CISA (Certified Information Systems Auditor), awarded by ISACA, is one of the certifications Learnsignal's existing cybersecurity certifications roundup mentions only briefly — it deserves a closer look, because it's genuinely one of the more relevant technology certifications for finance and audit professionals rather than a purely IT-security credential.
What CISA is and who it's for
CISA validates expertise specifically in auditing, controlling, and assuring information systems — distinct from certifications like CISSP or Security+, which focus on building and defending systems rather than auditing them. It's aimed at IT auditors, internal auditors moving into technology risk, IT risk and assurance managers, and increasingly external auditors whose audit work now routinely touches IT general controls and systems-based financial reporting. For accountants with an ACCA or CIMA background who move into internal audit, IT audit, or risk assurance roles, CISA is often the specific credential employers look for that a general accounting qualification doesn't cover.
Exam structure
According to ISACA's own 2026 exam content outline, the CISA exam consists of 150 questions across five domains, weighted as follows: Information Systems Auditing Process (18%), Governance & Management of IT (18%), Information Systems Acquisition, Development & Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The exam runs four hours and is scored on ISACA's scaled 200–800 system, with 450 needed to pass — a format shared across ISACA's certification family, including CISM and CRISC.
Eligibility and experience requirement
Unlike many entry-level IT certifications, CISA isn't something a career-changer can sit immediately. ISACA requires candidates to have a minimum of five years of professional experience in information systems auditing, control, or security work before they can be awarded the certification, though passing the exam itself has no prior-experience prerequisite — candidates can sit the exam first and satisfy the experience requirement afterward, within a set window. Certain other qualifications and a portion of general education can be substituted for up to a few years of that experience requirement, which is worth checking against ISACA's current substitution table for anyone close to the threshold. Maintaining the certification also requires ongoing continuing professional education once awarded, which is another point of overlap with the CPD obligations ACCA and CIMA members are already used to tracking.
How CISA complements ACCA and CIMA
Neither the ACCA nor CIMA syllabus covers IT audit methodology, systems-based controls testing, or IT governance frameworks in any real depth — those topics appear only tangentially within broader audit or risk management papers. CISA fills that gap directly, and because it's internationally recognised and vendor-neutral, it pairs naturally with an accounting qualification for anyone whose career is heading toward internal audit, IT risk, or systems assurance rather than traditional financial reporting or management accounting.
Career paths
CISA holders typically move into roles like IT Audit Manager, Cybersecurity Auditor, IT Risk and Assurance Manager, or Head of Internal Audit in organisations with significant technology risk exposure — which, in practice, now means most organisations of any size. Demand has grown alongside the expansion of IT general controls testing within statutory audits and the increasing regulatory focus on operational resilience and technology risk across financial services. That trend shows no sign of slowing, which is part of why CISA is increasingly listed as a preferred or required qualification in senior internal audit and risk-assurance job postings.
CISA versus CISM
The two certifications are easy to confuse because both come from ISACA and share the same exam format and scoring scale, but they serve different career tracks. CISA is built around auditing and assurance — testing whether systems and controls are working as intended, from an independent, evaluative standpoint. CISM, by contrast, is a management-track certification for people actually running an information security programme, covering governance, risk management, and incident response from an operational leadership perspective rather than an audit one. Some experienced professionals eventually hold both, since audit and security-management perspectives are genuinely complementary, but most candidates choose based on which side of the fence — assurance or operational leadership — their career is heading toward.
FAQs
Do I need an IT background to sit CISA?
No formal IT background is required to sit the exam, but the five-year professional experience requirement for certification must be in information systems auditing, control, or security, so most candidates come from audit, risk, or IT backgrounds already.
Is CISA better than CISSP for someone with an accounting background?
They serve different purposes. CISA focuses on auditing and assuring information systems, which aligns closely with audit and risk-assurance career paths; CISSP focuses on designing and managing security programmes, which is a more technical, security-operations-oriented path. Accountants moving into audit-adjacent roles typically find CISA the more directly relevant of the two.
How long does the exam take and how is it scored?
The exam is 150 questions over four hours, scored on a scaled 200–800 basis with 450 required to pass — the same scoring model ISACA uses across CISA, CISM, and CRISC.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience helping students advance their professional careers.
View all posts by Learnsignal Education Team
