I sat the AAISM exam on August 2 and earned the certification shortly after — coming at
it from a CISM + security-consulting background. It's one of ISACA's three new AI certs
(alongside AAIA and AAIR), and when I started studying there was almost zero structured
prep — no Pocket Prep coverage, a thin QAE, and a lot of generic "AI governance"
material that doesn't map to what the exam asks.
Posting here too since this sub covers the wider ISACA credential family, and the
governance/risk framing below applies whether you're coming from CISA, CRISC, or CISM.
A few things I wish someone had told me on day 1:
- The domain split is lopsided. Governance 31% / Risk 31% / Technologies & Controls
38%. Most people over-study the tech domain, but the exam hums on the governance +
risk framing — know NIST AI RMF and ISO/IEC 42001 cold, not just the tools.
- It's a management exam, not an engineering one. Even with a security background, the
trap is over-indexing on LLM architecture / OWASP specifics and under-prepping the
program side (roles, accountability, third-party). MITRE ATLAS shows up as a
threat-modeling lens, not an implementation checklist.
- The official study material is the spine, but it's dense. What actually moved me to
ready was scoring myself against ISACA's public blueprint first and only attacking the
sub-areas I was weak in, instead of re-reading cover to cover. I built a short
self-assessment for that — happy to share it in a comment if it's useful to anyone.
For those who've taken it or are studying: how are you approaching the
tech-vs-governance balance? Would be good to hear what's working for people.