AAIA Exam Guide: Eligibility, Domains, Preparation and Scheduling Decisions
The ISACA Advanced in AI Audit (AAIA) exam validates whether an experienced IT auditor or advisor can assess AI-related opportunities and challenges across governance, operations, and audit work. It is intended for professionals who assess, implement, maintain, or audit AI systems, and candidates must hold an active CISA or another qualified advanced-auditing designation with an IT-audit or IT-advisory focus. This guide helps you decide whether you are ready to register, which domain deserves the most study time, and how to organize preparation around official materials rather than question dumps.
Is AAIA the right certification for your role?
AAIA is aimed at experienced IT auditors and advisors who assess, implement, maintain, or audit AI systems. The practical fit question is not whether you use AI tools personally; it is whether your work requires you to evaluate AI governance, operational risk, controls, evidence, or audit outputs.
The credential is therefore a specialized progression for an established audit or advisory professional rather than a general introduction to artificial intelligence. Someone looking for basic AI vocabulary may need foundational learning before using the AAIA outline as a study plan. Someone already working with technology risk, assurance, or advisory engagements can use the outline to identify where AI-specific judgment must be added.
ISACA states that AAIA candidates must hold an active CISA or another qualified advanced-auditing designation with an IT-audit or IT-advisory focus. Check the qualifying-designation requirement before paying for registration. Passing the exam alone does not remove the prerequisite requirement for certification. Source: https://www.isaca.org/credentialing/aaia
Use your current responsibilities as a readiness test. Can you explain how an AI system should be governed, how its lifecycle and data risks should be controlled, and how an auditor would plan testing and evaluate evidence? If several answers are uncertain, treat that gap as a preparation priority rather than assuming practice-question familiarity will compensate for it.
What must happen before you schedule?
You must complete exam registration and payment before scheduling and taking the AAIA exam, and you must meet AAIA exam eligibility requirements. The immediate decision is whether to confirm your designation and payment status first or postpone registration while you close a knowledge gap.
ISACA says candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees. The same AAIA information identifies remote and in-person options, with exams administered at authorized PSI testing centers globally or as remotely proctored exams. Verify current appointment and system details in the official scheduling information before selecting an option. Source: https://www.isaca.org/credentialing/aaia
ISACA’s registration information says AAIA exam appointments are only available 90 days in advance. If a preferred site or date is not visible more than 90 days in advance, the official advice is to check again closer to the desired date. Availability is a scheduling matter, not evidence that your eligibility has failed.
The scheduling sequence provided by ISACA is to log in to your ISACA Account, open Certification & CPE Management, select Schedule Your Exam, and continue to the PSI dashboard. Check PSI test-site availability and system compatibility before committing to a date. Candidates in India, Mainland China, and Hong Kong should note ISACA’s stated restriction that the AAIA exam is exclusively available at testing centers in those locations. Source: https://www.isaca.org/credentialing/aaia
Rescheduling is permitted during the eligibility period without penalty when completed a minimum of 48 hours before the scheduled testing appointment. Save the official scheduling and remote-proctoring guidance with your appointment records, because delivery requirements can change and are separate from the exam content outline.
What does the exam actually measure?
The AAIA exam consists of 90 questions across three areas, all testing the ability to address real-world AI-related opportunities and challenges. Prepare to apply audit and assurance reasoning to scenarios rather than treating the exam as a glossary exercise.
The three tested areas are AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques. The content outline describes the domains, subtopics, and tasks as being developed through research, feedback, and validation from subject-matter experts and industry leaders. That makes the outline the correct starting point for mapping your existing knowledge to the exam.
Read each domain as a capability statement. Governance and Risk asks whether you can advise on responsible, strategically aligned AI adoption and mitigate implementation risks. Operations asks whether you can assess the controls and readiness surrounding the AI lifecycle. Auditing Tools and Techniques asks whether you can plan, test, collect and evaluate evidence, and communicate audit results.
A useful preparation note should contain more than definitions. For each task in the outline, write what an auditor would need to establish, what evidence could support the conclusion, which stakeholder owns the control, and what weakness would change the audit response. These are study prompts, not representations of live exam questions. Source: https://www.isaca.org/credentialing/aaia/aaia-exam-content-outline
How should you use the domain weights?
Let the official weighting determine study emphasis, but do not neglect a lower-weight domain. The AAIA exam weighting is 33% for AI Governance and Risk, 46% for AI Operations, and 21% for AI Auditing Tools and Techniques. Each percentage identifies an official exam domain and should be treated as a planning signal, not a passing-score prediction. Source: https://www.isaca.org/credentialing/aaia/aaia-exam-content-outline
AI Governance and Risk represents 33% of the exam and covers AI models and requirements, governance and program management, AI risk management, privacy and data governance programs, and leading practices, ethics, regulations, and standards for AI. Study this domain through decision chains: organizational objective, AI use case, governing policy, risk treatment, accountability, and evidence that the treatment operates.
AI Operations represents 46% of the exam and covers AI-specific data management, solution-development lifecycles, change management, supervision, testing, threats and vulnerabilities, and incident response. Give this domain the largest share of your planned review because it has the highest official weighting. Connect each lifecycle stage to ownership, control objectives, monitoring, escalation, and operational evidence.
AI Auditing Tools and Techniques represents 21% of the exam and covers audit planning, testing and sampling, evidence collection, audit data quality and analytics, and AI audit outputs and reports. Do not interpret the lower percentage as permission to skip audit mechanics. Strong AI knowledge without defensible planning, evidence, testing, and reporting is incomplete preparation.
A practical allocation method is to divide your study sessions into domain blocks that broadly reflect the official weighting, then reserve review time for weak topics identified through self-testing. This is a recommendation, not an ISACA rule. Keep the domain label beside every note and progress result so that a strong overall impression does not hide a serious weakness in one area.
How do the three domains connect in practice?
The domains form an audit chain: governance establishes direction and accountability, operations turns that direction into managed AI activity, and auditing tools and techniques provide a method for evaluating controls and reporting conclusions. Study them as connected responsibilities instead of three unrelated chapters.
For AI Governance and Risk, begin with the reason the organization wants to use an AI solution. Then ask whether the model, data, intended outcome, and affected parties fit approved strategy and policy. Continue through risk identification, privacy and data governance, ethical considerations, applicable requirements, and the responsibilities of decision-makers. The official domain description emphasizes strategic alignment, ethical and responsible policy, and mitigation of implementation risks. Source: https://www.isaca.org/credentialing/aaia/aaia-exam-content-outline
For AI Operations, follow the system from data management through development, change, supervision, testing, threat and vulnerability management, and incident response. Your notes should distinguish a design control from an operating control and should identify what happens when monitoring reveals drift, unexpected behavior, poor data quality, or a security event. This domain is about operational readiness as well as technical activity.
For AI Auditing Tools and Techniques, translate the earlier governance and operational questions into an audit approach. Define the objective and scope, determine suitable testing and sampling, evaluate the reliability and quality of evidence and audit data, apply analytics appropriately, and produce an output that communicates a supported conclusion. The official outline specifically identifies these audit-planning, evidence, data-quality, analytics, and reporting capabilities. Source: https://www.isaca.org/credentialing/aaia/aaia-exam-content-outline
When reviewing a scenario, ask three questions in order: what should the organization require, how should the AI capability operate, and how would an auditor know whether it works? This sequence helps prevent a common mistake—jumping to a technical test before establishing the governance objective or the operational risk.
Which official preparation materials are worth using?
Start with the official AAIA Exam Content Outline and candidate guide, then choose preparation products according to how independently you study. ISACA lists self-directed and instructor-supported options, so the right resource mix depends on whether you need reference depth, question-based practice, structured teaching, or live interaction.
The AAIA Review Manual is described by ISACA as a reference guide for preparing for the certification exam. ISACA also offers an official AAIA online review course with six months of access and 11 CPE upon completion. Use the manual to build understanding and use the course, if selected, to impose a learning sequence rather than passively reading pages. Source: https://www.isaca.org/credentialing/aaia; https://www.isaca.org/store2/product/AAIA-ORC-C
ISACA’s official AAIA exam-prep bundle includes the review-manual eBook, Questions, Answers and Explanations database, online review course, and exam registration. The AAIA page also describes a QAE resource as a six-month subscription to a 200+ question database. Confirm the current product contents in your ISACA account or the official store before purchase. Source: https://www.isaca.org/store2/product/AAIA-BUNDLE-C; https://www.isaca.org/credentialing/aaia
ISACA lists a live virtual workshop option. The workshop information states that on-demand programming will not be available for that program. It also describes an immersive 2-day or 4-day virtual training event, with the displayed event formats and CPE details varying by offering. Do not assume that a live workshop can be replayed; verify the specific enrollment terms before relying on it for your schedule. Source: https://www.isaca.org/training-and-events/online-training/virtual-workshops/aaia
The candidate-guide page lists English, Simplified Chinese, Japanese, and Spanish versions of the exam candidate guide. That does not mean the AAIA exam is offered in all those languages: the registration evidence lists the exam as available in English. Use the guide language that helps you understand procedures, while preparing for the exam language stated by ISACA. Source: https://www.isaca.org/credentialing/exam-candidate-guides; https://www.isaca.org/store2/product/AAIA-BUNDLE-C
How should you study when your audit background is strong but AI experience is uneven?
Use a gap-led plan rather than reading every topic with equal intensity. First map your audit experience to the outline, then add AI-specific concepts and lifecycle risks, and finally practice integrating governance, operations, and audit responses in one scenario.
Create a three-column diagnostic for each outline task: confident, familiar but untested, and unfamiliar. “Confident” should mean you can explain the decision and its evidence, not merely recognize a term. Place unfamiliar items in the appropriate domain and begin with the highest-impact weaknesses in AI Operations and any foundational gaps that could distort your governance or audit reasoning.
Build concept sheets around relationships. For a model-related topic, connect purpose, data, development, validation, deployment, monitoring, change, threats, incidents, and accountability. For privacy or data governance, connect data use to authorization, quality, stewardship, retention or handling requirements where relevant to the official material, and evidence. Avoid adding unsupported regulatory specifics simply to make notes appear authoritative.
After each study block, close the book and explain the topic in auditor language. State the risk, expected control or governance practice, evidence, testing approach, possible finding, and report implication. If you cannot make those links, reread the relevant section and revise the note. This active recall method is a practical recommendation, not an official exam requirement.
Use official QAE explanations to investigate why an answer is correct and why alternatives are weaker, where that resource is available to you. Record the underlying principle and the domain, not just the answer letter. Memorizing a question pattern is fragile, and unauthorized dumps or leaked questions are neither a reliable nor an appropriate substitute for learning the tested skills.
What is a practical AAIA study roadmap?
A workable roadmap has four passes: establish scope, learn the domains, integrate the audit response, and verify readiness. Move forward only when you can explain decisions and evidence without depending on copied wording or a memorized answer sequence.
Pass one is scope and eligibility. Read the official exam content outline from beginning to end, mark every subtopic and task, confirm your qualifying active designation, and review the candidate guide. Decide whether you will use the manual, online review course, live instruction, or a combination. Do not schedule merely because a resource has been purchased.
Pass two is domain learning. Study AI Governance and Risk first if your work is strong in audit execution but weak in AI policy, ethics, privacy, or risk management. Study AI Operations with particular care if your experience is primarily assurance reporting and does not include AI data, development, change, supervision, testing, vulnerability, or incident processes. Keep AI Auditing Tools and Techniques active throughout rather than leaving it to the final review.
Pass three is integration. Take a hypothetical organizational AI implementation and work through its strategic objective, governance structure, risk profile, data arrangements, lifecycle controls, monitoring, incident response, audit scope, evidence plan, testing, analytics, and report. This is not a prediction of exam content; it is a controlled way to practice the capability described by the outline.
Pass four is verification. Revisit every missed or uncertain item by domain, explain the governing principle aloud or in writing, and use fresh practice to test reasoning. Set a personal readiness rule: you should be able to justify an answer from the domain’s objectives and audit logic, not from remembering that a similar-looking question had a particular option.
Once your knowledge review is complete, choose a date that leaves enough room for administrative checks and focused revision. Confirm the appointment details through PSI, verify the selected delivery method, and keep the official candidate and scheduling guidance accessible. If your study plan is not yet stable, postponing registration may be more sensible than creating avoidable scheduling pressure.
Which preparation mistakes cause avoidable problems?
The most damaging mistakes are usually planning errors: ignoring eligibility, studying by familiarity instead of blueprint coverage, confusing AI concepts with audit conclusions, and treating practice questions as the curriculum. Correct these before adding another book, course, or question bank.
Do not begin with a generic AI course and assume it covers AAIA. General AI knowledge may not address governance and risk, operational readiness, or audit planning, evidence, analytics, and reporting in the way the official outline measures them. Use the AAIA outline to decide what additional learning is relevant.
Do not spend all your effort on the domain that feels comfortable. Experienced auditors may over-rely on familiar testing and reporting techniques, while technically experienced candidates may over-focus on models and implementation. Track weaknesses by official domain, including AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques.
Do not treat the 33% AI Governance and Risk weighting, the 46% AI Operations weighting, or the 21% AI Auditing Tools and Techniques weighting as a score guarantee. The percentages describe exam weighting, not a published pass mark or a promise that a particular study strategy will produce a result. Source: https://www.isaca.org/credentialing/aaia/aaia-exam-content-outline
Do not wait until appointment day to investigate delivery requirements. ISACA directs candidates to check PSI test-site availability and system compatibility, and remote delivery has its own guidance. If you need special accommodations, review the official process early rather than assuming a request can be handled at the last moment.
Finally, do not use exam dumps, leaked questions, or answer memorization as a preparation strategy. They cannot establish that you understand the professional judgment behind an answer, and relying on them can leave the exact governance, operational, evidence, and reporting weaknesses that the certification is intended to assess.
What happens after you pass?
Passing the exam is one step in earning and retaining AAIA; certification also involves the qualifying designation, application, ethics, fees, and continuing professional education. Put the post-exam obligations into your professional calendar before you register so the credential remains sustainable after the test.
To obtain the certification, ISACA states that candidates must pass the AAIA exam, maintain an active qualifying designation, pay a one-time US$50 application-processing fee, and apply within five years of passing the exam. ISACA also lists adherence to the Code of Professional Ethics as part of the certification journey. Source: https://www.isaca.org/credentialing/aaia/get-aaia-certified
AAIA holders must maintain the active status of the prerequisite certification used for their application. Certification holders must begin earning and reporting CPE in the calendar year after certification. The maintenance requirements page states that maintaining AAIA requires a minimum of 10 CPE annually and a total of 30 CPE over a 3-year reporting period, including 10 hours of CPE in the specialized domain of Artificial Intelligence annually. Source: https://www.isaca.org/credentialing/aaia/maintain-aaia-certification
The annual maintenance fee is US$20 for ISACA members and US$35 for non-members, with payment due annually by January 1. ISACA says a payment button is available in the Certification Dashboard when fees are due. Review the current maintenance page for the applicable process rather than relying on an old reminder or an informal checklist. Source: https://www.isaca.org/credentialing/aaia/maintain-aaia-certification
CPE records should be retained for a minimum of three years, and ISACA may select holders for an annual CPE audit. Keep completion evidence, reporting details, and the AI-specialized portion of your learning organized as you earn it. Missing documentation can create a compliance problem even when the learning itself occurred.
What should you do before committing to an exam date?
Make the decision in this order: confirm eligibility, read the outline, choose resources, diagnose gaps, complete integrated practice, then verify delivery and schedule. This sequence protects your preparation budget and keeps an appointment from becoming a substitute for readiness.
Open the official AAIA certification page and confirm the current registration, eligibility, scheduling, and delivery information. Pay the registration fee only after checking that your active CISA or other qualified designation satisfies the requirement. Remember that registration and payment are required before an appointment can be scheduled.
Download or review the official candidate guide and exam content outline. Create a checklist containing the three domains and every listed task. Beside each task, write one explanation of the risk or objective and one example of evidence or audit action. Update the checklist as your understanding improves.
Select study material that matches your constraint. Choose the manual when you need a reference base, the official online review course when structured online preparation suits you, live instruction when interaction matters and you can attend the scheduled event, and QAE practice when you need to test recall and reasoning. Check access periods and current inclusions on the official product page.
When ready, check PSI availability, system compatibility, and the delivery option that fits your circumstances. If you choose a remote appointment, follow the official remote-proctoring instructions; if you choose a center, verify the site and appointment details. If a preferred date is unavailable, use the official availability guidance rather than inventing an assumption about exam status.
After passing, complete the application within the permitted period, keep the prerequisite designation active, pay the application-processing fee, and plan CPE and maintenance payments. The best next action today is to compare your current experience against the official outline and mark the first domain task you cannot yet explain clearly.
Conclusion
AAIA preparation is strongest when it mirrors the professional work the credential measures: align AI use with governance and risk expectations, examine operational controls across the lifecycle, and produce an evidence-based audit response. Confirm the prerequisite before registration, use the official content outline to diagnose gaps, give AI Operations its 46% exam weighting while covering all three domains, and verify PSI arrangements before scheduling. Study resources can organize learning, but understanding the decisions behind governance, operations, testing, evidence, and reporting is the preparation that remains useful beyond the exam.