AAISM Exam Guide: Eligibility, Domains, Preparation, and Scheduling Decisions
The ISACA Advanced in AI Security Management (AAISM) certification validates the ability to manage AI-related security risk, establish policy and governance, and apply controls to AI systems. It is intended for experienced security and technology professionals, with certification eligibility open to holders of an active CISM or CISSP credential. This guide helps you decide whether AAISM fits your role, identify the domains that deserve the most study time, choose official preparation resources, and schedule the exam without relying on unverified question claims or exam dumps.
What does the AAISM certification validate?
AAISM is an AI-centric security management certification focused on translating AI risk into governance, risk treatment, vendor oversight, and technical controls. The credential is relevant when your work involves advising stakeholders, managing an AI security program, assessing AI systems, or supporting responsible enterprise use of AI. It is not presented as a general machine-learning developer certification.
ISACA describes AAISM as designed to help experienced IT professionals manage AI-related security risks, implement policy, and support responsible AI use. That purpose points to a management and assurance perspective: you need to connect business objectives, risk decisions, security requirements, and operational controls rather than study AI concepts in isolation.
The practical decision is whether your existing security background can be extended into AI-specific scenarios. If your experience is primarily application development or data science, you may need to build the governance, risk, and security-management foundation before beginning exam-focused revision. If you already lead security, risk, privacy, audit, or AI programs, the exam outline can help you identify the AI-specific gaps in your current knowledge.
Who is eligible to take and earn AAISM?
An active CISM or CISSP credential is required for AAISM certification eligibility. Passing the exam alone does not complete the certification process: candidates must also pay the application processing fee, adhere to ISACA’s Code of Professional Ethics and Continuing Professional Education Policy, and submit the certification application within the stated period.
ISACA identifies active CISM or CISSP holders, professionals with proven security or advisory experience, and people with experience assessing, implementing, and maintaining AI systems as potential AAISM candidates. The most useful fit is therefore someone who can interpret AI security decisions in an enterprise context, not someone relying only on theoretical familiarity with generative AI.
Before paying for registration, verify that your CISM or CISSP status is active and review the current eligibility instructions in your ISACA Account. After passing, the official process requires a one-time US$50 application processing fee. Candidates have five years after passing the exam to apply for AAISM certification. Requirements and application instructions should be confirmed on the official certification page before action. (https://www.isaca.org/credentialing/aaism/get-aaism-certified)
How is the AAISM exam structured?
The AAISM exam contains 90 questions covering three job-practice domains. The questions are intended to test knowledge and the ability to apply that knowledge to real-life job practices used by AI security management professionals. Prepare to select the most appropriate management or control decision in a scenario, rather than simply recall isolated definitions.
The three domains are AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls. The official content outline is the controlling reference for the current scope, task statements, and domain weighting. Download or review the current outline before building a study schedule, because training notes and third-party summaries may omit or reorganize topics.
The exam content weighting is 31% for AI Governance and Program Management, 31% for AI Risk Management, and 38% for AI Technologies and Controls. AI Technologies and Controls therefore has the largest official domain weighting, but the two 31% domains remain substantial and should not be treated as secondary. (https://www.isaca.org/credentialing/aaism/aaism-exam-content-outline)
What is covered in AI Governance and Program Management?
AI Governance and Program Management accounts for 31% of the exam and tests the ability to advise stakeholders through policy, data governance, program management, and incident response. Study this domain as an operating model: who makes decisions, which policies apply, how AI assets and data are governed, and how the organization responds when controls fail.
The outline identifies these areas within the domain: stakeholder considerations, industry frameworks, and regulatory requirements; AI-related strategies, policies, and procedures; AI asset and data life cycle management; AI security program development and management; and business continuity and incident response.
A productive study exercise is to create a governance map for a hypothetical enterprise AI service. Identify the accountable business owner, security decision-maker, data owner, privacy or compliance participants, approval gates, inventory requirements, and escalation route. Then add the artifacts that would make the process auditable, such as policy statements, lifecycle records, risk acceptance decisions, continuity arrangements, and incident playbook entries.
Avoid treating governance as a collection of broad ethical principles. Exam preparation should connect principles to enforceable policy, ownership, evidence, monitoring, and response. When reviewing a scenario, ask which decision must be made first, who has authority to make it, and what information is required before the AI system proceeds to the next lifecycle stage.
How should you study AI Risk Management?
AI Risk Management also represents 31% of the exam and focuses on assessing and managing enterprise-wide AI risks, threats, vulnerabilities, and supply-chain issues. The correct preparation emphasis is risk reasoning: establish context, identify exposure, evaluate consequences, choose treatment, and monitor whether the treatment remains suitable as the AI system or supplier changes.
The outline groups this domain around AI risk assessment, thresholds, and treatment; AI threat and vulnerability management; and AI vendor and supply-chain management. These topics require more than memorizing risk terminology. You should be able to distinguish a risk decision from a technical finding, recognize when a threshold has been exceeded, and select a proportionate treatment or escalation.
Build a risk register for several AI use cases rather than one generic system. Include the business purpose, affected data, model or service dependencies, threat and vulnerability information, impact, likelihood, risk owner, treatment, acceptance authority, review trigger, and supplier responsibility. This exercise exposes gaps in your understanding and gives you a repeatable way to analyze scenario-based questions.
Supplier questions deserve deliberate attention. Consider how due diligence, contract terms, service changes, data handling, access, incident notification, assurance evidence, and concentration risk affect the organization’s decision. Do not assume that outsourcing the model or platform transfers accountability for the enterprise risk.
What belongs in AI Technologies and Controls?
AI Technologies and Controls has the largest weighting at 38% and focuses on security technologies, techniques, and controls tailored to AI systems. Study the control objective first, then connect it to the AI lifecycle, threat, asset, data, or operating condition it is intended to address.
The official outline describes this domain as optimizing AI security and highlights knowledge of security technologies, techniques, and controls tailored to AI systems. Because the domain is broader than a list of tools, revise by asking what a control protects, how it is implemented, who operates it, and what evidence demonstrates that it works.
Use a control matrix as your main revision aid. For each AI security concern in the official material, record the affected component, control objective, preventive or detective character, responsible role, implementation dependency, monitoring signal, and residual-risk question. This method helps prevent a common mistake: choosing a technically impressive measure that does not address the stated risk or does not fit the system’s lifecycle.
Keep governance and technology connected. A control may require policy authorization, data classification, supplier support, secure configuration, logging, testing, or incident response. When a question offers several plausible controls, prefer the option that addresses the stated objective at the appropriate management level and can be integrated into the organization’s broader security program.
Which study material should you use first?
Start with the official AAISM Exam Content Outline, then use the official review manual and practice database to test whether you can apply each task. Choose a course only when you need structure, explanation, or accountability. Buying more material is not a substitute for mapping the material to the domains and correcting reasoning errors.
ISACA’s official AAISM exam-prep bundle includes exam registration, an eBook review manual, the Questions, Answers & Explanations database, and the online review course. The online review course is listed with six months of access, approximately 11 hours of seat time, and 11 CPE credits upon completion. The bundle and course are separate purchasing decisions, so verify what is included before ordering. (https://www.isaca.org/store2/product/AAISM-BUNDLE-C) (https://www.isaca.org/store/items/lms_aaism)
The official Questions, Answers & Explanations database is listed as a six-month subscription to a 200+ question pool. Use it for learning and diagnosis, not as a promise of the live exam’s content. Work through each item, explain why the selected answer fits the scenario, and record why the alternatives are weaker. Memorizing answer patterns creates fragile preparation and does not demonstrate competence.
Candidates who learn better with live instruction can consider ISACA’s virtual workshop. It is offered in a two-day format with eight hours per day or a four-day format with four hours per day, and each format provides up to 16 CPE credits. ISACA states that on-demand programming is not available for this program, so confirm that the live schedule fits your commitments before enrolling. (https://www.isaca.org/training-and-events/online-training/virtual-workshops/aaism)
How should you build a practical AAISM study roadmap?
A domain-led roadmap is more reliable than reading the manual from beginning to end without testing yourself. Use the first stage to establish scope, the middle stage to build application skill, and the final stage to close measured gaps and confirm that your scheduling arrangements are complete.
Stage one: establish your baseline. Read the official outline and mark every task as strong, familiar, or weak. Take the official free practice questions as a diagnostic if available through the AAISM certification page, but do not treat a short practice set as a prediction of your result. Create a study register with one row per task and a note explaining the evidence behind your confidence.
Stage two: study by decision flow. Begin with AI Governance and Program Management so that you understand ownership, policy, lifecycle, continuity, and response. Move to AI Risk Management and practice turning those governance decisions into risk thresholds, treatments, threat management, and supplier oversight. Finish the first pass with AI Technologies and Controls, then revisit the governance and risk consequences of each control choice.
Stage three: use deliberate practice. Complete official practice items in topic blocks, review every explanation, and update your study register. For every incorrect or uncertain answer, identify whether the problem was a missing concept, a misread scenario, confusion between governance and implementation, or failure to prioritize the stated objective. Re-study the cause, not just the answer.
Stage four: simulate decision-making without unauthorized material. Use mixed-domain practice from the official resources, explain your reasoning aloud or in writing, and practice eliminating answers that are too narrow, premature, unsupported, or disconnected from accountability. Avoid dumps, leaked questions, and claims that memorization guarantees passing; they are not a sound substitute for understanding the assessed job practices.
Stage five: make the readiness decision. Schedule only after you can explain the major tasks in all three domains and can identify the appropriate owner, risk response, or control objective in unfamiliar scenarios. If one domain remains weak, extend study time rather than compensating by repeatedly reviewing your strongest domain.
What preparation mistakes most often waste study time?
The most damaging mistakes are usually planning errors: ignoring eligibility, studying the domains in equal proportions without regard to the blueprint, and confusing familiarity with genuine application ability. Correct these before buying additional resources or selecting an exam appointment.
Do not begin with generic AI news or broad machine-learning tutorials unless the outline shows a direct knowledge gap. AAISM preparation should remain anchored to governance, program management, risk, threats, vulnerabilities, supply chain, technologies, and controls. Background reading is useful only when it helps you interpret one of those assessed responsibilities.
Do not allocate identical study time to every domain automatically. AI Technologies and Controls has an official weighting of 38%, while AI Governance and Program Management has an official weighting of 31% and AI Risk Management has an official weighting of 31%. Use those labels with the percentages when planning, then adjust for your professional background and diagnostic results.
Do not read practice explanations passively. A correct answer reached by guessing still represents a gap. Write a short justification and identify the fact or principle that would change your decision. Also avoid relying on unofficial question banks that claim to reproduce the exam. No practice source can justify an assumption that the live exam will repeat its wording or answer choices.
Finally, do not postpone administrative checks until the day before testing. Confirm credential eligibility, payment status, appointment availability, delivery requirements, account access, and rescheduling rules early enough to correct a problem.
How do registration and delivery choices work?
Registration and exam payment must be complete before an appointment can be scheduled. ISACA offers AAISM registration with remote and in-person delivery options, and the scheduling process uses the PSI dashboard. Check availability and system requirements before committing to a preferred date or delivery method.
ISACA states that candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees. Appointments are available only 90 days in advance, so an unavailable date does not necessarily mean the exam is unavailable; check again as the desired date approaches. If the preferred site or date is still missing, verify that eligibility has not expired in the ISACA Account.
The scheduling path described by ISACA is: log in to your ISACA Account, select Certification & CPE Management, choose the exam scheduling option, and continue to the PSI dashboard. ISACA also provides a scheduling guide and a remote proctoring guide. Read the relevant guide for your delivery choice instead of assuming that remote and in-person procedures are interchangeable. (https://www.isaca.org/credentialing/aaism)
Candidates in India, Mainland China, and Hong Kong should note ISACA’s stated restriction that the AAISM exam is exclusively available at testing centers. For all other locations, confirm the current options shown in your account and on the official registration page, since availability can depend on location and appointment inventory.
If plans change, ISACA states that an AAISM appointment may be rescheduled without penalty during the eligibility period when the change is made at least 48 hours before the scheduled testing appointment. Follow the rescheduling steps in the official guide and account rather than attempting to arrange a change through an unofficial channel.
How should you choose between self-study and training?
Choose self-study when you already understand security governance and risk management and can maintain a schedule independently. Choose an online review course or live workshop when you need a prescribed sequence, instructor explanation, or external deadlines. The right choice depends on the gap identified by your outline review, not on the number of products purchased.
The online review course is listed at US$549 for nonmembers and US$449 plus membership fees for members. The official exam-prep bundle is listed at US$1,360 for nonmembers and US$1,060 plus membership fees for members. These are current listed amounts in the supplied official material, so confirm the storefront before purchase and check whether your selected option includes registration, study content, or both. (https://www.isaca.org/store/items/lms_aaism) (https://www.isaca.org/store2/product/AAISM-BUNDLE-C)
A live virtual workshop may suit candidates who benefit from interaction and concentrated study. ISACA describes the workshop as either two days with eight hours per day or four days with four hours per day, with up to 16 CPE credits for either format. Because the workshop is live and not available on demand, compare its calendar with your intended exam preparation window before enrolling. (https://www.isaca.org/training-and-events/online-training/virtual-workshops/aaism)
Do not purchase a course simply to avoid making a study plan. Even in instructor-led training, keep your own domain map, questions log, and remediation list. After each lesson, translate the material into a governance decision, risk treatment, or control-selection example so that the learning remains connected to the exam’s job-practice orientation.
What should you do after passing?
Passing the exam is the first step in the AAISM certification pathway. Complete the application process promptly, maintain the required professional obligations, and plan continuing education in AI rather than treating the credential as a one-time administrative event.
After certification, AAISM holders must earn and report 10 CPE hours annually in the specialized domain of artificial intelligence, beginning in the calendar year after certification. The certification process also requires adherence to ISACA’s Code of Professional Ethics and Continuing Professional Education Policy.
Use the post-exam requirement as a study-planning consideration before you register. If your current role offers little exposure to AI security, identify credible professional-development activities in the specialized AI domain and keep records that support future CPE reporting. Always verify the current policy and reporting instructions through ISACA rather than relying on a training provider’s summary. (https://www.isaca.org/credentialing/aaism/get-aaism-certified)
What are the next actions for an AAISM candidate?
A sensible next action is to verify eligibility, download the current outline, and record a baseline for each domain before paying for training or selecting an appointment. This sequence prevents an avoidable mismatch between your credential status, study needs, delivery preference, and target date.
Complete these actions in order:
1. Confirm that your CISM or CISSP credential is active and review the certification requirements in your ISACA Account.
2. Read the official content outline and label your knowledge across AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls.
3. Build a study register using the official domain tasks, with special attention to the 38% AI Technologies and Controls domain and the 31% AI Governance and Program Management and 31% AI Risk Management domains.
4. Select the smallest official preparation combination that addresses your gap: review manual, QAE database, online course, or live workshop.
5. Practice explaining why an answer is the best governance, risk, or control decision; do not memorize unofficial dumps or assume that recalled questions will appear.
6. Pay registration, check PSI availability and delivery requirements, and schedule only when your preparation evidence supports the decision.
7. After passing, pay the application processing fee, submit the certification application within five years, and plan the annual AI-domain CPE obligation.
The official AAISM certification page, content outline, candidate-guide page, and ISACA storefront should remain your final checkpoints because scheduling availability, product listings, policies, and delivery instructions can change. (https://www.isaca.org/credentialing/aaism) (https://www.isaca.org/credentialing/aaism/aaism-exam-content-outline) (https://www.isaca.org/credentialing/exam-candidate-guides)
Conclusion
AAISM preparation is strongest when it follows the work the certification is intended to validate: govern AI responsibly, assess and treat risk, manage suppliers and vulnerabilities, and select controls that fit the system and its business context. Verify the CISM or CISSP requirement first, use the official outline to prioritize the three weighted domains, and make scheduling a separate administrative decision from readiness. A disciplined study register, official practice material, and explanation of your decisions will provide more useful evidence of preparation than any claim about dumps or guaranteed answers.