Skip to content

Artificial Intelligence Governance Professional (AIGP)

A knowledge-based certification covering AI governance foundations, the laws and standards that apply to AI, and how to govern AI development, deployment and ongoing use.

IAPP (International Association of Privacy Professionals)
Exam cost
$799 USD (non-member) / $649 USD (IAPP member). Retakes $625 / $475. Excludes the $250 certification maintenance fee per two-year term, waived by $295/year IAPP membership.
src
IAPP Store — AIGP Exam product page and Certification Maintenance Fee page (store.iapp.org)
chk
Duration
2 hours 45 minutes
Passing score
300 on a scaled 100-500 range (not a percentage) — 85 of the 100 questions are scored
Valid for
2 years, renewable with 20 CPE credits plus a maintenance fee or active membership

The AIGP is a governance credential. It tests whether you can navigate AI regulation, risk frameworks and life-cycle controls — not whether you can build, evaluate or secure a model. Read that sentence twice before you spend the money, because it is the whole decision.

Where the weights come from

The IAPP does not publish percentage weights. It publishes something better: the Body of Knowledge gives a minimum and maximum question count per domain. The percentages above are SkillPilot's arithmetic on the official blueprint — the midpoint of each range, expressed as a share of the total.

That arithmetic is unusually well-grounded. The midpoints are 18, 21, 23 and 23, summing to 85 — exactly the number of scored questions the IAPP's candidate handbook states. Treat the percentages as reliable for study planning, but cite the question ranges, not our percentages, if precision matters.

Your passing score is not a percentage

The exam is scaled 100–500, and 300 passes. This is not 60%. The scale maps raw correct answers onto a fixed range so that different exam forms are comparable, and the number of correct answers that lands on 300 varies. Fifteen of the 100 questions are unscored trial items you cannot identify. Do not budget your revision against "I need 60%" — you cannot know what the raw bar is.

The cost is not the exam fee

This is the part most write-ups get wrong. The exam is $799, or $649 as a member. Passing does not make you certified: the credential only becomes active once you hold IAPP membership or have paid a $250 certification maintenance fee, and that repeats every two-year term. You also owe 20 CPE credits per term, and letting either lapse suspends the credential and then revokes it.

Membership at $295/year covers the maintenance fee and cuts the exam price by $150, so buying membership first is usually cheaper than not. But be clear about what you are committing to: this is a subscription with an exam attached, not a one-off purchase. A failed first attempt is $625 non-member, $475 member.

Who should actually buy this

Worth it if AI governance is your job or is becoming it — privacy and compliance professionals extending into AI, risk and legal teams, engineers who have moved into policy work or who sit on an AI review board, consultants who need the credential on a proposal. In those roles the vocabulary is the product, and the AIGP supplies it faster than reading the AI Act alone would.

Skip it if you build systems. It will not make you a better ML engineer, it does not prove you can secure a model, and no hiring manager will read it as evidence that you can. If your interest is adversarial robustness, evaluation or model security, your money goes further elsewhere.

It is a young certification in a moving field

The AIGP launched in 2024 and the Body of Knowledge is already on version 2.1, restructured from seven domains to four. The IAPP reviews it annually and commits to 90 days' notice before new content appears. Regulation is moving faster than the syllabus, so verify the current BoK version yourself before you start studying — and expect the credential you renew in two years to test something different from the one you earn today.

Your progress0%

Exam domains

Understanding the foundations of AI governance

21%
Generally accepted definitions and types of AIRisks and harms posed by AI to individuals, groups, organizations and societyCommon principles of responsible AI — fairness, safety, privacy, transparency, accountabilityRoles and responsibilities of AI governance stakeholders, and cross-functional collaborationPolicies and procedures applied across every stage of the AI life cycleDifferences among AI developers, providers, deployers and users

Understanding how laws, standards and frameworks apply to AI

25%
How existing data privacy laws apply — lawful basis, purpose limitation, data minimization, DPIAsNondiscrimination, consumer protection and product liability laws applied to AIIntellectual property limits on the use of data for AI trainingThe EU AI Act risk classification — prohibited, high, limited and minimal riskRequirements for general-purpose AI models, enforcement and penaltiesThe OECD AI Principles, the NIST AI Risk Management Framework, and ISO/IEC 22989, 42001 and 42005

Understanding how to govern AI development

27%
Defining business context and performing impact assessments on an AI systemDesign and build governance — architecture and model selection, human oversight, operational controlsData governance, lawful rights to collect and use data, and data lineage and provenanceTraining and testing for performance, security, bias and interpretabilityRelease readiness, model cards and conformity requirementsContinuous monitoring, incident management, retraining and public transparency disclosures

Understanding how to govern AI deployment and use

27%
Evaluating model types — classic versus generative, proprietary versus open source, multimodalDeployment options — cloud, on-premise, edge, fine-tuning, RAG and agentic architecturesVendor and licensing agreement terms and risksApplying policies to deployment — risk, issue management and user trainingAudits, red teaming, threat modeling and security testing of deployed systemsForecasting secondary and downstream harms, and controls to deactivate an AI system

Preparation path

  1. 1

    Download the Body of Knowledge and read the blueprint numbers

    The BoK v2.1 is free, nine pages, and lists the minimum and maximum questions per domain. It is the exam's own specification. Read the performance indicators literally — the verbs (identify, understand, evaluate) tell you the depth each topic is tested at.

    ~4 hours
  2. 2

    Learn the vocabulary of AI governance before the law

    Domain I is definitions, principles and who is accountable for what. Get the developer/provider/deployer/user distinction straight first — it recurs throughout the legal domains, and every later question about obligations depends on correctly identifying which role you are in.

    ~10 hours
  3. 3

    Work through the EU AI Act by risk tier

    The Act is the single largest source of legal questions. Do not read it front to back. Learn the four risk tiers, what falls into each, and the specific obligations attached — then the general-purpose AI model rules, the enforcement regime and how duties differ by role.

    ~20 hours
  4. 4

    Learn the NIST AI RMF and the ISO standards by structure

    The blueprint names NIST's four core functions and ISO/IEC 22989, 42001 and 42005 explicitly. Questions test structure and purpose, not clause detail — know what Govern, Map, Measure and Manage each cover, and which ISO standard does terminology, management systems and impact assessment.

    ~12 hours
  5. 5

    Map the development and deployment domains onto real systems

    Domains III and IV are 54% of the exam and are the most practical part of it. Take an AI system you know and walk it end to end: impact assessment, data provenance, testing, model card, release, monitoring, incident handling and deactivation. Abstract memorisation fails here.

    ~18 hours
  6. 6

    Sort out the fees, then book

    Decide on membership before you buy the exam, not after. Membership cuts the exam fee and covers the maintenance fee, so it usually pays for itself on the first sitting. Then confirm the CPE obligation you are signing up to for as long as you keep the credential.

    ~3 hours

Frequently asked questions

Career Roadmaps