The most useful thing to say about the AAISM is who it is not for, because a lot of people searching for AI security certifications will bounce straight off the prerequisite. You need an active CISM or CISSP to sit it. That is a deliberate design choice and I think it is the right one. The market is currently flooded with AI certifications aimed at people with no relevant background, sold on the premise that a badge will substitute for experience, and ISACA has gone the other way by saying this credential only makes sense on top of an established security career.
The effect is that a hiring manager reading AAISM on a CV knows two things rather than one, and the second thing was already worth knowing. The content is structured around three domains and the weightings tell you a lot about the intent. Governance and programme management is 31 percent, covering policy, data governance, programme structure and incident response for AI systems. Risk management is another 31 percent, covering assessment of threats, vulnerabilities and the supply chain issues that come with enterprise AI adoption.
Technologies and controls is the largest block at 38 percent, and it is the section that keeps this from being a pure paperwork exam. That balance is roughly correct for the job. A security manager dealing with AI needs to be able to write the policy, but they also need to know what prompt injection actually is, why a model endpoint is a different exposure than a database, and what controls exist that are not simply the old controls with AI in the name. The supply chain emphasis is the part I would highlight to anyone deciding whether to bother.
Most organisations' real AI risk is not a model they trained. It is a vendor whose product quietly started calling a language model, a plugin with access to a document store, a fine tune of somebody else's weights, or an employee pasting customer data into a consumer chatbot. Those are third party and shadow IT problems wearing new clothes, and an exam that treats them as central is describing the actual threat surface rather than an idealised one. Incident response for AI systems gets similar credit from me, because the honest answer to what you do when a model leaks training data or an agent takes an action nobody authorised is that most organisations have no plan at all.
On the economics, this is a mid priced certification that becomes an expensive one if you buy the official preparation. The exam is $459 as a member and $599 otherwise, there is a $50 application fee once you pass, and ISACA's study materials and review courses are sold separately at prices that can double or triple the total. Membership is worth the arithmetic if you are going to hold any ISACA credential, which most people in this audience already do. The 90 question format is manageable and the questions are scenario oriented, so someone who genuinely manages security programmes will find much of it recognisable and will mostly be learning the AI specific overlay.
My reservations are mostly about age and evidence. AAISM launched in August 2025, which in credential terms is brand new. I cannot tell you yet that employers are asking for it by name, because there has not been time for that to show up in job postings, and anyone claiming otherwise is guessing. What I can say is that ISACA has a strong record of building certifications that stick, that the CISM comparison is the right mental model, and that the prerequisite structure means the credential is unlikely to be devalued by volume the way some vendor AI certifications already have been.
The other reservation is durability. Roughly a third of the exam concerns specific technologies and controls in an area where the threat landscape is genuinely shifting year to year, and a written exam will always lag. Expect the content outline to be revised, and expect your knowledge to need topping up regardless of what the continuing education requirements formally demand. My view is that this is a serious, well constructed credential for a narrow and senior audience, and within that audience it is worth holding.
The rating is 3.9 rather than higher because it is expensive, because the market recognition is still unproven, and because the very gating that makes it credible also means most people reading this cannot sit it. If you are one of the people who can, and your organisation is deploying AI without a coherent security position on it, this is a reasonable way to become the person who fixes that.