What the AIGP is — and why employers care
Lesson 1 of 5 in The AIGP Credential: Exam Anatomy, Logistics, and Study Strategy.
The AIGP — Artificial Intelligence Governance Professional — is the IAPP’s certification for people who run responsible-AI programs. The IAPP built its reputation certifying privacy professionals (CIPP/E, CIPM, CIPT); when AI regulation arrived, its AI Governance Center did the same for AI — making the AIGP the first major vendor-neutral AI governance credential on the market.
Read that phrase carefully, because it tells you what the exam is and is not. Vendor-neutral means no product knowledge: you will never be asked how to configure a tool. Governance means the exam tests judgment — which law applies, which control fits, which stakeholder owns the risk — not how to train a model. You need to understand what a foundation model or drift is, but you will never write code.
Privacy professional (CIPP/E, CIPM holder)
The most common on-ramp. Roughly a third of the exam’s legal material extends what you already know — lawful basis, DPIAs, automated decision-making, minimization — into AI contexts. Your gap is usually the technical vocabulary of Domain I and the development-governance detail of Domain III: model cards, red teaming, drift, testing types.
Legal and compliance counsel
You will find Domain II familiar in shape (statutes, obligations, penalties) but broad in coverage: the exam names the EU AI Act, the South Korean AI Basic Law, and US federal and state law in a single competency. Your gap is the operational half — Domains III and IV together carry the largest share of questions, and they test program mechanics, not legal analysis.
Risk, audit, and security managers
Frameworks are your home turf — NIST AI RMF, ISO/IEC 42001, impact assessments, lines of defense. Expect to invest in Domain II’s legal specifics (which law, which threshold, which role) and in AI-specific failure modes like hallucination and data poisoning that classic IT risk taxonomies miss.
Product, data, and engineering leaders
You know how systems get built; the exam asks how they get governed. Domain I’s definitions will feel easy. Budget most of your time for Domain II — the law-and-frameworks domain is where technologists lose the most points, usually on role distinctions (provider vs deployer) and on which obligation attaches to which actor.
Why bother? Because AI governance hiring outran the supply of people who can prove they know it. Job postings for AI governance leads, responsible-AI managers, and EU AI Act compliance roles increasingly list the AIGP by name — the same pattern the CIPP/E followed after the GDPR. A certification is never the competence itself, but it is the legible signal of it, and in a field two years old, legible signals are scarce.
The exam is maintained by the AIGP Exam Development Board — practitioners who review the Body of Knowledge on an annual cycle. Changes are announced at least 90 days before they can appear on the exam, which is your protection against studying the wrong material. The next lesson shows why that protection matters more for the AIGP than for almost any other certification right now.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.