Overview
Bring trust and insight to a world shaped by artificial intelligence.
AI is no longer on the horizon. Organizations are embedding AI into the core of business operations, decision-making and automation. As these systems grow more complex and influential, audit professionals must evolve to ensure they are governed effectively, aligned to strategic goals, and ethically sound.
Without specialized AI audit capabilities, organizations risk falling behind in both compliance and innovation.
ISACA’s AAIA certification bridges this critical skills gap by equipping credentialed auditors with the ability to audit machine learning models, intelligent automation tools, and data-driven decision systems. More than just oversight, AAIA prepares you to use AI to enhance the audit process itself.
This two-day, instructor-led course provides IS auditors with the foundational knowledge and background of AI solutions to evaluate their proper governance, design, development, and security to apply their expertise in audit and assurance activities in the enterprise.
The course is structured to align with the job practice and features a variety of knowledge check questions, case studies, activities, and discussions designed to apply the concepts to real-life business scenarios.
Private in-house training
Apart from public, instructor-led classes, we also offer private in-house trainings of this program for organizations. Call us at +852 2116 3328 or email us at [email protected] for more details.
Why Choose KORNERSTONE
- KORNERSTONE is the Only ISACA® Accredited Training Organization in HK
- ALL Official ISACA Material included
- Practical, scenario-based learning – focus on application, not just theory
- Over 85% Passing rate in ISACA program
- Pass Guaranteed (80% over attendance)
- Exclusive Offer on purchasing Exam Voucher
Skills Covered
ISACA’s AAIA certification bridges this critical skills gap by equipping credentialed auditors with the ability to audit machine learning models, intelligent automation tools, and data-driven decision systems. More than just oversight, AAIA prepares you to use AI to enhance the audit process itself.
Upon certification, successful candidates will be able to:
- Implement AI-driven audit processes
- Use AI to optimize audit processes
- Respond to risk and improve oversight
- Audit data-driven environments
- Deliver assurance across the AI lifecycle design
- Help implement AI to align with strategic stakeholder goals
Prerequisites
- Active CISA, CPA or CIA certification
- IT audit or advisory experience
- Some technical experience with AI systems
- Successful completion of the AAIA exam
Target Audience
IT Audit professionals with a CISA, CIA, or CPA certification looking to enhance their expertise in navigating AI-driven challenges while upholding the highest industry standards.
Mid-level to senior professionals who hold a CISA, CPA or CIA credential
- IT Auditor
- Senior IT Auditor
- Risk Manager
- Information Manager
Course Curriculum
Domain 1 — AI Governance and Risk (33%)
This Domain demonstrates your ability to advise stakeholders on implementing AI solutions through appropriate and effective policy, risk controls, data governance and ethical standards.
A–AI Models, Considerations, and Requirements
B–AI Governance and Program Management
C–AI Risk Management
D–Privacy and Data Governance Programs
E–Leading Practices, Ethics, Regulations, and Standards for AI
Domain 2 — AI Operations (46%)
This domain confirms your skill in balancing sustainability, operational readiness, and the risk profile with the benefits and innovation AI promises to support enterprise-wide adoption of this powerful technology.
A–Data management specific to AI
B–AI solution development methodologies and lifecycle
C–Change management specific to AI
D–Supervision of AI solutions (e.g. outputs, impacts, and decisions)
E–Testing techniques for AI solutions
F–Threats and vulnerabilities specific to AI
G–Incident response management specific to AI
Domain 3 — AI Auditing Tools and Techniques (21%)
This domain focuses on optimizing audit outcomes through innovation and highlights your knowledge of audit techniques tailored to AI systems and the use of AI-enabled tools streamline audit efficiency and provide faster, quality insight.
A–Audit planning and design
B–Audit testing and sampling methodologies
C–Audit evidence collection techniques
D–Audit data quality and data analytics
E–AI audit outputs and reports
Secondary Classifications – Tasks
- Evaluate impacts, opportunities, and risk when integrating AI solutions within the audit process.
- Utilize AI solutions to enhance audit processes, including planning, execution, and reporting.
- Evaluate AI solutions to advise on impact, opportunities, and risk to organization.
- Evaluate the impact of AI solutions on system interactions, environment, and humans.
- Evaluate the role and impact of AI decision-making systems on the organization and stakeholders.
- Evaluate the organization’s AI policies and procedures, including compliance with legal and regulatory requirements.
- Evaluate the monitoring and reporting of metrics (e.g., KPIs, KRIs) specific to AI.
- Evaluate whether the organization has defined ownership of AI-related risk, controls, procedures, decisions, and standards.
- Evaluate the organization’s data governance program specific to AI.
- Evaluate the organization’s privacy program specific to AI.
- Evaluate the organization’s problem and incident management programs specific to AI.
- Evaluate the organization’s change management program specific to AI.
- Evaluate the organization’s configuration management program specific to AI.
- Evaluate the organization’s threat and vulnerability management programs specific to AI.
- Evaluate the organization’s identity and access management program specific to AI.
- Evaluate vendors and supply chain management programs specific to AI solutions.
- Evaluate the design and effectiveness of controls specific to AI.
- Evaluate data input requirements for AI models (e.g., data appropriateness, bias, privacy).
- Evaluate system/business requirements for AI solutions to ensure alignment with enterprise architecture.
- Evaluate the AI solution lifecycle (e.g., design, development, deployment, monitoring, and decommissioning) and inputs/outputs for compliance and risk.
- Evaluate algorithms and models to ensure AI solutions are aligned to business objectives, policies, and procedures.
- Analyze the impact of AI on the workforce to advise stakeholders on how to address AI-related workforce impacts, training, and education.
- Evaluate that awareness programs align to the organization’s AI-related policies and procedures.
Dates & Locations
December 1, 2026 - December 15, 2026

Exam & Certification
- AAIA candidates must hold a CISA certification or one of the following certifications with an IT audit or IT advisory role focus: CIA, US CPA, ACCA or FCCA, Canadian CPA, Australian CPA or FCPA or the Japanese CPA designation.
- Pass the AAIA exam
- Adherence to the Code of Professional Ethics
Trainer for this course
Mr. S Cheung
AAIA, CISSP, CCSP, CISA, CDPSE, ISO 27001 Lead Auditor, ISO 20000 Lead Auditor, ISO 9001 Lead Auditor, ITIL
- Over 10 years of diverse experience in information security and cybersecurity fields, covering cloud security, network security, security operations, red & blue team assessment, and SRAA.
- Skilled in providing advisory services on information security management systems, security operations, and cybersecurity defense strategies by leveraging extensive knowledge and experience.
- Proficient in offering consultancy on industrial and government security standards like C-RAF, ISO27001, CSA CCM, PCIDSS, and SRAA, and assisting clients in designing and implementing security controls.
- Certified Kornerstone trainer for CISSP (Certified Information Systems Security Professional) and CCSP (Certified Cloud Security Professional) certifications.
Mr. A Yau
CISSP, CISA, CISM, CGEIT, CRISC, CDPSE
- Mr. Yau is currently holding a Senior Management Role as Principal Cybersecurity Consultant and Trainer with 20+ years of experience
- Specializes in leading engagements and serving clients in Information Security, including Next Generation Security Operation Center, IT Risk Assessment, Penetration Testing and IT Audit
- Led the implementation and execution of Next Generation Security Operation Center, Security Operation Center, Infrastructure
- Security for Mobile Device Management, Security Exchange 2010 and Infrastructure Security for Enterprise Cloud Services
- Holds ISACA Accredited Trainer and Certified Mile2 Instructor credentials








