The AAISM certification—ISACA’s Advanced in AI Security Management credential—is designed for experienced security leaders who already hold an active CISM or CISSP. It validates the ability to govern enterprise AI, manage AI-specific risk, and select controls across the AI lifecycle. The exam has 90 multiple-choice questions, lasts 150 minutes, and covers three domains. Exam fees are US$459 for ISACA members and US$599 for non-members. Candidates must pass, apply, pay US$50, and maintain continuing education requirements to remain certified.
The AAISM full form is Advanced in AI Security Management. ISACA created the credential for established cybersecurity professionals who must manage the security, governance and operational risks introduced by enterprise artificial intelligence.Unlike introductory AI certificates, theISACA AAISM certification is not intended to teach basic machine learning terminology. It builds on the security-management knowledge already demonstrated through CISM or CISSP.
The credential focuses on decisions such as:
Whether an AI use case fits the organisation’s risk appetite
How sensitive data should be controlled during model training
Which security requirements should appear in AI vendor contracts
How to identify model poisoning, adversarial manipulation and data leakage
How AI incidents should be investigated, escalated and reported
Where human oversight is required for high-impact AI decisions
In practical terms, ISACA Advanced in AI Security Management AAISM helps security leaders move from protecting conventional applications to governing systems whose behaviour may change as data, models and user interactions evolve.
The AAISM cert is best suited to experienced professionals involved in security leadership, risk management, governance, architecture, privacy or technology assurance.
Strong candidates include:
Chief information security officers
Information security managers
Cybersecurity consultants
Enterprise security architects
AI governance leaders
Technology risk managers
Privacy and compliance professionals
Security programme directors
Third-party risk specialists
Professionals securing AI-enabled products
Candidates should already understand security governance, risk treatment, incident management and control design. ISACA also recommends some experience assessing, implementing or maintaining AI systems.This is not an entry-level credential. A professional who is new to cybersecurity should first build broader security knowledge before starting an AAISM course.
The official AAISM certification requirements are clear: candidates must hold an active CISM or CISSP certification.
Passing the examination alone does not automatically award the credential. To become certified, you must:
Hold an active CISM or CISSP.
Pass the AAISM certification exam.
Pay the US$50 application processing fee.
Submit the certification application.
Follow ISACA’s Code of Professional Ethics.
Meet the continuing professional education requirements.
Candidates have five years after passing the examination to apply for certification.
The ISACA AAISM exam measures applied judgement rather than simple recall. Every question presents four answer choices and asks candidates to select the correct or best response.
Exam Detail
Official Information
Exam name
Advanced in AI Security Management
Number of questions
90 multiple-choice questions
Exam duration
2.5 hours or 150 minutes
Delivery
PSI testing centre or remote proctoring, where available
Languages
English, Spanish and Japanese
Passing score
450 on a 200–800 scale
Eligibility period
Six months after registration
Member exam fee
US$459
Non-member exam fee
US$599
There is no penalty for an incorrect response, so every question should be answered. ISACA uses scaled scoring, which means a score of 450 does not represent a simple percentage calculation.Residents of India, mainland China and Hong Kong must currently take the examination at an authorised testing centre; remote proctoring is not available in these locations. Candidates should confirm the latest delivery rules before registering.
The official AAISM syllabus contains three domains. Preparation time should reflect the weighting, but candidates should not ignore any domain because the final score is calculated across the complete exam.
Domain
Weight
Main Focus
AI Governance and Program Management
31%
Governance structures, policies, data lifecycle, programme management, business continuity and incident response
AI Risk Management
31%
Risk assessments, risk thresholds, threat management, vulnerability management, vendors and supply chains
AI Technologies and Controls
38%
AI architecture, model lifecycle, data controls, privacy, ethics, trust, safety, monitoring and security controls
This domain examines whether candidates can align AI security with enterprise objectives.You should understand stakeholder responsibilities, applicable frameworks, regulatory expectations, acceptable-use policies and AI asset management. You must also know how to incorporate AI threats into business continuity and incident response plans.A key exam distinction is the difference between governance and management. Governance sets direction, accountability and risk boundaries. Management implements programmes, procedures and controls within those boundaries.
This section focuses on identifying, analysing and treating AI-specific risk.
Candidates should be prepared to assess:
Training-data integrity
Model manipulation
Sensitive-data exposure
Unsafe or inaccurate output
Excessive system permissions
Shadow AI usage
Third-party model dependencies
AI supply-chain weaknesses
Regulatory and contractual exposure
A mature response does not attempt to eliminate every risk. It prioritises threats according to business impact, likelihood, legal obligations and the organisation’s approved risk appetite.
As the largest domain, this area deserves the greatest share of study time.It covers secure AI architecture, model selection, training, validation, deployment, monitoring and retirement. Candidates must also understand privacy controls, explainability, robustness, human oversight and trust-and-safety mechanisms.The exam does not require candidates to become data scientists. However, security managers must understand AI components well enough to challenge insecure designs and translate technical weaknesses into business risk.
The official AAISM exam cost is:
US$459 for ISACA members
US$599 for non-members
The AAISM exam fee is non-refundable and non-transferable. After passing, candidates pay an additional US$50 certification application fee.
The full AAISM certification cost may also include:
ISACA membership
Official review manual
Question database
Online review course
Instructor-led training
Retake fees, when required
Annual certification maintenance fees
The annual AAISM maintenance charge is US$20 for members and US$35 for non-members. Credential holders must report at least 10 relevant CPE hours annually and 30 CPE hours across a three-year reporting period. They must also maintain an active CISM or CISSP.
Therefore, comparing only the registration price can underestimate the real AAISM cost.
Effective AAISM certification training should combine domain knowledge with scenario-based decision-making.
ISACA offers several official preparation resources:
AAISM Online Review Course
Digital and printed Review Manual
Questions, Answers and Explanations database
Virtual workshops
Free practice questions
Member study groups
The official question database contains more than 200 questions and provides six months of access. ISACA’s virtual workshop includes instructor-led preparation, the review manual, question database and examination registration.
When comparing an AAISM online course or external AAISM training course, check whether it:
Follows the current exam content outline
Explains why an answer is best
Includes realistic management scenarios
Covers all three domains
Teaches AI-specific threats and controls
Includes timed mock examinations
Distinguishes governance decisions from technical actions
A reliable AAISM study guide should help you connect concepts rather than memorise isolated definitions. Your AAISM study material should show how governance, risk, architecture, privacy, vendor management and incident response influence one another.
Map every topic in the examination content outline against your current knowledge. Mark each area as strong, moderate or weak.
Spend more time on AI architecture, model lifecycle controls, data governance, monitoring, privacy, explainability and human oversight.
The best answer is often the action that establishes governance, confirms risk, involves the correct stakeholder or follows an approved process—not the fastest technical fix.
The examination tests practical knowledge and application. When reviewing a question, identify the role, objective, risk and decision level before analysing the answers.
Do not review only incorrect answers. Understanding why three options are weaker is essential for handling questions containing qualifiers such as BEST, MOST appropriate or FIRST.
The exam allows roughly 100 seconds per question. A timed mock helps expose slow decision-making, over-analysis and weak domains before the real test.
The answer to “Is AAISM worth it?” depends on your role and career direction. It is a strong option when you already hold CISM or CISSP and are responsible for enterprise AI adoption, AI governance, security architecture, third-party AI risk or security strategy. It can help demonstrate that your expertise extends beyond traditional security programmes into AI-specific governance, threats and controls.Its value is lower for beginners, hands-on machine-learning engineers seeking a development credential, or professionals without the required CISM or CISSP certification. The most valuable outcome is not adding another acronym to your résumé. It is gaining a repeatable method for asking better questions before an AI system is approved:
Who owns the risk?
What data does the model process?
How can the system be manipulated?
Which decisions require human review?
How will failures be detected?
What happens when the model or vendor changes?
Choose structured AAISM training, build your plan around the three official domains and schedule the examination only after you can consistently solve scenario-based questions from a security-management perspective.