You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The Certified Information Systems Auditor (CISA) certification is the global standard for professionals who audit, control, monitor, and assess an organization's information technology and business systems. It validates your ability to apply a risk-based approach to audit engagements, covering everything from IS auditing processes to the protection of information assets. Earning CISA demonstrates your expertise in IT audit and positions you for career growth in a field where professionals earn an average salary of US$149,000+.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The Certified Information Systems Auditor (CISA) certification, offered by ISACA, is world-renowned as the standard of achievement for those who audit, control, monitor, and assess an organization's information technology and business systems. It affirms your ability to apply a risk-based approach to audit engagements, ensuring that IT and business systems are protected, controlled, and provide value to the organization. With a focus on emerging technologies like AI and blockchain, CISA ensures IT audit professionals stay current on the latest technology trends and advancements.
Achieving CISA certification showcases your expertise and asserts your ability to handle the challenges and responsibilities of a modern IT auditor. The certification covers five key domains: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development & Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. CISA is globally accepted and recognized, required by many organizations and government agencies, and proves to employers that you are ready to add value to their enterprise.
The CISA certification is designed for IT professionals who are responsible for auditing, controlling, monitoring, and assessing an organization's information technology and business systems. It is ideal for mid to advanced-career IT professionals looking for leverage in career growth, including IT auditors, IS auditors, IT consultants, and security professionals. Candidates typically have experience in IT audit, control, security, or governance and are seeking to validate their expertise and advance their careers. The certification is also valuable for professionals who want to demonstrate their ability to apply a risk-based approach to audit engagements and stay current with emerging technologies.
ISACA recommends that candidates have experience in IT audit, control, security, or governance. While there is no formal prerequisite, a minimum of five years of professional work experience in information systems auditing, control, or security is required for certification. Experience in information systems auditing, control, or security; Knowledge of IT governance and management; Understanding of information systems acquisition, development, and implementation; Familiarity with information systems operations and business resilience; Awareness of protection of information assets and cybersecurity principles
Every domain and objective ISACA measures, with the weight they carry on the exam.
The official ISACA exam outline · checked 30 July 2026 · See the source
Everything ISACA publishes about sitting it, and nothing we inferred.
Pass the CISA certification exam.
The path ISACA lays out, how the credential is kept, and where to book.
Step-by-step path to Certified Information Systems Auditor
CISA certification requires renewal through earning Continuing Professional Education (CPE) credits. Certification holders must adhere to the Continuing Professional Education Policy to maintain their credential. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.
Register for the exam through PSI, ISACA’s authorized testing partner.
Schedule your examVisit the official ISACA certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe AAIA (Advanced in AI Audit) certification is designed for professionals who hold a CISA certification or another qualified designation. It builds on the expertise validated by CISA and focuses on AI-specific audit skills.
No, there is no prerequisite certification required to take the CISA exam. However, to earn the CISA credential, you must meet the experience and ethical requirements.
Yes, you can reschedule your CISA exam anytime without penalty during your eligibility period if done a minimum of 48 hours prior to your scheduled testing appointment.
You must present a government-issued identification that matches the name on your ISACA account. If you are creating an account, ensure your name matches what appears on your government-issued ID.
No, the CISA exam consists of 150 multiple-choice questions. There is no hands-on or lab component.
ISACA does not specify a retake policy on the official page. Candidates should refer to the exam candidate guide or contact ISACA for details.
ISACA members receive a discounted exam fee of US$575.00 compared to the non-member fee of US$760.00. No other discounts or vouchers are mentioned on the official page.
The official page does not specify the exact timing for score release. Candidates should refer to the exam candidate guide or contact ISACA for details.
CISA is designed for IT professionals who audit, control, monitor, and assess an organization's information technology and business systems. It is a must-have for mid to advanced-career IT professionals looking for leverage in career growth.
ISACA certifications require renewal through earning CPE credits. Passing a different exam may contribute to CPE credits, but the official page does not specify that passing another exam automatically renews CISA.
Every domain, every objective, and every concept ISACA measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official ISACA exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
28 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 24 objectives, 204 concepts written under them, and free questions against every one. When ISACA changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.