- What Is ACISE Certification?
- Who Issues ACISE and Why It Exists
- Why ACISE Is Not a Timed Multiple-Choice Exam
- The Four ACISE Competency Domains
- Eligibility: The Nine Qualifying Examinations Rule
- Approved Training Routes
- Recertification and Continuing Education
- Who Earns ACISE and Why
- How to Prepare for the Competency Assessment
- Frequently Asked Questions
- ACISE is issued through the Conference of State Bank Supervisors (CSBS) as an examiner-level credential.
- It's competency- and experience-assessed, not a timed multiple-choice exam.
- Candidates need nine qualifying IS/IT/cybersecurity examinations within three years, plus supervisor attestations.
- Training can come from the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or an accepted equivalent.
What Is ACISE Certification?
ACISE stands for Associate Certified Information Systems Examiner. It is a credential built specifically for examiners who assess information technology risk inside financial institutions - the professionals who sit across the table from bank management and evaluate whether IT governance, cybersecurity controls, and vendor management practices actually hold up. If you've landed on a page anywhere else on the internet describing ACISE as a proctored, timed, multiple-choice exam with a fixed pass rate and a flat fee schedule, that description belongs to a different credential with the same acronym. The Associate Certified Information Systems Examiner credential covered on this site works differently, and understanding that difference is the first step in preparing for it correctly.
Instead of a single sit-down exam, ACISE evaluates whether an examiner has demonstrated real competency across four defined areas through actual examination work, supervised experience, and formal training. This guide walks through what the credential covers, how eligibility and recertification actually function, and how to build a preparation plan that matches the way ACISE really assesses candidates. For a broader orientation to the credential's structure, our companion piece on ACISE Certification is a useful next stop, and if you're still untangling the acronym itself, see ACISE Meaning and What Does ACISE Stand For?.
Who Issues ACISE and Why It Exists
ACISE is administered under the Conference of State Bank Supervisors (CSBS), the organization that coordinates state banking regulation and examiner development across the United States. The credential was created to formalize what "qualified IT examiner" means at a time when financial institutions face growing technology and cybersecurity risk, and when state banking departments need a consistent way to verify that the examiners assigned to IT reviews actually have the depth of experience the work demands.
Because CSBS oversees a network of state examiners rather than a single testing population, the certification model reflects that reality: it's built to validate skills that were developed on the job, across real examinations, rather than skills demonstrated in a single artificial testing session. That structural choice shapes almost everything else about how candidates should prepare, and it's the reason generic exam-prep advice often misses the mark for this specific credential.
Why ACISE Is Not a Timed Multiple-Choice Exam
This is the single most important thing to understand before you start preparing: ACISE is a competency- and experience-assessed certification, not a timed multiple-choice examination. There is no countdown clock, no bank of randomized questions, and no scaled score delivered at the end of a testing session. Instead, the four "domain lines" you'll see referenced throughout ACISE materials are competency categories - areas of examiner skill that get evaluated through your actual work product, your training record, and attestations from supervisors who have observed your performance in the field.
That distinction matters enormously for how you should study. If you've been searching for information on how hard the ACISE exam is or an ACISE passing score, it helps to reframe the question: difficulty here is less about memorizing facts for a single test window and more about accumulating and documenting the right kind of examination experience over time, then being able to demonstrate that competency clearly when it's reviewed.
Key Takeaway
Prepare for ACISE the way you'd prepare for a competency review, not a timed test: build a documented track record of IT examination work, keep training certificates organized, and make sure supervisors can speak specifically to your performance in each domain.
The Four ACISE Competency Domains
ACISE organizes examiner competency into four domain lines. These aren't chapters in a study guide you memorize the night before a test - they're the categories a supervisor or reviewing body uses to evaluate whether your examination experience demonstrates well-rounded skill.
Domain 1: Technical
Covers the hands-on IT examination skills examiners need to assess an institution's technology environment - infrastructure, network architecture, cybersecurity controls, data management, and the technical mechanics of how information systems risk shows up in practice.
- Ability to evaluate technical controls and identify weaknesses during an actual examination
Domain 2: Conceptual
Focuses on the examiner's grasp of the broader framework behind IT risk - how governance, risk management, and strategic technology decisions connect to an institution's overall safety and soundness.
- Ability to connect specific findings to the bigger picture of institutional risk
Domain 3: Legal/Compliance
Addresses the regulatory and legal dimension of IT examination - knowing which rules, guidance, and compliance obligations apply, and being able to assess an institution's adherence to them.
- Ability to apply relevant regulatory expectations accurately during an exam
Domain 4: Communications
Covers how effectively an examiner conveys findings - to institution management, to examination teams, and in written reports - since technical findings only create value when they're communicated clearly and persuasively.
- Ability to write clear findings and present them constructively to stakeholders
For a deeper breakdown of what each of these competency categories involves and how they show up in real examiner work, see our full ACISE Exam Domains Guide.
Eligibility: The Nine Qualifying Examinations Rule
Because ACISE is experience-based, eligibility isn't a matter of registering and paying a fee to sit for a test. Candidates need to have participated in nine qualifying IS/IT/cybersecurity examinations within a three-year window. This requirement is the backbone of the whole credential - it's what ensures every certified examiner has recent, substantial, hands-on exposure to the kind of work the certification represents.
Alongside the examination count, candidates need:
- Appropriate examiner training completed through an approved pathway
- Supervisor-affirmed competency attestations covering the four domain lines
In practical terms, this means the biggest thing a prospective candidate can do to move toward certification is simple but not easy: get assigned to IT examinations, track them carefully, and make sure supervisors are documenting competency as they go rather than trying to reconstruct that record later. Our detailed walkthrough of ACISE requirements covers how to structure that documentation, and our ACISE Study Guide ties preparation directly to these eligibility mechanics rather than to generic test-day tactics.
Approved Training Routes
ACISE doesn't require candidates to prepare in isolation. There are recognized training pathways designed specifically to build the technical and regulatory grounding the domains require:
- CSBS IT Examiner School - training built directly around the state examiner track
- FDIC Information Technology Examination Course - a federally-run alternative that satisfies the same training expectation
- An accepted equivalent - for examiners whose employer or state agency has arranged comparable instruction
Choosing between these usually comes down to what your employing agency has access to and which schedule fits your examination assignments. What matters for certification purposes is that the training is completed and documented - not which specific course delivered it. Our ACISE Training resource breaks down how these routes compare and what to look for when confirming a course counts as an accepted equivalent.
Recertification and Continuing Education
Certification isn't a one-time achievement. ACISE holders must recertify by completing 63 continuing education hours every three years. Examiners who exceed that requirement in a given cycle aren't penalized for it - up to 14 excess hours can be carried forward into the next three-year cycle, which gives some flexibility to examiners who complete extra training during a particularly active year.
Recertification also requires continuing IT examination participation or oversight. In other words, continuing education alone isn't enough - certified examiners need to stay actively engaged in the examination work itself, whether by conducting exams directly or overseeing others who do. This keeps the credential tied to current, practical skill rather than a credential earned once and never revisited.
| Requirement | What It Involves |
|---|---|
| Qualifying examinations | Nine IS/IT/cybersecurity examinations within three years |
| Training | CSBS IT Examiner School, FDIC ITEC, or accepted equivalent |
| Attestation | Supervisor-affirmed competency across all four domain lines |
| Recertification cycle | 63 continuing education hours every three years |
| Excess CE carryover | Up to 14 hours applied to the next cycle |
| Ongoing activity | Continuing IT examination participation or oversight |
Who Earns ACISE and Why
ACISE is aimed at examiners working within, or alongside, state banking supervision - people whose job already involves evaluating IT risk at financial institutions. That includes state bank examiners specializing in technology and cybersecurity review, as well as examiners who move between safety-and-soundness work and dedicated IT examination assignments. Holding the credential signals to supervisors, hiring committees, and institutions under examination that the examiner has met a defined bar for experience, training, and demonstrated competency across all four domain lines.
Because the credential is tied so directly to a specific professional track, candidates considering it should think carefully about fit. If you're weighing whether the investment of time - accumulating qualifying examinations, completing training, gathering attestations, and maintaining continuing education - makes sense for your career path, our analysis on whether ACISE certification is worth it and our ACISE salary guide are good starting points. For a sense of where certified examiners work and what roles typically request the credential, see ACISE Jobs.
How to Prepare for the Competency Assessment
Because ACISE doesn't work like a standard certification exam, "studying" for it looks different too. There's no single test date to cram for. Instead, preparation is really about building competency deliberately and documenting it as you go, so that by the time your record is reviewed, the evidence is already organized.
Build the Examination Record
- Seek assignment to IT/cybersecurity examinations that count toward the nine-exam requirement
- Keep a running log of each examination, its scope, and your specific contributions
Complete Formal Training
- Enroll in CSBS IT Examiner School, the FDIC course, or a confirmed equivalent
- Save certificates and course outlines as documentation
Strengthen Weak Domains
- Use scenario review to reinforce Technical and Legal/Compliance knowledge, since these tend to require the most sustained study
- Practice writing exam findings to build Communications competency
Secure Attestations
- Discuss competency evidence with supervisors before the attestation is due
- Address any documented gaps in a domain proactively
If you want to pressure-test your understanding of the domain material itself - the Technical, Conceptual, Legal/Compliance, and Communications concepts examiners are expected to apply in the field - working through structured scenario questions on our ACISE practice platform is a practical way to check comprehension before your competency is reviewed. It won't replace supervised examination experience, but it can sharpen the conceptual and legal/compliance knowledge that underpins good field performance. For candidates who want a condensed reference while they work, the ACISE Cheat Sheet summarizes must-know facts in one page, and our notes on what the ACISE data shows and ACISE certification cost are worth reviewing before you commit time to the process.
Frequently Asked Questions
No. ACISE is a competency- and experience-assessed certification. The four domain lines are competency categories evaluated through examination participation, training, and supervisor attestation rather than through a scored, timed test.
Candidates need nine qualifying IS/IT/cybersecurity examinations completed within a three-year window, along with appropriate training and supervisor-affirmed competency attestations.
Accepted routes include the CSBS IT Examiner School, the FDIC Information Technology Examination Course, or another accepted equivalent training program.
Recertification requires 63 continuing education hours every three years, with up to 14 excess hours eligible to carry forward into the next cycle, plus ongoing participation in or oversight of IT examinations.
Technical, Conceptual, Legal/Compliance, and Communications - competency categories used to assess an examiner's demonstrated skill rather than sections of a timed exam.
Understanding ACISE for what it actually is - a competency-based credential built around real examination experience, structured training, and documented attestation - is the foundation for preparing effectively. From here, exploring the domain guide and reviewing practice scenarios on the ACISE practice site are reasonable next steps toward building a certification-ready record.