ISACA · AAIA
Validates the ability to audit AI systems across three domains: AI governance and risk management, AI operations and lifecycle risks, and AI auditing tools and techniques, covering AI model assessment, algorithm development oversight, and AI-enhanced audit processes.
Practice Questions
600
≈ 4 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Feb 2026
Use this AAIA practice exam to prepare for ISACA Advanced in AI Audit (AAIA) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA AAIA, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Advanced in AI Audit™ (AAIA™) is the world's first advanced, audit-specific certification focused on artificial intelligence, launched by ISACA in 2025. It validates that experienced audit and assurance professionals possess the specialized knowledge to evaluate AI systems across three core disciplines: AI governance and risk management, AI operations and lifecycle management, and AI auditing tools and techniques. The credential demonstrates competency in assessing AI model integrity, overseeing algorithm development, applying data governance principles, and leveraging AI-enhanced methodologies to strengthen audit processes.
Designed for professionals who already hold a foundational audit or accounting credential, the AAIA goes beyond general AI literacy to test applied judgment in real-world scenarios—covering ethical AI frameworks, regulatory compliance, threat identification, incident response, and the use of AI-powered analytics within audit engagements. As organizations accelerate AI adoption, the certification equips auditors to serve as credible advisors on AI-related risk, control design, and assurance reporting.
The AAIA is intended for experienced IT auditors, internal auditors, and assurance advisors who already hold a qualifying credential such as the CISA, CIA, US CPA, ACCA/FCCA, Canadian CPA, CPA Australia, or Japanese CPA (JICPA). It is best suited for professionals with several years of audit or advisory experience who are now encountering AI systems in the scope of their work and need a recognized credential to formalize that expertise.
Beyond traditional IT audit roles, the certification is also relevant to risk managers, compliance officers, technology consultants, and governance professionals in industries such as financial services, healthcare, and government—anywhere that AI deployments require independent assurance and structured oversight.
Candidates must hold an active, in-good-standing qualifying credential from an approved list: CISA (ISACA), CIA (IIA), US CPA (AICPA), ACCA or FCCA (Association of Chartered Certified Accountants), Canadian CPA, CPA Australia (CPA or FCPA), or Japanese CPA (JICPA). There are no formal work-experience requirements beyond holding one of these designations, but the exam content presupposes familiarity with audit methodology, risk assessment frameworks, and IT controls.
ISACA recommends that candidates have practical experience conducting IT or operational audits before attempting the AAIA, as the questions are scenario-based and test applied judgment rather than rote knowledge. Candidates do not need a prior AI background, though familiarity with AI concepts, machine learning lifecycles, and data governance will significantly aid preparation.
The AAIA exam consists of 90 multiple-choice questions, each presenting four answer options. Candidates have 150 minutes to complete the exam. Questions are entirely scenario-based, requiring candidates to analyze situations and select the best course of action rather than recall definitions. There are no unscored pretest items disclosed publicly.
The exam is delivered via computer at authorized PSI testing centers worldwide or through live remote proctoring. Candidates residing in India, Mainland China, or Hong Kong must test at a PSI center and are not eligible for remote proctoring. Scoring uses a scaled system ranging from 200 to 800; the passing score is 450. Preliminary pass/fail status is displayed on screen immediately after completion, and official scaled scores are emailed and posted to the candidate's ISACA account within 10 business days. Candidates who do not pass may retake up to four times within a 12-month period, with mandatory waiting periods of 30 days after the first failure and 90 days after subsequent failures.
The AAIA positions holders at the intersection of two high-demand disciplines—AI governance and professional audit—at a time when enterprises are rapidly scaling AI deployments while regulators worldwide (EU AI Act, SEC guidance, NIST AI RMF) are tightening accountability requirements. Certified professionals report salary premiums averaging 15–20% over non-certified peers in comparable audit roles, and the credential opens pathways to specialized positions including AI Audit Lead, Chief Risk Officer, AI Compliance Manager, and technology assurance advisory roles.
Because the AAIA is the only advanced, audit-specific AI credential in the market, it carries early-mover advantage: organizations in financial services, healthcare, government, and technology are actively seeking auditors who can independently assess AI risk without relying solely on data science teams. The certification is globally recognized and maintains the ISACA brand's credibility with audit committees and regulators, making it a strong differentiator when competing for senior internal audit, consulting, or advisory mandates involving AI systems.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An auditor assesses model extraction attack defenses for a proprietary sentiment analysis API serving external customers. The provider implements rate limiting of 100 queries per hour per API key and charges per-query fees. Security testing reveals an attacker successfully reconstructed 85 percent model accuracy using 50000 queries over three weeks. Which two defensive measures would most effectively prevent model extraction? (Select two!)
Multiple correct answersExplanation
Query response perturbation disrupts the attacker's ability to accurately reconstruct model parameters by introducing uncertainty in outputs, making extraction unreliable. Ensemble models with periodic rotation fundamentally change the underlying model architecture, invalidating extraction attempts and requiring attackers to restart. Reducing rate limits merely slows extraction without preventing it, as demonstrated by the three-week attack. Watermarking detects extraction after it occurs but does not prevent it. Multi-factor authentication addresses access control but does not prevent extraction by authenticated users who may be malicious or compromised.
2. An auditor assesses IEEE 7003-2024 bias profile implementation for a credit scoring model in production for 11 months. The bias profile was created during development and documents initial data sources, risk assessments, and mitigation strategies. The profile has not been updated since deployment despite three minor model updates and one data source change. What is the primary deficiency? (Select one!)
Explanation
IEEE 7003-2024 emphasizes that the bias profile must be a living document updated throughout the AI lifecycle, including post-deployment. The standard specifically requires updating the bias profile with monitoring results and revisiting risk assessments whenever the system or its environment changes. Model updates and data source changes clearly constitute system changes requiring bias profile updates. The bias profile should be updated incrementally rather than recreated entirely, maintaining continuity and traceability. The standard applies throughout the lifecycle including post-deployment, not just development phases. There are no specific percentage thresholds for triggering updates in the standard.
3. An auditor reviews Model Cards and Data Sheets for a facial recognition system deployed in a retail environment. The Model Card documents overall accuracy of 94% but provides no demographic breakdowns. The Data Sheet indicates training data was collected from internet sources with unknown demographic composition and no consent documentation. The system is deployed in California and European Union locations. Which two compliance risks are most critical? (Select two!)
Multiple correct answersExplanation
EU AI Act Article 5.1(e) explicitly prohibits untargeted scraping of facial images from internet or CCTV to create facial recognition databases - this is one of the banned AI practices with potential €35M fines. Training data from internet sources without consent likely violates this prohibition. GDPR Article 35 mandates Data Protection Impact Assessments for high-risk processing including biometric data; facial recognition in retail is high-risk requiring documented DPIA. IEEE 7003 provides guidance but is not legally binding regulation creating compliance risk. CCPA has biometric provisions but they are less stringent than EU AI Act prohibition. ISO 42001 is voluntary certification, not regulatory compliance risk at the same criticality level.
4. A government agency implements ISO/IEC 42001:2023 for AI management systems. During Clause 9 performance evaluation, the internal audit team discovers that AI system monitoring occurs monthly, but formal management reviews of the AI management system happen only once every 18 months. The CISO argues this frequency is sufficient given limited AI system changes. What should the auditor conclude? (Select one!)
Explanation
ISO 42001 Clause 9.3 requires management reviews to be conducted at planned intervals to ensure continuing suitability, adequacy, and effectiveness of the AI management system. While the standard allows organizations to determine appropriate intervals based on their context, 18-month gaps are excessive for ensuring the management system remains effective given the rapid evolution of AI technology and risks. Management reviews are distinct from operational monitoring and assess the management system itself, not just AI system performance. The reviews should be more frequent than every 18 months to maintain proper governance oversight.
5. An auditor evaluates deployment patterns for a personalized medicine recommendation system requiring patient-specific treatment suggestions within 24 hours of diagnosis. The system processes patient genomic data, medical history, and current medications to recommend therapies. Recommendations do not require real-time response but must reflect the latest clinical research. Patients receive recommendations once per diagnosis with periodic updates. Which deployment pattern best balances requirements and resource efficiency? (Select one!)
Explanation
Batch inference optimally matches the use case requirements and resource efficiency goals. The 24-hour response timeframe eliminates the need for real-time API latency, while scheduled batch processing can efficiently handle diagnosed patients in daily or more frequent batches. Batch processing enables incorporation of latest clinical research through daily model updates or data refreshes before inference runs. Pre-computed recommendations can be reviewed and delivered within the required timeframe. Real-time inference via API endpoints adds unnecessary infrastructure costs and complexity when 24-hour latency is acceptable. Edge deployment is inappropriate as the system requires access to comprehensive clinical research databases and genomic analysis capabilities unsuitable for edge devices. Canary deployment is a rollout strategy rather than an inference pattern and does not address the fundamental question of batch versus real-time inference architecture.
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
$17.99
One-time access to this exam