AAIA certification, officially the ISACA Advanced in AI Audit™, is an advanced credential for qualified audit and advisory professionals who assess artificial intelligence governance, risk, operations, controls, and audit processes. The AAIA exam contains 90 questions across three domains: AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. Candidates must hold an active CISA or another approved audit-focused designation. AAIA is designed for experienced professionals rather than entry-level candidates pursuing general AI knowledge.
The AAIA certification is ISACA's Advanced in AI Audit credential. It was created specifically for experienced auditors and advisors who need to evaluate how artificial intelligence is governed, developed, operated, controlled, monitored, and audited.
Unlike a general AI Auditor Course, AAIA is not simply an introduction to artificial intelligence. The certification tests whether an audit professional can apply established assurance principles to AI-specific risks such as data quality, bias, privacy, model behavior, security, governance, lifecycle management, regulatory requirements, and automated decision-making.
ISACA introduced AAIA in 2025 as an advanced, audit-specific artificial intelligence certification. The credential sits alongside other ISACA AI Certifications and AI-focused programs, including Advanced in AI Security Management and Advanced in AI Risk, but AAIA is specifically centered on audit and assurance.
For organizations adopting machine learning, generative AI, automated decision systems, and AI-enabled business processes, traditional IT controls alone may not provide enough assurance. An AI audit may need to examine the model, its training or operational data, governance responsibilities, human oversight, security controls, monitoring, output reliability, regulatory compliance, and downstream business impact.
That is the practical problem the ISACA AAIA credential addresses.
AAIA Detail
Current ISACA Information
Official name
ISACA Advanced in AI Audit™ (AAIA™)
Primary focus
Artificial Intelligence Audit and assurance
Exam questions
90 questions
Domain 1
AI Governance and Risk – 33%
Domain 2
AI Operations – 46%
Domain 3
AI Auditing Tools and Techniques – 21%
Member exam fee
US$459
Non-member exam fee
US$599
Certification application fee
US$50
Exam eligibility period
6 months after registration
Application deadline after passing
Within 5 years
Delivery
PSI test centers; remote proctoring where permitted
The domain weights and 90-question structure come from ISACA's current AAIA Exam Content Outline. Current registration information lists a US$459 member fee and US$599 non-member fee.
One of the most important differences between AAIA ISACA certification and many general AI credentials is its prerequisite requirement.
AAIA is an advanced certification rather than a beginner-level AI Audit Certification.
ISACA currently states that candidates must hold an active CISA or another qualifying professional designation. CISA holders qualify directly. ISACA also recognizes specified audit and accounting credentials when they have an appropriate IT audit or IT advisory focus, including credentials such as CIA, ACCA/FCCA, and qualifying CPA designations. Because ISACA has expanded this list since AAIA was launched, candidates should check the current eligibility page before registering.
This prerequisite changes the nature of the exam. AAIA does not need to establish that a candidate understands basic auditing from the beginning. Instead, it builds on existing audit expertise and asks professionals to apply that expertise to AI environments.
The certification is particularly relevant to:
IT auditors responsible for AI audit engagements.
CISA-certified professionals moving into artificial intelligence assurance.
Internal auditors working with AI-enabled business systems.
Technology risk and assurance consultants.
Professionals evaluating AI governance, privacy, security, and compliance.
Audit leaders advising management on AI adoption and control design.
Professionals who assess, implement, maintain, or audit AI systems.
ISACA specifically identifies experienced IT auditors, advisors, and professionals involved in evaluating or auditing AI systems as primary audiences for the credential.
An AI Auditor does more than verify whether an AI platform is functioning.
A serious Artificial Intelligence Audit asks whether the organization's use of AI is controlled, explainable to the required degree, appropriately governed, legally compliant, secure, monitored, and aligned with business objectives.
Consider an organization using an AI model to approve customer transactions. A conventional technology audit might focus heavily on user access, configuration, availability, change management, and security.
An AI-focused audit must go further.
The auditor may need to examine whether training and operational data are suitable, whether privacy requirements are respected, whether model outputs are monitored for unintended effects, whether management has established accountability, whether model changes are controlled, whether third-party AI providers create additional risks, and whether humans can intervene when automated decisions create unacceptable outcomes.
That is why AI audit certification increasingly intersects with governance, cybersecurity, data governance, model risk, privacy, and regulatory compliance.
The AAIA certification exam contains 90 questions across three officially defined domains.
This domain evaluates whether an auditor can assess AI governance structures and advise stakeholders on responsible AI implementation.
Topics include AI models and requirements, program governance, AI risk management, privacy, data governance, ethics, regulations, standards, and organizational policies.
A strong candidate should understand that governance is not simply about creating an "AI policy." Effective governance establishes accountability for models, data, risk acceptance, oversight, monitoring, exceptions, vendors, and automated decisions.
For an Artificial Intelligence Audit, the auditor may ask: Who owns the model? Who approves material changes? Who accepts AI risk? How is regulatory compliance evaluated? What happens when the model begins producing unexpected results?
Those are assurance questions rather than purely technical AI questions.
At 46%, AI Operations is the largest portion of the exam.
It includes AI-specific data management, solution development methodologies, lifecycle management, change management, supervision of AI outputs and decisions, testing techniques, AI threats and vulnerabilities, and incident response.
This weighting provides an important preparation insight: candidates should not study AAIA as a governance-only credential.
An AI Auditor must understand how AI operates through its lifecycle.
Suppose an organization approves an AI model after successful testing. Six months later, the underlying business data changes significantly. The model may still technically operate while producing less reliable decisions. An auditor therefore needs to understand monitoring, data drift, model performance, change processes, control ownership, and escalation procedures.
This operational perspective separates meaningful AI Audit work from checklist-based compliance reviews.
This domain focuses directly on conducting AI-related audits and using technology to improve audit execution.
ISACA's outline covers audit planning and design, testing and sampling, evidence collection, data quality, analytics, audit outputs, and reporting. It also expects professionals to understand how AI solutions can enhance audit planning, execution, and reporting.
This creates two distinct capabilities.
The auditor must know how to audit AI, but also how AI can be used within the audit function.
For example, an audit team could use AI-assisted analytics to examine larger data populations, identify unusual transactions, classify documentation, or highlight patterns requiring human investigation. The auditor remains responsible for evaluating whether those tools produce dependable evidence and whether their use introduces additional risk.
Searching for an AI Auditor Course may produce training programs covering anything from introductory AI concepts to ISO-based AI management systems.
AAIA has a more specific positioning.
Area
AAIA Certification
General AI Auditor Course
Credential type
Advanced professional certification
Varies by provider
Issuer
ISACA
Varies
Prerequisite
Qualified professional credential required
Often none
Main emphasis
AI governance, operations and auditing
Depends on course
Exam
Formal 90-question certification exam
Varies
Target level
Experienced auditors/advisors
Beginner to advanced
Audit application
Strong emphasis
Varies significantly
Someone new to auditing may benefit from foundational audit and AI education first. Professionals already holding CISA or another qualifying designation are much closer to the intended audience for ISACA AI Certification at the AAIA level.
The current certification path is straightforward:
Confirm eligibility. Make sure you hold an active CISA or another currently accepted designation.
Study the AAIA Exam Content Outline. Build your preparation around the 33%, 46%, and 21% domain weighting.
Prepare with legitimate resources. ISACA offers an AAIA Review Manual, online review course, Questions, Answers and Explanations database, workshops and a free practice exam.
Register for the AAIA exam. Registration provides a six-month eligibility window in which to take the exam.
Schedule through PSI. Testing is available through authorized centers and remote proctoring where allowed.
Pass the certification exam.
Pay the US$50 application processing fee and apply. ISACA allows candidates five years after passing to submit their certification application.
Candidates in India, Mainland China, and Hong Kong should note that ISACA currently states the AAIA exam is available only through testing centers in those locations, not live remote proctoring.
The strongest AAIA preparation starts with the exam content outline rather than trying to memorize isolated artificial intelligence terminology.
First, build enough technical AI understanding to discuss training data, models, outputs, bias, privacy, security, monitoring and lifecycle risks accurately.
Next, connect every concept to an audit objective.
Do not only ask, "What is model drift?" Ask, "What evidence would demonstrate that management detects, evaluates and responds to model drift?"
Do not only study AI governance frameworks. Ask, "How would an auditor determine whether governance responsibilities are actually operating?"
That mindset is critical because Artificial Intelligence Audit Certification preparation should develop assurance judgment rather than vocabulary recognition.
ISACA's official AAIA preparation resources currently include the review manual, online review course, a database containing more than 200 practice questions, virtual workshops and a free 12-question practice exam.
No. ISACA now has multiple AI-focused credentials aimed at different professional disciplines.
AAIA is centered on artificial intelligence audit and assurance. AAISM focuses on AI security management, while AAIR focuses on AI risk. ISACA's broader AI resources also include introductory courses and certificate-level learning options.
For an established auditor, this distinction matters. Choosing a credential should follow the professional responsibility you actually perform.
If your work asks, "Can we independently assess whether this AI system and its controls are trustworthy?" AAIA is directly aligned with that audit responsibility.
Traditional IT audit controls remain important, but AI introduces additional assurance questions.
The output of a conventional deterministic system generally follows programmed rules. An AI model may produce outputs based on statistical patterns, evolving data and model behavior that cannot always be interpreted through conventional application-control testing.
Auditors therefore need to evaluate issues such as training and input data, bias, model reliability, human oversight, privacy, third-party AI dependencies, lifecycle controls, monitoring, ethical requirements and organizational accountability.
ISACA has highlighted this challenge, noting that AI systems can differ significantly from traditional IT systems and may introduce risks related to models and technologies that auditors need specialized knowledge to evaluate.
That is where specialized AI audit expertise creates practical value.
The AAIA certification is best approached as an extension of professional audit capability, not simply another AI credential to add to a résumé.
Start with the official AAIA content outline. Measure your knowledge against AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. Give additional preparation time to AI Operations because it represents 46% of the current exam, but do not treat domain percentages as permission to ignore governance or audit methodology.
For professionals already qualified through CISA or another accepted audit designation, the next step is clear: strengthen the AI knowledge needed to ask better audit questions, evaluate AI controls with evidence, and communicate AI risk in terms management can act on. That is the real professional value behind ISACA AAIA.