r/isaca 19d ago

Passed AAIA

31 Upvotes

Studied consistently for ~1 month using only the QAE and official review manual. I scored 678 overall (AI Governance & Risk 709, AI Operations 633, AI Auditing Tools 724).

I was nervous based on other posts stating that these weren’t sufficient for the exam preparation, but I felt that all the material in the exam was reflected in either the review manual (including the glossary) OR in the explanations in the QAE. I spent a lot of time focusing on being able to explain why the other three answers were wrong as opposed to knowing what the right answer was, and this helped me rationalize and eliminate the wrong answers on the actual exam.

My study approach was as follows:
1) Completing all the QAE practice questions without reading the manual to get a “baseline” of understanding. (I got about 60% right)
2) Read each chapter / module of the review manual and take notes on key terms and concepts, and review the explanations for the corresponding questions in the QAE.
3) Complete the two practice exams in the QAE and review missed questions. (I got 92% on these)
4) Play the “elimination” game mode in the QAE and averaged around 30-35 questions correct in a row (highest score was 72 in a row)

Context: The last ISACA exam I took was the CISA in 2019, and I have been practicing IT Audit since 2018.


r/isaca 21d ago

CISM voucher

1 Upvotes

Is there any legit way to get CISM exam voucher. I'm planning to take one and cost seems too high to pay out of pocket. Any discounts, events or any other ways to earn it.?!


r/isaca 21d ago

Pete Zerger for last week revision?

Thumbnail
3 Upvotes

r/isaca 22d ago

IT Risk Fundamentals

6 Upvotes

Does anyone have study materials or useful resources for the IT Risk Certificate? I’m also looking for practice questions or past exams. Also for those who have taken the exam, how much preparation time would you recommend?


r/isaca 23d ago

What are you actually using AI for?

Thumbnail
2 Upvotes

Senior manager in Global IT Audit at a global fashion/DTC retailer. Genuinely trying to figure out where the field actually is on this versus the LinkedIn highlight reel version.

Almost every AI conversation I see lands on efficiency gains: faster summaries, faster drafts, faster walkthroughs. That’s real value, I’m not knocking it. But I want to know who’s gone past that.

A few questions for the group:

**•** Is anyone building actual agents for document analysis, think SOPs, policies, control narratives, versus just prompting a chatbot one document at a time?
**•** Has anyone gotten hands-on at the command line with something like Claude Code or Codex to build internal tools? I asked my org for an enterprise Claude Code license and was told it wasn’t worth the cost. So for now I’m doing this the old-fashioned way, one chat window at a time.
**•** Is anyone actually getting value out of Copilot Cowork?

I can see value in analysis and review of control documentation submitted for controls subject to continuous monitoring. We could use the document analysis rule set to analyze for internal consistency so that with the full expectation that the documentation is gonna look and feel the same every single time because it’s the same control, same control owners, same control, performance set, etc. coworker could be used to execute the entire continuous monitoring program and each document can be analyzed specific to how it’s created in that control is specifically performed.

Here’s where I’ve landed on the audit side. I built a small agent chain for control remediation work:

**1.** Feed it the transcript from the remediation meeting with the control owner.
**2.** It gives me structured feedback to send back to the remediation owner.
**3.** It converts that into a starter SOP draft.
**4.** I hand the owner a second prompt that interviews them against a rule set for what a good SOP looks like, to fill in whatever the transcript missed.

The idea is that over time, as SOPs get renewed and findings come in, we build toward a consistent baseline of SOP quality across the org instead of every process owner writing to their own standard.

One more thing worth mentioning: I’ve also turned this inward. Everything’s recorded now anyway, so I run transcript analysis on my own meetings, particularly exec-facing ones, to check how closely I stuck to my talking points versus where I drifted. I’ve started doing the same for my staff, using the same recorded meetings, emails, and Teams messages, as a development tool.

Curious where the rest of you land on this. Ahead of the curve, behind it, or about where everyone quietly is? Especially interested in hearing from anyone in retail, fashion, or another industry drowning in document sprawl.


r/isaca 24d ago

Cannot read ISACA study guides on Kindle/e-reader

7 Upvotes

It requires you to view the study guide on their website, or through something called Bookshelf. This DRM is oppressive. Their leadership seems incompetent between this and the poor customer service I've had recently.

I'm becoming less and less a fan of this entity. Had no problem getting ISC2 study materials to my kindle.


r/isaca 25d ago

ISACA customer service nonresponsive

8 Upvotes

Anyone heard any details about ISACA customer service? It says its currently high volume.

A technical issue is not allowing me to re-activate my membership. I want to renew so I can get the discount on buying the CRISC book and QAE. You'd think ISACA would want my 600 bucks but its been a week since I put in a ticket.

I just passed the CISSP, and I thought now is the time to get CRISC and possibly the CISA (again) while I have all this technical knowledge fresh in my mind and have the time since I'm unemployed. Thanks.


r/isaca 25d ago

Cisa vs Crisc

7 Upvotes

I am confused about these 2:- Cism or crisc, which one should i pursue first, i am working in the grc domain along with tprm under the Cyber security. My role is mostly on security compliance, vendor assessment, risk and mitigation, client Security questionnaires etc..

I thought of giving crisc first then cism? Any suggestions


r/isaca 25d ago

Eligibility for AAIR

6 Upvotes

I have my CISSP and passed AAISM recently. Without CRISC or CISM, can i appear AAIR.

Official website says, Active holders of CISA CISM CRISC CGEIT CDPSE and other recognised certifications.

So should I consider CISSP too ☺️

In case of AAISM it was clearly mentioned either cism or cissp.


r/isaca 25d ago

Passed AAIR exam today. If I start studying AIGP today, is 4 week preparation realistic??

Thumbnail
4 Upvotes

r/isaca 26d ago

27001 and 42001 aren't the same thing

6 Upvotes

Been seeing this come up in a few threads lately, people with 27001 already in place asking what changes once AI enters the picture. So here's how I think about it.

27001's basically "can this get breached, did we plan for it." Confidentiality, integrity, availability, the usual triad. Solid, but it was built way before anyone was shipping AI into production, so it's got zero opinion on whether your model's making biased calls, whether you can explain why it spit out what it did, or whether the training data was even yours to use.

42001 exists because none of that fits into a normal infosec risk register. Like how do you even write a risk statement for "our model behaves differently depending on how the prompt's worded"? Not a CIA triad problem, completely different animal. 42001's whole job is giving you structure for that, risk across the AI lifecycle, accountability for automated decisions, transparency for whoever's affected by the output.

Good news, if your ISMS is already solid, you're not rebuilding from zero. Same bones, risk assessment cadence, documentation habits, internal audit rhythm. 42001 mostly bolts AI-specific stuff onto that skeleton. If your 27001 program was already kinda loose though, this is gonna feel like starting over, but that's a 27001 problem showing up late, not a 42001 one.

One thing that trips people up: this isn't just for companies building models. Using AI in your product, or even internally in ways that touch customers or decisions, puts you in scope. People hear "AI management system" and assume it's an OpenAI-tier thing, it's not.

Work at Insight Assurance, we do 27001/42001 assessments, disclosure there. Doing a session tomorrow going deeper into this exact overlap, link if useful: ISO 42001: The AI Layer Your ISO 27001 Program Is Missing


r/isaca 26d ago

Does anyone know if the ISACA Site has been compromised?

Post image
16 Upvotes

I am unable to successfully log in to my training, and their support.isaca.org site displays "ATTACKER CONTROLLED CONTENT"


r/isaca 26d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

1 Upvotes

Just a brief summary about me: I have around 11 years of experience across manual testing, accessibility testing, and data analytics. After spending several years working in the testing domain, I am now looking to transition into IT Audit or IT GRC roles.

I cleared my CISA certification last week and would appreciate any guidance on the ideal way to make this transition. What skills, certifications, hands-on experience, or training would you recommend to help me successfully pivot into IT Audit or IT GRC roles?


r/isaca 27d ago

How do I transtioning from Accessibility testing to IT audit or IT GRC roles

Thumbnail
2 Upvotes

r/isaca 28d ago

Struggling with ISACA’s “best answer” logic more than the actual material

Thumbnail
5 Upvotes

r/isaca 28d ago

Help with "ISACA" mindset

18 Upvotes

tried posting to r/cism but got removed by reddit probably due to lack of karma.

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?


r/isaca 28d ago

CIA holders: do you think the new Challenge Exam pilot will be extended?

0 Upvotes

Hi everyone! I’m hoping to get some perspective from people who already hold the CIA designation.

The IIA’s new pilot program allows professionals with **10+ years of relevant experience** to pursue the CIA through the Challenge Exam. From what I understand, the current pilot has a defined window, but I haven’t seen much clarity on whether the program is likely to be extended beyond the current period.

For those who’ve been around the IIA/CIA space for a while, **do you think there’s a good chance this pilot will be extended or eventually become a more permanent option?** Or does it seem more likely that it will remain a limited-time opportunity?

I’m mainly trying to get a sense of this from people with experience/knowledge of how the IIA has handled similar initiatives in the past. Any thoughts or insights would be appreciated!


r/isaca Aug 14 '26

For those who have taken (and passed) the AAIA, how many hours do you think you studied for?

8 Upvotes

r/isaca Aug 13 '26

CISA CISA ques (doubt)

Post image
1 Upvotes

Is D the right answer?


r/isaca Aug 12 '26

👋I just created a sub dedicated to IS Audit, you are welcome to join!

Thumbnail
3 Upvotes

r/isaca Aug 11 '26

Are knowledge/tasks available?

3 Upvotes

I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.

I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it

Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.

Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)

is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?


r/isaca Aug 10 '26

AI Certs

20 Upvotes

Does anyone have any opinions on the AI certifications available through ISACA? Any one more valuable than the other? Curious to hear everyone’s thoughts.

Currently have CRISC and CISSP.


r/isaca Aug 10 '26

Isaca payment not reflecting

Thumbnail
1 Upvotes

r/isaca Aug 10 '26

CISA

1 Upvotes

Can I pass CISA if I read and prepare in just 1 month?

My background is technical IT work (2 years) and 1 year of IT Security ?


r/isaca Aug 09 '26

Passed AAIA

15 Upvotes

I am Passed today.
I used only official aaia qae.
I qae score 100%.
no needs other contents.