AAISM Certification, formally called Advanced in AI Security Management™, is an ISACA credential designed for experienced information security professionals who need to manage security risks created by artificial intelligence. Candidates must hold an active CISM or CISSP certification. The AAISM exam contains 90 questions across AI governance, AI risk management, and AI technologies and controls. Current exam fees are US$459 for ISACA members and US$599 for non-members, plus a US$50 certification application fee after passing.
The ISACA AAISM Certification validates advanced knowledge at the intersection of artificial intelligence, cybersecurity, governance, risk management, security architecture, data protection, and security controls.
AAISM stands for Advanced in AI Security Management™. ISACA introduced the certification in 2025 for experienced cybersecurity professionals who already have a strong security-management foundation and now need to address AI-specific risks.
This distinction matters. AAISM is not intended to teach cybersecurity fundamentals from the beginning. It builds on established security-management knowledge and focuses on challenges such as securing AI systems, governing their use, assessing AI-related risk, managing data, overseeing third-party AI solutions, and creating appropriate controls.
A practical example is an organization adopting a generative AI platform connected to confidential corporate data. A traditional security program may already address identity, access control, data classification, monitoring, and vendor risk. An AAISM-certified professional should understand how those controls must be extended for AI-specific concerns such as model behavior, AI data lifecycles, human oversight, AI supply chains, explainability, robustness, and AI-specific incident handling.
AAISM is an advanced credential, so its eligibility requirement is more restrictive than many entry-level AI certifications.
To register for the AAISM certification exam, candidates must hold an active CISM or CISSP certification.
That means AAISM is particularly relevant for professionals working as:
Information Security Managers
Cybersecurity Managers
Security Architects
CISOs and security leaders
AI Security Managers
Governance, Risk and Compliance professionals
Security consultants
Enterprise security professionals
AI governance and security specialists
Having general cybersecurity experience without an active CISM or CISSP does not currently satisfy the AAISM certification prerequisite.
ISACA also indicates that candidates should have some familiarity with assessing, implementing, or maintaining AI systems.
The AAISM exam Cost depends on ISACA membership status.
AAISM Cost Item
Current Fee
ISACA Member Exam Cost
US$459
Non-Member Exam Cost
US$599
Certification Application Fee
US$50
These are the current fees listed by ISACA.
Therefore, the basic AAISM Certification Cost after passing is approximately US$509 for an ISACA member or US$649 for a non-member, before considering membership, training, study materials, taxes, or other optional preparation expenses.
Candidates should distinguish between the AAISM certification exam cost and the total preparation budget. AAISM Training, official review material, question databases, workshops, or third-party training programs can increase the total investment.
The current AAISM certification exam contains 90 questions covering three job-practice domains.
Domain
Exam Weight
AI Governance and Program Management
31%
AI Risk Management
31%
AI Technologies and Controls
38%
This area measures whether candidates can connect AI security requirements with organizational governance and security-management practices.
Important areas include AI policies, regulatory considerations, stakeholder responsibilities, data and AI asset lifecycle management, security-program development, business continuity, and AI-related incident response.
A strong candidate should be able to move beyond identifying a technical vulnerability and consider questions such as: Who owns this AI risk? Which policy applies? Does the AI system require additional oversight? How should an AI-related incident be escalated?
The second domain concentrates on identifying, assessing, treating, and monitoring AI risk.
Topics include AI risk assessments, risk thresholds, threat management, vulnerability management, vendor risk, and AI supply-chain risk.
For example, adopting a third-party AI service creates more than traditional vendor risk. Security leaders may also need to understand where data is processed, how models interact with organizational information, how updates affect the risk profile, and which responsibilities remain with the customer.
At 38%, AI Technologies and Controls is the largest AAISM exam domain.
It covers areas including:
AI security architecture and design
AI model lifecycle considerations
Data management controls
Privacy controls
Ethical, trust and safety controls
Security monitoring
AI-specific security controls
ISACA also includes topics such as model selection, training and validation within this domain.
Candidates should therefore understand AI technology sufficiently to make security-management decisions without treating the AAISM exam as a data-science or machine-learning engineering certification.
The AAISM certification process can be summarized in five stages:
Maintain an active CISM or CISSP credential.
Register and pay for the AAISM exam.
Prepare for and pass the AAISM certification exam.
Pay the US$50 application processing fee.
Submit the AAISM certification application and comply with ISACA's professional ethics and continuing education requirements.
Candidates receive a six-month exam eligibility period after registration and payment. ISACA also allows candidates up to five years after passing to apply for the certification.
Registration is continuous rather than limited to fixed testing windows.
One important regional consideration applies to candidates in India, Mainland China, and Hong Kong: ISACA currently states that AAISM must be taken at a testing center in these regions and is not available through live remote proctoring there.
Effective AAISM Training should not rely on memorizing definitions alone.
The exam focuses on professional decision-making. Your preparation should teach you how governance, risk, architecture, data management, incident response, vendor management, and AI technology interact.
A strong preparation strategy should include four layers.
Start with the current AAISM exam content outline. Assign study time according to the weighting rather than treating every topic equally.
Because AI Technologies and Controls represents 38%, this domain deserves slightly more preparation time.
Candidates coming from CISM or CISSP backgrounds may already understand risk assessment, governance, incident management, access control, and architecture.
The challenge is applying those principles to AI.
Focus on risks involving AI models, training and operational data, privacy, bias, trust, robustness, third-party AI services, AI lifecycle security, human oversight, and monitoring.
Do not study only by asking, “What does this term mean?”
Ask questions such as:
What should the security manager do first?
Which control best reduces the identified AI risk?
Which stakeholder should own the decision?
When should an AI system require reassessment?
This approach develops the management perspective needed for scenario-driven professional exams.
ISACA provides an official AAISM Review Manual, Online Review Course, Questions, Answers & Explanations database, and free practice questions.
Practice questions should be used to find weaknesses, not simply memorize answers.
If you miss a question, identify whether the problem came from lack of technical knowledge, misunderstanding risk ownership, missing governance context, or choosing a technically possible answer rather than the best management decision.
The answer depends mainly on your current career responsibilities.
AAISM has the strongest alignment for professionals who already work in security management and increasingly need to evaluate AI-enabled systems.
Its value is different from a broad AI certificate. AAISM combines existing cybersecurity management expertise with AI-specific governance, risk, architecture, control, and data-management considerations.
ISACA describes the credential as building upon the established security-management practices found in CISM and CISSP while adding AI-centric expertise.
Professionals working in organizations deploying generative AI, machine-learning platforms, AI-enabled security tools, automated decision systems, or AI-powered SaaS applications may find particularly strong alignment between the AAISM body of knowledge and their operational responsibilities.
Searchers sometimes use the phrase AAISM certificate, but ISACA formally identifies AAISM as a certification rather than a basic course-completion certificate.
That difference is important.
A training certificate usually confirms completion of learning material. The AAISM Certification requires an eligible underlying credential, successful completion of the certification exam, an application process, professional ethics compliance, and continuing professional education obligations.
Create a study plan around the three official domains rather than collecting unrelated AI material.
Spend your early preparation building conceptual understanding. Move next to scenario-based questions. During the final stage, concentrate on weak areas revealed through practice exams.
Experienced security professionals should pay particular attention to areas that may not have appeared prominently in older security-management programs: AI lifecycle risk, AI-specific architecture, model security, responsible AI, data controls, human oversight, and AI supply-chain risk.
The objective is not to become an AI developer. It is to become better at making defensible security-management decisions about AI systems.
For candidates who want structured AAISM certification training, exam-focused preparation, and guided study support, explore
If you already hold CISM or CISSP and AI systems are entering your organization's security, risk, governance, or technology environment, AAISM provides a focused path for developing the next layer of security-management knowledge.
Start with the official three-domain blueprint, identify your weakest AI-security areas, build a structured AAISM Training plan, and use scenario-based practice to test whether you can apply the concepts—not merely recognize them.
The strongest AAISM preparation connects every technical AI issue back to governance, risk, business impact, control selection, accountability, and measurable security outcomes.