AIGP is the first professional certification built specifically for the people responsible for governing AI. It validates that a professional understands what AI governance is, how existing and new laws and standards apply to AI, and how to govern AI across its development, deployment, and ongoing use.
The Artificial Intelligence Governance Professional (AIGP) credential is issued by the IAPP (International Association of Privacy Professionals). It is designed for professionals who develop, integrate, deploy, or oversee AI systems and AI governance programs, and who need a shared, vendor-neutral foundation across law, risk, ethics, and technical practice.
The exam is built on the AIGP Body of Knowledge and Exam Blueprint. As of version 2.0.1 (effective 3 February 2025), the Body of Knowledge is organized into four domains, weighted by the number of scored questions drawn from each.
Inside This Module — The Four Domains
Domain I16 to 20 scored questions%
Understanding the Foundations of AI Governance
What AI governance is, including the common principles and pillars used to build an AI governance program that works regardless of industry, sector, or size.
- Generally accepted definitions and types of AI, and the risks and harms AI can pose to individuals, groups, organizations, and society
- The unique characteristics of AI that require governance: complexity, opacity, autonomy, speed and scale, potential for harm, data dependency, and probabilistic outputs
- Common principles of responsible AI: fairness, safety and reliability, privacy and security, transparency and explainability, accountability, and human-centricity
- Establishing roles, responsibilities, cross-functional collaboration, and training and awareness for AI governance
- Differences among AI developers, deployers, and users from a governance perspective
- Policies and procedures across the AI life cycle, including data privacy and security updates and third-party (procurement, supply chain) risk
Domain II19 to 23 scored questions%
Understanding How Laws, Standards and Frameworks Apply to AI
Existing laws that apply to AI, plus the new AI-specific laws, standards, and frameworks shaping the field.
- How existing data privacy laws apply to AI: notice, choice, consent and purpose limitation; data minimization and privacy by design; data controller obligations; and sensitive or special categories of data such as biometrics
- How other existing laws apply to AI: intellectual property, non-discrimination, consumer protection, and product liability
- The main elements of the EU AI Act: the risk classification framework (prohibited, high-risk, limited-risk, minimal-risk), high-risk requirements, general-purpose AI models, enforcement and penalties, and the roles of providers, deployers, importers, and distributors
- The main industry standards and tools: the OECD AI principles, the NIST AI Risk Management Framework and Playbook, the NIST ARIA program, and the core ISO AI standards (ISO/IEC 22989 and ISO/IEC 42001)
Domain III21 to 25 scored questions%
Understanding How to Govern AI Development
The responsibilities of AI governance professionals for designing, building, training, testing, and maintaining AI models.
- Govern the designing and building of the model: business context and use case, impact assessments, applicable laws, ethical considerations, human oversight, and identifying and managing internal and external risks
- Govern the collection and use of data in training and testing: data governance requirements, data quality and fit-for-purpose, data lineage and provenance, and managing issues and risks during training and testing
- Govern the release, monitoring, and maintenance of the model: readiness and conformity (model cards), continuous monitoring and retraining, periodic audits, red teaming and security testing, incident management, and public transparency disclosures
Domain IV21 to 25 scored questions%
Understanding How to Govern AI Deployment and Use
Responsibilities for selecting an AI model, then deploying and using it responsibly through ongoing monitoring, maintenance, and other obligations, whether the model is proprietary or from a third party.
- Evaluate the key factors and risks in the decision to deploy: use-case context, differences in AI model types (classic vs generative, proprietary vs open source, small vs large, language vs multimodal), and deployment options (cloud vs on-premise vs edge, fine-tuning, retrieval-augmented generation)
- Assess the model before deployment: impact assessment, applicable laws, vendor or open-source agreement terms, and the added obligations and liability of deploying a proprietary model
- Govern deployment and use: apply policies and controls, continuous monitoring and retraining, periodic audits and red teaming, incident documentation and post-market monitoring, forecasting secondary and downstream harms, external communication plans, and the ability to deactivate or localize a model when required
Core Concepts You'll Master
AIGP is less about a single technology and more about a way of thinking: how to place any AI system inside a defensible governance program, map the laws and standards that apply, and manage risk across the model's full life cycle from design to deployment to retirement.
Governance
Master the responsible-AI principles (fairness, safety and reliability, privacy and security, transparency and explainability, accountability, human-centricity), and how governance responsibilities differ for developers, deployers, and users of AI.
Risk Management
Be fluent in AI impact assessments, bias and harm identification, human oversight, third-party and vendor risk, and the difference between deploying an open-source model versus building your own.
Frameworks
Know the core frameworks cold: the EU AI Act's risk tiers and high-risk requirements, the NIST AI Risk Management Framework and Playbook, the OECD AI principles, and the ISO/IEC 22989 and 42001 standards.
Security Leadership
Understand how to stand up an AI governance program: roles and responsibilities, cross-functional collaboration, policies across the life cycle, training and awareness, and incident and post-market monitoring.
Exam at a Glance
| Questions | 100 |
| Duration | 2 hours 45 minutes, plus a 15-minute break |
| Format | Multiple choice |
| Passing score | Scored on a 100 to 500 scale; 300 is passing |
| Experience required | No formal prerequisites. IAPP recommends prior experience in AI, privacy, data governance, or compliance. |
Download the AIGP Reference & Study Guide
Volume I — the full exam-at-a-glance, all four domains, and the study essentials, in one branded PDF.
Get the PDF →
Get notified when new Academy modules launch
New certification modules, study resources, and GRC career guides — the moment they're ready.
Unsubscribe anytime, one click. We never share your details.
Where AIGP Takes You
- AI Governance Manager / Lead — Builds and runs the AI governance program across legal, risk, data, and engineering.
- Responsible AI Manager — Operationalizes responsible-AI principles into policy, review, and controls.
- AI Risk / Model Risk Manager — Assesses and manages AI risk across the model life cycle.
- Privacy or Compliance leader expanding into AI — AIGP is the natural bridge from privacy, GRC, or audit into AI oversight.
- AI Policy / Regulatory Analyst — Tracks and interprets the EU AI Act, NIST, ISO, and emerging AI law.
AIGP validates AI-governance knowledge; it does not by itself qualify anyone for a role. Hiring managers still weigh experience, judgment, and domain depth.
AIGP, the Artificial Intelligence Governance Professional credential, and IAPP are trademarks of the International Association of Privacy Professionals. GRC Careers is not affiliated with, endorsed by, or sponsored by IAPP.
Domain structure, weights, competencies, and performance indicators verified 2026-08-06 against IAPP's official AIGP Body of Knowledge and Exam Blueprint, version 2.0.1, effective 3 February 2025. Exam format, fees, scoring, and maintenance verified against IAPP published sources on 2026-08-06. Confirm current fees on the IAPP store before registering.
This is an original GRC Careers Academy module. It contains no real exam questions.