
The AAISM certification—ISACA’s Advanced in AI Security Management credential—is designed for experienced security leaders who already hold an active CISM or CISSP. It validates the ability to govern enterprise AI, manage AI-specific risk, and select controls across the AI lifecycle. The exam has 90 multiple-choice questions, lasts 150 minutes, and covers three domains. Exam fees are US$459 for ISACA members and US$599 for non-members. Candidates must pass, apply, pay US$50, and maintain continuing education requirements to remain certified.
The AAISM full form is Advanced in AI Security Management. ISACA created the credential for established cybersecurity professionals who must manage the security, governance and operational risks introduced by enterprise artificial intelligence.Unlike introductory AI certificates, theISACA AAISM certification is not intended to teach basic machine learning terminology. It builds on the security-management knowledge already demonstrated through CISM or CISSP.The credential focuses on decisions such as:
In practical terms, ISACA Advanced in AI Security Management AAISM helps security leaders move from protecting conventional applications to governing systems whose behaviour may change as data, models and user interactions evolve.
The AAISM cert is best suited to experienced professionals involved in security leadership, risk management, governance, architecture, privacy or technology assurance.Strong candidates include:
Candidates should already understand security governance, risk treatment, incident management and control design. ISACA also recommends some experience assessing, implementing or maintaining AI systems.This is not an entry-level credential. A professional who is new to cybersecurity should first build broader security knowledge before starting an AAISM course.
The official AAISM certification requirements are clear: candidates must hold an active CISM or CISSP certification.Passing the examination alone does not automatically award the credential. To become certified, you must:
Candidates have five years after passing the examination to apply for certification.
The ISACA AAISM exam measures applied judgement rather than simple recall. Every question presents four answer choices and asks candidates to select the correct or best response.
| Exam Detail | Official Information |
| Exam name | Advanced in AI Security Management |
| Number of questions | 90 multiple-choice questions |
| Exam duration | 2.5 hours or 150 minutes |
| Delivery | PSI testing centre or remote proctoring, where available |
| Languages | English, Spanish and Japanese |
| Passing score | 450 on a 200–800 scale |
| Eligibility period | Six months after registration |
| Member exam fee | US$459 |
| Non-member exam fee | US$599 |
There is no penalty for an incorrect response, so every question should be answered. ISACA uses scaled scoring, which means a score of 450 does not represent a simple percentage calculation.Residents of India, mainland China and Hong Kong must currently take the examination at an authorised testing centre; remote proctoring is not available in these locations. Candidates should confirm the latest delivery rules before registering.
The official AAISM syllabus contains three domains. Preparation time should reflect the weighting, but candidates should not ignore any domain because the final score is calculated across the complete exam.
| Domain | Weight | Main Focus |
| AI Governance and Program Management | 31% | Governance structures, policies, data lifecycle, programme management, business continuity and incident response |
| AI Risk Management | 31% | Risk assessments, risk thresholds, threat management, vulnerability management, vendors and supply chains |
| AI Technologies and Controls | 38% | AI architecture, model lifecycle, data controls, privacy, ethics, trust, safety, monitoring and security controls |
This domain examines whether candidates can align AI security with enterprise objectives.You should understand stakeholder responsibilities, applicable frameworks, regulatory expectations, acceptable-use policies and AI asset management. You must also know how to incorporate AI threats into business continuity and incident response plans.A key exam distinction is the difference between governance and management. Governance sets direction, accountability and risk boundaries. Management implements programmes, procedures and controls within those boundaries.
This section focuses on identifying, analysing and treating AI-specific risk.Candidates should be prepared to assess:
A mature response does not attempt to eliminate every risk. It prioritises threats according to business impact, likelihood, legal obligations and the organisation’s approved risk appetite.
As the largest domain, this area deserves the greatest share of study time.It covers secure AI architecture, model selection, training, validation, deployment, monitoring and retirement. Candidates must also understand privacy controls, explainability, robustness, human oversight and trust-and-safety mechanisms.The exam does not require candidates to become data scientists. However, security managers must understand AI components well enough to challenge insecure designs and translate technical weaknesses into business risk.
The official AAISM exam cost is:
The AAISM exam fee is non-refundable and non-transferable. After passing, candidates pay an additional US$50 certification application fee. The full AAISM certification cost may also include:
The annual AAISM maintenance charge is US$20 for members and US$35 for non-members. Credential holders must report at least 10 relevant CPE hours annually and 30 CPE hours across a three-year reporting period. They must also maintain an active CISM or CISSP. Therefore, comparing only the registration price can underestimate the real AAISM cost.
Effective AAISM certification training should combine domain knowledge with scenario-based decision-making.ISACA offers several official preparation resources:
The official question database contains more than 200 questions and provides six months of access. ISACA’s virtual workshop includes instructor-led preparation, the review manual, question database and examination registration. When comparing an AAISM online course or external AAISM training course, check whether it:
A reliable AAISM study guide should help you connect concepts rather than memorise isolated definitions. Your AAISM study material should show how governance, risk, architecture, privacy, vendor management and incident response influence one another.
Map every topic in the examination content outline against your current knowledge. Mark each area as strong, moderate or weak.
Spend more time on AI architecture, model lifecycle controls, data governance, monitoring, privacy, explainability and human oversight.
The best answer is often the action that establishes governance, confirms risk, involves the correct stakeholder or follows an approved process—not the fastest technical fix.
The examination tests practical knowledge and application. When reviewing a question, identify the role, objective, risk and decision level before analysing the answers.
Do not review only incorrect answers. Understanding why three options are weaker is essential for handling questions containing qualifiers such as BEST, MOST appropriate or FIRST.
The exam allows roughly 100 seconds per question. A timed mock helps expose slow decision-making, over-analysis and weak domains before the real test.
The answer to “Is AAISM worth it?” depends on your role and career direction. It is a strong option when you already hold CISM or CISSP and are responsible for enterprise AI adoption, AI governance, security architecture, third-party AI risk or security strategy. It can help demonstrate that your expertise extends beyond traditional security programmes into AI-specific governance, threats and controls.Its value is lower for beginners, hands-on machine-learning engineers seeking a development credential, or professionals without the required CISM or CISSP certification. The most valuable outcome is not adding another acronym to your résumé. It is gaining a repeatable method for asking better questions before an AI system is approved:
Choose structured AAISM training, build your plan around the three official domains and schedule the examination only after you can consistently solve scenario-based questions from a security-management perspective.