ISACA · AAIA
Validates the ability to audit AI systems across three domains: AI governance and risk management, AI operations and lifecycle risks, and AI auditing tools and techniques, covering AI model assessment, algorithm development oversight, and AI-enhanced audit processes.
Practice Questions
600
≈ 4 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Feb 2026
Use this AAIA practice exam to prepare for ISACA Advanced in AI Audit (AAIA) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA AAIA, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Advanced in AI Audit™ (AAIA™) is the world's first advanced, audit-specific certification focused on artificial intelligence, launched by ISACA in 2025. It validates that experienced audit and assurance professionals possess the specialized knowledge to evaluate AI systems across three core disciplines: AI governance and risk management, AI operations and lifecycle management, and AI auditing tools and techniques. The credential demonstrates competency in assessing AI model integrity, overseeing algorithm development, applying data governance principles, and leveraging AI-enhanced methodologies to strengthen audit processes.
Designed for professionals who already hold a foundational audit or accounting credential, the AAIA goes beyond general AI literacy to test applied judgment in real-world scenarios—covering ethical AI frameworks, regulatory compliance, threat identification, incident response, and the use of AI-powered analytics within audit engagements. As organizations accelerate AI adoption, the certification equips auditors to serve as credible advisors on AI-related risk, control design, and assurance reporting.
The AAIA is intended for experienced IT auditors, internal auditors, and assurance advisors who already hold a qualifying credential such as the CISA, CIA, US CPA, ACCA/FCCA, Canadian CPA, CPA Australia, or Japanese CPA (JICPA). It is best suited for professionals with several years of audit or advisory experience who are now encountering AI systems in the scope of their work and need a recognized credential to formalize that expertise.
Beyond traditional IT audit roles, the certification is also relevant to risk managers, compliance officers, technology consultants, and governance professionals in industries such as financial services, healthcare, and government—anywhere that AI deployments require independent assurance and structured oversight.
Candidates must hold an active, in-good-standing qualifying credential from an approved list: CISA (ISACA), CIA (IIA), US CPA (AICPA), ACCA or FCCA (Association of Chartered Certified Accountants), Canadian CPA, CPA Australia (CPA or FCPA), or Japanese CPA (JICPA). There are no formal work-experience requirements beyond holding one of these designations, but the exam content presupposes familiarity with audit methodology, risk assessment frameworks, and IT controls.
ISACA recommends that candidates have practical experience conducting IT or operational audits before attempting the AAIA, as the questions are scenario-based and test applied judgment rather than rote knowledge. Candidates do not need a prior AI background, though familiarity with AI concepts, machine learning lifecycles, and data governance will significantly aid preparation.
The AAIA exam consists of 90 multiple-choice questions, each presenting four answer options. Candidates have 150 minutes to complete the exam. Questions are entirely scenario-based, requiring candidates to analyze situations and select the best course of action rather than recall definitions. There are no unscored pretest items disclosed publicly.
The exam is delivered via computer at authorized PSI testing centers worldwide or through live remote proctoring. Candidates residing in India, Mainland China, or Hong Kong must test at a PSI center and are not eligible for remote proctoring. Scoring uses a scaled system ranging from 200 to 800; the passing score is 450. Preliminary pass/fail status is displayed on screen immediately after completion, and official scaled scores are emailed and posted to the candidate's ISACA account within 10 business days. Candidates who do not pass may retake up to four times within a 12-month period, with mandatory waiting periods of 30 days after the first failure and 90 days after subsequent failures.
The AAIA positions holders at the intersection of two high-demand disciplines—AI governance and professional audit—at a time when enterprises are rapidly scaling AI deployments while regulators worldwide (EU AI Act, SEC guidance, NIST AI RMF) are tightening accountability requirements. Certified professionals report salary premiums averaging 15–20% over non-certified peers in comparable audit roles, and the credential opens pathways to specialized positions including AI Audit Lead, Chief Risk Officer, AI Compliance Manager, and technology assurance advisory roles.
Because the AAIA is the only advanced, audit-specific AI credential in the market, it carries early-mover advantage: organizations in financial services, healthcare, government, and technology are actively seeking auditors who can independently assess AI risk without relying solely on data science teams. The certification is globally recognized and maintains the ISACA brand's credibility with audit committees and regulators, making it a strong differentiator when competing for senior internal audit, consulting, or advisory mandates involving AI systems.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A multinational corporation implements AI systems across EU and non-EU jurisdictions. The Chief Audit Executive asks which governance framework provides the only certifiable AI management system standard. Which framework should the auditor recommend? (Select one!)
Explanation
ISO/IEC 42001:2023 is the first and only certifiable international AI management system standard, using a Plan-Do-Check-Act structure with Annex A reference controls. Organizations can obtain third-party certification demonstrating conformance. NIST AI RMF is a voluntary framework providing guidance but is not certifiable. EU AI Act is binding regulation requiring compliance but does not offer certification. IEEE 7000 series provides ethical standards and guidelines but individual standards are not management system certifications.
2. An auditor evaluates deployment patterns for a fraud detection system requiring sub-100ms response time with zero downtime during updates. Which deployment pattern should the auditor recommend? (Select one!)
Explanation
Blue/Green deployment maintains two complete environments allowing instant switching between versions, achieving zero downtime during updates while supporting real-time inference with sub-100ms latency requirements. One environment serves production traffic while the other is updated and validated. Batch inference pre-computes predictions on a schedule and cannot meet sub-100ms real-time requirements. Shadow mode runs models in parallel without serving predictions, used for pre-production validation not production deployment. Canary deployment gradually shifts traffic but introduces risk during the rollout period and adds complexity for systems requiring instant rollback.
3. A technology company implements NIST AI RMF for a conversational AI system. During the MEASURE function, the team evaluates trustworthy characteristics using quantitative metrics. Which NIST AI RMF characteristic serves as foundational to all other characteristics and must be validated first? (Select one!)
Explanation
Valid and Reliable is explicitly identified as the foundational characteristic in NIST AI RMF because a system must first produce accurate and consistent results before other characteristics can be meaningfully evaluated. An invalid or unreliable system cannot be fairly assessed for safety, fairness, or other properties. Accountable and Transparent relates to all other characteristics but is not foundational. Fairness and Privacy-Enhanced are important but depend on the system being valid and reliable first.
4. An auditor reviews COBIT for AI implementation mapping AI governance activities to COBIT domains. The organization has established AI strategic planning and policy development processes. Which COBIT domain should these governance activities be mapped to? (Select one!)
Explanation
COBIT's Align, Plan, and Organize domain covers strategic AI planning and policy development activities that translate governance direction into actionable plans and organizational structures. APO focuses on planning and organizing IT resources including AI capabilities. EDM operates at the highest governance level focusing on evaluation and direction rather than planning execution. BAI addresses AI development and deployment implementation rather than strategic planning. DSS covers AI operations and service delivery rather than strategic planning activities.
5. A logistics company implements real-time route optimization AI in critical infrastructure. Under the EU AI Act risk classification system, how should this system be categorized and what is the primary compliance requirement? (Select one!)
Explanation
AI systems used in critical infrastructure management are explicitly classified as high-risk under the EU AI Act Annex III, requiring strict compliance including conformity assessment before deployment, registration in the EU database, risk management systems, data governance, technical documentation, record-keeping, transparency, and human oversight. Unacceptable risk applies to prohibited practices like social scoring and manipulative AI. Limited risk applies to systems like chatbots requiring only transparency. Minimal risk applies to systems like spam filters with no specific requirements.
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
$17.99
One-time access to this exam