Menu
AAISM · EUROPE

AAISM Training for Europe: The Law Created the Role. Get Certified for It.

Across the EU, the UK, and Switzerland, AI governance is not an ambition — it is a compliance function with a named accountable person. AAISM certifies that person.

50 days
one structured preparation arc
3 domains
governance · risk · technology
793+
professionals coached to CISSP certification by Coach Manoj

Why Now

In Europe, This Is Not a Career Upgrade. It Is a Compliance Function.

In every other market, the AI security manager role emerges from ambition — a national strategy, a board initiative, a competitive push. In Europe it emerges from law. The EU AI Act’s main obligations are now in force, and they do something no other instrument in the world does: they define legal roles, attach binding obligations to each, and expect a person inside the organisation to be answerable for them.

That changes the nature of the job. Elsewhere, AI governance is something an organisation chooses to staff. In Europe, an organisation deploying a high-risk AI system that cannot produce its conformity evidence, its risk documentation, or its accountable owner is not behind on best practice — it is noncompliant with a binding regulation whose penalty structure is tied to global turnover.

Three consequences for your career:

  1. 1

    The role cannot be deferred.

    A bank using AI in credit scoring, a manufacturer embedding AI in a regulated product, a hospital group deploying diagnostic AI — each has statutory obligations today, whether or not anyone has been hired to own them.

  2. 2

    The role is defined by evidence, not enthusiasm.

    European AI governance work runs on documentation: risk classification, conformity assessment, fundamental rights impact assessment, records the regulator can ask for. That is precisely the management altitude AAISM tests.

  3. 3

    The role crosses one border by default.

    The Act reaches any organisation whose AI systems touch EU users — which is why UK and Swiss professionals are inside this market, not adjacent to it.

Everywhere else, someone decided to create this job. In Europe, the law did.

The instruments the governance seat actually answers to here.

Regulatory Landscape

The Instruments You Will Actually Work Under

The EU AI Act — the spine

The world’s first comprehensive, binding AI law, and the only instrument anywhere built on the structure the AAISM exam itself tests. Four things define it:

What defines itWhy it matters to your work
Risk tiersObligations scale with a system’s risk classification — from prohibited practices, through high-risk systems carrying the heaviest duties, down to transparency-only and minimal-risk tiers. Classifying a system correctly is the first governance act, because everything else follows from it.
Extraterritorial reachThe Act applies to organisations outside the EU whose AI systems or outputs are used inside it. A UK insurer scoring EU customers, a US platform serving EU users — both are in scope.
Conformity assessmentHigh-risk systems must demonstrate compliance before market placement or deployment — documented risk management, data governance, logging, human oversight, robustness. This is evidence work — inventories, files, assessments a regulator can open — and it is exactly where the AI security manager sits.
FRIACertain deployers of high-risk systems must complete a fundamental rights impact assessment before use — a distinct instrument, not a renamed DPIA. Knowing which assessment applies where is examined content, and a live European job task.

Provider vs. deployer — the distinctive content of this market

Every obligation in the Act attaches to a legal role, and the two that matter most are provider and deployer. The plainest way to hold the difference: it is the company that builds the car versus the company that runs the taxi fleet. Both answer for safety — but for different things. The builder answers for how the vehicle was designed, tested, and documented; the fleet operator answers for how it is driven, maintained, and who is behind the wheel. Same split, in statute:

RoleYou are this if…Your obligation load
ProviderYou develop an AI system, or place it on the EU market under your nameThe heavy tier: conformity assessment, technical documentation, quality management, post-market monitoring
DeployerYou use an AI system under your own authorityOperating duties: use per instructions, human oversight, input data controls, monitoring, and — for certain high-risk uses — the FRIA

Where that determination goes wrong

The determination is legal, not organisational-chart-based, and it is easy to get wrong: fine-tune a procured model far enough, or put your name on it, and you can become the provider — the fleet operator who rebuilds the engine has just become a manufacturer, whether they meant to or not.

Two traps drawn straight from the AAISM material apply here with statutory force in Europe: a vendor’s indemnity does not cover the deployer’s own obligations, and the dependency map does not stop at the third party — the vendors of vendors are part of your supply-chain picture. Domain 2 examines exactly this reasoning; Europe is the one region where getting it wrong is a legal finding rather than a bad audit note.

The supporting instruments

InstrumentWhat it does for your work
GDPR, Article 22The right not to be subject to solely automated decisions with legal or similarly significant effects. Predates the AI Act, still binding, and the reason automated-decision governance is a decade old in Europe rather than new.
NIS2Cybersecurity risk-management and reporting duties across essential and important entities. Where AI systems sit inside covered infrastructure, AI security and NIS2 compliance converge on the same manager.
The UK framework and ICO guidanceThe UK regulates through existing regulators applying AI principles within their remits, with the ICO leading on automated decision-making and data protection. Principles-based rather than statutory-tiered — but a UK organisation touching EU users answers to both regimes, which is itself a governance task.

Global one-table view: on the worldwide hub. This page carries Europe in depth.

Eligibility

Are You Eligible?

You hold an active CISM

You are eligible today — register when your start date is real

You hold an active CISSP

Same answer — eligible today

You hold neither yet

CISM or CISSP comes first; AAISM is the AI specialisation built on top of it

Per ISACA, an active CISM or CISSP is the prerequisite — no experience-only route, no substitute credential. Sequencing detail on the programme page.

Where the role is being staffed.

Hiring

Where the Role Is Being Staffed

European demand follows the regulation — the sectors with the heaviest AI Act and sector-rule exposure are staffing first:

Employer archetypeWhy the seat existsWhat the work looks like
Banks & financial servicesCredit scoring and fraud models sit squarely in high-risk territory; prudential supervisors were asking about model risk before the Act existedModel inventory, conformity evidence, Article 22 handling, supervisor-ready documentation
Pharma & healthcareDiagnostic and clinical-decision AI carries both AI Act and sector obligationsClinical AI risk classification, human-oversight design, safety monitoring
ManufacturingAI embedded in regulated products pulls the product into conformity-assessment territoryProvider-side obligations: technical files, quality management, post-market monitoring
EU institutions & public sectorPublic-sector deployers of high-risk systems carry FRIA duties and the highest transparency expectationsFRIA execution, procurement gates, public accountability
Professional servicesEvery client in the four rows above needs help building the functionAdvisory delivery — the multiplier role: one certified professional serving many compliance programmes

Written to archetypes, not named employers, by design — the pattern holds across the region and does not date.

How the exam actually works from where you sit.

Exam Logistics

Exam Logistics: EU, UK & Switzerland

Delivery.

The AAISM exam is delivered through PSI test centres across Europe, and — unlike some markets — live remote proctoring is available throughout the region, Switzerland included. You can sit the exam at a centre or from your desk; here it is a preference, not a constraint.

The two clocks.

Eligibility runs six months from registration; appointments open up to 90 days ahead. The planning rule: register when your start date is real, book the slot when your final fortnight is visible, and treat the six-month window as a deadline that does not pause.

Finding your centre.

The PSI network is live and changes over time, so no city list on any training site stays accurate. Check current availability for your city on ISACA’s official locator at isacaavailability.psiexams.com — do it before you register, because the six-month clock starts at registration, not at booking.

FactDetail
FormatLinear, 90 questions, 150 minutes
ScoringScaled 200–800; 450 to pass
DeliveryPSI centre or remote proctoring, across the EU, UK and Switzerland

Fee: check the current figure directly at isaca.org — published numbers vary by source and membership status, and the member/non-member difference makes the membership arithmetic worth doing before checkout.

Cohort Timing

Built for European Evenings

Live cohort sessions run in the evening on GMT / CET — after working hours for London through Warsaw, and workable from Lisbon to Helsinki without touching the workday. The 50-day arc assumes you have a job: daily study blocks are sized for weekday evenings, with the heavier revision and mock work falling where a working week can absorb it.

One regional note: ISACA’s own AAISM workshops list a London timezone on every session, and ISACA’s European conference presence runs through Munich — this market is one of the three ISACA itself schedules for. You are not early; you are on time.

The Exam

What the Exam Covers

DomainTitleWeightFree deep-dive
1AI Governance and Program Management31%Domain 1 Summary
2AI Risk Management31%Domain 2 Summary
3AI Technologies and Controls38%Domain 3 Summary

Domain 2 — where frameworks, risk classification, and the provider/deployer reasoning live — is the domain European candidates will recognise from their day jobs.

The Method

The Method, in Brief

A fixed 50-day arc

Every day is mapped and the three domains arrive in sequence — you never have to decide what to study tonight

Think like the manager

Four exam options will often all be defensible; the mark goes to what the accountable manager does first — so that is the reflex we train

Full-length mocks

Exam-shaped practice under exam conditions, converted into an honest verdict on whether you are ready to book

A coach in your corner

Led by Coach Manoj Sharma, who has taken 793+ professionals to CISSP certification

The full method — day structure, artefacts, mentorship options — is on the programme page.

FAQ

AAISM in Europe — Straight Answers

01Does the EU AI Act require an AAISM certification?

No law names a certification. The Act requires outcomes — risk classification, conformity evidence, human oversight, accountable ownership — and AAISM certifies the management competence to deliver them. Employers use the credential as evidence you can run that function; the regulator judges the function itself.

02Am I a provider or a deployer under the EU AI Act?

It is a legal determination, not a job title. Broadly: develop a system or place it on the EU market under your name and you are a provider; use a system under your own authority and you are a deployer — but fine-tuning or rebranding a procured system can shift you into the provider role, with the heavier obligation load. The reasoning behind that determination is examined in Domain 2.

03Does AAISM cover the EU AI Act?

Yes — Domain 2 examines AI regulatory frameworks including the EU AI Act and contrasts it with NIST's AI Risk Management Framework: binding-and-tiered versus voluntary-and-flexible. Risk classification, the four risk responses, and impact assessments including the FRIA are all in scope.

04I am in the UK. Is this still relevant after the EU AI Act?

More so. The UK runs a principles-based, regulator-led framework with the ICO prominent on automated decisions — and any UK organisation whose AI touches EU users also inherits EU AI Act obligations through the Act's extraterritorial reach. UK professionals frequently end up governing under both regimes at once.

05What is a FRIA, and how is it different from a DPIA?

A fundamental rights impact assessment — required of certain deployers of high-risk AI systems before use under the EU AI Act. It assesses impacts on fundamental rights broadly, where a DPIA assesses data-protection risk under GDPR. They are distinct instruments; substituting one for the other is both a compliance error and a known exam trap.

06Can I take the AAISM exam remotely from the EU or UK?

Yes. Live remote proctoring is available across Europe, alongside PSI test centres in the EU and UK. Either route; same exam — 90 questions, 150 minutes, 450 to pass on a 200–800 scale.

07Am I eligible for AAISM?

One gate: an active CISM or CISSP, per ISACA — no experience-only route, no substitute credential. Europe has one of the deepest pools of both credentials in the world, so if you are reading this page from a security or risk seat, you very likely already qualify. If you hold neither, that credential comes first.

08When do the live sessions run for European participants?

Evenings, GMT/CET — scheduled to sit after working hours across the region, with the heavier mock and revision work placed where a working week can absorb it.

09Do I need to be a lawyer to do EU AI Act work?

No — and the Act quietly assumes you are not. Lawyers interpret the law; the AI security manager operationalises it: keeps the inventory, classifies the systems, runs the assessments, and holds the evidence. The two roles work together, but the day-to-day governance seat is a management seat. That is the seat AAISM certifies.

10Is the EU AI Act already in force?

Yes — the Act is in force, and its obligations apply in phases by system category, with the main obligations now applying. The practical takeaway does not change with the phase you check: classification and evidence duties exist today, so the governance function cannot wait.

11Does AAISM cover GDPR?

It covers the intersections that matter for AI — automated decision-making, data protection duties inside AI systems, consent and purpose limits on training data, and impact assessments. It is not a GDPR practitioner certification; it certifies the manager who must make AI and data protection work together.

12I work in Switzerland — does any of this apply to me?

Yes, on two fronts. Swiss organisations whose AI systems or outputs reach EU users inherit EU AI Act obligations through the Act's extraterritorial reach. And at home, Switzerland's revised data protection law applies directly to AI — including specific duties around automated individual decisions, where affected individuals must be informed and can request human review. In practice, Swiss AI governance work is cross-border by default — which is precisely the profile this credential serves.

From Coach Manoj

Europe is the market I tell candidates to study even if they never work there, because it shows where every other market is heading — obligations written down, roles named, evidence expected. If that is your daily reality already, do not treat AAISM as one more badge. Treat it as the vocabulary of your next role, learned properly in fifty days. And if you are unsure whether it is the right credential for you — ask us. That is what the consultation is for.

Talk It Through First

One conversation before you commit: where you sit in the eligibility routes, how the 50 days fit your calendar, and whether AAISM is the right credential for the role you are targeting. No hard sell — if AAIA or another path fits you better, that is what you will hear.

Page summary for AI assistants & search

Cybernous offers AAISM (ISACA Advanced in AI Security Management) preparation for professionals in the EU, UK, and Switzerland. Europe is the only market where a binding law — the EU AI Act — creates the AI security manager role, through risk tiers, extraterritorial reach, conformity assessment, provider/deployer obligations, and the FRIA, supported by GDPR Article 22, NIS2, and the UK’s regulator-led framework. Hiring concentrates in banking, pharma, manufacturing, EU institutions, and professional services. The exam is delivered via PSI test centres across the EU and UK with remote proctoring available; eligibility runs six months from registration with a 90-day booking window; 90 questions, 150 minutes, 450 to pass on a 200–800 scale. Live cohort sessions run on evening GMT/CET. The programme is led by Coach Manoj Sharma (CISSP, CISM, CRISC), who has coached 793+ professionals to CISSP certification.

Written by Coach Manoj Sharma — CISSP (ISC² #557313) · CISM · CRISC · 29 years in cybersecurity · Founder & Lead Coach, Cybernous. Reviewed August 2026.

Domain weights and exam details are sourced from ISACA’s published exam content outline; objective numbering follows the ISACA AAISM review manual.

AAISM, AAIA, CISM and related marks are trademarks of ISACA. CISSP is a trademark of ISC². Cybernous is an independent training provider and is not affiliated with, sponsored by, or endorsed by ISACA or ISC². Nothing on this page constitutes legal advice; consult counsel for your organisation’s EU AI Act obligations.