ISACA AAISM Certification: Exam Cost, Requirements, Domains & Training Guide
ISACA AAISM Certification validates advanced capability in securing, governing, and managing enterprise artificial intelligence. It is designed for experienced security professionals who already hold an active CISM or CISSP. Candidates must pass a 90-question exam covering AI governance and program management, AI risk management, and AI technologies and controls. The current exam fee is US$459 for ISACA members and US$599 for non-members, followed by a US$50 certification application fee after passing and meeting requirements for certification and professional ethics obligations.
What Is the ISACA AAISM Certification?
The ISACA AAISM Certification, formally called ISACA Advanced in AI Security Management™ (AAISM™), is an advanced credential for experienced cybersecurity professionals responsible for managing the security risks created by enterprise AI.
Rather than testing introductory artificial intelligence concepts, AAISM focuses on how security leaders govern AI, evaluate AI-specific risks, establish controls, protect AI systems and data, manage third-party exposure, and integrate AI securely into existing enterprise security programs.
ISACA positions AAISM specifically for experienced professionals and requires candidates to hold an active CISM or CISSP certification. This makes the credential different from entry-level AI certificates that anyone can pursue.
The credential is particularly relevant for professionals working as:
Information Security Managers
Cybersecurity Managers
CISOs and Deputy CISOs
Security Architects
Governance, Risk and Compliance professionals
AI Security Managers
Technology Risk Leaders
Security Consultants
Enterprise Security Program Managers
AAISM builds on established security-management knowledge rather than replacing it.
Who Is Eligible for aaism Certification?
The most important requirement for aaism Certification is straightforward: you must hold an active CISM or CISSP credential to pursue the certification.
ISACA identifies the credential as suitable for professionals with established security or advisory experience and some knowledge of assessing, implementing or maintaining AI systems.
AAISM Eligibility Requirements
Candidates therefore should verify that their qualifying certification remains active before investing in the aaism certification exam.
A professional with strong AI security experience but no CISM or CISSP does not currently satisfy the certification requirement merely through work experience.
aaism exam Cost and aaism Certification Cost
The official aaism exam Cost depends on ISACA membership status at registration.
As of September 2026:
ISACA member exam fee: US$459
Non-member exam fee: US$599
Certification application processing fee after passing: US$50
That means the direct aaism Certification Cost is at least:
These figures do not include optional aaism Training, review manuals, question databases, workshops, membership costs or other preparation expenses.
AAISM also carries an annual maintenance fee of US$20 for ISACA members and US$35 for non-members. ISACA states that the same total maintenance fee applies even when a professional holds multiple ISACA Advanced certifications.
What Is the aaism certification exam Format?
The current aaism certification exam contains 90 questions across three job-practice domains.
ISACA designed the assessment around practical responsibilities performed by professionals managing enterprise AI security rather than pure memorization of AI terminology.
AAISM Exam Domains
The weighting matters when building a study plan. AI Technologies and Controls represents the largest portion at 38%, but the two management-oriented domains together account for 62% of the exam.
A technically strong candidate should therefore avoid preparing as though AAISM were simply an AI security engineering exam.
Domain 1: AI Governance and Program Management — 31%
This domain tests whether candidates can help an organization establish the structure needed to manage AI securely.
Topics include:
Stakeholder requirements
Industry frameworks
Regulatory requirements
AI security strategy
AI-specific policies and procedures
Data and asset lifecycle management
AI security program development
Business continuity
AI-related incident response
A useful way to think about this domain is through ownership.
For example, purchasing a generative AI platform is not simply a technology decision. Security leaders may need to determine who approves AI use cases, which information may enter the system, how models are inventoried, how incidents are escalated and which risks senior management accepts.
AAISM expects candidates to connect those decisions to enterprise governance.
Domain 2: AI Risk Management — 31%
This section focuses on identifying and treating risks created by AI adoption.
ISACA includes:
AI risk assessments
Risk thresholds and treatment
Threat identification
Vulnerability management
Vendor risk
AI supply-chain risk
Traditional cybersecurity risks still matter, but AI adds different failure modes.
Consider an organization deploying an external large language model. The security review may need to examine prompt injection, sensitive-data exposure, training-data concerns, model manipulation, insecure integrations, excessive agency, third-party dependencies and unreliable outputs.
The security manager's responsibility is not merely identifying technical weaknesses. The candidate must understand how to translate them into risk decisions, controls, monitoring and accountability.
Domain 3: AI Technologies and Controls — 38%
The largest AAISM domain covers the controls used throughout the AI lifecycle.
Official areas include:
AI security architecture and design
Model selection, training and validation
Data-management controls
Privacy controls
Ethical, trust and safety controls
Security monitoring and technical controls
This is where security-management knowledge must connect with AI architecture.
For instance, an enterprise AI application may involve a foundation model, retrieval-augmented generation, vector databases, APIs, identity services and confidential corporate data. Securing only the model misses much of the attack surface.
A strong AAISM candidate should think about the entire AI system, including identities, datasets, interfaces, third-party services, monitoring and human oversight.
What Skills Does isaca aaism certification Validate?
The isaca aaism certification is intended to demonstrate that a security professional can move beyond discussing AI risk and actively manage it.
ISACA's job-practice tasks include the ability to:
Establish AI-related security policies and procedures.
Support AI governance aligned with business objectives.
Assess AI-specific threats and vulnerabilities.
Conduct AI impact assessments.
Address vendor and supply-chain risk.
Design AI-focused security architecture.
Implement appropriate security controls.
Protect data throughout the AI lifecycle.
Develop AI incident-management processes.
Define metrics for AI security.
Apply human oversight to AI inputs and outputs.
Integrate AI risk into continuity and recovery planning.
These responsibilities explain why AAISM is aimed at established security professionals rather than beginners.
aaism Training: How Should You Prepare?
Effective aaism Training should combine the official exam outline with scenario-based decision making.
ISACA currently provides several preparation options, including an online review course, official review manual, Questions, Answers & Explanations database, virtual workshops and a free practice quiz. The official QAE resource contains a pool of more than 200 practice questions.
A practical preparation sequence is:
1. Start With the Exam Content Outline
Map your knowledge against all three domains before reading large amounts of study material.
2. Strengthen AI Fundamentals
Understand model lifecycle concepts, machine learning, generative AI, data pipelines, model validation and AI architecture well enough to evaluate security implications.
3. Study Through a Security-Management Lens
Do not approach every question as an engineer. AAISM often requires the perspective of a security manager advising stakeholders, defining governance, treating risk or selecting appropriate controls.
4. Practice Scenario Questions
For each question, ask:
What is the business objective?
What risk is actually being addressed?
Who should own the decision?
Is governance required before technology?
Which action provides the strongest risk treatment?
5. Review Weak Domains
Use practice results to identify whether your biggest gap is governance, risk management or AI technologies and controls.
Well-designed aaism certification training should therefore teach judgment, not just definitions.
How Do You Become AAISM Certified?
Passing the exam does not automatically issue the final aaism certificate.
The certification process is:
Hold an active CISM or CISSP.
Register for and pass the AAISM exam.
Pay the US$50 application processing fee.
Submit the certification application.
Follow ISACA's Code of Professional Ethics.
Maintain the qualifying certification and satisfy continuing education requirements.
Candidates have five years from the date they pass the AAISM exam to apply for certification.
Once registered for the exam, candidates receive a six-month eligibility period in which to take it. Exam appointments are normally displayed only up to 90 days in advance, and rescheduling without penalty is permitted when completed at least 48 hours before the appointment and within the eligibility period.
How Do You Maintain the AAISM Certification?
AAISM is not a one-time credential.
After certification, holders must begin earning and reporting continuing professional education from the following calendar year. ISACA requires 10 CPE hours annually specifically in the AI domain. Qualifying CPE may also count toward other ISACA certifications when it satisfies their requirements.
This requirement is important because AI security changes much faster than many traditional control environments.
A professional preparing for AAISM should therefore view the credential as part of an ongoing security-management discipline involving:
AI governance
Emerging AI attacks
Regulatory requirements
Model security
Data protection
Third-party AI risk
AI-enabled security operations
Is ISACA AAISM Certification Worth Pursuing?
ISACA AAISM Certification is most relevant when your job already involves security leadership and AI is becoming part of your organization's technology environment.
It can be particularly useful if you already hold CISM or CISSP and need to demonstrate that you can apply established cybersecurity-management principles specifically to artificial intelligence.
Its strongest value is the intersection of three responsibilities: governance, risk and technical AI security controls.
Before registering, confirm that your CISM or CISSP is active, review the official AAISM exam outline, assess your knowledge across the 31% / 31% / 38% domain weighting, and build your preparation around real enterprise AI security decisions rather than memorizing isolated terminology.
Comments
Post a Comment