Almost everyone who looks at this credential makes the same two assumptions, and both are wrong.
The first is that an AI audit certification is mostly about auditing. It is not: AI Operations carries 46 percent of the AAIA exam, nearly half the paper, against 21 percent for auditing tools and techniques. The second is that you can decide to sit it. You cannot. ISACA requires an active CISA certification or one of fifteen other named designations before it will let you register at all, which makes AAIA one of the few advanced credentials that checks your existing qualifications before it checks your knowledge. The exam itself is 90 questions in 150 minutes, scored on a scale where 450 out of 800 passes, at 459 US dollars for members and 599 for everyone else.
Who Is Allowed to Take the AAIA Exam?
Only holders of a qualifying designation. ISACA requires an active CISA certification, or one of fifteen accounting and internal audit designations held by someone working in an IT audit or IT advisory role. Sixteen routes exist in total, and there is no open registration for anyone outside that list.
The accepted designations beyond CISA are the Institute of Internal Auditors CIA, the US CPA, the ACCA and FCCA, the Australian CPA and FCPA, the Japanese CPA, the Canadian CPA, the ICAEW ACA and FCA, the Nigerian CNA, the Chartered Accountants Australia and New Zealand CA and FCA, and the Hong Kong CPA and FCPA. CISA holders qualify automatically; every other route carries the condition that the holder works in IT audit or IT advisory.
| Route | Issuing body | Condition |
|---|---|---|
| CISA | ISACA | Active certification, no role condition |
| CIA | Institute of Internal Auditors | IT audit or IT advisory role focus |
| US CPA | US state boards of accountancy | IT audit or IT advisory role focus |
| ACCA and FCCA | Association of Chartered Certified Accountants | IT audit or IT advisory role focus |
| CPA and FCPA | CPA Australia | IT audit or IT advisory role focus |
| CPA | Japan Financial Services Agency | IT audit or IT advisory role focus |
| CPA | Canadian provincial accounting bodies | IT audit or IT advisory role focus |
| ACA and FCA | ICAEW | IT audit or IT advisory role focus |
| CNA | Association of National Accountants of Nigeria | IT audit or IT advisory role focus |
| CA and FCA | Chartered Accountants Australia and New Zealand | IT audit or IT advisory role focus |
| CPA and FCPA | Hong Kong Institute of Certified Public Accountants | IT audit or IT advisory role focus |
The composition of that list tells you what ISACA thinks this credential is for. It is not aimed at machine learning engineers who want an audit qualification. It is aimed at established auditors, most of them from an accountancy background, who now have artificial intelligence inside the systems they were already assessing. The full list and the role conditions are published on ISACA’s own AAIA credential page. If you hold the CIA designation rather than CISA, that is a valid route provided your role qualifies.
What Are the AAIA Exam Details?
AAIA is 90 questions in 150 minutes, scored on a scaled range where 450 out of 800 is the pass mark. It costs 459 US dollars for ISACA members and 599 for non-members, and it is delivered through PSI either at a test centre or under remote proctoring.
| Field | Value |
|---|---|
| Exam name | ISACA Advanced in AI Audit |
| Exam code | AAIA |
| Questions | 90 |
| Duration | 150 minutes |
| Passing score | 450 on a scaled range |
| Price | $459 member, $599 non-member |
| Delivery | PSI test centre or remote proctoring |
| Prerequisite | CISA or one of fifteen named designations |
| Eligibility window | Six months from registration |
| Application fee | $50 after passing |
| Published domains | 3, weighted, totalling 100% |
The timing is comfortable at 100 seconds per question, which matters because ISACA writes long stems. What is less comfortable is the scaled score. A 450 out of 800 is not the same as scoring 56 percent, because the scale is a conversion rather than a percentage, and ISACA does not publish how many raw correct answers it corresponds to. Treat it as a threshold you cannot compute your way to.
Because the scale hides the arithmetic, the only reliable feedback loop before the day is answering questions written in the exam’s own shape and seeing where you fall over. Working through AAIA sample questions is more informative here than on an exam that publishes a percentage, precisely because you cannot self-mark against a known target.
Why Is AI Operations 46 Percent of the Paper?
Because you cannot audit a thing you do not understand operationally. AI Operations carries 46 percent, AI Governance and Risk 33 percent, and AI Auditing Tools and Techniques only 21 percent. ISACA has weighted the exam toward how AI systems are built, run and attacked rather than toward audit method.
| Domain | Weight | Sub-areas |
|---|---|---|
| AI Operations | 46% | 7: data management, development lifecycle, change management, supervision, testing techniques, threats and vulnerabilities, incident response |
| AI Governance and Risk | 33% | 5: AI models and requirements, governance and programme management, risk management, privacy and data governance, leading practices and standards |
| AI Auditing Tools and Techniques | 21% | 5: audit planning and design, testing and sampling, evidence collection, data quality and analytics, outputs and reports |
Read that against the entry requirement and the design becomes obvious. Every candidate already holds an audit designation, so ISACA has no need to test audit fundamentals; those were established by CISA or CPA or CIA years earlier. What it does need to establish is whether an experienced auditor understands data balancing, model supervision, adversarial threats and AI incident response well enough to audit them competently.
The practical consequence for study planning is uncomfortable for a lot of candidates. The 46 percent domain is the one furthest from their day job, and the 21 percent domain is the one closest to it. Time spent should be the inverse of comfort.
What Does the AI Governance and Risk Domain Cover?
Five sub-areas at 33 percent: the models and requirements themselves, governance and programme management, risk management, privacy and data governance, and the leading practices, ethics, regulations and standards that surround them. It is the domain that asks what good looks like before anything is assessed.
The first sub-area is more technical than its title suggests. It names types of AI, machine learning and AI models, algorithms, the AI life cycle and business considerations, which means a candidate has to be able to distinguish model families and place a system in its life cycle stage. That is not governance vocabulary, it is engineering vocabulary used for a governance purpose.
The standards sub-area is where preparation goes wrong
Sub-area E covers standards, frameworks and regulations related to AI, alongside ethical considerations. It is easy to skim because it looks like background reading, and it sits in the largest governance domain. The most widely adopted of those frameworks is the NIST AI framework, and its four functions map closely onto how the governance domain is organised, so reading it directly is a better use of time than reading a summary of it.
Risk management and privacy sit alongside as their own sub-areas: risk identification, assessment and monitoring in one, and data governance plus privacy considerations in the other. Anyone who has run a conventional risk programme will find the structure familiar and the content shifted, because AI risk includes categories such as model drift and training data provenance that a traditional register does not carry.
What Is Inside the Seven AI Operations Sub-Areas?
The heaviest domain on the paper breaks into seven parts: data management specific to AI, solution development methodologies and lifecycle, change management, supervision of AI solutions, testing techniques, threats and vulnerabilities, and incident response management. Together they are 46 percent.

Data management alone names seven topics: collection, classification, confidentiality, quality, balancing, scarcity and security. Data balancing and data scarcity are the two that rarely appear in a general audit syllabus, and both are genuinely AI-specific. An imbalanced training set produces a model that performs well on aggregate and badly on the group that was under-represented, which is an audit finding rather than a technical curiosity.
Testing, threats and incident response
Sub-area E splits testing into conventional software testing applied to AI solutions and AI-specific testing techniques, which is a distinction worth internalising because it is how a question will be framed. Sub-area F covers types of AI-related threats and the controls for them; the reference taxonomy for that material is MITRE ATLAS, which catalogues adversarial techniques against machine learning systems in the same structured way ATT&CK does for conventional intrusion.
Incident response is broken into five named stages: prepare, identify and report, assess, respond, and post-incident review. That is a conventional structure applied to an unconventional subject, and the exam interest is in what changes at each stage when the thing that failed is a model rather than a server.
Supervision of AI solutions is the shortest sub-area and names a single topic, AI agency. It is small in the syllabus and large in practice, because the question of how much a system decides on its own is what determines the control set around it.
How Small Is the Auditing Domain, Really?
Twenty-one percent, across five sub-areas: audit planning and design, testing and sampling methodologies, evidence collection techniques, data quality and analytics, and audit outputs and reports. It is the smallest domain on an audit certification, which is the single most counter-intuitive fact about AAIA.
The content is nonetheless specific rather than generic. Audit planning names the identification of AI assets, types of AI controls, AI audit use cases and internal training for AI use. Testing names the design of an AI audit, AI audit testing methodologies, AI sampling and testing AI outcomes. Sampling an AI system is not the same activity as sampling transactions, and the syllabus treats it as its own topic for that reason.
Evidence collection covers data collection, walkthroughs and interviews, and AI collection tools. The inclusion of walkthroughs and interviews is a reminder that this is still an audit exam: a significant part of establishing how a model is governed comes from asking people, not from querying a system.
The final sub-area, outputs and reports, covers reports, audit follow-up and quality assurance. It is the smallest slice of the smallest domain, and it is also the part every candidate already knows how to do, which is a reasonable explanation for its size.
What Does Registering for AAIA Involve?
Four steps with real deadlines attached. Confirm you hold a qualifying designation, register and pay in full, schedule through PSI within a six-month eligibility window, and after passing submit a certification application with a 50 US dollar processing fee.

The six-month window is the one to plan around. Eligibility is established at registration and expires six months later, so registering early to lock a price and then studying at leisure is a mistake. Scheduling opens 48 hours after payment clears, appointments are only visible 90 days ahead, and rescheduling is free provided it is done at least 48 hours before the appointment.
One regional restriction worth knowing before you book
Candidates in India, mainland China and Hong Kong cannot use remote proctoring for this exam and must sit it at a testing centre. That is specific to AAIA rather than a general ISACA policy, and it changes the logistics considerably for candidates in three of the largest markets for the credential.
Passing the exam is also not the same as being certified. A candidate must hold the qualifying designation, pass, pay the application fee and adhere to the Code of Professional Ethics, and there is a five-year window from the exam date in which to apply. Our earlier AAIA exam overview covers the credential’s positioning for readers deciding whether to start.
Does AAIA Replace CISA or Build on It?
It builds on it and cannot exist without it. AAIA is an advanced credential layered on top of an existing audit designation, and CISA is the primary route to it. The two are not alternatives, and a candidate who lets a CISA lapse loses the qualification that made AAIA available.
That relationship explains the syllabus more than anything else does. Because CISA has already established audit process, controls and governance fundamentals, AAIA does not retest them. It tests the subject matter that has arrived since: how AI systems are constructed, what goes wrong with them, and what an auditor has to know to form a view.
For anyone not yet holding a qualifying designation, the sequence is unavoidable. CISA first, then AAIA, and the gap between them should be spent working with AI systems rather than reading about them, because the 46 percent domain rewards operational familiarity. Our comparison of CISA and CISM is a useful starting point for choosing that first credential, since only one of the two opens the AAIA route.
How Should You Prepare for the AAIA Exam?
Invert your instincts. The domain closest to your existing expertise is the smallest, and the one furthest from it is nearly half the paper. Six steps in the order that reflects the weighting rather than the order the syllabus lists them.
- Confirm your qualifying designation is active before spending anything, because registration is closed to anyone outside the sixteen accepted routes and the check happens at registration rather than at the exam.
- Give AI Operations the most study time despite it being the least familiar domain, since its seven sub-areas carry 46 percent of the paper between them.
- Learn the AI-specific data topics properly, especially data balancing and data scarcity, because those two have no equivalent in a conventional audit syllabus and are named individually.
- Read a recognised AI risk framework end to end rather than a summary of one, so the standards and ethics sub-area of the governance domain becomes structural knowledge instead of a list of names.
- Work through the adversarial threat categories against AI systems and the controls for each, since threats and vulnerabilities is a named sub-area and the material is unfamiliar to most auditors.
- Leave the auditing domain until last and treat it as calibration rather than learning, because at 21 percent it is the smallest domain and you already hold a designation that proved you can do it.
Register only when the study plan is real, because the six-month eligibility window starts at registration and not at the point you feel ready. A candidate who registers on the day they decide to pursue the credential typically loses two of those six months to reading they could have done first.
Frequently Asked Questions
Can anyone register for the AAIA exam?
No. ISACA requires an active CISA certification or one of fifteen named accounting and internal audit designations held in an IT audit or IT advisory role. There is no open registration route.
How many questions are on the AAIA exam?
90 questions in 150 minutes, which is 100 seconds each. The timing is comfortable, which matters because ISACA writes long question stems.
What is the passing score for AAIA?
450 on ISACA’s scaled range. It is a conversion rather than a percentage, and ISACA does not publish how many raw correct answers it corresponds to, so it cannot be worked out in advance.
How much does the AAIA exam cost?
459 US dollars for ISACA members and 599 for non-members. A separate 50 dollar application processing fee is payable after passing, when you apply for the certification itself.
Which AAIA domain carries the most weight?
AI Operations at 46 percent, across seven sub-areas. AI Governance and Risk is 33 percent and AI Auditing Tools and Techniques only 21 percent, which is the smallest domain on the paper.
How long is AAIA eligibility valid after registering?
Six months from the date of registration. The fee must be paid in full before scheduling, appointments open 48 hours after payment, and slots are only visible 90 days ahead.
Can I take AAIA with remote proctoring?
In most regions, yes, through PSI. Candidates in India, mainland China and Hong Kong are the exception and must sit the exam at a testing centre.
Does passing the exam make me AAIA certified?
Not on its own. You must also hold a qualifying designation, pay the application processing fee and adhere to the Code of Professional Ethics. There is a five year window from passing in which to apply.
Do I need CISA before AAIA?
CISA is the primary route but not the only one. Fifteen accounting and internal audit designations also qualify, provided the holder works in an IT audit or IT advisory role.
Is AAIA a technical exam?
More technical than most auditors expect. The largest domain covers AI data management, development lifecycle, testing techniques, adversarial threats and incident response, none of which is audit method.
Conclusion
Two numbers define this credential. Sixteen, the number of designations that let you register at all. And 46, the percentage of the exam that is about how AI systems work rather than how they are audited.
Plan around both. Check your designation is active before you spend anything, and do not register until the study plan is real, because the six-month eligibility clock starts at registration rather than at readiness. Then put your hours where the weighting is, not where your confidence is: the operations domain covering data balancing, model supervision, adversarial threats and AI incident response deserves roughly half your preparation, and the auditing domain deserves the least of it. That inversion is uncomfortable for an experienced auditor, and it is exactly what ISACA built the exam to test.
