ACISE logo
Focused certification exam prep
Start practice

What Is A ACISE?

TL;DR
  • ACISE stands for Associate Certified Information Systems Examiner, granted through the Conference of State Bank Supervisors (CSBS).
  • It is a competency- and experience-assessed credential, not a timed multiple-choice exam.
  • Candidates need nine qualifying IS/IT/cybersecurity examinations completed within three years, plus supervisor attestations.
  • Training can come from the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent.

What Is a ACISE?

A ACISE, or Associate Certified Information Systems Examiner, is a designation for financial institution examiners who specialize in information systems, IT, and cybersecurity examination work. Unlike credentials built around a single proctored exam, the ACISE is a competency- and experience-based certification. It confirms that an examiner has actually performed a defined volume of IS/IT/cybersecurity examinations, received recognized training, and had that competency attested to by a qualified supervisor.

If you're trying to understand the credential from the ground up, this overview pairs well with our companion pieces on ACISE Meaning and What Does ACISE Stand For?, which unpack the terminology in more detail. This article focuses specifically on what the designation is, who issues it, and what candidates must demonstrate to earn it.

Not a Simulated Exam: There is no single sit-down, timed, multiple-choice test that produces an ACISE. The certification is built from documented field experience, approved training, and attested competency across four domain areas.

Who Grants the ACISE Credential

The ACISE designation is issued through the Conference of State Bank Supervisors (CSBS), the national organization that represents state financial regulators. Because CSBS sits at the intersection of state banking supervision and IT examination practice, the ACISE credential is specifically oriented toward examiners who work within, or alongside, state and federal banking supervisory structures rather than toward general IT auditors in the private sector.

This regulatory lineage matters for how you prepare. It's why the credential leans on documented examination history and supervisor sign-off rather than a proctored knowledge test - the goal is to verify that an examiner can competently perform the job in the field, not just answer questions about it.

How the ACISE Assessment Actually Works

Because the ACISE is competency- and experience-assessed, candidates don't "sit" for an exam in the traditional sense. Instead, the four domain lines function as competency categories against which experience and training are evaluated. That distinction is critical, and it's why generic exam-prep advice - timers, answer-choice elimination tricks, scoring curves - doesn't transfer cleanly to ACISE preparation.

What does transfer is disciplined preparation around the competencies themselves: understanding what each domain expects, documenting your examination history against those expectations, and being ready to discuss real scenarios with clarity. Our ACISE difficulty guide goes deeper into how this competency model changes the nature of "difficulty" compared to a conventional certification exam, and our ACISE passing score breakdown explains how competency is judged when there's no numeric cut score in the traditional sense.

Key Takeaway

Prepare for the ACISE by building a defensible record of examination work and demonstrated competency - not by cramming for a timed test.

The Four ACISE Competency Domains

The ACISE evaluates competency across four domain lines. Each one maps to a distinct part of what an IS/IT examiner does in the field, and each should get dedicated attention when you're building your experience file or studying supporting material.

Domain 1: Technical

Covers the hands-on IT and information systems knowledge examiners rely on: system architecture, network and infrastructure controls, information security practices, and the technical mechanics of the systems being examined.

  • Understanding core IT infrastructure and control environments
  • Recognizing technical risk indicators during an examination

Domain 2: Conceptual

Focuses on the examiner's ability to translate technical findings into broader risk concepts - connecting a specific control weakness to institution-level risk, governance, and management practices.

  • Linking technical observations to overall risk assessment
  • Applying examination frameworks consistently across engagements

Domain 3: Legal/Compliance

Addresses the regulatory and legal framework examiners must operate within, including relevant statutes, guidance, and supervisory expectations that shape how findings are documented and reported.

  • Applying applicable regulatory guidance accurately
  • Documenting findings in a manner that withstands supervisory review

Domain 4: Communications

Evaluates the examiner's ability to communicate findings clearly to institution management, supervisory teams, and other stakeholders - a core competency given how much of examination work involves reporting and dialogue.

  • Writing clear, defensible examination findings
  • Communicating risk to non-technical stakeholders

For a full breakdown of how each domain is weighted in competency review and what specific topics fall under each, see our complete guide to all four ACISE content areas. Our one-page ACISE cheat sheet is also a useful quick-reference once you've studied each domain in depth.

Eligibility: The Nine-Examination Rule

To pursue the ACISE, candidates must meet an experience threshold: nine qualifying IS/IT/cybersecurity examinations completed within a three-year window. This isn't a training exercise - it's real examination work performed in the field, and it needs to be documented in a way that a reviewing body can verify.

Alongside the examination count, candidates need:

  • Appropriate examiner training (see approved routes below)
  • Supervisor-affirmed competency attestations confirming the candidate performed at an acceptable level across the domain areas

Because the three-year window is fixed, timing matters. Examiners who spread qualifying examinations too thinly across their career, rather than concentrating nine within a rolling three-year period, can find themselves short of eligibility even with a long examination history. Our detailed requirements and eligibility guide walks through how to plan your examination assignments so you hit the threshold within the window, and how to organize supervisor attestations well before you apply.

Plan the Window, Not Just the Count: Nine examinations sounds straightforward, but the three-year clock means examiners should track dates as carefully as volume. Falling one examination short inside the window resets the clock.

Approved Training Routes

Training is a required component alongside examination experience. CSBS recognizes several paths:

  • CSBS IT Examiner School - the primary training track built specifically around state examiner needs
  • FDIC Information Technology Examination Course - a federally delivered equivalent covering comparable ground
  • An accepted equivalent - other recognized coursework that satisfies the same training objectives

Whichever route you take, the training should reinforce the same four domains the competency review will assess: Technical, Conceptual, Legal/Compliance, and Communications. If you're weighing which training path fits your schedule and background, our ACISE training guide compares the options in more depth, and our certification cost breakdown outlines what training, application, and maintenance expenses typically look like for candidates working through this process.

Recertification and Continuing Education

Earning the ACISE isn't the end of the obligation - maintaining it requires ongoing engagement with the field. Recertification requires:

  • 63 continuing education hours every three years
  • Up to 14 eligible excess hours can be carried forward into the next recertification cycle
  • Continued IT examination participation or oversight during the cycle

This structure rewards examiners who stay consistently active rather than trying to front-load hours right before a deadline. Because excess hours carry forward, a strong CE year can ease the burden on a slower one - but ongoing examination participation or oversight is a separate requirement that CE hours alone can't substitute for.

Cycle Start

Establish Your Baseline

  • Log qualifying examination participation as it happens
  • Identify CE opportunities tied to each of the four domains
Mid-Cycle

Track and Adjust

  • Review CE hours earned against the 63-hour target
  • Confirm continued examination oversight is documented
Cycle End

Reconcile and Carry Forward

  • Confirm any excess hours (up to 14) to carry into the next cycle
  • Submit recertification documentation ahead of deadlines

Who Pursues and Hires ACISEs

The ACISE is built for examiners already embedded in financial supervision - typically those working within state banking departments, examination teams that coordinate with state regulators, or institutions that supply IT examination staff to that ecosystem. It signals that an examiner has hands-on, verified competency across technical, conceptual, legal/compliance, and communications work - not just classroom exposure.

For examiners weighing whether to pursue it, our ROI analysis of the ACISE certification looks at how the credential fits into an examiner's career trajectory, and our ACISE earnings guide discusses how the designation is generally viewed in relation to compensation and role progression. If you're exploring open roles, our ACISE jobs overview covers the kinds of positions where the credential is most relevant.

Preparing Your Competency File

Because there's no single test day, ACISE preparation is really about building and organizing evidence. That means:

  1. Maintaining a running log of every qualifying examination, dated and categorized by which domain competencies it demonstrated
  2. Requesting supervisor attestations promptly after examinations, rather than trying to reconstruct memory of performance months later
  3. Reviewing domain-specific material - Technical, Conceptual, Legal/Compliance, and Communications - on a rotating basis so no single area is neglected as the three-year window progresses
  4. Confirming training records from CSBS IT Examiner School, the FDIC course, or an accepted equivalent are complete and accessible

A structured review calendar still helps here, even though there's no exam date to count down to. Scheduling review time by domain - Technical topics one stretch, Legal/Compliance guidance another - keeps preparation aligned with how competency is actually assessed. For a step-by-step version of this approach, see our ACISE study guide for 2026, and if you want a sense of how candidates typically fare across the process, our ACISE pass rate analysis looks at what the available data actually shows.

Practicing domain-based scenario analysis - working through realistic examination situations across all four competency areas - is one of the more effective ways to prepare, and it's the same approach we build into the scenario library on our main practice platform. If you haven't looked through the ACISE Exam Prep practice resources yet, it's worth reviewing before you finalize your competency documentation, and the practice tools available here can help reinforce domain concepts as you study.

FeatureACISE Certification
FormatCompetency- and experience-assessed, not a timed multiple-choice exam
Certifying BodyConference of State Bank Supervisors (CSBS)
Domain StructureFour competency categories: Technical, Conceptual, Legal/Compliance, Communications
Core EligibilityNine qualifying IS/IT/cybersecurity examinations within three years
Training RequirementCSBS IT Examiner School, FDIC IT Examination Course, or accepted equivalent
Recertification63 CE hours every three years; up to 14 excess hours carried forward

Frequently Asked Questions

Is the ACISE a timed exam like other certifications?

No. The ACISE is competency- and experience-assessed. There's no single timed, multiple-choice exam - instead, examiners are evaluated against four domain competencies through documented examination experience and supervisor attestation.

How many examinations do I need to qualify for the ACISE?

Candidates need nine qualifying IS/IT/cybersecurity examinations completed within a three-year period, along with appropriate training and supervisor-affirmed competency attestations.

What training satisfies the ACISE requirement?

CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent training program can satisfy the training component of eligibility.

How do I maintain the ACISE once I earn it?

Recertification requires 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward, plus ongoing IT examination participation or oversight.

What are the four ACISE competency domains?

Technical, Conceptual, Legal/Compliance, and Communications. Each represents a distinct competency area examiners must demonstrate through their examination experience and training.

Ready to pass your ACISE exam?

Put this into practice with free ACISE questions across every exam domain.