AAISM exam format: questions, score and cost
Here is what ISACA publishes about the AAISM exam, and what it does not.
| Credential | ISACA Advanced in AI Security Management (AAISM) |
| Number of questions | 90 |
| Domains | 3 |
| Eligibility | Active CISM or CISSP required |
| Exam fee — ISACA member | US$459 |
| Exam fee — non-member | US$599 |
| Application processing fee | US$50 after passing |
| Window to apply after passing | 5 years |
| Duration | Not published on ISACA’s exam pages |
| Passing score | Not published on ISACA’s exam pages |
The prerequisite is a gate, not advice
Most certifications “recommend” experience. ISACA states plainly that AAISM candidates must hold an active CISM or CISSP certification. If you hold neither, AAISM is not available to you yet, and no amount of AI knowledge substitutes.
ISACA also expects proven experience in security or advisory roles and some expertise assessing, implementing and maintaining AI systems. Those are not enforced the way the certification gate is, but they describe who the questions are written for.
Two costs, two stages
Passing the exam is not the same as holding the credential. There is a US$50 application processing fee after you pass, and you have five years from passing to apply. Budget for both, and do not let the application lapse — a passed exam that was never converted into a credential is wasted money.
Membership changes the arithmetic. At US$459 against US$599, the US$140 saving is a meaningful fraction of ISACA membership itself, so run the numbers before booking if you are not already a member.
Domain weighting
| Domain | Weight | Approx. questions |
|---|---|---|
| AI Governance and Program Management | 31% | ~28 |
| AI Risk Management | 31% | ~28 |
| AI Technologies and Controls | 38% | ~34 |
Question counts are derived from the 90-question total and ISACA’s published percentages.
The distribution matters more than it looks. Candidates assume a security management credential is mostly governance and risk, then find the largest single domain is the technical one — architecture, model lifecycle, data controls, privacy and safety controls, and monitoring. Plan accordingly.
What ISACA does not publish
Neither the exam duration nor the passing score appears on ISACA’s AAISM pages. Treat any specific figure you find elsewhere with suspicion unless it cites ISACA directly. ISACA’s exams have historically used a scaled score rather than a raw percentage, so “how many can I get wrong” is the wrong question regardless.
How ISACA questions read
ISACA’s house style is consistent across its credentials and AAISM follows it. Expect:
- Scenario-led, management-perspective questions. You are the person accountable, deciding what to do.
- “BEST”, “FIRST”, “MOST” qualifiers, usually capitalised. Several options are defensible; one is best given the stated priority. The qualifier is the question.
- Business framing over technical minutiae. Even in the technologies domain, questions tend to ask which control addresses a stated risk rather than how to configure it.
If you have sat CISM or CRISC, this style will be familiar and is a real advantage. If your background is vendor exams, the shift from “which button” to “what should the accountable manager do first” takes deliberate practice.
Maintaining it
ISACA credentials carry continuing professional education requirements, and AAISM has its own CPE policy. Confirm the current hours and annual maintenance fee with ISACA before you certify, so the ongoing commitment is not a surprise.