AI Audit Fieldwork and Testing
Fieldwork includes walkthroughs, control testing, evidence inspection, data analysis, reperformance, sampling, technical tests, and issue validation.
How to study for ISACA AAIA
Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.
Core concepts
Concept 1
AI fieldwork should combine interviews, document review, control testing, data analysis, walkthroughs, and technical testing where appropriate.
Exam cue: Choose tests that match the control objective and AI risk.
Concept 2
Testing should verify design and operating effectiveness of governance, data, model, security, monitoring, and incident controls.
Exam cue: Use reperformance or analytics when evidence can be independently verified.
Concept 3
Auditors need sufficient, reliable, relevant evidence to support findings and conclusions.
Exam cue: Validate exceptions before drafting findings.
Risk pitfalls and guardrails
Accepting screenshots without checking completeness or reliability.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Testing policy existence instead of operating effectiveness.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Using samples that do not represent AI risk or usage.
Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.
Memory anchors
Walkthrough
A walkthrough traces an AI process from initiation through controls, outputs, and evidence.
Design Effectiveness
Design effectiveness asks whether a control is capable of addressing the AI risk.
Operating Effectiveness
Operating effectiveness asks whether a control actually worked over the audit period.
Reperformance
Reperformance independently repeats a control, calculation, or test to verify the result.
Sample Selection
Sample selection chooses items that support valid conclusions about the audited population.
Evidence Reliability
Evidence reliability depends on source, completeness, accuracy, independence, and tamper resistance.
Exception Validation
Exception validation confirms whether a possible issue is real, relevant, and supported.
Technical Test
A technical test evaluates AI behavior, data, model, security, monitoring, or system configuration directly.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A control owner says every high-risk model received approval. What procedure provides the STRONGEST evidence?
Which procedure BEST tests whether a monitoring alert is handled effectively?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
