What's actually inside ISACA's new AI security certification?

ISACA just launched the first AI-specific security management certification. Here's what's actually in it.

AAISM covers three domains: AI governance and program management, AI risk management, and AI technologies and controls. It requires a CISM or CISSP as a prerequisite — it's built to sit on top of existing security management expertise, not replace it.

For anyone tracking toward an AI Security Architect path, this is the credential that most directly signals readiness for that specific intersection.

Why pursue it now, instead of waiting?

AI governance is moving from "policy document nobody reads" to "control plane that gets audited," and the certifications that map cleanly onto that shift are still new enough that visible, early fluency stands out. AAISM's three domains mirror exactly the questions a board starts asking once AI systems move from pilot to production: who owns the risk, what controls actually exist, and how is the whole thing governed day to day.

I'm pursuing it next, once CISSP is complete — deliberately sequenced, since AAISM assumes the security management foundation CISSP provides and builds AI-specific governance and risk material on top of it rather than starting from zero.