AAIA Study Guide: Domain-by-Domain Plan to Pass First Try

I passed the AAIA on my first attempt while working full time. More hours wasn’t the answer. Studying the right things in the right order, weighted to how the exam actually scores, was.

This is the plan I wish I had on day one. It goes domain by domain, scenario first, and it tracks the exact blueprint ISACA publishes. If you are still deciding whether the certification is worth it, start with the companion guide on AAIA cost, eligibility, and whether it’s worth it. Then come back here and build your prep.

The AAIA exam at a glance

Before you study a single question, internalize how the exam is scored. Everything below flows from these facts, all taken from ISACA’s official credentialing pages:

FactDetail
Questions90 multiple-choice questions
Time2.5 hours (150 minutes), confirmed against author’s own exam record
Passing score450 on a scaled 200 to 800 range
Exam feeUS$459 (member) / US$599 (non-member), plus a US$50 application fee
Eligibility window6 months from registration to sit
PrerequisiteAn existing credential with an IT audit or advisory focus: CISA, CIA, a US/Canadian/Australian/Japanese CPA, ACCA/FCCA, or other qualifying credentials. See ISACA’s official credentialing page for the full list.
DomainsAI Governance & Risk (33%), AI Operations (46%), AI Auditing Tools & Techniques (21%)

Two numbers should reshape your entire plan: the scaled passing score of 450, and the 46% weighting on AI Operations. The AAIA is not a definitions test. It rewards judgment under realistic audit scenarios, and nearly half of it lives in a single domain. Spreading study time evenly is the most likely mistake a first-timer makes.

Why the AAIA is harder than candidates expect

If you came from CISA, you are used to questions that reward recall plus a layer of best-answer reasoning. The AAIA pushes further. Questions drop you into a situation (a model drifting in production, a vendor that won’t disclose its training data, a governance committee that never defined its AI risk appetite) and ask what the auditor should do next. Two answers usually look defensible. One is correct because of sequence, materiality, or independence.

That means memorizing frameworks gets you maybe halfway. The other half is pattern recognition: seeing the scenario type and knowing the disciplined auditor’s move. You build that only by working through scenario questions, not flashcards alone. Candidates who rely on framework memorization tend to stall in Domain 2 where the reasoning gap is widest.

Step 1: Let the blueprint allocate your time

Map your study hours to the domain weights, not to your comfort zone:

  • AI Operations, 46%. This is the exam. Give it roughly half your time.
  • AI Governance & Risk, 33%. A third of your time. Heaviest on frameworks and regulation.
  • AI Auditing Tools & Techniques, 21%. The smallest slice, and the one where audit veterans get overconfident and lose easy points.

If you remember only one thing from this article, remember this: do not study the three domains equally. A 50/30/20 split mirrors the exam and protects your scaled score where it counts.

Step 2: The domain-by-domain study guide

Domain 1: AI Governance and Risk (33%)

ISACA’s outline covers AI models and requirements, governance and program management, AI risk management, privacy and data governance, and the ethics, regulations, and standards layer. Anchor your study around the frameworks that recur across questions:

  • NIST AI Risk Management Framework (AI RMF): know the Govern, Map, Measure, and Manage functions cold.
  • EU AI Act: the risk tiers (unacceptable, high, limited, minimal) and what the high-risk obligations actually require.
  • ISO/IEC 42001 and ISO/IEC 23894 for AI management and risk guidance.

Don’t just memorize the names. Practice mapping a scenario to the right framework and the right control.

Domain 2: AI Operations (46%)

This is the largest and most operational domain: data management for AI, the solution development lifecycle, change management, supervision of AI outputs and decisions, testing techniques, AI-specific threats and vulnerabilities, and incident response. Expect heavy coverage of:

  • Model drift, bias, and explainability: how an auditor detects and evidences each.
  • AI lifecycle controls, and where audit checkpoints belong from data sourcing to deployment.
  • AI-specific threats such as prompt injection, data poisoning, and model inversion, along with the controls that mitigate them.

This is where timed practice pays off most. Half the exam lives here, and it is the domain where reasoning beats recall by the widest margin.

Domain 3: AI Auditing Tools and Techniques (21%)

Audit planning and design, testing and sampling, evidence collection, data quality and analytics, and audit outputs and reports. Seasoned auditors should score highest here, but only if they translate familiar IT-audit discipline into the AI context. Ask yourself what counts as sufficient, appropriate evidence when the system under audit is a probabilistic model.

Step 3: Practice scenario questions, not definitions

Definition banks teach you to recognize a term. The AAIA asks you to act. Your practice should:

  • Be written in ISACA’s reasoning style: scenario-first, with a realistic audit situation.
  • Give explanations for every option, so you learn why the right answer is right and why each plausible distractor is wrong.
  • Track your weakest domain so you can redirect time toward it.

Quantity matters less than coverage and explanation quality. A few hundred well-explained questions across all three domains beats a thousand recycled definitions every time.

Step 4: Use spaced repetition for the framework layer

The governance domain has a memorization core (framework structures, regulatory tiers, standard numbers) that fades fast. Spaced-repetition flashcards are the most efficient way to hold it. Run them daily in short bursts and let the algorithm resurface what you keep missing.

Step 5: Simulate the real exam before you book it

Two weeks out, sit a full 90-question mock under timed conditions. Score it on the scaled model. A mock does three things a quiz cannot. It builds time discipline, because you have under 100 seconds per question. It surfaces the domain where you are actually weak. And it removes exam-day surprise. If you cannot clear the equivalent of 450 scaled on a realistic mock, you are not ready, and that is a US$459 lesson worth learning for free.

A realistic 4-to-6-week study schedule

For a working professional putting in 5 to 7 hours a week:

  • Weeks 1 to 2: Read the blueprint. Study Domain 2 (AI Operations) first, because it is the biggest. Start daily flashcards.
  • Weeks 3 to 4: Domain 1 (Governance & Risk) and the framework deep-dive. Begin daily question sets, and review every wrong answer.
  • Week 5: Domain 3 (Tools & Techniques). Ramp question volume. Keep flashcards running.
  • Week 6: Full timed mock exam, remediate weak domains, light review, then book the exam.

Compress to four weeks if you already hold CISA and audit AI systems day to day.

Common mistakes that fail first-timers

  • Studying domains evenly. The 33/46/21 weighting is a gift. Use it.
  • Memorizing instead of reasoning. Frameworks are table stakes; the exam tests judgment, not memory.
  • Skipping the timed mock. Working at under 100 seconds per question is a skill you have to rehearse.
  • Ignoring AI-specific threats. Drift, bias, poisoning, and inversion show up repeatedly in Domain 2.
  • Treating it like CISA. The overlap is real, but the AI context changes the right answer more often than veterans expect.

Tools and resources

Start free. ISACA publishes a short official practice quiz at isaca.org, and several sites offer free question samples. Both are useful for calibrating difficulty before you spend anything.

Whatever tool you choose, hold it to the same bar: scenario reasoning, full explanations, domain-weighted coverage, and a realistic timed mock. Anything less won’t prepare you for how the exam actually tests.

Frequently asked questions

How hard is the ISACA AAIA exam? It is a judgment exam, not a recall exam. The 90 questions ask what an auditor should do in realistic AI situations, with multiple defensible-looking answers. Candidates who rely on framework memorization tend to struggle. Those who practice scenario reasoning across all three domains pass.

How long should I study for the AAIA? Most working professionals need 4 to 6 weeks at 5 to 7 hours per week. Existing CISA holders who audit AI systems can compress to about 4 weeks. Weight roughly half your time to the AI Operations domain, which is 46% of the exam.

What is the AAIA passing score? 450 on a scaled 200 to 800 range. Raw scores are converted to a scaled score so different exam versions are comparable, and 450 is always the pass line.

Do I need a prerequisite to take the AAIA? Yes. You need an existing credential with an IT audit or advisory focus, such as CISA, CIA, a recognized CPA designation, or ACCA/FCCA. See ISACA’s official credentialing page for the full list of qualifying credentials.

Are free AAIA practice questions enough to pass? Free samples are good for gauging difficulty, but they are too few and rarely explain every answer option. To pass on the first try, you need broad coverage with explanations and at least one full timed mock.

Last reviewed: July 2026. Exam fees, format, and eligibility requirements are subject to change. Confirm current details on ISACA’s official credentialing pages before registering.

AAIA salary data: what AI audit roles verifiably pay in 2026

Review the three AAIA exam domains and their weighting. AAIA exam domains explained

Written by Baz Abouelenein
Higher-education CIO and IT auditor. AAIA · CISA · CISM · CRISC · CISSP · PMP

Not affiliated with or endorsed by ISACA, ISC², or PMI.

AAIA, CISA, CISM, and CRISC are registered trademarks of ISACA. CISSP is a registered trademark of ISC². PMP is a registered trademark of PMI. IT Audit Prep is not affiliated with, endorsed by, or sponsored by ISACA, ISC², or PMI.