If you already hold CISM or CISSP and you have booked ISACA's Advanced in AI Security Management exam, eight weeks is enough. The AAISM study plan below assumes six to eight hours a week and works backwards from the three domains ISACA actually publishes, weighted 31 percent, 31 percent and 38 percent. That last figure matters more than most candidates realise, and it is where the plan spends the most time.
The exam is 90 questions in 150 minutes, and you need a scaled score of 450 out of 800 to pass. That is roughly 100 seconds per question, so pace is a real constraint, not a footnote.
What the AAISM Exam Actually Tests
AAISM is not a technical AI engineering exam. It is a management exam that assumes you can already read a control framework, and it asks whether you can apply security management thinking to AI systems specifically.
| Item | Detail |
|---|---|
| Questions | 90 |
| Duration | 150 minutes (2.5 hours) |
| Passing score | 450 on a 200 to 800 scale |
| Question style | Multiple choice and scenario-based |
| Prerequisite | Active CISM or CISSP |
| Exam fee | US$459 member, US$599 non-member |
| Application fee | US$50, one time, after you pass |
| Delivery | PSI test centre or remote proctoring |
The domain weights are published in ISACA's exam content outline:
| Domain | Weighting |
|---|---|
| 1. AI Governance and Program Management | 31% |
| 2. AI Risk Management | 31% |
| 3. AI Technologies and Controls | 38% |
Three domains, 22 supporting tasks. Domain 3 is the largest single block and the one furthest from what a CISM or CISSP already taught you, which is why the plan front-loads governance and saves the second half for controls.
Exam Tip: A scaled 450 is not 450 out of 800 raw marks and it is not "56 percent". ISACA scales scores so that 450 represents a consistent standard of competence across exam forms. Do not try to reverse-engineer how many questions you can afford to drop.
Before You Start: The CISM or CISSP Gate
There is no way around this one. You must hold a current, active CISM or CISSP to sit AAISM. An expired credential does not count, there is no experience-only waiver, and ISACA does not accept an equivalent certification in its place.
Two consequences for your planning:
- If your CISM or CISSP has lapsed, reinstating it is step zero and adds weeks. Sort that before you book anything.
- You must keep that underlying certification active for as long as you hold AAISM. It is a maintenance requirement, not just an entry ticket.
If you are still working towards the prerequisite, our 12-week CISM study plan is the faster of the two routes for most people already working in security management.
How Long You Actually Need to Study for AAISM
Eight weeks at six to eight hours a week, so 50 to 65 hours total, is the right target for a candidate who holds CISM or CISSP and has some exposure to AI systems at work.
Adjust from there:
- Six weeks if you already run an AI governance programme, sit on an AI risk committee, or have worked through the EU AI Act or ISO/IEC 42001 in anger.
- Ten to twelve weeks if your AI exposure is limited to using a chatbot. Domain 3 will cost you the extra time, not the governance domains.
Cramming works badly here because a large share of the questions are scenario-based. Scenario questions reward pattern recognition built over weeks, not recall built over a weekend.
The 8-Week AAISM Study Plan
Each week assumes one longer weekend session and two or three shorter weeknight sessions. Practise questions from week two onwards, not week six. Recognising the scenario shape is the skill being tested.
Weeks 1 and 2: Domain 1, AI Governance and Program Management (31%)
Read the domain end to end, then build your own one-page map of it before touching any questions.
Cover:
- AI governance structures, and who owns AI risk in an organisation that already has an information security steering committee
- AI policy, acceptable use, and how AI-specific policy sits alongside existing security policy rather than replacing it
- Data governance for training data, including provenance, retention and consent
- AI programme management, funding, and stakeholder reporting
- Roles and responsibilities across the AI lifecycle
Start 20 practice questions at the end of week 2. Expect to score badly. The point is to learn how ISACA phrases a governance question, which is almost always "what should the information security manager do first" rather than "what is the definition of".
Weeks 3 and 4: Domain 2, AI Risk Management (31%)
This is the domain where CISM holders have the biggest head start, because the risk process is the familiar one applied to a new asset class.
Cover:
- AI-specific threat modelling, including prompt injection, training data poisoning, model inversion and model extraction
- Risk assessment for AI systems, and how model risk differs from application risk
- Third-party and supply chain risk for foundation models and AI vendors
- Risk treatment, acceptance and the reporting line to the board
- Regulatory and compliance drivers, including the EU AI Act risk tiers and ISO/IEC 42001
By the end of week 4 you should be able to explain, without notes, why a high-risk classification under the EU AI Act changes what controls you owe. Run 40 mixed questions across domains 1 and 2 and review every wrong answer against the domain outline.
Weeks 5, 6 and 7: Domain 3, AI Technologies and Controls (38%)
Three weeks, because this is 38 percent of the exam and the least familiar material for most candidates.
Cover:
- How models are built and deployed, enough to reason about where controls attach: training, fine-tuning, retrieval, inference, agents
- Security architecture for AI systems, including segmentation of training environments and inference endpoints
- Access control, authentication and authorisation for models, prompts and vector stores
- Data protection across the pipeline, covering training data, embeddings and outputs
- Monitoring, logging and detection for AI systems, including what an AI incident looks like in a log
- AI incident response, containment options when the failing component is a model, and rollback
- Testing and assurance, including red teaming and evaluation
You do not need to be able to fine-tune a model. You need to be able to say where a control goes and why. If you can describe the difference between securing a retrieval-augmented pipeline and securing a fine-tuned model, you are at the right depth.
Do 60 to 80 questions across week 7, mostly Domain 3.
Week 8: Full Mocks and Weak-Domain Repair
No new material this week. Sit at least two full 90-question mocks under timed conditions, ideally at the same time of day as your booked exam slot.
Then:
- Score each mock by domain, not overall. A 70 percent average hiding a 45 percent in Domain 3 is a fail waiting to happen.
- Spend two evenings on your weakest domain only.
- Re-read your week 1 governance map. Domain 1 material fades fastest because you learned it first.
- Stop studying 24 hours before the exam.
Our AAISM practice questions are written to the same three-domain split, so mock scores map directly onto where your revision goes next.
What Trips Candidates Up on the AAISM Exam
Answering as an engineer. The most common failure is picking the technically strongest answer rather than the one a security manager would choose first. ISACA wants governance sequence: assess, then decide, then implement.
Treating AI risk as ordinary application risk. Several scenarios hinge on something specific to models, such as training data provenance or non-deterministic output, and the generic answer is the distractor.
Underweighting Domain 3. Candidates coming from CISM find domains 1 and 2 comfortable, revise them because it feels productive, and walk into 38 percent of the exam underprepared.
Pace. At 100 seconds a question, a candidate who spends four minutes on the first ten scenario questions is behind for the rest of the paper. Flag and move on.
Exam Day: Scoring, Timing and the 450 Threshold
You get a pass or fail result on screen at the end, with the official score following by email. Scores are reported on the 200 to 800 scale, and 450 is the pass mark.
Two practical points. Your registration comes with a 12-month eligibility window, so book the date early and let the deadline work for you. And passing is not the end of it: you submit a US$50 application afterwards, and the certification is not yours until that is processed.
Maintaining it costs 30 CPE hours over a rolling three-year cycle, with a minimum of 10 hours in any single year, plus an annual maintenance fee and keeping your CISM or CISSP active. If you take the remote proctored option, the check-in discipline in our guide to online proctored exam rules applies to PSI's delivery too.
Frequently Asked Questions
Is the AAISM exam difficult?
It is harder than the domain list suggests, mainly because Domain 3 covers AI technologies most security managers have not worked with directly. The governance and risk domains are comfortable for anyone holding CISM. Candidates who fail usually fail on the 38 percent technical controls domain rather than on governance.
What study materials are available for the AAISM exam?
ISACA publishes an official review manual and a question database, and sells an optional review course. Outside ISACA, the useful supplements are the EU AI Act text, ISO/IEC 42001, the NIST AI Risk Management Framework and the OWASP Top 10 for large language model applications, all of which map onto exam content.
Where can I find practice questions for the AAISM exam?
CertCrush has a free ISACA AAISM question bank split by the three official domains, so you can see which domain is dragging your score down rather than just a single percentage.
What are the prerequisites for AAISM certification?
An active CISM or CISSP. There is no alternative route, no experience-only waiver and no other credential ISACA accepts in place of those two. You also have to keep the underlying certification current for as long as you hold AAISM.
How much does it cost to get AAISM certified?
The exam is US$459 for ISACA members and US$599 for non-members, plus a one-off US$50 application fee after you pass and an annual maintenance fee of US$20 for members or US$35 for non-members. Full pricing and the case for sitting it at all is in our AAISM certification breakdown.
Ready to Start Practising?
The plan above only works if you are testing yourself from week two, because AAISM scenario questions are a pattern-recognition skill and you cannot build that by reading. Score by domain every time so you know whether your revision is going to the 38 percent that decides the result.
Create a free CertCrush account and work through the AAISM question bank domain by domain. If you are still deciding between AI security certifications, our comparison of SecAI+ and AAISM and the wider AI governance certification roundup will settle it before you spend the exam fee.
