ACISE logo
Focused certification exam prep
Start practice

ACISE Exam Domains 2026: Complete Guide to All 4 Content Areas

TL;DR
  • ACISE has four competency categories: Technical, Conceptual, Legal/Compliance, and Communications.
  • ACISE is competency- and experience-assessed, not a timed multiple-choice exam like many other certifications.
  • Eligibility requires nine qualifying IS/IT/cybersecurity examinations completed within three years.
  • Supervisors must formally attest to your competency across all four domain areas before certification.

Overview: What the ACISE Domains Actually Measure

If you're preparing for the Associate Certified Information Systems Examiner (ACISE) credential, the first thing to understand is that the "domains" aren't sections of a timed test. ACISE, administered under the Conference of State Bank Supervisors (CSBS) examiner certification framework, is a competency- and experience-assessed credential. The four domain lines function as competency categories that your supervisor evaluates and attests to based on your actual performance during qualifying IS/IT/cybersecurity examinations - not as buckets of multiple-choice questions on an exam day.

That distinction changes how you should prepare. Instead of memorizing flashcards for a simulated exam, you're building a documented track record across four skill areas: Technical, Conceptual, Legal/Compliance, and Communications. Understanding what each domain covers - and how examiners demonstrate mastery of it in the field - is the foundation of a realistic ACISE preparation strategy.

Why This Matters: Because ACISE certification hinges on supervisor-affirmed competency rather than a pass/fail exam score, candidates who understand the domain framework early can start collecting the right evidence during their qualifying examinations, rather than scrambling to demonstrate competency retroactively.

For a broader look at how these domains fit into the overall certification path, see our ACISE Requirements guide, which walks through eligibility, the nine-examination threshold, and the attestation process in detail.

Domain 1: Technical

Technical Competency

The Technical domain covers the hands-on information systems and IT knowledge examiners apply during a financial institution examination. This is where reviewers assess whether you can evaluate the systems, controls, and infrastructure that examinations are actually built around.

  • Understanding of core banking systems, network architecture, and IT general controls
  • Ability to evaluate cybersecurity controls, data security practices, and vendor/third-party technology risk
  • Comfort reviewing IT audit reports, vulnerability assessments, and incident response documentation
  • Application of examination procedures to real technology environments encountered during fieldwork

Supervisors look for evidence that you can independently identify technology weaknesses, connect them to institutional risk, and apply appropriate examination procedures - not just recite terminology. This competency area tends to be the one candidates spend the most time building through the CSBS IT Examiner School or the FDIC Information Technology Examination Course, since technical fluency underpins everything else in the examination process.

Domain 2: Conceptual

Conceptual Competency

The Conceptual domain measures your ability to connect technical findings to broader risk management, governance, and institutional strategy. It's less about spotting a control gap and more about understanding what that gap means for the institution as a whole.

  • Risk-based examination philosophy and how IT risk maps to overall institutional risk
  • Understanding of governance structures, board and management oversight of IT
  • Ability to prioritize findings by materiality and institutional impact
  • Judgment in applying examination scope decisions to varying institution sizes and complexity

This domain is often the hardest for newer examiners to demonstrate, since it requires synthesizing technical detail into judgment calls a supervisor can observe and sign off on. If you're unsure how demanding this aspect of the certification really is compared to the others, our breakdown of ACISE difficulty discusses where candidates most often need additional experience before their supervisor is comfortable attesting to this competency.

Legal/Compliance Competency

The Legal/Compliance domain assesses your grasp of the regulatory framework governing IT examinations at financial institutions, along with your ability to apply that framework consistently and defensibly.

  • Familiarity with applicable regulatory guidance and interagency examination standards for IT
  • Understanding of consumer protection, privacy, and data-handling regulatory expectations tied to technology
  • Ability to document findings in a manner that supports enforcement or corrective action, when warranted
  • Consistent application of examination standards across institutions of varying size and risk profile

Because this domain touches directly on regulatory defensibility, supervisors weigh it heavily when attesting to competency. Weak documentation habits or inconsistent application of standards in this area can slow down your certification timeline even if your technical skills are strong.

Key Takeaway

Treat every qualifying examination as an opportunity to practice writing findings that would hold up to regulatory or legal scrutiny - this is exactly what your supervisor is evaluating under the Legal/Compliance domain.

Domain 4: Communications

Communications Competency

The Communications domain evaluates how effectively you convey findings, both in writing and verbally, to bank management, boards, and examination teams. Strong technical work has limited value if it can't be communicated clearly to non-technical stakeholders.

  • Clarity and professionalism in written examination reports and findings memos
  • Ability to explain technical risk in terms that bank management and boards can act on
  • Effective collaboration within examination teams and with supervisory staff
  • Skill in delivering difficult or sensitive findings constructively during exit meetings

This domain is frequently underestimated. Candidates who are technically strong sometimes struggle here simply because they haven't practiced translating findings for a non-IT audience. Supervisors typically observe this competency directly during exit interviews and report reviews, so it's worth deliberately seeking feedback on your written and verbal communication throughout your qualifying examinations.

DomainCore FocusHow It's Demonstrated
TechnicalIT systems, controls, cybersecurityFieldwork findings and examination procedures
ConceptualRisk-based judgment and governanceScoping decisions and prioritization of findings
Legal/ComplianceRegulatory framework and documentationDefensible findings and consistent standard application
CommunicationsReporting and stakeholder engagementWritten reports and exit meeting performance

How Competency in Each Domain Gets Assessed

Because ACISE is not a simulated certification exam, there's no single test day where all four domains are scored simultaneously. Instead, competency is built and evidenced across the nine qualifying IS/IT/cybersecurity examinations required within a three-year window. Your supervisor observes your performance across these examinations and, alongside completion of appropriate examiner training, provides attestations affirming that you've reached competency in each of the four areas.

This means the "exam" experience for ACISE candidates is really an ongoing evaluation embedded in real examination work. Training programs - whether the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent - are designed to build the foundational knowledge your supervisor will later assess in live examination settings.

Practical Implication: Since attestation is supervisor-driven rather than score-driven, proactively discussing domain expectations with your supervisor early in your qualifying examinations can help you close competency gaps before they become a certification bottleneck.

Once you're certified, maintaining that status isn't a one-time event either. Recertification requires 63 continuing education hours every three years, with up to 14 eligible excess hours carried forward, plus ongoing IT examination participation or oversight. In other words, the domains stay relevant well past your initial certification - they continue to frame how your professional development and CE activities should be structured.

Building a Domain-by-Domain Preparation Plan

Even though ACISE isn't a study-for-a-test-date credential, structuring your preparation around the four domains still helps you build competency efficiently and identify gaps before your supervisor's attestation review. A simple domain-focused approach over several weeks can help organize training coursework, examination assignments, and self-review.

Weeks 1-2

Technical Foundations

  • Complete or review core IT Examiner School / FDIC IT Examination Course material
  • Focus qualifying examination assignments on technology and control review tasks
Weeks 3-4

Conceptual Judgment

  • Practice risk-prioritization on findings from recent examinations
  • Seek supervisor feedback on scoping and materiality decisions
Weeks 5-6

Legal/Compliance Precision

  • Review applicable regulatory guidance relevant to recent findings
  • Draft findings language and have a supervisor review for defensibility
Weeks 7-8

Communications Polish

  • Request feedback on written reports and exit meeting delivery
  • Practice explaining technical findings to non-technical stakeholders

This kind of structured rotation works well alongside broader study planning. Our ACISE Study Guide goes deeper into pacing your preparation across the full eligibility window, and our ACISE Cheat Sheet condenses the domain essentials into a single quick-reference page you can revisit before supervisor check-ins.

Documenting Domain Competency for Your Application

Because attestation drives certification, documentation habits matter as much as skill itself. Candidates who keep organized records of their qualifying examinations - noting which domain competencies were demonstrated in each assignment - tend to move through the attestation and application process more smoothly.

  • Keep a running log of examinations completed, noting technology focus areas covered under the Technical domain
  • Note specific instances where you made risk-prioritization or scoping decisions relevant to the Conceptual domain
  • Save examples of findings language or regulatory citations tied to the Legal/Compliance domain
  • Request written or verbal feedback from supervisors on report quality and exit meetings for the Communications domain

This kind of record-keeping also makes conversations with your supervisor more concrete when it's time for them to complete attestations. If you're still mapping out eligibility timing or want to understand how the nine-examination requirement interacts with your training schedule, the ACISE Requirements guide covers that groundwork, and our ACISE practice test platform can help reinforce domain concepts as you prepare for supervisor discussions and training coursework.

Key Takeaway

Documentation tied to each domain is your best tool for a smooth attestation process - start logging domain-specific evidence from your very first qualifying examination.

It's also worth understanding the full cost picture before committing to the training and examination path, since qualifying examinations, training courses, and continuing education all carry associated costs over the certification timeline. Our ACISE Certification Cost breakdown outlines what to budget for as you work through the four domains toward certification. And if you're weighing whether the domain-based competency model translates into stronger career outcomes, browsing current ACISE-related job listings can help contextualize how employers value each of these skill areas in practice. You can also use our practice resources to sharpen the technical and conceptual knowledge that underpins domain competency before you head into qualifying examinations.

FAQ: ACISE Domains

Are the ACISE domains scored on a single exam day?

No. ACISE is competency- and experience-assessed rather than a timed multiple-choice exam. The four domains - Technical, Conceptual, Legal/Compliance, and Communications - are evaluated across your qualifying IS/IT/cybersecurity examinations and confirmed through supervisor attestations.

How many domains does ACISE have, and what are they?

There are four domain lines: Technical, Conceptual, Legal/Compliance, and Communications. Each represents a competency category your supervisor evaluates rather than a scored test section.

Which domain do candidates typically find most challenging?

Many candidates find the Conceptual domain challenging because it requires demonstrating judgment - connecting technical findings to institutional risk and governance - rather than simply applying technical knowledge.

Do the domains matter after I'm certified?

Yes. Recertification requires 63 continuing education hours every three years (with up to 14 excess hours carried forward) plus ongoing IT examination participation or oversight, so maintaining domain competency remains relevant throughout your career.

What training routes help build competency across all four domains?

The CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent are the recognized training routes that help build the foundational knowledge assessed through supervisor attestation.

Ready to pass your ACISE exam?

Put this into practice with free ACISE questions across every exam domain.