Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's advanced AI audit credential as of 2026, covering the three domains, exam format, the CISA, CIA, or CPA prerequisite, career paths, the frameworks it tests against, and how AAIA compares to AAISM and AAIR. A complete reference guide for auditors weighing the AAIA.
AI policy, oversight, risk assessment, and the regulatory layer. 33% of the exam.
The AI lifecycle, MLOps, validation, and drift and bias monitoring. The heaviest domain at 46%.
Scoping AI audits, evidence collection, analytics, and reporting. 21% of the exam.
AAIA is ISACA's advanced AI audit credential, launched in 2025 as the first certification built specifically for auditors who need to assure AI systems.
It validates the ability to evaluate, monitor, and validate AI systems from a governance and risk perspective, and to apply audit tools and techniques to AI. The work it tests is practical and scenario based: assessing whether AI controls operate effectively, gathering evidence in AI environments, and reporting findings, not building models.
Because it is an advanced add-on, AAIA has a hard prerequisite: an active audit credential such as CISA, CIA, or CPA. It is issued by ISACA, the body behind CISA, and it maps directly to the AI frameworks regulators and audit committees are adopting.
Four things that set AAIA apart as AI lands on the audit plan and organizations need assurance it can be trusted.
CISA, CIA, and CPA were never designed for the complexity of AI: dynamic data pipelines, models even their developers can't fully explain, and decisions made in milliseconds. AAIA is the first and only advanced credential aimed squarely at assuring those systems, answering a single question: can this AI be trusted?
AAIA is an advanced credential with a hard prerequisite: an active CISA, CIA, or CPA, or a recognized global equivalent. That gate means every holder already has a proven audit foundation, and the exam builds AI-specific assurance skills on top of it.
Because AAIA is so new, the market signal is strong relative to the number of holders, and ISACA's brand carries weight with audit committees and regulators. Our guide on GRC certifications for 2026 covers where it fits.
AAIA is not currently part of the DoD 8140 qualification matrix. Its weight comes from ISACA's audit standing and from the frameworks it tests against by name: the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and sector rules from financial services to healthcare.
For audit teams whose organizations operate under those regimes, that alignment is exactly what makes the credential useful right now.
Everything you need to know about the certification, the exam structure, and how to maintain AAIA as of 2026.
AAIA covers the audit and assurance side of AI. Professionals who span security, risk, or policy often pair it with one of these to cover the full AI governance picture.
ISACA's Advanced in AI Security Management is for those who secure and govern AI rather than audit it. It shares AAIA's exam structure and requires an active CISM or CISSP.
ISACA's Advanced in AI Risk focuses on governing and managing AI risk across the enterprise. It requires one of around 25 qualifying risk or security designations, and complements an audit specialty.
The IAPP AI Governance Professional comes at AI from the policy and law side, with deep EU AI Act coverage and no prerequisite. A common pairing with AAIA for auditors who need the policy view too.
AAIA is a specialization, not a starting point. It sits on top of an audit foundation and points toward the broader AI security, risk, and governance credentials around it.
The required base
The add-on
Two questions to answer before you commit: can you sit it, and should you pursue AAIA specifically. Here's a straight answer to both.
You're eligible now.
AAIA is gated behind an active audit credential: CISA, CIA, or CPA, or a recognized global equivalent such as ACCA, FCCA, or a Canadian, Australian, or Japanese CPA. If you hold one, you meet the prerequisite. ISACA also expects around three years of audit, risk, or compliance experience, with at least one in technology-related auditing.
Earn the prerequisite first.
There is no test-first path for AAIA. You cannot sit it without a qualifying audit designation. For most people the CISA is the better first investment: it is the most widely recognized IT audit credential, it qualifies you for AAIA, and it opens more doors on its own in the short term.
AAIA targets audit and assurance roles focused on AI. These are the roles the credential is built for, sitting on top of an existing audit foundation.
Leads audits of AI systems and the controls around them, from model governance to monitoring. The role AAIA was built to validate as AI lands on the audit plan.
Runs an audit function now responsible for AI implementations alongside traditional systems, setting scope and standards for how AI gets assured.
Provides independent assurance that AI controls operate effectively, testing everything from training data governance to drift and bias monitoring.
Audits AI implementations from inside the organization, evaluating algorithmic bias, evidence integrity, and compliance with emerging AI rules.
Verifies that AI systems meet obligations such as the EU AI Act and sector-specific regulations, and documents the evidence that proves it.
Advises on AI control design and the evidence to gather before the auditors arrive, bridging the gap between AI operations and assurance.
ISACA's three advanced AI credentials share an exam structure but aim at different jobs: auditing AI, securing AI, and managing AI risk. Here's how they line up.
| AAIA | AAISM | AAIR | |
|---|---|---|---|
| Issuer | ISACA | ISACA | ISACA |
| Focus | AI audit and assurance | AI security management | AI risk management |
| Prerequisite | CISA, CIA, or CPA | Active CISM or CISSP | One of ~25 risk or security certs |
| Exam Format | 90 questions, 2.5 hours | 90 questions, 2.5 hours | 90 questions, 2.5 hours |
| Passing Score | 450 / 800 | 450 / 800 | 450 / 800 |
| Renewal | 30 CPEs over 3 years | 30 CPEs over 3 years | 30 CPEs over 3 years |
| DoD 8140 Approved | No | No | No |
| Best For | Auditors assuring AI | Security leaders governing AI | Risk pros managing AI |
All three are advanced credentials that require an existing designation. Pricing and prerequisites vary; check ISACA for the current qualifying list before you register.
Our ISACA AAIA boot camp covers all three domains over two days, with your exam voucher and official courseware included, built for auditors who already hold CISA, CIA, or CPA and are taking on AI.
Choosing among the AI credentials, the ISACA AI family, and where AAIA fits in AI assurance.
A deeper look at why ISACA built AAIA, the gap that CISA, CIA, and CPA left open for auditing AI systems, and what makes the credential land at exactly the right moment.
AAIA is for auditors who verify controls, AAISM for managers who set strategy, AAIR for risk pros. A clear read on which of the three ISACA AI credentials fits your work.
SecAI+ is for practitioners who touch keyboards, AAISM for managers who set strategy, AAIA for auditors who verify controls. How to pick the right AI credential for the job you do.
Where AI audit fits in the wider governance, risk, and compliance landscape, and how AAIA sits alongside CISA and CRISC as AI governance reshapes GRC work.
The questions that actually clarify the choice: your jurisdiction, the frameworks you already run, and how mature your AI program is. Where an audit credential like AAIA fits.
The frameworks and accountability structures auditors test against, from ISO/IEC 42001 and the NIST AI RMF to the OECD principles, and the context AAIA is grounded in.
A clear-eyed look at the wave of new AI credentials, which ones address a real market gap, and how AAIA stacks up against the rest of the 2026 launches.
The AAIA job practice is organized into three domains, with weights that are deliberately uneven. Click any domain for what it covers.
AI policy and board oversight, roles and ethical principles, AI inventory and risk assessment, data governance and privacy, and the regulatory layer: the EU AI Act, ISO/IEC 42001, the NIST AI RMF, and sector rules.
The heaviest domain. The AI and ML lifecycle and MLOps, secure development, model validation and testing, deployment, and monitoring for drift, performance, and bias, plus change management and incident response.
The audit-specific work: scoping AI audits, control design and effectiveness testing, evidence collection and documentation, AI-enabled analytics applied to audits, and reporting and communicating findings.
Domains and weights reflect the ISACA AAIA Exam Content Outline as of the 2025 launch. ISACA updates its outlines on a regular cycle.
The questions candidates ask most often when researching the Advanced in AI Audit certification.
AAIA is ISACA's advanced AI audit credential, launched in 2025 as the first certification built specifically for auditing AI systems. It validates the ability to evaluate, monitor, and assure AI from a governance and risk perspective, and to apply audit tools and techniques to AI. It's built for experienced auditors, not beginners.
AAIA fits internal auditors, external auditors, and compliance professionals who already hold a CISA, CIA, or CPA and now have AI systems on their audit plan. People who secure AI rather than audit it are usually better served by AAISM, and those focused on risk by AAIR.
You need a qualifying audit credential, and CISA is the most common path. AAIA also accepts CIA, CPA, and recognized global equivalents such as ACCA, FCCA, and Canadian, Australian, or Japanese CPA designations. There is no test-first option; you must hold one before you register.
As of 2026 the AAIA exam costs $459 for ISACA members and $599 for non-members, with pricing that can vary by region. Confirm the current fee on ISACA's site when you register, since published figures for the newer AI credentials have varied. Many candidates take a boot camp that folds the exam voucher in.
The AAIA exam is 90 scenario-based, multiple-choice questions over 2.5 hours, delivered through PSI in person or via remote proctoring. It tests applied judgment rather than recitation. You need a scaled score of 450 out of 800 to pass.
The three AAIA domains are AI Governance and Risk at 33 percent, AI Operations at 46 percent, and AI Auditing Tools and Techniques at 21 percent. AI Operations carries nearly half the exam and is where auditors from a traditional background most often lose points.
AAIA is maintained on a three-year cycle. You earn 30 Continuing Professional Education (CPE) credits over the cycle, with a minimum of 10 per year focused on AI, and pay an annual maintenance fee to ISACA. You also need to keep your prerequisite designation active while you hold AAIA.
Not currently. AAIA does not appear on the DoD 8140 Approved Qualifications Matrix V2.1. Its recognition rests on ISACA's standing in audit and on the AI frameworks it tests against, such as the NIST AI RMF, ISO/IEC 42001, and the EU AI Act, rather than on DoD 8140 status.
All three are ISACA advanced AI credentials with the same exam structure. AAIA is for auditors who verify AI controls, AAISM is for security leaders who secure and govern AI, and AAIR is for risk professionals managing AI risk. They differ mainly in focus and in which prerequisite certification you need.
AAIA from ISACA is an audit credential that requires a CISA, CIA, or CPA and centers on assuring AI systems and gathering evidence. AIGP from the IAPP comes at AI from the policy, privacy, and law side, with deep EU AI Act coverage and no prerequisite. Auditors who need both the assurance and the policy view sometimes pair them.
Yes. ISACA launched AAIA in 2025 as the first and only advanced audit-specific AI certification, alongside AAISM for security and, later, AAIR for risk. Because it is new, the market signal is strong relative to the small number of current holders.
For credentialed auditors who have AI systems on their audit plan, AAIA is one of the few credentials that speaks directly to assuring AI in 2026. ISACA's brand carries weight with audit committees, and the content tests real operational AI knowledge. For those without a qualifying credential, earning a CISA first is the better move.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.