How Hard Is the AAIA Exam? An Honest Answer

How hard is the AAIA exam: 90 questions, 150 minutes, three domains weighted 33/46/21, pass mark 450 of 800

How hard is the AAIA exam? Harder than the question count suggests, and hard in a specific direction. You get 90 multiple-choice questions in 150 minutes across three domains, which is about 100 seconds per question. The content is new to almost everybody sitting it. The hard part, though, is the framing. The AAIA is an audit exam about AI, so the credited answer is usually an assurance decision about scope, evidence, testing, independence, or reporting, and only rarely the technical fix a machine learning engineer would reach for.

One honest caveat first. ISACA launched the AAIA in 2025, so it is a young credential with very little published about it, and ISACA does not publish AAIA pass rates. Anyone quoting you a percentage is making it up, because there is no source to quote. What follows is the knowable part: the format, the scoring model, the domain weights, and the two very different ways candidates get caught out.

Why can nobody tell you the AAIA pass rate?

Because the number does not exist in public. ISACA does not release pass rates for its certifications, and the AAIA is a little over a year old, so even the informal community estimate that builds up around an established exam has not had time to form. With an older exam you can at least triangulate from thousands of write-ups. The AAIA has none of that yet, and the certified base is small, partly because the exam is eligibility-gated behind an existing audit or accountancy credential, which the AAIA requirements and eligibility rules set out in full.

So judge your readiness against the published facts: the format, the scoring scale, and the domain weights. They are more useful than a pass rate anyway.

What does the format tell you about the difficulty?

The exam is 90 multiple-choice questions in a single 150-minute session. No simulations, no labs, no written component. Every answer is on the screen in front of you, so the task is selection and ranking rather than production.

That works out to roughly 100 seconds per question. Enough time to read a three-line scenario, discard two options, and think properly about the remaining two. Not enough to reason your way from first principles through an unfamiliar concept on more than a handful of items. If AI operations vocabulary is still new to you on exam day, the clock stops being generous quickly.

Scoring is scaled. ISACA converts your raw score onto a common 200 to 800 scale, with 450 required to pass. Both numbers come from ISACA directly: the AAIA Exam Candidate Guide sets out the 200 to 800 scale and the 450 pass mark, and ISACA's own scoring explanation lists the AAIA among the exams it covers. Some items are unscored pretest questions that you cannot identify while sitting the exam. Because the score is scaled, there is no published conversion from questions answered correctly to a scaled result, so anybody quoting you a percentage correct is guessing at a conversion ISACA has never published.

Which AAIA domain makes the exam hard?

One of them, and it is not close. The published weights:

Domain Weight
1. AI Governance and Risk 33%
2. AI Operations 46%
3. AI Auditing Tools and Techniques 21%

Domain 2, AI Operations, is 46% of the paper. On a 90-question exam that is roughly 41 questions, nearly half the test riding on one domain. It is the single most important planning fact about the AAIA, and the one candidates most often ignore, because Domain 3 is the comfortable one and Domain 1 reads like governance work they already do.

Look at what Domain 2 contains: data management for AI, development methodologies and the AI solution lifecycle, change management, supervision of AI outputs and decisions, testing techniques, AI-specific threats and vulnerabilities, and AI incident response. In practice that means data lineage, training and test splits, model versioning, retraining as a change event, drift detection, human oversight, bias testing, and adversarial testing. For most auditors, every item on that list is new surface area.

Domain 3 at 21% distorts your sense of difficulty in the other direction. It is audit planning, sampling, evidence collection, data analytics, and reporting: your existing method pointed at a new object. Because you understand it on first reading, the exam feels easier than it is, and candidates walk out of a practice set with a false signal. The AAIA domains explained breaks all three down, and the AAIA study plan turns the weights into hours.

Is the AAIA an AI exam or an audit exam?

This is the question that decides most scores. The AAIA is an audit exam whose subject happens to be AI. The stem describes an AI system with a problem, and the four options usually include at least one technically correct remediation. That option is usually not the credited answer.

The pattern in one line: the question asks what an assurance professional does about the situation, and the engineer's move sits on screen as a distractor. When a production model has no documented data lineage, the credited move is to record the gap as a finding and scope its effect on your conclusion, because the training data is now unverifiable. Rebuilding the pipeline is somebody else's job. When bias testing ran once before deployment and never again, the point is that a one-time test does not support an ongoing assurance opinion.

Independence carries the same weight. Testing performed only by the team that built the model is weaker evidence than testing by an independent validation function, and the same applies to who sets the drift thresholds. If the model team defines acceptable degradation for its own model, that is self-assessment, and the exam expects you to notice. Evidence quality behaves as it always has: a vendor's assurance statement is an assertion, while a reproducible test report against preserved data and a preserved model version is evidence.

Read every practice question with one filter: what decision is being made, and is it mine to make as the auditor? That turns unfamiliar AI content into a familiar reasoning task.

Why the AAIA is hard for an experienced auditor

You arrive with the method already installed. Scope, risk, control, test, evidence, finding, report. Domain 3 will feel like a formality, and much of Domain 1 reads as governance vocabulary you have used for years with a model sitting where the application used to.

The gap is Domain 2, and it is a real gap rather than a terminology one. Model risk does not behave like application risk. A traditional system changes when its code changes, so you audit the change by auditing the code. A model changes when its training data changes, which means a retrain with no code change at all is a material change to production behavior. Organizations that run retraining as a routine scheduled task outside change control have a control gap, and the exam expects you to identify it.

The rest of the domain follows the same shape. Data lineage is the chain from source system through pipeline run and transformation to the exact dataset version a model trained on, and without it you cannot attribute a model's behavior to anything. Drift comes in more than one form: input distributions shift, or the relationship between inputs and outcomes shifts while the inputs look unchanged. Human oversight is a control you test rather than accept, because a review step where reviewers approve almost everything in seconds is oversight on paper only. AI incident response has to reach the model itself, which means a rehearsed rollback to a retained prior version, not just a ticket.

Why the AAIA is hard for an AI or data professional

The mirror image, and this group underestimates the exam more badly. You know what SHAP does, what concept drift is, and why a 99% accuracy score on an imbalanced fraud dataset means nothing. That is worth real marks in Domain 2, though fewer than you expect, because the questions are about controlling and evidencing the technology rather than building it.

What is missing is the audit half. Sampling methodology, evidence sufficiency, working papers, independence, materiality, and how a finding gets written are assumed as background rather than taught by the exam. A usable finding carries a condition, a criterion, a cause, an effect, and a recommendation, tied to evidence another auditor could re-examine. "The model is biased" is an observation, and it stops well short of all five. Choosing what to test and how much of it to test is a discipline rather than an instinct, and it is the discipline the AAIA assumes you brought with you.

The eligibility gate is ISACA telling you this openly: the exam is written for someone who already audits for a living. So if your route in was CPA-side rather than IT-audit-side, or if your daily work is model development, study the audit reasoning as hard as the AI content. What the CISA exam covers is a reasonable picture of the method the AAIA takes as given.

How well do you need to know NIST AI RMF, ISO/IEC 42001, and the EU AI Act?

Well enough to audit against them, not well enough to recite them. Domain 1 includes a sub-area for leading practices, ethics, regulations, and standards for AI, and in AI assurance work the reference points that dominate are the NIST AI Risk Management Framework, ISO/IEC 42001 for AI management systems, and the EU AI Act with its risk-tier approach.

The depth expected is assurance depth. For each one, know what it expects an organization to be able to demonstrate, then know what evidence would demonstrate it. That translation from framework language into control, sample, evidence, and finding is the part general AI training does not teach and the part that earns marks. Clause numbers, article numbers, and compliance dates are the wrong thing to memorize, and regulatory detail moves faster than exam outlines do, so treat any date or threshold you read as something to re-check.

Does the shortage of practice material make it harder?

Yes, and it is a genuine part of the difficulty rather than a complaint. Mature ISACA exams have thousands of circulating practice items and years of forum discussion mapping the traps. The AAIA has a small fraction of that. Third-party question banks are thin, and the ones that exist have not been sat against enough times for anyone to know how representative they are.

That matters more here than it would on a knowledge-recall exam. What the AAIA tests is a reasoning pattern, and a pattern installs through repetition against explained answers. On a mature exam you can brute-force that with volume. On this one you cannot, so each question has to do more work for you, which means explained ones or none. Our AAIA study guide was built for that shortage: all three domains at the real 33/46/21 weighting, plus two full-length practice exams where every answer is explained, including why each wrong option is wrong.

So how hard is the AAIA exam, really?

Hard in a narrow, trainable way. The format is as forgiving as multiple choice gets and the syllabus is small, only three domains. What makes it demanding is genuinely new subject matter in Domain 2, thin third-party practice material, and an answer pattern that rewards the assurance decision over the technical one.

Weight your hours to the blueprint, spend most of them on AI Operations, retrain your instinct toward evidence and reporting, and confirm the current format and pass mark on ISACA's AAIA page before you register. A schedule for that sits in the AAIA study plan, and the AAIA certification overview covers eligibility, fees, and delivery.

FAQ

What is the AAIA pass rate?

ISACA does not publish pass rates for the AAIA, and the credential is too new for a reliable informal figure to exist. Any percentage you find quoted online was invented by somebody. Judge your readiness against the published facts instead: the three domain weights of 33/46/21, the 90-question and 150-minute format, and the 450 scaled pass mark.

What score do you need to pass the AAIA?

450 on a scaled range of 200 to 800. Because the score is scaled rather than a raw percentage, there is no official conversion from questions answered correctly to a scaled result. The 90-question, 150-minute format is confirmed on ISACA's official AAIA page, so check the current pass mark and scoring detail against the AAIA candidate guide on ISACA's site before you rely on it.

Which AAIA domain is the hardest?

Domain 2, AI Operations, on both counts. It is 46% of the exam, close to half the paper, and it is the part of the syllabus a career auditor has least prior exposure to. Data lineage, model versioning, retraining as a change event, drift detection, human oversight, and AI incident response are all new surface area for most candidates, and there is no version of this exam where you can skip them.

Is the AAIA harder than the CISA?

They are hard in different places, so the honest answer depends on your background. The CISA is a much larger syllabus with a longer exam and decades of accumulated study material. The AAIA is shorter and narrower but sits on newer content with far less practice material available, and it assumes the audit method the CISA teaches. How hard the CISA exam is covers that side in detail.

Do I need a technical AI background to pass the AAIA?

No, and it is not the deciding factor. The exam tests whether you can evaluate and evidence AI systems, not whether you can build them. A technical background shortens the learning curve on Domain 2 vocabulary, but candidates from that route often underestimate the audit reasoning, which is assumed rather than taught. Either way the preparation is the same: learn the AI operations content properly, then drill explained questions until the assurance answer feels automatic.


Looking for a plain-English AAIA guide? ISACA AAIA: Simply Certified Study Guide covers all three domains from the AI auditor's lens, with two full-length practice exams, every answer explained.

Simply Certified is an independent publisher. AAIA and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.