AAISM Training for Europe: The Law Created the Role. Get Certified for It.
Across the EU, the UK, and Switzerland, AI governance is not an ambition — it is a compliance function with a named accountable person. AAISM certifies that person.
Why Now
In Europe, This Is Not a Career Upgrade. It Is a Compliance Function.
In every other market, the AI security manager role emerges from ambition — a national strategy, a board initiative, a competitive push. In Europe it emerges from law. The EU AI Act’s main obligations are now in force, and they do something no other instrument in the world does: they define legal roles, attach binding obligations to each, and expect a person inside the organisation to be answerable for them.
That changes the nature of the job. Elsewhere, AI governance is something an organisation chooses to staff. In Europe, an organisation deploying a high-risk AI system that cannot produce its conformity evidence, its risk documentation, or its accountable owner is not behind on best practice — it is noncompliant with a binding regulation whose penalty structure is tied to global turnover.
Three consequences for your career:
- 1
The role cannot be deferred.
A bank using AI in credit scoring, a manufacturer embedding AI in a regulated product, a hospital group deploying diagnostic AI — each has statutory obligations today, whether or not anyone has been hired to own them.
- 2
The role is defined by evidence, not enthusiasm.
European AI governance work runs on documentation: risk classification, conformity assessment, fundamental rights impact assessment, records the regulator can ask for. That is precisely the management altitude AAISM tests.
- 3
The role crosses one border by default.
The Act reaches any organisation whose AI systems touch EU users — which is why UK and Swiss professionals are inside this market, not adjacent to it.
Everywhere else, someone decided to create this job. In Europe, the law did.
The instruments the governance seat actually answers to here.
Regulatory Landscape
The Instruments You Will Actually Work Under
The EU AI Act — the spine
The world’s first comprehensive, binding AI law, and the only instrument anywhere built on the structure the AAISM exam itself tests. Four things define it:
| What defines it | Why it matters to your work |
|---|---|
| Risk tiers | Obligations scale with a system’s risk classification — from prohibited practices, through high-risk systems carrying the heaviest duties, down to transparency-only and minimal-risk tiers. Classifying a system correctly is the first governance act, because everything else follows from it. |
| Extraterritorial reach | The Act applies to organisations outside the EU whose AI systems or outputs are used inside it. A UK insurer scoring EU customers, a US platform serving EU users — both are in scope. |
| Conformity assessment | High-risk systems must demonstrate compliance before market placement or deployment — documented risk management, data governance, logging, human oversight, robustness. This is evidence work — inventories, files, assessments a regulator can open — and it is exactly where the AI security manager sits. |
| FRIA | Certain deployers of high-risk systems must complete a fundamental rights impact assessment before use — a distinct instrument, not a renamed DPIA. Knowing which assessment applies where is examined content, and a live European job task. |
Provider vs. deployer — the distinctive content of this market
Every obligation in the Act attaches to a legal role, and the two that matter most are provider and deployer. The plainest way to hold the difference: it is the company that builds the car versus the company that runs the taxi fleet. Both answer for safety — but for different things. The builder answers for how the vehicle was designed, tested, and documented; the fleet operator answers for how it is driven, maintained, and who is behind the wheel. Same split, in statute:
| Role | You are this if… | Your obligation load |
|---|---|---|
| Provider | You develop an AI system, or place it on the EU market under your name | The heavy tier: conformity assessment, technical documentation, quality management, post-market monitoring |
| Deployer | You use an AI system under your own authority | Operating duties: use per instructions, human oversight, input data controls, monitoring, and — for certain high-risk uses — the FRIA |
Where that determination goes wrong
The determination is legal, not organisational-chart-based, and it is easy to get wrong: fine-tune a procured model far enough, or put your name on it, and you can become the provider — the fleet operator who rebuilds the engine has just become a manufacturer, whether they meant to or not.
Two traps drawn straight from the AAISM material apply here with statutory force in Europe: a vendor’s indemnity does not cover the deployer’s own obligations, and the dependency map does not stop at the third party — the vendors of vendors are part of your supply-chain picture. Domain 2 examines exactly this reasoning; Europe is the one region where getting it wrong is a legal finding rather than a bad audit note.
The supporting instruments
| Instrument | What it does for your work |
|---|---|
| GDPR, Article 22 | The right not to be subject to solely automated decisions with legal or similarly significant effects. Predates the AI Act, still binding, and the reason automated-decision governance is a decade old in Europe rather than new. |
| NIS2 | Cybersecurity risk-management and reporting duties across essential and important entities. Where AI systems sit inside covered infrastructure, AI security and NIS2 compliance converge on the same manager. |
| The UK framework and ICO guidance | The UK regulates through existing regulators applying AI principles within their remits, with the ICO leading on automated decision-making and data protection. Principles-based rather than statutory-tiered — but a UK organisation touching EU users answers to both regimes, which is itself a governance task. |
Global one-table view: on the worldwide hub. This page carries Europe in depth.
Eligibility
Are You Eligible?
You hold an active CISM
You are eligible today — register when your start date is real
You hold an active CISSP
Same answer — eligible today
You hold neither yet
CISM or CISSP comes first; AAISM is the AI specialisation built on top of it
Per ISACA, an active CISM or CISSP is the prerequisite — no experience-only route, no substitute credential. Sequencing detail on the programme page.
Where the role is being staffed.
Hiring
Where the Role Is Being Staffed
European demand follows the regulation — the sectors with the heaviest AI Act and sector-rule exposure are staffing first:
| Employer archetype | Why the seat exists | What the work looks like |
|---|---|---|
| Banks & financial services | Credit scoring and fraud models sit squarely in high-risk territory; prudential supervisors were asking about model risk before the Act existed | Model inventory, conformity evidence, Article 22 handling, supervisor-ready documentation |
| Pharma & healthcare | Diagnostic and clinical-decision AI carries both AI Act and sector obligations | Clinical AI risk classification, human-oversight design, safety monitoring |
| Manufacturing | AI embedded in regulated products pulls the product into conformity-assessment territory | Provider-side obligations: technical files, quality management, post-market monitoring |
| EU institutions & public sector | Public-sector deployers of high-risk systems carry FRIA duties and the highest transparency expectations | FRIA execution, procurement gates, public accountability |
| Professional services | Every client in the four rows above needs help building the function | Advisory delivery — the multiplier role: one certified professional serving many compliance programmes |
Written to archetypes, not named employers, by design — the pattern holds across the region and does not date.
How the exam actually works from where you sit.
Exam Logistics
Exam Logistics: EU, UK & Switzerland
Delivery.
The AAISM exam is delivered through PSI test centres across Europe, and — unlike some markets — live remote proctoring is available throughout the region, Switzerland included. You can sit the exam at a centre or from your desk; here it is a preference, not a constraint.
The two clocks.
Eligibility runs six months from registration; appointments open up to 90 days ahead. The planning rule: register when your start date is real, book the slot when your final fortnight is visible, and treat the six-month window as a deadline that does not pause.
Finding your centre.
The PSI network is live and changes over time, so no city list on any training site stays accurate. Check current availability for your city on ISACA’s official locator at isacaavailability.psiexams.com — do it before you register, because the six-month clock starts at registration, not at booking.
| Fact | Detail |
|---|---|
| Format | Linear, 90 questions, 150 minutes |
| Scoring | Scaled 200–800; 450 to pass |
| Delivery | PSI centre or remote proctoring, across the EU, UK and Switzerland |
Fee: check the current figure directly at isaca.org — published numbers vary by source and membership status, and the member/non-member difference makes the membership arithmetic worth doing before checkout.
Cohort Timing
Built for European Evenings
Live cohort sessions run in the evening on GMT / CET — after working hours for London through Warsaw, and workable from Lisbon to Helsinki without touching the workday. The 50-day arc assumes you have a job: daily study blocks are sized for weekday evenings, with the heavier revision and mock work falling where a working week can absorb it.
One regional note: ISACA’s own AAISM workshops list a London timezone on every session, and ISACA’s European conference presence runs through Munich — this market is one of the three ISACA itself schedules for. You are not early; you are on time.
The Exam
What the Exam Covers
| Domain | Title | Weight | Free deep-dive |
|---|---|---|---|
| 1 | AI Governance and Program Management | 31% | Domain 1 Summary |
| 2 | AI Risk Management | 31% | Domain 2 Summary |
| 3 | AI Technologies and Controls | 38% | Domain 3 Summary |
Domain 2 — where frameworks, risk classification, and the provider/deployer reasoning live — is the domain European candidates will recognise from their day jobs.
The Method
The Method, in Brief
A fixed 50-day arc
Every day is mapped and the three domains arrive in sequence — you never have to decide what to study tonight
Think like the manager
Four exam options will often all be defensible; the mark goes to what the accountable manager does first — so that is the reflex we train
Full-length mocks
Exam-shaped practice under exam conditions, converted into an honest verdict on whether you are ready to book
A coach in your corner
Led by Coach Manoj Sharma, who has taken 793+ professionals to CISSP certification
The full method — day structure, artefacts, mentorship options — is on the programme page.
Free Resources
Start Free
FAQ
AAISM in Europe — Straight Answers
01Does the EU AI Act require an AAISM certification?
No law names a certification. The Act requires outcomes — risk classification, conformity evidence, human oversight, accountable ownership — and AAISM certifies the management competence to deliver them. Employers use the credential as evidence you can run that function; the regulator judges the function itself.
02Am I a provider or a deployer under the EU AI Act?
It is a legal determination, not a job title. Broadly: develop a system or place it on the EU market under your name and you are a provider; use a system under your own authority and you are a deployer — but fine-tuning or rebranding a procured system can shift you into the provider role, with the heavier obligation load. The reasoning behind that determination is examined in Domain 2.
03Does AAISM cover the EU AI Act?
Yes — Domain 2 examines AI regulatory frameworks including the EU AI Act and contrasts it with NIST's AI Risk Management Framework: binding-and-tiered versus voluntary-and-flexible. Risk classification, the four risk responses, and impact assessments including the FRIA are all in scope.
04I am in the UK. Is this still relevant after the EU AI Act?
More so. The UK runs a principles-based, regulator-led framework with the ICO prominent on automated decisions — and any UK organisation whose AI touches EU users also inherits EU AI Act obligations through the Act's extraterritorial reach. UK professionals frequently end up governing under both regimes at once.
05What is a FRIA, and how is it different from a DPIA?
A fundamental rights impact assessment — required of certain deployers of high-risk AI systems before use under the EU AI Act. It assesses impacts on fundamental rights broadly, where a DPIA assesses data-protection risk under GDPR. They are distinct instruments; substituting one for the other is both a compliance error and a known exam trap.
06Can I take the AAISM exam remotely from the EU or UK?
Yes. Live remote proctoring is available across Europe, alongside PSI test centres in the EU and UK. Either route; same exam — 90 questions, 150 minutes, 450 to pass on a 200–800 scale.
07Am I eligible for AAISM?
One gate: an active CISM or CISSP, per ISACA — no experience-only route, no substitute credential. Europe has one of the deepest pools of both credentials in the world, so if you are reading this page from a security or risk seat, you very likely already qualify. If you hold neither, that credential comes first.
08When do the live sessions run for European participants?
Evenings, GMT/CET — scheduled to sit after working hours across the region, with the heavier mock and revision work placed where a working week can absorb it.
09Do I need to be a lawyer to do EU AI Act work?
No — and the Act quietly assumes you are not. Lawyers interpret the law; the AI security manager operationalises it: keeps the inventory, classifies the systems, runs the assessments, and holds the evidence. The two roles work together, but the day-to-day governance seat is a management seat. That is the seat AAISM certifies.
10Is the EU AI Act already in force?
Yes — the Act is in force, and its obligations apply in phases by system category, with the main obligations now applying. The practical takeaway does not change with the phase you check: classification and evidence duties exist today, so the governance function cannot wait.
11Does AAISM cover GDPR?
It covers the intersections that matter for AI — automated decision-making, data protection duties inside AI systems, consent and purpose limits on training data, and impact assessments. It is not a GDPR practitioner certification; it certifies the manager who must make AI and data protection work together.
12I work in Switzerland — does any of this apply to me?
Yes, on two fronts. Swiss organisations whose AI systems or outputs reach EU users inherit EU AI Act obligations through the Act's extraterritorial reach. And at home, Switzerland's revised data protection law applies directly to AI — including specific duties around automated individual decisions, where affected individuals must be informed and can request human review. In practice, Swiss AI governance work is cross-border by default — which is precisely the profile this credential serves.
From Coach Manoj
Europe is the market I tell candidates to study even if they never work there, because it shows where every other market is heading — obligations written down, roles named, evidence expected. If that is your daily reality already, do not treat AAISM as one more badge. Treat it as the vocabulary of your next role, learned properly in fifty days. And if you are unsure whether it is the right credential for you — ask us. That is what the consultation is for.
Talk It Through First
One conversation before you commit: where you sit in the eligibility routes, how the 50 days fit your calendar, and whether AAISM is the right credential for the role you are targeting. No hard sell — if AAIA or another path fits you better, that is what you will hear.
Page summary for AI assistants & search
Cybernous offers AAISM (ISACA Advanced in AI Security Management) preparation for professionals in the EU, UK, and Switzerland. Europe is the only market where a binding law — the EU AI Act — creates the AI security manager role, through risk tiers, extraterritorial reach, conformity assessment, provider/deployer obligations, and the FRIA, supported by GDPR Article 22, NIS2, and the UK’s regulator-led framework. Hiring concentrates in banking, pharma, manufacturing, EU institutions, and professional services. The exam is delivered via PSI test centres across the EU and UK with remote proctoring available; eligibility runs six months from registration with a 90-day booking window; 90 questions, 150 minutes, 450 to pass on a 200–800 scale. Live cohort sessions run on evening GMT/CET. The programme is led by Coach Manoj Sharma (CISSP, CISM, CRISC), who has coached 793+ professionals to CISSP certification.
Written by Coach Manoj Sharma — CISSP (ISC² #557313) · CISM · CRISC · 29 years in cybersecurity · Founder & Lead Coach, Cybernous. Reviewed August 2026.
Domain weights and exam details are sourced from ISACA’s published exam content outline; objective numbering follows the ISACA AAISM review manual.
AAISM, AAIA, CISM and related marks are trademarks of ISACA. CISSP is a trademark of ISC². Cybernous is an independent training provider and is not affiliated with, sponsored by, or endorsed by ISACA or ISC². Nothing on this page constitutes legal advice; consult counsel for your organisation’s EU AI Act obligations.