Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about the IAPP's AI governance certification as of 2026, covering the four BoK v2.1 domains, exam format, costs, career paths, and how the AIGP compares to ISACA's AAISM and AAIA. A complete reference for anyone weighing the AIGP or trying to understand what it covers.
What AI governance is, responsible AI principles, and lifecycle policies.
The EU AI Act, privacy law, NIST AI RMF, and the ISO AI standards.
Impact assessments, data governance, and release oversight. The heaviest domain alongside Domain IV.
Deployment decisions, vendor terms, monitoring, and accountability.
AIGP is the IAPP's AI governance certification, launched in April 2024, and currently the only globally recognized credential dedicated specifically to AI governance.
It validates the knowledge to develop, deploy, and oversee AI systems responsibly across four domains. The point isn't building models. It's proving you can govern them: setting policy, applying the laws and frameworks that now regulate AI, and holding systems accountable from design through deployment the way a governance lead has to.
The credential is vendor-neutral, carries no prerequisites, and is built around the regulatory stack organizations are now staffing against: the EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001. AIGP is issued and maintained by the IAPP, the same body behind the CIPP, CIPM, and CIPT privacy credentials.
Four things driving demand for the credential as organizations scramble to stand up AI governance programs.
The AIGP is the only globally recognized certification dedicated to AI governance, and it comes from the IAPP, a credentialing body with two decades of standing in privacy and a mature exam infrastructure behind it. That institutional foundation is why the credential carried weight from day one.
ISACA's AAISM and AAIA both require an existing credential like CISM, CISSP, or CISA before you can even register. The AIGP has no formal prerequisites, so governance-side professionals can start here directly.
IAPP research from 2026 found only 1.5 percent of organizations feel fully satisfied with their AI governance staffing. Our breakdown of what the AIGP costs and pays covers the salary math behind that gap.
The AIGP is not a DoD 8140 credential. It does not appear in the Qualification Matrix V2.1, and neither do ISACA's AI certifications, so none of them will satisfy a cyber-coded position requirement.
Its weight comes from the regulatory side instead: the EU AI Act now in force, the NIST AI Risk Management Framework as the de facto US standard, and ISO/IEC 42001 emerging as the global benchmark for AI management systems.
Everything you need to know about the certification, the exam structure, and how to maintain the AIGP as of 2026.
The AIGP establishes the governance foundation. From there, most professionals specialize: into AI security management, AI audit, or privacy engineering. Note that the ISACA AI credentials carry hard prerequisites the AIGP does not.
ISACA's Advanced in AI Security Management is built for security leaders defending AI systems: governance, risk, and AI-specific controls. It requires an active CISM or CISSP, so it's the natural next step for security managers extending into AI.
ISACA's Advanced in AI Audit targets experienced auditors who evaluate AI systems for compliance, risk, and operational effectiveness. It requires an active CISA, CIA, or CPA, and it's where AIGP-grounded governance knowledge meets formal assurance work.
ISACA's Certified Data Privacy Solutions Engineer covers implementing privacy by design in technical systems. For AIGP holders who came from the privacy side, it's the path that turns governance policy into engineering practice.
With no prerequisites, the AIGP can be a first credential. In practice most candidates arrive from privacy or compliance work, earn the AIGP as their AI governance anchor, and then specialize by role.
Common starting points, none required
The AI governance anchor
Two questions to answer before you commit: can you certify, and should you pursue the AIGP specifically. Here's a straight answer to both.
No prerequisites, no experience requirement.
The AIGP has no prerequisite credential and no documented experience requirement, which makes it unusual among professional certifications and the most accessible of the major AI credentials. Purchase the exam, and you have one year to schedule and sit for it through Pearson VUE or remote OnVue proctoring.
Open entry doesn't mean easy entry.
Around 30 percent of the exam is scenario-based, and the scenarios assume you can reason like someone who has worked near privacy, compliance, risk, or AI systems. Candidates coming in completely cold pass, but they spend more prep time building the regulatory and lifecycle context the questions take for granted.
The AIGP maps to the governance, risk, and compliance side of AI work, the roles organizations are scrambling to fill as the EU AI Act and state AI laws take hold.
Owns the organization's AI governance program end to end: policy, intake review, impact assessments, and the accountability structures that keep AI use defensible.
Extends an existing privacy program into AI, covering training data use, automated decision-making, and the transparency duties privacy law now attaches to AI systems.
Maps obligations under the EU AI Act and sector rules to internal controls, evidence, and reporting, then keeps the program audit-ready as regulations shift.
Assesses AI-specific risk across the model lifecycle and brings it into the enterprise risk register in language the board can actually act on.
Advises on AI contracts, vendor terms, and regulatory positions, including the provider-versus-deployer distinctions that EU AI Act liability turns on.
Runs AI initiatives with governance built in from intake, coordinating legal, security, data, and product teams so oversight never gets bolted on after launch.
Shortest version: AIGP is for the people who govern AI, AAISM is for the security leaders who defend it, and AAIA is for the auditors who verify it.
| AIGP | AAISM | AAIA | |
|---|---|---|---|
| Issuer | IAPP | ISACA | ISACA |
| Focus | AI governance, law, lifecycle oversight | AI security management | AI audit and assurance |
| Prerequisites | None | Active CISM or CISSP | Active CISA, CIA, or CPA |
| Exam Format | 100 items, 2 hrs 45 min, linear | 90 items, 2.5 hours | 90 items, 2.5 hours |
| Passing Score | 300 (scaled 100 to 500) | 450 (scaled 200 to 800) | 450 (scaled 200 to 800) |
| Renewal | 20 CPEs over 2 years | 30 CPEs over 3 years | 30 CPEs over 3 years |
| DoD 8140 Approved | No | No | No |
| Best For | Privacy, compliance, risk, legal, program leaders | Security managers and CISOs | IT auditors and assessors |
Pricing and renewal details vary by membership status. None of the three appear in the DoD 8140 Qualification Matrix V2.1, dated September 19, 2025.
Our official IAPP AIGP boot camp covers all four BoK v2.1 domains over two days, with authorized courseware, scenario-question drills, and your exam voucher included, so you leave exam-ready.
Exam prep, certification strategy, cost breakdowns, and how the AIGP stacks up against the other AI credentials.
A close look at the credential itself: what the AIGP actually tests, who it fits, where it stands among emerging AI certifications in 2026, and an honest read on its market value.
The foundation underneath the credential: what AI governance actually is, the major frameworks, and why it now matters to IT, security, compliance, and risk teams.
The full money picture: exam fees, training costs, the salary data behind AI governance roles, and the staffing gap that is driving demand for the credential.
A study plan organized around the four BoK v2.1 domains, with the question weightings and the operational translation skill the scenario items really test.
The questions to settle before committing budget or study time, so you and your team land on the credential that actually matches the work in front of you.
How ISACA split AI into three role-specific extensions, what each one requires, and how that stacking approach compares to the AIGP's open-door model.
Practitioner, manager, or auditor: how the new wave of AI security certifications divides by role, and where governance credentials like the AIGP sit alongside them.
The AIGP Body of Knowledge v2.1 is organized into four domains, each with a published range of scored questions out of 85. Click any domain for what it covers.
What AI governance is and why AI needs it: the types and risks of AI, the common principles of responsible AI, roles and responsibilities for governance stakeholders, and the policies that apply across every stage of the AI lifecycle, including third-party risk.
How existing privacy, IP, nondiscrimination, consumer protection, and product liability laws reach AI, plus the main elements of AI-specific laws like the EU AI Act, and the standards stack: OECD principles, the NIST AI RMF, and ISO 22989, 42001, and 42005.
Governing the design and build of AI systems: impact assessments, data governance for training and testing, documentation like model cards, and the release, monitoring, and maintenance activities that keep a system compliant once it ships.
The deployment decision and what follows it: evaluating model types and deployment options, reviewing vendor and licensing terms, continuous monitoring, incident documentation, transparency obligations, and controls to deactivate a system when required.
Domains and question ranges reflect the IAPP AIGP Body of Knowledge v2.1, effective February 2, 2026. The IAPP reviews the BoK annually and announces changes at least 90 days before they reach the exam.
The questions candidates ask most often when researching the Artificial Intelligence Governance Professional certification.
The Artificial Intelligence Governance Professional (AIGP) is a vendor-neutral certification from the IAPP that validates your ability to develop, deploy, and oversee AI systems responsibly. It covers AI governance principles, the laws and frameworks that apply to AI, and how to govern AI across development and deployment. It's currently the only globally recognized certification dedicated specifically to AI governance.
The AIGP is issued by the IAPP, the International Association of Privacy Professionals, the same body behind the CIPP, CIPM, and CIPT privacy credentials. The IAPP launched the AIGP exam in April 2024, making it one of the newest credentials in the AI space, backed by an established credentialing organization.
No. The AIGP is a governance certification, not a technical one. You won't train machine learning models or write code. The exam tests whether you can set responsible AI policy, apply laws like the EU AI Act, work with frameworks like the NIST AI RMF and ISO/IEC 42001, and govern AI systems through their lifecycle.
Under Body of Knowledge v2.1, effective February 2, 2026, the four domains are Understanding the Foundations of AI Governance (16 to 20 scored questions), Understanding How Laws, Standards and Frameworks Apply to AI (19 to 23), Understanding How to Govern AI Development (21 to 25), and Understanding How to Govern AI Deployment and Use (21 to 25).
The AIGP exam costs $649 for IAPP members and $799 for non-members. You must sit for the exam within one year of purchase. Training Camp's 2-day AIGP boot camp includes the exam voucher in its program fee.
The AIGP exam has 100 questions, 85 scored and 15 unscored pilot questions, delivered in a linear format over 2 hours and 45 minutes including a 15-minute break. It's administered through Pearson VUE, either at a test center or via remote OnVue proctoring. Scoring is scaled from 100 to 500, and 300 is required to pass.
No. The AIGP has no formal prerequisites, which sets it apart from the ISACA AI credentials like AAISM and AAIA that require an existing certification such as CISM, CISSP, or CISA. A background in privacy, compliance, risk, or AI technology helps but isn't required to sit for the exam.
The AIGP is valid for two years. You maintain it by earning 20 continuing professional education (CPE) credits during that period and paying a certification maintenance fee, which is covered for active IAPP members.
No. The AIGP doesn't appear in the DoD 8140 Qualification Matrix V2.1, dated September 19, 2025. Neither do ISACA's AAISM or AAIA. The AIGP's recognition comes from a different direction: alignment with the EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001. If you need an 8140-approved path, see the full DoD 8140 work role paths.
Most candidates find the AIGP moderately difficult. The challenge is breadth, not depth. You're asked to apply governance reasoning across law, risk, and lifecycle activities rather than recall isolated facts. Candidates who study against the BoK v2.1 blueprint and practice scenario questions tend to find the rigor manageable.
Most candidates spend four to eight weeks preparing, depending on background in AI, privacy, or compliance. A focused boot camp compresses that timeline by working straight from the BoK v2.1 blueprint and drilling the scenario-style questions that carry the most weight on the exam.
Choose the AIGP if your work centers on governance: policy, regulatory compliance, vendor risk, and responsible AI programs. Choose ISACA's AAISM if you're a security leader defending AI systems and you already hold the required CISM or CISSP. The AIGP has no prerequisite, which makes it the more accessible entry into AI credentials for governance-side professionals.
For governance, privacy, compliance, and risk professionals, yes. The EU AI Act is in force, the NIST AI RMF has become the de facto US standard, and IAPP research shows only 1.5 percent of organizations feel fully satisfied with their current AI governance staffing. The AIGP is the credential most directly aimed at that gap.
Whether you're weighing the certification, comparing AI credentials, or planning AI governance training for a team, tell us where you are and we'll help you map out the right path.