AAISM prerequisites: CISM or CISSP required

Updated September 20, 2026

AAISM has something most certifications do not: a genuine, enforced prerequisite.

AAISM candidates must hold an active CISM or CISSP certification.

That is ISACA’s wording, and it is a gate rather than a recommendation. No amount of AI expertise, security experience or enthusiasm substitutes for it. If you hold neither credential, AAISM is not currently available to you.

The hard requirement

RequirementStatus
Active CISM or CISSPMandatory
Experience in security or advisory rolesExpected
Expertise assessing, implementing and maintaining AI systemsExpected

Note the word active. A lapsed CISM does not qualify, and your CISM or CISSP must remain active for your AAISM to stand. That means maintaining two credentials with two sets of continuing education and two renewal cycles — an ongoing obligation worth understanding before you start.

The softer expectations

ISACA describes candidates as having proven experience in security or advisory roles and some expertise assessing, implementing and maintaining AI systems. These are not checked at booking, but they describe who the questions are written for.

In practice that means:

  • You have been accountable for something, not just implemented it. ISACA questions are written from the perspective of the person who answers for the outcome.
  • You have encountered AI systems at work — a deployment, a risk review, a vendor assessment, a policy question.
  • You are comfortable with risk language: likelihood, impact, threshold, treatment, appetite.

You do not need to be technical in a hands-on sense. There is no coding, no configuration and no mathematics. The technologies domain is 38% of the exam but it asks which control addresses which weakness, not how to implement it.

What it costs to get there

Exam fee — ISACA memberUS$459
Exam fee — non-memberUS$599
Application processing fee after passingUS$50
Window to apply after passing5 years

The member and non-member gap is US$140, which is a large enough fraction of ISACA membership that it is worth pricing membership before booking — particularly if you will also be paying CISM maintenance.

The five-year application window is generous but real. Passing the exam does not make you certified; you must apply. Do not let that lapse.

If you hold neither CISM nor CISSP

You have three honest options.

Get CISM first. The natural route if your work is security management, and it is the credential AAISM’s structure and question style most closely follow. Budget several months.

Get CISSP first. Broader and more technical, more widely recognised outside ISACA’s orbit, and equally accepted as the AAISM prerequisite.

Choose a different AI security credential. If the prerequisite is out of reach for now, vendor-neutral alternatives exist without a certification gate. CompTIA SecAI+ recommends 3–4 years in IT and 2+ in security but enforces nothing, which makes it reachable much sooner.

That last option is worth taking seriously rather than treating AAISM as the only destination. The two credentials address overlapping subject matter at different career stages.

If you already hold CISM or CISSP

You are eligible today, and most of your preparation is narrower than you think. The governance and risk domains use methodology you already have; what is new is the AI-specific content inside them, plus the technologies domain.

Realistic estimate: four to six weeks. See AAISM vs CISM for the detailed delta, and the study plan for how to spend the time.

Before you book

  1. Confirm your CISM or CISSP is active, not lapsed.
  2. Price ISACA membership against the US$140 exam saving.
  3. Try the free sample questions to check the style feels familiar.
  4. Read the technologies domain guide — if that content is entirely foreign, budget the full six weeks.