About the Exam

ISACA's Advanced in AI Security Management (AAISM) certification is designed for experienced security professionals, especially active CISM and CISSP holders. The exam covers AI governance and program management, AI risk management, and AI technologies and controls. Passing demonstrates the ability to identify, assess, monitor, and mitigate risk associated with enterprise AI solutions and support AI security operations.

Exam Topics

  • AI Governance and Program Management31%
  • AI Risk Management31%
  • AI Technologies and Controls38%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 9, 2026 at 7:54 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

AI Governance and Program Management

Which option BEST allows an organization to retain visibility into its AI usage?

Explanation

A comprehensive inventory of AI systems and the business units that use them provides a complete, current view of where AI is deployed across the organization. This supports oversight of usage, ownership, risk, and governance.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

AI Governance and Program Management

The CEO of a large, multi-sector organization has discovered that, without formal guidance, business units have developed shadow IT by incorporating AI into their daily operations. In response, an AI governance group has been established to address this issue. Which of the following is MOST important for the group to gather from each business unit?

Explanation

An inventory of models in use provides the essential visibility needed to govern AI across the organization. It establishes what AI capabilities exist, where they are used, and which systems require risk assessment, ownership, controls, and monitoring.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

AI Governance and Program Management

Which option BEST characterizes the role of risk documentation within an AI governance program?

Explanation

Risk documentation records and communicates how AI risks are governed and managed, creating evidence for transparency, accountability, and compliance oversight by external stakeholders. NIST notes that systematic documentation strengthens AI risk management and increases transparency and accountability.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

AI Risk Management

Which key risk indicator (KRI) is MOST relevant for assessing the effectiveness of an organization’s AI risk management program?

Explanation

The percentage of AI projects that comply with established requirements directly indicates whether AI risk-management controls and governance processes are being followed. Counts of systems, models, or training requests measure scale or activity, not the effectiveness of risk management.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

AI Risk Management

When preparing for an AI incident, which of the following should be completed FIRST?

Explanation

An AI incident response program needs an accountable cross-functional team with AI expertise before it can design, operate, and maintain incident reporting, recovery, containment, and eradication processes.

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home