I took the ISACA Advanced in AI Audit exam in January 2026 and passed on my first attempt. Here is the short answer to the question in the title: the AAIA is very passable for a prepared CISA holder, and it will humble an unprepared one. It is not hard because the AI content is exotic. It is hard because nearly half the exam lives in one domain, AI Operations, and because the question style punishes the exact instinct that made you good at CISA: reaching for the answer that is correct in general instead of the answer that is correct for the scenario in front of you.
That distinction decided more questions on my exam than any framework definition did. The rest of this post breaks down where the difficulty actually sits, what the numbers say, and how to know when you are ready.
Everything in this table comes from ISACA's official AAIA Exam Candidate Guide and certification page, current as of July 2026.
| Fact | Detail |
|---|---|
| Questions | 90 multiple choice, four options each, one best answer |
| Time | 2.5 hours (150 minutes) |
| Domain 1: AI Governance and Risk | 33% |
| Domain 2: AI Operations | 46% |
| Domain 3: AI Auditing Tools and Techniques | 21% |
| Scoring | Scaled 200 to 800, passing score 450 |
| Wrong answers | No penalty. Never leave a blank. |
| Prerequisite | Active CISA, or a qualifying designation such as CIA or CPA |
| Cost | US $459 for ISACA members, US $599 for non-members, non-refundable |
| Delivery | PSI testing center or online remote proctoring |
| Results | Preliminary pass/fail on screen at submission; official score report within approximately 10 business days |
Two numbers in that table matter more than the rest. The first is 46. The second is 150.
ISACA has not published an official pass rate for the AAIA. Any site quoting one is guessing, and the guess usually lives next to a "guaranteed pass" dumps package, which should tell you what the number is for.
So skip the percentage. The honest way to talk about difficulty is this: the exam is scored on a scale of 200 to 800, you need 450, and the people who miss that bar tend to miss it for predictable reasons. ISACA's own blog ran a candid piece from a candidate who failed the AAIA and wrote about it, which I respect, because most of what you will read online is written by people selling certainty. Real candidates fail this exam. The failure accounts that circulate publicly point to the same three causes, and none of them is "the AI was too technical."
If you hold CISA, you already know ISACA's question grammar: the qualifiers like MOST and BEST and FIRST, the four options where two are defensible, the answer that favors evidence over opinion. All of that transfers. In that sense the AAIA feels familiar from the first question.
The difference is shape. CISA covers a wide field at moderate depth. The AAIA covers one field, AI systems, at real depth, and it quietly tests a mindset change that no amount of traditional IT audit experience gives you for free: traditional IT audit assumes deterministic systems, where the system does what the code tells it to do. AI systems are probabilistic. The same model can produce different outputs depending on when it was retrained, what data it learned from, and how the input interacts with learned patterns. A control that fully satisfies a deterministic system, a code review, a change ticket, a config baseline, can be the wrong answer for a model whose behavior drifts after deployment.
My take after sitting both: CISA is harder to prepare for because of its breadth. The AAIA is harder to sit, question by question, because the scenarios are longer, the distractors are closer together, and the exam keeps checking whether you actually understand why auditing a model is different from auditing a system. I wrote a full breakdown of that gap in From CISA to AAIA in 90 Days. Which one you earn first is a separate question with a firmer answer: see AAIA vs CISA, and which to get first.
Candidates split study time evenly across three domains because the outline lists three domains. The exam does not work that way.
AI Operations, the model lifecycle, data pipelines, deployment, monitoring, drift, is nearly half your score sheet. If Domain 2 is your weakest area, no amount of governance fluency will carry you to 450. Weight your study hours to match the blueprint: roughly half on Domain 2, a third on Domain 1, the rest on Domain 3. I mapped where CISA holders struggle domain by domain in AAIA Exam Domains Explained.
This is the pattern that separates passing from failing, so I will be specific. A scenario describes an organization partway through something: a risk assessment already performed, a model already validated, an incident already contained. One answer option is a textbook best practice, something like "conduct a comprehensive risk assessment." It is a good answer to many audit questions. It is the wrong answer here, because the scenario told you it already happened, and the question asked what you do NEXT.
Read every scenario twice before looking at the options. First pass: what kind of organization, what AI system, what is actually being asked. Second pass: hunt for the detail that narrows it, a named regulation, a step already completed, a failure mode already identified. The best answer addresses the situation as described, not the situation in the abstract. The most impressive-sounding option is a distractor more often than it is the key.
Ninety questions in 150 minutes is one minute and forty seconds per question. Scenario stems eat that fast. Candidates rarely run out of knowledge on this exam. They run out of time, usually by spending four minutes wrestling one hard Domain 3 question in the first hour and then rushing ten easy ones at the end. Triage instead: answer what you know, flag what you do not, and come back with momentum. And since there is no penalty for wrong answers, a blank is the only guaranteed zero on the exam.
One logistical note that affects pacing: you get one break with the proctor's permission, and the timer does not stop for it. Budget as if the 150 minutes is continuous, because it is.
Some difficulty deflation, in fairness. Every question has four options and one best answer, so disciplined elimination pays: kill one obviously wrong option and your odds on a pure guess jump to 33%. Your audit fundamentals genuinely transfer in Domains 1 and 3, where governance structures, evidence standards, and reporting logic look like the work you already do. And the exam rewards a rule you already live by professionally: when two options both seem right, choose the one that produces objective, testable evidence.
If you are still deciding whether the credential justifies the effort, the full cost and eligibility breakdown covers that question, and the AAIA vs AAISM vs AIGP comparison covers whether this is even the right exam for your role.
Both are offered through PSI. I will flag the tradeoff candidates underestimate: remote proctoring adds a check-in ritual, a 360-degree room scan, a desk scan, a mirror check of your laptop edges, and a hard list of rules where reading a question out loud or glancing at a phone can void the exam without refund. If your home setup is not genuinely controlled, the testing center is the lower-stress option. Whichever you choose, schedule early: appointments open only 90 days out, and your registration fee is forfeited if the six-month eligibility window closes on you.
The signal I trust is not hours studied. It is performance under exam conditions. Before you book the appointment, you should be able to do two things:
That second condition is the one candidates skip, and it is why time pressure shows up as "the exam was harder than the practice questions" in so many post-exam threads.
This is exactly the gap I built AAIA Prep to close. Every question is matched to the exam's domain weights, the explanations teach the "best answer for THIS scenario" discipline, and timed full-exam mode makes condition number two automatic. The first 30 questions and 20 flashcards are free, no account required, so you can benchmark where you stand today. Or start with the 22 free practice questions with explanations right here on the site.
What is the AAIA pass rate?
ISACA has not published one. Treat any specific pass-rate figure you see online as invented. The scored bar is 450 on a 200 to 800 scale.
Is the AAIA harder than CISA?
Different hard. CISA is broader and harder to prepare for. AAIA is narrower, deeper, and harder question by question, especially if your machine learning lifecycle knowledge is thin. CISA holders who study Domain 2 seriously pass it.
What happens if I fail?
ISACA allows up to four attempts within a rolling twelve-month period, with a 30-day wait after your first attempt and 90 days between later attempts, and each retake carries a new exam fee. Your score report includes a domain-level breakdown, so you know exactly where to rebuild.
How long should I study?
For a working CISA holder, two to three months of structured prep is realistic. The 90-day bridge plan lays out the sequence week by week.
How many questions is the AAIA exam?
90 multiple-choice questions in 150 minutes, weighted 33% AI Governance and Risk, 46% AI Operations, 21% AI Auditing Tools and Techniques.
Dr. Baz Abouelenein is a higher education CIO who holds the AAIA, CISA, CISM, CRISC, CISSP, and PMP. He passed the AAIA on his first attempt in January 2026 and built AAIA Prep to give candidates the scenario-based, exam-weighted practice he could not find while preparing.
Try the AAIA Prep question bank → The AAIA Prep question bank has 1,155 original questions at exam difficulty, including 20 four-question scenario sets. 30 free to try.
Not affiliated with or endorsed by ISACA, ISC², or PMI.
AAIA, CISA, CISM, and CRISC are registered trademarks of ISACA. CISSP is a registered trademark of ISC². PMP is a registered trademark of PMI. IT Audit Prep is not affiliated with, endorsed by, or sponsored by ISACA, ISC², or PMI.