AAIA prerequisites: CISA or equivalent

Updated September 20, 2026

AAIA has an enforced eligibility gate. You cannot certify without one of a defined set of professional designations.

What qualifies

CISA — ISACA’s Certified Information Systems Auditor — qualifies on its own.

Alternatively, one of a defined group of audit and accounting designations, held in an IT audit or IT advisory role:

  • CIA — Certified Internal Auditor, from the Institute of Internal Auditors
  • US CPA — from a US state board of accountancy
  • ACCA (or FCCA)
  • Canadian CPA
  • Australian CPA (or FCPA)
  • Japanese CPA
  • and further international equivalents recognised by ISACA

The qualifier on the second group matters: the designation must be held by someone working in IT audit or IT advisory. A CPA in financial reporting is not the intended candidate; a CPA leading technology audits is.

Confirm your specific designation against ISACA’s current list before paying for anything — the recognised set is defined by ISACA and can change.

What is expected but not enforced

ISACA writes AAIA for people who audit for a living. Practically, the questions assume:

  • You have planned and executed audits and formed opinions
  • You think in terms of assertions, evidence and sufficiency
  • You are comfortable reporting a limitation rather than implying assurance you lack

You do not need to be technical. No coding, no configuration, no mathematics. The operations domain is 46% of the exam, but it asks what should happen and what would evidence it — not how to implement anything.

What it costs

Exam fee — ISACA memberUS$459
Exam fee — non-memberUS$599
Application processing feeUS$50 after passing
Eligibility period after registering6 months to sit
Window to apply after passing5 years

Two clocks, and people miss the first. Registering starts a six-month window to actually sit the exam. Register when you are ready to study, not when the idea first appeals.

The US$140 member saving is a large enough share of ISACA membership to be worth pricing, particularly if you are also paying CISA maintenance.

If you hold none of these

Three routes, in order of directness:

Earn CISA. The natural path if you audit information systems. It is also the credential whose question style AAIA follows most closely, so it is preparation as well as eligibility.

Earn CIA or a recognised accounting designation and work in IT audit or advisory. A longer route, and only sensible if you were heading there anyway.

Choose a credential without an eligibility gate. If AI assurance is the goal and the gate is the obstacle, CompTIA SecAI+ covers overlapping subject matter with no enforced prerequisite. It is a security rather than audit credential, but much of the AI risk and control content is shared.

If you already hold CISA

You are eligible today, and your preparation is narrower than the syllabus length suggests — the audit techniques domain is only 21% and it is method you have.

Budget five to six weeks, with two thirds of it in AI Operations. See AAIA vs CISA for the detailed delta and the study plan for how to allocate the time.

Keeping it

AAIA carries its own continuing professional education requirement, and your qualifying designation must remain active. That means two credentials, two CPE obligations and two maintenance fees indefinitely. Confirm both with ISACA before certifying, so the ongoing commitment is a decision rather than a surprise.

Before you book

  1. Verify your designation is on ISACA’s current qualifying list and is active.
  2. Price ISACA membership against the US$140 saving.
  3. Try the free sample questions.
  4. Read the operations domain guide. If that content is entirely unfamiliar, budget the full six weeks — it is 46% of the exam.