ISACA · AAIA
Validates the ability to audit AI systems across three domains: AI governance and risk management, AI operations and lifecycle risks, and AI auditing tools and techniques, covering AI model assessment, algorithm development oversight, and AI-enhanced audit processes.
Practice Questions
600
≈ 4 practice exams
Duration
150 minutes
Passing Score
450/800
Difficulty
AssociateLast Updated
Feb 2026
Use this AAIA practice exam to prepare for ISACA Advanced in AI Audit (AAIA) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA AAIA, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Advanced in AI Audit™ (AAIA™) is the world's first advanced, audit-specific certification focused on artificial intelligence, launched by ISACA in 2025. It validates that experienced audit and assurance professionals possess the specialized knowledge to evaluate AI systems across three core disciplines: AI governance and risk management, AI operations and lifecycle management, and AI auditing tools and techniques. The credential demonstrates competency in assessing AI model integrity, overseeing algorithm development, applying data governance principles, and leveraging AI-enhanced methodologies to strengthen audit processes.
Designed for professionals who already hold a foundational audit or accounting credential, the AAIA goes beyond general AI literacy to test applied judgment in real-world scenarios—covering ethical AI frameworks, regulatory compliance, threat identification, incident response, and the use of AI-powered analytics within audit engagements. As organizations accelerate AI adoption, the certification equips auditors to serve as credible advisors on AI-related risk, control design, and assurance reporting.
The AAIA is intended for experienced IT auditors, internal auditors, and assurance advisors who already hold a qualifying credential such as the CISA, CIA, US CPA, ACCA/FCCA, Canadian CPA, CPA Australia, or Japanese CPA (JICPA). It is best suited for professionals with several years of audit or advisory experience who are now encountering AI systems in the scope of their work and need a recognized credential to formalize that expertise.
Beyond traditional IT audit roles, the certification is also relevant to risk managers, compliance officers, technology consultants, and governance professionals in industries such as financial services, healthcare, and government—anywhere that AI deployments require independent assurance and structured oversight.
Candidates must hold an active, in-good-standing qualifying credential from an approved list: CISA (ISACA), CIA (IIA), US CPA (AICPA), ACCA or FCCA (Association of Chartered Certified Accountants), Canadian CPA, CPA Australia (CPA or FCPA), or Japanese CPA (JICPA). There are no formal work-experience requirements beyond holding one of these designations, but the exam content presupposes familiarity with audit methodology, risk assessment frameworks, and IT controls.
ISACA recommends that candidates have practical experience conducting IT or operational audits before attempting the AAIA, as the questions are scenario-based and test applied judgment rather than rote knowledge. Candidates do not need a prior AI background, though familiarity with AI concepts, machine learning lifecycles, and data governance will significantly aid preparation.
The AAIA exam consists of 90 multiple-choice questions, each presenting four answer options. Candidates have 150 minutes to complete the exam. Questions are entirely scenario-based, requiring candidates to analyze situations and select the best course of action rather than recall definitions. There are no unscored pretest items disclosed publicly.
The exam is delivered via computer at authorized PSI testing centers worldwide or through live remote proctoring. Candidates residing in India, Mainland China, or Hong Kong must test at a PSI center and are not eligible for remote proctoring. Scoring uses a scaled system ranging from 200 to 800; the passing score is 450. Preliminary pass/fail status is displayed on screen immediately after completion, and official scaled scores are emailed and posted to the candidate's ISACA account within 10 business days. Candidates who do not pass may retake up to four times within a 12-month period, with mandatory waiting periods of 30 days after the first failure and 90 days after subsequent failures.
The AAIA positions holders at the intersection of two high-demand disciplines—AI governance and professional audit—at a time when enterprises are rapidly scaling AI deployments while regulators worldwide (EU AI Act, SEC guidance, NIST AI RMF) are tightening accountability requirements. Certified professionals report salary premiums averaging 15–20% over non-certified peers in comparable audit roles, and the credential opens pathways to specialized positions including AI Audit Lead, Chief Risk Officer, AI Compliance Manager, and technology assurance advisory roles.
Because the AAIA is the only advanced, audit-specific AI credential in the market, it carries early-mover advantage: organizations in financial services, healthcare, government, and technology are actively seeking auditors who can independently assess AI risk without relying solely on data science teams. The certification is globally recognized and maintains the ISACA brand's credibility with audit committees and regulators, making it a strong differentiator when competing for senior internal audit, consulting, or advisory mandates involving AI systems.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An auditor is evaluating data lineage documentation for an AI system. The organization tracks the origin of training data and maintains version snapshots, but does not document the specific transformation steps applied during feature engineering or the relationships between derived features. Which critical data lineage components are missing? (Select two!)
Multiple correct answersExplanation
Complete data lineage requires transformation history documenting all processing steps including feature engineering, and dependency mapping showing relationships between original and derived features. The scenario states the organization has source tracking and version control but lacks transformation documentation and dependency relationships. Access audit trails are important for security but are not described as missing in the scenario.
2. An organization implements a machine learning pipeline with separate training and inference workflows. The data science team reports that models perform with 94 percent accuracy during training validation but only 78 percent accuracy in production. An auditor investigates and discovers that training data uses batch processing from a data warehouse updated weekly, while production inference uses real-time API data from operational systems. Which data quality dimension is most likely causing the performance gap? (Select one!)
Explanation
Consistency measures uniformity of data across different sources, formats, and systems. When training data comes from a weekly-updated data warehouse with batch processing transformations, and production data comes from real-time operational APIs, inconsistencies arise in formats, encoding, transformations, and semantic interpretations. These inconsistencies cause models to encounter production data that differs systematically from training patterns, degrading performance. Accuracy addresses correctness of individual values but does not explain cross-source discrepancies. Completeness focuses on missing values which would manifest differently. Timeliness addresses currency but the issue is source heterogeneity rather than staleness, as real-time production data is actually more current than weekly warehouse data.
3. A government agency conducting procurement evaluation receives SOC 2 Type II reports from three AI vendor finalists. Vendor A provides a standard SOC 2 report covering Security and Availability. Vendor B provides SOC 2 covering Security, Availability, and Processing Integrity with AI-specific control descriptions. Vendor C provides SOC 2 covering all five Trust Services Criteria plus additional AI-specific control testing. From a risk-based AI audit perspective, which vendor demonstrates the most comprehensive third-party assurance? (Select one!)
Explanation
Vendor C provides the most comprehensive assurance by covering all five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy) plus AI-specific control testing. For AI systems handling sensitive data, Privacy and Confidentiality are critical alongside Processing Integrity for output accuracy. AI-specific control descriptions and testing demonstrate that the auditor evaluated controls unique to AI systems rather than only general IT controls. Vendor A's limited scope misses critical AI-relevant criteria. Vendor B improves on Vendor A but still omits Privacy and Confidentiality. SOC 2 reports are not equivalent when criteria scope differs significantly.
4. An auditor evaluates NIST AI RMF MAP 5 impact characterization for a facial recognition system used in building access control. The risk assessment documents technical failure modes and likelihood estimates but does not include stakeholder engagement activities, impact magnitude assessments for affected individuals, or evaluation of disproportionate impacts on demographic subgroups. Which MAP 5 element is deficient? (Select one!)
Explanation
NIST AI RMF MAP 5 requires impact characterization to assess both likelihood and magnitude of impacts, engage stakeholders to understand consequences, and evaluate disproportionate impacts on different populations. The scenario shows technical risk assessment without stakeholder engagement or demographic impact analysis, which is insufficient for MAP 5. Facial recognition for access control can disproportionately impact certain demographic groups due to documented accuracy disparities across skin tones, genders, and ages. MAP 5 explicitly requires understanding impacts on affected individuals and communities, not just technical failure probabilities. Stakeholder engagement appears in both MAP and GOVERN functions with different emphases. While EU AI Act has specific demographic assessment requirements, NIST AI RMF independently requires evaluating disproportionate impacts as part of trustworthy AI risk management. Complete MAP 5 implementation requires qualitative stakeholder input alongside quantitative technical assessments.
5. An auditor tests fairness for a medical treatment recommendation system using multiple fairness metrics across racial demographic groups. Analysis reveals the system achieves demographic parity with equal recommendation rates across groups and achieves calibration with predicted success rates matching actual outcomes within each group. However, the system fails equal opportunity with different true positive rates across groups. The model developer argues calibration is most important for medical treatment because predicted success probabilities must be accurate. Which auditor response is most appropriate? (Select one!)
Explanation
The impossibility theorem for fairness metrics establishes that calibration, equal opportunity, and demographic parity cannot be simultaneously satisfied unless base rates are equal across groups or the classifier is perfect. The scenario demonstrates this impossibility with achieved calibration and demographic parity but failed equal opportunity. The auditor must recognize this mathematical constraint and facilitate organizational discussion about fairness priority tradeoffs rather than demanding impossible simultaneous satisfaction. Medical treatment contexts create tensions between calibration accuracy for individual decision-making and equal opportunity to ensure groups receive equal benefit from effective treatments. Simply accepting calibration ignores equal opportunity concerns that some groups may receive fewer beneficial recommendations. Accepting demographic parity alone does not address outcome quality. The appropriate response acknowledges the impossibility result and guides stakeholders through values-based tradeoff decisions about which fairness definition aligns with medical ethics and treatment goals.
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
Artificial Intelligence Fundamentals Certificate
AI-Fundamentals · 600 questions
$17.99
One-time access to this exam