Last updated: August 2026
If you're a CISM or CISSP holder searching for "AAISM exam prep," you've probably noticed there isn't much out there yet. That's because ISACA's Advanced in AI Security Management (AAISM) is a brand-new credential — which means the study resources are still catching up to the demand. This guide covers what the exam actually tests, how it's structured, and how to build a study plan that doesn't waste your time on the wrong material.
AAISM (Advanced in AI Security Management) is ISACA's first AI-focused security management credential. Unlike entry-level AI courses aimed at generalists, AAISM is built for people who already manage security programs and need to extend that expertise to AI-specific risk — governance, vendor oversight, model risk, and regulatory exposure.
Eligibility: You must hold an active CISM or CISSP to sit for the exam. ISACA isn't trying to create AI security specialists from a blank slate — it's testing whether experienced security managers can apply what they already know (risk tolerance, governance structures, program management) to AI systems specifically.
The scenario-based questions are the real difficulty spike. This isn't a definitions test — you're given a situation (a vendor using an undisclosed foundation model, a shadow-AI deployment, a model drifting out of its approved use case) and asked to choose the most defensible next action, not just the "correct" textbook answer.
| Domain | Weight | Focus |
|---|---|---|
| Domain 1: AI Governance and Program Management | 31% | Policy, oversight structures, accountability, AI program lifecycle |
| Domain 2: AI Risk Management | 31% | Risk identification, assessment, third-party/vendor AI risk, treatment |
| Domain 3: AI Technologies and Controls | 38% | Technical controls, model security, AI-specific threats and mitigations |
Domain 3 carries the most weight and tends to require the most study time — it's the domain most likely to trip up candidates whose background is heavier on governance/GRC than on the technical side of how AI systems actually fail.
It depends heavily on your background. If you've already worked with AI governance or vendor risk in practice, the exam will feel like an extension of your day job. If your CISM/CISSP experience is more traditional (network security, IAM, classic GRC) without much AI exposure, expect Domain 3 to require real study time — it's newer material even for experienced security managers.
Because AAISM is so new, there's a real gap in scenario-based practice material — most of what exists right now is the official ISACA manual plus a handful of blog posts summarizing the exam format (like this one). If you want to test where you stand before committing to a full study plan, StudyBase's free AAISM diagnostic covers all three domains and shows you which one needs the most work — no signup required to try the first set of questions.
Is AAISM worth it if I already have CISM or CISSP?
For security leaders and GRC professionals who are now accountable for AI risk, vendor oversight, or AI-related regulatory compliance, AAISM is currently the only credential that validates that specific skill set at an advanced level.
How is StudyBase different from just studying the official ISACA manual?
The manual is the source of truth for terminology and frameworks, but it doesn't tell you where you actually stand. StudyBase's diagnostic and practice banks are blueprint-mapped and scenario-based, so you spend study time on the domains and question types that trip up experienced managers — especially Domain 3 — instead of re-reading material you already know.
Not affiliated with or endorsed by ISACA. AAISM is an ISACA certification mark, used only to describe the exam this content refers to.