The AIGP certification has matured into a detailed governance exam that spans AI foundations, law and standards, development governance, and deployment governance. The current IAPP Body of Knowledge is version 2.1, effective February 2, 2026, and explicitly includes modern concerns such as generative AI, agentic AI, general-purpose models, risk classification, data provenance, impact assessment, red teaming, drift, post-market monitoring, and system deactivation.
The current AIGP exam contains 100 questions and runs for 2.75 hours. IAPP states that questions are multiple choice, some are scenario based, and multi-select items require the exact number of responses indicated for credit. The certification term is two years. The current Body of Knowledge provides question ranges rather than percentage weights: Domain I has 16–20 questions, Domain II 19–23, Domain III 21–25, and Domain IV 21–25.
Domain I establishes the governance foundation before regulation or technology
The first domain asks what AI is, why it needs governance, what harms it can create, and which responsible-AI principles should guide oversight. The current BoK names fairness, safety and reliability, privacy and security, transparency and explainability, accountability, and human-centricity.
The deeper point is that governance exists because AI can be opaque, probabilistic, autonomous, fast, scalable, data-dependent, and capable of causing harm or misuse. A general AI foundation for non-programmers can help with terminology, but AIGP expects governance reasoning around those characteristics.
Organizational expectations are part of the exam, not just technical controls
Domain I also includes roles and responsibilities, cross-functional collaboration, training and awareness, and governance approaches that vary by organization size, maturity, industry, products, risk tolerance, and objectives. Governance therefore needs an operating model.
Candidates should understand the differences among AI developers, providers, deployers, and users from a governance perspective. The same organization can occupy more than one role, and obligations or risks can shift depending on which role is being performed.
AI lifecycle policies connect privacy, security, data governance, and third-party risk
The current BoK expects policies across use-case assessment, risk management, ethics by design, data acquisition, model development, testing, deployment, monitoring, documentation, reporting, and incident management. Existing privacy, security, data-governance, and intellectual-property policies may need to be updated for AI.
Third-party risk is included too: procurement, contracts, supply chain, human resources, and acceptable-use controls can all matter. AI governance is therefore an enterprise control system rather than one “AI policy.”
Domain II covers existing laws as well as AI-specific laws
The second domain asks how privacy, intellectual-property, nondiscrimination, consumer-protection, and product-liability laws can apply to AI. It then moves into AI-specific regulatory frameworks, risk classifications, documentation, conformity and impact assessments, human oversight, transparency, general-purpose AI, enforcement, and organizational roles.
The current BoK names examples such as the EU AI Act, South Korean AI Basic Law, and federal or state AI rules affecting private-sector organizations. The exam is not limited to one jurisdiction; it tests the governance concepts that recur across current laws.
Privacy law is applied through familiar requirements in an AI context
Candidates should understand transparency, choice, lawful basis, purpose limitation, data minimization, privacy by design, controller obligations, processor relationships, cross-border transfers, data-subject rights, automated decision-making, incident management, breach notification, record keeping, and sensitive data such as biometrics.
The broader IAPP certification context can help candidates who already know privacy concepts, but AIGP asks how those concepts change or intensify around AI systems and data-intensive workflows.
Standards and frameworks give organizations operational governance tools
The current BoK explicitly includes OECD trustworthy-AI principles, the NIST AI Risk Management Framework and Playbook, and ISO standards 22989, 42001, and 42005. Candidates should know the core purpose of these frameworks and how they help structure governance.
The practical distinction is between law, standard, and voluntary framework. An organization can use a framework to build controls even when a law does not prescribe the exact implementation mechanism.
Domain III governs AI development from use case through release
The development domain covers defining business context, impact assessment, ethical design, architecture and model selection, human oversight, data analysis, metrics and thresholds, stakeholder engagement, operational controls, risk mitigation, benchmarking, pilot testing, and documentation.
Data governance is a major part of this domain: lawful rights to collect and use data, quality, quantity, integrity, fit-for-purpose, lineage, provenance, training, testing, bias, security, performance, interpretability, and validation.
Release and maintenance turn development governance into continuous governance
The current BoK requires readiness assessment, production release, model cards, conformity requirements, continuous monitoring, maintenance, updates, retraining, audits, red teaming, threat modeling, security testing, incident management, and public disclosures where required.
It also expects candidates to understand brittleness, weak robustness, poor data, insufficient testing, and model or data drift as sources of operational incidents. Governance does not end at deployment.
Domain IV governs model selection, deployment, and use
The final domain covers business objectives, performance, data availability, ethics, workforce readiness, classic versus generative models, proprietary versus open source, small versus large models, language versus multimodal capability, and cloud versus on-premises versus edge deployment.
The BoK also names fine-tuning, retrieval-augmented generation, agentic architectures, vendor or licensing terms, proprietary-model liability, impact assessment, training, continuous monitoring, downstream harms, external communication, and controls to deactivate or localize a system.
The current AIGP exam is a lifecycle governance exam
The strongest mental model is one AI use case from proposal to retirement: define purpose, classify risk, identify laws, assess impact, govern data, choose and test the system, document decisions, deploy with controls, monitor outcomes, handle incidents, communicate externally, and deactivate if necessary.
The current v2.1 BoK is effective February 2, 2026 and supersedes version 2.0.1. IAPP states that the Body of Knowledge is reviewed annually and that changes to exam content are communicated in advance. This matters because AI governance evolves quickly; candidates should prepare from the current document rather than rely on an older training outline that predates newer agentic, general-purpose-model, or international-law content.
The official IAPP exam store currently lists a member price of $649 and a non-member price of $799. The exam must be completed within one year of purchase and can be taken remotely or at Pearson VUE testing centers. Administrative details do not replace study, but they help candidates plan a realistic certification timeline.
IAPP’s current maintenance rules also reinforce that AIGP is intended as a continuing professional credential. The term is two years, and certification holders must submit 20 continuing-education credits related to the AIGP Body of Knowledge and meet the applicable maintenance-fee requirement. Governance knowledge is expected to evolve after the exam.
The question ranges show that Domains III and IV deserve substantial applied study. Together they can account for 42 to 50 questions, covering development and deployment governance. A candidate who knows laws and principles but cannot apply governance to design, testing, monitoring, vendors, incidents, and retirement will have a visible readiness gap.
Likewise, Domain II is broader than memorizing the EU AI Act. The BoK deliberately includes existing privacy, intellectual-property, nondiscrimination, consumer-protection, product-liability, international AI laws, and standards. The governance professional must know when an AI problem is already governed by older law even before an AI-specific rule is considered.
Agentic AI is now visible in both the program framing and deployment objectives. The BoK names agentic architectures among deployment options and discusses secondary or unintended uses and downstream harms. Candidates should understand that autonomy and tool use can increase both operational value and governance burden.
General-purpose AI also has a distinct regulatory place. Domain II explicitly expects knowledge of special requirements for general-purpose models, while Domains III and IV require candidates to understand model selection and deployment context. The same model can create different governance obligations depending on whether an organization develops, provides, or deploys it.
Bloom’s Taxonomy is included in the current BoK to signal question depth. IAPP notes that exam questions mostly focus on remember/understand and apply/analyze levels. Candidates should therefore prepare beyond recall: define responsible-AI principles, then apply them to a vendor, deployment, incident, or legal-risk scenario and explain the stronger governance action.
The exam’s 100-question structure also makes pacing important. With 2.75 hours and some scenario-based or multi-select items, candidates need to recognize the governing domain quickly and avoid spending too long debating a detail that can be revisited. The current blueprint’s question ranges are useful for allocating practice proportionally.
Domain III and Domain IV also overlap deliberately. Development governance includes release, monitoring, and maintenance for systems an organization builds, while deployment governance covers selecting and governing systems an organization uses, including third-party models. The difference often depends on the organization’s role in the AI value chain.
The BoK’s treatment of deactivation is significant. Governance includes the ability to stop or localize a system when regulation, performance, safety, or risk requires it. Candidates should consider exit and containment controls during design rather than waiting until an incident makes shutdown urgent.
Another current feature of the BoK is its explicit attention to workforce readiness and external communication. Governance professionals are expected to think about whether people can use the system responsibly and how limitations or incidents should be communicated, not only whether technical controls exist.
The scope is therefore multidisciplinary by design. Legal knowledge without technical lifecycle literacy is incomplete, while technical risk management without law, ethics, and organizational accountability is equally incomplete. AIGP is built to test that intersection.
That breadth is the defining feature of the current AIGP blueprint.
It rewards connected governance judgment.
That is the point.
Within the broader IAPP certification ecosystem, AIGP is distinctive because it combines technical AI literacy with governance, legal, risk, and operational responsibilities. The current v2.1 blueprint rewards candidates who can connect those disciplines into one operating program.