Know the exam before you study for it.
The AIGP (Artificial Intelligence Governance Professional) is the IAPP's certification for professionals who ensure AI is developed, deployed, and used responsibly and lawfully. The exam is not a memorization test: about a third of it drops you into realistic scenarios — a vendor claim, a biased model, a deployment decision — and asks what a governance professional should do. The content below follows the same domain and competency structure the official Body of Knowledge uses; each performance indicator is described in Vantage's own words and links to the concept(s) here that teach it — so you can see exactly what is and isn't covered yet.
Take a mock exam →Understanding the Foundations of AI Governance
Focuses on what AI governance is, including the common principles and pillars to build an AI governance program. This domain covers best practices regardless of industry, sector or size.
- Recognize widely used definitions of AI and the main categories it falls into.
- Recognize the categories of risk and harm AI can create for people, groups, organizations and society at large (for example, objectives that drift from intent, ethical and bias concerns, and risks tied to complexity and scale).
- Recognize the traits that set AI apart and demand a holistic governance approach (for example, its complexity, opacity, autonomy, speed and scale, potential for harm or misuse, reliance on data, and probabilistic rather than deterministic behavior).
- Recognize and put into practice the widely shared principles of responsible AI (for example, fairness, safety and reliability, privacy and security, transparency and explainability, accountability, and keeping people at the center).
- Assign clear roles and responsibilities to everyone involved in AI governance.
- Build cross-functional collaboration into the AI governance program (for example, to bring in a wider range of expertise and perspective and make the program more effective).
- Build and roll out a training and awareness program that brings every stakeholder up to speed on AI terminology, strategy and governance.
- Tailor the governance approach to the organization's size, maturity, industry, products and services, objectives and appetite for risk.
- Distinguish how governance responsibilities, opportunities and needs differ across AI developers, providers, deployers and end users.
- Write and roll out policies that keep every stage of the AI life cycle overseen and accountable (for example, use-case assessment, risk management, ethics-by-design, data acquisition and use, model and system development, training and testing, deployment and monitoring, documentation and reporting, and incident management).
- Review and refresh existing policies — data privacy, security, data governance, intellectual property and the like — so they account for AI.
- Develop and maintain the policies, assessments and contract terms that manage third-party risk (for example, procurement, supply chain, HR and acceptable-use concerns).
Understanding How Laws, Standards and Frameworks Apply to AI
Focuses on existing laws that apply to AI, as well as AI-specific laws, standards and frameworks. For the AI governance professional, this means an understanding of the major elements of current AI laws (e.g., the EU AI Act, the South Korean AI Basic Law, federal and state AI laws that apply to private sector organizations).
- Understand how requirements around transparency, choice, lawful basis and purpose limitation carry over to AI.
- Understand how data-minimization and privacy-by-design obligations apply when building or using AI.
- Understand how a data controller's obligations extend to AI (for example, privacy impact assessments, engaging third-party processors, cross-border transfers, data-subject rights, automated decision-making, incident management, breach notification and record-keeping).
- Understand the heightened requirements that attach to sensitive or special categories of data (biometric data, for instance).
- Understand how intellectual property law bears on AI (for example, restrictions on using certain data to train a model).
- Understand how nondiscrimination law applies to AI (for example, in employment, credit, lending, housing and insurance decisions).
- Understand how consumer-protection law constrains AI (for example, by prohibiting unfair or deceptive practices).
- Understand how product-liability law applies to AI (for example, defects in design or manufacture).
- Understand how AI-specific laws classify systems by risk tier (such as prohibited, high, limited and minimal) and which uses fall into each.
- Understand the core obligations around risk management, data governance, technical documentation, conformity or impact assessments, and record-keeping.
- Understand the core obligations around human oversight, transparency and notification, and quality management.
- Understand the separate rules that apply specifically to general-purpose AI models.
- Understand how these laws are enforced and what penalties noncompliance can bring.
- Understand how obligations differ depending on an organization's role (provider, deployer, importer or distributor).
- Understand the OECD's principles, framework and recommended practices for trustworthy AI.
- Understand the structure of NIST's AI Risk Management Framework and its companion Playbook (its core functions and their categories/subcategories).
- Understand the core ISO standards for AI (22989, 42001 and 42005).
Understanding How to Govern AI Development
Focuses on the responsibilities of AI governance professionals with respect to designing, building, training, testing and maintaining AI systems.
- Establish the business context and intended use case for the AI system.
- Carry out, or review, an impact assessment of the AI system.
- Put policies, procedures, best practices and ethical considerations into the design-and-build process (for example, defining the AI's purpose, gathering requirements, choosing architecture and model, human oversight, data analysis, setting metrics and thresholds, stakeholder engagement and feedback, and operational controls).
- Surface and manage the internal and external risk factors that arise while building the model and system (for example, a probability/severity harms matrix, a risk-mitigation hierarchy, stakeholder mapping, use-case evaluation, benchmarking, and pre-deployment pilots and testing).
- Keep a record of the design-and-build process, to support compliance and risk management.
- Put data-governance requirements in place and follow them (for example, confirming and recording the lawful basis for collecting and using data, and assessing its quality, quantity, integrity and fitness for purpose).
- Track and record where the data came from and how it has moved and changed (its lineage and provenance).
- Plan and run the training and testing program for the model and system (unit, integration, validation, performance, security, bias and interpretability testing, among others).
- Surface and manage the issues and risks that come up while training and testing the model and system.
- Keep a record of the training-and-testing process, to validate results, support compliance and manage risk.
- Assess whether the system is ready for production and prepare its release (for example, producing a model card and meeting conformity requirements).
- Monitor the AI system on an ongoing basis and set a regular cadence for maintenance, updates and retraining.
- Run periodic checks on the system's performance, reliability and safety (audits, red-teaming, threat modeling and security testing, for example).
- Manage incidents, issues and risks as they arise, and keep a record of them.
- Work with stakeholders across the organization to understand why AI incidents happen (for example, brittleness, insufficient robustness, poor data quality, inadequate testing, or model/data drift).
- Meet public transparency obligations through appropriate disclosures (for example, technical documentation, instructions for deployers, and post-market monitoring plans).
Understanding How to Govern AI Deployment and Use
Focuses on the responsibilities of AI governance professionals with respect to selecting an AI model, then deploying and using it responsibly through ongoing monitoring, maintenance, and other key obligations. This domain applies in any deployment context, such as a company deploying its own proprietary model or one from a third party.
- Understand the context surrounding the AI use case (business objectives, performance requirements, data availability, ethical considerations and workforce readiness, among others).
- Understand how AI model types differ (classic versus generative, proprietary versus open source, small versus large, and language-only versus multimodal).
- Understand the range of deployment options available (cloud, on-premise or edge; and using a model as-is or adapting it via fine-tuning, retrieval-augmented generation, agentic architectures or other techniques).
- Carry out, or review, an impact assessment of the AI system under consideration.
- Review the vendor or licensing agreement for its key terms and risks.
- Understand the risks and opportunities specific to deploying a company's own proprietary model (for example, heavier obligations and greater potential liability).
- Put policies, procedures, best practices and ethical considerations into the deployment process (for example, data governance, risk management, issue management and user training).
- Monitor the deployed model and system on an ongoing basis, with a regular cadence for maintenance, updates and retraining.
- Run periodic checks on the system's performance, reliability and safety (audits, red-teaming, threat modeling and security testing, for example).
- Keep a record of incidents, issues, risks and the post-market monitoring plan.
- Anticipate and mitigate the risk of secondary, unintended uses and the downstream harms they could cause.
- Put a plan in place for communicating externally when needed.
- Build a policy and the controls needed to deactivate or roll back an AI system when necessary (for example, due to regulatory requirements or performance problems).