AAIA: ISACA Advanced in AI Audit (AAIA)
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the AAIA Exam
Plan, test, and report AI audits with confidence
250 original practice questions for the ISACA AAIA (Advanced in AI Audit) exam. Every question includes detailed explanations, scenario-based context, and exam tips. Covers all 3 domains: AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques — grounded in the frameworks the exam is built on: ISACA ITAF, NIST AI RMF, ISO/IEC 42001, the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the EU AI Act.
AAIA is ISACA’s advanced credential for IS auditors who already hold an active CISA (or another ISACA-approved advanced audit designation) and now need to audit enterprise AI. It is not an ML-engineering exam, and it is not a security-management exam — it tests audit judgment: how you plan and scope an AI audit, test AI controls (design vs operating effectiveness), gather sufficient and appropriate evidence, classify findings and rate risk, preserve independence, and report and follow up.
Who Should Take This Exam?
The AAIA is designed for experienced IS auditors and assurance professionals auditing enterprise AI — IT audit managers, AI audit leads, internal audit directors, external and assurance auditors, and audit-committee liaisons. An active CISA is required to earn the credential (ISACA also accepts certain other approved advanced audit designations such as CIA, CPA, ACCA, or CA with an IT-audit focus).
Typical study time: 4-8 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | AAIA |
| Title | ISACA Advanced in AI Audit |
| Duration | 150 minutes |
| Questions | 90 |
| Pass Score | 450 / 800 |
| Cost | $459 USD (member) / $599 USD |
| Provider | PSI |
| Prerequisite | Active CISA (or ISACA-approved advanced audit designation) |
| Question Types | Multiple choice |
| Official Page | View on ISACA → |
Exam Domains & Weights
The AAIA exam covers 3 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| AI Governance and Risk | 33% | 83 |
| AI Operations | 46% | 115 |
| AI Auditing Tools and Techniques | 21% | 52 |
| Total | 100% | 250 |
💡 Study tip: AI Operations carries the most weight (46%) — that’s where data management, the AI development lifecycle, change management, supervision, AI-specific testing techniques, AI threats/vulnerabilities, and incident response live, so start there. Governance and Risk (33%) is where the frameworks sit — know the NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE, with GOVERN cross-cutting), ISO/IEC 42001 vs 23894 vs 22989, and the EU AI Act’s four risk tiers. Auditing Tools and Techniques (21%) is the signature audit domain — master ITAF-based planning, sampling, evidence, and reporting.
Practice Exam — 250 Questions
Prepare for the AAIA with our 250-question practice exam covering all 3 exam domains. Every question is a real-world AI-audit scenario — planning, control testing, evidence evaluation, findings, or reporting — with detailed explanations mapped to the frameworks the exam is built on.
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
ISACA Certification Path
ISACA certs are role-based, not hierarchical. CISA for auditors, CISM for security managers, CRISC for risk professionals, CGEIT for IT governance, CDPSE for privacy — and the advanced AI pair: AAIA for auditing AI (for CISA holders) and AAISM for securing AI (for CISM/CISSP holders).
Related ISACA Certifications
If you’re studying for the AAIA, you might also be interested in these ISACA certifications:
- AAISM: ISACA Advanced in AI Security Management — 250 practice questions
- CISA: ISACA Certified Information Systems Auditor — 250 practice questions
- CRISC: ISACA Certified in Risk and Information Systems Control — 250 practice questions
- CDPSE: ISACA Certified Data Privacy Solutions Engineer — 250 practice questions
Study Tips
- Keep the auditor’s lens — the answer is almost always an audit judgment (plan, test, gather evidence, classify a finding, report), never “implement the control” (that’s management’s job) and never a line of code
- Separate design from operating effectiveness — design effectiveness asks whether a control is suitably designed; operating effectiveness asks whether it actually operated over the period. Sufficient and appropriate (relevant + reliable) evidence is the recurring test
- Know the frameworks cold — ISACA ITAF (5th Edition), NIST AI RMF (GOVERN/MAP/MEASURE/MANAGE), ISO/IEC 42001, OWASP Top 10 for LLM Apps (2025), MITRE ATLAS, and the EU AI Act’s four risk tiers
- Master the attack taxonomy — data poisoning (training-time) vs evasion (inference-time) vs model inversion vs membership inference vs model extraction, and the controls an auditor tests for each
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Check the official page — official exam details always have the latest objectives