If you hold the Certified Information Systems Auditor (CISA) credential, you know traditional IT general controls. You audit logical access, change management, and disaster recovery. You evaluate deterministic systems — specific inputs produce specific outputs.

The ISACA Advanced in AI Audit (AAIA) certification requires this foundation. In fact, holding a CISA (or an equivalent like the CIA or CPA) is mandatory to take the AAIA exam.

The transition from CISA to AAIA is not a credential upgrade. The audit object changes. CISA trains you to evaluate whether controls exist and whether they work. AAIA asks whether the system itself can be trusted — and AI systems fail in ways that traditional controls were never designed to catch. A model that was accurate last quarter may not be accurate today. Algorithmic bias lives in the training data; removing it usually means rebuilding the dataset, not adjusting a configuration. Adversarial inputs aren't a vulnerability in the conventional sense; they're a side effect of how neural networks generalize.

This guide maps the knowledge gaps between the CISA syllabus and AAIA domains. It breaks down how your audit skills apply to AI, where they fall short, and how to close the gap in 90 days.

The CISA Baseline: What You Already Know

Your CISA experience gives you a strong advantage. You do not need to relearn audit methodology fundamentals.

1. The Audit Process

CISA teaches you to plan audits, define scope, gather evidence, and communicate findings. AAIA expects this. Domain 3 of AAIA (AI Auditing Tools and Techniques) asks you to apply this process to AI.

The Gap: How do you gather sufficient evidence when auditing a "black box" neural network that even developers cannot fully explain?

2. IT Governance and Management

CISA covers IT strategy, steering committees, and policy frameworks like COBIT. AAIA requires evaluating AI governance structures.

The Gap: Traditional IT governance manages resource risk and keeps IT connected to business goals. AI governance adds ethical risk, societal impact, and regulatory compliance under frameworks like the EU AI Act. You need to learn the NIST AI RMF and ISO 42001 structures.

3. Information Systems Acquisition, Development, and Implementation

CISA covers the Systems Development Life Cycle (SDLC). You audit requirements, code testing, and production migration.

The Gap: AI development follows a Machine Learning Operations (MLOps) lifecycle, not a traditional SDLC. You must audit data ingestion, feature engineering, model training, validation testing (e.g., holdout sets), and continuous retraining.

4. Information Systems Operations and Business Resilience

CISA covers service level management, database administration, and incident response.

The Gap: AI operations require monitoring for data drift and concept drift. Models degrade if production data diverges from training data. You need to audit controls that detect this drift.

5. Protection of Information Assets

CISA covers logical access controls, network security, and cryptography.

The Gap: AI introduces new attack vectors beyond traditional firewalls. You must audit defenses against prompt injection, data poisoning, model inversion, and adversarial evasion attacks.

Want to test your CISA-to-AAIA knowledge gap right now? Try 50 free AAIA practice questions →

Month 1: Bridging the Governance Gap (AAIA Domain 1)

Focus the first 30 days on AI governance frameworks and regulations. This maps to AAIA Domain 1 (AI Governance and Risk), which accounts for 33% of the exam.

The Mindset Shift: From Deterministic to Probabilistic Risk

CISA deals with binary risks: access granted or denied. AI risks exist on a spectrum.

You cannot eliminate all bias in a model; you measure and mitigate it to acceptable levels. Audit objectives shift from verifying error absence to verifying statistical thresholds for fairness and accuracy.

The Study Focus: The 21 Frameworks

AAIA tests specific frameworks. General risk management principles will not suffice.

  • Master the NIST AI RMF: Know the four core functions (Govern, Map, Measure, Manage) and their interactions. Understand "trustworthy AI" as valid, safe, secure, resilient, accountable, transparent, explainable, privacy-enhanced, and fair.
  • Master ISO/IEC 42001: This Artificial Intelligence Management System (AIMS) standard follows the High-Level Structure of ISO 27001. Focus on the AI System Impact Assessment and Annex A controls for the AI lifecycle.
  • Master the EU AI Act: Understand the four risk tiers (Unacceptable, High, Limited, Minimal). Focus on Article 16 obligations for High-Risk systems, the main audit focus.

The EU AI Act's high-risk deadline moved to December 2, 2027. The substantive obligations did not. Most CISA programs cover about a third of what Articles 9–15 require. Read: EU AI Act Delayed to December 2027: What IT Auditors Must Know →

Month 2: Bridging the Operations Gap (AAIA Domain 2)

Spend the second 30 days on AI development and deployment mechanics. This maps to AAIA Domain 2 (AI Operations), the largest exam section at 46%. CISA holders find this the hardest.

The Mindset Shift: From SDLC to MLOps

In SDLC, code is logic. In machine learning, data is logic. The algorithm learns data patterns. Auditing AI operations means auditing data pipelines and validation testing.

The Study Focus: The AI Lifecycle and Security

Become fluent in data science and MLOps vocabulary.

  • Data Management: Audit data provenance, quality, and lineage. Verify training datasets are clean and free of unauthorized copyrighted material.
  • Model Validation: Distinguish training, validation, and testing (holdout) data. Understand cross-validation. Evaluate metrics like precision, recall, and F1 score to assess model accuracy.
  • Adversarial Threats: Study the MITRE ATLAS framework. Understand how attackers manipulate outputs by altering inputs (evasion) or corrupt models during training (data poisoning). Audit defenses against prompt injection in Large Language Models (LLMs).
  • Continuous Monitoring: Audit thresholds and alerts for data drift and concept drift in production.

Domain 2 is where most CISA holders lose points. See how AAIA Prep targets your weakest domain automatically. Explore AAIA Prep features →

Month 3: Bridging the Audit Execution Gap (AAIA Domain 3)

The final 30 days focus on applying new knowledge to audit execution. This maps to AAIA Domain 3 (AI Auditing Tools and Techniques), which accounts for 21% of the exam.

The Mindset Shift: From Substantive Testing to Control Testing

As a CISA, you sample 25 user access requests to verify approval. You cannot sample 25 ChatGPT outputs to verify model accuracy. The model may produce 25 different answers to the same prompt.

Audit controls around the model — governance, training data quality checks, automated monitoring alerts — rather than probabilistic outputs.

The Study Focus: Evidence and Explainability

Learn to gather evidence in a black-box environment.

  • Scoping the Audit: Use the organization's AI inventory (required by ISO 42001) to define audit scope based on model risk.
  • Evaluating Explainability: If a model denies a loan, the organization must explain why. Audit mechanisms like SHAP values or LIME that interpret complex models.
  • AI-Enabled Auditing: AAIA tests your ability to use AI tools to improve audits, such as machine learning for anomaly detection in large financial datasets.

The Path to the AAIA Credential

Transitioning from CISA to AAIA requires effort. For IT auditors working in organizations that deploy or govern AI systems, it is a direct extension of existing audit methodology into a domain where most audit teams currently lack coverage.

To pass in 90 days, avoid passive reading. Practice applying concepts to complex, scenario-based exam questions. Train your brain to think probabilistically.

Download AAIA Prep on the App Store

Other AAIA apps exist, but none match the depth. AAIA Prep has 1,155 original questions — nearly double the competition — 8 adaptive study modes, 200 spaced-repetition flashcards, and a full 21-framework library. Built by a CIO who passed in the first year the exam was available.

  • 1,155 Practice Questions: 1,155 questions versus ISACA's 200+ question QAE database, mapped exactly to the 33/46/21 domain weighting.
  • Domain Accuracy Dashboard: Track performance by domain. Identify strengths and weaknesses to focus study time.
  • 21 Frameworks Library: Breakdowns of frameworks tested on the exam, including NIST, ISO 42001, and the EU AI Act.
  • 200 Spaced-Repetition Flashcards: Efficiently memorize technical vocabulary of MLOps and adversarial threats.
  • Full Mock Exams: 90-question simulations with scaled scoring to test readiness under timed conditions.

Most candidates who pass on the first attempt spend 6 to 8 weeks cycling through questions until their readiness score holds above 75%.

Not sure which AI certification to pursue first? Read: AAIA vs AAISM vs AIGP: Which Is Right for You? →

  1. [1]
  2. [2]