AAISM vs CISM: how they differ
These are not alternatives, and the comparison is unusual for that reason: CISM (or CISSP) is a prerequisite for AAISM. You do not choose between them. You hold one, then you add the other.
The useful question is therefore not “which is better” but “what does AAISM add that CISM did not cover, and how much work is that?”
The relationship
| CISM | AAISM | |
|---|---|---|
| Position | Foundational security management credential | Specialisation on top of it |
| Eligibility | Work experience in security management | Active CISM or CISSP required |
| Scope | Information security management, all of it | Security management applied to AI |
| Largest domain | Information security programme | AI Technologies and Controls (38%) |
| Questions | Longer paper | 90 |
CISM establishes that you can govern, build and run a security programme. AAISM asks whether you can do that when the asset is a model, the supply chain includes pretrained weights and third-party datasets, and the failure modes include things software has never done before.
What carries over
More than you might expect. AAISM’s domain structure is recognisably ISACA:
- Governance — stakeholders, policy, frameworks, regulatory requirements. Same discipline, AI-specific content.
- Risk management — assessment, thresholds, treatment, vendor and supply chain. The methodology is the one you already use.
- Incident response and business continuity — familiar processes, new incident types.
- Programme management — building and running a security programme, now an AI security programme.
The question style carries over completely. If you are used to ISACA’s BEST/FIRST/MOST framing and the accountable-manager perspective, you already have a real advantage.
What is genuinely new
AI asset and data lifecycle management. Training data is an asset with provenance, integrity and retention concerns that ordinary data classification does not fully cover.
AI-specific threats and vulnerabilities. Poisoning, model extraction and inversion, evasion, prompt injection. These are not variations on familiar attacks; they target stages that traditional systems do not have.
AI vendor and supply chain management. Pretrained models, third-party datasets, model APIs and the libraries around them. Assessing a model provider is not the same exercise as assessing a SaaS vendor.
The technologies domain — 38%, the largest. AI security architecture and design, the model lifecycle including selection, training and validation, data management controls, privacy, ethical, trust and safety controls, and security controls and monitoring. This is the part CISM holders most often underestimate, because they expect a management credential to stay at the policy layer. It does not.
How much new study for a CISM holder?
Realistically four to six weeks, weighted heavily toward the technologies domain.
The trap is assuming that because the domain names look familiar, the content is. AI Risk Management uses risk methodology you know, but the threat catalogue, the vendor questions and the supply chain concerns are new. AI Governance uses governance you know, but the frameworks, regulatory requirements and asset lifecycle are AI-specific.
Do not skim the governance and risk domains because they sound like CISM. Read them for what is different about AI, and you will find it in nearly every knowledge area.
Does AAISM replace CISM?
No, and it cannot — your CISM must remain active for AAISM to stand. That means maintaining two credentials, two sets of CPE and two renewal cycles. Factor that into the decision before you start: AAISM is an addition to your obligations, not a substitution.
Who should add it
CISM or CISSP holders whose organisations are deploying AI and who are now the person being asked whether it is safe. If that describes your last quarter, AAISM is the structured version of the reading you are already doing.
If AI has not reached your remit yet, there is no urgency — the prerequisite is not going anywhere, and you can add it when the work arrives.