The AAIA Certification, officially ISACA Advanced in AI Audit, is an advanced credential for experienced audit and advisory professionals who evaluate artificial intelligence governance, operations, risk, controls, and audit practices. The exam has 90 multiple-choice questions, lasts 150 minutes, and covers three domains: AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. Candidates need an active CISA or another qualifying audit credential and must meet ongoing CPE requirements to maintain the certification.
The AAIA Certification stands for Advanced in AI Audit and is offered by ISACA for experienced audit and advisory professionals who need to assess artificial intelligence systems, governance structures, controls, risks, and business impacts.
Unlike a general AI auditor course, AAIA is positioned as an advanced professional credential. It is designed for people who already understand auditing and now need to evaluate how organizations design, deploy, govern, monitor, and control AI solutions.
The credential is particularly relevant as organizations increasingly use machine learning, generative AI, automated decision systems, and AI-enabled business processes. Traditional audit approaches remain important, but AI introduces additional concerns involving data quality, model behavior, bias, privacy, transparency, accountability, cybersecurity, human oversight, and regulatory compliance.
An AI Auditor therefore needs to understand established audit principles as well as the characteristics that make AI systems different from conventional technology environments.
The current ISACA AAIA exam contains 90 multiple-choice questions and gives candidates 150 minutes to complete the examination.
AAIA Exam Detail
Current Information
Certification
Advanced in AI Audit (AAIA)
Provider
ISACA
Questions
90 multiple-choice questions
Duration
150 minutes / 2.5 hours
Domains
3
Member Exam Cost
US$459
Nonmember Exam Cost
US$599
Application Fee
US$50
Exam Eligibility Period
6 months after registration
Delivery
Testing center or remote proctoring where available
Candidates should remember that exam pricing, testing policies, and regional availability can change. It is always useful to verify the current details before registering.
The AI Audit Certification is divided into three domains that reflect the work of professionals assessing AI governance, operational implementation, and assurance.
AAIA Domain
Exam Weight
AI Governance and Risk
33%
AI Operations
46%
AI Auditing Tools and Techniques
21%
The largest domain is AI Operations at 46%, which means candidates should not prepare for AAIA as though it were only a governance or policy exam. They also need to understand how AI systems operate throughout their lifecycle.
The first domain focuses on how organizations establish responsible oversight of artificial intelligence.
Candidates should understand AI models, governance structures, program management, enterprise risk, privacy, data governance, ethics, regulations, standards, and organizational accountability.
For an Artificial Intelligence Audit, an auditor should determine whether responsibility for AI decisions is clearly defined. A model may generate technically accurate results, but the organization still needs clear ownership of its use, controls, exceptions, monitoring, and consequences.
For example, suppose an organization deploys an AI system to support lending decisions. An auditor should not only ask whether the application works correctly. The audit may also need to examine whether training data is appropriate, whether bias is monitored, whether decisions can be explained, whether privacy requirements are addressed, and whether adequate human oversight exists.
This is where AI audit differs from a traditional IT control review.
AI Operations is the largest part of the examination and deserves significant preparation time.
This domain covers AI-specific data management, development methodologies, AI lifecycle management, change management, supervision of AI solutions, testing, vulnerabilities, and incident response.
A strong AI auditor needs to understand what happens from data collection and model development through deployment, monitoring, modification, and eventual retirement.
Data is especially important.
Traditional applications are largely driven by programmed logic, while many AI systems depend heavily on the quality, relevance, completeness, and characteristics of their data. Poor-quality or biased data can produce unreliable outcomes even if the technical infrastructure appears secure.
Auditors therefore need to assess areas such as data appropriateness, privacy, model inputs, model outputs, monitoring, and changes over time.
AI models can also behave differently as their operating environments evolve. Auditors may therefore need to consider model drift, changing data distributions, unexpected outputs, human overrides, and ongoing performance monitoring.
The third domain focuses specifically on how an Artificial Intelligence Audit should be planned and performed.
Topics include audit planning, audit design, testing, sampling, evidence collection, data quality, analytics, audit reporting, and the use of AI-enabled technologies during the audit process.
An important distinction is that AAIA does not only teach professionals how to audit AI.
It also addresses how AI tools can support audit activities.
AI may help with document analysis, anomaly detection, data analysis, risk identification, testing, and reporting. However, the use of AI within an audit also creates new concerns.
Auditors need to consider output reliability, confidentiality of uploaded information, explainability, validation, data protection, and the possibility that AI-generated conclusions may be incomplete or incorrect.
The auditor remains responsible for professional judgment.
The AAIA Certification is not designed as a beginner-level credential.
Candidates need an active qualifying professional certification before earning AAIA. An active CISA is one of the main qualifying credentials. Selected advanced audit and accounting certifications may also be accepted when the professional works in an appropriate audit or advisory role.
Qualifying credentials may include professional designations such as CIA, CPA, ACCA, FCCA, Chartered Accountant credentials, and other approved audit or accounting qualifications, subject to current ISACA eligibility requirements.
The basic certification process is:
Hold an active qualifying professional credential.
Register for and pass the AAIA exam.
Complete the certification application.
Pay the applicable application fee.
Follow professional ethics and continuing education requirements.
Candidates should confirm their qualifying credential before investing in the exam.
The ISACA AI Certification is particularly relevant to experienced professionals working in assurance, governance, risk, and advisory functions.
Potential candidates include IT auditors, internal auditors, technology risk professionals, audit managers, governance specialists, compliance professionals, consultants, and professionals responsible for evaluating AI-enabled systems.
The credential can also be useful for professionals who advise boards, audit committees, management teams, or technology leaders about AI controls and organizational readiness.
Someone who is completely new to auditing may find AAIA too advanced.
The credential assumes that candidates already understand professional audit concepts and can apply those skills to the additional complexity introduced by AI.
ISACA has developed several AI-focused credentials aimed at different professional roles.
AAIA focuses primarily on AI audit and assurance.
AAISM focuses on AI security management and protecting AI-enabled environments.
AAIR focuses more directly on AI risk management and lifecycle risk.
This distinction matters when deciding which ISACA AI certifications best match your career goals.
An auditor assessing whether AI controls operate effectively may align best with AAIA. A cybersecurity manager responsible for protecting AI systems may prefer AAISM, while a risk professional responsible for enterprise AI risk may find AAIR more relevant.
Your current role and future responsibilities should guide the decision.
A strong AI Auditor Course should go beyond basic artificial intelligence terminology.
Candidates should learn how to evaluate AI governance, model lifecycle controls, data management, cybersecurity, privacy, bias, ethics, monitoring, third-party risk, regulatory obligations, and audit evidence.
Training should also include realistic scenarios.
For example, if an organization uses an AI model supplied by a third-party vendor, an auditor may need to assess vendor governance, contractual responsibilities, data usage, monitoring arrangements, access controls, testing evidence, incident procedures, and organizational dependence on the supplier.
Another useful scenario involves generative AI.
An organization may allow employees to use generative AI tools without having clear policies for confidential information. The audit concern is not simply that employees use AI. The auditor should examine governance, acceptable-use policies, awareness, monitoring, technical restrictions, privacy, and accountability.
This type of scenario-based preparation builds stronger AI audit certification skills than memorizing definitions.
Strong AI governance defines who owns AI systems, who approves their use, how risk is assessed, and how performance is monitored.
Without clear governance, organizations may deploy AI tools without understanding their business impact or regulatory exposure.
An auditor may need to assess whether there is an AI inventory, whether high-risk systems receive stronger oversight, whether responsibilities are assigned, and whether changes to models or data are properly controlled.
AI governance should also address ethical issues.
If an AI system influences hiring, lending, insurance, healthcare, security, or employee monitoring, poor governance can create serious legal and reputational consequences.
Data quality is one of the most important issues in Artificial Intelligence Audit.
AI systems depend on data for training, validation, testing, and ongoing operation.
An auditor should therefore consider whether data is accurate, complete, relevant, representative, protected, and appropriately governed.
Weak data can produce misleading outputs even when the model itself appears technically sophisticated.
Auditors may also need to examine where the data comes from, whether the organization has permission to use it, whether personal information is properly protected, and whether historical data introduces unintended bias.
AI risks can continue after deployment.
Models may perform well initially but become less reliable as business conditions, customer behavior, input data, or external environments change.
This creates the need for continuous monitoring.
Auditors should understand concepts such as performance thresholds, exception handling, model drift, human oversight, escalation, and change control.
A well-governed AI system should have defined expectations for acceptable performance and clear procedures for responding when those expectations are not met.
Begin by reviewing the three exam domains and identifying where your current experience is strongest.
Experienced auditors may already understand assurance methodology but need deeper knowledge of AI models, lifecycle risks, data issues, AI operations, and emerging technology.
Technology professionals may understand AI systems but need stronger knowledge of audit planning, evidence, governance, and reporting.
Spend the largest portion of your preparation time on AI Operations, because it represents 46% of the exam.
Use legitimate practice questions to identify reasoning gaps rather than memorize answers.
When reviewing a question, ask why every incorrect option is weaker from an audit, governance, control, or risk perspective.
Scenario-based preparation is particularly valuable because real AI audits often involve competing priorities rather than simple right-or-wrong technical answers.
AAIA holders need ongoing AI-focused professional education because artificial intelligence continues to change rapidly.
Certification holders are expected to complete specialized continuing professional education and keep the prerequisite certification used for AAIA active.
Ongoing education is especially important because AI regulations, model capabilities, security threats, governance expectations, and audit methodologies can change quickly.
Professionals should continue developing knowledge in AI governance, cybersecurity, privacy, data management, generative AI, AI regulations, model risk, and audit analytics.
AAIA Certification can be particularly valuable for experienced audit professionals whose organizations are adopting AI faster than their existing assurance programs can adapt.
The credential addresses a growing professional need: organizations require auditors who can evaluate not only traditional IT controls but also AI models, data, governance, ethics, lifecycle management, operational monitoring, and AI-enabled decisions.
It is less suitable as a first audit certification.
Professionals without an established audit background should generally build core audit knowledge and experience before pursuing this advanced specialization.
For experienced auditors, however, the value is clear. AI is increasingly used in financial processes, cybersecurity operations, customer services, HR, analytics, risk management, and enterprise applications.
Audit teams need professionals who can determine whether these systems are properly controlled, responsibly governed, compliant, and aligned with organizational objectives.
Treat the Artificial Intelligence Audit Certification as the beginning of an AI assurance specialization rather than the end of your learning.
Combine AAIA preparation with practical knowledge of AI governance frameworks, model lifecycle processes, data quality, privacy, cybersecurity, generative AI controls, vendor management, bias testing, monitoring, regulatory expectations, and audit analytics.
The strongest AI Auditor should be able to ask the right assurance questions: Who owns this AI system? What decisions does it influence? What data does it depend on? What can go wrong? Which controls reduce that risk? How do we know those controls are working?
That is the professional capability the ISACA AAIA Certification is designed to develop and validate.