Skip to content

The AAISM exam domains, explained

Vishwen Labs

Three stacks of grey document folders on a dark oak desk, two of equal height and a third taller, each held by a brass clip

The AAISM exam has three domains: AI Governance and Program Management at 31%, AI Risk Management at 31%, and AI Technologies and Controls at 38%. Across 90 questions that is roughly 28, 28 and 34 questions. ISACA's outline breaks the domains into thirteen topics, coded 1A to 3E, and twenty-two task statements.

Domain 1: AI Governance and Program Management (31%)

Five topics. 1A is stakeholder considerations, industry frameworks and regulatory requirements: who has a say in how AI is used, which frameworks an organisation might adopt, and which laws bind it. 1B is AI-related strategies, policies and procedures. 1C is the AI asset and data life cycle, meaning the inventory of models, datasets and pipelines and what happens to each from creation to retirement. 1D is the security programme itself: building it, resourcing it, reporting on it. 1E is business continuity and incident response when the thing that fails is a model.

For a CISM holder this is home ground with new furniture. The programme-management reflexes transfer; the inventory does not, because most organisations have never listed their models the way they list their servers.

Domain 2: AI Risk Management (31%)

Three topics. 2A covers AI risk assessment, thresholds and treatment: identifying what can go wrong with a model, deciding how much of it the organisation will accept, and choosing what to do about the rest. 2B is threat and vulnerability management, the AI-specific catalogue of prompt injection, data poisoning, model extraction and the rest, and how to keep on top of it. 2C is vendors and the supply chain, which in practice means models and services you did not build and cannot fully inspect.

Questions here tend to test judgement about thresholds and treatment rather than the names of attacks. Knowing what data poisoning is earns nothing on its own; knowing which control to fund first does.

Domain 3: AI Technologies and Controls (38%)

The largest domain, and the one most managers find hardest, because it is where the exam expects you to understand the technology well enough to choose controls for it. 3A is security architecture and design. 3B is the AI life cycle: model selection, training, validation and deployment. 3C is data management controls. 3D is privacy, ethical, trust and safety controls. 3E is security controls and monitoring, which is where detection, logging and response for AI systems live.

At 38% of the paper, weakness here is expensive. It is also the domain where people who came through CISM rather than engineering start furthest behind.

Learn screen listing AAISM lessons by exam outline code, with Governance at 73% mastery and 31% of the exam
AAISM Exam Prep's lesson list follows the outline codes. Each domain shows its percentage of the exam beside your mastery of it, so the 38% domain is never mistaken for a third of the work.

How to weight your AAISM study by domain

Study in the exam's proportions and then tilt toward wherever you are weakest. A plan that gives each domain a third of the time under-serves Domain 3 by about a fifth, and Domain 3 is where the marginal question is most likely to sit.

AAISM Exam Prep applies the same 31, 31, 38 weighting to its readiness score, so the number on the home screen already reflects how the exam would treat your current mix of strengths. The daily drill goes to the weakest topic by code, which on the home screen shown in the store listing is 3E, security controls and monitoring.

The twenty-two task statements

Beneath the thirteen topics ISACA lists twenty-two task statements, each a verb phrase describing something a certified person does: assessing, designing, implementing, monitoring, reporting. They are worth reading once, slowly, because the questions are written to those verbs. A question about a vendor model is rarely asking what the model does; it is asking what you, the manager, do about it.

AAISM™ and CISM® are trademarks of ISACA. This app is an independent study aid and is not affiliated with, endorsed by, or sponsored by ISACA.

Questions people also ask

Which AAISM domain has the most questions?

AI Technologies and Controls, at 38% of the exam. On a 90-question paper that is about 34 questions, against roughly 28 each for Governance and Risk. It is also the most technical of the three, so it usually deserves more than 38% of a manager's study time.

Are the AAISM domains the same as the CISM domains?

No. CISM has four domains built around information security governance, risk, programme development and incident management in general. AAISM has three, all specific to AI: governance and programme management, risk management, and technologies and controls. The management reflexes carry over; the content is new.