Domain II, second half: AI-specific law and the framework stack (II.C–II.D)

Lesson 3 of 4 in AIGP Domains I–II Recap: Foundations, Laws, Standards, and Frameworks.

II.C (6–8 questions) is the EU AI Act’s home turf, with the South Korean AI Basic Law and US state laws as supporting cast. This academy teaches the Act canonically across eight EU AI Act modules — the recap here is only the exam’s skeleton of it:

II.D (3–5 questions) is the framework stack, and its questions are nearly always the same move: which instrument, and which part of it, does this scenario call for? The OECD AI Principles give the shared vocabulary (and the AI-system definition the EU AI Act adopted); the NIST AI RMF gives a voluntary risk process (Govern–Map–Measure–Manage, plus the Playbook and the Generative AI Profile); and three ISO standards divide the labour — 22989 defines the words, 42001 defines the management system you can certify against, and 42005 defines the impact-assessment process.

II.D at a glance: which instrument does what (full treatment in ISO Standards Landscape and NIST AI RMF modules)
InstrumentWhat it isWhat the exam asks about itThe trap

OECD AI Principles (2019, rev. 2023)

Intergovernmental principles — the first, and the source of the near-universal AI-system definition

Recognise the principles (human-centred values, transparency, robustness, accountability, inclusive growth) and that the EU AI Act borrowed the OECD definition

Not binding law, and not a process framework — it tells you what good looks like, not how

NIST AI RMF 1.0 (2023) + Playbook + GenAI Profile

Voluntary US risk-management process framework

Name the four functions — Govern (cross-cutting culture) wrapped around Map → Measure → Manage — and place an activity in the right one

“Voluntary” is load-bearing: no certification, no penalties. Candidates who answer “fined for violating the NIST RMF” fail that question

ISO/IEC 22989 (2022)

AI concepts and terminology standard

Pure vocabulary questions — which standard defines the shared language

It imposes zero obligations; it only defines terms

ISO/IEC 42001 (2023)

AI management-system standard (AIMS) — Plan-Do-Check-Act, the “ISO 27001 of AI”

It is the certifiable one: organisations can be audited and certified against it, and it can evidence (not presume) EU AI Act readiness

Certification ≠ legal compliance — a 42001 certificate is not a conformity assessment under the AI Act

ISO/IEC 42005 (2025)

AI system impact assessment guidance

The standard to name when a scenario needs a structured harms-to-people assessment process

Guidance, not certifiable requirements — and distinct from a DPIA

Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.