The AIGP (Artificial Intelligence Governance Professional) is the IAPP’s certification for people who govern how AI is built and used. The exam has 100 multiple-choice questions (85 of them scored) in 2 hours 45 minutes, you need 300 on IAPP’s 100 to 500 scale to pass, and it costs $649 for IAPP members or $799 for non-members. There are no prerequisites.
This AIGP study guide walks through the four domains of IAPP’s current body of knowledge (version 2.1, in effect since February 2, 2026), the laws and frameworks it actually names, and a study plan built on IAPP’s own preparation advice. Exam facts come from IAPP’s published materials and are labeled as such; the study advice is ours.
AIGP at a glance
| Credential | Artificial Intelligence Governance Professional (AIGP) |
| Certifying body | IAPP |
| Exam fee | $649 for IAPP members, $799 for non-members |
| Retakes | $475 for members, $625 for non-members (IAPP’s AIGP candidate handbook) |
| Questions | 100 multiple choice: 85 scored, 15 unscored |
| Time | 2 hours 45 minutes, plus a 15-minute break |
| Passing score | 300 on a scale of 100 to 500 |
| Delivery | Pearson VUE test center, or online through Pearson VUE’s OnVUE |
| Prerequisites | None |
| Training | Optional. IAPP sells online, live online and in-person AIGP training, but you can buy the exam without it |
| Deadline | Schedule and take the exam within one year of purchase |
| Body of knowledge | Version 2.1, effective February 2, 2026 |
| Results | Immediately after the exam, with a breakdown by section |
| Renewal | Every 2 years: 20 continuing education credits tied to the AIGP body of knowledge, plus a $250 maintenance fee per term for non-members (the first is included in the exam price; members’ fees are covered by membership) |
Checked against IAPP’s AIGP certification page, AIGP exam store page, certification FAQs, AIGP body of knowledge v2.1 and AIGP candidate handbook on October 6, 2026.
Who the AIGP is for
IAPP says anyone responsible for adopting or managing AI in an organization will benefit from the AIGP, so it isn’t only for lawyers. Its candidate handbook lists AI compliance, risk management, legal and governance, data scientists, AI project managers, model ops teams, social scientists and trust professionals as the people it fits best.
You don’t need a technical background, but you do need to be comfortable with how AI systems are built, tested and deployed, because half the exam is about governing that work. If you already hold an ISACA audit, risk or security credential, compare the AIGP with ISACA’s advanced AI certifications in our AI governance certifications guide before you choose.
What changed in the 2026 body of knowledge
IAPP’s body of knowledge (BoK) version 2.1 took effect on February 2, 2026 and replaced version 2.0.1. IAPP’s AIGP page says the update adds coverage of AI legislation beyond the EU AI Act, uses “system” terminology throughout the relevant sections, and adds examples to the performance indicators.
Two practical consequences. First, check the BoK version on any prep material you buy, because older guides were written for the earlier outline. Second, the BoK is reviewed every year, and IAPP says changes are announced at least 90 days before new content appears on the exam, so download the current PDF from IAPP rather than relying on a copy someone shared.
The four AIGP domains at a glance
The BoK is organized into four domains. Each one lists competencies (broad knowledge areas) and performance indicators (the specific tasks you should be able to do), and the exam blueprint gives the minimum and maximum number of questions from each domain.
| Domain (IAPP’s published BoK) | What it covers | Questions (range) |
|---|---|---|
| I. Understanding the foundations of AI governance | What AI is, why it needs governance, roles, policies across the life cycle | 16–20 |
| II. Understanding how laws, standards and frameworks apply to AI | Privacy and other existing laws, AI-specific laws, OECD, NIST and ISO | 19–23 |
| III. Understanding how to govern AI development | Design, data, training, testing, release and monitoring | 21–25 |
| IV. Understanding how to govern AI deployment and use | Deciding to deploy, assessing the system, governing it in use | 21–25 |
Domains III and IV together account for 42 to 50 questions on IAPP’s ranges, so the exam leans toward governing real AI work rather than reciting definitions. The single biggest competency in the whole BoK is IV.C, governing the deployment and use of an AI system, at 9 to 11 questions.
On question style, the BoK says IAPP questions mostly sit at the remember/understand and apply/analyze levels of Bloom’s taxonomy, and the verb that starts each performance indicator (identify, evaluate, implement, define) signals how deep the questions go. IAPP’s candidate handbook says some questions are tied to case studies, and IAPP’s February 2026 free study guide includes a sample multi-select item (choose 3 of 5, no partial credit), so practice reading every option carefully.
Domain I: Understanding the foundations of AI governance (16–20 questions)
What the BoK lists:
- I.A Understand what AI is and why it needs governance (4–6): generally accepted definitions and types of AI; risks and harms to individuals, groups, organizations and society; the traits that make AI need its own governance, such as complexity, opacity, autonomy, speed and scale, data dependency and probabilistic outputs; and the common principles of responsible AI (fairness, safety and reliability, privacy and security, transparency and explainability, accountability, human-centricity).
- I.B Establish and communicate organizational expectations (5–7): roles and responsibilities, cross-functional collaboration, a training and awareness program, tailoring governance to company size, maturity, industry and risk tolerance, and the differences among AI developers, providers, deployers and users.
- I.C Establish policies and procedures across the AI life cycle (6–8): oversight policies from use-case assessment through incident management, updating existing privacy, security, data governance and intellectual property policies for AI, and managing third-party risk through policies, assessments and contracts.
How to study it: learn the responsible AI principles well enough to apply them to a scenario, not just list them. Be precise about developers, providers, deployers and users: the BoK notes that many organizations fill more than one role, and later domains build on the distinction. To see what these ideas look like inside a real company, read our guides to a lightweight AI council, an AI acceptable-use policy and an AI governance operating model for mid-size IT.
Domain II: Understanding how laws, standards and frameworks apply to AI (19–23 questions)
What the BoK lists:
- II.A How existing data privacy laws apply to AI (4–6): transparency, choice, lawful basis and purpose limitation; data minimization and privacy by design; controller obligations such as privacy impact assessments, third-party processors, cross-border transfers, data subject rights, automated decision-making, breach notification and record keeping; sensitive or special categories of data such as biometrics; and how intellectual property law can limit the use of data for training.
- II.B How other existing laws apply to AI (4–6): nondiscrimination law (employment, credit, lending, housing and insurance), consumer protection (unfair and deceptive practices) and product liability (design and manufacturing defects).
- II.C The main elements of AI-specific laws (6–8): risk classification (prohibited, high, limited and minimal risk), requirements for risk management, data governance, technical documentation, conformity and impact assessments, record keeping, human oversight, transparency and quality management, distinct rules for general-purpose AI models, enforcement and penalties, and how obligations differ for providers, deployers, importers and distributors.
- II.D The main industry standards and tools (3–5): the OECD principles for trustworthy AI, the NIST AI Risk Management Framework and Playbook, and the core ISO AI standards (22989, 42001 and 42005).
How to study it: build a one-page map of the EU AI Act covering its risk tiers, the roles it assigns, its general-purpose AI rules and its penalties, because II.C is written around exactly those categories. Then add the other laws the BoK names (see the next section) at a higher level. For privacy, the BoK describes obligations by concept rather than by statute, so practice explaining how each concept changes when the data feeds a model. If you work in the US, our guide to mapping SOX and state privacy obligations before an AI pilot is a useful worked example.
Laws and frameworks the AIGP BoK names
Searchers often ask whether the AIGP covers the EU AI Act, NIST or ISO 42001. Here is everything the version 2.1 BoK names, and where. If a law or framework is not in this table, the BoK does not name it.
| Law or framework | Where the BoK names it | What to know |
|---|---|---|
| EU AI Act | Domain II introduction, as an example of a current AI law | Its risk tiers, roles, general-purpose AI rules and penalties line up with the II.C performance indicators |
| South Korean AI Basic Law | Domain II introduction | Named alongside the EU AI Act; IAPP’s 2026 update added AI legislation beyond the EU AI Act |
| Federal and state AI laws for private-sector organizations | Domain II introduction | Named as a category, with no specific statute listed |
| Existing privacy, nondiscrimination, consumer protection, product liability and IP laws | II.A and II.B | Described by concept (lawful basis, data subject rights, unfair and deceptive practices and so on) rather than by statute |
| OECD principles for trustworthy AI | II.D | The principles, framework, policies and recommended practices |
| NIST AI Risk Management Framework and Playbook | II.D | Core functions, categories and subcategories. NIST names the four functions Govern, Map, Measure and Manage |
| ISO/IEC 22989, 42001 and 42005 | II.D | AI concepts and terminology, AI management systems, and AI system impact assessment |
Treat the BoK’s “e.g.” lists as examples, not limits: IAPP notes that questions may come from any topic listed under each area.
Domain III: Understanding how to govern AI development (21–25 questions)
What the BoK lists:
- III.A Govern the designing and building of the AI system (6–8): defining the business context and use case, performing or reviewing an impact assessment, applying policies and ethics to design choices (requirements, architecture and model selection, human oversight, metrics and thresholds, stakeholder engagement), managing design risks with tools such as a probability and severity harms matrix, a risk mitigation hierarchy, stakeholder mapping, benchmarking and pre-deployment pilots, and documenting the process.
- III.B Govern data in training and testing (6–8): data governance requirements (lawful rights to collect and use data, and data quality, quantity, integrity and fitness for purpose), data lineage and provenance, planning training and testing (unit, integration, validation, performance, security, bias and interpretability), managing issues found in testing, and documenting results.
- III.C Govern release, monitoring and maintenance (8–10): release readiness (including the model card and conformity requirements), continuous monitoring with a schedule for maintenance and retraining, audits, red teaming, threat modeling and security testing, managing incidents, understanding why AI incidents happen (brittleness, lack of robustness, poor data, insufficient testing, model or data drift), and public disclosures such as technical documentation, instructions for use and post-market monitoring plans.
How to study it: pick one example AI system and walk it through the life cycle, writing the artifact a governance lead would expect at each step: a use-case statement, an impact assessment, a data lineage note, a test plan, a model card and a monitoring plan. III.C carries the most questions in this domain, so make sure you can explain what triggers retraining and what belongs in a post-market monitoring plan. Our guide to building an AI inventory shows how organizations keep track of the systems they govern.
Domain IV: Understanding how to govern AI deployment and use (21–25 questions)
What the BoK lists:
- IV.A Evaluate key factors and risks in the decision to deploy (6–8): the context of the use case (business objectives, performance requirements, data availability, ethical considerations, workforce readiness), the differences between model types (classic or generative, proprietary or open source, small or large, language or multimodal), and deployment options (cloud, on-premise or edge, and using a model as is or with fine-tuning, retrieval augmented generation or agentic architectures).
- IV.B Perform key activities to assess the AI system (5–7): an impact assessment on the selected system, the key terms and risks in vendor or licensing agreements, and the extra obligations and liability that come with deploying your own proprietary model.
- IV.C Govern the deployment and use of the AI system (9–11): applying policies (data governance, risk management, issue management, user training), continuous monitoring, audits and red teaming, documenting incidents and post-market monitoring plans, forecasting secondary or unintended uses and downstream harms, external communication plans, and a policy and controls to deactivate or localize a system when needed.
How to study it: this domain applies whether a company deploys its own model or one from a vendor, so practice both. Read a real AI vendor agreement and list the terms that shift risk to you. You don’t need to build a retrieval or agent system, but you should be able to say what each deployment choice changes for governance. Our posts on vendor security review questions and shadow AI policy cover two situations the IV.C indicators describe.
A study plan for the AIGP
IAPP recommends at least 30 hours of study before your exam and suggests preparing in this order: review the body of knowledge, consider certification training, take the AIGP practice exam, then buy and schedule the exam.
Is IAPP training required? No. The AIGP has no prerequisites, and IAPP’s FAQ describes training as one step you can take, adding that courses are not purely test prep and don’t guarantee a pass. IAPP’s handbook also notes that the training and the exam are developed separately, by different groups of subject matter experts. Training suits you if you learn best with an instructor or your employer is paying. If not, you can prepare from the BoK, IAPP’s free study guide and its practice exam.
IAPP’s official AIGP resources:
- AIGP body of knowledge and exam blueprint (free): your checklist. IAPP calls it the main guide to what the exam covers.
- Free AIGP study guide: IAPP’s February 2026 edition, with the BoK outline, exam format and sample questions.
- AIGP practice exam: 100 questions in the same format as the real exam, with answers and explanations, sold in the IAPP store for $50 (members) or $60 (non-members).
- AIGP training: self-paced online, live online, in-person and group options.
- AIGP candidate handbook: scoring, scheduling, retake and certification rules.
A five-week plan (about 33 hours): this is our suggested pacing, built around IAPP’s 30-hour minimum and the domain weights. Stretch it if AI law is new to you.
| Week | Focus | Hours |
|---|---|---|
| 1 | Read the whole BoK once, then work through Domain I | 6 |
| 2 | Domain II.A and II.B: privacy and other existing laws | 6 |
| 3 | Domain II.C and II.D: AI-specific laws, OECD, NIST AI RMF and the ISO standards | 7 |
| 4 | Domain III: governing AI development, start to finish | 7 |
| 5 | Domain IV, then the IAPP practice exam and a final pass on your weakest domain | 7 |
After the practice exam, go back to the BoK and mark every performance indicator you couldn’t explain in your own words. Those are your last study sessions.
Exam day
- Buy the exam in the IAPP store first, then schedule it with Pearson VUE at least 24 hours ahead. You can test at a center or online through OnVUE, which isn’t available in every country.
- Each question is worth one point, unanswered questions count as wrong, and there is no extra penalty for a wrong answer, so answer everything.
- You see your result as soon as you finish, along with your scaled score and how you did in each section of the blueprint.
Keeping the AIGP after you pass
The AIGP runs in two-year terms that start the day after you pass. To recertify, report 20 continuing education credits that match the AIGP BoK and keep your certification maintenance fee current. IAPP members have the fee covered by membership; non-members pay $250 per term, and IAPP’s store says the first term is included in the non-member exam price. If you earn extra credits in the last six months of a term, you can carry up to 10 into the next one.
Our guide to AI certification renewal rules compares the AIGP with other AI credentials, and the free renewal tracker keeps your dates in one place.
AIGP vs other AI governance credentials
| Credential | Prerequisite | Exam fee | Exam | Renewal |
|---|---|---|---|---|
| IAPP AIGP | None | $649 members, $799 non-members | 100 questions (85 scored), 2 hours 45 minutes | 20 credits every 2 years |
| ISACA AAIA (AI audit) | Active CISA, or CIA, CPA or similar with an IT audit or advisory focus | $459 members, $599 non-members, plus $50 application fee | 90 questions, 2.5 hours | 10 CPE hours a year |
| ISACA AAISM (AI security management) | Active CISM or CISSP | $459 members, $599 non-members, plus $50 application fee | 90 questions, 2.5 hours | 10 CPE hours a year |
| PMI-CPMAI (managing AI projects) | Complete PMI’s required prep course | $899, or $699 for PMI members, course included | 120 questions (100 scored), 160 minutes | 30 PDUs every 3 years |
The AIGP is the only one of these with no prerequisite and a focus on law and policy. For the full field, including ISO/IEC 42001 credentials, see our AI governance certifications guide; if security is your focus, our AI security certifications guide covers that side. To see where the AIGP sits among every AI credential, browse the AI certification index or our ranking of the best AI certifications in 2026. Budgeting? The AI certification cost calculator adds up exam, training and renewal fees →
HOW TO // AI is not affiliated with or endorsed by the IAPP. AIGP and Artificial Intelligence Governance Professional are marks of the IAPP; we reference them descriptively. This guide is original and based on IAPP’s published body of knowledge and candidate materials. Check the official AIGP page before you buy.
Keep exploring: AAISM study guide · PMI-CPMAI study guide
Related guides
- AI Governance Certifications in 2026: Every Real Option Compared
- AAISM Study Guide: ISACA’s AI Security Management Exam, Domain by Domain
- PMI-CPMAI Study Guide: All 5 Exam Domains and the 6 CPMAI Phases
- AI Security Certifications in 2026: SecAI+, AAISM, GIAC and More
Frequently asked questions
How much does the AIGP certification cost?
The AIGP exam costs $649 for IAPP members and $799 for non-members. IAPP's candidate handbook lists retakes at $475 for members and $625 for non-members, and non-members pay a $250 maintenance fee for each two-year term after the first.
Is IAPP training required to take the AIGP exam?
No. The AIGP has no prerequisites, and IAPP's FAQ describes training as one step you can take rather than a requirement. IAPP recommends at least 30 hours of study and suggests reviewing the body of knowledge and taking its practice exam.
What is the AIGP passing score?
You need 300 on IAPP's scale of 100 to 500. IAPP notes that 300 does not represent 60 percent; it is a cut score set by an exam development board and psychometric analysis.
How many questions are on the AIGP exam?
There are 100 multiple-choice questions, of which 85 are scored and 15 are unscored. You get 2 hours 45 minutes plus a 15-minute break, at a Pearson VUE test center or online.
What are the AIGP domains?
IAPP's body of knowledge version 2.1 has four domains: foundations of AI governance (16 to 20 questions), how laws, standards and frameworks apply to AI (19 to 23), governing AI development (21 to 25) and governing AI deployment and use (21 to 25).
Does the AIGP cover the EU AI Act and NIST AI RMF?
Yes. The body of knowledge names the EU AI Act and the South Korean AI Basic Law as examples of AI laws, and lists the NIST AI Risk Management Framework and Playbook, the OECD principles and ISO/IEC 22989, 42001 and 42005 as standards and tools.
How long should I study for the AIGP?
IAPP recommends at least 30 hours of study for each of its certifications. Plan for more if AI law and privacy concepts are new to you.
Does the AIGP certification expire?
It runs in two-year terms. To recertify you report 20 continuing education credits tied to the AIGP body of knowledge and keep the certification maintenance fee paid, which IAPP membership covers.




