AAIA: ISACA Advanced in AI Audit (AAIA)

Expert ISACA ISACA
Browse certifications

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

About the AAIA Exam

Plan, test, and report AI audits with confidence

250 original practice questions for the ISACA AAIA (Advanced in AI Audit) exam. Every question includes detailed explanations, scenario-based context, and exam tips. Covers all 3 domains: AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques — grounded in the frameworks the exam is built on: ISACA ITAF, NIST AI RMF, ISO/IEC 42001, the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the EU AI Act.

AAIA is ISACA’s advanced credential for IS auditors who already hold an active CISA (or another ISACA-approved advanced audit designation) and now need to audit enterprise AI. It is not an ML-engineering exam, and it is not a security-management exam — it tests audit judgment: how you plan and scope an AI audit, test AI controls (design vs operating effectiveness), gather sufficient and appropriate evidence, classify findings and rate risk, preserve independence, and report and follow up.

Who Should Take This Exam?

The AAIA is designed for experienced IS auditors and assurance professionals auditing enterprise AI — IT audit managers, AI audit leads, internal audit directors, external and assurance auditors, and audit-committee liaisons. An active CISA is required to earn the credential (ISACA also accepts certain other approved advanced audit designations such as CIA, CPA, ACCA, or CA with an IT-audit focus).

Typical study time: 4-8 weeks of focused study

Exam Quick Facts

DetailValue
Exam CodeAAIA
TitleISACA Advanced in AI Audit
Duration150 minutes
Questions90
Pass Score450 / 800
Cost$459 USD (member) / $599 USD
ProviderPSI
PrerequisiteActive CISA (or ISACA-approved advanced audit designation)
Question TypesMultiple choice
Official PageView on ISACA →

Exam Domains & Weights

The AAIA exam covers 3 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.

DomainWeightPractice Qs
AI Governance and Risk33%83
AI Operations46%115
AI Auditing Tools and Techniques21%52
Total100%250

💡 Study tip: AI Operations carries the most weight (46%) — that’s where data management, the AI development lifecycle, change management, supervision, AI-specific testing techniques, AI threats/vulnerabilities, and incident response live, so start there. Governance and Risk (33%) is where the frameworks sit — know the NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE, with GOVERN cross-cutting), ISO/IEC 42001 vs 23894 vs 22989, and the EU AI Act’s four risk tiers. Auditing Tools and Techniques (21%) is the signature audit domain — master ITAF-based planning, sampling, evidence, and reporting.

Practice Exam — 250 Questions

Prepare for the AAIA with our 250-question practice exam covering all 3 exam domains. Every question is a real-world AI-audit scenario — planning, control testing, evidence evaluation, findings, or reporting — with detailed explanations mapped to the frameworks the exam is built on.

What you get:

  • ✅ Exam simulation mode with timer
  • ✅ Spaced repetition for weak areas
  • ✅ Detailed explanations for every question
  • ✅ Progress tracking across domains
  • ✅ 20 free questions — no account needed

ISACA Certification Path

ISACA certs are role-based, not hierarchical. CISA for auditors, CISM for security managers, CRISC for risk professionals, CGEIT for IT governance, CDPSE for privacy — and the advanced AI pair: AAIA for auditing AI (for CISA holders) and AAISM for securing AI (for CISM/CISSP holders).

If you’re studying for the AAIA, you might also be interested in these ISACA certifications:

Study Tips

  1. Keep the auditor’s lens — the answer is almost always an audit judgment (plan, test, gather evidence, classify a finding, report), never “implement the control” (that’s management’s job) and never a line of code
  2. Separate design from operating effectiveness — design effectiveness asks whether a control is suitably designed; operating effectiveness asks whether it actually operated over the period. Sufficient and appropriate (relevant + reliable) evidence is the recurring test
  3. Know the frameworks cold — ISACA ITAF (5th Edition), NIST AI RMF (GOVERN/MAP/MEASURE/MANAGE), ISO/IEC 42001, OWASP Top 10 for LLM Apps (2025), MITRE ATLAS, and the EU AI Act’s four risk tiers
  4. Master the attack taxonomy — data poisoning (training-time) vs evasion (inference-time) vs model inversion vs membership inference vs model extraction, and the controls an auditor tests for each
  5. Use our practice exam — try the 20 free questions first to gauge your readiness
  6. Check the official pageofficial exam details always have the latest objectives
20 Free Questions Practice Exam $9 →