ISACA’s AAISM: The First AI Security Management Certification, Examined
By The Cyber Leader | balancedsec.com
In August 2025, ISACA did something long overdue. They launched a certification built specifically for security managers who need to deal with AI. Not data scientists. Not ML engineers. Security managers.
The timing wasn’t subtle. Organizations were already deploying AI systems across their operations, and most had no one formally responsible for securing those deployments. ISC2’s 2025 AI Adoption Survey found that over one-third of surveyed cybersecurity professionals cited AI as the biggest skills shortfall on their teams, and 42% said they’re actively exploring or testing AI-focused security tools. ISACA’s response was the Advanced in AI Security Management (AAISM): a credential designed to sit atop existing security management expertise and extend it into AI governance, risk, and technical controls.
I believe it’s the first certification that treats AI security as a management and leadership discipline rather than as a demonstration of technical knowledge. For CISSP or CISM holders, it’s the most directly relevant option on the market right now. But “first” doesn’t automatically mean “complete,” and the certification has limitations worth understanding before you charge the card.
Who It’s For (And Who It Isn’t)
The most important design decision ISACA made was the prerequisite. You can’t sit for the AAISM exam without an active CISM or CISSP certification. Active. Not expired or in progress.
That single requirement tells you everything about the intended audience. AAISM isn’t trying to create AI security professionals from scratch. It’s trying to take experienced security managers who already think in terms of governance, risk tolerance, and program management, and give them the AI-specific knowledge they’re missing. In other words, the credential is additive, not foundational.
The target candidate is a security leader, GRC professional, or anyone accountable for enterprise AI risk, vendor oversight, or regulatory compliance around AI systems. If your organization isn’t working with AI, or if you’re in a purely hands-on technical role with no governance responsibilities, this may not be the right investment.
The Exam: What You’re Walking Into
The AAISM exam consists of 90 multiple-choice questions and lasts 2.5 hours, roughly 1 minute and 40 seconds per question. The passing score is 450 on ISACA’s 200–800 scaled scoring system. It’s computer-based and administered through PSI testing centers or via remote proctoring (available in most countries worldwide, with a few specific regional exceptions). Available in English and Spanish.
Cost: $459 for ISACA members, $599 for non-members, plus a one-time $50 application fee after passing. You get a 12-month eligibility window, up to three attempts at full price each, and can schedule up to 90 days in advance.
Maintenance is notably lighter than what you’re used to. AAISM requires just 10 CPE hours per year (30 over three years), with an annual fee of $20 for members or $35 for non-members, due January 1st. Compare that to the CISSP’s 120 CPE credits over three years. You do need to keep your qualifying CISM or CISSP active throughout. One practical note for CISSP holders: your CISSP fee is due on your certification anniversary, but the AAISM fee is due January 1st. Different calendars. Worth noting now.
The Three Domains
Domain 1: AI Governance and Program Management (31%)
This is where CISSP holders will feel the most solid footing. This domain covers the creation, implementation, and maintenance of ethical and secure AI systems. Per the AAISM exam content outline, it covers stakeholder engagement, industry frameworks and regulatory requirements; AI-related policies and procedures; AI asset and data lifecycle management; security program development; and business continuity/incident response as they apply to AI systems.
If you’ve spent time in CISSP Domain 1 (Security and Risk Management), the concepts are structurally familiar. What’s new is the application layer. AI asset classification doesn’t work the same way as traditional IT asset management. A trained model isn’t a server. The regulatory frameworks (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) are ones you probably haven’t had to operationalize before.
Domain 2: AI Risk Management (31%)
This domain covers AI risk assessment, thresholds, and treatment; threat and vulnerability management; and AI vendor and supply chain management. It tests your ability to assess both the risks and opportunities that come with enterprise AI adoption.
The vendor and supply chain piece deserves extra attention. Multiple exam prep providers flag third-party AI risk as one of the most heavily tested areas, and the one candidates consistently underestimate. My research suggests that the AAISM exam treats AI as a supply chain problem. The questions test whether you can evaluate the risk posture of cloud AI providers, SaaS vendors running AI-powered automation, and managed model services where you don’t control the training data or model architecture.
Domain 3: AI Technologies and Controls (38%)
The largest domain by weight, and where most CISSP holders will need the most study time. It covers AI security architecture and design; the AI lifecycle (model selection, training, validation); data management controls; privacy/ethical/trust/safety controls; and security controls and monitoring.
The AI lifecycle subtopics are where I think the CISSP foundation stretches thinnest. Model selection, training pipelines, and validation processes are not in the CISSP CBK. You don’t need to become an ML engineer, but you do need to understand how models are built, what can go wrong at each phase, and what controls are appropriate.
The privacy, ethics, and trust component is a differentiator. This is where AAISM goes beyond traditional security into the realm of responsible AI, covering bias detection, fairness in automated decision-making, and transparency requirements. The EU AI Act’s risk classification system explicitly requires these controls for high-risk systems, and organizations in regulated industries need people who understand how to implement them.
Prep Materials and Study Strategy
ISACA offers several official prep resources: the AAISM Official Review Manual (digital and print), an online review course ($449 for members / $549 for non-members), and a 200+-question QAE database with a 12-month subscription. As with other exams, there may be a members-only study group on ISACA Engage, but I haven’t found a public link yet.
The review manual ($105 for non-members, $89 for members) is available either as a hardcopy book delivered to your physical address or as a platform-locked ebook accessible only through the platform's browser-based interface. Note that you can save all or a part of your eBook in your browser's cache for offline reading, but you’ll need to activate the feature before you need it.
Third-party options are still limited. Destination Certification offers a 3-day online bootcamp. Training Camp offers a 3-day in-person bootcamp with a claimed 94% pass rate and a voucher. While the cost of the bootcamp is not explicitly listed as a single public price on their main landing page, similar advanced ISACA boot camps generally run $2,500 to $3,000.
Because the cert launched less than a year ago, don’t expect the depth of community study guides, YouTube walkthroughs, or Reddit threads that exist for CISSP or CISM. Supplementing with the OWASP Top 10 for LLMs, MITRE ATLAS, and the NIST AI RMF will give you practical grounding in the frameworks referenced in the exam.
Returning to third-party risk, consider using the NIST framework to assess how to verify that a third-party vendor (such as a cloud AI provider) is meeting its own safety claims, a frequent theme in the AAISM's managerial reasoning questions.
One study tip that comes up repeatedly: the questions are scenario-based and rarely black-and-white. You’re choosing the least risky option, not the perfect one. If you’ve been through the CISSP, you know the feeling. From what I’ve read, the “ISACA mindset” leans heavily toward governance-first thinking.
The Bottom Line
The AAISM is one of the strongest governance-path AI security credentials currently available for experienced security managers. The prerequisite keeps the quality bar high, the domain coverage is relevant, and the maintenance burden is light. Every hour you spend studying counts toward your CISSP renewal as Group A credit.
But it won’t teach you hands-on model security testing (look at Practical DevSecOps’ CAISP for that). It doesn’t go deep on agentic AI security, arguably the fastest-moving threat vector right now. The third-party study ecosystem is immature. And because the certification is less than a year old, its market recognition is still building.
For CISSP holders: from what I have gathered, your Domain 1 knowledge maps strongly to AAISM Domains 1 and 2. Domain 3 (38% of the exam) is where you’ll need to put in real study time. Budget accordingly. If AI governance is in your job description today, or will be in the next 18 months, the AAISM is worth serious consideration. The window to be early is still open.


