AAISM certification is ISACA’s Advanced in AI Security Management credential for experienced security professionals who already hold an active CISM or CISSP. It validates practical knowledge across AI governance and program management, AI risk management, and AI technologies and controls. The exam has 90 questions, and current registration costs US$459 for ISACA members or US$599 for non-members. Candidates can prepare through ISACA’s official review resources, training, practice questions, and a structured study plan focused on real-world AI security decisions and scenarios.
AAISM stands for Advanced in AI Security Management. It is an ISACA certification created for security professionals who need to manage security risks associated with artificial intelligence while helping organizations use AI responsibly and effectively. Unlike entry-level AI courses, AAISM assumes that candidates already understand information security management. The credential builds on the security-management foundations associated with CISM and CISSP and adds specialized knowledge covering AI governance, AI-specific risks, AI technologies, data considerations, controls, and security operations. That positioning makes AAISM particularly relevant to security managers, cybersecurity leaders, governance professionals, risk specialists, architects, and experienced practitioners who are becoming responsible for AI-enabled systems. ISACA describes AAISM as a credential that validates the experience and knowledge of CISM and CISSP holders regarding AI-specific security issues while addressing how AI can be leveraged for organizational growth and innovation.
The main distinction of ISACA AAISM is its combination of established security-management practices with AI-specific security concerns. Traditional cybersecurity programs typically address identity, networks, applications, infrastructure, vulnerabilities, incidents, and enterprise risk. AI introduces additional considerations: model behavior, training and inference data, AI supply chains, privacy, model-related threats, governance, accountability, monitoring, and the possibility that AI systems themselves become part of an organization's attack surface. AAISM focuses on the management decisions surrounding these issues rather than treating AI as simply another technology. For example, consider an organization deploying a generative AI assistant that can access internal documents. A security leader must think beyond whether the application has authentication. They also need to consider what data the model can access, how prompts and outputs are handled, whether sensitive information can leak, how third-party AI providers are assessed, what controls are applied, and how incidents involving AI will be detected and managed.
That broader management perspective is central to the AAISM credential.
One of the most important facts about AAISM certification requirements is that this is not an open-entry certification. Candidates must hold an active CISM or CISSP credential to register for the AAISM exam. After passing the examination, candidates must complete the certification application process. ISACA states that candidates have five years from the date they pass the exam to apply for certification. The application requires a US$50 processing fee. The certification also has continuing education requirements. AAISM holders must earn and report at least 10 CPE hours annually related to the credential and at least 30 AAISM-related CPE hours during a three-year reporting period.
The basic path is therefore:
Hold an active CISM or CISSP.
Prepare for and pass the AAISM exam.
Pay the US$50 certification application fee.
Submit the certification application.
Maintain the credential through required CPE activities and professional ethics requirements.
The AAISM syllabus is organized into three job-practice domains. The current exam contains 90 questions designed around real-life AI security management practices.
AAISM Domain
Exam Weight
Main Focus
AI Governance and Program Management
31%
Governance, policies, stakeholders, frameworks, regulations, and program management
AI Risk Management
35%
AI risk identification, assessment, treatment, monitoring, and management
AI Technologies and Controls
34%
AI technologies, data, development, security controls, monitoring, and operational considerations
The first domain examines how security professionals establish governance around AI. It includes stakeholder considerations, industry frameworks, regulatory requirements, AI strategies, policies, procedures, and program management. The second domain concentrates on AI risk management. This is particularly important because AI risk does not exist in isolation. A security leader may need to evaluate risks involving data, models, vendors, privacy, business processes, regulatory obligations, and operational dependencies. The third domain addresses AI technologies and controls, requiring candidates to understand how AI systems work from a security-management perspective and how appropriate controls can be designed and maintained.
The AAISM exam consists of 90 questions across the three domains. ISACA uses computer-based testing, with authorized PSI testing centers and remote-proctored options depending on location and eligibility. Candidates should also understand that AAISM is not positioned as a basic AI literacy exam. ISACA recommends that candidates have experience assessing, implementing, and maintaining AI systems before pursuing the credential. This distinction matters when choosing an AAISM study guide. Someone who already manages security programs should spend less time memorizing basic security concepts and more time understanding how those concepts change when AI becomes part of the environment. A useful preparation approach is to repeatedly ask management-oriented questions: What is the risk? Who owns it? What control addresses it? What evidence demonstrates that the control works? What happens when the AI system changes? How should the organization monitor the risk after deployment?
Current AAISM certification cost needs to be separated into examination and application expenses.
ISACA currently lists the AAISM examination at US$459 for members and US$599 for non-members. After passing, candidates pay a one-time US$50 certification application processing fee.
Cost Component
ISACA Member
Non-Member
AAISM exam registration
US$459
US$599
Certification application fee
US$50
US$50
Training and preparation materials are separate expenses. ISACA offers an official AAISM Review Manual, online review options, practice questions and answers, and instructor-led training opportunities.
Because training prices can change, candidates should verify the current amount directly with ISACA before budgeting for an AAISM course.
An AAISM training course should do more than walk through terminology. The strongest preparation connects the syllabus to practical security-management decisions. ISACA currently offers an AAISM virtual workshop designed to develop knowledge around operational AI readiness, enhanced threat detection and response, and the strategic use of AI within organizations. The workshop provides 16 CPE credits. Candidates looking for an AAISM online course should evaluate whether the program covers all three exam domains and whether it provides explanations rather than only question banks. A strong course should help learners move through a cycle of learn → apply → test → analyze → revise. That process is more valuable than repeatedly reading the same material.
The quality of AAISM study material matters because the certification is specialized. Candidates should prioritize authoritative resources and materials mapped directly to the official exam content outline.
A practical preparation library can include:
The official AAISM exam content outline
ISACA's AAISM Review Manual
Official practice questions and explanations
Instructor-led or virtual AAISM training
AI governance and security frameworks
Notes based on real organizational AI use cases
Practice scenarios involving AI risk, controls, governance, and incident management
The purpose of these resources should be to develop decision-making ability. If a practice question asks which control is most appropriate, the candidate should understand the business and security reasoning behind the answer rather than memorize a letter choice.
A focused preparation process can be built around the official domain weights.
First, establish your baseline. Review the three AAISM domains and determine which areas overlap with your existing CISM or CISSP knowledge and which areas are genuinely new.
Next, study AI-specific concepts. Focus on AI governance, AI risk, data management, AI lifecycle considerations, threats, vulnerabilities, controls, monitoring, and responsible AI practices.
Then, use practice questions diagnostically. Do not treat every incorrect answer as a memorization problem. Identify whether the mistake came from a knowledge gap, misreading, poor risk analysis, or confusion between two plausible controls.
Finally, practice scenario-based reasoning. The closer your preparation gets to real management decisions, the more useful it becomes. Ask yourself how you would justify a security recommendation to a business executive, risk committee, development team, or regulator.
For the right professional, AAISM is worth considering because it occupies a specialized position between established security-management expertise and emerging AI security responsibilities. The certification is especially relevant if your role involves AI governance, security strategy, risk management, security architecture, AI adoption, compliance, or oversight of AI-enabled systems. Its eligibility requirement is also significant. Because candidates must already hold CISM or CISSP, AAISM functions as an advanced specialization rather than a foundational cybersecurity credential. The value will depend on your career direction. Someone seeking an introductory AI credential may need a different starting point. An experienced security professional responsible for managing AI-related risk, however, may find the specialization much more directly applicable.
AAISM should not be confused with a general AI course. A general course may teach machine-learning concepts, generative AI fundamentals, prompt engineering, or practical AI tools. AAISM is centered on security management of AI. That distinction becomes important when organizations move from experimentation to production. Learning how to use an AI tool is different from determining whether an organization should deploy it, what risks it introduces, which controls are necessary, how vendors should be evaluated, and how security teams should monitor it. AAISM addresses the second set of questions.
If you already hold an active CISM or CISSP and your responsibilities increasingly involve AI security, start with the official AAISM exam content outline rather than buying multiple study resources immediately. Map the three domains against your current experience, identify the weakest areas, and then select an AAISM training course or study material that directly addresses those gaps. Check the current ISACA registration requirements and AAISM exam cost before scheduling, then build your preparation around governance, risk, technologies, and controls. That approach turns AAISM from another certification to study for into a focused professional specialization in managing security risks created—and opportunities enabled—by AI.