CISA: the certification that owns IT audit
Some certifications are advantageous; CISA is closer to mandatory. Job adverts for IT audit roles in South Africa's banks, auditors-general and Big Four firms list it not as preferred but as required — the credential effectively defines its profession.
ISACA's exam covers five domains: the audit process itself, IT governance, systems acquisition and development, operations and resilience, and information asset protection. The perspective throughout is assurance — can you gather evidence and form defensible conclusions about whether controls work?
Experience requirements (five years, with substitutions for education) mirror the CISSP model: pass the exam early, bank it, and certify as the experience accrues.
The career economics are compelling. IT auditors start in structured graduate-adjacent programmes, move through senior auditor to audit management, and frequently exit sideways into better-paid risk and governance leadership — CISA remains the passport at every step.
Preparation rewards structured study: the exam tests ISACA's specific framing of concepts, which instructor-led courses drill efficiently.