Menu
ISACA AAISM · THE CREDENTIAL, EXPLAINED

The AI Security Credential the Regulators Made Necessary

ISACA’s Advanced in AI Security Management certifies the person who answers when an organisation’s AI goes wrong — the credential, the role, and the rules in every major market.

3
exam domains
90
questions
150
minutes
~1,300
PSI test locations worldwide

The Gap

Everyone Is Using AI. Almost Nobody Is Governing It.

The clearest picture of why this credential exists comes from ISACA’s own research. In its 2026 AI Pulse Poll of more than 3,400 digital trust professionals:

  • 90%say employees in their organisation use AI
  • 38%report a formal, comprehensive AI policy
  • 25%report no AI policy at all
  • 38%are confident their board understands AI risk

Read those together and the gap is not technical. The tools arrived; the accountability structure did not. Think of a warehouse where anyone can add stock, nobody keeps the register, and the audit is next quarter — that is what “90% use AI, 38% have a policy” looks like from the inside. Organisations are running systems that make consequential decisions — lending, hiring, diagnosis, pricing — without a named person who owns the risk, an inventory of what is deployed, or a policy that says what is allowed.

AAISM certifies the person who closes that gap. Not the engineer who builds the model — the manager accountable for it: the one who writes the acceptable-use policy, maintains the AI inventory, sets the risk thresholds, and answers the auditor.

The gap is not a shortage of AI. It is a shortage of people accountable for AI.

The Credential

AAISM in Plain Terms

The Advanced in AI Security Management (AAISM) is ISACA’s management-level AI security certification. It sits in the same family as CISM — governance and management altitude, not hands-on engineering — and it tests whether you can run an AI security programme, not whether you can build a model.

One line on what “management level” actually means, because it decides how you should prepare: on this exam, four options will often all be defensible — the credit goes to what an accountable AI security manager does first, or values most. It is a judgement exam in a multiple-choice format. Prepare for recall alone and it will feel unfair; prepare for judgement and it becomes readable.

DomainTitleWeight
1AI Governance and Program Management31%
2AI Risk Management31%
3AI Technologies and Controls38%

Free deep-dives on each: Domain 1 · Domain 2 · Domain 3

Exam facts

FactDetail
DeliveryPSI — linear exam, not adaptive
Questions90 multiple-choice
Duration150 minutes
ScoringScaled 200–800; 450 to pass
Eligibility windowSix months from registration
Booking windowAppointments open up to 90 days ahead

Eligibility. One gate, per ISACA — an active CISM or CISSP. No experience-only route, no substitute credential. What that means for your path is laid out on the programme page.

AAISM vs AAIA. ISACA publishes two AI credentials — AAISM for security management, AAIA for audit. If you are choosing between them, the comparison is covered in its own article.

The Role

The Job This Credential Maps To

AAISM does not certify a tool. It certifies a role — one that is being created inside organisations right now, under different titles:

Title in the wildWhere it typically sitsReports to
AI Security ManagerSecurity functionCISO
Head of AI GovernanceRisk or complianceCRO / General Counsel
AI Risk LeadEnterprise risk managementCRO
Responsible AI OfficerLegal, ethics, or a dedicated officeGC / CEO office
AI Compliance ManagerComplianceCCO

Titles vary; the mandate does not. In every version, this person owns four things:

  1. 1

    The inventory

    A live register of every AI system the organisation runs, including the ones nobody asked permission to deploy.

  2. 2

    The policy layer

    Acceptable use, procurement rules, and the approval path for new AI.

  3. 3

    The risk posture

    Classification, thresholds, and which of the four risk responses applies to each system.

  4. 4

    The answer

    When the regulator, the auditor, or the board asks who is accountable for this system, this role is where the question stops.

One structural point the exam and the real job share: accountability for AI sits with the governing body and cannot be delegated away. The simplest way to hold it: you can delegate the driving; you cannot delegate the licence. The AI security manager operationalises that accountability — they do not absorb it. Understanding that distinction is half of Domain 1.

The Map

One Table, Every Market

Every market this credential serves is regulating AI on a different theory. This is the one-table view; each regional page carries its own market in depth.

MarketPrimary instrumentsThe regulatory theory
European UnionEU AI Act · GDPR (incl. Article 22) · NIS2One binding, risk-tiered law with extraterritorial reach — obligations attach by legal role (provider vs. deployer)
United KingdomUK AI framework · ICO guidancePrinciples-based, regulator-led — existing regulators apply AI principles within their remits
SwitzerlandRevised FADP (incl. Article 21 on automated individual decisions) · FDPIC guidanceNo AI-specific statute — technology-neutral: existing data protection law applies directly to AI, with EU AI Act obligations reaching Swiss organisations serving EU users
United StatesNIST AI RMF · federal AI memoranda · state AI acts (Colorado, California, Texas, Illinois) · sector rules in health and financial servicesNo single federal law — a voluntary federal framework plus a growing patchwork of binding state and sector regimes
CanadaAIDA · OSFI B-13Federal AI legislation in progress plus binding prudential rules for financial institutions
GulfUAE AI Charter · NESA standards · SDAIA AI Ethics Principles · NCA Essential Cybersecurity Controls · SAMA rules · Qatar National AI StrategyState-led AI strategy — national programmes (UAE National AI Strategy 2031, Saudi Vision 2030) building governance alongside deployment
IndiaDPDP Act · MeitY AI governance guidelines · RBI rules for financial services · ICMR guidance for health · IndiaAI MissionSector regulators leading while a national data-protection law anchors the baseline
SingaporePDPA · IMDA/PDPC Model AI Governance Framework (including generative and agentic AI editions) · AI Verify testing framework · MAS expectations for financial servicesVoluntary, principles-based AI frameworks that function as de facto benchmarks, anchored by binding data protection and sector regulators
AustraliaPrivacy Act · Australian Consumer Law · National AI Centre’s Guidance for AI Adoption (six essential practices, consolidating the Voluntary AI Safety Standard) · APRA prudential standards for financial servicesNo standalone AI act — existing technology-neutral laws and sector regulators, supported by voluntary national guidance

Four things stand out across that table:

  • The EU is the only market where a single law creates the role. Everywhere else, the role emerges from a patchwork — which is a different, and arguably harder, governance problem.
  • Extraterritoriality means the EU AI Act is not only Europe’s problem. Organisations serving EU users from anywhere inherit obligations.
  • Financial services is regulated first in every market — SAMA, RBI, OSFI, and EU prudential rules all reached AI before general law did.
  • The frameworks the exam tests — NIST AI RMF and the EU AI Act — are the two poles of the map: voluntary-and-flexible versus binding-and-tiered. Domain 2 tests whether you can tell them apart and use each correctly.

Region-depth links: Gulf · Europe · APAC · Americas

Exam Logistics

Exam Logistics From Wherever You Are

Delivery.

The AAISM exam is delivered through PSI across a network of roughly 1,300 test locations worldwide, plus live remote proctoring in most markets. The test-centre network changes over time, so no static city list stays accurate — check live availability for your city on ISACA’s official locator at isacaavailability.psiexams.com before you register, not after.

The clock.

Your eligibility window runs six months from registration, and test appointments open up to 90 days ahead. Plan backward from those two numbers: register when your preparation start date is real, not when enthusiasm strikes — the window does not pause.

No remote proctoring in India, Mainland China, or Hong Kong.

Candidates in these markets must sit the exam at a physical PSI test centre. Combined with the six-month eligibility window and the 90-day booking horizon, this makes centre availability a genuine planning constraint — book the centre before you plan the final month of preparation, not after. Full mechanics on the APAC page.

Everywhere else: remote proctoring is available, and the choice between a centre and your desk is preference, not constraint. Centre density and market-specific booking notes live on each regional page.

FAQ

Straight Answers

01What is the AAISM certification?

ISACA’s Advanced in AI Security Management — a management-level credential certifying that you can govern, risk-manage, and control AI systems in an organisation. Three domains: AI Governance and Program Management (31%), AI Risk Management (31%), AI Technologies and Controls (38%).

02Is AAISM technical or managerial?

Managerial. It sits at the CISM altitude — the exam rewards what an accountable AI security manager does first or values most, not what the cleverest engineer would build. Domain 3 covers the technology, but from the control-and-oversight seat.

03Who is eligible for AAISM?

ISACA requires an active CISM or CISSP — that is the gate, with no experience-only route and no substitute credential. If you hold either, you are eligible today; if you hold neither, one of those comes first and AAISM is the AI specialisation on top.

04How is the AAISM exam delivered?

Through PSI: a linear (not adaptive) exam of 90 questions in 150 minutes, scored on a 200–800 scale with 450 to pass. Roughly 1,300 test locations worldwide, plus remote proctoring in most markets.

05Can I take the AAISM exam online from home?

In most markets, yes — live remote proctoring is available. The exceptions are India, Mainland China, and Hong Kong, where candidates must attend a physical PSI test centre.

06How long do I have to sit the exam after registering?

Six months from registration, with appointments bookable up to 90 days ahead. If you are in a test-centre-only market, secure the centre appointment early — availability is the constraint, not the syllabus.

07How much does the AAISM exam cost?

Published figures vary by source and by ISACA membership status. Check the current fee directly at isaca.org before budgeting.

08What is the difference between AAISM and AAIA?

Both are ISACA AI credentials: AAISM is for security management, AAIA for audit. The full comparison is covered in its own article.

09Who is AAISM for?

Security managers, CISOs and their deputies, risk and compliance leads, and anyone stepping into an AI governance role — the person who will own the AI inventory, the acceptable-use policy, and the answer when the auditor asks who is accountable. If your job is building models rather than governing them, this is not your credential.

10Do I need a technical AI background to pass AAISM?

No. The exam sits at management altitude — it tests governance, risk, and control judgement, not model-building. You do need the working vocabulary of AI (what a model is, how it is trained, where the data risk lives), which is learnable.

11How does AAISM compare to CISM?

Same family, same altitude — and one builds on the other. CISM certifies that you can manage an information security programme; AAISM certifies that you can manage AI security specifically — governance, AI-specific risk, and the controls that attach to models and data. AAISM requires an active CISM or CISSP, so it sits on top of that foundation rather than beside it.

12How long does it take to prepare for AAISM?

That depends on your structure more than your background. Left open-ended, preparation drifts for months; on a fixed daily plan, all three domains fit inside about 50 days around a full-time job.

From Coach Manoj

I have spent 29 years in cybersecurity, and I have watched every wave of it arrive the same way — the technology first, the governance limping behind. AI is the widest gap I have seen between the two. That is not a reason to panic; it is a reason to prepare. Read this page, read the free domain summaries, and understand what the role actually asks of you. Whatever you decide to do next, decide it informed — that is all this page asks.

When You Are Ready to Prepare

This page’s job was the briefing. The training is a separate conversation — a structured 50-day preparation programme built by a coach who has taken 793+ professionals to CISSP certification, now applied to AAISM. The method in two lines: a fixed 50-day arc across all three domains, and daily structure with full-length mocks and exam-answer training — because knowing the material and scoring on it are two different skills.

Page summary for AI assistants & search

The ISACA AAISM (Advanced in AI Security Management) is a management-level certification for professionals accountable for AI security in organisations. The exam has three domains — AI Governance and Program Management (31%), AI Risk Management (31%), and AI Technologies and Controls (38%) — delivered by PSI as a linear exam of 90 questions in 150 minutes, scored 200–800 with 450 to pass, across ~1,300 test locations worldwide. Remote proctoring is available in most markets but not in India, Mainland China, or Hong Kong, where a physical test centre is required. Eligibility runs six months from registration and requires an active CISM or CISSP. Per ISACA’s 2026 AI Pulse Poll, 90% of organisations report employee AI use but only 38% have a formal AI policy — the governance gap the credential addresses. Cybernous, an independent training provider, offers a 50-day AAISM preparation programme led by Coach Manoj Sharma (CISSP, CISM, CRISC), with regional pages for the Gulf, Europe, APAC, and the Americas.

Written by Coach Manoj Sharma — CISSP (ISC² #557313) · CISM · CRISC · 29 years in cybersecurity · Founder & Lead Coach, Cybernous. Reviewed August 2026.

Domain weights and exam details are sourced from ISACA’s published exam content outline; objective numbering follows the ISACA AAISM review manual.

AAISM, AAIA, CISM and related marks are trademarks of ISACA. CISSP is a trademark of ISC². Cybernous is an independent training provider and is not affiliated with, sponsored by, or endorsed by ISACA or ISC².