ISACA AAISM Certification: Exam Cost, Requirements, Domains & Training Guide

 

ISACA AAISM Certification validates advanced capability in securing, governing, and managing enterprise artificial intelligence. It is designed for experienced security professionals who already hold an active CISM or CISSP. Candidates must pass a 90-question exam covering AI governance and program management, AI risk management, and AI technologies and controls. The current exam fee is US$459 for ISACA members and US$599 for non-members, followed by a US$50 certification application fee after passing and meeting requirements for certification and professional ethics obligations.

What Is the ISACA AAISM Certification?

The ISACA AAISM Certification, formally called ISACA Advanced in AI Security Management™ (AAISM™), is an advanced credential for experienced cybersecurity professionals responsible for managing the security risks created by enterprise AI.

Rather than testing introductory artificial intelligence concepts, AAISM focuses on how security leaders govern AI, evaluate AI-specific risks, establish controls, protect AI systems and data, manage third-party exposure, and integrate AI securely into existing enterprise security programs.

ISACA positions AAISM specifically for experienced professionals and requires candidates to hold an active CISM or CISSP certification. This makes the credential different from entry-level AI certificates that anyone can pursue.

The credential is particularly relevant for professionals working as:

  • Information Security Managers

  • Cybersecurity Managers

  • CISOs and Deputy CISOs

  • Security Architects

  • Governance, Risk and Compliance professionals

  • AI Security Managers

  • Technology Risk Leaders

  • Security Consultants

  • Enterprise Security Program Managers

AAISM builds on established security-management knowledge rather than replacing it.

Who Is Eligible for aaism Certification?

The most important requirement for aaism Certification is straightforward: you must hold an active CISM or CISSP credential to pursue the certification.

ISACA identifies the credential as suitable for professionals with established security or advisory experience and some knowledge of assessing, implementing or maintaining AI systems.

AAISM Eligibility Requirements

Requirement

Current AAISM Rule

Qualifying certification

Active CISM or CISSP required

AAISM exam

Must pass

Application deadline

Apply within 5 years of passing

Application processing fee

US$50

Ethics

Follow ISACA Code of Professional Ethics

Continuing education

Specialized AI CPE required after certification

Candidates therefore should verify that their qualifying certification remains active before investing in the aaism certification exam.

A professional with strong AI security experience but no CISM or CISSP does not currently satisfy the certification requirement merely through work experience.

aaism exam Cost and aaism Certification Cost

The official aaism exam Cost depends on ISACA membership status at registration.

As of September 2026:

  • ISACA member exam fee: US$459

  • Non-member exam fee: US$599

  • Certification application processing fee after passing: US$50

That means the direct aaism Certification Cost is at least:

Candidate Type

Exam Fee

Application Fee

Minimum Direct Cost

ISACA Member

US$459

US$50

US$509

Non-member

US$599

US$50

US$649

These figures do not include optional aaism Training, review manuals, question databases, workshops, membership costs or other preparation expenses.

AAISM also carries an annual maintenance fee of US$20 for ISACA members and US$35 for non-members. ISACA states that the same total maintenance fee applies even when a professional holds multiple ISACA Advanced certifications.

What Is the aaism certification exam Format?

The current aaism certification exam contains 90 questions across three job-practice domains.

ISACA designed the assessment around practical responsibilities performed by professionals managing enterprise AI security rather than pure memorization of AI terminology.

AAISM Exam Domains

Domain

Weight

AI Governance and Program Management

31%

AI Risk Management

31%

AI Technologies and Controls

38%

The weighting matters when building a study plan. AI Technologies and Controls represents the largest portion at 38%, but the two management-oriented domains together account for 62% of the exam.

A technically strong candidate should therefore avoid preparing as though AAISM were simply an AI security engineering exam.

Domain 1: AI Governance and Program Management — 31%

This domain tests whether candidates can help an organization establish the structure needed to manage AI securely.

Topics include:

  • Stakeholder requirements

  • Industry frameworks

  • Regulatory requirements

  • AI security strategy

  • AI-specific policies and procedures

  • Data and asset lifecycle management

  • AI security program development

  • Business continuity

  • AI-related incident response

A useful way to think about this domain is through ownership.

For example, purchasing a generative AI platform is not simply a technology decision. Security leaders may need to determine who approves AI use cases, which information may enter the system, how models are inventoried, how incidents are escalated and which risks senior management accepts.

AAISM expects candidates to connect those decisions to enterprise governance.

Domain 2: AI Risk Management — 31%

This section focuses on identifying and treating risks created by AI adoption.

ISACA includes:

  • AI risk assessments

  • Risk thresholds and treatment

  • Threat identification

  • Vulnerability management

  • Vendor risk

  • AI supply-chain risk

Traditional cybersecurity risks still matter, but AI adds different failure modes.

Consider an organization deploying an external large language model. The security review may need to examine prompt injection, sensitive-data exposure, training-data concerns, model manipulation, insecure integrations, excessive agency, third-party dependencies and unreliable outputs.

The security manager's responsibility is not merely identifying technical weaknesses. The candidate must understand how to translate them into risk decisions, controls, monitoring and accountability.

Domain 3: AI Technologies and Controls — 38%

The largest AAISM domain covers the controls used throughout the AI lifecycle.

Official areas include:

  • AI security architecture and design

  • Model selection, training and validation

  • Data-management controls

  • Privacy controls

  • Ethical, trust and safety controls

  • Security monitoring and technical controls

This is where security-management knowledge must connect with AI architecture.

For instance, an enterprise AI application may involve a foundation model, retrieval-augmented generation, vector databases, APIs, identity services and confidential corporate data. Securing only the model misses much of the attack surface.

A strong AAISM candidate should think about the entire AI system, including identities, datasets, interfaces, third-party services, monitoring and human oversight.

What Skills Does isaca aaism certification Validate?

The isaca aaism certification is intended to demonstrate that a security professional can move beyond discussing AI risk and actively manage it.

ISACA's job-practice tasks include the ability to:

  1. Establish AI-related security policies and procedures.

  2. Support AI governance aligned with business objectives.

  3. Assess AI-specific threats and vulnerabilities.

  4. Conduct AI impact assessments.

  5. Address vendor and supply-chain risk.

  6. Design AI-focused security architecture.

  7. Implement appropriate security controls.

  8. Protect data throughout the AI lifecycle.

  9. Develop AI incident-management processes.

  10. Define metrics for AI security.

  11. Apply human oversight to AI inputs and outputs.

  12. Integrate AI risk into continuity and recovery planning.

These responsibilities explain why AAISM is aimed at established security professionals rather than beginners.

aaism Training: How Should You Prepare?

Effective aaism Training should combine the official exam outline with scenario-based decision making.

ISACA currently provides several preparation options, including an online review course, official review manual, Questions, Answers & Explanations database, virtual workshops and a free practice quiz. The official QAE resource contains a pool of more than 200 practice questions.

A practical preparation sequence is:

1. Start With the Exam Content Outline

Map your knowledge against all three domains before reading large amounts of study material.

2. Strengthen AI Fundamentals

Understand model lifecycle concepts, machine learning, generative AI, data pipelines, model validation and AI architecture well enough to evaluate security implications.

3. Study Through a Security-Management Lens

Do not approach every question as an engineer. AAISM often requires the perspective of a security manager advising stakeholders, defining governance, treating risk or selecting appropriate controls.

4. Practice Scenario Questions

For each question, ask:

  • What is the business objective?

  • What risk is actually being addressed?

  • Who should own the decision?

  • Is governance required before technology?

  • Which action provides the strongest risk treatment?

5. Review Weak Domains

Use practice results to identify whether your biggest gap is governance, risk management or AI technologies and controls.

Well-designed aaism certification training should therefore teach judgment, not just definitions.

How Do You Become AAISM Certified?

Passing the exam does not automatically issue the final aaism certificate.

The certification process is:

  1. Hold an active CISM or CISSP.

  2. Register for and pass the AAISM exam.

  3. Pay the US$50 application processing fee.

  4. Submit the certification application.

  5. Follow ISACA's Code of Professional Ethics.

  6. Maintain the qualifying certification and satisfy continuing education requirements.

Candidates have five years from the date they pass the AAISM exam to apply for certification.

Once registered for the exam, candidates receive a six-month eligibility period in which to take it. Exam appointments are normally displayed only up to 90 days in advance, and rescheduling without penalty is permitted when completed at least 48 hours before the appointment and within the eligibility period.

How Do You Maintain the AAISM Certification?

AAISM is not a one-time credential.

After certification, holders must begin earning and reporting continuing professional education from the following calendar year. ISACA requires 10 CPE hours annually specifically in the AI domain. Qualifying CPE may also count toward other ISACA certifications when it satisfies their requirements.

This requirement is important because AI security changes much faster than many traditional control environments.

A professional preparing for AAISM should therefore view the credential as part of an ongoing security-management discipline involving:

  • AI governance

  • Emerging AI attacks

  • Regulatory requirements

  • Model security

  • Data protection

  • Third-party AI risk

  • AI-enabled security operations

Is ISACA AAISM Certification Worth Pursuing?

ISACA AAISM Certification is most relevant when your job already involves security leadership and AI is becoming part of your organization's technology environment.

It can be particularly useful if you already hold CISM or CISSP and need to demonstrate that you can apply established cybersecurity-management principles specifically to artificial intelligence.

Its strongest value is the intersection of three responsibilities: governance, risk and technical AI security controls.

Before registering, confirm that your CISM or CISSP is active, review the official AAISM exam outline, assess your knowledge across the 31% / 31% / 38% domain weighting, and build your preparation around real enterprise AI security decisions rather than memorizing isolated terminology.


Comments

Popular posts from this blog

How Long to Study for CEH Certification: A Complete Guide

All About CompTIA Data+

The Role of a Client Success Manager in Driving Growth