- What Is the ACISE Certification?
- Who Grants ACISE and Why It Matters
- The Four ACISE Competency Domains
- Eligibility Requirements
- How ACISE Differs From a Timed Exam
- Preparing Your Application and Documentation
- Maintaining Certification: Recertification and CE Hours
- Who Pursues ACISE and Career Fit
- Building a Readiness Timeline
- Frequently Asked Questions
- ACISE is granted by the Conference of State Bank Supervisors (CSBS) and assesses competency and experience, not a timed multiple-choice test.
- Eligibility requires nine qualifying IS/IT/cybersecurity examinations within three years plus supervisor-affirmed attestations.
- Approved training routes include CSBS IT Examiner School and the FDIC Information Technology Examination Course.
- The credential covers four domains: Technical, Conceptual, Legal/Compliance, and Communications.
What Is the ACISE Certification?
The Associate Certified Information Systems Examiner (ACISE) credential recognizes examiners who have demonstrated real-world competency in evaluating information systems risk within financial institutions. Unlike many professional certifications built around a single high-stakes exam day, ACISE is structured as a competency- and experience-based designation. Candidates prove readiness through documented examination work, supervisor attestations, and completion of recognized training, rather than by sitting for a timed, proctored exam with a scored cut line.
That distinction matters enormously for how you should prepare. If you're coming from a background in exams that use scaled scores and passing thresholds, you'll want to recalibrate your expectations early. For a broader orientation to the credential before diving into specifics, our overview of what ACISE certification actually involves is a useful companion piece to this article.
Who Grants ACISE and Why It Matters
The Conference of State Bank Supervisors (CSBS) administers the ACISE designation. CSBS represents state banking regulators, and the certification is tightly connected to the practical work of examining information systems within state-chartered financial institutions. Because the credential is tied to a regulatory body rather than a generic testing vendor, the path to earning it runs through actual examination assignments, formal training coursework, and sign-off from supervisors who have observed your work firsthand.
This regulatory grounding is also why ACISE carries weight with the organizations that hire for these roles. If you're mapping the credential against career outcomes, our guide to ACISE-related job roles breaks down where this designation is most commonly required or preferred, and our ROI analysis of ACISE certification looks at the value proposition in more depth.
The Four ACISE Competency Domains
Rather than testing knowledge in isolated questions, ACISE evaluates competency across four domain lines. These are not "chapters to memorize" so much as categories of professional judgment you must demonstrate through your examination work and attestations.
Domain 1: Technical
Covers your ability to evaluate the technical infrastructure, controls, and risk exposures within an institution's information systems environment.
- Assessing network architecture, access controls, and system configurations
- Evaluating data security controls and vulnerability management practices
- Recognizing red flags in IT operations that warrant deeper examination scrutiny
Domain 2: Conceptual
Focuses on the examiner's grasp of risk management frameworks and how IS risk connects to broader institutional soundness.
- Applying risk-based examination frameworks to IT environments
- Connecting technology risk to safety-and-soundness principles
- Interpreting how emerging technology affects institutional risk posture
Domain 3: Legal/Compliance
Addresses the regulatory and compliance dimension of information systems examination work.
- Understanding applicable regulatory guidance governing IT examinations
- Documenting findings in a manner that supports supervisory action
- Recognizing compliance gaps tied to information systems governance
Domain 4: Communications
Assesses the examiner's ability to translate technical findings into clear guidance for institutions and supervisory teams.
- Writing examination findings that are accurate and actionable
- Communicating risk to non-technical bank management and boards
- Coordinating findings with fellow examiners and supervisory staff
For a deeper breakdown of how these four areas interact and what evidence best demonstrates competency in each, see our dedicated guide to all four ACISE domains.
Eligibility Requirements
Because ACISE is competency- and experience-based, eligibility is built around demonstrated examination work rather than a single application form. The core components include:
- Nine qualifying IS/IT/cybersecurity examinations completed within a three-year window
- Appropriate examiner training, completed through an accepted program
- Supervisor-affirmed competency attestations confirming your demonstrated skill across the domain areas
Accepted training routes include the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another accepted equivalent. Choosing the right training path early affects how quickly you can accumulate qualifying examinations and how well-documented your competency record will be by the time you're ready to apply.
Our full ACISE requirements and eligibility breakdown walks through each of these components in more detail, including how the three-year examination window is typically tracked.
Key Takeaway
Start logging qualifying examinations and supervisor feedback from day one of your examiner role - by the time you're ready to apply, you'll need a clear paper trail across all nine examinations and all four domains.
How ACISE Differs From a Timed Exam
Many certification candidates search for details on "exam format," "passing score," or "test day" logistics - and it's worth being direct here: ACISE does not work that way. There is no proctored, multiple-choice exam window to schedule, and no scaled score to hit. Instead, readiness is demonstrated through:
- The volume and recency of qualifying examinations you've completed
- Completion of recognized examiner training coursework
- Written attestations from supervisors who can vouch for your competency in each domain
This changes what "studying" for ACISE actually means. Rather than drilling practice questions against the clock, your preparation is about building examination reps, closing skill gaps your supervisor identifies, and making sure your documentation reflects competency across Technical, Conceptual, Legal/Compliance, and Communications work. If you're weighing how demanding this path is compared to traditional certifications, our difficulty guide and our look at what the available data shows both address this comparison directly.
| Traditional Timed Certification Exam | ACISE Competency Pathway |
|---|---|
| Scored multiple-choice questions on exam day | Competency demonstrated across nine qualifying examinations |
| Fixed passing score / cut line | Supervisor-affirmed attestation of competency in each domain |
| One-time proctored testing appointment | Training completion plus a multi-year examination track record |
| Retake policy if you fail | Continued examination work and skill development until attestation is met |
Preparing Your Application and Documentation
Since ACISE hinges on documentation rather than a test score, the strength of your application depends on how well you've tracked and organized your examiner history. Practical steps that make the process smoother:
- Maintain a running log of each qualifying examination, including dates, institution type, and your role on the exam team
- Request supervisor feedback in writing after major examinations, not just at annual review time
- Map each completed examination against the four domains so you can identify gaps before they become application problems
- Confirm your training completion (CSBS IT Examiner School, FDIC IT Examination Course, or equivalent) is documented and retrievable
Understanding the fee and cost mechanics tied to training, application, and maintenance also helps you plan the financial side of this path - our ACISE certification cost breakdown covers these details. For candidates who want a structured way to prepare their competency evidence and review domain concepts alongside their examination work, our ACISE study guide is built specifically around this application-and-competency model rather than a test-prep model.
Maintaining Certification: Recertification and CE Hours
Earning ACISE isn't the finish line - the credential requires ongoing maintenance to stay current. Recertification requires:
- 63 continuing education hours completed every three years
- Up to 14 eligible excess hours carried forward into the next cycle if you exceed the requirement
- Continued participation in, or oversight of, IT examinations to demonstrate your competency remains active
This structure rewards examiners who stay engaged with the field year-round rather than cramming CE hours at the last minute. Building a habit of logging relevant training, webinars, and examination oversight work throughout each three-year cycle makes recertification far less stressful.
Who Pursues ACISE and Career Fit
ACISE candidates are typically working examiners already embedded in state or federal financial regulatory environments, or professionals moving into IT examination roles from broader bank examination backgrounds. Because eligibility requires nine qualifying examinations completed over three years, the credential is inherently tied to people already doing the work - not outside candidates studying toward an entry-level test.
This makes ACISE most relevant to:
- Bank examiners transitioning into or specializing in information systems/IT examination work
- IT and cybersecurity professionals moving into regulatory examination roles
- Examiners seeking formal recognition of competency to support career advancement within state banking supervision
If you're still getting oriented to the acronym and its scope, our companion articles on what ACISE is, what the ACISE designation means, and what ACISE stands for provide quick-reference context before you dive into the eligibility mechanics.
Building a Readiness Timeline
Because ACISE unfolds over a multi-year examination window rather than a single study season, your "prep schedule" should be structured around accumulating and documenting competency, not cramming content. A simple way to think about pacing across your three-year eligibility window:
Foundation and Training
- Complete CSBS IT Examiner School, the FDIC IT Examination Course, or an accepted equivalent
- Begin logging qualifying examinations against the Technical and Conceptual domains
Domain Breadth
- Seek examination assignments that stretch your Legal/Compliance and Communications experience
- Request written supervisor feedback after each major examination
Documentation and Application
- Reach nine qualifying examinations across the three-year window
- Finalize supervisor attestations and assemble your application record
Generic study techniques like spaced review or structured weekly checklists still have a place here - but they should be applied to reviewing domain concepts and closing competency gaps your supervisor flags, not to memorizing practice-test answers. Our one-page review of must-know ACISE facts is designed as a quick refresher for exactly this kind of ongoing review, and you can sharpen your understanding of domain-specific scenarios using the practice resources on our main ACISE practice test platform.
Frequently Asked Questions
No. ACISE is a competency- and experience-based designation from the Conference of State Bank Supervisors. Readiness is demonstrated through qualifying examinations, training completion, and supervisor attestations rather than a timed, scored exam.
Candidates need nine qualifying IS/IT/cybersecurity examinations completed within a three-year period, along with appropriate training and supervisor-affirmed competency attestations.
Accepted training routes include the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another accepted equivalent program. See our ACISE training guide for more on choosing between these routes.
Recertification requires 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward, plus ongoing participation in or oversight of IT examinations.
Technical, Conceptual, Legal/Compliance, and Communications. Each reflects a category of competency assessed through your actual examination work rather than a scored test section.
Whether you're just starting to track qualifying examinations or preparing your final attestation package, understanding how the ACISE competency framework fits together - and reviewing domain scenarios using resources like our practice platform - puts you in a far stronger position than treating this like a conventional exam-day certification.