The AIGP certification overview covers what the exam tests and who it is for. This guide goes a level deeper: what to actually study, in what order, which frameworks you need to know cold, and how to manage the exam itself.
AIGP rewards applied governance judgment over memorization. About 30 percent of the exam is tied to case studies, per IAPP. That changes how you should prepare. Reading the Body of Knowledge once is not enough; you need to be able to apply its concepts to a scenario you have never seen before.
Study in this order. It follows how the domains build on each other, not just their exam weight.
Start here even though it is not the largest domain. Every other domain assumes you already have this vocabulary: the principles of responsible AI, the difference between developers, deployers, and users, and why AI's opacity and probabilistic outputs demand governance that traditional IT risk programs do not need.
Once the foundations are solid, layer on the legal and regulatory landscape: the EU AI Act's risk tiers, the NIST AI RMF, ISO/IEC 42001, the OECD principles, and how existing privacy and consumer-protection law reaches AI. This domain is the most memorization-heavy of the four, and flashcards work well here.
Now apply Domains I and II to the build phase: impact assessments, data governance during training and testing, model cards, red teaming, and pre-release transparency disclosures.
Finish with the post-deployment side: vendor and third-party risk, ongoing monitoring, incident response, and the ability to deactivate or localize a model. Domains III and IV together make up roughly 54 percent of the exam, so budget the most review time here in the final week before your test.
What to master, beyond the definitions: be able to explain why AI needs its own governance discipline rather than reusing an existing IT-risk or privacy program. The exam tests this through AI's distinguishing traits, namely complexity, opacity, autonomy, speed and scale, data dependency, and probabilistic or non-deterministic output, and expects you to connect each trait to a specific governance control.
Also know the six commonly tested responsible-AI principles cold: fairness, safety and reliability, privacy and security, transparency and explainability, accountability, and human-centricity. Expect scenario questions that ask you to identify whether a described organization is acting as a developer, deployer, or user of a given AI system, since governance obligations shift depending on that role.
Common trap: confusing developer obligations with deployer obligations when a company both builds and uses its own model. The exam tests both roles separately even when one entity holds both.
This is the domain candidates most often underestimate. You need working fluency in:
Common trap: mixing up which EU AI Act obligations attach to providers versus deployers. The exam separates these deliberately.
Think life cycle, not checklist. The exam moves through design and build (business context, impact assessments, ethical considerations, human oversight) into training and testing (data governance, data lineage and provenance, quality and fit-for-purpose) and finally into release readiness (model cards, red teaming and security testing, periodic audits, public transparency disclosures). Be able to place any given governance activity, for example documenting data lineage, at the correct life-cycle stage.
Common trap: assuming testing only means model performance testing. The exam also folds bias, fairness, and security testing under the same stage.
Covers everything after a model ships: evaluating deployment options (cloud versus on-premise versus edge, fine-tuning versus retrieval-augmented generation), assessing a model before deployment (impact assessments, vendor or open-source license terms, added liability when deploying a proprietary third-party model), and governing it in production (continuous monitoring, incident documentation, post-market monitoring, forecasting downstream harms, and the ability to deactivate or localize a model when required).
Common trap: underestimating vendor and third-party risk. A large share of Domain IV questions concern AI systems the organization did not build itself.
No. The exam tests whether you can apply the risk tiers and obligations to a scenario, not cite article numbers.
Not harder, but it is applied. Candidates who only read the Body of Knowledge without practicing scenario judgment tend to underperform relative to their content knowledge.
There is no official recommendation. Candidates with existing privacy, risk, or compliance backgrounds typically need less time on Domain I; candidates newer to governance should budget the most time there before moving to Domains II to IV.
Domains III and IV, Governing AI Development and Governing AI Deployment and Use, are roughly 27 percent each, so together they are over half the exam. Budget the most review time for those two in your final week.
About 30 percent, per IAPP. That is why the exam rewards applied governance judgment rather than memorization alone, and why reading the Body of Knowledge once is not enough.
300 on a 100 to 500 scaled range. The scaled score is not a simple percentage of correct answers, so there is no point trying to reverse-engineer your standing mid-exam.
Domain weights, exam format, and framework names are sourced from IAPP's official AIGP Body of Knowledge and Exam Blueprint v2.0.1 (effective 3 February 2025). Confirm current fees, CPE requirements, and exam details at iapp.org before you register.