AAIA cheat sheet
Last-minute reference for AAIA. The exam rewards the answer an auditor could evidence, not the one that sounds most thorough.
Exam facts
| Questions | 90 |
| Domains | 3 |
| Requires | CISA or an equivalent designation |
| Exam fee | 459 USD member / 599 USD non-member, plus a 50 USD application fee |
Domain weights
| Domain | Weight |
|---|---|
| AI Operations | 46% |
| AI Governance and Risk | 33% |
| AI Auditing Tools and Techniques | 21% |
Operations is the largest, which surprises people expecting a governance-heavy exam.
Evidence hierarchy
Strongest to weakest, and the exam is consistent about this:
- Re-performance or automated testing across the full period
- Inspection of records showing the control operated, with dates
- Observation on a single day
- Inquiry of the control owner
- Management representation alone
A signed policy shows design. Completed assessments for systems actually in production show operation.
Finding severity
| Finding | Severity |
|---|---|
| High-risk model in production with no approval or oversight | Highest |
| Production AI system with no identified owner | Highest |
| Cannot evidence which personal data feeds a model | Significant — lawful basis and rights unprovable |
| Change management over models not operating | Significant |
| Model documentation incomplete | Moderate |
| Quarterly rather than monthly reporting | Low |
| Inconsistent artefact naming | Administrative |
Recurring right answers
- Start with the inventory — owners, purpose, risk classification
- Segregation of duties — the builder does not approve and deploy
- Versioned artefacts, inputs and parameters with retained logs to reconstruct a past decision
- Ongoing fairness monitoring with thresholds, not pre-deployment testing alone
- Statistical sampling with a documented method, not whatever management selects
- Verify AI-generated summaries against source evidence; the auditor keeps responsibility
Traps
- 18 months without re-evaluation means current performance is unknown, not merely undocumented.
- Aggregate metrics cannot explain an individual decision.
- Least-privilege scoping, not a longer system prompt, limits agent damage.
Night-before checklist
- Three domains; Operations is 46%
- Evidence hierarchy in order
- What makes a finding highest severity
- Check ID and proctoring rules — see exam day
Take the 20-question practice test.