From CISA to CIA: Your Application and Preparation Guide
Active CISA holders can earn CIA through a one-part Challenge examination. Start by confirming your certification is active, preparing proof of good standing and applying through The IIA. Passing the CISA exam alone does not qualify you for this route.
The task is to extend your existing audit knowledge across the internal-audit function. Your preparation should follow the current Challenge syllabus, including responsibilities beyond technology assurance.
If you already work in IT audit, you will recognize several concepts in the Challenge syllabus. The preparation decision is which topics you can apply confidently and which need closer study.
This guide separates qualification, application and preparation. If you are still comparing the two credentials, start with CIA vs CISA.

Can CISA Holders Take the CIA Challenge Exam?
The entry requirement is an active CISA designation. The IIA asks for public-registry proof of good standing and government-issued photo identification. Separate proof of experience is not required for this Challenge pathway. See The IIA’s CISA eligibility instructions.
| Your situation | What to do |
|---|---|
| You hold an active CISA | Check your registry record and gather the application documents. |
| You passed CISA but are not yet certified | Complete ISACA’s certification process before applying through this route. |
| Your CISA is not active | Resolve your certification standing with ISACA before relying on it for eligibility. |
ISACA separates passing its exam from obtaining the certification. The latter also involves an application and its professional requirements. An exam-pass notification is therefore different from evidence that you hold the designation. Check ISACA’s certification process.
Certification and Membership Are Different
ISACA and IIA memberships are independent. Eligibility for this Challenge pathway comes from your active CISA designation, while IIA member pricing depends on an active IIA membership recognized at the time of purchase.
Candidates residing in the UK/Republic of Ireland or South Africa must currently be IIA members to apply for the CIA Challenge Exam. See The IIA’s country-specific membership requirement.
Documents to Prepare for the CISA Challenge Route
Get the evidence ready before starting the payment process. Use current records, and check the details against your certification and CCMS profiles.
- Verify your CISA standing. ISACA’s public verification tool uses the certification type, certification number and last name exactly as recorded in your profile.
- Obtain current proof. Follow the verification service and application instructions for the evidence required. An old certificate is not a substitute for checking current standing.
- Prepare valid government-issued photo ID. Make sure the document is readable and the name agrees with the profile you will use for the application.
- Check CCMS details. Review your name, primary address and email. Keep access to that email because application notices and requests will arrive there.
Use ISACA’s Verify a Certification service to check the record. Its guidance explains that the annual certification status matters even where a certificate displays a longer cycle date.
If verification does not find your record, recheck the number and exact profile name, then contact ISACA if necessary. Follow CCMS’s current upload instructions for document format. Use the accepted format requested in CCMS, and resolve any evidence query before booking.
How to Apply for the CIA Challenge Exam Through CCMS
CCMS is The IIA’s Certification Candidate Management System. Apply first, obtain approval, then register and book the exam. Keep those stages separate.
The steps below follow The IIA’s published global CCMS process. Pricing, taxes and some administrative arrangements can differ where certification is handled through a National Institute. Follow the route shown for your country before paying. Check The IIA’s global administration guidance.
1. Confirm Your CISA and Prepare the Documents
Use the checklist above. Resolve certification-standing or profile issues before submitting information that conflicts with your supporting records.
2. Select the CISA Challenge Pathway
Sign in to CCMS. The IIA’s published sequence uses “Apply for Certified Internal Auditor”, followed by “CIA Challenge Program for Qualified Information Systems Auditors”.
3. Submit the Application and Complete Approval
Pay the application fee and upload the requested documents. Check for follow-up requests. The application must be approved before exam registration.
The current handbook gives you 90 days after The IIA processes your application payment to complete the application, including required documentation and on-screen steps. If you do not finish within those 90 days, the application expires and you must reapply. This is separate from the exam-registration authorization period.
4. Register for the Exam
After approval, open Manage My Program in CCMS, select the examination and complete registration/payment. Check the authorization dates before planning a sitting.
5. Book the Pearson VUE Appointment
Use Access Pearson VUE through CCMS. Select an available test-center appointment within both an offered testing window and your authorization period. Save the confirmation and check its date, time and location.
The current Candidate Handbook explains application completion and booking. For arrival, identification and testing-room rules, read our CIA exam at Pearson VUE guide.
Already Enrolled in the Traditional CIA Program?
Ask CCMS Help about switching before purchasing another application. Before requesting a program change, compare Challenge and three-part CIA, including existing passes and remaining fees. The IIA requires deactivation of the traditional program and does not refund or transfer its fees between these programs. Read the official switching FAQ.
Need help organizing these steps? Our team supports prospective and enrolled learners with documents, application planning and registration guidance. Ask about application and preparation support.
CIA Challenge Fees and Deadlines for CISA Holders
Under the published standard USD schedule, application plus one exam registration totals $995 for IIA members or $1,625 for nonmembers. Membership dues, preparation, retakes and possible taxes are separate.
| Official item | IIA member | Nonmember |
|---|---|---|
| Application | $150 | $380 |
| Exam registration | $845 | $1,245 |
| First-attempt total | $995 | $1,625 |
Under the standard published schedule, the member-rate application and first exam registration are $630 lower than the nonmember schedule. Whether joining produces a net saving depends on your local membership dues, any joining fee or tax, and whether membership is mandatory in your market.
Fee components: The IIA’s published pricing. Totals are application plus examination arithmetic.
Outside North America, check your National Institute’s pricing and applicable taxes. Verify active IIA membership before purchasing a member-priced item. For a fuller budget, use our CIA certification cost guide.
Applications
The credential-based CISA route is open year-round. It is separate from the experienced-professional pilot.
Exam Authorization
Registration authorizes 180 days or until program expiry, whichever comes first. Challenge extensions are unavailable.
Testing Windows
The regular months are February, June, September and November. Local arrangements and appointment availability can differ.
Check the exact expiry shown in CCMS. The CISA route has a three-year program eligibility period, but an individual registration does not remain valid for that entire period. See our CIA Challenge dates and deadlines guide for current windows and local exceptions.
What CISA Holders Need to Study for the Challenge Exam
The current unified syllabus applies from 1 June 2026. It covers five content areas in one 150-question, 180-minute examination. Your CISA qualification determines the entry route, not a reduced list of topics. Check The IIA’s current syllabus.
| Current content area | Weight | Review priority |
|---|---|---|
| Internal Audit Professionalism and Quality | 20% | Mandate, independence, professional conduct and quality responsibilities. |
| Internal Audit Operations and Audit Plan | 15% | Risk-based priorities, resources and coordination of assurance. |
| Engagement Planning | 20% | Objectives, scope, criteria, risks and the work program. |
| Engagement Performance | 25% | Procedures, evidence, analysis and supported conclusions. |
| Engagement Results and Monitoring | 20% | Findings, communication, action plans and effective follow-up. |
For detailed topics and the official PDF, read the CIA Challenge Exam syllabus guide.
Extend Your Audit Perspective Beyond IT
CISA already covers audit planning, evidence, reporting and professional conduct. Use that foundation while checking how the Challenge syllabus applies those ideas across the organization. ISACA’s CISA outline describes that existing coverage.
In our preparation approach, CISA holders should pay particular attention to internal-audit function governance, chief audit executive responsibilities, audit strategy and resources, non-IT business processes, engagement conclusions, residual risk and communication with the board and senior management. These are study priorities inferred from the two outlines, not official topic exemptions.
For each scenario, identify the process objective, who owns the risk and what evidence supports the next audit action. A system can operate as designed while the business process still has weak authorization or monitoring.

| Build on | Check in your preparation |
|---|---|
| Technology risks and controls | Operational and business-process risks, including how controls support organizational objectives. |
| Audit evidence and testing | Evidence sufficiency and appropriate procedures across financial and non-IT engagements. |
| Reporting weaknesses | Communication with senior management and the board, including unresolved risk. |
| Remediation tracking | Whether a management action has been implemented and is working. |
This is preparation guidance, not an official exemption or percentage-overlap map.
Study the Global Internal Audit Standards alongside questions. Focus on responsibilities: management owns processes and controls, while internal audit evaluates them and communicates its conclusions.
How to Prepare for the CIA Challenge Exam as a CISA Holder
Start with a Full-Syllabus Diagnostic
Attempt questions across all five areas before assuming your strongest work topics will also be your strongest exam topics. Record the reason for each error: missing knowledge, misunderstood responsibility, weak evidence analysis or an incorrect next step.
Study Weaker Topics, Then Practise by Area
Use current materials and review the relevant Standards. After each practice set, explain why the best answer fits the scenario and why the closest alternative fails. Return to the concept when your explanation is uncertain.
Complete Mixed, Timed Mocks
Practise the full examination format, including movement between different subject areas. Review recurring errors after each attempt. The exam averages 72 seconds per question, calculated from 180 minutes and 150 questions, but individual questions will take different amounts of time.
Discuss repeated weaknesses with faculty, then choose an appointment within your authorization period. Your preparation plan should reflect diagnostic results, existing experience and the target window.
Good IT Access Controls Do Not Prove Good Payment Controls
A company’s ERP restricts vendor-record access to authorized users. However, those users can change supplier bank details without independent approval. Appropriate access permissions do not establish that each change is valid.
An internal-audit review should examine the business authorization, change records and evidence of independent checks. Adding another password rule would leave the approval weakness unresolved. This illustrates why preparation should connect technology controls with the process they support.
Original EduDelphi teaching illustration. It is not an official, recalled or live IIA exam question.

Use our Challenge preparation and readiness checklist to review unfamiliar questions, pacing and recurring mistakes before your attempt.
CISA to CIA Challenge Exam FAQs
Does passing CISA automatically give me CIA?
No. Passing CISA and obtaining CISA certification are separate stages. An active CISA holder can apply through the Challenge route, then must pass its examination and complete the applicable program requirements.
Do CISA holders need to submit separate work-experience evidence?
The IIA does not require separate proof of experience for this Challenge program. You still need the active CISA designation used for eligibility. That does not remove ISACA’s requirements for obtaining CISA itself.
Is IIA membership compulsory?
Membership is not generally required, but The IIA requires it for candidates residing in the UK/Republic of Ireland and South Africa. Local National Institute arrangements can differ. ISACA membership is separate. Check The IIA’s membership guidance before paying.
How long should a CISA holder study?
Use your diagnostic results to set the plan. An experienced auditor may already understand several subjects, while function management or non-IT controls may need closer review. Set weekly study time, complete the coverage and leave time for full mocks and error review.
Can I prepare with older CISA Challenge materials?
Compare them with the current five-area syllabus. Older resources may explain established concepts but miss changes in the outline or professional standards. Choose a primary preparation system explicitly covering the current blueprint.
What is the passing score?
The CIA reporting scale runs from 250 to 750, with 600 required to pass. A scaled score of 600 does not mean 80% correct. There is no published universal raw-score percentage that guarantees a pass. See the official handbook.
Is there an official pass rate specifically for CISA holders?
We have not verified a current official CISA-holder Challenge pass-rate table. Traditional three-part CIA pass rates describe a different examination population. Use them neither as Challenge rates nor as a personal prediction of success.
When will I receive my result and CIA designation?
From the September 2026 testing window, official Challenge results are issued within three weeks of the exam date, with email notification. The current process no longer provides the immediate unofficial Challenge result used previously. The CISA-route FAQ lists a further 7-14 business days for the designation to appear after program completion and remaining requirements. Check current result timing.
What happens if I do not pass?
A further attempt requires new registration/payment and an eligible appointment after the minimum 30-day wait. The regular Challenge route allows up to eight total attempts within program eligibility. Review your result and study gaps before choosing another window. Read the retake and timing guidance.
Do I maintain CIA and CISA separately afterward?
Yes. They remain separate credentials with their own renewal and continuing-education rules. Plan for both organizations’ requirements, even where an activity may qualify under each policy. Start with our CIA CPE and renewal guide and ISACA’s CISA maintenance instructions.
CISA-Focused Preparation and Application Support
EduDelphi supports prospective and enrolled learners with syllabus-gap reviews, application documents, registration planning and exam preparation. Faculty-led teaching, an organized LMS, 3,000+ practice and revision questions, multiple full-length exam simulators and direct faculty support help you work through the current syllabus.
The IIA decides eligibility and awards CIA. Our team helps you prepare and navigate the process.

Get Your CIA Challenge Preparation Plan
Discuss your CISA background, identify topics to prioritize and get guidance on your application and exam preparation.
Explore the CIA Challenge Exam preparation course or send an enquiry for a personalized syllabus-gap review.
Meet Tanvi P. and Shyam Sarrof
Tanvi P.
CIA, CFE, CISA, CAMS
Tanvi brings 20+ years of international experience across audit, investigations, financial crime, risk, controls and compliance. Her background includes Standard Chartered, Citi’s Global Investigations Unit and KPMG Forensic Services.
Her CISA and CIA credentials bring both technology-assurance and internal-audit perspectives to preparation. Teaching focuses on scenario interpretation, evidence and the reasoning behind close answer choices.
Shyam Sarrof
CPA (USA), CMA (USA), ACA, ACMA, CS, CFA, ACTM, MBA, B.Com (H)
Shyam has 13+ years of CIA training experience and 22+ years across audit, controls, finance, risk and advisory. He connects engagement decisions with business processes, helping learners understand how objectives, evidence and control weaknesses affect audit conclusions.





















