AIGP study guide
A full study guide for the AIGP exam: what it covers, how the four domains fit together, and every Domain I topic published free, in full.
The Artificial Intelligence Governance Professional (AIGP) is the IAPP's certification in AI governance. Most candidates come to it from privacy, legal, compliance or risk roles; a growing number are technical people who now own governance work. There are no prerequisites, and anyone can book the exam. The syllabus is broad: how machine learning works, the EU AI Act, the NIST AI Risk Management Framework, and the practical governance of AI systems in development and in use. Questions are scenario-based, so the exam tests whether you can apply this material, not whether you can define it.
This guide follows the exam's structure: four domains, studied in order, because each builds on the last. Domain I is published here in full — all 15 topics, free, no account needed. Domains II to IV are summarised below so you know what is in them; their full topics and practice questions are in the app, where Domain I is also free.
The exam at a glance
The practical facts, from the current Body of Knowledge (version 2.1, effective 2 February 2026):
| Questions | 100 multiple-choice and multi-select (85 scored, 15 unscored pilots), heavily scenario-based |
|---|---|
| Time | 3 hours |
| Scoring | Scaled 100–500; pass at 300; no penalty for wrong answers |
| Cost | US$799 ($649 for IAPP members); delivered by Pearson VUE, at a test centre or remotely |
| Domains | I: 16–20 questions · II: 19–23 questions · III: 21–25 questions · IV: 21–25 questions |
Booking, retakes, difficulty and certification maintenance are covered in the full AIGP exam guide.
How to use this guide
Exam questions describe a situation and ask what should happen next, and often two of the four options look defensible. Reading alone does not prepare you for that. The candidates who pass are generally the ones who answered the most practice questions and read the explanations.
Work in small loops: read one topic, answer its practice questions straight away, and read the explanation even when you were right. Take the domains in order — Domain II's laws regulate the systems Domain I teaches you to classify, and Domains III and IV build on both. A week-by-week plan, with realistic hours by background, is at how to study for the AIGP.
Domain I — the foundations of AI governance (16–20 questions), free in full
The rest of the syllabus stands on this domain: what an AI system is and how it learns, who is in the value chain, what harms these systems cause, and how an organisation builds a governance programme in response. It also introduces distinctions the other three domains reuse constantly, such as provider and deployer, or transparency and explainability. All 15 topics are free here:
Understand what AI is and why it needs governance
- What AI is: from AI to ML to deep learning to generative and agentic AI
- How machines learn: supervised, unsupervised, reinforcement and semi-supervised training
- Comparing AI models: four axes, expert systems, and capability levels
- Why AI needs its own governance, and how to describe a system: the OECD's five dimensions
- Principles of responsible AI: FIPs, OECD AI Principles, ethics by design, and trustworthy AI
- How AI fails and who gets hurt: failure modes and the five levels of harm
Establish and communicate organizational expectations for AI governance
- Roles across the AI value chain: developer, provider, deployer and user
- Governance structures, models and stakeholder roles
- Tailoring AI governance to your organization
- Building buy-in: leadership, training, AI literacy and culture
Establish policies and procedures to apply throughout the AI life cycle
- The AI development life cycle: from planning to decommissioning
- Policies across the AI life cycle, and use case assessment
- Evaluating and updating existing policies for AI
- Categories of AI risk, and risk assessment and calculation
- Managing third-party AI risk
Domain II — how laws, standards and frameworks apply to AI (19–23 questions)
The legal domain, in three layers. First, the laws that applied to AI before any AI-specific law existed: data protection (above all the GDPR — lawful basis, purpose limitation, automated decision-making), intellectual property and copyright, nondiscrimination law, consumer protection, and product liability. Scenarios in this layer ask which existing regime a described system has tripped.
Second, AI-specific law, led by the EU AI Act: the risk tiers from prohibited practices through high-risk to minimal risk, the different obligations on providers and deployers of high-risk systems, the general-purpose AI rules, and the Article 4 AI-literacy duty. Third, the standards layer: the OECD AI Principles, the NIST AI Risk Management Framework with its Govern, Map, Measure and Manage functions and seven trustworthiness characteristics, and the core ISO trio of 22989 (concepts and terminology), 42001 (AI management systems) and 42005 (impact assessments). Many Domain II questions turn on who is bound — a US deployer, an EU provider, a vendor — so learn each instrument together with the role it binds.
Condensed notes on the main Domain II topics are free here:
- Why existing privacy law still governs AI, and the data protection principles that apply across the life cycle
- GDPR and AI: Article 22 automated decision-making, DPIAs, and the controller's ten obligations
- Pseudonymization, anonymization, sensitive data, and privacy-enhancing technologies
- Intellectual property law and AI: authorship, training data, and the licensing puzzle
- Nondiscrimination law and AI across health care, insurance, employment, credit and housing
- Consumer protection and product liability law applied to AI
- The TAKE IT DOWN Act: a narrow but testable federal example
- The global AI regulation landscape and operator roles
- The EU AI Act: risk classification framework, all four tiers
- The EU AI Act: high-risk system requirements, by obligation theme and by role
- The EU AI Act: general-purpose AI (GPAI) models and the systemic-risk tier
- The EU AI Act: enforcement, penalties, and the implementation timeline
- South Korea's AI Basic Act and the global patchwork: US, Japan, China and beyond
- How to build a multi-jurisdiction AI compliance strategy
- ISO/IEC AI standards (22989, 42001, 42005) and adjacent frameworks
Domain III — how to govern AI development (21–25 questions)
Domain III is the builder's view of the AI life cycle. It covers governance during design (defining the use case, setting requirements and acceptance criteria), governance of the data used for training and testing (provenance, quality, consent, representativeness, and the bias that results when those are neglected), and governance of testing, release and maintenance: evaluation against requirements, documentation, staged release, then monitoring once the system is out.
Together with Domain IV it carries roughly half the paper. Expect scenarios about incomplete training data, skipped evaluations and unowned monitoring, where the correct answer is usually procedural: assess first, document, assign an owner.
Condensed notes on key Domain III topics are free here:
- The AI system development life cycle: seven stages, and where governance touches each one
- Training, testing and validation: the three data subsets, and how to test an AI system
- Testing depth: metrics and thresholds, system audits, alignment/repeatability/adversarial testing, and resource allocation
- Human oversight during development: the Three Lines of Defense model, and decommissioning governance
- Managing and monitoring AI systems after deployment: inventory, drift, and champion/challenger testing
Domain IV — how to govern AI deployment and use (21–25 questions)
Domain IV is the deployer's view — the organisation using an AI system rather than building one, which is most organisations. It covers the decision to deploy (model types, deployment options, and the risks of each), assessing the chosen system before it goes live (impact assessments, vendor due diligence, contract terms), and governing the system in use: monitoring for drift and misuse, handling incidents, and communicating with the people the system affects.
These questions test judgement about sequence and responsibility. When a scenario says a deployed model has started behaving oddly, the tested skill is knowing what happens next — contain, assess, notify, document — and what is owed to users, regulators and the vendor.
Condensed notes on key Domain IV topics are free here:
- Agentic AI governance: infrastructure, risk models, and safety best practices
- Managing third-party risk: policies, vendor screening, and evaluating the licensing agreement
- Incident response, the kill switch, and downstream consequence management
- AI auditing, accountability automation, and governance testing tools
A study plan, condensed
Plan for 30 to 60 focused hours: about four weeks with a privacy or compliance background, six to eight coming to the field fresh. In outline: a week on Domain I (this page, then its questions), a week on Domain II with the EU AI Act and NIST AI RMF at the centre, a week each on Domains III and IV, then one or two weeks of mixed, timed practice on whichever domain your scores say is weakest. Booking the exam early helps; most people study more consistently against a fixed date. The expanded plan is at how to study for the AIGP, and a comparison of courses and books is at best AIGP exam prep.
The vocabulary problem
A large share of AIGP questions turn on distinctions between terms that sound interchangeable: robustness and resilience, transparency and explainability, fairness and bias, provider and deployer. The free 196-term glossary collects every definition this guide uses in one place. It is worth a full pass in your final week.
Which Body of Knowledge version this tracks
The exam is written against Body of Knowledge version 2.1, effective 2 February 2026. That revision reorganised the previous seven domains into the four above and replaced "AI models" with "AI systems" throughout, because governance obligations attach to whole systems and their supply chains, not just the model. Everything on this site, from the topics to the 492-question bank, is aligned to that version and will be updated when the IAPP publishes the next one. If you are using older third-party materials, check which version they track: pre-2025 resources still teach the seven-domain structure.
Frequently asked questions
What are the four domains of the AIGP exam?
Domain I covers the foundations of AI governance — what AI systems are, the harms they cause, and how organisations build governance programmes. Domain II covers how laws, standards and frameworks apply to AI, led by the EU AI Act and the NIST AI RMF. Domain III covers governing AI development, from design through data to release. Domain IV covers governing deployment and use — the deployer's decisions, assessments and monitoring. Domains III and IV together carry roughly half the questions.
Is this AIGP study guide really free?
The material on this site is free with no account: all 15 Domain I topics in full, 50 practice questions with explanations, the 196-term glossary and the exam guides. The app's Domain I tier — including all 100 of its practice questions — is also free, no card details. Only Domains II–IV in full depth, the rest of the question bank and the timed mocks need a pass.
Do I need the official IAPP study materials?
No single resource is required. The IAPP's free Body of Knowledge and exam blueprint define everything the exam can ask, and self-study passes on third-party materials are routine. What matters is that whatever you use tracks the current Body of Knowledge (version 2.1) and makes you practise scenario questions, not just read.
Where should I start studying for the AIGP?
Download the free Body of Knowledge from the IAPP so you know the terrain, then start with Domain I on this page — read a topic, practise its questions immediately, and move on. Once Domain I feels solid, follow the domain order with a plan: our six-week schedule is in the how-to-study guide.
Is there an AIGP study guide PDF?
Not from us, deliberately. AI governance law changes faster than a PDF can be reprinted — this guide is a live page, updated when the Body of Knowledge changes, rather than a static document that goes stale. If you specifically want a printed or downloadable book, Wiley's Sybex study guide is the main option; it is compared alongside everything else at best AIGP exam prep.
How does this compare to a paid AIGP certification study guide?
This page covers Domain I in full for free and summarises Domains II–IV, which is roughly what a paid study guide covers at a glance. The difference is depth and practice: paid books teach by reading, while this site pairs every topic with practice questions and, in the app, a full question bank and timed mocks. A full comparison of paid options — training, books, video courses — is at best AIGP exam prep.
Then practise it
Reading is only the first pass. There are 50 free practice questions with full explanations on this site. The app has all 100 Domain I questions free with progress tracking; a pass adds Domains II to IV, the rest of the 492-question bank, timed mock exams and flashcards.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.