AAISM exam format: questions, score and cost

Updated September 20, 2026

Here is what ISACA publishes about the AAISM exam, and what it does not.

CredentialISACA Advanced in AI Security Management (AAISM)
Number of questions90
Domains3
EligibilityActive CISM or CISSP required
Exam fee — ISACA memberUS$459
Exam fee — non-memberUS$599
Application processing feeUS$50 after passing
Window to apply after passing5 years
DurationNot published on ISACA’s exam pages
Passing scoreNot published on ISACA’s exam pages

The prerequisite is a gate, not advice

Most certifications “recommend” experience. ISACA states plainly that AAISM candidates must hold an active CISM or CISSP certification. If you hold neither, AAISM is not available to you yet, and no amount of AI knowledge substitutes.

ISACA also expects proven experience in security or advisory roles and some expertise assessing, implementing and maintaining AI systems. Those are not enforced the way the certification gate is, but they describe who the questions are written for.

Two costs, two stages

Passing the exam is not the same as holding the credential. There is a US$50 application processing fee after you pass, and you have five years from passing to apply. Budget for both, and do not let the application lapse — a passed exam that was never converted into a credential is wasted money.

Membership changes the arithmetic. At US$459 against US$599, the US$140 saving is a meaningful fraction of ISACA membership itself, so run the numbers before booking if you are not already a member.

Domain weighting

DomainWeightApprox. questions
AI Governance and Program Management31%~28
AI Risk Management31%~28
AI Technologies and Controls38%~34

Question counts are derived from the 90-question total and ISACA’s published percentages.

The distribution matters more than it looks. Candidates assume a security management credential is mostly governance and risk, then find the largest single domain is the technical one — architecture, model lifecycle, data controls, privacy and safety controls, and monitoring. Plan accordingly.

What ISACA does not publish

Neither the exam duration nor the passing score appears on ISACA’s AAISM pages. Treat any specific figure you find elsewhere with suspicion unless it cites ISACA directly. ISACA’s exams have historically used a scaled score rather than a raw percentage, so “how many can I get wrong” is the wrong question regardless.

How ISACA questions read

ISACA’s house style is consistent across its credentials and AAISM follows it. Expect:

  • Scenario-led, management-perspective questions. You are the person accountable, deciding what to do.
  • “BEST”, “FIRST”, “MOST” qualifiers, usually capitalised. Several options are defensible; one is best given the stated priority. The qualifier is the question.
  • Business framing over technical minutiae. Even in the technologies domain, questions tend to ask which control addresses a stated risk rather than how to configure it.

If you have sat CISM or CRISC, this style will be familiar and is a real advantage. If your background is vendor exams, the shift from “which button” to “what should the accountable manager do first” takes deliberate practice.

Maintaining it

ISACA credentials carry continuing professional education requirements, and AAISM has its own CPE policy. Confirm the current hours and annual maintenance fee with ISACA before you certify, so the ongoing commitment is not a surprise.