IAPP AIGP AI governance professional certification exam guide banner

AI Governance Certification: What the AIGP Exam Really Asks of You

AIGP is the exam code for the IAPP Certified Artificial Intelligence Governance Professional, and it is the first credential from a recognised privacy body to treat AI oversight as a discipline in its own right. One hundred questions, one hundred and sixty-five minutes, scored on a scale from 100 to 500 with 300 to pass. The fee is $649 for IAPP members and $799 for everyone else, which puts it near the top of the AI governance certification market and makes the decision to sit it a real one rather than an obvious one.

What makes AIGP unusual is what its blueprint leaves out. There are four body-of-knowledge domains and no published percentage weightings, so you cannot plan revision by chasing the biggest block. This guide walks the four domains in plain language, sets out the laws and frameworks the objectives name directly, gives the true cost including the parts people forget, and answers the question the search data says candidates actually ask: is it worth it.

What Is the AIGP Certification and Who Runs It?

AIGP is run by the International Association of Privacy Professionals, the body behind the CIPP, CIPM and CIPT credentials. It certifies that the holder can build and run an AI governance programme rather than write model code. The exam is 100 questions in 165 minutes through Pearson VUE, and it covers foundations, applicable law, development governance and deployment governance.

The framing matters. IAPP did not build a technical AI exam and then bolt policy onto it. It built a governance exam and left the mathematics alone. Nothing in the blueprint asks you to tune a model. Plenty of it asks you to decide whether a model should ship.

“The AIGP credential demonstrates competency in AI development, the ability to conduct ethical AI deployment, and the ability to utilize best practices in AI management to ensure safety and trust.”

IAPP, Certification programme description

IAPP publishes a free Body of Knowledge and Exam Blueprint alongside a free study guide on the official AIGP page, which is unusual for a credential at this price and worth taking seriously as the primary reading. Its own positioning is that AI governance is now a cross-industry requirement rather than a technology-sector concern, which is reflected in objectives that reach into employment, credit, lending, housing and insurance.

What Do the Four AIGP Domains Actually Cover?

The AIGP body of knowledge has four domains. The first establishes what AI governance is and how to set it up inside an organisation. The second covers the legal and standards landscape. The third governs building an AI system. The fourth governs deploying and running one, including systems you bought rather than built.

Domain one: the foundations

This domain asks for the accepted definitions and types of AI, the categories of harm AI can cause, and the characteristics that make AI hard to govern in the first place: opacity, autonomy, speed and scale, data dependency, and probabilistic rather than deterministic outputs. It then moves into organisational mechanics, defining roles, building cross-functional collaboration, and writing life-cycle policy.

One objective is easy to underestimate. You are expected to distinguish developers, providers, deployers and users from a governance perspective, because their responsibilities and exposure differ. That distinction returns in the legal domain and again in the deployment domain.

Domain two: laws, standards and frameworks

Here the exam tests how existing privacy law applies to AI, how non-privacy law applies, what AI-specific law requires, and which industry standards matter. Nondiscrimination, consumer protection, product liability and intellectual property all appear by name.

Domain three: governing development

Three objective groups cover designing and building the system, governing the data used to train and test it, and governing release, monitoring and maintenance. Model cards, conformity requirements, red teaming, threat modelling, data lineage and provenance, and drift are all named.

Domain four: governing deployment and use

The final domain is the one most candidates live in professionally. It covers deployment decisions, vendor and licensing risk, impact assessment of a system you did not build, and the controls needed to deactivate or localise a system when regulation or performance demands it. It also asks about model types and deployment options, including retrieval augmented generation and agentic architectures. Anyone weighing whether this maps to their day job will find the AIGP certification overview a quicker read than the full blueprint.

Why Does the AIGP Blueprint Publish No Domain Weightings?

Unlike most certification blueprints, the AIGP body of knowledge lists domains and objectives without attaching a percentage to any of them. There is no published statement that domain two is worth thirty percent or that domain one is worth fifteen. That absence is a planning fact, not an oversight to be filled in with a guess.

What that changes about revision

On a weighted exam you can rationally over-invest in the heaviest domain. Here you cannot, so the sensible default is to treat all four as equally likely to appear and to let objective count rather than assumed weight guide your time. Domains two, three and four each carry three or four objective groups; domain one carries three. That is as close to a distribution signal as the blueprint offers.

It also means you should be sceptical of any study resource that presents AIGP domain percentages as fact. If a percentage is not in IAPP’s own blueprint, someone has estimated it.

A second consequence is that scenario questions can legitimately straddle domains. A question about a vendor-supplied hiring model touches deployment governance, nondiscrimination law and impact assessment at once, and no single domain owns it.

Which Laws and Frameworks Does the AIGP Exam Test?

The AIGP blueprint names its sources rather than gesturing at them. It requires the OECD principles for trustworthy AI, the NIST AI Risk Management Framework and Playbook including its core functions and categories, and the core ISO AI standards 22989, 42001 and 42005. On the legal side it requires the risk classification framework and enforcement model of AI-specific law.

The four AI risk tiers the AIGP exam expects candidates to apply: prohibited, high, limited and minimal

The risk tiers you are expected to apply

The blueprint asks you to understand a four-tier risk classification covering prohibited, high, limited and minimal risk, and to know what systems and uses fall into each. That vocabulary comes from the EU AI Act, and the exam expects you to place a described system into the right tier rather than to recite the tiers.

Alongside the tiers, you need the obligations that attach to each: risk management, data governance, technical documentation, conformity and impact assessments, record keeping, human oversight, transparency and notification, and quality management. General-purpose AI models carry their own distinct requirements, and the obligations differ again between providers, deployers, importers and distributors.

Where privacy law stops and AI law starts

The exam is careful about the boundary. Transparency, lawful basis, purpose limitation, data minimisation and privacy by design are tested as privacy requirements applied to AI. Automated decision making, cross-border transfers, data subject rights and breach notification are tested as controller obligations applied to AI. Those are privacy questions in an AI setting, and a CIPP holder will recognise them immediately.

What is genuinely new is the ethics and safety layer. Fairness, safety and reliability, transparency and explainability, accountability and human-centricity are examined as principles you can apply to a described scenario. IEEE’s autonomous systems work is the clearest public grounding for where those principles came from, and reading it makes the difference between recognising the words and being able to argue with them.

How Much Does the AIGP Exam Cost and What Score Passes?

The AIGP exam costs $649 USD for IAPP members and $799 USD for non-members, and is delivered through Pearson VUE. It runs 100 questions in 165 minutes and is scored on a scale from 100 to 500, with 300 required to pass. That is just under one hundred seconds per question, which is generous for definition items and tight for the longer scenario items.

DetailValue
Exam nameIAPP Certified Artificial Intelligence Governance Professional
Exam codeAIGP
Questions100
Duration165 minutes
Passing score300 on a 100 to 500 scale
Price$649 member, $799 non-member
DeliveryPearson VUE

The number people budget wrong

The $150 gap between the member and non-member price is close to the cost of IAPP membership itself, which is why most candidates end up joining rather than paying the higher fee. Work out the combined figure before you decide which route looks cheaper. The exam is bought directly from the IAPP store, so the pricing is easy to confirm rather than inferred.

A scaled score of 300 out of 500 is not sixty percent of questions answered correctly. Scaling adjusts for the difficulty of the particular form you sit, so treat it as needing consistent competence across all four domains rather than a fixed count of right answers.

Is the AIGP Certification Worth It?

AIGP is worth it if AI governance is already landing on your desk and you need a defensible vocabulary for it. It is not worth it as a speculative entry credential for someone with no privacy, risk, legal or compliance grounding, because the exam assumes you already know how a governance programme works and only teaches you to apply that to AI.

Who the AIGP AI governance certification suits and who it does not

The case for

  • It is the first AI governance credential from a body that hiring managers in privacy and compliance already recognise, which matters more than the syllabus in a job application.
  • The blueprint is genuinely current, built around risk tiers, general-purpose models and deployment realities rather than around abstract ethics.
  • It transfers across industries. The objectives reach into employment, lending, housing and insurance, so the credential is not locked to technology employers.

The case against

  • The price is high for a self-funded candidate, and the certification term is short at two years, so it is a recurring cost rather than a one-off.
  • There is no hands-on component. If your role is building models rather than governing them, this credential will not close that gap.
  • The field is moving fast enough that a governance credential earned today will need genuine maintenance, not just a renewal fee.

The honest test is whether you can name a decision at work in the last six months that this material would have changed. If you can, the fee is easy to justify. If you cannot, wait until you can.

Does a Privacy Background Transfer to AI Governance?

A privacy background transfers well to roughly half of AIGP and not at all to the rest. Domain two rewards it heavily, because the exam tests how existing privacy law applies to AI and a CIPP or CIPM holder already knows impact assessments, controller obligations, cross-border transfers and breach notification. Domains three and four are new ground.

What carries over

Impact assessment methodology, data minimisation, lawful basis reasoning, third-party processor management, record keeping and incident handling all appear in AIGP with the same shape they have in privacy work. Candidates from a CIPM background in particular tend to find the organisational objectives in domain one straightforward, because programme design is programme design.

What does not

The model life cycle is genuinely new for most privacy professionals. Training and testing governance, data lineage and provenance, drift, red teaming, model cards and conformity assessment are engineering-adjacent concepts, and reading about them is not the same as being able to reason about them under time pressure. So is the vocabulary of model types, where the exam distinguishes classic from generative, proprietary from open source, and single-modality from multimodal systems.

Candidates who have already sat an IAPP exam should read the write-up on recent blueprint changes before planning, because the body of knowledge has moved since the credential launched and older study notes drift out of date quickly.

How Should You Build an AIGP Study Plan?

The efficient order is to read the free blueprint first, close the legal domain second, then work the two governance-of-practice domains, and finish on scenario reasoning. That order works because the legal domain is the most memorisable and the deployment domain is the most judgement-based, so the facts should be settled before the judgement is practised.

  1. Download IAPP’s free Body of Knowledge and Exam Blueprint and treat it as the syllabus of record rather than any third-party summary.
  2. Learn the four risk tiers and the obligations attached to each until you can place a described system without hesitating.
  3. Separate the four actor roles, provider, deployer, importer and distributor, and learn what changes between them, because scenario questions turn on exactly that.
  4. Work through the NIST AI Risk Management Framework core functions and the three ISO standards named in the blueprint, at the level of what each is for rather than clause by clause.
  5. Map the AI life cycle end to end, from use-case assessment through training and testing to release, monitoring and incident management.
  6. Practise deployment scenarios where the system was bought rather than built, since vendor and licensing risk is its own named objective.
  7. Run timed practice at roughly one hundred seconds a question so the longer scenario items stop feeling like a time trap.

Most candidates with a privacy background report six to ten weeks of part-time study. Candidates arriving from a purely technical role usually need longer, because the legal domain has no shortcut and cannot be reasoned out from first principles. When you are close to booking, the collected AIGP preparation materials are a useful final checklist against the blueprint.

Frequently Asked Questions

How many questions are on the AIGP exam?

The AIGP exam contains 100 questions and you get 165 minutes to complete them. That works out at just under one hundred seconds per question. Definition items move quickly, so the real time pressure comes from the longer scenario questions that describe a whole AI system and its context.

What score do you need to pass the AIGP exam?

You need 300 on a scale that runs from 100 to 500. Because the score is scaled rather than a raw percentage, it adjusts for the difficulty of the specific exam form you sit. Treat it as needing consistent competence across all four domains rather than a fixed number of correct answers.

How much does the AIGP certification cost?

The exam is $649 USD for IAPP members and $799 USD for non-members. Because the gap is close to the price of membership itself, most candidates join IAPP rather than pay the higher fee. Work out the combined cost before deciding which route is genuinely cheaper for you.

Are there prerequisites for the AI governance certification?

IAPP sets no mandatory prerequisite certification or minimum experience for AIGP, and its certification policy FAQ confirms it. In practice the blueprint assumes working familiarity with how a governance or compliance programme operates, so candidates with no privacy, legal, risk or audit grounding usually find domains one and two much harder.

Which domain is worth the most marks in AIGP?

None is published as heaviest. The AIGP body of knowledge lists four domains without percentage weightings, so any resource quoting AIGP domain percentages is estimating. Plan on all four being equally likely to appear and let objective count rather than assumed weight guide your revision time.

Does the AIGP exam require technical AI knowledge?

Not at a build level. You are never asked to train or tune a model. You are asked to reason about model types, deployment options, training and testing governance, drift and red teaming, so you need the vocabulary of the model life cycle without needing the mathematics behind it.

How long is the AIGP certification valid?

The AIGP certification term runs two years from the day after you pass, after which it must be maintained. That short cycle is deliberate in a field where regulation and practice are both moving quickly, but it does make the credential a recurring cost rather than a single purchase.

Is AIGP worth it if you already hold a CIPP?

Usually yes, because roughly half the blueprint builds directly on privacy knowledge you already have and the rest is genuinely new. The legal domain will feel familiar. The development and deployment governance domains will not, and those are where your study time should concentrate.

What laws does the AIGP exam cover?

The blueprint covers existing privacy law applied to AI, plus intellectual property, nondiscrimination, consumer protection and product liability law. It then covers AI-specific law, including the four-tier risk classification, the obligations attached to each tier and the enforcement and penalty framework.

How long does it take to prepare for the AIGP exam?

Candidates with a privacy or compliance background commonly report six to ten weeks of part-time study. Those arriving from a purely technical role should plan longer, because the legal domain cannot be reasoned out from first principles and has to be learned as material.

Conclusion

AIGP is a governance exam wearing an AI badge, and reading it that way makes the whole blueprint easier. The four domains move from setting a programme up, through the law it has to satisfy, into building and then running systems, and the absence of published weightings means none of them can safely be skipped. The legal domain is the most learnable, the deployment domain is the most judgement-heavy, and the ethics layer is where privacy professionals meet material they have not seen before.

Decide on the strength of your own case rather than on the credential’s newness. If AI oversight is already part of your role, the vocabulary this exam builds will pay for itself quickly, and working practice items against the published blueprint is the fastest way to find out how far your existing knowledge already carries you.

Rating: 5 / 5 (1 votes)