Jason Edwards

Certified: The ISACA AAISM Audio Course

Welcome to Certified: The ISACA AAISM Audio Course. If you’re responsible for security, risk, assurance, or governance and AI is now part of your environment, you’re in the right place. This course is designed to help you prepare for the ISACA AAISM certification with clear explanations and practical framing, so the topics feel manageable instead of abstract. Each episode stays focused on the concepts the exam tests, while still connecting them to real situations you might face when reviewing AI use cases, third-party AI services, or internal model development. Expect straightforward definitio...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 66 — Reduce AI attack surface through smart deployment and integration choices (Task 10) 14.02.2026

This episode explains how to reduce AI attack surface by making smart deployment and integration choices, which AAISM tests by asking what design decision most effectively lowers exposure without relying on a single tool. You will learn to minimize public endpoints, restrict plugin and connector capabilities, limit data access by default, and avoid unnecessary features that expand what an attacker...

Episode 65 — Design AI security architecture with clear trust boundaries and data flows (Task 10) 14.02.2026

This episode teaches how to design AI security architecture by clearly defining trust boundaries and data flows, because AAISM questions often hinge on whether you can place controls based on how information and authority actually move through the system. You will learn to map where data is collected, transformed, stored, and used for training or inference, and where identities, keys, and permissi...

Episode 64 — Domain 3 overview: secure AI technologies using architecture and controls (Task 10) 14.02.2026

This episode introduces Domain 3 as the “how you actually secure it” domain, focusing on architecture and control implementation that makes AI systems defensible in real operations, which AAISM tests through deployment, integration, and control design scenarios. You will learn how to think in trust boundaries, data flows, identity paths, and dependency chains so you can place controls where they r...

Episode 63 — Domain 2 quick review: risk lifecycle, threats, testing, and vendors (Tasks 4–9) 14.02.2026

This episode reinforces Domain 2 by connecting the risk lifecycle, threat assessment, reassessment triggers, security testing, vulnerability management, and vendor oversight into a single continuous loop, which is how AAISM expects you to reason under exam pressure. You will review how intake and scope drive threat relevance, how likelihood and impact shape prioritization, and how treatments must...

Episode 62 — Verify vendor AI security through audits, tests, and contract enforcement (Task 9) 14.02.2026

This episode explains how to verify vendor AI security using audits, targeted tests, and enforceable contract terms, which AAISM tests by asking what creates real assurance when visibility ends at the provider boundary. You will learn how to distinguish paper evidence from operational proof, and how to request and evaluate artifacts like audit reports, control mappings, penetration testing summari...

Episode 61 — Monitor vendor controls using evidence, updates, and incident notifications (Task 9) 14.02.2026

This episode teaches how to monitor AI vendor controls as an ongoing responsibility, because AAISM scenarios often test whether you can maintain assurance after onboarding instead of assuming the initial review is enough. You will learn how to define what evidence must be delivered, how often it must be refreshed, and how to validate changes when vendors update models, platforms, or data handling...

Episode 60 — Embed vendor AI security requirements before procurement begins (Task 9) 14.02.2026

This episode explains how to embed vendor AI security requirements early, because AAISM questions often test whether you can prevent downstream risk by shaping procurement, contracts, and onboarding criteria before a vendor is selected. You will learn how to define requirements around data handling, logging and audit access, incident notification, model update transparency, access controls, retent...

Episode 59 — Retest and document fixes so AI vulnerabilities stay closed (Task 7) 14.02.2026

This episode teaches how to retest and document remediation so vulnerabilities stay closed over time, which AAISM often tests through scenarios where fixes are applied quickly but later regress due to model updates, pipeline changes, or permission drift. You will learn how to define retest criteria, capture before-and-after evidence, and document residual risk decisions when a fix is partial or de...

Episode 58 — Build AI vulnerability management from discovery to remediation (Task 7) 14.02.2026

This episode explains how to build AI vulnerability management as a complete workflow from discovery through remediation, which AAISM tests by asking how you ensure weaknesses are found, prioritized, fixed, and verified. You will learn to treat vulnerabilities broadly, including misconfigurations in endpoints, weak access control in pipelines, unsafe prompt integrations, insecure secret handling,...

Episode 57 — Design AI security testing that matches your model, data, and use case (Task 7) 14.02.2026

This episode teaches how to design AI security testing that is fit for purpose, because AAISM questions often challenge you to choose testing that matches the model type, data flows, deployment context, and expected misuse patterns. You will learn to define test objectives such as resisting prompt injection, preventing data leakage, validating access boundaries, confirming logging coverage, and ve...

Episode 56 — Build a reassessment cadence that prevents stale AI risk decisions (Task 6) 14.02.2026

This episode explains how to set a reassessment cadence that prevents stale AI risk decisions while still respecting operational capacity, which AAISM tests by asking what governance routine best maintains control effectiveness over time. You will learn how to combine event-driven triggers with time-based reviews, and how to set cadence based on system criticality, data sensitivity, rate of change...

Episode 55 — Monitor external changes like laws, vendors, and new AI capabilities (Task 6) 14.02.2026

This episode teaches how to monitor external changes that should trigger AI risk reassessment, because AAISM scenarios often include shifting laws, vendor updates, or new model capabilities that invalidate older decisions. You will learn how to track regulatory movement, standards guidance, and enforcement trends in a way that produces actionable requirements, not noise. We also cover vendor-drive...

Episode 54 — Monitor internal changes that require AI risk reassessment (Task 6) 14.02.2026

This episode explains which internal changes should trigger AI risk reassessment and why AAISM treats reassessment as a governance-controlled decision, not a vague “review occasionally” idea. You will learn internal triggers such as new data sources, changes in user population, new integrations, altered business objectives, model updates, pipeline refactors, and permission changes that expand acce...

Episode 53 — Keep threat understanding current as attackers and tools evolve (Task 5) 14.02.2026

This episode teaches how to keep threat understanding current so threat assessments do not become stale, which AAISM tests through scenarios where new model capabilities or attacker techniques change the risk picture. You will learn practical inputs for threat refresh, including monitoring new abuse methods, tracking vendor platform changes, reviewing internal incident patterns, and analyzing near...

Episode 52 — Assess AI threats by likelihood and impact, not hype and fear (Task 5) 14.02.2026

This episode explains how to assess AI threats using likelihood and impact so your conclusions are defensible, which AAISM often tests by presenting dramatic scenarios and asking for a measured, risk-based response. You will learn how to estimate likelihood by looking at exposure, attacker effort, control strength, and detection capability, and how to estimate impact by considering data sensitivit...

Episode 51 — Identify the AI threat landscape using realistic abuse cases (Task 5) 14.02.2026

This episode teaches how to identify the AI threat landscape by focusing on realistic abuse cases instead of generic fear, because AAISM questions reward threat thinking that is tied to assets, workflows, and likely attacker goals. You will learn to build threat awareness around how AI systems are actually used, including data pipelines, model endpoints, prompts, integrations, and downstream busin...

Episode 50 — Assign AI risk owners and approvals so accountability is never unclear (Task 4) 14.02.2026

This episode teaches how to assign AI risk owners and approval authority so accountability cannot be disputed, which AAISM tests by asking who should accept risk, who should implement controls, and who should verify effectiveness. You will learn how to define ownership for different risk types, including data risks, model-behavior risks, deployment and access risks, and third-party risks, and how...

Episode 49 — Connect AI risks to enterprise risk reporting and decision-making (Task 4) 14.02.2026

This episode explains how to connect AI risks to enterprise risk reporting so leadership can compare them against other priorities and make clear decisions, which AAISM frequently tests through reporting, escalation, and governance scenarios. You will learn to express AI risk in business terms by describing harm, likelihood, impact, affected stakeholders, and control effectiveness, then mapping th...

Episode 48 — Run the AI risk management life cycle from intake to monitoring (Task 4) 14.02.2026

This episode teaches the AI risk management life cycle as a repeatable workflow, which AAISM tests by asking what to do next when a new use case appears, when risks are discovered, or when monitoring shows unexpected behavior. You will learn how to run intake with clear scope, assumptions, and stakeholders, then perform risk identification and analysis across data, model behavior, deployment conte...

Episode 47 — Domain 2 overview: manage AI risk while enabling business opportunity (Task 4) 14.02.2026

This episode introduces Domain 2 as the exam’s core risk-management engine, showing how AAISM expects you to manage AI risk in a way that supports business opportunity rather than blocking it with vague caution. You will learn how Domain 2 connects intake, assessment, treatment, monitoring, and reporting into a continuous loop, and why decisions must be documented, owned, and measurable. We use ex...

Episode 46 — Domain 1 recap drill: pick the right task under pressure (Tasks 1–21) 14.02.2026

This episode is a fast, exam-style recap that trains you to identify the underlying task being tested in Domain 1, because many AAISM questions are won or lost by recognizing whether the scenario is governance, policy, inventory, metrics, training, or evidence rather than a purely technical control choice. You will practice translating scenario details into what must be produced or decided, such a...

Episode 45 — Plan for vendor outages and safe degraded modes in AI systems (Task 17) 14.02.2026

This episode teaches how to plan for vendor outages and degraded operation without creating unsafe or noncompliant AI behavior, which AAISM tests through resilience scenarios where teams must choose between downtime and risky continuity. You will learn how to define “safe degraded mode” options such as limiting features, restricting outputs to low-risk use cases, enforcing stricter human review, o...

Episode 44 — Set recovery goals for AI services, data pipelines, and vendors (Task 17) 14.02.2026

This episode explains how to set recovery goals for AI services in a way that matches business impact and operational reality, which AAISM questions often test by asking what should be prioritized and how to justify recovery targets. You will learn to define recovery objectives for availability, data integrity, and decision safety, then translate them into practical goals for model endpoints, supp...

Episode 43 — Add AI systems to business continuity plans without hidden weak points (Task 17) 14.02.2026

This episode teaches how to include AI systems in business continuity planning so operational resilience covers the full AI delivery chain, which AAISM tests through scenarios where outages and incidents reveal overlooked dependencies. You will learn to map continuity scope across model endpoints, data pipelines, feature stores, identity services, logging, and third-party platforms, then identify...

Episode 42 — Eradicate root causes and recover safely after AI security incidents (Task 16) 14.02.2026

This episode explains how eradication and recovery work in AI incidents, emphasizing that “restore service” is not the same as “restore trust,” which AAISM questions often probe through post-containment decision-making. You will learn to identify likely root-cause categories such as credential exposure, misconfigured access controls, unsafe prompt integrations, compromised data sources, or ungover...

Listen to the Certified: The ISACA AAISM Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.