The Body of Knowledge and the four-domain blueprint
Lesson 2 of 5 in The AIGP Credential: Exam Anatomy, Logistics, and Study Strategy.
Every question on the exam traces back to one document: the Body of Knowledge (BoK). It lists the domains, the competencies inside each domain, and the performance indicators — verb-led statements like “identify the types of risks posed by AI” or “evaluate key terms in vendor agreements” — that questions are written against. If a fact is not reachable from a performance indicator, it cannot be tested. The BoK is therefore not background reading; it is the exam’s contract with you, and the single most useful free download in your preparation.
The current contract is BoK Version 2.1 — approved by the Exam Development Board on 9 September 2025 and effective on exams from 2 February 2026.
| Legacy domain (pre-2026) | Where that content lives now |
|---|---|
Foundations of AI | Domain I (I.A — definitions, types, unique characteristics) |
AI impacts & responsible-AI principles | Domain I (I.A — risks, harms, and principles) |
AI development life cycle | Domain III — now a full quarter of the exam on governing development |
Implementing responsible AI governance | Split: program design and policies → Domain I (I.B, I.C); operational governance → Domains III and IV |
Existing law (privacy, IP, anti-discrimination…) | Domain II (II.A privacy law; II.B other existing law) |
Emerging AI-specific law | Domain II (II.C AI-specific law; II.D standards and frameworks) |
Ongoing issues & concerns | Dissolved — generative and agentic AI content is folded into all four domains rather than quarantined at the end |
Here is the four-domain blueprint itself. The numbers are question ranges, not percentages — the blueprint commits to a minimum and maximum count per domain and per competency on every exam form.
| Domain | Questions | Competencies (question range) | In one sentence |
|---|---|---|---|
I — Understanding the foundations of AI governance | 16–20 | I.A definitions, risks & principles (4–6) · I.B roles & program design (5–7) · I.C policies across the life cycle (6–8) | What AI is, why it needs governing, and who does what in the program |
II — Understanding how laws, standards and frameworks apply to AI | 19–23 | II.A privacy law (4–6) · II.B other existing law (4–6) · II.C AI-specific law (6–8) · II.D standards & frameworks (3–5) | Old law applied to AI, new AI law, and the OECD/NIST/ISO framework stack |
III — Understanding how to govern AI development | 21–25 | III.A design & impact assessment (6–8) · III.B data governance, training & testing (6–8) · III.C release, monitoring & incidents (8–10) | Governance checkpoints from use-case definition through release and post-release |
IV — Understanding how to govern AI deployment and use | 21–25 | IV.A deployment decisions & model choices (6–8) · IV.B deployer assessments & vendor risk (5–7) · IV.C monitoring, communication & deactivation (9–11) | Choosing, contracting for, operating, and — when needed — switching off AI |
Two readings of this table should shape your entire study plan.
First: the operational half outweighs the legal half. Domains III and IV together supply 42–50 questions — up to half the exam — and they test program mechanics: impact assessments, data documentation, testing regimes, post-market monitoring, vendor contracts, deactivation controls. Candidates from legal backgrounds routinely over-study Domain II because it feels like the “real” material. The blueprint says otherwise.
Second: the competency ranges are targeting data. IV.C alone (9–11 questions) is worth more than the whole of II.D (3–5). When your practice scores arrive broken down by domain, these ranges tell you exactly where a weak area costs you most.
The BoK also names its in-scope instruments: the EU AI Act, the South Korean AI Basic Law, and US federal and state AI laws applying to the private sector; the OECD trustworthy-AI framework; NIST AI RMF and its Playbook; and ISO/IEC 22989, 42001 and 42005. Generative and agentic AI are explicitly in scope across all domains.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.