Jason Edwards
Certified: The ISACA AAIA Audio Course
Welcome to Certified: The ISACA AAIA Audio Course. I’m your guide for this series, and my job is to make AI auditing feel clear, structured, and doable for people who already have a full plate. Across these episodes, you’ll build a practical mental model for how AI systems work in an organization and how an auditor or assurance professional should evaluate them. Expect plain language, a steady pace, and a focus on what you can actually test, document, and defend. We’ll spend time on governance, data, models, controls, and monitoring, but we’ll always bring it back to audit outcomes: scope, cri...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 38 — Document AI incidents clearly for regulators, contracts, and executive updates (Task 15) 14.02.2026 15:55
This episode focuses on Task 15 by explaining how to document AI incidents in a way that serves regulators, contracts, and executive stakeholders, because AAISM commonly tests whether you can turn technical facts into clear, auditable records without speculation or missing context. You’ll learn how to write incident documentation that captures what happened, what systems and data were affected, wh...
Episode 37 — Investigate AI security incidents by collecting the right evidence fast (Task 15) 14.02.2026 16:37
This episode introduces Task 15 by teaching how to investigate AI security incidents through fast, disciplined evidence collection, because AAISM expects you to prioritize what preserves truth and supports defensible decisions before focusing on attribution or deeper analysis. You’ll define the evidence categories that matter for AI incidents, including access and authentication logs, prompt and o...
Episode 36 — Domain 1 quick review: governance, policies, assets, metrics, and training (Tasks 1–3) 14.02.2026 15:25
This episode consolidates Domain 1 by reviewing the key ideas behind Tasks 1–3, helping you connect governance leadership, policy structure, inventory discipline, metrics, and training into one coherent program model that AAISM tests through scenario-based “best answer” logic. You’ll reinforce how a governance charter sets authority and scope, how policies become enforceable standards and procedur...
Episode 35 — Operationalize tools with tuning, ownership, and measurable outcomes (Task 19) 14.02.2026 16:47
This episode covers the operational reality of AI security tools, emphasizing Task 19 by showing that tools only reduce risk when they are tuned, owned, and measured over time, which is why AAISM questions often prefer governance and process steps that keep controls effective after deployment. You’ll learn how to establish tool ownership, define maintenance routines, and tune detections using real...
Episode 34 — Implement AI security tools into monitoring, alerting, and response workflows (Task 19) 14.02.2026 16:01
This episode explains how to implement AI security tools so they actually function inside monitoring, alerting, and response workflows, aligning to Task 19 and reflecting how AAISM rewards integration and accountability over standalone tooling. You’ll learn how to connect AI telemetry to your existing security operations processes, including how alerts are triaged, who owns investigation steps, wh...
Episode 33 — Review AI security tools by coverage, gaps, and operational fit (Task 19) 14.02.2026 18:05
This episode focuses on Task 19 by showing how to review AI security tools based on coverage, gaps, and operational fit, because AAISM expects you to choose controls that work in real environments, integrate with existing operations, and produce evidence rather than buying tools that look impressive but don’t reduce risk. You’ll define what “coverage” means for AI systems, including visibility int...
Episode 32 — Use metrics to prioritize work and prove security program value (Task 18) 14.02.2026 17:34
This episode teaches how to use AI security metrics to prioritize work and demonstrate program value, aligning with Task 18 and preparing you for AAISM items where the best answer connects measurement to decisions, resource allocation, and risk reduction. You’ll learn how to translate raw signals into action, such as using inventory coverage and assessment completion rates to identify uncontrolled...
Episode 31 — Monitor AI metrics to spot misuse, drift, and early incident signals (Task 18) 14.02.2026 14:55
This episode explains how continuous monitoring turns AI security metrics into early warning signals, which is exactly what Task 18 is getting at when AAISM questions ask what you should measure and how you should respond when behavior changes. You’ll connect leading indicators like unusual prompt volume, spikes in denied requests, abnormal data access patterns, output toxicity flags, and sudden s...
Episode 30 — Define AI security metrics leaders can understand and act on (Task 18) 14.02.2026 14:22
This episode focuses on Task 18 by teaching you to define AI security metrics that leaders can use to make decisions, because AAISM favors measurable, outcome-linked reporting over technical noise that cannot drive prioritization or accountability. You’ll learn how to select metrics that reflect governance health, risk exposure, and control performance, such as inventory completeness, assessment c...
Episode 29 — Build an AI security program that fits the enterprise security program (Task 19) 14.02.2026 15:22
This episode addresses Task 19 by showing how to build an AI security program that fits into the enterprise security program instead of competing with it, because AAISM emphasizes alignment with existing governance, risk, and control structures to avoid gaps and duplicated effort. You’ll learn how to integrate AI-specific concerns—like model changes, prompt handling, and output safety—into establi...
Episode 28 — Manage retention and deletion to reduce long-term AI data exposure (Task 14) 14.02.2026 15:59
This episode teaches Task 14 through retention and deletion discipline, because AI systems tend to accumulate prompts, outputs, logs, and derived artifacts that quietly expand exposure over time, and AAISM questions often test whether you can reduce that long-term risk with defensible rules. You’ll define what must be retained for security monitoring, incident response, audit, and regulatory requi...
Episode 27 — Preserve data integrity so models stay reliable and trustworthy (Task 14) 14.02.2026 15:56
This episode focuses on preserving data integrity so models remain reliable, which is central to Task 14 because AAISM treats integrity failures as both a security problem and a governance problem when decisions depend on model outputs. You’ll define integrity controls such as dataset versioning, provenance tracking, validation checks, change approvals, and monitoring signals that detect unexpecte...
Episode 26 — Protect training and test data with access control and secure storage (Task 14) 14.02.2026 19:27
This episode explains how to protect training and test data using access control and secure storage, aligning to Task 14 and preparing you for AAISM questions where the strongest answer limits exposure, enforces least privilege, and produces audit-ready evidence. You’ll learn how to define who should access training datasets, evaluation sets, labels, and feature stores, and how to separate duties...
Episode 25 — Identify data risks across the AI life cycle: leaks and tampering (Task 14) 14.02.2026 16:03
This episode targets Task 14 by teaching you to identify data risks across the AI life cycle, with a focus on leaks and tampering, because AAISM expects you to reason about where data can be exposed or altered from intake through training, evaluation, deployment, and ongoing operations. You’ll define key risk types such as unauthorized disclosure through prompts and outputs, exposure through logs...
Episode 24 — Keep the AI inventory accurate with routine governance checks (Task 13) 14.02.2026 14:27
This episode covers how to keep the AI inventory accurate through routine governance checks, reinforcing Task 13 with the exam-critical idea that inventories decay unless they are embedded into change management, vendor oversight, and operational review cycles. You’ll learn how governance routines detect drift such as new integrations, expanded data access, model swaps, feature flags that change b...
Episode 23 — Classify AI assets by sensitivity, criticality, and compliance scope (Task 13) 14.02.2026 15:24
This episode expands Task 13 by showing how to classify AI assets using sensitivity, criticality, and compliance scope, because AAISM questions frequently ask you to choose controls and governance actions that match the asset’s impact if it fails, leaks, or behaves unexpectedly. You’ll define classification dimensions that matter for AI systems, including data confidentiality in prompts and output...
Episode 22 — Inventory AI assets: models, prompts, data, and key dependencies (Task 13) 14.02.2026 17:48
This episode teaches Task 13 by explaining how to inventory AI assets in a way that supports governance, risk decisions, and exam-ready control evidence, because AAISM treats “you can’t secure what you don’t know you have” as a foundational truth. You’ll define what counts as an AI asset beyond the model itself, including prompts and prompt templates, embeddings and vector stores, training and eva...
Episode 21 — Refresh training when threats, tools, and regulations change (Task 21) 14.02.2026 15:03
This episode focuses on Task 21 by showing how to refresh AI security training as threats, tools, and regulations evolve, because AAISM questions often reward the choice that sustains secure behavior over time rather than treating training as a one-and-done compliance step. You’ll learn how to define refresh triggers such as new AI features, vendor model updates, changes in data sources, emerging...
Episode 20 — Build AI security awareness training that sticks in daily work (Task 21) 14.02.2026 16:12
This episode builds on Task 21 by teaching how to create AI security awareness training that changes daily behavior, because AAISM expects you to reduce human-driven exposure through repeatable learning, not one-time policy acknowledgements. You’ll define the training outcomes that matter for the exam and for real operations: recognizing sensitive data, using approved tools, validating outputs bef...
Episode 19 — Create acceptable use guidelines that reduce risky AI behavior (Task 21) 14.02.2026 15:59
This episode focuses on Task 21 by showing how acceptable use guidelines reduce risky AI behavior in a way that is enforceable and measurable, which is exactly how AAISM frames human-driven risk as part of AI security management. You’ll define what acceptable use must address: what tools and systems are approved, what data is prohibited from input, how outputs may be used in decisions, and what ov...
Episode 18 — Essential Terms: Plain-Language Glossary for fast, accurate recall (Tasks 1–22) 14.02.2026 15:13
This episode strengthens your exam performance by tightening your definitions in plain language, because AAISM frequently tests whether you can distinguish similar governance, risk, and AI security terms under time pressure across Tasks 1–22. You’ll reinforce high-confusion term pairs such as policy versus standard, risk identification versus risk assessment, monitoring versus testing, incident co...
Episode 17 — Keep AI security policies current using ownership and change control (Task 2) 14.02.2026 16:18
This episode targets the “policy drift” problem and shows how to keep AI security policies current through ownership and change control, which Task 2 treats as essential because AI systems evolve quickly and outdated guidance is functionally the same as no guidance. You’ll learn how to assign policy owners, define review triggers, and integrate updates into existing governance and enterprise chang...
Episode 16 — Turn policies into standards, guidelines, and step-by-step procedures (Task 2) 14.02.2026 15:45
This episode explains how to translate policy into standards, guidelines, and procedures, which is a key Task 2 competency because AAISM expects you to operationalize governance into repeatable actions that produce consistent evidence. You’ll define how each artifact functions: policies set mandatory intent, standards specify measurable requirements, guidelines provide recommended options, and pro...
Episode 15 — Write AI security policies people can follow without guessing (Task 2) 14.02.2026 13:23
This episode teaches how to write AI security policies that are usable in daily work, aligning to Task 2 and preparing you for AAISM questions where the “best” option is the one that reduces ambiguity, assigns responsibility, and can be enforced and audited. You’ll learn the difference between policy intent and operational direction, and how to write policy statements that clearly define scope, re...
Episode 14 — Prove conformity by building defensible evidence for regulators and contracts (Task 8) 14.02.2026 13:34
This episode focuses on how to prove conformity by building defensible evidence, which is central to Task 8 and shows up across the exam whenever the correct choice emphasizes documentation, traceability, and repeatability over informal assurances. You’ll define what “defensible evidence” looks like for AI security: records of approvals, scoped assessments, control ownership, monitoring outputs, i...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.