The AAISM is ISACA’s Advanced in AI Security Management credential, and new is the word that explains most of what follows. New exam, new training materials, new subject matter that is changing faster than any of them can keep up with. I passed it in July 2026. The credential is worth holding and the training was worth buying – but all of it still has the rough edges of a first edition, and the honest way to review it is as one.

The course

ISACA’s AAISM course is about sixteen hours, and it moves. It packs an enormous amount of ground into that window, which is both the point and the limit. If you like the format – a fast, dense survey that names every topic and lingers on none – it is a decent review. What it cannot do is teach you the subject. There is too much territory, and sixteen hours only buys you the skeleton. The meat you supply yourself, out of experience or out of the reading. Go in expecting the map, not the territory.

That is not really a criticism of the course. It is arithmetic. AI security touches governance, risk, regulation, threat modeling, and the technical controls under all of it, and no single course covers that in depth in four days. A survey that admits it is a survey is doing its job.

The textbook

The ISACA textbook is where the detail lives, and the detail is there. The presentation is not.

Reading it feels like reading a cell-phone contract. Font sizes change for logical and obvious structural reasons, without the page breaks or other readability cues a human eye is trained to parse. Prose runs straight into footnotes and fine print with no visual break. Chapters and topics bleed together with little to mark where one ends and the next begins. The content is complete; locating the important parts of it is your problem, not the book’s. A more cynical reader might question if the textbook was written by AI as a markdown document; it certainly reads like it was formatted for one.

A textbook has one job past holding the content, and that is telling you what matters and where you are. This one doesn’t. It needs an editor with a red pen and a style guide, tasked to create an actual printed book readable by physically embodied intelligences. Until it gets one, the material is still in there for anyone willing to dig it out. Just be prepared for a slog.

The practice questions

The question-and-answer study guide is the best-built piece of the set. It walks you through practice questions section by section with immediate feedback on each answer, then gives you full practice exams. As a way to drill the material and find your soft spots, the interface does exactly what you want and does it well. This is the part I would pay for again on its own.

One caveat, and I’ll stay vague about the exam itself on purpose: treat the practice questions as a study aid, not a rehearsal. A strong practice score tells you that you have learned the material. It does not tell you how the exam itself will go. Study with them. Don’t calibrate your confidence on them.

The exam

One general observation is safe to make and worth making: it is built to test judgment and prioritization more than recall of regulations or technical facts. You need to know the regulations and the technical facts; without those you will fail. You also need to calibrate your judgement to what the creators of the exam think is correct on questions of prioritization and risk tolerance, where a single correct answer is elusive.

That is the right call for the subject. AI security is mostly a set of judgment calls right now, because nobody has the settled answers yet – the field is still being written. But testing judgment instead of recall makes the exam feel less deterministic than a fact-based one. It rewards the ability to weigh and rank competing concerns, which is harder to study for than a list of facts and harder to feel certain about in the chair. If you are used to certifications where the right answer is simply the true one, adjust your expectations before you sit down.

Verdict

Everything here traces to one fact: all of it is new. New credential, new training materials, and a subject being rewritten every few months. It shows. The course is a detailed survey of a rapidly changing regulatory and technical landscape, covering legislation still being written. The textbook has the content but not the organization. The practice engine is genuinely good. The exam measures judgment in a domain where judgment is still being worked out. The rough edges are real.

I would do it again. The credential is a real one – an exam, not a certificate of completion – and it forced me to sit down and work through the AI-security material deliberately instead of absorbing it in fragments off the job. In a field moving this fast, that structured push is worth something on its own.

Worth it if you already have security grounding and the necessary prerequisites (CISSP for me), and want the credential plus a reason to survey the AI-security landscape end to end. Less so if you need the training to teach you the subject from nothing; it will hand you the outline, you’ll memorize the facts, and miss the judgement that is the most important part, and the part that takes the most time to develop. This certification should not be your first exposure to these concepts, and that’s why the prerequisites are in place.


For the other half of my 2026 AI-security coursework – ISC2’s six-course bundle, reviewed course by course – see The ISC2 AI Course Bundle .