Not every CPA who reads about AAIA qualifies for it, and most articles on this topic won't tell you that part. Holding a CPA license is one of ISACA's accepted designations, but it comes with a condition CISA doesn't: your role needs an IT audit or advisory focus, not just an active license.
That condition filters out more CPAs than it lets through. Most CPA work, like tax, financial statement audit, general accounting, doesn't clearly meet it. Some do, and knowing which side of that line you're on matters more than knowing AAIA exists at all.
This article walks through what counts, why the newer CPA Exam discipline choices matter as context (not as the requirement itself), and why this is worth tracking even if you don't clear the bar today.
Does Being a CPA Automatically Qualify You for AAIA?
No. An active CPA license gets you onto ISACA's list of accepted designations, but the role-focus condition still applies. ISACA's own language asks whether your actual role has an IT audit or advisory focus, not whether your license is active in good standing alone. A CPA doing corporate tax work and a CPA running SOC engagements hold the identical credential, and only one of them clearly fits what ISACA is asking for.
What Counts as "IT Audit or Advisory" for a CPA
ISACA doesn't publish a precise checklist, so this comes down to what your role involves day to day. Some reasonable anchors: running or supporting SOC 1 or SOC 2 engagements clearly counts. IT general controls testing as part of a financial statement audit likely counts. Pure tax preparation, general ledger accounting, or financial statement audit work with no IT-specific component is a much harder case to make, even though the license itself is identical.
SOC engagement work specifically is worth unpacking, since it's the clearest example. A SOC 2 engagement evaluates a service organization's controls around security, availability, processing integrity, confidentiality, and privacy, testing access provisioning, change management, and system monitoring rather than financial statement balances. A CPA running these engagements is already doing IT-focused audit work in substance, even though the license and the designation "CPA" look identical to a colleague who's never touched one. That distinction, substance over title, is exactly what ISACA's role-focus condition is trying to capture.
Building the Role-Focus Track Record If You're Not There Yet
If your current work doesn't clearly meet the bar, the realistic path runs through your engagement mix, not a new credential. Ask to join the next SOC engagement your firm runs, even in a supporting capacity. If your firm doesn't do SOC work, IT general controls testing within a standard financial statement audit is a more accessible entry point, since most audits of meaningful size touch it somewhere. Making the shift explicit and building a documented pattern over a few engagement cycles matters more than any single assignment.
Looking for some exam prep guidance and mentoring?
Learn about our personal mentoring

The ISC Discipline Is a Signal, Not the Requirement
Since 2024, the CPA Exam has used a core-plus-discipline structure: three required Core sections (Auditing and Attestation, Financial Accounting and Reporting, Regulation) plus one Discipline section chosen from Business Analysis and Reporting, Information Systems and Controls, or Tax Compliance and Planning. ISC is the one built around IT audit, SOC engagements, data management, and security controls, the closest thing the CPA path has to AAIA's own territory.
Here's the nuance worth getting right: choosing ISC on your exam doesn't automatically satisfy AAIA's role-focus condition, and not choosing it doesn't automatically disqualify you either. ISACA's condition is about your current role, not which discipline you tested in years ago. An ISC-background CPA now working in general tax doesn't clearly qualify. A CPA who chose a different discipline but works in IT audit today very well might. Treat an ISC background as a strong signal of fit, not as the actual qualifying mechanism.
Why This Matters for Financial Audit Even If You Don't Qualify Yet
AI isn't staying confined to IT systems. It's moving directly into the general ledger, transaction classification, and reconciliation work that sits at the center of traditional financial audit, which changes what auditors need to evaluate regardless of whether their role is formally labeled "IT audit." One Forbes piece on AI reshaping accounting put the concern plainly: as AI agents take over more routine accounting work, professional skepticism, the skill that lets an auditor look at a confident, polished output and say "I don't buy it," is at real risk of eroding if it isn't trained deliberately.
That shift is already showing up in real audit relationships. Coverage of a recent AI-native accounting platform working directly with two of the Big Four described auditors needing to trace material transactions back through an AI agent's decisions, reconstructing what the system relied on and why it reached a given result, work that looks a lot more like AI audit than traditional financial statement review. If your role doesn't clearly meet AAIA's bar today, it may well move in that direction regardless of what your CPA discipline happened to be.
The regulatory side is starting to catch up too. The PCAOB, which oversees audits of U.S. public companies, is one of the bodies eventually expected to formalize how AI-assisted work gets evaluated in an audit, which means the informal, ad hoc way most firms are handling AI-touched engagements right now won't stay informal indefinitely. CPAs who build AI-specific audit judgment now are positioning ahead of that formalization rather than reacting to it once it arrives.
Certification in 3 Days
Study everything you need to know for the AAISM exam in a 3-day bootcamp!
Frequently Asked Questions
It's a reasonable indicator that your background aligns with what ISACA is looking for, but it isn't what ISACA evaluates. Your current role is. Don't assume an ISC background alone clears the bar, and don't assume its absence rules you out either.
If you don't currently meet the role-focus condition, you can't register for AAIA yet regardless of interest. Worth tracking the space and how AI is entering financial audit generally, so that if your role does shift, you're not starting from zero.
It affects the path more than the outcome. Larger firms with dedicated SOC or IT audit practices make it easier to rotate into qualifying work explicitly. At a smaller firm without a separate IT audit function, the more realistic route is volunteering for the IT-controls component of whatever financial statement audits your firm already runs, which exists in some form on most engagements of real complexity even without a dedicated SOC practice around it.
Destination Certification Bridges the Role-Focus Gap
For the CPAs who do clear that role-focus bar, SOC engagement work, IT controls testing, anything with a genuine IT audit or advisory component, AAIA is a specific, structured way to formalize AI-specific audit skills your CPA license alone doesn't test.
Once your engagement mix clears the role-focus bar, DestCert's self-paced AAIA MasterClass gives you a workbook, exam strategy videos, a 90-question practice test, and a student Discord and email support while you prepare.









