ISACA (Information Systems Audit and Control Association) — Vendor Overview
V016 · IT Audit, Governance, Risk, Compliance · 4 active certifications · SA presence: Strong
Quick pitch: ISACA is the global leader in IT audit, risk, and governance certifications; CISA is mandatory or strongly preferred for IT audit roles at banks, insurance companies, and organisations subject to compliance audits (SOX, GDPR, etc.).
Company Snapshot
| Field | Detail |
|---|---|
| Full name | Information Systems Audit and Control Association |
| Founded | 1969 — established IT audit as a discipline |
| Headquarters | Schaumburg, Illinois, USA |
| Employees | ~300 globally (2026) |
| Revenue | Private non-profit; revenue estimates ~$80–120M annually |
| Listed | Non-profit |
| Core business | Develops and administers IT audit, governance, risk, and compliance certifications (CISA, CISM, CGEIT, CRISC); provides training and maintains frameworks. 100% certification and training revenue. |
| SA office | No direct office; strong partner network including TrackitSA, Westcon-Comstech, regional training providers |
What ISACA Does
ISACA is the global non-profit authority for IT audit, governance, and risk management. The organisation develops CISA (the global standard for IT auditors), CISM (IT security governance), CGEIT (IT governance), and CRISC (risk management) certifications. ISACA members and certified professionals maintain exceptionally high ethical standards and professional development requirements.
ISACA maintains approximately 168,000+ members globally with 50,000+ CISA holders. The organization is vendor-neutral and highly respected by regulatory bodies (SEC, central banks, audit firms). Competitors are vendor-specific programs and competing certifications (CompTIA Security+), but CISA remains the gold standard for IT auditors globally. The certification program is designed for audit professionals, IT managers, and governance specialists.
Certification Portfolio
Active certifications (4 total)
| Level | Cert Name | Code | Domain | Cost (USD) | Valid |
|---|---|---|---|---|---|
| Professional | CISA – Certified Information Systems Auditor | CISA | IT Audit | $760 | 3 yrs |
| Professional | CISM – Certified Information Security Manager | CISM | IT Security Governance | $760 | 3 yrs |
| Professional | CGEIT – Certified in the Governance of Enterprise IT | CGEIT | IT Governance | $760 | 3 yrs |
| Professional | CRISC – Certified in Risk and Information Systems Control | CRISC | Risk Management | $760 | 3 yrs |
Recommended starting cert
CISA (Certified Information Systems Auditor) — Professional-level credential validating expertise in IT audit, control, and assurance across 5 domains (processes, governance, information protection, service delivery, and risk). Suitable for internal audit professionals, external auditors, and IT managers. 4-hour exam; ~150 questions. 3-year validity. Prerequisites: 5 years IT audit/control experience (or equivalent education). ~4–6 months study.
Cert ladder for new starters
CISA (IT Audit) → CISM (Security Governance) or CRISC (Risk)
CGEIT (Governance specialist track)
Why ISACA Matters in 2026
CISA is mandatory or strongly preferred for IT audit roles at regulated financial institutions, insurance companies, and government agencies. LinkedIn shows 12,000+ open CISA-related job postings globally. CISA is required or preferred by major audit firms (Deloitte, EY, KPMG, Accenture) and regulatory bodies (Federal Reserve, SEC, central banks).
ISACA's frameworks (COBIT, Val IT, Risk IT) are industry standards for IT governance. CISA holders command premium salaries, particularly in financial services and regulated industries. The certification ecosystem is exceptionally healthy; ISACA invests heavily in training and community development. CISA remains in strong demand as regulatory requirements increase globally (GDPR, SOX, HIPAA, etc.).
Job Market Data
Global demand
| Metric | Value | Source | Date |
|---|---|---|---|
| Active job postings mentioning CISA | 12,000+ | LinkedIn Jobs | May 2026 |
| Growth YoY | +10% | LinkedIn Salary Insights | 2025–2026 |
| Top job title hiring | IT Audit Manager | May 2026 | |
| Top hiring countries | USA, UK, Canada, Australia, Singapore | May 2026 |
Common job titles requiring ISACA skills
| Job Title | Seniority | Median USD Salary | Median ZAR Salary |
|---|---|---|---|
| Internal Audit Specialist | Mid | $72,000 | R66,200/month |
| IT Audit Manager | Senior | $115,000 | R105,800/month |
| IT Risk Manager / CRISC | Senior | $125,000 | R115,000/month |
| Audit Director / CISA-Expert | Executive | $160,000+ | R147,200+/month |
South Africa Presence
Direct presence
ISACA has no direct office in South Africa but operates through a strong partner network. Primary partners include TrackitSA, Westcon-Comstech, and regional audit and compliance training providers. CISA is exceptionally valued in SA banking and government audit functions.
SA job market
South African banks (ABSA, Nedbank, FirstRand, Standard Bank, Investec) mandate CISA or equivalent for IT audit roles. Government agencies and state-owned enterprises (Eskom, Transnet, SARS) require CISA for compliance and governance roles. CISA is required by major SA audit firms (Deloitte, EY, KPMG, Accenture) for IT audit professionals.
Median salary for CISA-certified IT Auditor in SA is R105,800/month (approximately $5,800 USD), rising to R147,200+/month for IT Risk Manager and audit leadership roles.
SA training providers
| Provider | Cert(s) offered | URL |
|---|---|---|
| TrackitSA | CISA, CISM, CRISC | trackitsa.co.za |
| Westcon-Comstech Academy | CISA, CISM | westcon.co.za |
| ISACA Learning Hub | All ISACA certs | isaca.org/learning |
| Linux Academy / A Cloud Guru | CISA | acloudguru.com |
Vendor Ecosystem
Key technologies and platforms
- COBIT framework (IT governance standard)
- Val IT framework (IT value delivery)
- Risk IT framework (risk management)
- ITIL (IT service management)
- ISO 27001 / 27002 (information security)
- NIST Cybersecurity Framework
- SOX, GDPR, HIPAA compliance requirements
Complementary vendors and certs
| Complementary Vendor | Why they pair well |
|---|---|
| ISC² (CISSP) | Security professional complements IT auditor |
| COBIT / ITIL certifications | Governance frameworks used in IT audit |
| Internal audit certifications (CIA) | Broader audit knowledge complements IT audit |
| Compliance certifications (GDPR, SOX) | Regulatory knowledge supports audit career |
Community and resources
| Resource | Type | URL |
|---|---|---|
| ISACA Learning Hub | Official | isaca.org/learning |
| ISACA Community of Interest | Community | isaca.org/community |
| r/isaca | Community | reddit.com/r/isaca |
| ISACA YouTube | Learning | youtube.com/c/ISACAChannel |
Vendor History & Roadmap
Key milestones
| Year | Event |
|---|---|
| 1969 | Founded; established IT audit as a discipline |
| 1978 | Launched CISA certification |
| 2000 | Developed COBIT governance framework |
| 2010 | Introduced CISM and Risk IT frameworks |
| 2012 | Launched CRISC (risk management) |
| 2018 | Introduced CGEIT (governance) specialisation |
| 2023 | Expanded focus on AI governance and risk |
| 2024–2026 | Focus on AI audit, data governance, cloud compliance |
| 2026 | AI governance and supply chain risk becoming certification focus |
Outlook
ISACA is firmly positioned as the global leader in IT audit, governance, and risk certifications. The organisation's non-profit status and focus on audit and governance ensure long-term relevance in regulated industries. For certification professionals, CISA remains secure and in strong demand, particularly in financial services and regulated organisations. CISM and CRISC specialisations are increasingly sought after. Exam content will evolve to include AI governance, cloud security auditing, and third-party risk management over the next 12–24 months.
Frequently Asked Questions
Q: Is ISACA worth investing in for my career? Yes, especially if you want an audit or governance career. CISA is mandatory or strongly preferred for IT audit roles at regulated organisations.
Q: How often do ISACA certs expire? All ISACA certifications expire after 3 years. Renewal requires earning 20 Continuing Professional Education (CPE) credits annually or passing a renewal exam.
Q: Are ISACA certs recognised in South Africa? Absolutely. CISA is mandatory for SA IT audit professionals at banks and regulated organisations.
Q: What's the best cert to start with from ISACA? CISA. It requires 5 years IT audit experience or equivalent. Expect 4–6 months study with extensive audit knowledge requirements.
Related Content
- Cert Roadmap → — Full progression diagram
- Ecosystem Deep Dive → — Technology landscape, tools, job market
- Individual Cert Files → — Per-exam breakdowns
Sources
| # | Source | URL | Used for |
|---|---|---|---|
| 1 | ISACA Credentialing | isaca.org/credentialing | Company data, cert portfolio |
| 2 | ISACA About | isaca.org/about | History, mission |
| 3 | LinkedIn Jobs – CISA | linkedin.com/jobs | Job market data |
| 4 | TrackitSA (SA Partner) | trackitsa.co.za | SA presence, training |
Template version: 2026-05-03 | Maintained by IT Career Roadmap