- Maps to ISACA Domain 1, AI Governance and Risk (33%).
- Explain AI and machine learning models, their inputs and outputs, and what an auditor needs to know about how they are built.
- Evaluate AI solutions to advise on impact, opportunities, and risk to the organization.
- Check that system and business requirements for AI solutions line up with enterprise architecture.
- Assess the impact of AI solutions on system interactions, the environment, and people.
Advanced in AI Audit™ (AAIA™) Certification Training Course
Learn how to audit AI systems and how to use AI in your own audit work. Accumentum prepares active CISA holders and other qualified auditors for ISACA's Advanced in AI Audit (AAIA) exam.
Learn to audit AI systems and to use AI in your own audit work.
The Advanced in AI Audit™ (AAIA™) Certification Training Course with Accumentum prepares experienced IT auditors and advisors to audit AI governance, AI operations, and AI controls. ISACA launched AAIA on May 19, 2025, and describes it as the first advanced audit-specific artificial intelligence certification designed for experienced auditors.
AAIA is an advanced credential with a prerequisite. Any active CISA holder qualifies. Holders of certain other active designations also qualify if they work in an IT audit or IT advisory role, including CIA, US CPA, ACCA, and Canadian, Australian, Japanese, and Hong Kong CPA designations. This course is written for that audience.
The ten modules follow ISACA's three AAIA exam domains: AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). AI Operations is the largest domain, so it gets four modules covering data management, the AI solution life cycle, change management, supervision of AI outputs, testing, threats, and incident response.
Sessions stay close to audit work. You plan and scope an AI audit, decide what evidence proves a control works, test data and model inputs, and write findings a board or audit committee can act on. The course also covers how AI tools can help with audit planning, execution, and reporting.
Build AAIA exam readiness and practical AI audit skills.
Audit AI governance and risk
Evaluate AI policies, program structure, ownership of AI risk, privacy and data governance, and alignment with laws, regulations, standards, and ethics.
Assess AI operations
Review data management, the AI solution life cycle, change and configuration management, supervision of AI outputs, testing, threats, and incident response for AI.
Plan and perform AI audits
Design AI audits, choose testing and sampling methods, collect evidence, check data quality, and report results on AI systems.
Use AI in the audit
Weigh the impacts, opportunities, and risk of AI in the audit process, and use AI solutions to support audit planning, execution, and reporting.
Who Should Attend
- IT auditors and audit managers who hold an active CISA and are asked to audit AI systems.
- Internal auditors and accountants with a qualifying designation, such as CIA or CPA, who work in an IT audit or IT advisory role.
- Risk and compliance advisors who assess, implement, maintain, or audit AI systems.
- Audit leaders building an AI audit plan or updating their audit methodology for AI.
Prerequisites
- ISACA requires AAIA candidates to hold an active CISA or an active designation from ISACA's qualified list. Holders of designations other than CISA qualify when they work in an IT audit or IT advisory role. Confirm your eligibility on isaca.org before you register.
- The course assumes working knowledge of IT audit practice at the CISA level, including audit planning, controls testing, evidence, and reporting.
- Basic familiarity with AI concepts such as models, training data, and model outputs helps, and the first module covers them for audit purposes.
- Training does not replace ISACA's certification requirements. After passing the exam you still apply to ISACA and follow its Code of Professional Ethics and CPE policy.
The AAIA training course covers all three ISACA domains across ten modules.
Every module opens with the ISACA domain it maps to. AI Operations is the largest domain, so it gets four modules.
AI Models, Considerations, and Requirements
AI Governance and Program Management
AI Risk Management
Privacy, Data Governance, Ethics, and Standards
Data Management and the AI Solution Life Cycle
Change Management and Supervision of AI Solutions
Testing Techniques for AI Solutions
AI Threats, Vulnerabilities, and Incident Response
AI Audit Planning, Testing, and Evidence
Audit Data Analytics, Reporting, and AI-Enabled Audit
- Maps to ISACA Domain 1, AI Governance and Risk (33%).
- Review the organization's AI policies and procedures, including compliance with legal and regulatory requirements.
- Confirm that the organization has defined ownership of AI-related risk, controls, procedures, decisions, and standards.
- Test whether awareness programs match AI-related policies and procedures.
- Analyze the impact of AI on the workforce so you can advise on training and education.
- Maps to ISACA Domain 1, AI Governance and Risk (33%).
- Assess the role and impact of AI decision-making systems on the organization and its stakeholders.
- Review vendor and supply chain management programs specific to AI solutions.
- Check algorithms and models against business objectives, policies, and procedures.
- Look at how AI metrics such as KPIs and KRIs are monitored and reported.
- Maps to ISACA Domain 1, AI Governance and Risk (33%).
- Review the organization's privacy program and data governance program as they apply to AI.
- Assess data input requirements for AI models, including data appropriateness, bias, and privacy.
- Relate AI governance to leading practices, ethics, regulations, and standards for AI.
- Identify where audit findings on AI ethics and regulatory compliance should be escalated.
- Maps to ISACA Domain 2, AI Operations (46%).
- Audit data management specific to AI, from data sourcing and preparation to retention.
- Assess the AI solution life cycle, including design, development, deployment, monitoring, and decommissioning, for compliance and risk.
- Trace inputs and outputs at each life cycle stage.
- Review AI solution development methodologies used by the organization.
- Maps to ISACA Domain 2, AI Operations (46%).
- Evaluate the organization's change management program specific to AI.
- Review the configuration management program and the identity and access management program specific to AI.
- Examine how the organization supervises AI solutions, including outputs, impacts, and decisions.
- Test the design and effectiveness of controls specific to AI.
- Maps to ISACA Domain 2, AI Operations (46%).
- Review testing techniques used for AI solutions before and after deployment.
- Evaluate whether testing covers accuracy, bias, and the data used to train and run the model.
- Decide what test evidence an auditor should request and how to judge it.
- Link testing results back to AI control design and the organization's risk appetite.
- Maps to ISACA Domain 2, AI Operations (46%).
- Identify threats and vulnerabilities specific to AI.
- Assess the organization's threat and vulnerability management programs specific to AI.
- Review problem and incident management programs specific to AI.
- Walk through incident response management for AI, from detection through reporting and recovery.
- Maps to ISACA Domain 3, AI Auditing Tools and Techniques (21%).
- Plan and design an audit of an AI system or AI program, including scope and objectives.
- Choose audit testing and sampling methods that fit AI systems.
- Collect audit evidence with techniques suited to AI, and judge whether it is sufficient.
- Evaluate the impacts, opportunities, and risk of bringing AI solutions into the audit process.
- Maps to ISACA Domain 3, AI Auditing Tools and Techniques (21%).
- Check audit data quality and apply data analytics in AI audits.
- Write AI audit outputs and reports that give stakeholders clear findings and recommendations.
- Use AI solutions to support audit planning, execution, and reporting.
- Review the controls you need around AI tools used inside the audit function.
Designed for IT auditors preparing for the ISACA AAIA exam.
Instructor-Led Sessions
Live virtual sessions focused on auditing AI governance, AI operations, and AI controls.
Audit Scenarios
Case discussions that ask what an auditor should test, what evidence to request, and how to report the finding.
Domain-Mapped Materials
Study materials organized by ISACA's three AAIA domains and their published weights.
Exam Readiness Review
Review of the exam structure, domain coverage, and ISACA-style questions with one best answer before you schedule.
About the ISACA AAIA exam
AAIA Exam Readiness
Accumentum's AAIA course prepares active CISA holders and other qualified auditors to plan, test, and report on AI across all three ISACA domains.

ISACA launched the Advanced in AI Audit (AAIA) certification on May 19, 2025, and describes it as the first advanced audit-specific artificial intelligence certification designed for experienced auditors.
The AAIA exam has 90 multiple choice questions and a time limit of 2.5 hours (150 minutes). Every question has a stem and four answer options, with one best answer. Domains are AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%).
ISACA reports scores on a scale of 200 to 800, and you need 450 or higher to pass. The exam is offered in English, Simplified Chinese, and Spanish.
Candidates must hold an active CISA or an active designation from ISACA's qualified list. Exams are computer-based and taken at PSI testing centers or through remote proctoring. Remote proctoring is not available to residents of India, Mainland China, and Hong Kong. After you register, you have six months to take the exam.
To become certified you must hold a qualifying designation, pass the exam, apply within five years of passing, pay ISACA's application processing fee, and follow ISACA's Code of Professional Ethics and CPE policy. Once certified, you must earn and report 10 hours of CPE in artificial intelligence each year, starting the calendar year after certification.
Accumentum is an independent training provider. ISACA sets and changes exam rules, fees, and policies, so confirm current details on isaca.org before you register.
Questions we hear about AAIA eligibility, the exam, and what ISACA expects after you pass.
Advanced in AI Audit (AAIA) is an ISACA certification for IT audit professionals who audit AI and use AI in audit work. ISACA launched it on May 19, 2025, and describes it as the first advanced audit-specific artificial intelligence certification designed for experienced auditors.
Anyone with an active CISA qualifies. ISACA also accepts an active CIA, US CPA, ACCA or FCCA, CPA Australia CPA or FCPA, Japanese CPA, Canadian CPA, ICAEW ACA or FCA, ANAN CNA, CA ANZ CA or FCA, or HKICPA CPA or FCPA, for holders who work in an IT audit or IT advisory role. Check isaca.org for the current list.
Three domains: AI Governance and Risk (33%), AI Operations (46%), and AI Auditing Tools and Techniques (21%). The ten Accumentum modules each map to one of these domains.
ISACA lists 90 multiple choice questions and 2.5 hours (150 minutes) to complete them. Each question has one best answer out of four options.
Scores are reported on a scale of 200 to 800, and a score of 450 or higher passes. Domain results are for information only and are not used to calculate your score.
The exam is computer-based and taken at a PSI testing center or through remote proctoring. Remote proctoring is not available to residents of India, Mainland China, and Hong Kong. You have six months from registration to take the exam. ISACA offers it in English, Simplified Chinese, and Spanish.
You apply to ISACA for certification within five years of passing. ISACA requires an active qualifying designation, payment of its application processing fee, and agreement to its Code of Professional Ethics and CPE policy.
ISACA requires 10 hours of CPE in artificial intelligence each year, starting the calendar year after you are certified. If those hours meet the rules for other ISACA certifications you hold, they may count toward those too.
AAIA is ISACA's AI audit credential and requires an active CISA or another qualifying audit or accounting designation. AAISM is ISACA's AI security management credential and requires an active CISM or CISSP. Accumentum offers training for both.
No. You earn AAIA by passing the ISACA exam and meeting ISACA's certification requirements. Accumentum is an independent training provider, and ISACA sets the exam rules, fees, and policies.
Enroll in the ISACA AAIA Certification Training Course with Accumentum.
Enroll in the Advanced in AI Audit™ (AAIA™) Certification Training Course with Accumentum to prepare for ISACA's AI audit exam.
You will work through all three AAIA domains with an instructor and practice the planning, testing, and reporting decisions auditors make when AI is in scope.
Before you enroll, confirm that you hold an active CISA or another designation on ISACA's qualified list, since ISACA requires one to sit the exam. For course dates and enrollment help, visit Accumentum's registration page.
Bring AI into your audit plan with AAIA training.
Confirm your ISACA eligibility first, then register or contact us with questions about the course.