Jason Edwards
Certified: The ISACA AAIA Audio Course
Welcome to Certified: The ISACA AAIA Audio Course. I’m your guide for this series, and my job is to make AI auditing feel clear, structured, and doable for people who already have a full plate. Across these episodes, you’ll build a practical mental model for how AI systems work in an organization and how an auditor or assurance professional should evaluate them. Expect plain language, a steady pace, and a focus on what you can actually test, document, and defend. We’ll spend time on governance, data, models, controls, and monitoring, but we’ll always bring it back to audit outcomes: scope, cri...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 13 — Perform AI impact assessments with scope, evidence, and actionable results (Task 8) 14.02.2026 16:08
This episode teaches you how to perform an AI impact assessment that produces actionable results rather than a generic narrative, aligning directly to Task 8 and preparing you for questions that test whether you can define scope, gather evidence, and recommend controls with clear ownership. You’ll learn to set boundaries first—what system, what users, what decisions, what data flows, and what life...
Episode 12 — Plan AI impact assessments early so compliance is not an afterthought (Task 8) 14.02.2026 16:43
This episode explains why impact assessments must be planned early, not bolted on after deployment, and it targets Task 8 by showing how AAISM expects you to integrate assessment timing into intake, design, and governance checkpoints. You’ll define what an AI impact assessment is in practice: a structured evaluation of intended use, stakeholders affected, data sensitivity, legal and ethical concer...
Episode 11 — Translate AI regulations into practical, testable security requirements (Task 3) 14.02.2026 15:33
This episode trains you to convert AI regulations and external obligations into concrete, testable security requirements, which is the core of Task 3 and a common “best answer” driver on AAISM when options compete between vague principles and measurable controls. You’ll learn how to read regulatory language for intent—such as transparency, accountability, privacy, safety, and documentation—then tr...
Episode 10 — Apply ethical principles when AI outcomes create real business risk (Task 3) 14.02.2026 14:17
This episode teaches how to apply ethical principles in a way that reduces real business risk, aligning with Task 3 and showing up in questions where the correct answer prioritizes harm reduction, transparency, accountability, and privacy alongside security controls. You’ll define core ethical concerns—bias, unfair outcomes, unsafe automation, misuse, and overcollection—and connect them to governa...
Episode 9 — Use industry frameworks to organize AI governance and security work (Task 3) 14.02.2026 14:49
This episode covers how to use industry frameworks to organize AI governance and security work, emphasizing Task 3’s focus on translating external expectations—ethics, privacy, and regulatory pressures—into structured, testable requirements. You’ll learn how frameworks function on the exam: they provide a shared vocabulary, coverage map, and evidence checklist, helping you avoid ad hoc control sel...
Episode 8 — Set governance routines that keep AI security decisions consistent (Task 1) 14.02.2026 14:48
This episode explains how governance routines turn intent into repeatable action, which matters for Task 1 because AAISM expects you to sustain AI security decisions over time, not just design them once. You’ll build a practical cadence of reviews and checkpoints for AI intake, impact assessment timing, inventory updates, control health, incident learnings, and vendor status, and you’ll learn how...
Episode 7 — Define AI roles and responsibilities so decisions are owned and clear (Task 1) 14.02.2026 14:18
This episode focuses on clarifying AI roles and responsibilities so accountability is explicit, which is a frequent AAISM decision point because strong governance requires named owners for risk acceptance, control operation, and evidence production. You’ll define typical role categories—business owner, model owner, data owner, security, privacy, risk, legal, and operations—and learn how to express...
Episode 6 — Build an AI governance charter that aligns to business objectives (Task 1) 14.02.2026 14:12
This episode teaches how to build an AI governance charter that exam questions treat as the “source of truth” for scope, authority, and priorities, which is why it anchors Task 1 and influences many best-answer choices. You’ll break down charter essentials: purpose, scope of AI systems covered, decision rights, stakeholder roles, risk tolerance alignment, oversight cadence, and required outputs su...
Episode 5 — Domain 1 overview: lead AI governance and program management confidently (Task 1) 14.02.2026 14:40
This episode frames Domain 1 through the lens of Task 1, focusing on how to lead AI governance and program management so decisions are consistent, auditable, and aligned to business objectives instead of being improvised project by project. You’ll define what AI governance means in AAISM terms: clear authority, documented decision rights, repeatable oversight routines, and measurable outcomes tied...
Episode 4 — Exam Acronyms: High-Yield Audio Reference for AAISM daily practice (Tasks 1–22) 14.02.2026 15:56
This episode delivers a practical acronym and terminology alignment session designed for daily recall, because AAISM questions often hinge on whether you interpret governance, risk, and assurance language the way ISACA intends. You’ll clarify how common security acronyms and AI terms behave in exam contexts, including where they signal ownership, evidence, monitoring, or lifecycle controls, and wh...
Episode 3 — Walk through an AI system life cycle in clear, simple language (Task 22) 14.02.2026 13:44
This episode builds a clean, exam-ready mental model of the AI system life cycle so you can consistently place risks, controls, and evidence in the right phase, which is central to Task 22 and frequently implied across other tasks. You’ll define each phase—from idea and intake through data collection, model development, training, evaluation, deployment, operations, change management, and retiremen...
Episode 2 — Understand how AAISM questions map to real AI security work (Tasks 1–22) 14.02.2026 13:50
This episode explains how AAISM questions mirror real AI security work by testing whether you can connect governance decisions, risk assessments, and control evidence to a specific AI use case, rather than treating AI as a separate “special” security universe. You’ll learn to spot the exam’s recurring pattern: identify the AI asset and lifecycle phase, determine the accountable role, select the ri...
Episode 1 — Exam orientation and a spoken 30-day plan to pass AAISM (Tasks 1–22) 14.02.2026 15:28
This episode sets your baseline for what AAISM tests and how to use a simple spoken routine to cover Tasks 1–22 in 30 days without guessing what matters, focusing on how ISACA-style items reward clear governance, risk thinking, and control ownership over tool trivia. You’ll translate the task list into a weekly cadence that rotates governance foundations, risk workflow decisions, and technical con...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.