AAISM Exam Guide: Eligibility, Domains, Study Strategy and Scheduling Decisions
The ISACA Advanced in AI Security Management (AAISM) certification validates the ability to manage AI-related security risk, establish governance, and apply controls to AI systems. It is intended for experienced security and technology professionals who already hold an active CISM or CISSP credential, particularly those advising on or managing enterprise AI initiatives. This guide helps you decide whether you are ready to register, which exam domains need the most attention, what preparation format fits your background, and how to turn the official outline into a workable study plan.
Is AAISM the right certification for your role?
AAISM is most relevant when your work connects AI adoption with security management, risk decisions, governance, policy, or enterprise controls. It is not positioned as an entry-level artificial intelligence credential; the eligibility requirement and the official audience both point toward professionals who already understand security management and are now responsible for applying that judgment to AI.
Who the credential serves
ISACA identifies active CISM or CISSP holders, professionals with proven security or advisory experience, and people with experience assessing, implementing, and maintaining AI systems as potential AAISM candidates. The Chicago Chapter’s review-course description further identifies CISOs and security leaders, AI program owners, risk and compliance managers, security architects, privacy officers, internal auditors, and product and data leaders as relevant participants.
That audience suggests a practical distinction. A security manager who must approve an AI use case, establish accountability, assess a model supplier, or connect AI threats to controls is likely to benefit more than a candidate seeking a broad introduction to machine learning. Your preparation should therefore emphasize decisions, evidence, and control selection rather than only learning AI terminology.
What AAISM does not replace
AAISM does not remove the need for the underlying security-management knowledge represented by CISM or CISSP. ISACA states that candidates must hold either an active CISM or CISSP credential. If neither credential is active, resolve that eligibility issue before buying exam registration or building an AAISM schedule.
What does the AAISM exam measure?
The exam contains 90 questions covering three job-practice domains, and ISACA describes the questions as testing knowledge and ability on real-life job practices used by AI security management professionals. Treat the outline as a description of work decisions: identify the governing objective, assess the risk, select an appropriate response, and align technology or controls with the business context.
Domain 1: AI Governance and Program Management — 31%
The 31% AI Governance and Program Management domain measures the ability to advise stakeholders through policy, data governance, program management, and incident response. Its outline areas include stakeholder considerations, industry frameworks and regulatory requirements; AI-related strategies, policies, and procedures; AI asset and data life cycle management; AI security program development and management; and business continuity and incident response.
Study this domain as an operating model rather than a list of policy headings. Be able to connect an AI initiative to accountable stakeholders, a policy decision to an operating procedure, and an incident-response action to continuity objectives. When reviewing a scenario, ask who owns the decision, what evidence supports it, which life-cycle stage is affected, and how the organization will monitor or revise the arrangement.
Domain 2: AI Risk Management — 31%
The 31% AI Risk Management domain confirms skill in assessing and managing risks, threats, vulnerabilities, and supply-chain issues connected with enterprise-wide AI adoption. The listed areas are AI risk assessment, thresholds, and treatment; AI threat and vulnerability management; and AI vendor and supply-chain management.
Preparation should focus on prioritization. Practice distinguishing an unacceptable exposure from one that can be treated with safeguards, transferred through a supplier arrangement, accepted by an authorized owner, or avoided by changing the use case. Include dependencies such as data sources, models, platforms, service providers, and downstream users. A strong answer will usually preserve the risk-management process rather than jump directly to a technical countermeasure.
Domain 3: AI Technologies and Controls — 38%
The 38% AI Technologies and Controls domain is the largest domain and focuses on optimizing AI security through technologies, techniques, and controls tailored to AI systems. The official outline identifies this domain as a test of knowledge of security technologies, techniques, and controls for AI.
Do not interpret the weighting as permission to ignore governance or risk. Instead, use the domain to test whether you can select controls that address a defined AI threat while considering the system’s life cycle, data, architecture, users, and operating environment. Organize notes by threat-to-control relationships: what could happen, why the control helps, where it operates, and what residual risk remains.
How to use the weighting
Use the official weights to allocate attention, not to predict individual questions or calculate a passing result. Domain 3—AI Technologies and Controls—has the largest share at 38%, while Domain 1—AI Governance and Program Management—and Domain 2—AI Risk Management—each account for 31%. Build a study schedule that covers all three domains, then give additional review time to the area where your diagnostic work shows the weakest reasoning.
Which official requirements should you settle first?
Confirm eligibility and the certification sequence before choosing study materials. Passing the exam alone is not the complete certification process: ISACA requires an active CISM or CISSP credential, a passed certification exam, payment of the one-time application processing fee, adherence to the Code of Professional Ethics, and adherence to the Continuing Professional Education Policy.
Eligibility and application sequence
The practical sequence is to verify that your CISM or CISSP credential is active, register for and pass the AAISM exam, pay the one-time US$50 application processing fee, and submit the certification application. ISACA states that candidates have five years from passing the exam to apply for AAISM certification.
Do not postpone the administrative checks until the week of the exam. Sign in to your ISACA account, confirm the credential status and access to certification functions, and keep a record of the steps still outstanding. The official certification page is the authority for the application process, fee, ethics requirements, and any storefront or process notices.
Maintenance after certification
AAISM holders must earn and report 10 CPE hours annually in the specialized domain of artificial intelligence, beginning in the calendar year after certification. Consider this requirement when assessing the credential’s ongoing commitment: retain evidence of relevant learning and reporting rather than treating the exam as the end of the process.
How should you choose preparation materials?
Start with the current AAISM Exam Content Outline and candidate guide, then select materials that support understanding and application. ISACA lists self-paced training, study resources, and group training; its official exam-prep bundle includes exam registration, an eBook review manual, the Questions, Answers & Explanations database, and the online review course.
A sensible self-study combination
For independent preparation, use the outline to create a domain checklist, the review manual to build conceptual coverage, and the official Questions, Answers & Explanations database to test application. The database is listed as a six-month subscription to a pool of 200+ questions. Use those items to expose gaps and explain decisions, not to memorize a sequence of answers.
The online review course is listed with six months of access, approximately 11 hours of seat time, and 11 CPE credits upon completion. ISACA lists it at US$549 for nonmembers and US$449 plus membership fees for members. Verify the current storefront listing before purchase because product details and pricing can change.
When live instruction may help
A live workshop can be useful if you need structured pacing, discussion of ambiguous management scenarios, or accountability. ISACA offers an AAISM virtual workshop in either a two-day format with eight hours per day or a four-day format with four hours per day; each format provides up to 16 CPE credits. The workshop page states that on-demand programming will not be available for that program, so confirm the format and attendance expectations before enrolling.
Choose live instruction because it solves a specific preparation problem, not because it substitutes for individual practice. You still need to map the instruction to the outline, revisit missed concepts, and work through questions without relying on group discussion to supply the answer.
How to avoid unreliable shortcuts
Do not use exam dumps, leaked questions, or answer memorization as a preparation strategy. They cannot establish that you understand governance choices, risk treatment, supplier exposure, or control selection, and using unauthorized content can conflict with exam and professional obligations. Prefer the official outline, candidate guide, ISACA preparation products, and legitimate training.
What study method fits an experienced security professional?
Use a diagnose–learn–apply cycle. First identify which domain tasks you can explain and which you only recognize by vocabulary. Next study the weak concept in context. Finally apply it to a short scenario and write why one response is stronger than the alternatives. This approach is more useful for a job-practice exam than repeatedly rereading pages.
Build a decision-based knowledge map
Create three working documents, one for each domain. For every outline topic, record the objective, stakeholders, assets or data involved, principal risks, possible treatments, relevant controls, and evidence that would demonstrate effective operation. Keep the entries short enough to review, but specific enough to distinguish a policy from a control or a risk from an incident.
For example, an AI vendor issue should not remain a vague note such as “check supplier security.” Identify what the organization needs to know about the service, which risks arise from dependence or data handling, what due-diligence evidence is appropriate, which contract or monitoring mechanism addresses the concern, and who accepts residual risk.
Practice reading scenario questions
Read the question stem for its decision point before examining every option. Look for terms that establish priority, such as an existing incident, an unapproved use case, a material supplier dependency, a missing policy, or a control that is ineffective. Then eliminate options that act at the wrong level, occur too late, bypass accountability, or solve a different problem.
When two options appear plausible, compare their sequence and scope. A governance question may favor establishing responsibility and policy before deploying a technical measure. A risk question may favor assessing impact and likelihood before selecting treatment. A control question may require a safeguard that directly addresses the stated AI exposure rather than a general security activity. These are study heuristics, not predictions of specific live exam content.
Keep an error log
After each practice session, record the topic, the tempting wrong answer, the reason it was wrong, and the principle that supports the correct choice. Classify the error as knowledge, interpretation, sequencing, or careless reading. Revisit the error log at the end of each study cycle; a rising score without a reduction in repeated reasoning errors can create false confidence.
A practical AAISM study roadmap
A useful roadmap has four stages: establish the baseline, cover the outline, integrate the domains, and verify readiness. The calendar can be short or extended according to your experience and availability, but each stage should end with evidence of improvement rather than a feeling that the material looks familiar.
Stage 1: Establish your baseline
Read the complete official outline and mark each task as confident, familiar, or unfamiliar. Take legitimate sample questions or the free AAISM practice exam offered by ISACA as a diagnostic, not as a forecast of your result. Review every answer, including correct guesses, and use the findings to choose your first study topics.
At this point, also check your active CISM or CISSP status, identify whether you prefer remote or in-person delivery, and inspect the candidate guide for current scheduling and exam rules. Administrative clarity prevents a strong study plan from being undermined by an eligibility or appointment problem.
Stage 2: Cover the three domains
Work through Domain 1, Domain 2, and Domain 3 in outline order, using the review manual or selected course as the main explanation source. After each topic, write a short operational example: a governance artifact, a risk decision, a supplier checkpoint, an incident-response action, or a control objective. Then test the topic with official practice material.
Give extra revision to Domain 3—AI Technologies and Controls—because its official weighting is 38%, but do not defer the two 31% domains. Governance and risk provide the decision context in which a technology control is selected, monitored, and adjusted.
Stage 3: Integrate the domains
Link one scenario across the domains. Begin with an AI initiative and its stakeholders; identify the policy and life-cycle requirements; assess threats, vulnerabilities, suppliers, and risk thresholds; select controls; and define continuity or incident-response actions. This exercise reveals whether you can move from governance to risk to implementation without treating each domain as an isolated subject.
Use your notes to explain trade-offs aloud or in writing. A useful explanation names the business objective, the exposure, the accountable owner, the chosen response, and the evidence needed to verify that the response works.
Stage 4: Verify readiness
In the final review stage, stop collecting new resources unless the outline exposes a clear gap. Complete mixed practice, analyze the error log, and return to primary notes for weak topics. Read questions carefully and practice selecting the best management action rather than the most technically impressive action.
Set a registration decision point: proceed when you can explain the outline topics, consistently reason through mixed scenarios, and have confirmed eligibility and delivery requirements. If your practice shows one weak domain, delay the appointment or revise the plan rather than hoping that familiarity will compensate for the gap.
How can you prepare for remote or in-person delivery?
ISACA offers AAISM registration with remote and in-person delivery options, and its certification page describes computer-based exams administered at authorized PSI testing centers or as remotely proctored exams. Choose the format you can support reliably, then use the official scheduling and remote-proctoring guidance to verify the current technical and procedural requirements.
Scheduling steps
After exam registration fees have been paid, candidates can schedule a testing appointment as early as 48 hours later. ISACA directs candidates to log in to their account, select Certification & CPE Management, and choose the exam-scheduling option; the process then takes the candidate to the PSI dashboard, where the appointment is scheduled.
Appointments are only available 90 days in advance according to ISACA’s certification information. If a preferred site or date is unavailable, check whether the desired date falls within that window and confirm that your exam eligibility has not expired. Do not assume that a missing appointment means the exam is unavailable everywhere.
Rescheduling and location constraints
ISACA states that an AAISM appointment can be rescheduled without penalty during the eligibility period when the change is made at least 48 hours before the scheduled testing appointment. The official instruction is to log in to the ISACA account and follow the Scheduling Guide’s rescheduling steps.
The certification page also states that, for residents of India, Mainland China, and Hong Kong, the AAISM exam is exclusively available at testing centers. Candidates in those locations should verify the available center before choosing a preparation or registration timeline.
A delivery checklist
Before confirming an appointment, review the current candidate guide, scheduling guide, remote-proctoring guide, and PSI compatibility information supplied by ISACA. Check the selected delivery type, appointment time, eligibility window, and any accommodation process that applies to you. Complete these checks early enough to correct a technical or logistical issue without sacrificing final revision time.
Which mistakes most often weaken preparation?
The most damaging mistakes are usually planning errors: studying outside the outline, treating AI security as only a technical subject, ignoring the eligibility sequence, and using practice questions for recognition rather than reasoning. Correct these by tying every study activity to a domain task and by recording the decision logic behind each answer.
Mistake: reading without producing evidence
Passive reading can make unfamiliar material feel known. Require an output after each study block: a risk-treatment comparison, a stakeholder map, a life-cycle control summary, a supplier review checklist, or an incident-response sequence. If you cannot explain the output without the book open, the topic needs another pass.
Mistake: overfocusing on AI vocabulary
Terminology matters, but the credential is framed around AI security management. Do not spend the entire plan memorizing model or architecture terms while neglecting policy, risk thresholds, program management, vendor risk, continuity, and controls. For each technical concept, connect it to an asset, threat, decision owner, or security outcome.
Mistake: confusing the best control with the first control
A control can be technically sound yet unsuitable as the immediate response if the organization has not defined the use case, owner, risk, or policy position. Scenario practice should make you distinguish foundational governance and assessment actions from implementation safeguards and monitoring activities.
Mistake: ignoring the administrative finish line
Some candidates focus on passing and overlook the certification application. Keep the active CISM or CISSP evidence, application steps, processing-fee requirement, ethics obligations, and five-year application period in the same planning record as your study milestones.
What should you do next?
Take four actions in order: open the current official outline, verify your active CISM or CISSP status, choose a preparation route based on your weakest domain, and review the current candidate and scheduling guidance before paying for an appointment. This creates a defensible decision about readiness instead of a registration made on impulse.
If you are still deciding
Compare the credential’s focus with your work. If you manage AI security risk, governance, policy, suppliers, incident response, or AI controls, the subject matter may align with your responsibilities. If you are new to security management or do not hold an active CISM or CISSP credential, address that foundation and eligibility question first.
If you are ready to register
Select official preparation resources that match your learning style, map them to the three domains, and schedule only after checking delivery availability and account eligibility. Once payment is complete, use the ISACA-to-PSI scheduling path rather than relying on third-party instructions. Save the appointment details and revisit the official rules before the exam.
If practice results are uneven
Do not respond to a weak result by buying more unrelated material. Return to the specific outline task, explain the concept in an operational scenario, complete targeted practice, and update your error log. Reassess after the targeted cycle; readiness is stronger when improvement appears across mixed domains, not only in the area just reviewed.
Conclusion
AAISM preparation is most effective when treated as a management-decision exercise grounded in the official outline. Confirm the active CISM or CISSP requirement, study all three domains using their labeled weightings, give particular attention to the 38% AI Technologies and Controls domain without neglecting governance or risk, and use legitimate practice to improve reasoning. Then verify the current PSI, delivery, rescheduling, and application instructions before committing to an appointment. Official requirements can change, so consult ISACA’s AAISM pages and candidate materials at each registration milestone.