Back to home
Free Sample

Try ISACA AAISM

Try 10 questions now. No account, no card.

A free account unlocks 25 questions per course plus readiness tracking.

Get full access to ISACA AAISM

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

Until 30 November

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

ISACA · Exam reference

About the ISACA AAISM exam

ISACA's Advanced in AI Security Management (AAISM) is the first advanced certification for security leaders responsible for governing, assessing, and controlling AI systems. It's a scenario-based management exam covering AI governance, AI risk, and AI technologies and controls — and it requires an active CISM or CISSP to sit. Built for CISOs, security managers, and risk leads who now own the AI question.

10

Sample questions

150 min

Exam time limit

70%

Practice pass mark

$599

Exam voucher

The ISACA Advanced in AI Security Management (AAISM) is the first certification built specifically for the security leaders who now have to answer for AI. ISACA launched it in August 2025, and unlike the wave of general AI literacy badges, it is genuinely advanced: you must already hold an active CISM or CISSP before you can register. That prerequisite tells you what the exam is really about. AAISM does not ask you to build a transformer or tune a learning rate. It asks what a security manager does when the business wants a customer-facing chatbot next quarter, when a vendor cannot tell you what their foundation model was trained on, or when an indirect prompt injection turns your RAG pipeline into an exfiltration channel. Every question is scenario-based, and the answer ISACA wants is the most defensible management action, not the most technical one. The syllabus spans three domains. AI Governance and Program Management (31%) covers stakeholders, NIST AI RMF, ISO/IEC 42001, the EU AI Act, policy, the AI asset and data life cycle, and incident response. AI Risk Management (31%) covers risk assessment and thresholds, impact assessments, model theft, data poisoning, evasion, membership inference, and vendor and supply chain risk. AI Technologies and Controls (38%), the heaviest domain, covers secure architecture patterns, the secure AI life cycle, data management controls, privacy and ethics controls, and continuous monitoring. If you are a CISO, security manager, risk lead, or consultant being asked to sign off on AI systems, AAISM is the credential that puts a recognised framework behind your judgement.

Exam Domains Covered

AI Governance and Program Management · 31%AI Risk Management · 31%AI Technologies and Controls · 38%

Exam Format & Details

90 scenario-based multiple-choice questions in 150 minutes (2.5 hours) — roughly 100 seconds per question. Scored on ISACA's 200–800 scale, with 450 required to pass. You see a provisional result on screen and the official score report lands in your ISACA account shortly after. Delivered by PSI, either at a test centre or via remote proctoring. Registration is US$459 for ISACA members and US$599 for non-members, plus a one-time US$50 application processing fee once you pass. You must hold an active CISM or CISSP to register, and you have a six-month eligibility window from the date you register. No performance-based questions, no labs, no essay section. Every item is a written scenario ending in a "best", "first", "primary", or "most" style question — the scope word is usually what separates the key from the distractors.

Why Practice Questions Matter

AAISM questions rarely have one obviously wrong answer. All four options are usually defensible actions, and the exam is testing whether you can rank them the way a competent security manager would. That skill doesn't come from reading — it comes from repetition against realistic stems until the ranking becomes instinct. Practice questions also expose the two traps that sink otherwise well-prepared candidates: reaching for the technical fix when the scenario calls for a governance response, and missing the scope word that changes which answer is correct. At roughly 100 seconds per question, that judgement has to be automatic before you sit down.

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISACA AAISM exam — not actual exam content.

Q1.A clinical trials sponsor uses a foundation model hosted in the United States, fine-tuned by a partner in Ireland and accessed by investigators in Singapore and Brazil. The board asks the AI security manager to eliminate jurisdictional risk by consolidating everything into a single region. Which of the following is the BEST response?

  • A.Consolidate all processing into the region where the majority of trial subjects reside
  • B.Map each leg of the data journey, document the lawful basis, and apply appropriate controls to each
  • C.Rely on the vendor's standard contractual clauses to cover every transfer in the chain
  • D.Restrict investigator access to the region in which the foundation model is hosted

Domain: AI Technologies and Controls

Q2.A wholesale distributor has onboarded a foundation model provider after a thorough due diligence exercise and the use case is now live. The vendor manager regards the risk work as complete and has closed the file. Which of the following should the AI security manager establish as the PRIMARY ongoing control?

  • A.A continuous monitoring routine anchored on a fixed evaluation set and licence change alerts
  • B.An annual reassessment of the provider's security certifications
  • C.A quarterly commercial review of consumption and spend
  • D.A user satisfaction survey covering the quality of the assistant's answers

Domain: AI Risk Management

Q3.A global law firm's newly drafted AI policy runs to forty pages and specifies the exact chatbot product and version that partners may use for legal research. The vendor has shipped two new versions since the draft was circulated. Which of the following should the AI security manager recommend FIRST?

  • A.Update the policy text to name the current vendor version before publication.
  • B.Move the tool-specific and version-specific detail into a supporting procedure and keep the policy technology neutral.
  • C.Shorten the policy to ten pages and publish a one-page summary for all staff.
  • D.Ask the AI ethics committee to approve the policy as drafted so publication is not delayed.

Domain: AI Governance and Program Management

Q4.A telco network operations centre sees one service account consuming roughly ten times its normal token volume against the internal LLM. The pattern started overnight and is continuing. The account belongs to a team that runs periodic batch summarisation jobs. Which of the following should the AI security manager do FIRST?

  • A.Treat the anomaly as possible model abuse and investigate the account's prompts and sessions under the incident playbook
  • B.Raise the token quota for the account so operational jobs are not disrupted
  • C.Ask finance to model the cost impact before deciding on any action
  • D.Disable the service account immediately until the team explains the usage

Domain: AI Technologies and Controls

Q5.A chain of veterinary clinics uses a model to triage after-hours symptom calls. Monitoring shows it has begun under-triaging one category of animal, and the AI security lead judges there is a genuine safety risk. The model owner, a regional operations director, wants the model kept live until the next scheduled release window. Which of the following BEST describes the appropriate handling of this decision?

  • A.The data scientist who built the model should decide, as that person best understands the failure mode
  • B.The model owner's decision stands unchanged, because the model owner is accountable for the model's outcomes
  • C.The steering committee should be convened to vote before the model can be suspended
  • D.The AI security lead may suspend the model on safety grounds with notification, while the model owner remains accountable for the business decision

Domain: AI Governance and Program Management

Frequently Asked Questions

What is included in the free ISACA AAISM sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full ISACA AAISM course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the ISACA AAISM course page.

Are these official ISACA exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.

Which domains does the ISACA AAISM course cover?

The course covers 3 exam domains: AI Governance and Program Management, AI Risk Management, AI Technologies and Controls.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.