CISA: is it worth it?
The systems-audit credential that matters once your fincrime work becomes model validation, tuning governance and technology audit.
Last reviewed September 2, 2026
What it is and who runs it
CISA is ISACA's Certified Information Systems Auditor credential. It is not a financial crime credential at all — which is exactly why it carries weight in the corner of the field where the question is whether a monitoring system's controls, data lineage and change management would survive an audit.
Pricing is published: $575 for ISACA members, $760 for non-members, plus a $50 application fee. Maintenance is 120 CPE hours over three years plus an annual fee in the $45–$85 band, and there is a five-year IS audit or control experience requirement.
Issued by ISACA · official issuer page ↗
Current format and requirements on the issuer's site — we do not restate exam length, question counts or pass rates unless the issuer publishes them openly.
Who it's actually for
CISA serves fincrime technology and model-governance people: those who own tuning documentation, above-the-line and below-the-line testing, data-quality controls, and the evidence pack an examiner or internal audit asks for. It also suits AML practitioners moving into second-line oversight of systems rather than cases.
For an alert-queue analyst it is the wrong spend. Take it when governance responsibility arrives, not in anticipation of it.
FinCrime technology roles → · Transaction monitoring roles →
Live market demand
Loading live demand…
Cost of ownership
| Credential | Exam cost | Renewal | Prerequisite |
|---|---|---|---|
| CISA | $575 member / $760 non-member + $50 application | 120 CPE / 3 yrs + $45–$85 / yr | 5 yrs IS audit/control experience |
Figures are the verified ones we can source; where an issuer gates pricing we say so rather than estimate. Most institutions of any size reimburse both exam and renewal — ask at offer stage if you can.
When to choose it over the alternatives
Against CAMS: complementary rather than competing. CAMS says you understand the obligation; CISA says you can audit the system that discharges it. In technology-governance postings the pair reads strongly.
Against CRCM: CRCM is regulation breadth, CISA is control depth. Model validation and system audit work points to CISA.
How people prepare
ISACA's own review materials plus a live audit cycle is the common route. The distinguishing preparation for fincrime candidates is being able to explain a monitoring platform in control terms — inputs, lineage, thresholds, change control — rather than in typology terms.
How practitioners actually build these skills →
Training-partner offers coming — providers interested in reaching this audience: /partners.
Frequently asked
How much does CISA cost?
$575 for ISACA members and $760 for non-members, plus a $50 application fee; maintenance is 120 CPE over three years plus $45–$85 a year.
Is CISA useful in financial crime?
In the technology and model-governance corner, yes — tuning, validation and system audit. It is not a substitute for an AML credential in casework roles.
What experience does CISA require?
Five years of information systems audit, control or security experience, with the issuer's published substitutions.
Other credential guides
The default AML screen at US institutions: what it signals, what it costs to own, and when in a career it actually pays.
The investigator's credential: a deeper examination than the AML marks, and the right one if your days are fraud and forensic work.
The cross-discipline financial crime credential: respected, broader than CAMS, and screened for less often.
The US bank regulatory compliance mark — mid-career by design, and the one that spans lending and deposits as well as BSA.
The privacy credential financial crime teams meet at the data boundary — useful at the edges, not a fincrime mark.
The sanctions specialism from ACAMS: precise, narrow, and only worth taking once sanctions is genuinely your line.
The UK and EMEA ladder: graded coursework with University of Manchester association rather than a single exam.