AAISM vs AAIA: which one is for you?
Vishwen Labs

AAISM is for people who run AI security and sits on an active CISM or CISSP. AAIA, Advanced in AI Audit, is for people who audit AI systems and sits on an audit credential such as CISA. If your job is deciding how AI is secured, take AAISM; if your job is checking whether someone else did, take AAIA.
What AAISM and AAIA each certify
Both are ISACA credentials aimed at AI, and both are advanced in the sense that each requires an existing certification first. AAISM, Advanced in AI Security Management, certifies that you can build and run the programme that keeps an organisation's AI systems secure: governance, risk treatment, controls, vendors, incident response. AAIA, Advanced in AI Audit, certifies that you can plan and perform an audit of AI systems and the controls around them.
The distinction is the same one that separates CISM from CISA. One credential is held by the person accountable for the controls, the other by the person who gives assurance over them.
Prerequisites for AAISM and AAIA
AAISM requires an active CISM or CISSP; ISACA states this on the certification's own page, and there is no experience-based route around it. AAIA requires an audit credential, with CISA the obvious one and ISACA accepting certain equivalents from other bodies. Check ISACA's AAIA page for the current list, because it is the one thing most likely to change.
For many people the prerequisite decides the question before the job description does. A security manager with CISM cannot sit AAIA without first earning an audit credential, and an auditor with CISA cannot sit AAISM without CISM or CISSP.
What the AAISM exam looks like
AAISM is 90 questions over three domains: AI Governance and Program Management at 31%, AI Risk Management at 31%, and AI Technologies and Controls at 38%. The reported time limit is 150 minutes, and the score is scaled from 200 to 800 with 450 to pass. AAIA has its own outline, written from the auditor's seat, and its own format; take the figures from ISACA's AAIA page rather than assuming they match.

Choosing between AAISM and AAIA
Match the credential to the job you hold now rather than the one you might hold in five years. Someone who spends their week approving AI vendors, setting model-use policy and answering the board's questions about AI risk belongs in AAISM. Someone who spends it testing whether those policies are followed and writing findings belongs in AAIA.
Two cases are less clear. A GRC generalist who does some of both should follow the prerequisite they already hold. A consultant who advises on AI security programmes without owning one is still doing management work, and AAISM fits better than AAIA.
Taking both AAISM and AAIA
Some people will end up with both, typically those who hold CISM and CISA already and work across security and assurance. The overlap in subject matter is real, since both exams care about AI governance, risk and controls, but the questions are asked from different seats and the answers that score differ accordingly. Take the one that matches your current role first; the second becomes much easier once the vocabulary is familiar.
AAISM™ and CISM® are trademarks of ISACA. This app is an independent study aid and is not affiliated with, endorsed by, or sponsored by ISACA.
Questions people also ask
Can I take AAISM without CISM or CISSP?
No. ISACA requires candidates to hold an active CISM or CISSP before sitting the AAISM exam. If you hold neither, CISM is the more direct route, since AAISM is built to extend it.
Is there an ISACA AI certification for risk professionals?
Yes. Alongside AAISM for security management and AAIA for audit, ISACA offers AAIR, Advanced in AI Risk, aimed at risk practitioners. It has its own prerequisites and outline, so check ISACA's page for it if risk rather than security or audit is your seat.


