The ISACA Advanced in AI Audit (AAIA) exam has 90 questions and a 150-minute time limit. It tests your ability to evaluate risks and controls in artificial intelligence systems. CISA holders know IT general controls, access management, and change management. The AAIA domains require a different frame. Traditional software either executes a rule or it doesn't. AI models produce outputs that vary with the input distribution, drift over time, and can be manipulated by adversarial inputs — none of which a standard ITGC control set was designed to catch.
The exam divides into three domains: AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). Domain 2 is where most IT auditors lose points. It's the largest section by weight, the most technical in content, and the section that feels least like a traditional CISA exam — most of what's tested here didn't exist in the audit world ten years ago.
Domain 1 tests your ability to advise stakeholders on AI implementation that fits organizational goals, create ethical AI policies, and mitigate risks. It establishes the vocabulary and regulatory context for the rest of the exam.
Traditional auditors assume standard IT risk management applies fully to AI. It does not.
Software failures in IT are usually binary — a code error produces a wrong output. AI failures can occur when a model functions correctly but produces biased outputs because the training data was skewed. You are governing a system that learns and changes over time, not a static system patched periodically.
Generic answers about "establishing a steering committee" fail if the question targets ISO 42001's AI System Impact Assessment. Memorize the structural requirements of the 21 AI frameworks tested. The exam distinguishes between them at the control level.
The EU AI Act is a primary reference for Domain 1. The high-risk deadline moved to December 2, 2027 — the substantive obligations in Articles 9–15 did not. Read: EU AI Act Delayed to December 2027: What IT Auditors Must Know →
Most IT auditors lack practical experience with the machine learning lifecycle. Without understanding training, validation, and holdout testing data, you cannot audit model performance metrics.
Drift is the concept that trips candidates most often. Data drift means the statistical properties of input data change over time. Concept drift means the relationship between the input and the target variable shifts. A credit card fraud detection model loses accuracy if consumer spending habits change — as they did sharply in 2020. Controls that detect drift and trigger retraining are what you audit. Not the model outputs themselves.
Domain 3 tests audit techniques tailored to AI systems and the use of AI-enabled tools to improve audit efficiency.
Auditors apply traditional substantive testing to AI outputs. Testing 25 transactions cannot verify AI model function. Outputs are probabilistic — the same input can generate different outputs depending on model architecture and state.
Test controls around the model: governance structures, training data quality checks, monitoring alerts. Not just outputs. Explainability is a separate audit objective. If a model denies a loan, the organization must explain why to customers and regulators. Verify that explainability tools like SHAP or LIME are implemented and functioning — not just present in documentation.
ISACA lists 23 cross-domain skills that cut across all three domains. They confirm the AAIA tests practical advisory ability, not just technical knowledge.
See how the Domain Accuracy Dashboard in AAIA Prep pinpoints your weakest domain automatically. Try 50 free questions across all 3 domains →
Reading whitepapers will not pass this exam. Practice applying concepts to audit scenarios.
Know the difference between data drift and concept drift. Know which NIST AI RMF function — Govern, Map, Measure, or Manage — applies to a given audit scenario. Know what ISO 42001's AI System Impact Assessment requires and when it triggers. These distinctions appear on the exam as scenario questions, not definition recalls.
Candidates who pass on the first attempt typically spend 6 to 8 weeks cycling through practice questions until their domain accuracy stabilizes. Domain 2 is where most of that time goes.
Holding CISA already? Here is how the two exams compare. Read: From CISA to AAIA in 90 Days →
Want to test yourself on all three domains right now? Try 25 free AAIA practice questions →
Know the domains. Now build a study plan that actually gets you to exam day ready. How to Pass the ISACA AAIA Exam: A First-Attempt Playbook →