AAISM certification is ISACA’s advanced credential for experienced security leaders who need to govern, assess, and secure enterprise artificial intelligence. The AAISM full form is Advanced in AI Security Management. Eligibility requires an active CISM or CISSP. The exam contains 90 multiple-choice questions, lasts 150 minutes, and covers AI governance, risk management, technologies, and controls. It suits security managers, architects, risk leaders, and CISOs responsible for safe AI adoption, policy, oversight, resilience, and measurable security outcomes across complex modern organizations.
The ISACA Advanced in AI Security Management (AAISM) certification validates a security professional’s ability to manage AI-related security risks at the enterprise level. It is not a beginner AI certificate or a technical machine-learning qualification. Instead, ISACA AAISM sits at the intersection of information security management, AI governance, risk, architecture, privacy, incident response, and responsible AI use.The credential extends the security-management foundation demonstrated by CISM or CISSP holders. ISACA positions it for professionals who must help organizations adopt AI without losing control of sensitive data, regulatory obligations, third-party exposure, model behavior, or operational resilience. Candidates should already have some experience assessing, implementing, or maintaining AI systems.
The ISACA AAISM certification is best suited to:
A beginner can take AAISM training to build knowledge, but cannot earn the certification without an active CISM or CISSP. ISACA’s training may be open to a wider group of security practitioners, while the credential itself is intentionally designed as an advanced specialization.
The official AAISM certification requirements are:
AAISM does not publish a separate multi-year experience application. The active CISM or CISSP serves as the qualifying professional foundation for the credential.
| Exam detail | Official information |
|---|---|
| Certification | ISACA Advanced in AI Security Management |
| Questions | 90 multiple-choice questions |
| Time allowed | 150 minutes |
| Passing score | 450 on a 200–800 scale |
| Domain 1 | AI Governance and Program Management — 31% |
| Domain 2 | AI Risk Management — 31% |
| Domain 3 | AI Technologies and Controls — 38% |
| Languages | English, Spanish, and Japanese |
| Member exam fee | US$459 |
| Non-member exam fee | US$599 |
| Delivery | PSI testing center or remote proctoring, subject to region |
| Eligibility window | Six months after registration |
The AAISM certification exam uses “one best answer” questions. More than one option may appear technically possible, but the strongest response normally reflects risk-based prioritization, appropriate accountability, governance principles, and enterprise security objectives. There is no penalty for an incorrect response, so candidates should answer every question.Residents of India, mainland China, and Hong Kong currently must take the ISACA AAISM exam at a testing center rather than through live remote proctoring.
This part of the AAISM syllabus covers stakeholder responsibilities, regulatory requirements, AI policies, asset and data life-cycle governance, security program development, business continuity, and AI incident response.Strong candidates should be able to define decision rights, establish risk ownership, align AI initiatives with business objectives, and create escalation paths for issues such as data leakage, unauthorized model use, harmful outputs, or service disruption.
This domain tests AI risk assessment, risk thresholds, treatment decisions, threats, vulnerabilities, vendors, and supply-chain exposure.Preparation should cover risks such as poisoned or poor-quality data, prompt injection, model theft, insecure integrations, privacy leakage, adversarial inputs, biased outcomes, weak human oversight, and dependency on external model providers. Candidates should select controls based on business impact and risk appetite rather than choosing the most expensive technical safeguard by default.
The largest domain covers AI security architecture, model selection, training and validation, data controls, privacy, ethics, trust, safety, monitoring, and security controls.Candidates do not need to become data scientists, but they must understand AI systems well enough to govern and secure them. Focus on control placement across data ingestion, development, testing, deployment, inference, monitoring, change management, and retirement. Know where human review, logging, access control, model evaluation, red teaming, output filtering, and incident detection reduce risk.
The direct AAISM certification cost includes the exam, application fee, and ongoing maintenance:
| Cost component | ISACA member | Non-member |
|---|---|---|
| AAISM exam cost | US$459 | US$599 |
| Application fee | US$50 | US$50 |
| Minimum initial total | US$509 | US$649 |
| Annual maintenance fee | US$20 | US$35 |
Training, books, practice databases, membership, retakes, travel, and taxes can increase the total AAISM cost. Before purchasing an AAISM online course, compare its domain coverage, instructor credentials, practice-question quality, access period, and alignment with the current exam outline.An inexpensive AAISM course that teaches only general AI terminology may not prepare candidates for management-focused scenarios involving governance, ownership, risk acceptance, vendor controls, and incident escalation.
Start your AAISM study guide with the official exam content outline. Use the official review manual as the primary AAISM study material, then add structured AAISM certification training, scenario-based practice questions, and focused review sessions. ISACA also provides an official online review course and a free practice quiz.A practical six-week preparation plan is:
Choose an AAISM training course that teaches application rather than memorization. Effective training connects each security control to a defined risk, accountable owner, evidence source, monitoring method, and response process.
The challenge is not mainly remembering definitions. It is recognizing the most appropriate management response when technical, legal, operational, and business priorities conflict.Candidates should practise identifying the accountable owner, the risk decision that must occur first, and the evidence required to validate a control. Deep knowledge of one AI product is less useful than understanding how governance, architecture, data, vendors, monitoring, and incident response work together across an enterprise.
AAISM is worth it when your role already carries CISM- or CISSP-level responsibility and your organization uses AI in products, operations, security, customer service, analytics, or decision-making. It can distinguish professionals who understand both established security-management principles and AI-specific risk.The AAISM cert may offer less immediate value to beginners, machine-learning engineers seeking coding depth, or professionals without CISM or CISSP. AI fundamentals, cloud AI security, data governance, or technical model-security training may be a better first step for those audiences.The practical value of AAISM ISACA certification lies in translating AI risk into policies, architecture decisions, control evidence, executive reporting, incident processes, and defensible business choices.
Create or sign in to your ISACA account, confirm that your active CISM or CISSP can be verified, purchase the exam, and schedule through PSI. Registration creates a six-month eligibility window. After passing, pay the application fee and submit the certification application.Before paying the AAISM exam fee, download the latest candidate guide and examination content outline. Build your preparation around the official domain weighting, devote the most study time to AI Technologies and Controls, and practise choosing the best management action—not merely a technically valid action.