Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about ISACA's advanced AI security credential as of 2026, covering the three domains, exam format, the CISM or CISSP prerequisite, career paths, the frameworks it maps to, and how AAISM compares to AAIA and AAIR. A complete reference guide for security leaders weighing the AAISM.
AI policy, data governance, program oversight, and incident response. 31% of the exam.
Assessing and managing AI-specific risk, threats, and supply chain issues. 31% of the exam.
AI security architecture, the model lifecycle, and tailored controls. The heaviest domain at 38%.
AAISM is ISACA's advanced AI security credential, launched in 2025 for experienced security leaders who already hold a CISM or CISSP.
It validates the ability to identify, assess, and mitigate the risks that come with enterprise AI, and to govern AI systems across their lifecycle. It is not a model-building or coding exam. It tests the management-level judgment to set AI policy, run an AI security program, and answer for it to the board, which is exactly the gap that traditional security credentials left open.
Because it is an advanced add-on, AAISM has a hard prerequisite: an active CISM or CISSP. It is issued by ISACA, the body behind CISM, CISA, and CRISC, and it maps directly to the AI frameworks enterprises and regulators are adopting.
Four things that set AAISM apart as organizations scramble to put governance around the AI they are already running.
Most AI credentials are either deeply technical or purely about policy. AAISM sits in the management seat: it asks how you advise the board on AI risk appetite, set the governance framework, and run the program. As of 2026, that is the role organizations are struggling to staff.
AAISM is an advanced credential with a hard prerequisite: you must hold an active CISM or CISSP to sit it. That gate means every AAISM holder already has a proven security management foundation, and the exam builds AI expertise on top rather than starting from scratch.
As of 2026, AI governance and security roles command a meaningful premium over general security management, with senior roles running well into six figures. Our guide on choosing an AI governance certification covers the trade-offs.
AAISM is not currently part of the DoD 8140 qualification matrix. Its weight comes from ISACA's standing and from mapping directly to the frameworks enterprises and regulators are adopting: the NIST AI Risk Management Framework, ISO/IEC 42001, the OWASP Top 10 for LLM Applications, and MITRE ATLAS.
For organizations operating under the EU AI Act or building toward it, that framework alignment is exactly what makes the credential useful right now.
Everything you need to know about the certification, the exam structure, and how to maintain AAISM as of 2026.
AAISM covers the security management side of AI. Professionals who span audit, risk, or policy often pair it with one of these to cover the full AI governance picture.
ISACA's Advanced in AI Risk focuses on governing and managing AI risk across the enterprise. It shares AAISM's exam structure and requires one of around 25 qualifying risk or security designations.
ISACA's Advanced in AI Audit is for auditors who verify whether AI controls actually work. It requires an audit credential such as CISA, CIA, or CPA, and pairs naturally with a security or risk specialty.
The IAPP AI Governance Professional comes at AI from the policy and law side, with deep coverage of the EU AI Act. A common pairing with AAISM for people who need both the operational and the policy view.
AAISM is a specialization, not a starting point. It sits on top of a security management foundation and points toward the broader AI audit, risk, and governance credentials around it.
The required base
The add-on
Two questions to answer before you commit: can you sit it, and should you pursue AAISM specifically. Here's a straight answer to both.
You're eligible now.
AAISM is an advanced credential gated behind an active CISM or CISSP. If you hold either, you meet the prerequisite. Register, sit the 90-question exam, and pass with a scaled score of 450. ISACA also recommends real experience assessing or maintaining AI systems going in.
Earn the prerequisite first.
Unlike most certifications, there is no test-first path for AAISM. You cannot sit it without an active CISM or CISSP. If neither is in hand, the right move is to earn one of those first, then come back to AAISM as the AI specialization on top.
AAISM targets leadership roles in AI security and governance. These are the roles the credential is built for, sitting on top of an existing security management foundation.
Owns the security of an organization's AI systems end to end, from model pipelines to deployed services. The role AAISM was built to validate as enterprises put AI into production.
Builds and runs the policies, accountability structures, and oversight that govern how AI is adopted and used, mapping frameworks like NIST AI RMF and ISO/IEC 42001 onto the business.
Identifies and mitigates AI-specific risk: data poisoning, model bias, prompt injection, and third-party and supply chain exposure across the AI lifecycle.
Security executives now accountable for AI risk to the board. AAISM is the credential that signals you can govern AI, not just understand it technically.
Designs secure AI system architectures and the controls around model selection, training, validation, and monitoring across the lifecycle.
Advises organizations on secure, responsible, and compliant AI adoption, including EU AI Act readiness and vendor and supply chain assessment.
ISACA's three advanced AI credentials share an exam structure but aim at different jobs: securing AI, auditing AI, and managing AI risk. Here's how they line up.
| AAISM | AAIA | AAIR | |
|---|---|---|---|
| Issuer | ISACA | ISACA | ISACA |
| Focus | AI security management | AI audit and assurance | AI risk management |
| Prerequisite | Active CISM or CISSP | CISA, CIA, or CPA | One of ~25 risk or security certs |
| Exam Format | 90 questions, 2.5 hours | 90 questions, 2.5 hours | 90 questions, 2.5 hours |
| Passing Score | 450 / 800 | 450 / 800 | 450 / 800 |
| Renewal | 30 CPEs over 3 years | 30 CPEs over 3 years | 30 CPEs over 3 years |
| DoD 8140 Approved | No | No | No |
| Best For | Security leaders governing AI | Auditors assuring AI | Risk pros managing AI |
All three are advanced credentials that require an existing designation. Pricing and prerequisites vary; check ISACA for the current qualifying list before you register.
Our ISACA AAISM boot camp covers all three domains over three days, with your exam voucher and official courseware included, built for security leaders who already hold CISM or CISSP and are taking on AI.
Choosing among the AI credentials, the ISACA AI family, and where AAISM fits in AI governance.
AAISM is for managers who set AI security strategy, AAIA for auditors who verify controls, AAIR for risk pros. A clear read on which of the three ISACA AI credentials fits your work.
A deeper look at why ISACA built AAISM, what gap it fills for CISM and CISSP holders, and what each of the three exam domains actually asks you to demonstrate.
SecAI+ is for practitioners who touch keyboards, AAISM for managers who set strategy, AAIA for auditors. How to pick the right AI security credential for the job you actually do.
The questions that actually clarify the choice: your jurisdiction, the frameworks you already run, and how mature your AI program is. Where AAISM fits in that decision.
The frameworks and accountability structures behind responsible AI, from ISO/IEC 42001 and the NIST AI RMF to the OECD principles, and the context AAISM is built on.
The governance-and-policy counterpart to AAISM. How the IAPP AI Governance Professional credential fits for people coming at AI from the privacy and compliance side.
Why AAISM exists, who it is and is not for, and how it sits on top of the security management foundation that CISM and CISSP holders already have.
The AAISM job practice is organized into three domains, each carrying its own weight on the exam. Click any domain for what it covers.
Advising stakeholders on AI security, building AI-specific policies and procedures, managing the AI asset and data lifecycle, running the AI security program, and incident response tailored to AI.
Assessing and managing the risks, threats, vulnerabilities, and supply chain issues that come with enterprise-wide AI adoption, from data poisoning and model bias to third-party AI exposure.
The heaviest domain. AI security architecture and design, the AI lifecycle, data management controls, privacy and trust and safety controls, and the security controls and monitoring tailored to AI systems.
Domains and weights reflect the ISACA AAISM Exam Content Outline as of the 2025 launch. ISACA updates its outlines on a regular cycle.
The questions candidates ask most often when researching the Advanced in AI Security Management certification.
AAISM is ISACA's advanced AI security credential, launched in 2025. It validates the ability to identify, assess, and mitigate AI-related risk and to govern AI systems at the program level. It's built for experienced security leaders rather than beginners, and it has a hard prerequisite.
AAISM fits security managers, CISOs, and risk and compliance leaders whose organizations are adopting AI and who already hold a CISM or CISSP. It isn't a technical model-building exam and it isn't for beginners. People coming at AI from policy or law are usually better served by AIGP.
Yes. AAISM is an advanced credential with a hard prerequisite: you must hold an active CISM or CISSP to register and sit the exam. There is no test-first path. If you don't hold either, you need to earn one before pursuing AAISM.
As of 2026 the AAISM exam costs $459 for ISACA members and $599 for non-members, and you have a 12-month window after registering to sit it. Pricing can vary slightly by region. Many candidates take a boot camp that folds the exam voucher into the course price.
The AAISM exam is 90 questions over 2.5 hours, combining multiple choice and scenario-based items, delivered through PSI in person or via remote proctoring. The questions test management judgment rather than coding. You need a scaled score of 450 out of 800 to pass.
The three AAISM domains are AI Governance and Program Management, AI Risk Management, and AI Technologies and Controls. AI Technologies and Controls carries the heaviest weight at 38 percent, with the other two at 31 percent each.
AAISM is maintained on a three-year cycle. You earn 30 Continuing Professional Education (CPE) credits over the cycle, focused on the AI domain, with a minimum each year, and pay an annual maintenance fee to ISACA. You also follow the ISACA Code of Professional Ethics.
Not currently. AAISM does not appear on the DoD 8140 Approved Qualifications Matrix V2.1. Its recognition rests on ISACA's standing and on its alignment to the AI frameworks enterprises and regulators use, such as the NIST AI RMF, ISO/IEC 42001, and the EU AI Act, rather than on DoD 8140 status.
All three are ISACA advanced AI credentials with the same exam structure. AAISM is for security leaders who secure and govern AI, AAIA is for auditors who verify AI controls, and AAIR is for risk professionals managing AI risk. They differ mainly in focus and in which prerequisite certification you need.
AAISM from ISACA is a security-management credential that requires a CISM or CISSP and centers on securing and governing AI systems. AIGP from the IAPP comes at AI from the policy, privacy, and law side, with deep EU AI Act coverage and no security prerequisite. Many professionals pair the two.
Yes. ISACA launched AAISM in 2025 as part of a new family of advanced AI credentials alongside AAIA for audit and AAIR for risk. Because it is new, there are few competing reference points, which is part of why early holders stand out for AI security governance roles.
For CISM or CISSP holders whose organizations are adopting AI, AAISM is one of the few credentials that speaks directly to governing AI security at the management level in 2026. AI governance roles carry a salary premium and the talent gap is real. It's less useful for those without the prerequisite or on a purely hands-on technical track.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.