Try ISACA AAISM
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to ISACA AAISM
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
ISACA · Exam reference
About the ISACA AAISM exam
ISACA's Advanced in AI Security Management (AAISM) is the first advanced certification for security leaders responsible for governing, assessing, and controlling AI systems. It's a scenario-based management exam covering AI governance, AI risk, and AI technologies and controls — and it requires an active CISM or CISSP to sit. Built for CISOs, security managers, and risk leads who now own the AI question.
10
Sample questions
150 min
Exam time limit
70%
Passing score
$599
Exam voucher
The ISACA Advanced in AI Security Management (AAISM) is the first certification built specifically for the security leaders who now have to answer for AI. ISACA launched it in August 2025, and unlike the wave of general AI literacy badges, it is genuinely advanced: you must already hold an active CISM or CISSP before you can register. That prerequisite tells you what the exam is really about. AAISM does not ask you to build a transformer or tune a learning rate. It asks what a security manager does when the business wants a customer-facing chatbot next quarter, when a vendor cannot tell you what their foundation model was trained on, or when an indirect prompt injection turns your RAG pipeline into an exfiltration channel. Every question is scenario-based, and the answer ISACA wants is the most defensible management action, not the most technical one. The syllabus spans three domains. AI Governance and Program Management (31%) covers stakeholders, NIST AI RMF, ISO/IEC 42001, the EU AI Act, policy, the AI asset and data life cycle, and incident response. AI Risk Management (31%) covers risk assessment and thresholds, impact assessments, model theft, data poisoning, evasion, membership inference, and vendor and supply chain risk. AI Technologies and Controls (38%), the heaviest domain, covers secure architecture patterns, the secure AI life cycle, data management controls, privacy and ethics controls, and continuous monitoring. If you are a CISO, security manager, risk lead, or consultant being asked to sign off on AI systems, AAISM is the credential that puts a recognised framework behind your judgement.
Exam Domains Covered
Exam Format & Details
90 scenario-based multiple-choice questions in 150 minutes (2.5 hours) — roughly 100 seconds per question. Scored on ISACA's 200–800 scale, with 450 required to pass. You see a provisional result on screen and the official score report lands in your ISACA account shortly after. Delivered by PSI, either at a test centre or via remote proctoring. Registration is US$459 for ISACA members and US$599 for non-members, plus a one-time US$50 application processing fee once you pass. You must hold an active CISM or CISSP to register, and you have a six-month eligibility window from the date you register. No performance-based questions, no labs, no essay section. Every item is a written scenario ending in a "best", "first", "primary", or "most" style question — the scope word is usually what separates the key from the distractors.
Why Practice Questions Matter
AAISM questions rarely have one obviously wrong answer. All four options are usually defensible actions, and the exam is testing whether you can rank them the way a competent security manager would. That skill doesn't come from reading — it comes from repetition against realistic stems until the ranking becomes instinct. Practice questions also expose the two traps that sink otherwise well-prepared candidates: reaching for the technical fix when the scenario calls for a governance response, and missing the scope word that changes which answer is correct. At roughly 100 seconds per question, that judgement has to be automatic before you sit down.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISACA AAISM exam — not actual exam content.
Q1.A container terminal's developers argue that because the output filter reliably catches sensitive data, the input filter and the retrieval access checks can be removed to cut latency on the yard planning assistant. They have benchmark figures showing a measurable speed gain. Which of the following is the BEST basis for the AI security manager's response?
- A.The latency gain from removing filters is usually too small to matter in practice
- B.Output filters cannot be assured to the same level as input filters
- C.Regulators mandate input filtering for all AI systems handling operational data
- D.Each layer is imperfect and it is the combination of layers that catches most failures
Domain: AI Technologies and Controls
Q2.A bottling plant is training a visual quality inspection model on images from its production line. The data science team runs training jobs from general developer workstations and pulls frameworks and pretrained weights directly from public repositories. Which of the following changes would MOST reduce risk to the training environment?
- A.Increase the accuracy threshold the model must meet before promotion
- B.Move training to an isolated subnet with identity-based access and pull all libraries from a curated internal registry
- C.Require the team to document which frameworks each training run used
- D.Encrypt the image dataset at rest on the developer workstations
Domain: AI Technologies and Controls
Q3.A recruitment agency's resume screening model reaches 94 percent accuracy on its holdout test set and meets every functional criterion agreed at project start. The AI security manager is asked to sign the evaluation gate this week. Which of the following is the MOST important additional evidence to require?
- A.Latency measurements under expected peak load
- B.Confirmation that the holdout test set was large enough to be meaningful
- C.Results showing whether the model performs equally well across demographic groups
- D.A comparison of accuracy against the manual screening process it replaces
Domain: AI Technologies and Controls
Q4.A retail brokerage chains two models: a summarisation model produces draft research notes that are passed directly as input to a compliance checking model, with no validation in between. The team argues that because both models are internal there is nothing to check. Which of the following BEST describes the risk the AI security manager should raise?
- A.The first model's output crosses a trust boundary into the second and must be validated like any other untrusted input
- B.The two models will drift at different rates and become inconsistent over time
- C.The chained design roughly doubles token consumption for every research note
- D.The compliance model's system prompt may conflict with the summarisation model's
Domain: AI Technologies and Controls
Q5.A telco launched a churn prediction model nine months ago after full validation and a red team exercise. Since then the customer base and tariff mix have changed considerably, and no evaluation has been rerun. Which of the following is the PRIMARY concern for the AI security manager?
- A.The original red team report may not have been shared widely enough
- B.The model owner has not requested additional training data
- C.Controls and results that passed at launch may no longer hold, because evaluation is a continuous practice rather than a one-off
- D.The model documentation has not been reviewed by the data steward
Domain: AI Technologies and Controls
Frequently Asked Questions
What is included in the free ISACA AAISM sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full ISACA AAISM course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the ISACA AAISM course page.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the ISACA AAISM course cover?
The course covers 3 exam domains: AI Governance and Program Management, AI Risk Management, AI Technologies and Controls.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.