AAISM: ISACA Advanced in AI Security Management (AAISM)
Browse certifications
Exam Resources
Official learning paths, exam details, skills measured, and community resources to supplement your study.
About the AAISM Exam
Govern, assess, and control enterprise AI security risk with confidence
250 original practice questions for the ISACA AAISM (Advanced in AI Security Management) exam. Every question includes detailed explanations, scenario-based context, and exam tips. Covers all 3 domains: AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls — grounded in the frameworks the exam is built on: NIST AI RMF, ISO/IEC 42001, the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the EU AI Act.
AAISM is ISACA’s advanced credential for security leaders who already hold an active CISM or CISSP and now need to govern, assess, and secure enterprise AI. It is not an ML-engineering exam — it tests governance judgment, risk treatment, and control selection for AI and generative-AI systems.
Who Should Take This Exam?
The AAISM is designed for experienced security managers and leaders governing enterprise AI — CISOs, AI security managers, AI governance leads, security and risk architects, and GRC managers. An active CISM or CISSP is required to earn the credential.
Typical study time: 4-8 weeks of focused study
Exam Quick Facts
| Detail | Value |
|---|---|
| Exam Code | AAISM |
| Title | ISACA Advanced in AI Security Management |
| Duration | 150 minutes |
| Questions | 90 |
| Pass Score | 450 / 800 |
| Cost | $459 USD (member) / $599 USD |
| Provider | PSI |
| Prerequisite | Active CISM or CISSP |
| Question Types | Multiple choice |
| Official Page | View on ISACA → |
Exam Domains & Weights
The AAISM exam covers 3 domains. Focus your study time based on the weights below — higher-weighted domains have more exam questions.
| Domain | Weight | Practice Qs |
|---|---|---|
| AI Governance and Program Management | 31% | 78 |
| AI Risk Management | 31% | 77 |
| AI Technologies and Controls | 38% | 95 |
| Total | 100% | 250 |
💡 Study tip: AI Technologies and Controls carries the most weight (38%) — that’s where AI-specific security architecture, the model lifecycle, privacy-enhancing techniques, and adversarial-ML defenses live, so start there. But Governance (31%) and Risk (31%) are nearly as heavy — know the NIST AI RMF functions (GOVERN, MAP, MEASURE, MANAGE), the OWASP Top 10 for LLM Applications (2025), and the difference between data poisoning, evasion, model inversion, membership inference, and model extraction cold.
Practice Exam — 250 Questions
Prepare for the AAISM with our 250-question practice exam covering all 3 exam domains. Every question is a real-world governance, risk, or control scenario with detailed explanations mapped to the frameworks the exam is built on.
What you get:
- ✅ Exam simulation mode with timer
- ✅ Spaced repetition for weak areas
- ✅ Detailed explanations for every question
- ✅ Progress tracking across domains
- ✅ 20 free questions — no account needed
ISACA Certification Path
ISACA certs are role-based, not hierarchical. CISA for auditors, CISM for security managers, CRISC for risk professionals, CGEIT for IT governance, CDPSE for privacy — and AAISM as the advanced AI-security specialization for CISM/CISSP holders governing enterprise AI.
Related ISACA Certifications
If you’re studying for the AAISM, you might also be interested in these ISACA certifications:
- CISM: ISACA Certified Information Security Manager — 250 practice questions
- CRISC: ISACA Certified in Risk and Information Systems Control — 250 practice questions
- CISA: ISACA Certified Information Systems Auditor — 250 practice questions
- CDPSE: ISACA Certified Data Privacy Solutions Engineer — 250 practice questions
Study Tips
- Know the frameworks cold — NIST AI RMF (GOVERN/MAP/MEASURE/MANAGE), ISO/IEC 42001, OWASP Top 10 for LLM Apps (2025), MITRE ATLAS, and the EU AI Act’s four risk tiers are the backbone of the exam
- Master the attack taxonomy — data poisoning (training-time) vs evasion (inference-time) vs model inversion vs membership inference vs model extraction are the most-confused distinctions
- Think like a governor, not an engineer — the answer is usually a governance principle, risk-treatment decision, or control selection, not a product or a line of code
- Use our practice exam — try the 20 free questions first to gauge your readiness
- Check the official page — official exam details always have the latest objectives