Jason Edwards
Certified: The ISACA AAIA Audio Course
Welcome to Certified: The ISACA AAIA Audio Course. I’m your guide for this series, and my job is to make AI auditing feel clear, structured, and doable for people who already have a full plate. Across these episodes, you’ll build a practical mental model for how AI systems work in an organization and how an auditor or assurance professional should evaluate them. Expect plain language, a steady pace, and a focus on what you can actually test, document, and defend. We’ll spend time on governance, data, models, controls, and monitoring, but we’ll always bring it back to audit outcomes: scope, cri...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 88 — Audit AI vendor claims, contracts, and control evidence without getting sold (Task 10) 15.02.2026 12:38
This episode teaches you how to audit AI vendor claims, contracts, and control evidence without getting sold by polished marketing metrics and generic security statements. You’ll learn how to challenge claims like “fair,” “transparent,” “secure,” and “state-of-the-art” by asking for definitions, test methods, limitations, and what the vendor will do when outcomes cause harm or compliance exposure....
Episode 87 — Evaluate AI vendors and supply chain controls where your visibility ends (Task 10) 15.02.2026 12:22
This episode explains how to evaluate AI vendors and supply chain controls when your visibility ends at the contract boundary, because Task 10 often tests whether you can demand accountability and evidence without assuming you can “audit the vendor’s code.” You’ll learn how to assess vendor risk by focusing on what the vendor provides—models, data, tooling, hosting, or APIs—and what that means for...
Episode 86 — Audit least privilege for pipelines, service accounts, and model endpoints (Task 16) 15.02.2026 13:11
This episode focuses on auditing least privilege in the places where AI systems most often break it: pipelines, service accounts, and model endpoints. You’ll learn how “too much access” creates unique AI risk, such as unauthorized dataset changes, silent model swaps, tampering with thresholds, or abuse of inference APIs to extract sensitive behavior and outputs. We’ll cover how to test least privi...
Episode 85 — Evaluate identity and access management for AI models, data, and keys (Task 16) 15.02.2026 14:02
This episode teaches you how to evaluate identity and access management for AI systems, because Task 16 scenarios often test whether you protect the most sensitive assets: models, training data, and the keys and tokens that enable inference and integrations. You’ll learn to map identities across humans, service accounts, automation, and vendor access, then verify that each role has only the permis...
Episode 84 — Build threat monitoring that catches abuse of models and prompts early (Task 19) 15.02.2026 13:46
This episode focuses on threat monitoring that detects abuse of models and prompt interfaces early, because Task 19 expects monitoring to catch misuse patterns before they become data loss, harmful outputs, or operational incidents. You’ll learn what “abuse” looks like in logs and metrics, including abnormal query rates, unusual input patterns, repeated probing for sensitive outputs, attempts to b...
Episode 83 — Evaluate AI threat and vulnerability management programs for real coverage (Task 19) 15.02.2026 14:40
This episode teaches you how to evaluate whether an AI threat and vulnerability management program has real coverage, because Task 19 scenarios often describe “we have a program” while leaving model and data risks unaddressed. You’ll learn how to assess scope first: whether the program includes training pipelines, data stores, model registries, inference endpoints, prompt interfaces where applicab...
Episode 82 — Understand data poisoning, evasion, and model theft in plain language (Domain 2F) 15.02.2026 14:24
This episode breaks down three high-yield AI attack categories—data poisoning, evasion, and model theft—in plain language so you can recognize them in AAIA scenarios and select realistic controls. You’ll learn how poisoning alters training data or labels so the model learns the wrong patterns, how evasion manipulates inputs at inference time to trick outputs without changing the model, and how mod...
Episode 81 — Evaluate AI threats and vulnerabilities that do not exist in normal IT (Domain 2F) 15.02.2026 14:50
This episode explains AI-specific threats and vulnerabilities that go beyond normal IT risk, which matters for Domain 2F because AAIA expects you to recognize failure modes unique to models, data pipelines, and inference behavior. You’ll learn how threats shift from “break the server” to “break the decision,” including manipulation of inputs, abuse of model behavior, leakage of sensitive outputs,...
Episode 80 — Prove AI controls work over time, not only on launch day (Task 12) 15.02.2026 16:31
This episode teaches you how to prove AI controls work over time, because Task 12 often tests whether you can validate continuous control effectiveness in a world where data, models, and environments change. You’ll learn how controls degrade when monitoring is ignored, when ownership shifts, when data sources evolve, and when model updates happen without full validation and documentation. We’ll co...
Episode 79 — Evaluate the design and effectiveness of AI-specific controls (Task 12) 15.02.2026 17:56
This episode focuses on evaluating the design and effectiveness of AI-specific controls, because Task 12 is about proving that controls exist for AI risks that traditional IT controls do not fully address. You’ll learn how to identify AI-specific controls across data governance, model validation, explainability requirements, drift monitoring, human oversight triggers, and change management that tr...
Episode 78 — Choose AI testing methods that match the risk of the use case (Domain 2E) 15.02.2026 17:08
This episode teaches you how to choose testing methods that match use-case risk, because Domain 2E expects you to scale testing depth based on impact, not apply a one-size-fits-all checklist. You’ll learn how high-impact decisions demand deeper validation, broader scenario coverage, stronger segment analysis, and stricter acceptance thresholds, while lower-impact decisions can use lighter-weight t...
Episode 77 — Test AI solutions for accuracy, robustness, bias, and safety (Domain 2E) 15.02.2026 15:57
This episode explains how to test AI solutions across four dimensions—accuracy, robustness, bias, and safety—because Domain 2E questions often require you to choose a test plan that reflects real operational risk. You’ll learn how accuracy testing confirms objective performance, robustness testing checks stability under noise and edge cases, bias testing evaluates unequal outcomes and proxy effect...
Episode 76 — Validate supervision of AI impacts on fairness, safety, and quality (Domain 2D) 15.02.2026 17:14
This episode focuses on validating whether supervision actually covers fairness, safety, and quality impacts, because Domain 2D expects oversight to detect harm patterns that pure accuracy metrics can miss. You’ll learn how to define what “fairness” and “safety” mean in the organization’s context, then verify that supervision mechanisms measure those outcomes using segment reporting, sampling, and...
Episode 75 — Build human oversight triggers for AI decisions that need escalation (Domain 2D) 15.02.2026 18:37
This episode teaches you how to build human oversight triggers that route the right AI decisions to review and escalation, because Domain 2D frequently tests whether you can define oversight that is targeted, timely, and defensible. You’ll learn how to decide what should trigger review, including low-confidence outputs, policy exceptions, high-impact outcomes, novel situations outside training con...
Episode 74 — Supervise AI outputs: detect harmful decisions before customers do (Domain 2D) 15.02.2026 18:46
This episode explains how to supervise AI outputs so harmful decisions are detected internally before customers, employees, or regulators surface the problem, which is a core Domain 2D expectation. You’ll learn to treat supervision as a control system that combines monitoring metrics, sampling strategies, human review, and escalation triggers tied to decision impact. We’ll cover how supervision di...
Episode 73 — Audit access to model artifacts, pipelines, and configuration repositories (Task 14) 15.02.2026 17:42
This episode focuses on auditing access controls for model artifacts, pipelines, and configuration repositories, because Task 14 expects you to protect the elements that directly shape AI outcomes and evidence integrity. You’ll learn how to evaluate who can view, modify, approve, and deploy model versions, datasets, feature logic, and configuration baselines, and why “developer convenience” is not...
Episode 72 — Prove reproducibility: model versions, parameters, and training snapshots (Task 14) 15.02.2026 15:36
This episode teaches you how to prove reproducibility for AI systems, because Task 14 scenarios often test whether the organization can recreate a model’s behavior when questions arise about fairness, safety, accuracy, or compliance. You’ll learn what reproducibility requires in practice: preserved model versions, captured training parameters, documented feature pipelines, and training snapshots o...
Episode 71 — Evaluate configuration management for AI across code, data, and models (Task 14) 15.02.2026 17:52
This episode explains how configuration management for AI must cover more than application settings, because Task 14 expects you to control anything that can change outcomes, including code, data pipelines, and model artifacts. You’ll learn how to identify configuration items that matter most—feature logic, preprocessing rules, training parameters, thresholds, prompts or templates where applicable...
Episode 70 — Audit emergency changes for AI when risk forces fast decisions (Task 13) 15.02.2026 15:06
This episode teaches you how to audit emergency changes for AI when risk forces fast decisions, because AAIA questions often test whether you can balance urgency with governance instead of abandoning controls under pressure. You’ll learn what qualifies as an emergency change, how emergency procedures should differ from normal change, and what minimum controls must still exist, including documented...
Episode 69 — Audit model update approvals, testing evidence, and release readiness (Task 13) 15.02.2026 14:44
This episode focuses on auditing model updates by verifying approvals, testing evidence, and release readiness, because Task 13 scenarios often revolve around a model change that created unexpected harm or compliance issues. You’ll learn how update approvals should confirm that the change is justified, risks are assessed, stakeholders are informed, and acceptance criteria are met, especially when...
Episode 68 — Evaluate change management for AI where “updates” can change outcomes (Task 13) 15.02.2026 14:54
This episode explains why change management for AI must be stricter than typical software change management, because in AI, “updates” can silently change outcomes even when interfaces stay the same. You’ll learn how changes can enter through code, data sources, feature logic, model parameters, infrastructure dependencies, and even operating conditions, and why each path needs control, testing, and...
Episode 67 — Evaluate model performance claims using audit-grade skepticism (Task 9) 15.02.2026 14:20
This episode focuses on evaluating model performance claims with audit-grade skepticism, because AAIA scenarios often include impressive numbers that are meaningless without context, constraints, and evidence. You’ll learn how to challenge claims by asking what data was used, how it was sampled, whether leakage was prevented, what baseline was compared, and whether performance holds across relevan...
Episode 66 — Evaluate model explainability expectations without overpromising certainty (Task 9) 15.02.2026 14:42
This episode teaches you how to evaluate explainability expectations without overpromising certainty, because Task 9 questions often test whether you can set realistic transparency requirements based on decision impact and stakeholder needs. You’ll learn the difference between explaining how a model generally behaves, explaining why a specific output occurred, and explaining whether the outcome is...
Episode 65 — Test model alignment to policy: what it should do versus what it does (Task 9) 15.02.2026 14:52
This episode focuses on testing model alignment to policy by comparing what the model should do to what it actually does, which is a common AAIA scenario pattern when organizations have policies but cannot prove behavior matches them. You’ll learn how to translate policy constraints into test cases, including prohibited uses, required disclosures, human review requirements, and limits on sensitive...
Episode 64 — Evaluate algorithms and models for alignment to business objectives (Task 9) 15.02.2026 14:12
This episode teaches you how to evaluate whether an algorithm or model aligns to business objectives, because Task 9 questions often focus on fit-for-purpose decisions rather than technical novelty. You’ll learn how alignment starts with the business decision and the acceptable tradeoffs, including what errors matter most, what fairness or safety constraints apply, and what level of explainability...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.