AAISM certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
AI Governance And Program Management
“AI Governance And Program Management” addresses objectives, decision ownership, risk significance, strength of the available evidence, sequence of action, and well-founded conclusions as part of AAISM — ISACA Advanced in AI Security Management. Candidates need to assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case, without accepting a result that the available evidence cannot support. It leads into “AI Risk Management” in the published outline.
Question notes
Knowing the heading “AI Governance And Program Management” is not sufficient; the scenario can hinge on professional role, order of action, evidence quality, or stakeholder accountability. The principal risk is evidence that cannot sustain the claim, misplaced ownership, early conclusions, or a response disconnected from the risk driving the case. The response should be supported by an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Official numeric emphasis is preserved outside the prose, with no estimate of how many items may represent it.
Preparation tips
Build preparation for “AI Governance And Program Management” around context, action, failure, and proof. Exercise: Build an evidence matrix linking objective, risk, control, test, result, and conclusion; then challenge one weak source. The checklist must expose insufficient evidence, confused responsibility, premature judgment, or corrective work that addresses an effect but not the underlying risk. Required proof: an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Build the next exercise from this verified state, focusing on “AI Risk Management”.
AI Risk Management
Candidates preparing “AI Risk Management” should frame it around objectives, accountable roles, risk significance, fitness of supporting information, sequence of action, and well-founded conclusions. The objective is met when they can separate accountable roles, request sufficient support, and act in the order the scenario requires. In the published sequence, it follows “AI Governance And Program Management” and precedes “AI Technologies And Controls”.
Question notes
For “AI Risk Management,” context matters: evidence, risk significance, and sequence often distinguish the strongest answer from a partial one. Challenge the result with insufficient evidence, confused responsibility, premature judgment, or corrective work that addresses an effect but not the underlying risk, then verify it using a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. The numeric blueprint emphasis remains in its structured field; this narrative adds no inferred percentage or item estimate.
Preparation tips
Study “AI Risk Management” through contrasting cases. Start with this exercise: Compare management, implementation, and assurance perspectives on the same case and document why their next actions differ. Build the weaker case around a weak factual basis, ambiguous accountability, unsupported conclusions, or a response aimed at the visible symptom rather than the risk driving the case. Separate the two results using a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Explain which assumptions this leaves for “AI Technologies And Controls”.
AI Technologies And Controls
For “AI Technologies And Controls,” the relevant professional context is objectives, responsible parties, risk significance, evidence quality, sequence of action, and supportable conclusions. The candidate is expected to assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case, without treating isolated vocabulary as proof of competence. It draws on work established in “AI Risk Management”.
Question notes
Before acting on “AI Technologies And Controls,” read the full scenario; the expected judgment should remain proportional to risk and consistent with governance responsibilities. Test the response for a weak factual basis, ambiguous accountability, unsupported conclusions, or a response aimed at the visible symptom rather than the source of risk. Confirm the outcome with traceability from objective to risk, evidence, judgment, conclusion, and stakeholder communication. Official numeric emphasis is preserved outside the prose, with no estimate of how many items may represent it.
Preparation tips
Study “AI Technologies And Controls” through contrasting cases. Start with this exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Build the weaker case around a weak factual basis, ambiguous accountability, unsupported conclusions, or a remedy that changes the symptom while leaving the actual exposure. Separate the two results using a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Use evidence from “AI Risk Management” as an input to the final review.
