Auditing artificial intelligence is one of those phrases that sounds impressive and falls apart under questioning. Ask most internal audit functions what testing an AI system involves and you will get either a control checklist borrowed from software development or an admission that they have not worked it out. The AAIA is ISACA's answer, and the reason I rate it reasonably well is the domain weighting, which shows somebody thought properly about where the difficulty lies. Governance and risk takes 33 percent, auditing tools and techniques takes 21 percent, and AI operations takes 46 percent.
That operations block being nearly half the exam is the important decision. It means the credential is not simply asking whether a policy exists and whether someone signed it, which is where a lazier version of this exam would have landed. It is asking about how these systems actually run: data lineage and quality, model lifecycle and versioning, monitoring and drift, human oversight in practice rather than on paper, and how you obtain evidence about a system whose behaviour is statistical. Getting audit evidence out of a probabilistic system is the genuinely hard problem here and it deserves the weighting.
The prerequisite structure is generous in scope and strict in principle. CISA holders qualify outright, and so do a range of accounting and internal audit credentials including CIA, US CPA, ACCA, and various national chartered accountant designations, provided the work has an IT audit or advisory flavour. As with the AAISM, this gating is what makes the credential worth anything. Nobody is going to hold AAIA who could not already plan and execute an audit, so the credential is measuring the AI specific increment rather than pretending to certify auditing from scratch.
You also have to keep the underlying designation active to stay certified, which is a sensible way of preventing the thing from becoming a standalone badge detached from any real qualification. On practicalities, the exam is 90 questions in 150 minutes, which works out to about a minute and forty seconds each. That is tight for scenario questions and the operations domain is where I would expect most candidates to lose time, because those questions require you to reason about a described system rather than recall a definition. Costs are $459 for members and $599 for non members with a $50 application fee on passing, and ISACA's official review materials are an additional and not insignificant expense.
There is a five year window to apply for certification after passing and a six month eligibility period from registration to sit the exam, both of which are administratively fine but worth diarising. My honest concern with the whole category is that AI audit as a discipline is still being invented, and a certification is a snapshot of a consensus that has not fully formed. Some of what this exam tests will look naive in three years, in the same way early cloud audit guidance now reads as quaint. Against that, somebody has to go first, and audit functions cannot wait for the field to settle before they start covering AI systems in their plans.
A structured, validated body of knowledge produced by the organisation that already defines IT audit practice is a much better starting point than each firm improvising its own approach, which is what has been happening. Who should do it? A fairly small group: IT auditors with AI in scope, internal audit managers building the methodology for their function, assurance and second line risk professionals, and consultants who need to be credible when a client asks how they would audit a model. For those people this is close to essential reading regardless of whether the exam itself ever gets recognised, because the content outline is a decent map of the problem. For everyone else, including the many people who arrive at AI certifications hoping for a career change, this is the wrong door and the eligibility rules will tell you so before you get far.
I have landed on 3.8, slightly below the AAISM, for two reasons. The audience is even narrower, and the underlying discipline is less mature than AI security, which means more of what you learn is provisional. Neither is a criticism of how the credential is built. If your job is assurance and your organisation is deploying models, this is the most serious option available and probably employer funded.