AAIA certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
AI Governance And Risk
The assessment boundary for “AI Governance And Risk” covers objectives, decision ownership, risk significance, fitness of supporting information, sequence of action, and well-founded conclusions. Applied work in this area should show that the candidate can separate accountable roles, request sufficient support, and act in the order the scenario requires. It leads into “AI Operations” in the published outline.
Question notes
When a scenario reaches “AI Governance And Risk,” remember that question context may require separating management ownership from independent assurance responsibility. Check specifically for this failure condition: insufficient evidence, confused responsibility, premature judgment, or action taken against a secondary issue rather than the source of risk. Judge completion through an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Published weighting guides relative priority but does not disclose a dependable item count.
Preparation tips
Turn “AI Governance And Risk” into a reviewable practice artifact. Exercise: Compare management, implementation, and assurance perspectives on the same case and document why their next actions differ. Challenge condition: insufficient evidence, confused responsibility, premature judgment, or an intervention focused on what is visible instead of the underlying risk. Completion evidence: a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Complete the exercise by tracing one consequence into “AI Operations”.
AI Operations
“AI Operations” defines an applied capability within AAIA — ISACA Advanced in AI Audit: intended model behavior, grounding and data boundaries, trust controls, evaluation, integration, deployment, and ongoing observation. Success depends on being able to connect the intended use to suitable data and controls, evaluate representative behavior, and define how unsafe or degraded results are handled. In the published sequence, it follows “AI Governance And Risk” and precedes “AI Auditing Tools And Techniques”.
Question notes
For “AI Operations,” context matters: the expected judgment should remain proportional to risk and consistent with governance responsibilities. Challenge the result with weak grounding, untested model behavior, excessive permissions, misleading evaluation, or deployment without monitoring and escalation, then verify it using evaluation cases, grounded responses, trust-control results, integration traces, deployment checks, and monitored behavior after release. Use the dedicated weight field for published emphasis rather than deriving a question count from this note.
Preparation tips
Keep a short decision journal for “AI Operations.” Complete this exercise: Trace one AI-assisted interaction from input and data access through model response, downstream action, evaluation, and monitoring. Record whether you detected or prevented weak grounding, untested model behavior, excessive permissions, misleading evaluation, or deployment without monitoring and escalation. Attach evaluation cases, grounded responses, trust-control results, integration traces, deployment checks, and monitored behavior after release. End with a clear statement of how the result affects “AI Auditing Tools And Techniques”.
AI Auditing Tools And Techniques
The “AI Auditing Tools And Techniques” portion of AAIA — ISACA Advanced in AI Audit focuses on objectives, assigned accountability, risk significance, strength of the available evidence, sequence of action, and supportable conclusions. A complete response should connect accountability with evidence needs before deciding which action belongs next in the sequence. It draws on work established in “AI Operations”.
Question notes
For “AI Auditing Tools And Techniques,” the assessment context matters: question context may require separating management ownership from independent assurance responsibility. Failure mode to test: unreliable support, unclear ownership, conclusions reached too early, or corrective work that addresses an effect but not the underlying risk. Verification should include a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. The numeric blueprint emphasis remains in its structured field; this narrative adds no inferred percentage or item estimate.
Preparation tips
Study “AI Auditing Tools And Techniques” through contrasting cases. Start with this exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Build the weaker case around insufficient evidence, confused responsibility, premature judgment, or action taken against a secondary issue rather than the source of risk. Separate the two results using traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Use evidence from “AI Operations” as an input to the final review.
