Advanced in AI Security Management (AAISM)
A management-level AI security credential covering AI governance, risk management, and technical controls — gated behind an active CISM or CISSP, which rules out most engineers early in the field.
- src
- ISACA — Advanced in AI Security Management (AAISM) credential page (isaca.org/credentialing/aaism)
- chk
Before anything else about this certification: you cannot sit it without an active CISM or CISSP. ISACA states this plainly, there is no experience waiver, and it changes who this page is useful to.
If you are working through the AI security engineer path and looking for a credential to aim at, this is not it — not yet. The AAISM describes the job above the one that roadmap trains for.
Who it is actually for
Security managers who already hold a CISM or CISSP and have acquired AI systems inside their remit. That is a real and growing group, and for them the AAISM is well targeted: it is the first credential to treat AI security as a management discipline with its own risk vocabulary rather than as a subsection of application security.
For a hands-on engineer, the framing is the problem. The largest domain is technical in subject at 38%, but it is written as assurance and oversight — which controls should exist, how you would know they work, who is accountable when they do not. That is a legitimate skill. It is not the skill of building the guardrail.
Against the AIGP
The comparison worth making is with the IAPP's AIGP, which this site also covers.
The AIGP has no certification prerequisite and takes a deliberately broad audience, including people arriving from legal and policy work. The AAISM sits inside ISACA's security management track and gates on CISM or CISSP.
So the choice is usually made for you. If you hold neither prerequisite, the AIGP is the accessible governance credential. If you already hold a CISM or CISSP and your organisation is an ISACA shop, the AAISM slots into a maintenance cycle you are already paying for.
What ISACA publishes, and what it does not
The domain weights are official and they sum cleanly: AI Technologies and Controls 38%, AI Governance and Program Management 31%, AI Risk Management 31%. The 90-question count is published too.
The duration and the passing score are not on ISACA's public AAISM pages. The 150 minutes and the 450-of-800 scaled score that circulate widely come from ISACA's general scoring model and from third-party summaries. Both are probably right; neither is confirmed on the pages this entry cites, and this page will not present them as though they were.
The real cost
The advertised $459 or $599 is not the number. Add the $50 application fee, the annual maintenance fee, and the continuing-education requirement across a three-year cycle. Then add the prerequisite — a CISM or CISSP has its own exam fee, its own experience requirement and its own annual maintenance.
Counted honestly, the AAISM is the cheapest part of a multi-year, multi-thousand-dollar commitment. That is fine if you were on that path already. It is a poor reason to start down it.
Exam domains
AI Technologies and Controls
38%AI Governance and Program Management
31%AI Risk Management
31%Preparation path
- 1
Confirm you are eligible before spending anything
AAISM requires an active CISM or CISSP. It is a bolt-on credential and cannot be earned from scratch, so for most engineers the real first step is several years and a separate certification away. Check this before budgeting for study material.
~1 hours - 2
Learn the governance frameworks the exam is built on
Nearly a third of the marks are governance and program management, and the vocabulary comes from published frameworks rather than from practice. The NIST AI Risk Management Framework is the most directly useful free source, and the EU AI Act supplies the regulatory shape.
~20 hours - 3
Work the risk domain as risk, not as security
Identification, assessment, treatment and monitoring, in ISACA's vocabulary rather than an engineer's. This is the domain where technical candidates lose marks: the expected answer is often a governance response where instinct suggests a control.
~18 hours - 4
Cover the technical controls domain, the largest at 38%
Architecture, data protection, model and supply chain integrity, and monitoring. Engineers arriving from hands-on AI security work will find this the easiest block, but the framing is assurance and oversight rather than implementation.
~20 hours