The blueprint

Every question traces to a line in the Body of Knowledge.

Each competency (left) branches into its performance indicators (middle), which link to the concepts here that teach them (right). The domain and competency structure follows IAPP's publicly published AIGP Body of Knowledge v2.1; the performance-indicator wording has been independently written by Vantage, not copied verbatim, to minimize reproduction of IAPP's own text — see Legal & Disclaimers for the full statement. 0 of 58 indicators have no concept yet; those show as an open branch instead of pretending coverage exists.

Domain I · Understanding the Foundations of AI Governance
I.AGrasp the core definition of AI and the reasons it calls for governance.
Recognize widely used definitions of AI and the main categories it falls into.
Recognize the categories of risk and harm AI can create for people, groups, organizations and society at large (for example, objectives that drift from intent, ethical and bias concerns, and risks tied to complexity and scale).
Recognize the traits that set AI apart and demand a holistic governance approach (for example, its complexity, opacity, autonomy, speed and scale, potential for harm or misuse, reliance on data, and probabilistic rather than deterministic behavior).
Recognize and put into practice the widely shared principles of responsible AI (for example, fairness, safety and reliability, privacy and security, transparency and explainability, accountability, and keeping people at the center).
I.BSet and share the organization's expectations for how AI will be governed.
Assign clear roles and responsibilities to everyone involved in AI governance.
Build cross-functional collaboration into the AI governance program (for example, to bring in a wider range of expertise and perspective and make the program more effective).
Build and roll out a training and awareness program that brings every stakeholder up to speed on AI terminology, strategy and governance.
Tailor the governance approach to the organization's size, maturity, industry, products and services, objectives and appetite for risk.
Distinguish how governance responsibilities, opportunities and needs differ across AI developers, providers, deployers and end users.
I.CPut policies and procedures in place that hold across the full AI life cycle.
Write and roll out policies that keep every stage of the AI life cycle overseen and accountable (for example, use-case assessment, risk management, ethics-by-design, data acquisition and use, model and system development, training and testing, deployment and monitoring, documentation and reporting, and incident management).
Review and refresh existing policies — data privacy, security, data governance, intellectual property and the like — so they account for AI.
Develop and maintain the policies, assessments and contract terms that manage third-party risk (for example, procurement, supply chain, HR and acceptable-use concerns).
Domain II · Understanding How Laws, Standards and Frameworks Apply to AI
II.AUnderstand how AI intersects with data privacy law as it already stands.
Understand how requirements around transparency, choice, lawful basis and purpose limitation carry over to AI.
Understand how data-minimization and privacy-by-design obligations apply when building or using AI.
Understand how a data controller's obligations extend to AI (for example, privacy impact assessments, engaging third-party processors, cross-border transfers, data-subject rights, automated decision-making, incident management, breach notification and record-keeping).
Understand the heightened requirements that attach to sensitive or special categories of data (biometric data, for instance).
Understand how intellectual property law bears on AI (for example, restrictions on using certain data to train a model).
II.BUnderstand how other bodies of existing law reach AI.
Understand how nondiscrimination law applies to AI (for example, in employment, credit, lending, housing and insurance decisions).
Understand how consumer-protection law constrains AI (for example, by prohibiting unfair or deceptive practices).
Understand how product-liability law applies to AI (for example, defects in design or manufacture).
II.CUnderstand the core building blocks of laws written specifically for AI.
Understand how AI-specific laws classify systems by risk tier (such as prohibited, high, limited and minimal) and which uses fall into each.
Understand the core obligations around risk management, data governance, technical documentation, conformity or impact assessments, and record-keeping.
Understand the core obligations around human oversight, transparency and notification, and quality management.
Understand the separate rules that apply specifically to general-purpose AI models.
Understand how these laws are enforced and what penalties noncompliance can bring.
Understand how obligations differ depending on an organization's role (provider, deployer, importer or distributor).
II.DUnderstand the leading industry standards and frameworks that apply to AI.
Understand the OECD's principles, framework and recommended practices for trustworthy AI.
Understand the structure of NIST's AI Risk Management Framework and its companion Playbook (its core functions and their categories/subcategories).
Understand the core ISO standards for AI (22989, 42001 and 42005).
Domain III · Understanding How to Govern AI Development
III.AApply governance to how an AI system is designed and built.
Establish the business context and intended use case for the AI system.
Carry out, or review, an impact assessment of the AI system.
Put policies, procedures, best practices and ethical considerations into the design-and-build process (for example, defining the AI's purpose, gathering requirements, choosing architecture and model, human oversight, data analysis, setting metrics and thresholds, stakeholder engagement and feedback, and operational controls).
Surface and manage the internal and external risk factors that arise while building the model and system (for example, a probability/severity harms matrix, a risk-mitigation hierarchy, stakeholder mapping, use-case evaluation, benchmarking, and pre-deployment pilots and testing).
Keep a record of the design-and-build process, to support compliance and risk management.
III.BApply governance to the data used to train and test the AI model and system.
Put data-governance requirements in place and follow them (for example, confirming and recording the lawful basis for collecting and using data, and assessing its quality, quantity, integrity and fitness for purpose).
Track and record where the data came from and how it has moved and changed (its lineage and provenance).
Plan and run the training and testing program for the model and system (unit, integration, validation, performance, security, bias and interpretability testing, among others).
Surface and manage the issues and risks that come up while training and testing the model and system.
Keep a record of the training-and-testing process, to validate results, support compliance and manage risk.
III.CApply governance to releasing, monitoring and maintaining the AI system.
Assess whether the system is ready for production and prepare its release (for example, producing a model card and meeting conformity requirements).
Monitor the AI system on an ongoing basis and set a regular cadence for maintenance, updates and retraining.
Run periodic checks on the system's performance, reliability and safety (audits, red-teaming, threat modeling and security testing, for example).
Manage incidents, issues and risks as they arise, and keep a record of them.
Work with stakeholders across the organization to understand why AI incidents happen (for example, brittleness, insufficient robustness, poor data quality, inadequate testing, or model/data drift).
Meet public transparency obligations through appropriate disclosures (for example, technical documentation, instructions for deployers, and post-market monitoring plans).
Domain IV · Understanding How to Govern AI Deployment and Use
IV.AWeigh the key factors and risks that bear on the decision to deploy an AI system.
Understand the context surrounding the AI use case (business objectives, performance requirements, data availability, ethical considerations and workforce readiness, among others).
Understand how AI model types differ (classic versus generative, proprietary versus open source, small versus large, and language-only versus multimodal).
Understand the range of deployment options available (cloud, on-premise or edge; and using a model as-is or adapting it via fine-tuning, retrieval-augmented generation, agentic architectures or other techniques).
IV.BCarry out the key activities involved in assessing an AI system.
Carry out, or review, an impact assessment of the AI system under consideration.
Review the vendor or licensing agreement for its key terms and risks.
Understand the risks and opportunities specific to deploying a company's own proprietary model (for example, heavier obligations and greater potential liability).
IV.CApply governance to how the AI system is deployed and used.
Put policies, procedures, best practices and ethical considerations into the deployment process (for example, data governance, risk management, issue management and user training).
Monitor the deployed model and system on an ongoing basis, with a regular cadence for maintenance, updates and retraining.
Run periodic checks on the system's performance, reliability and safety (audits, red-teaming, threat modeling and security testing, for example).
Keep a record of incidents, issues, risks and the post-market monitoring plan.
Anticipate and mitigate the risk of secondary, unintended uses and the downstream harms they could cause.
Put a plan in place for communicating externally when needed.
Build a policy and the controls needed to deactivate or roll back an AI system when necessary (for example, due to regulatory requirements or performance problems).