Jason Edwards

Certified: The ISACA AAIA Audio Course

Welcome to Certified: The ISACA AAIA Audio Course. I’m your guide for this series, and my job is to make AI auditing feel clear, structured, and doable for people who already have a full plate. Across these episodes, you’ll build a practical mental model for how AI systems work in an organization and how an auditor or assurance professional should evaluate them. Expect plain language, a steady pace, and a focus on what you can actually test, document, and defend. We’ll spend time on governance, data, models, controls, and monitoring, but we’ll always bring it back to audit outcomes: scope, cri...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 63 — Audit AI decommissioning: retirement criteria and data cleanup duties (Task 8) 15.02.2026

This episode focuses on AI decommissioning, because Task 8 scenarios sometimes test whether you can manage the end of the lifecycle with the same discipline as development and deployment. You’ll learn how to define retirement criteria, such as models that no longer meet requirements, models that create unacceptable harm, systems that cannot be supported operationally, or use cases that no longer h...

Episode 62 — Audit AI monitoring controls: drift, performance, and incident triggers (Task 8) 15.02.2026

This episode teaches you how to audit AI monitoring controls for drift, performance, and incident triggers, because Task 8 expects monitoring to be designed and proven, not improvised after problems surface. You’ll learn how to define what must be monitored based on decision impact, including performance trends, stability of input data, fairness and segment outcomes where relevant, and operational...

Episode 61 — Audit AI deployment controls: approvals, gates, and rollback readiness (Task 8) 15.02.2026

This episode focuses on deployment controls for AI, because Task 8 scenarios often test whether you treat deployment as a controlled release with approvals, gates, and rollback readiness rather than a simple “go live.” You’ll learn how approval gates should confirm that requirements were met, validation evidence is complete, privacy and security constraints are enforced, and operational owners are...

Episode 60 — Embed vendor AI security requirements before procurement begins (Task 9) 14.02.2026

This episode introduces Task 9 by showing how to embed vendor AI security requirements before procurement begins, because AAISM expects you to shape vendor risk outcomes early through clear requirements, evidence expectations, and contractual controls rather than trying to “fix” weak vendor posture after adoption. You’ll define what vendor requirements should cover for AI services: data handling a...

Episode 59 — Retest and document fixes so AI vulnerabilities stay closed (Task 7) 14.02.2026

This episode completes the Task 7 vulnerability thread by teaching how to retest and document fixes so vulnerabilities stay closed, because AAISM often tests whether you can prove remediation with evidence and prevent reintroduction through drift, model updates, or configuration changes. You’ll learn how to design retesting that actually validates risk reduction, such as confirming access permissi...

Episode 58 — Build AI vulnerability management from discovery to remediation (Task 7) 14.02.2026

This episode focuses on Task 7 by explaining how to build AI vulnerability management from discovery to remediation, because AAISM treats vulnerability management as an end-to-end control process that includes identification, prioritization, ownership, fixes, and evidence—not just scanning and ticket creation. You’ll learn how “vulnerabilities” show up in AI environments, including misconfigured a...

Episode 57 — Design AI security testing that matches your model, data, and use case (Task 7) 14.02.2026

This episode introduces Task 7 by teaching how to design AI security testing that matches your model, data, and use case, because AAISM expects you to test what can realistically fail in your specific deployment instead of applying generic security tests that miss AI-specific failure modes. You’ll define what “AI security testing” means here: validating access controls and data protections, probin...

Episode 56 — Build a reassessment cadence that prevents stale AI risk decisions (Task 6) 14.02.2026

This episode covers Task 6 by teaching you to build a reassessment cadence that prevents stale AI risk decisions, because AAISM often rewards answers that institutionalize review routines rather than relying on ad hoc “we’ll revisit later” promises. You’ll define how cadence works in practice: scheduled reviews for high-impact systems, event-driven reviews for major changes, and lightweight check-...

Episode 55 — Monitor external changes like laws, vendors, and new AI capabilities (Task 6) 14.02.2026

This episode focuses on Task 6 by showing how external changes should drive AI risk reassessment, because AAISM expects you to manage risk in a live environment where laws, vendor terms, threat activity, and AI capabilities can shift without your internal teams making any code change. You’ll learn how to track external triggers such as new regulatory requirements, updated contract language, vendor...

Episode 54 — Monitor internal changes that require AI risk reassessment (Task 6) 14.02.2026

This episode teaches Task 6 by explaining how to monitor internal changes that should trigger AI risk reassessment, because AAISM commonly tests whether you can recognize when a prior approval is no longer valid due to scope, data, or control changes. You’ll define internal change triggers such as expanding the user population, adding new data sources, enabling plugins or connectors, changing prom...

Episode 53 — Keep threat understanding current as attackers and tools evolve (Task 5) 14.02.2026

This episode addresses Task 5 by showing how to keep threat understanding current as attackers and tools evolve, because AI systems and their integrations change quickly and AAISM expects you to maintain an updated threat view that feeds governance, monitoring, and reassessment decisions. You’ll learn what “current” means operationally: regularly reviewing new abuse patterns, vendor capability cha...

Episode 52 — Assess AI threats by likelihood and impact, not hype and fear (Task 5) 14.02.2026

This episode focuses on Task 5 by teaching you to assess AI threats using likelihood and impact rather than hype, because AAISM questions often include distractors that overreact to novel terminology while ignoring practical risk drivers. You’ll learn how to evaluate whether a threat is credible in your environment by examining access paths, data sensitivity, control strength, user behavior, vendo...

Episode 51 — Identify the AI threat landscape using realistic abuse cases (Task 5) 14.02.2026

This episode covers Task 5 by building a practical view of the AI threat landscape using realistic abuse cases, because AAISM expects you to recognize how AI systems can be attacked or misused without relying on vague “AI is risky” statements. You’ll define what a threat landscape means in exam terms: the set of credible threat actors, their objectives, and the tactics that can affect AI confident...

Episode 50 — Assign AI risk owners and approvals so accountability is never unclear (Task 4) 14.02.2026

This episode completes the set by teaching Task 4’s accountability core: assigning AI risk owners and approvals so responsibility is explicit, decisions are traceable, and risk acceptance is intentional rather than accidental. You’ll define what it means to “own” AI risk, including being accountable for controls, monitoring outcomes, exception handling, and lifecycle changes that alter exposure, a...

Episode 49 — Connect AI risks to enterprise risk reporting and decision-making (Task 4) 14.02.2026

This episode focuses on Task 4 by showing how to connect AI risks to enterprise risk reporting and decision-making, because AAISM expects AI risk to be expressed in the same language leaders already use for prioritization, funding, and acceptance decisions. You’ll learn how to translate AI-specific concerns—like prompt injection, model drift, unsafe automation, and vendor dependency—into risk stat...

Episode 48 — Run the AI risk management life cycle from intake to monitoring (Task 4) 14.02.2026

This episode teaches Task 4 by walking through the AI risk management life cycle from intake to monitoring, because AAISM questions often test whether you can apply risk management as a continuous loop rather than a single assessment document. You’ll define the lifecycle stages as intake and scope definition, risk identification, analysis and prioritization, treatment selection, control implementa...

Episode 47 — Domain 2 overview: manage AI risk while enabling business opportunity (Task 4) 14.02.2026

This episode introduces Domain 2 through Task 4 by explaining how AAISM expects you to manage AI risk while enabling business opportunity, which means balancing innovation with disciplined risk management that leadership can defend. You’ll define AI risk in practical terms—uncertainty that impacts confidentiality, integrity, availability, safety, compliance, and reputation—then connect that to a r...

Episode 46 — Domain 1 recap drill: pick the right task under pressure (Tasks 1–21) 14.02.2026

This episode is a Domain 1 recap drill designed to improve speed and accuracy under pressure by training you to identify which task is being tested and what the most defensible next step looks like across Tasks 1–21. You’ll rehearse fast classification of scenarios into governance and program management, policy and procedure operationalization, framework and ethics alignment, impact assessment dis...

Episode 45 — Plan for vendor outages and safe degraded modes in AI systems (Task 17) 14.02.2026

This episode covers Task 17 by teaching how to plan for vendor outages and safe degraded modes, because many AI deployments depend on external model services, and AAISM scenarios often hinge on whether you can keep operations safe when a vendor fails or changes behavior unexpectedly. You’ll define “safe degraded mode” as an intentionally designed fallback that reduces functionality while preservin...

Episode 44 — Set recovery goals for AI services, data pipelines, and vendors (Task 17) 14.02.2026

This episode focuses on Task 17 by showing how to set recovery goals for AI services, data pipelines, and vendors, because AAISM expects you to define recovery in measurable terms that match business impact and risk tolerance instead of using vague “restore ASAP” language. You’ll learn how to express recovery goals through service priorities, maximum tolerable downtime, data freshness expectations...

Episode 43 — Add AI systems to business continuity plans without hidden weak points (Task 17) 14.02.2026

This episode addresses Task 17 by teaching how to add AI systems to business continuity plans without hidden weak points, because AAISM tests whether you can treat AI services as real dependencies with failure modes, not optional features that can be ignored during outages. You’ll define what business continuity means for AI-enabled processes by identifying which business functions rely on inferen...

Episode 42 — Eradicate root causes and recover safely after AI security incidents (Task 16) 14.02.2026

This episode focuses on Task 16 by explaining how to eradicate root causes and recover safely after an AI security incident, because AAISM expects you to move beyond containment into durable fixes that prevent recurrence while maintaining evidence and governance discipline. You’ll learn how to distinguish symptom fixes, like disabling a feature, from root-cause eradication actions, like correcting...

Episode 41 — Notify and escalate during AI incidents with the right triggers (Task 16) 14.02.2026

This episode covers Task 16 by teaching how to notify and escalate during AI incidents using the right triggers, because AAISM often tests whether you can recognize when an AI issue crosses the threshold from “operational anomaly” to “security incident” that requires formal governance, legal, privacy, or executive involvement. You’ll define escalation triggers such as confirmed or suspected sensit...

Episode 40 — Contain AI incidents quickly by limiting access and stopping risky flows (Task 16) 14.02.2026

This episode introduces Task 16 by focusing on rapid containment actions for AI incidents, because AAISM questions often test whether you can stop harm first by limiting access and risky data flows while preserving evidence and keeping governance decision rights intact. You’ll define containment for AI contexts, including disabling compromised accounts, revoking or narrowing plugin and connector p...

Episode 39 — Report AI security incidents on time without losing accuracy (Task 15) 14.02.2026

This episode teaches how to report AI security incidents on time while maintaining accuracy, aligning with Task 15 and reflecting how AAISM balances speed, governance, and evidence when deadlines are driven by regulation, contracts, or internal escalation policies. You’ll learn how to manage reporting with incomplete information by clearly separating confirmed facts from open questions, defining w...

Listen to the Certified: The ISACA AAIA Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.