Anyway, it was good experience - observing the QSA program from inside (basically, the ISA is the same as QSA but without ability to work as QSA). Now I even better understand the reason for ambiguous definitions and weird interpretations of PCI. The PCI DSS consists of 12 main requirements. In order to validate each of 12 requirements during the audit, QSA is provided with Testing Procedures which are listed in the same document. There are total of 310 (!) testing procedures. The net duration of training is about 10 hours or 600 minutes (2 days minus time for introduction, final exam, and breaks) which leaves the instructor with less than 2 minutes per testing procedure - including explanation, samples, questions, knowledge check etc.
Note: Information about PCI DSS Requirements (including Testing Procedures) and QSA Training is publicly available which allows to calculate the numbers above without any "inside" knowledge.