I hold both. The order is not a preference, and the reason is a rule most comparisons never mention.
ISACA will not certify you in Advanced in AI Audit until you already hold an active credential from its qualified designation list. The CISA is the most common one. Fifteen other credentials also qualify.
Then comes the part that changes the math. ISACA's AAIA maintenance requirements include one line that almost nobody quotes: "Maintain active status on prerequisite certification used to apply for AAIA." Let the CISA lapse and you do not keep the AAIA. The AAIA never becomes a standalone credential. Choosing your entry credential means choosing what you will maintain for the rest of your career.
Disclosure: I build study apps for both of these exams. That is a reason to check my work rather than take it on trust, so every figure below links to the ISACA page it came from. All ISACA pages cited were checked on 4 August 2026.
Earn the CISA first, unless you already hold one of the fifteen other qualifying credentials and work in an IT audit or IT advisory role. In that case you can go straight to the AAIA.
There is no route where the AAIA replaces the CISA. It stacks on top of a qualification you already hold, and it depends on that qualification staying active for as long as you keep it.
ISACA's AAIA certification page lists sixteen. Only one of them qualifies unconditionally.
| Credential | Issuing body | Condition |
|---|---|---|
| CISA | ISACA | All holders qualify |
| CIA | Institute of Internal Auditors | IT audit or IT advisory role focus |
| US CPA | US state boards of accountancy | IT audit or IT advisory role focus |
| ACCA | Association of Chartered Certified Accountants | IT audit or IT advisory role focus |
| FCCA | ACCA (Fellow) | IT audit or IT advisory role focus |
| CPA | CPA Australia | IT audit or IT advisory role focus |
| FCPA | CPA Australia (Fellow) | IT audit or IT advisory role focus |
| CPA | Japan Financial Services Agency | IT audit or IT advisory role focus |
| CPA | Canadian provincial accounting bodies | IT audit or IT advisory role focus |
| ACA | ICAEW | IT audit or IT advisory role focus |
| FCA | ICAEW (Fellow) | IT audit or IT advisory role focus |
| CNA | Association of National Accountants of Nigeria | IT audit or IT advisory role focus |
| CA | Chartered Accountants Australia and New Zealand | IT audit or IT advisory role focus |
| FCA | CA ANZ (Fellow) | IT audit or IT advisory role focus |
| CPA | Hong Kong Institute of CPAs | IT audit or IT advisory role focus |
| FCPA | HKICPA (Fellow) | IT audit or IT advisory role focus |
Read the list, not the sentence above it. ISACA's page opens that section with a one-line summary naming nine designations: CISA, CIA, US CPA, ACCA or FCCA, Canadian CPA, Australian CPA or FCPA, and the Japanese CPA. The full list sits directly beneath it and runs to sixteen. Skim the sentence and stop, and a chartered accountant from England, Australia, New Zealand, Hong Kong, or Nigeria would reasonably conclude they do not qualify. They do.
The summary sentence appears to have been left behind by ISACA's own expansions. The AAIA launched on 19 May 2025 with three qualifying credentials: CISA, CIA, and CPA. On 22 July 2025 ISACA added six more accounting designations, reaching nine. The remaining seven were added later, on a date ISACA has not announced.
Every other ISACA certification you earn is yours to keep on its own terms. The AAIA is not.
ISACA's AAIA maintenance requirements list four obligations, and the fourth is the one that matters here:
That last requirement is permanent. If you qualify through the CISA, you carry the CISA's own 20 CPE hours a year, 120 across three years, and US$45 annual fee for as long as you want to keep the AAIA. Qualify through a CPA and you carry your state board's licensure and CPE obligations instead, which are typically heavier than either ISACA credential.
The practical consequence: choose your door deliberately, because you are choosing the credential you will maintain for the rest of your career. The AAIA's own upkeep is modest. What sits underneath it is not.
ISACA does not publish an answer, and that is worth knowing before you pay.
The prerequisite appears in exactly one place in the AAIA Exam Candidate Guide: step one of "How to become Certified," which runs active credential, pass the exam, pay the US$50 application fee, submit the application. The guide's registration section covers scheduling and eligibility windows and never mentions the prerequisite at all.
So the rule is documented as a certification requirement. Whether anyone verifies it at registration is not addressed in any ISACA document I can find.
Three facts make that gap expensive to test. Exam fees are non-refundable and non-transferable. Registration opens a six-month eligibility window, extendable once for US$75. And ISACA restricts candidates who pass from retaking the same exam "within the application time period of 5 years," which tells you a five-year gap between passing and applying is contemplated.
If you are considering passing the AAIA before your prerequisite is active, ask ISACA support in writing and keep the reply. A five-minute email is cheaper than a US$459 assumption.
| Attribute | CISA | AAIA |
|---|---|---|
| Questions | 150 multiple choice | 90 multiple choice |
| Time | 4 hours (240 minutes) | 2.5 hours (150 minutes) |
| Domains | 5 | 3 |
| Domain weights | 18% / 18% / 12% / 26% / 26% | 33% / 46% / 21% |
| Scoring | 200–800 scale, 450 to pass | 200–800 scale, 450 to pass |
| Exam fee | US$575 member / US$760 non-member | US$459 member / US$599 non-member |
| Application fee | US$50 | US$50 |
| Experience required | 5+ years, waivers up to 3 years | None of its own; a qualifying credential plus, for 15 of the 16, an IT audit or advisory role |
| Annual CPE | 20 hours | 10 hours |
| Annual maintenance fee | US$45 member / US$85 non-member | US$20 member / US$35 non-member |
The AAIA's three domains are AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). Domain 2 alone is nearly half the exam, which is the most useful number on this page for anyone budgeting study time. I covered where that weighting catches IT auditors out separately.
One caution about those percentages. ISACA states that domain-level results are reported "for informational purposes only," and that scores are based on the total number of items answered correctly regardless of domain. The weights describe how much of the exam covers each area. They are not a scoring formula, and there is no per-domain minimum to clear.
For early-career auditors, yes. The exam is the visible hurdle. The experience is the binding one.
ISACA requires five or more years of experience in IS/IT audit, control, assurance, or security, gained within the ten-year period preceding your application. Waivers cover a maximum of three years, so the shortest legitimate path still involves two years of qualifying work.
You then have five years from your passing date to apply. That produces the sequence most people actually run: pass the CISA exam, accumulate the experience, apply once you qualify, then move to the AAIA after the CISA is active.
Because the exam comes first and the experience clock runs in parallel, most people start studying long before they can apply. If you want question practice for that stage, I build CISA Prep: Audit Exam Practice for the CISA and AAIA Prep: AI Audit Exam for the AAIA. Both are free to download with the first set of questions unlocked.
If you are two years into an IT audit career hoping the AAIA is a way around that wait, it is not. The prerequisite must be active at the point you apply for AAIA certification, and it must stay active afterward.
Exam and application fees come to US$1,134 at member rates and US$1,459 at non-member rates.
| Item | Member | Non-member |
|---|---|---|
| CISA exam | US$575 | US$760 |
| CISA application | US$50 | US$50 |
| AAIA exam | US$459 | US$599 |
| AAIA application | US$50 | US$50 |
| Total | US$1,134 | US$1,459 |
Member pricing is not free. ISACA professional membership is US$145 a year plus local chapter dues, which vary by chapter. If you spread the two exams across two calendar years, that is two years of dues. Membership still pays for itself here: the two exams alone are US$325 cheaper at member rates.
Then the recurring cost. Holding both means two maintenance fees every year, US$65 combined at member rates, and two separate CPE reporting obligations: 20 hours for the CISA and 10 for the AAIA, with no overlap credit between them.
If you hold a CPA, CIA, ACCA, ICAEW, CA ANZ, HKICPA, or ANAN qualification and your role is unambiguously IT audit or IT advisory, ISACA's own list says the CISA is not required.
Two cautions before you act on that. ISACA does not publish a definition of "IT audit or IT advisory role focus," a rubric for assessing it, or an evidence standard. Compare that with the CISA, where experience must be independently verified by a supervisor or manager. The role condition on the fifteen non-CISA paths is not documented anywhere I can find, which means you are self-assessing against a test ISACA has not written down.
And the exam fee is non-refundable. So if your role sits anywhere near the boundary, in tax, in financial audit, in general assurance, confirm your specific designation and role with ISACA support in writing before you register.
Take the CISA anyway if you want the IT audit credential on its own merits, or if your employer's job architecture asks for it by name. Just do not assume you need it as a gateway when your existing qualification may already open the door.
Different rather than harder. The CISA is broader and longer: five domains, 150 questions, four hours. The AAIA is narrower and faster, and it punishes surface familiarity with AI operations rather than rewarding breadth.
I took the AAIA in January 2026 and passed on the first attempt. My longer write-up on how hard the AAIA actually is covers the time pressure and the trap-answer pattern in detail. If you already hold the CISA and want the study bridge rather than the comparison, start with what carries over from CISA to AAIA. For the wider picture on cost and career value, see the AAIA certification guide and what AI auditors actually earn.
Do I need the CISA to get the AAIA?
You need an active credential from ISACA's list of qualified designations. The CISA is the only one that qualifies unconditionally. Fifteen other credentials qualify if you hold an IT audit or IT advisory role focus.
Which is better, the AAIA or the CISA?
Neither, because they answer different questions. The CISA is a foundational IT audit credential you can hold on its own. The AAIA is an advanced credential that requires one of those foundations and cannot be held without it. The real decision is the order, and for most people ISACA has already made it.
Can I take the AAIA exam before I am CISA certified?
ISACA documents the prerequisite as a certification requirement and does not publish an eligibility check at exam registration. Because fees are non-refundable and non-transferable, confirm your position with ISACA support in writing before registering.
What happens to my AAIA if my CISA lapses?
ISACA's AAIA maintenance requirements state that you must maintain active status on the prerequisite certification used to apply. The AAIA is a dependent credential and is not designed to survive on its own.
Does the AAIA have its own work-experience requirement?
No years-of-experience count appears in the certification steps. Fifteen of the sixteen qualifying paths add a role condition instead: you must hold an IT audit or IT advisory role focus.
Is the AAIA replacing the CISA?
No. ISACA describes it as an advanced credential for IT audit professionals who already hold a qualifying designation.
How much does it cost to get both?
US$1,134 in exam and application fees at ISACA member rates, or US$1,459 at non-member rates, plus membership dues of US$145 a year and local chapter dues if you want member pricing.
What are the ongoing requirements?
The CISA requires 20 CPE hours annually, 120 across three years, and a US$45 annual maintenance fee for members. The AAIA requires 10 CPE hours annually, 30 across three years, a US$20 annual fee for members, and continued active status on the prerequisite credential.
How many attempts do I get at the AAIA?
Four attempts in a rolling twelve-month period: one initial sitting plus three retakes. Waits are 30 days after the first attempt and 90 days after the second and third, and each attempt costs the full registration fee.
I hold an ICAEW or Hong Kong CPA qualification. Am I eligible?
ISACA's qualified designation list includes ICAEW ACA and FCA and HKICPA CPA and FCPA, with an IT audit or IT advisory role focus. Those designations are absent from the one-line summary on ISACA's AAIA page but present in the full list beneath it.
Current as of August 2026. ISACA sets exam fees, eligibility, and CPE requirements and changes them without much notice. ISACA has also announced CPE policy changes effective 1 January 2027, so verify maintenance figures against ISACA's official pages before relying on them. This article is information, not career or financial advice.
Dr. Baz Abouelenein is a higher education CIO who holds the AAIA, CISA, CISM, CRISC, CISSP, and PMP. He passed the AAIA on his first attempt in January 2026.
I build a question bank for each of these certifications. Both are free to download, and both are iPhone and iPad apps.
Taking the CISA first, as most readers here will be? CISA Prep: Audit Exam Practice has 1,000 questions mapped across the five CISA domains and 68 subtopics, 505 of them scenario-based, plus a full 150-question mock on the same 200 to 800 scale the real exam uses. 30 questions and 20 flashcards are free, with no account and no card.
Already qualified and going straight to the AAIA? AAIA Prep: AI Audit Exam has 1,155 practice questions, 80 of them inside 20 multi-question scenarios, plus a full 90-question mock exam with scaled scoring on the same 200 to 800 scale ISACA uses. 30 questions free.