- What ACISE Certification Actually Involves
- The Four ACISE Competency Domains
- Eligibility: The Nine-Exam Rule and What Counts
- Approved Training Routes
- Building Your Competency Documentation File
- A Realistic Preparation Timeline
- Staying Certified After Approval
- Why Applications Stall (And How to Avoid It)
- FAQ
- ACISE is a competency- and experience-assessed certification from CSBS, not a timed multiple-choice exam.
- You need nine qualifying IS/IT/cybersecurity examinations completed within three years to be eligible.
- The four domains - Technical, Conceptual, Legal/Compliance, Communications - are competency categories, not exam sections.
- Approved training paths include CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent.
What ACISE Certification Actually Involves
If you've studied for a proctored, timed certification exam before, you need to reset your expectations for ACISE. The Associate Certified Information Systems Examiner credential, issued by the Conference of State Bank Supervisors (CSBS), is assessed through documented competency and verified field experience - not a single sit-down test with a passing score printed at the end. There is no exam-day scenario where you answer 150 multiple-choice questions in three hours and walk out with a result.
That distinction matters enormously for how you "study." Success with ACISE looks less like cramming flashcards the night before an exam and more like assembling a defensible, well-organized record of examinations performed, training completed, and supervisor sign-off on your abilities across four defined competency areas. If you're coming to this guide expecting a traditional test-prep walkthrough, start with our overview of what ACISE actually is and our breakdown of how difficult the ACISE process really is before you build a study plan - the difficulty here is administrative and experiential, not test-taking difficulty.
The Four ACISE Competency Domains
CSBS organizes examiner competency into four domain lines. Unlike a scored exam blueprint, these are not weighted sections you answer questions from - they are the categories your supervisor and the certifying body use to evaluate whether your on-the-job examination work demonstrates sufficient maturity. For a full breakdown of each area, see our complete guide to all four ACISE domains.
Domain 1: Technical
Covers your ability to evaluate an institution's information systems environment, infrastructure, and controls with accuracy during an examination.
- Demonstrated capability assessing IT infrastructure risk during real examinations
Domain 2: Conceptual
Reflects your grasp of how IT risk connects to broader institution risk, safety, and soundness - thinking beyond the checklist.
- Ability to translate technical findings into institution-level risk conclusions
Domain 3: Legal/Compliance
Assesses familiarity with the regulatory and supervisory framework governing IT examinations of financial institutions.
- Working knowledge of applicable examination standards and supervisory expectations
Domain 4: Communications
Measures how effectively you convey findings - to examination teams, institution management, and supervisory chains.
- Clear, documented communication of examination conclusions and recommendations
Because competency in each domain is affirmed by a supervisor based on your actual examination performance, the best "study material" is your own examination file. Reviewing prior workpapers, reports, and feedback with each domain in mind is more valuable than generic test-prep content. Our one-page ACISE review sheet organizes the domain language so you can map your experience against it quickly.
Eligibility: The Nine-Exam Rule and What Counts
Before competency attestation even becomes relevant, you have to meet the baseline eligibility bar. CSBS requires candidates to have participated in nine qualifying IS/IT/cybersecurity examinations within a three-year window. This is the single most important number to plan around, because it defines your entire preparation timeline - you cannot shortcut it with extra study hours or a retake.
- Nine qualifying examinations must fall within a rolling three-year period
- Examinations must be IS/IT/cybersecurity-focused to count toward eligibility
- Appropriate examiner training must accompany your examination history
- A supervisor must affirm your competency across the domain areas
For the full eligibility breakdown, including how examination participation is typically tracked and what supervisors look for when they sign off, read our dedicated ACISE requirements and eligibility guide. If you're mapping out cost and timing alongside eligibility, our ACISE certification cost breakdown and guide to ACISE testing windows and deadlines are useful companions.
Key Takeaway
Start counting your qualifying examinations now. If you're new to IS/IT examination work, your realistic ACISE timeline is measured in years of field experience, not weeks of study.
Approved Training Routes
Alongside examination volume, CSBS expects candidates to complete recognized examiner training. There are a few accepted paths:
- CSBS IT Examiner School - the primary training track built specifically for state examiner development
- FDIC Information Technology Examination Course - a recognized federal alternative that covers overlapping material
- An accepted equivalent - training that CSBS determines satisfies the same competency-building objective
Which route makes sense depends on your employer, your state, and which course is scheduled soonest. If your agency already has a training pipeline in place, use it - the goal is documented completion, not a specific brand of course. Our ACISE training guide compares these routes in more depth and explains how training completion feeds into your overall application package.
Building Your Competency Documentation File
Because there's no single exam session to prepare for, the most productive thing you can do to "pass on your first attempt" is build a clean, organized file well before you submit anything. Think of this as your equivalent of exam prep - except the deliverable is a paper trail, not a score.
- Log every qualifying examination as you complete it: institution type, examination scope, your role, and dates. Don't reconstruct this later from memory.
- Request supervisor feedback tied to domain language. Ask supervisors to comment specifically on Technical, Conceptual, Legal/Compliance, and Communications performance, not just general praise.
- Keep training completion certificates from CSBS IT Examiner School, the FDIC course, or your equivalent training in one place.
- Track continuing education as it happens so you're not scrambling to reconstruct hours later - this habit also sets you up well for recertification.
- Review your file annually against the domain descriptions so gaps in experience surface early enough to address them.
A Realistic Preparation Timeline
Because ACISE readiness spans years of examination work rather than weeks of review, a traditional cram schedule doesn't apply. What does help is using structured review blocks to organize your documentation and close domain-specific gaps as you approach the point of eligibility. Here's a compressed version scaled to the final months before you plan to submit your application.
Inventory Your Examination History
- List every qualifying IS/IT/cybersecurity examination and confirm it falls within the three-year window
- Identify any gaps toward the nine-examination threshold
Domain Self-Assessment
- Review your workpapers and reports against Technical and Conceptual domain descriptions
- Note where supervisor feedback is thin and request additional written commentary
Legal/Compliance and Communications Review
- Revisit regulatory guidance referenced in recent examinations
- Gather examples of written reports and presentations that demonstrate clear communication
Training Verification and Final Assembly
- Confirm CSBS IT Examiner School, FDIC course, or equivalent training completion is documented
- Assemble the full file and request final supervisor attestation
Notice what's absent from this schedule: there's no domain-weighted question bank to drill and no simulated exam to time yourself against. If you came looking for that kind of prep, our ACISE study guide hub and practice environment at ACISE Exam Prep are still useful for reinforcing domain concepts through scenario-based review, even though the real evaluation happens through your employer and CSBS.
Staying Certified After Approval
Getting approved isn't the finish line. ACISE recertification requires 63 continuing education hours every three years, and CSBS allows up to 14 eligible excess hours to carry forward into the next cycle if you exceed the requirement. Beyond CE hours, you also need to maintain continuing IT examination participation or oversight - the credential is meant to reflect an active examiner, not a one-time achievement.
| Requirement | Detail |
|---|---|
| Continuing education hours | 63 hours every three years |
| Excess hour carryover | Up to 14 hours eligible to roll into next cycle |
| Ongoing activity requirement | Continued IT examination participation or oversight |
Building CE tracking into your normal workflow from day one - the same way you logged qualifying examinations before certification - makes recertification far less stressful. Treat the 14-hour carryover as a small buffer, not a target to plan around.
Why Applications Stall (And How to Avoid It)
Most delays in the ACISE process aren't caused by a lack of technical skill. They're caused by administrative gaps that could have been caught earlier:
- Examinations that fall just outside the three-year window because logging started late
- Training certificates that were never saved or can't be located when the application file is assembled
- Supervisor attestations that don't map to the four domains, forcing a second round of feedback requests
- Continuing education hours tracked informally, leading to disputes during recertification
Each of these is preventable with the documentation habits outlined above. If you're still deciding whether the multi-year investment is worthwhile given your career goals, our analysis of whether ACISE certification is worth it and our look at who hires ACISE-certified examiners can help you weigh the return before you commit years of examination work toward it. For a numbers-focused view, see our ACISE salary guide and ACISE pass rate data breakdown.
Key Takeaway
The candidates who move through ACISE certification fastest aren't necessarily the strongest technical examiners - they're the ones who documented their examination history and training consistently from the start.
Frequently Asked Questions
No. ACISE is a competency- and experience-assessed certification from CSBS. Instead of a timed exam, candidates are evaluated on qualifying examination history, completed training, and supervisor-affirmed competency across four domain areas.
CSBS requires nine qualifying IS/IT/cybersecurity examinations completed within a three-year period, along with appropriate examiner training and supervisor competency attestation.
Technical, Conceptual, Legal/Compliance, and Communications. These are competency categories used to evaluate your examination work, not sections of a scored test. See our full domains guide for detail on each.
CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another CSBS-accepted equivalent all satisfy the training component of eligibility.
You need 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward, plus ongoing participation in or oversight of IT examinations.