Free AAIA Practice Test: ISACA Advanced in AI Audit

Prepare for the ISACA Advanced in AI Audit (AAIA) certification with 168 active FlashGenius practice questions, instant scoring, and detailed explanations. The practice bank covers AI Governance and Risk, AI Operations, and AI Auditing Tools and Techniques.

Start the 10-question mixed AAIA quick test or review the AAIA cheat sheet.

AAIA exam overview

The AAIA exam configuration contains 90 questions in 150 minutes across three domains. Use the domain weights to prioritize study time, then practice switching between governance, operations, and audit scenarios.

Domain 1: AI Governance and Risk (33%)

Covers AI governance structures, policy, accountability, risk assessment, ethics, privacy, and regulatory considerations. Practice this domain.

Domain 2: AI Operations (46%)

Covers the AI lifecycle, data and model management, deployment, monitoring, change management, and operational controls. Practice this domain.

Domain 3: AI Auditing Tools and Techniques (21%)

Covers audit planning, evidence, testing approaches, AI-assisted audit tools, reporting, and follow-up. Practice this domain.

AAIA study plan

  1. Start with AI Operations, the largest domain at 46%, then review AI Governance and Risk at 33% and AI Auditing Tools and Techniques at 21%.
  2. Complete a domain test, read every explanation, and record the concepts behind missed questions rather than memorizing answer letters.
  3. Finish with mixed quick-start sets and practice pacing for the 150-minute exam. FlashGenius scores are study guidance and do not convert to an official ISACA scaled score.

Official exam information

FlashGenius practice material is unofficial study guidance. Confirm current exam policies and registration details with ISACA's official AAIA information.

AAIA guides and practice questions

AAIA sample questions with answers

Sample Question 1 — AI Auditing Tools and Techniques

An audit team uses an explainability tool to support testing of a customer eligibility model. The tool produces explanations based on a surrogate model, and the explanations vary materially across repeated runs. The business has used the explanations to justify model decisions to compliance reviewers. Which recommendation is MOST appropriate?

  1. A. Define acceptable use limits and require corroboration before using explanations as audit evidence. (Correct answer)
  2. B. Increase the number of sampled decisions so unstable explanations average out over the audit period.
  3. C. Replace the explainability tool with a visualization dashboard approved by the business owner.
  4. D. Report that model decisions are unsupported because surrogate explanations are inherently invalid.

Correct answer: A

Explanation: A is the best recommendation because the issue is evidence reliability, not merely sample size or presentation format. Materially different outputs across repeated runs indicate the tool should not be relied on without defined usage boundaries and corroborating evidence. B is insufficient because a larger sample does not fix instability in the explanations themselves. C addresses presentation and business approval, but neither establishes that the explanations are reliable for audit or compliance use. D is too absolute because surrogate explanations are not automatically unusable; their limitations must be governed and supplemented with other evidence.

Sample Question 2 — AI Governance and Risk

A large financial services organization has an approved AI policy requiring all AI use cases to be registered and risk-tiered before production use. The central AI inventory is populated through business unit self-reporting. During audit planning, procurement records show several AI-related subscriptions not listed in the inventory, and SSO logs show active users of those applications. Management states the missing items are likely low-risk drafting tools. Which control deficiency is MOST significant?

  1. A. The AI policy has not been refreshed since several business units adopted generative AI tools.
  2. B. The AI inventory is not reconciled to procurement and access records before oversight reporting. (Correct answer)
  3. C. The steering committee minutes do not consistently record discussion of low-risk AI use cases.
  4. D. The risk-tiering template does not require a separate field for vendor model ownership.

Correct answer: B

Explanation: B is correct because inventory completeness is the foundational governance control. If the inventory relies on self-reporting and is not reconciled to independent sources such as procurement and access records, the organization cannot demonstrate that all AI use cases were registered and risk-tiered before production. That weakness undermines committee oversight, reporting, and downstream control reliance. A is relevant but less significant because a policy can be current and still be ineffective if completeness is not validated. C is a downstream issue; committee discussion cannot cover use cases that never entered the inventory. D may improve classification detail, but it is less critical than the failure to identify the full population of AI use cases.

Sample Question 3 — AI Operations

A retail bank deployed an updated AI credit-risk scoring model before a seasonal lending campaign. The change ticket exists, but independent validation sign-off was dated after production deployment. Management states the release was urgent and that early default-rate indicators improved. What should the auditor evaluate FIRST?

  1. A. Whether the deployment was linked to documented approval and exception handling before release (Correct answer)
  2. B. Whether post-release portfolio metrics indicate improved model performance after deployment
  3. C. Whether the model repository contains release notes for the deployed model version
  4. D. Whether the rollback procedure was referenced in the release planning materials

Correct answer: A

Explanation: A is best because the first audit priority is to confirm whether the model was authorized for production or released under a documented exception before deployment. Without that evidence, accountability and control operation are unproven. B is wrong because improved outcomes do not substitute for pre-release authorization. C is wrong because release notes support traceability, not approval. D is wrong because rollback readiness is relevant, but it is secondary to whether the release was properly authorized.

Sample Question 4 — AI Auditing Tools and Techniques

An organization maintains an AI model inventory used to scope AI audits. Business owners annually certify that their inventory entries are complete. The auditor is concerned that models deployed through cloud machine learning services may be omitted. Which audit procedure is MOST appropriate?

  1. A. Reconcile cloud deployment records to the model inventory and investigate unmatched services. (Correct answer)
  2. B. Review annual business owner certifications for completeness statements and sign-off dates.
  3. C. Compare the inventory taxonomy to AI definitions used in the enterprise risk policy.
  4. D. Interview model owners about whether they know of unregistered cloud-based models.

Correct answer: A

Explanation: A is best because it uses independent system evidence to test the completeness assertion directly. Reconciling actual cloud deployment records to the model inventory is the strongest way to identify omitted models and investigate exceptions. B and D rely on management or owner assertions, which are weaker when the risk is that deployed models were not reported. C may help assess definitional consistency, but it does not determine whether all deployed models are actually captured in the inventory.

Sample Question 5 — AI Governance and Risk

An auditor is evaluating whether a post-deployment monitoring control for a credit risk AI model operated effectively during the audit period. The control requires threshold breaches to be investigated, approved, and tracked to closure. Which evidence BEST supports the conclusion?

  1. A. Monitoring logs reconciled to incident tickets showing breach review, approval, and closure dates. (Correct answer)
  2. B. A dashboard screenshot showing current model accuracy and stability metrics within tolerance.
  3. C. A quarterly attestation from the model owner stating that monitoring was performed as required.
  4. D. A validation report issued before deployment showing that baseline model performance was acceptable.

Correct answer: A

Explanation: A is the best evidence because it directly supports operating effectiveness during the audit period. Reconciliation of monitoring logs to incident tickets demonstrates that breaches were detected completely and that each required step—investigation, approval, and closure—occurred. B shows only current status at a point in time and does not prove that breaches during the period were handled as required. C is weaker evidence because management attestation does not independently demonstrate control execution. D relates to predeployment validation, not post-deployment monitoring performance during the period under review.

Sample Question 6 — AI Operations

An insurer uses an AI propensity model to prioritize customer retention offers. After an upstream feed change, the nightly scheduler logs show successful job completion, but the number of customers receiving scores declined. Management notes that campaign conversion rates for scored customers remain acceptable. What is the PRIMARY audit concern?

  1. A. The absence of source-to-score reconciliation may allow silent exclusion of records (Correct answer)
  2. B. The stable conversion rate may not reflect the quality of model predictions
  3. C. The updated lineage document may not describe all upstream data dependencies
  4. D. The scheduler completion logs may not identify the responsible support team

Correct answer: A

Explanation: A is best because the key operational risk is silent omission of source records after the upstream change, and source-to-score reconciliation is the control that would detect that completeness failure. B is wrong because acceptable conversion rates for scored customers can mask missing customers who were never scored. C is wrong because lineage documentation explains dependencies but does not detect excluded records in daily operation. D is wrong because support-team identification affects accountability, not whether the scored population is complete.

Sample Question 7 — AI Auditing Tools and Techniques

An audit analytics script using machine learning is reused across multiple regulatory audits to identify unusual transactions. The script was modified during the current audit, and the results were consistent with prior-period findings, but there is no evidence of independent review of the modified script. Which recommendation is MOST appropriate?

  1. A. Require version control and independent review before relying on modified audit analytics scripts. (Correct answer)
  2. B. Accept the current results because they are consistent with prior-period audit findings.
  3. C. Limit future use of machine learning scripts to nonregulatory audit engagements only.
  4. D. Request management to confirm that the unusual transaction population is complete.

Correct answer: A

Explanation: A is the most appropriate recommendation because once an audit analytics script is modified, the reliability of the audit evidence depends on controlled change management, including versioning and independent review, before the results are relied upon. B is incorrect because similar results do not validate that the modified logic operated as intended. C is disproportionate and does not address the actual deficiency, which is lack of governance over script changes. D may relate to population completeness, but it does not mitigate the risk that the modified audit tool itself produced unreliable results.

Sample Question 8 — AI Governance and Risk

A financial services firm requires material AI model changes to be approved by the model risk committee before release. Management states that no unauthorized model changes occurred during the audit period. Which evidence BEST supports the conclusion?

  1. A. Change tickets reconciled to deployment logs with committee approvals for all material releases. (Correct answer)
  2. B. A management representation letter stating that all material changes followed the approval process.
  3. C. Meeting minutes showing the committee discussed several AI model changes during the period.
  4. D. A release calendar listing planned model updates and responsible teams for the audit period.

Correct answer: A

Explanation: A is best because the conclusion requires evidence of both completeness and authorization: the auditor must know what was actually deployed and whether each material release had committee approval. Reconciling change tickets to deployment logs, then tracing them to approvals, provides that assurance. B is weaker because a representation letter is not independent evidence of actual deployments. C may show that some changes were discussed, but it does not demonstrate that all material deployed changes were approved. D reflects planned activity rather than what was actually released, so it cannot support a conclusion that no unauthorized changes occurred.

AAIA Practice Test FAQs

What is the ISACA Advanced in AI Audit (AAIA) exam?

AAIA is an ISACA certification exam focused on auditing artificial intelligence systems. It covers AI governance and risk, AI operations, and AI auditing tools and techniques.

How many questions and how much time does the AAIA exam have?

The AAIA exam configuration is 90 questions in 150 minutes across three domains.

What score is required for AAIA?

ISACA uses a scaled score, with 450 on an 800-point scale listed as the passing score in the exam configuration. Practice-test percentages are not equivalent to an official ISACA scaled score.

How should I use AAIA practice questions?

Use mixed questions to find broad knowledge gaps, then use domain practice to review the concepts and explanations behind incorrect answers. FlashGenius readiness thresholds are study guidance, not official ISACA passing scores.

Which AAIA domain has the greatest weight?

AI Operations has the largest listed weight at 46%, followed by AI Governance and Risk at 33% and AI Auditing Tools and Techniques at 21%.

Explore AAIA Tests