← StudyBase

AAISM Exam Prep: The Complete Study Guide for ISACA's New AI Security Certification

Last updated: August 2026

If you're a CISM or CISSP holder searching for "AAISM exam prep," you've probably noticed there isn't much out there yet. That's because ISACA's Advanced in AI Security Management (AAISM) is a brand-new credential — which means the study resources are still catching up to the demand. This guide covers what the exam actually tests, how it's structured, and how to build a study plan that doesn't waste your time on the wrong material.

What Is the AAISM Certification?

AAISM (Advanced in AI Security Management) is ISACA's first AI-focused security management credential. Unlike entry-level AI courses aimed at generalists, AAISM is built for people who already manage security programs and need to extend that expertise to AI-specific risk — governance, vendor oversight, model risk, and regulatory exposure.

Eligibility: You must hold an active CISM or CISSP to sit for the exam. ISACA isn't trying to create AI security specialists from a blank slate — it's testing whether experienced security managers can apply what they already know (risk tolerance, governance structures, program management) to AI systems specifically.

Exam Format at a Glance

  • 90 questions — multiple-choice and scenario-based
  • 2.5 hours (150 minutes) — roughly 1.6 minutes per question
  • Scaled scoring, 200–800 range
  • Passing score: 450
  • Delivered through ISACA's authorized testing partners, in-person or remote proctored

The scenario-based questions are the real difficulty spike. This isn't a definitions test — you're given a situation (a vendor using an undisclosed foundation model, a shadow-AI deployment, a model drifting out of its approved use case) and asked to choose the most defensible next action, not just the "correct" textbook answer.

The Three Domains

DomainWeightFocus
Domain 1: AI Governance and Program Management31%Policy, oversight structures, accountability, AI program lifecycle
Domain 2: AI Risk Management31%Risk identification, assessment, third-party/vendor AI risk, treatment
Domain 3: AI Technologies and Controls38%Technical controls, model security, AI-specific threats and mitigations

Domain 3 carries the most weight and tends to require the most study time — it's the domain most likely to trip up candidates whose background is heavier on governance/GRC than on the technical side of how AI systems actually fail.

How to Build Your Study Plan

  1. Start with the official ISACA review manual. It's the source of truth for terminology and framework alignment — skipping it and going straight to practice questions is a common mistake.
  2. Weight your study time to match the exam weighting. Domain 3 is 38% of the exam; don't split your time evenly across all three domains.
  3. Prioritize scenario-based practice over flashcard memorization. Because the exam tests applied judgment, drilling definitions alone won't prepare you for the actual question format. Practice questions that force you to weigh trade-offs (e.g., "which control is most appropriate," not just "which control exists") map much more closely to what you'll see on exam day.
  4. Map the domains to your own work experience. If you've handled a vendor risk assessment, a governance committee, or an incident response process, spend a few minutes translating that experience into AI-specific terms — it makes the scenario questions far more intuitive.
  5. Time yourself early. At 1.6 minutes per question, time pressure is a real factor. Run practice sets under exam-length conditions at least twice before test day.

Is the AAISM Exam Hard?

It depends heavily on your background. If you've already worked with AI governance or vendor risk in practice, the exam will feel like an extension of your day job. If your CISM/CISSP experience is more traditional (network security, IAM, classic GRC) without much AI exposure, expect Domain 3 to require real study time — it's newer material even for experienced security managers.

Where to Find Practice Questions

Because AAISM is so new, there's a real gap in scenario-based practice material — most of what exists right now is the official ISACA manual plus a handful of blog posts summarizing the exam format (like this one). If you want to test where you stand before committing to a full study plan, StudyBase's free AAISM diagnostic covers all three domains and shows you which one needs the most work — no signup required to try the first set of questions.

FAQ

Is AAISM worth it if I already have CISM or CISSP?
For security leaders and GRC professionals who are now accountable for AI risk, vendor oversight, or AI-related regulatory compliance, AAISM is currently the only credential that validates that specific skill set at an advanced level.

How is StudyBase different from just studying the official ISACA manual?
The manual is the source of truth for terminology and frameworks, but it doesn't tell you where you actually stand. StudyBase's diagnostic and practice banks are blueprint-mapped and scenario-based, so you spend study time on the domains and question types that trip up experienced managers — especially Domain 3 — instead of re-reading material you already know.

Not affiliated with or endorsed by ISACA. AAISM is an ISACA certification mark, used only to describe the exam this content refers to.