AIGP exam guide 2026 (Body of Knowledge v2.1)
The AIGP (Artificial Intelligence Governance Professional) is the IAPP's certification for professionals who govern AI systems. The current exam is built on Body of Knowledge v2.1, effective 2 February 2026, across four domains. It is 100 multiple-choice questions in 2.75 hours, scaled 100 to 500 with 300 to pass. The exam tests applied judgment, not memorized definitions: in most questions several answers look plausible and only one fits the responsible-AI governance approach the IAPP defines. Preparing well means studying the current BoK and practicing applied reasoning, not collecting question dumps.
What the AIGP is
The AIGP is the certification offered by the IAPP for professionals who work at the intersection of AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → and governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry →: how AI is built, deployed, and regulated responsibly. It is becoming the reference credential in AI governanceAI governanceGovernance extended for AI: the same organizational steering at the highest level, widened to cover what makes AI different (it works in probabilities rather than fixed rules, learns from data, and can act at a speed and scale no human reviewer can match). It inherits the existing governance structure and brings AI inside the disciplines the organization already runs, rather than creating a parallel system in a silo. It operates on two levels, design and execution. See governance, governance design, execution level, responsible AI.Open full entry → as the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → and comparable regimes make the discipline a board-level responsibility. The professionals organizations are hiring are the ones who can operationalize governance frameworks, not only describe them, which is exactly what the exam is designed to test.
Get the version right first
Before anything else, make sure you are preparing for the current exam. The Body of Knowledge was restructured from seven domains to four in February 2025, and updated to version 2.1 on 2 February 2026. Most study material online still references the old seven-domain structure or the previous version. If your materials do not reference v2.1, you are preparing for the wrong exam.
The v2.1 update is a recalibration, not an overhaul, but the shifts matter. The most visible change is terminological: "AI models" has been replaced by "AI systems" throughout, reflecting that governance reaches beyond the model to the whole system, its supply chainsupply chainThe layered chain behind an AI product (foundation models, datasets, labeling services, integrators), each layer adding risk the buyer never contracted for directly.Open full entry →, and its downstream uses. New performance indicators were added around agentic architectures, third-party riskthird-party riskRisk inherited through vendors and their supply chains. For AI this means invisible training-data defects, layered model dependencies and silent updates.Open full entry → management, and strengthened data governance. The BoK is a free download from iapp.org, and it is the single most important document to study from, because it is the exact blueprint the exam is built on.
The four domains
BoK v2.1 organizes the exam into four domains:
- Understanding the foundations of AI governance. Fundamental AI concepts and system types, the principlesprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → of responsible AIresponsible AIThe set of principles an AI system should live up to: fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, and human oversight. Widely shared and sitting under the EU AI Act and the major frameworks. On their own the principles are statements of intent; the law turns them into duties that cannot be met unless they are carried inside the organization's governance, which is how responsible AI lands in governance rather than beside it. The seven principles are organized into seven pillars, one pillar per principle. See principle, pillar, governance. The seventh principle carries two names in practice: human oversight in the seven-pillar model, and human-centricity in the IAPP AIGP body of knowledge; the substance overlaps.Open full entry →, how AI creates value and introduces riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry →, and the ethical dimensions. This is the conceptual bedrock, and it is the smallest domain by weight. A common mistake is to over-study it because it feels foundational; the exam does not allocate most of its marks here.
- How laws and standards apply to AI. How current and emerging laws apply to AI systems, and how the major frameworks (the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001ISO/IEC 42001The international requirements standard for AI management systems, published in 2023 and certifiable. It defines how an organization establishes, implements, maintains, and continually improves a management system for AI. Certification against ISO/IEC 42001 does not create a legal presumption of conformity with the EU AI Act. See AI management system, harmonized standard.Open full entry →, the GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry →) function as governance instruments.
- Governing AI development. The AI lifecycle, the context in which AI risks are managed, and the implementation of responsible AI governance during development.
- Governing AI deployment and use. Governance once a system is live: oversight, monitoring, and the duties that fall on the organization deploying AI.
Download the current BoK for the exact weighting of each domain, and let those weightings drive how you allocate your study time. Spending equal time on each domain, or most of your time on Domain 1, is the most common way well-prepared candidates underperform.
How the exam works
The exam is 100 questions in 2.75 hours, with a 15-minute break. Of the 100 questions, 85 are scored and 15 are unscored pilot questionspilot questionAn unscored item (15 of the AIGP's 100) being trialed for future exams. It is indistinguishable from scored items, and a reason not to panic over any single question.Open full entry → being trialed for future exams; you will not know which are which, so treat them all seriously. Scoring is scaled from 100 to 500, with 300 the passing threshold. Roughly 30% of questions are connected to case studies that present a real-world governance scenario.
The certification term is two years. Maintaining it requires 20 continuing-education credits aligned to the BoK and a maintenance fee, which is covered if you hold IAPP membership. This matters for a cost decision discussed below.
The thing that catches well-prepared candidates
The single most important thing to understand about the AIGP is that it is scenario-based, not a recall test. In most questions, three of the four answers look plausible. Only one aligns with the responsible-AI governance approach the IAPP has defined. You cannot reliably eliminate the wrong answers by recognizing definitions; you have to reason from the governance principles to the choice the framework would make in that situation.
This is why memorization fails and why question dumps are a poor foundation. A dump teaches you the answer to a specific question; the exam asks you to apply judgment to a scenario you have not seen. The candidates who pass comfortably are the ones who have internalized a way of thinking about governance, so that when a novel scenario appears they can work out which answer the framework supports. Building that applied reasoning is the real work of preparation, and it is what separates a credential holder who gets hired from one who merely passed.
How to prepare
A realistic preparation plan has three parts: study the current BoK and a structured course built on v2.1; practice scenario-based questions to train applied reasoning rather than recall; and work from a governance framework so that the scenarios connect to a coherent way of thinking rather than a list of facts. Be honest with yourself about the time: most candidates need well over the runtime of any video course, often 50 to 100 hours of active study, even with a strong privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry → or compliance background. Treating a course's video length as your study timeline is the most common way to underestimate the commitment.
For a detailed plan, see how to study for the AIGP. If you are still deciding whether to sit the exam at all, see is the AIGP worth it. If you are weighing it against a privacy credential, see AIGP vs CIPP.
How GovCompass prepares you
GovCompass approaches the AIGP the way the exam itself does: through applied governance reasoning built on a framework, not memorization. The free Responsible AI knowledge base covers the laws and frameworks the exam tests, organized around the seven pillarspillarA responsible-AI principle as something an organization actively holds rather than merely endorses: one of the seven pillars of responsible AI, one per principle. A pillar is held, not implemented, by naming the harms that would breach the principle, assessing their risk, and placing controls that reduce it. Distinct from agentic AI, which is not one of the seven but a condition that changes how all of them are governed. See principle, harm, risk, agentic AI.Open full entry → of responsible AI. The Academy builds the applied, scenario-based depth on top of it.
The AIGP track in the Academy builds that applied depth: original lessons on the current Body of Knowledge, scenario-based questions that train the judgment the exam tests, and honest readiness tracking that reflects your performance rather than how much you have read. It is the first track, with more frameworks to follow. Try it before you decide on the AIGP preparation page: a real practice question and a full sample lesson, no account needed.
Disclaimer
GovCompass is an independent resource and is not affiliated with, endorsed by, or sponsored by the International Association of Privacy Professionals (IAPP). "AIGP", "IAPP", and "CIPP" are trademarks of the IAPP, used here for identification only. GovCompass content is educational and does not guarantee any exam result. Always verify exam details against the official IAPP Body of Knowledge and exam blueprint at iapp.org.
Frequently asked questions
- Which Body of Knowledge version is the current AIGP exam based on?
- Body of Knowledge v2.1, effective 2 February 2026, organized into four domains. Materials that still reference the old seven-domain structure or an earlier version are out of date.
- How is the AIGP exam structured?
- 100 multiple-choice questions in 2 hours 45 minutes, with a 15-minute break; about a third are linked to case-study scenarios. 85 are scored and 15 are unscored pilot questions, and scoring is scaled from 100 to 500, with 300 to pass.
- What are the four AIGP domains?
- Understanding the foundations of AI governance; how laws, standards and frameworks apply to AI; governing AI development; and governing AI deployment and use. The foundational domain is the smallest by weight, so allocate time by the current Body of Knowledge weightings rather than evenly.
- What does AIGP stand for?
- Artificial Intelligence Governance Professional. It is the IAPP's certification for professionals who govern AI systems, and the current exam is built on Body of Knowledge v2.1.