameworks and accountability structures — and then meet a run of scenario items about degradation, versioning, and incident handling that carry far more marks than the ground they were confident on.
AAIA vs CISA: which one, and when
CISA is the broad foundation: five domains spanning the audit process, governance of IT, acquisition and development, operations and resilience, and protection of information assets, tested across 150 questions in four hours. AAIA is narrower and deeper. It assumes the audit fundamentals rather than teaching them and spends its 90 questions on applying them to AI.
For most people the sequencing is straightforward. If you are building an audit career, CISA first — it establishes the vocabulary, the independence mindset, and the evidence standards the AAIA takes for granted. If you already audit for a living and AI has landed in your scope, AAIA is the specialization that makes you credible on it. For most people, though, the sequencing is not really a choice: ISACA gates AAIA registration behind an active CISA or another qualified designation, so CISA is a prerequisite rather than a recommendation. Confirm your own eligibility on ISACA's AAIA page before planning around it.
Both exams share the same 200–800 scale and the same 450 cut score, so a CISA holder already understands that a scaled score is not a percentage and that raw performance is converted to account for differences between exam forms.
What transfers from CISA is more than it first appears: audit planning, evidence sufficiency, the reflex to answer as an independent auditor rather than as the engineer who would fix it, and the discipline of separating what management should remediate from what you should test. What doesn't transfer is the technical vocabulary of the model lifecycle and, more fundamentally, the assumption that a control environment stays still between reviews. If you're weighing the two, our CISA exam prep guide sets out that exam's format and domains, and how hard the CISA exam is covers what candidates find difficult about it.
Why exam dumps fail this exam
Memorized item-and-answer pairs transfer badly to a scenario-weighted exam, and AAIA is heavily scenario-weighted. The discriminating detail lives in the scenario, not the stem: two questions can look nearly identical and have different best answers because the organization, the stage of the audit, or the control already in place is different. Several options are usually defensible; the exam asks which is best, or which comes first. Memorizing that the answer was the third option teaches you nothing about ranking defensible options, which is the entire skill being assessed.
Scraped material also ages badly here. AI assurance practice is moving quickly, particularly around monitoring and evaluation, and content harvested from a previous sitting carries no explanation of why the wrong answers were wrong. Beyond effectiveness, using or distributing stolen exam content breaches ISACA's certification agreement — and the value of an advanced credential rests entirely on the integrity of the people holding it.
The functional replacement is scenario-style practice with worked explanations that tell you why each distractor loses. That is the part that builds transferable judgment, and it is exactly the part a stolen answer key cannot contain.
How to study for the AAIA
Start by allocating study time roughly in proportion to the weights: about a third on AI Governance and Risk, close to half on AI Operations, a fifth on AI Auditing Tools and Techniques. Weights tell you where the marks are, but not where you're weak, so take a scored diagnostic early and adjust — a strong operations background may mean governance deserves more of your time than its 33% suggests.
Practice in the exam's real conditions rather than in isolation. Full-length, timed mocks of 90 questions in 150 minutes on the 200–800 scale do two things a casual question grind can't: they train the pacing, and they turn "I feel ready" into a number you can compare against 450. Sitting one early is uncomfortable and worth it, because the gaps it exposes are cheaper to fix early than late.
Track readiness per domain rather than as a single overall percentage. An aggregate score hides exactly the failure mode this exam punishes — comfortable on two domains, thin on the one carrying nearly half the marks. Review the questions you got right but weren't sure about, not only the ones you missed; on a best-answer exam, a lucky pick and a reasoned one look identical in your score and nothing alike on exam day. And rehearse the habit of naming the control objective before reading the options, which is the most reliable way to stop a technically-correct-but-not-best answer from looking attractive.
CertPrepX has 700+ AAIA practice questions and 1,200+ flashcards, covering all three domains with practice weighted toward AI Operations, plus full-length mocks scored on the real scale. See the full AAIA exam prep guide for the format, domains, and readiness scoring in one place.
Frequently asked questions
How many questions are on the AAIA exam? 90 multiple-choice questions, in 150 minutes.
What is the passing score for AAIA? It's scored on a 200–800 scale with a passing score of 450 — the same scale ISACA uses for CISA and CISM.
Is the AAIA for beginners? No, and not merely by convention — ISACA requires an active CISA or another qualified designation to register, so the AAIA is closed to candidates without an audit credential.
Do I need CISA before AAIA? In most cases yes, and it is a formal requirement rather than a convention. ISACA requires AAIA candidates to hold an active CISA or another qualified designation — CIA, US CPA, ACCA/FCCA, Canadian CPA, Australian CPA/FCPA and the Japanese CPA are among those accepted. Check the current list on ISACA's AAIA page before you register or buy study material.
How long should I study for the AAIA? Long enough to be scoring consistently above 450 on full-length mocks with no domain lagging — which depends far more on your starting point than on a fixed number of weeks. If you already audit AI systems day to day, the governance and operations material will feel familiar and the tooling domain may need the most work; if AI is new to your scope, expect AI Operations to take the largest share of your time, as it does of the exam.