The AAISM certification, formally ISACA Advanced in AI Security Management, is an advanced credential for experienced security professionals who want to lead AI governance, risk management, and security controls. It is available to active CISM or CISSP holders and validates practical ability across AI governance, AI risk, and AI technologies and controls. The exam contains 90 questions, and current ISACA pricing is US$459 for members and US$599 for non-members, followed by a US$50 certification application fee after passing exam successfully.
AAISM is ISACA's specialized security-management certification for professionals responsible for securing artificial intelligence systems and managing AI-related enterprise risk.
The AAISM full form is Advanced in AI Security Management. ISACA launched the credential to extend established security-management knowledge into AI-specific governance, risk, technology, controls, data security, and responsible-use issues.
Unlike an entry-level AI certificate, ISACA AAISM certification is designed for established security professionals. It builds on the management knowledge represented by credentials such as CISM and CISSP.
An AAISM professional may be expected to help an organization:
Develop AI security policies and standards.
Assess threats and vulnerabilities affecting AI solutions.
Evaluate third-party and AI supply-chain risk.
Define security controls for AI architectures.
Protect training, validation, and operational data.
Integrate AI risk into enterprise security programs.
Manage AI-related incidents and business continuity.
Address privacy, ethics, trust, explainability, and safety.
That management perspective is what separates AAISM ISACA from general AI courses focused mainly on prompting, machine learning, or AI development.
The most important AAISM certification requirement is straightforward:
You must hold an active CISM or CISSP certification to take the AAISM exam.
ISACA specifically designed AAISM as an advanced credential that supplements established security-management expertise. Candidates should also have some familiarity with assessing, implementing, or maintaining AI systems.
To earn the credential, candidates must:
Hold an active CISM or CISSP.
Register for and pass the AAISM certification exam.
Pay the US$50 application processing fee.
Submit the certification application.
Follow ISACA's Code of Professional Ethics.
Meet ongoing Continuing Professional Education requirements.
Candidates have five years after passing the exam to apply for certification. Once certified, AAISM holders must earn and report 10 AI-focused CPE hours annually, beginning the calendar year after certification.
This means professionals without CISM or CISSP should not treat AAISM as their first cybersecurity certification.
The ISACA AAISM exam measures practical judgment rather than simply testing AI terminology.
AAISM Exam Detail
Current Information
Certification
Advanced in AI Security Management
Exam provider
ISACA
Number of questions
90
Exam type
Computer-based
Passing score
450 on ISACA's 200–800 scale
Eligibility
Active CISM or CISSP
Member exam cost
US$459
Non-member exam cost
US$599
Certification application fee
US$50
Exam eligibility after registration
6 months
Exam administrator
PSI
ISACA confirms that the AAISM exam consists of 90 questions. ISACA's certification scoring model requires 450 or higher to pass.
Registration is continuous. After paying the AAISM exam fee, candidates receive a six-month eligibility period and may generally schedule through PSI. Testing-center and remote-proctoring availability depends on location. ISACA currently states that candidates in India, Mainland China, and Hong Kong must take AAISM at a testing center rather than through live remote proctoring.
Understanding the official AAISM syllabus is more useful than memorizing isolated definitions.
This domain addresses the management structure surrounding enterprise AI.
Key subjects include:
AI governance roles and responsibilities
Regulatory and industry requirements
AI security policies and procedures
AI asset and data lifecycle management
AI security program development
Business continuity
AI incident response
Candidates should understand how AI security requirements connect with broader enterprise governance rather than treating AI as an isolated technology project.
This domain evaluates the ability to identify, assess, monitor, and treat AI-related security risk.
Major topics include:
AI risk assessments
Risk thresholds and treatment
AI threats and vulnerabilities
AI-specific attack exposure
Vendor risk
Third-party AI services
AI supply-chain management
The practical challenge is choosing the best risk response in a business context, not simply identifying every technically possible vulnerability.
This is the largest portion of the AAISM certification exam.
It covers:
AI security architecture and design
Model selection, training, and validation
Data-management controls
Privacy controls
Ethical and responsible AI
Trust and safety
AI security controls
Monitoring and detection
Because 38% of the examination comes from this domain, candidates should spend significant preparation time connecting AI architecture with security controls, data protection, monitoring, and risk treatment.
The current official AAISM certification cost begins with the exam registration fee:
ISACA member AAISM exam cost: US$459
Non-member AAISM exam cost: US$599
Certification application fee after passing: US$50
Therefore, the minimum direct credentialing cost is approximately US$509 for members or US$649 for non-members, before optional training or study resources.
Your total AAISM cost can be higher if you purchase an AAISM course, review manual, question database, workshop, or third-party AAISM certification training.
Candidates should compare membership benefits before registration rather than evaluating only the headline AAISM exam fee.
Effective AAISM training should combine AI knowledge with security-management decision making.
ISACA currently provides several official preparation options:
AAISM Online Review Course
AAISM Official Review Manual
Questions, Answers & Explanations Database
Virtual workshops
Free practice questions
ISACA member study groups
The official QAE database provides access to a pool of 200+ practice questions, while the AAISM study guide/review manual serves as the principal reference for the exam content.
When evaluating an AAISM online course or AAISM training course, prioritize one that teaches why one governance, risk, or control decision is stronger than another. Question memorization alone is a weak preparation method for scenario-based security-management decisions.
A practical preparation sequence is:
Download the official exam content outline.
Map your current knowledge against all three domains.
Study the official AAISM material.
Build understanding before attempting large quantities of questions.
Give Domain 3 additional attention.
AI Technologies and Controls represents 38% of the examination.
Study AI risk as an enterprise problem.
Connect technical weaknesses with governance, business impact, regulatory obligations, and risk treatment.
Practice scenario-based questions.
Learn to distinguish a technically possible answer from the best management decision.
Review every incorrect answer.
Identify whether the weakness is knowledge, interpretation, governance perspective, or exam technique.
An ISACA-published 2026 account from a successful candidate specifically emphasized repeated reading of the official manual and carefully reviewing explanations for practice questions rather than merely tracking scores.
The AAISM cert is particularly relevant to:
CISOs and security leaders
Information security managers
Cybersecurity architects
Security consultants
AI governance professionals
Enterprise risk professionals with security responsibilities
Security professionals reviewing GenAI deployments
CISM or CISSP holders moving into AI security leadership
For example, a security manager approving an enterprise generative-AI platform must consider more than access control. They may need to assess training-data exposure, prompt injection, sensitive-data leakage, third-party model risk, model monitoring, incident response, regulatory obligations, and human oversight.
That cross-functional responsibility closely reflects what ISACA Advanced in AI Security Management AAISM is intended to validate.
AAISM can be worth it for experienced CISM or CISSP holders whose responsibilities increasingly involve AI security, governance, or risk.
Its strongest value is specialization. Instead of proving general cybersecurity knowledge again, it demonstrates that an established security professional can apply management principles to AI-specific threats and controls.
It may be especially valuable if your organization is deploying generative AI, machine-learning systems, AI-enabled security tools, or third-party AI services.
AAISM is less suitable for someone beginning a cybersecurity career or looking primarily for hands-on machine-learning engineering skills.
For eligible professionals, the best next step is simple: review the official AAISM certification requirements and exam content outline, identify gaps across the three domains, then choose an AAISM certification training approach that combines structured study material, scenario practice, and real AI-security decision making.