Jason Edwards
Certified: The ISACA AAIA Audio Course
Welcome to Certified: The ISACA AAIA Audio Course. I’m your guide for this series, and my job is to make AI auditing feel clear, structured, and doable for people who already have a full plate. Across these episodes, you’ll build a practical mental model for how AI systems work in an organization and how an auditor or assurance professional should evaluate them. Expect plain language, a steady pace, and a focus on what you can actually test, document, and defend. We’ll spend time on governance, data, models, controls, and monitoring, but we’ll always bring it back to audit outcomes: scope, cri...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Welcome to the ISACA AAIA Audio Course 15.02.2026 1:00
Certified: The ISACA AAIA Audio Course is an audio-first program built for working professionals who need a practical path into AI auditing. If you’re an internal auditor, risk manager, security leader, compliance professional, or governance practitioner who suddenly has “AI” on the agenda, this course is for you. You do not need to be a data scientist to follow along, but you should be ready to t...
Episode 112 — Exam-Day Tactics: Calm, fast, defensible answers for AAIA scenarios (Exam-Day Tactics) 15.02.2026 14:37
This final episode gives you exam-day tactics that keep you calm, fast, and defensible when AAIA scenarios feel ambiguous or overloaded with details. You’ll learn a reliable pacing approach that prevents early-question time traps, plus a reading strategy that spots what the question is really testing: governance decision rights, risk treatment logic, lifecycle control points, evidence selection, o...
Episode 111 — Spaced Retrieval Mega-Review: All 23 tasks in one connected storyline (Review: Tasks 1–23) 15.02.2026 12:50
This mega-review pulls all 23 AAIA tasks into one connected storyline so you can recall them as a single audit narrative instead of a scattered checklist. You’ll revisit how tasks start with evaluating AI opportunities and impacts, then move into defining requirements and architecture fit, mapping risks to controls, and validating privacy, ethics, and compliance constraints. From there, you’ll con...
Episode 110 — Spaced Retrieval Review: Domain 3 audit tools and techniques, simplified (Review: Domain 3) 15.02.2026 12:46
This review episode reinforces Domain 3 by walking through the audit toolset you need—planning, criteria, testing methods, sampling, evidence integrity, analytics, and reporting—in a single connected flow that matches exam logic. You’ll revisit how to define scope around decision impact, convert policies and obligations into measurable criteria, select AI-aware audit techniques, and collect eviden...
Episode 109 — Utilize AI to enhance audit reporting without hallucinated conclusions (Task 23) 15.02.2026 13:58
This episode focuses on using AI to enhance audit reporting without hallucinated conclusions, because Task 23 expects you to recognize that confident language is not evidence and that AI can generate plausible but unsupported statements. You’ll learn how AI can help draft report structure, improve clarity, and standardize wording, while you enforce strict sourcing: every key claim must map back to...
Episode 108 — Utilize AI to enhance audit execution while preserving evidence quality (Task 23) 15.02.2026 12:10
This episode teaches you how to use AI to enhance audit execution while preserving evidence quality, because Task 23 scenarios often test whether efficiency improvements still produce defensible workpapers and conclusions. You’ll learn where AI can assist safely, such as summarizing large policy sets, clustering exceptions, proposing sample stratification ideas, and drafting test steps, while you...
Episode 107 — Utilize AI to enhance audit planning without outsourcing judgment (Task 23) 15.02.2026 13:38
This episode focuses on Task 23 by showing how to use AI to enhance audit planning without outsourcing professional judgment, because AAIA expects you to treat AI as an assistant to thinking, not a replacement for accountability. You’ll learn how AI can help organize background information, identify potential risk themes, draft preliminary scopes, and suggest interview questions, while you remain...
Episode 106 — Prevent AI-in-audit blind spots: bias, leakage, and overreliance risks (Task 22) 15.02.2026 13:38
This episode teaches you how to prevent AI-in-audit blind spots, with a focus on three risks that show up in Task 22 scenarios: bias, leakage, and overreliance. You’ll learn how audit AI can reflect biased training data or biased prompts, leading to uneven scrutiny across teams or systems, and how to counter that with review practices, diverse sampling, and validation against independent evidence....
Episode 105 — Evaluate impacts and risk when integrating AI into the audit process (Task 22) 15.02.2026 13:34
This episode focuses on Task 22 by evaluating impacts and risk when AI is integrated into the audit process itself, because AAIA expects you to govern AI use in assurance work with the same discipline you audit in others. You’ll learn how audit AI can introduce new risks, such as confidentiality exposure through data sharing, biased analysis that skews audit focus, and overconfidence in automated...
Episode 104 — Follow up AI audits so fixes stick and risk stays reduced (Domain 3E) 15.02.2026 13:36
This episode explains how to follow up AI audits so remediation actually sticks and risk stays reduced, because Domain 3E recognizes that AI environments change quickly and “we fixed it” can evaporate after the next retrain or deployment. You’ll learn how to design follow-up work that verifies corrective actions are implemented, operating, and still aligned to the original criteria, including evid...
Episode 103 — Write AI findings that tie cause, risk, evidence, and remediation together (Domain 3E) 15.02.2026 13:41
This episode focuses on writing AI audit findings that tie cause, risk, evidence, and remediation into one coherent story, because Domain 3E expects findings to be defensible and useful, not just critical. You’ll learn how to describe the condition clearly, reference the criteria it violates, and present evidence that is traceable to model versions, data states, and control operation records. We’l...
Episode 102 — Deliver AI audit reports executives understand and teams can act on (Domain 3E) 15.02.2026 13:48
This episode teaches you how to deliver AI audit reports that executives understand and teams can act on, because Domain 3E often tests whether you can translate technical and governance issues into clear, risk-based communication. You’ll learn how to structure reporting around business impact and decision risk, not around model jargon, while still being precise about criteria, evidence, and contr...
Episode 101 — Use analytics to detect drift, anomalies, and control breakdown trends (Domain 3D) 15.02.2026 16:56
This episode focuses on using analytics as an audit technique to detect drift, anomalies, and control breakdown trends, because Domain 3D expects you to go beyond spot checks and prove what is happening over time. You’ll learn how to use trend analysis across model performance, outcome distributions, exception rates, manual overrides, and complaint signals to identify early warnings that controls...
Episode 100 — Audit data quality before trusting any AI output or model score (Domain 3D) 15.02.2026 15:21
This episode teaches you why auditing data quality must happen before you trust any AI output or model score, because Domain 3D scenarios often hinge on the fact that “good models” fail when inputs are wrong, incomplete, biased, or out of date. You’ll learn how to evaluate data quality dimensions that matter for audit conclusions—accuracy, completeness, consistency, timeliness, representativeness,...
Episode 99 — Validate evidence integrity when models and data change over time (Domain 3C) 15.02.2026 15:21
This episode focuses on validating evidence integrity in environments where models and data change over time, because AI auditing fails quickly when you cannot prove which version produced which outcome. You’ll learn how to confirm that evidence is complete, consistent, and tied to specific model versions, configuration states, and data snapshots, so findings cannot be dismissed as “from before th...
Episode 98 — Collect AI audit evidence: logs, lineage, artifacts, and change records (Domain 3C) 15.02.2026 14:10
This episode explains how to collect AI audit evidence across logs, lineage, artifacts, and change records, because Domain 3C expects you to prove what happened, when it happened, and under which model and data conditions. You’ll learn how operational logs support questions about access, inference usage, exceptions, and incidents, while lineage artifacts support questions about where data came fro...
Episode 97 — Test AI controls with evidence, not opinions or vendor demos (Domain 3B) 15.02.2026 13:54
This episode teaches you how to test AI controls using evidence, because Domain 3B scenarios often tempt you to accept “trust me” statements, impressive demos, or subjective opinions as proof. You’ll learn how to define what evidence is required for common AI controls, such as approvals for model changes, validation reports tied to acceptance criteria, monitoring configurations with thresholds and...
Episode 96 — Design sampling for AI decisions that reveals bias and failure modes (Domain 3B) 15.02.2026 14:59
This episode focuses on designing sampling approaches that reveal bias and failure modes in AI decisions, because AAIA questions often ask what sampling plan best supports a defensible conclusion. You’ll learn how to sample across time, segments, and decision types so you can detect drift, representation gaps, and inconsistent outcomes that hide inside averages. We’ll cover how to choose samples t...
Episode 95 — Use audit techniques tailored to AI systems, not generic checklists (Domain 3B) 15.02.2026 14:32
This episode teaches audit techniques that are tailored to AI systems, because Domain 3B often tests whether you can select methods that match AI realities like data dependence, model updates, and outcome supervision. You’ll learn how to combine walkthroughs of data and decision flows with targeted control testing, including verifying approval gates, validating versioning and reproducibility, and...
Episode 94 — Choose audit criteria for AI using policy, risk, and outcomes (Domain 3A) 15.02.2026 14:20
This episode explains how to choose audit criteria for AI by using policy, risk, and outcomes, because AAIA expects you to build criteria that can be proven with evidence, not just referenced as “best practice.” You’ll learn how internal policies and procedures become criteria when they include roles, required steps, thresholds, approvals, and recordkeeping expectations. We’ll cover how risk appet...
Episode 93 — Build AI audit objectives that connect directly to business risk (Domain 3A) 15.02.2026 16:29
This episode teaches you how to build audit objectives that connect directly to business risk, because AAIA scenarios often test whether you can write objectives that are meaningful and testable instead of generic. You’ll learn to express objectives in terms of what must be true for the AI use case to be acceptable, such as decisions being accurate enough for the purpose, fair within defined thres...
Episode 92 — Plan an AI audit: scope, criteria, stakeholders, and timing choices (Domain 3A) 15.02.2026 16:30
This episode explains how to plan an AI audit in a way that produces a workable scope, clear criteria, the right stakeholders, and timing that fits the AI lifecycle. You’ll learn how to define scope by anchoring on the business decision the AI influences, the impacted systems and data flows, and the most meaningful risks, rather than scoping only to “the model.” We’ll cover criteria selection at a...
Episode 91 — Spaced Retrieval Review: Domain 2 operations and controls, simplified (Review: Domain 2) 15.02.2026 15:32
This review episode reinforces Domain 2 by pulling operations and controls into a compact, easy-to-recall mental model that matches how AAIA questions are written. You’ll revisit how data pipelines, development practices, deployment gates, monitoring, supervision, and security controls fit together, with quick reminders of what “good evidence” looks like for each area. We’ll refresh the control th...
Episode 90 — Run AI incident response: detect, triage, contain, recover, and learn (Domain 2G) 15.02.2026 13:44
This episode walks through AI incident response as a complete lifecycle—detect, triage, contain, recover, and learn—because Domain 2G expects you to treat AI incidents as operational events with governance consequences and evidence requirements. You’ll learn how detection relies on monitoring, supervision, and stakeholder feedback, and how triage should quickly identify decision impact, affected p...
Episode 89 — Evaluate AI problem and incident management programs for fast containment (Task 20) 15.02.2026 13:15
This episode focuses on evaluating AI problem and incident management programs with an emphasis on fast containment, because Task 20 scenarios often involve harmful outputs, drift-driven failures, or abuse patterns that require immediate action. You’ll learn how AI incidents differ from typical IT incidents, including the need to stop harmful decisions quickly, preserve evidence about model versio...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.