Study resourcesAIGP

The complete study library

Explore the AIGP study library

Search 127 free study resources for AIGP. Find a lesson, review a term or choose a practice session.

127 resources

Guide · AIGP

AIGP Body of Knowledge 2026 explained

The four domains in the 2026 IAPP AIGP Body of Knowledge, translated into a practical study plan and exam-scenario checklist.

Guide · AIGP

AIGP exam format and blueprint

Current AIGP format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.

Guide · AIGP

AIGP exam questions

How to approach AIGP questions using context, risk, governance controls and accountability.

Guide · AIGP

AIGP practice exam

Independent AIGP practice questions, a timed-study method and an evidence-led review routine.

Guide · AIGP

AIGP study guide

Free AIGP notes and study lessons arranged around four current knowledge areas, with retrieval practice and scenario review.

Guide · AIGP

AIGP study plan

A four-week AIGP study plan using the published outline, retrieval practice and scenario questions.

Practice · AIGP

Find the AIGP areas to study next.

Take a free 10-question AIGP diagnostic. Get an immediate domain score and a personalised study plan without creating an account.

Glossary · AIGP

AIGP glossary

AIGP glossary with key AI governance terms, linked lessons and a practical way to review exam vocabulary.

Guide · AIGP

How to pass the AIGP

How to prepare for the IAPP AIGP exam using current format details, a flexible study plan, common mistakes and exam-style practice.

Guide · AIGP

Is the AIGP exam hard?

Is the AIGP exam hard? Format, pass mark, the four domain weights, where candidates struggle and a practical way to prepare.

Practice · AIGP

Free AIGP mini mock

Try 25 exam-style AIGP practice questions free, with explanations and a domain score. No account or payment required.

Practice · AIGP

Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use?

Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use? Answer with a worked explanation and related free lesson.

Lesson · AIGP

The AI system development life cycle

Seven stages from plan/design to decommissioning, with governance hooks at each. The life cycle is iterative, not linear and building AI is never a…

Lesson · AIGP

The AI family tree

Each layer is a subset of the one above: GenAI ⊂ DL ⊂ ML ⊂ AI. Agentic AI is the odd one out - it can be comprised of all categories of AI, leveraging…

Lesson · AIGP

Architectures and the buzzwords that matter

Governance pros must hold a credible conversation about architectures: transformer models (process inputs in parallel), multimodal models/LMMs (WHO 2024…

Lesson · AIGP

Four building-block terms

Data, algorithm, model and system nest inside each other and the exam tests them exactly. An algorithm produces the model; the model applies algorithms to…

Lesson · AIGP

Expert systems

An older flavour of AI that mimics a human expert in one field via a knowledge base, inference engine and user interface. The canonical example is a…

Lesson · AIGP

Five algorithms to recognise on sight

Governance pros must recognise five algorithms to talk risk: linear regression, logistic regression (binary outcome), decision trees, random forests (an…

Lesson · AIGP

The four ways machines learn

Four ML approaches: supervised (labelled), unsupervised (unlabelled), semi-supervised (small labelled + large unlabelled) and reinforcement (agent learns…

Lesson · AIGP

The intelligence ladder: ANI to ASI

Four levels of AI capability, only ANI fully real today. Broad AI is the intermediate step; AGI and ASI do not currently exist. If a question describes a…

Lesson · AIGP

Model face-offs the exam loves

Four head-to-head comparisons straight from the performance indicator: classic vs generative, proprietary vs open source, small vs large LMs, and language…

Lesson · AIGP

OECD Framework for the Classification of AI Systems

A user-friendly framework that classifies AI systems and examines their risks across five dimensions (mnemonic PEDMT). Privacy sits under People and…

Lesson · AIGP

Tech megatrends and AI

Some megatrends fuel AI, some are fuelled by it, and some raise the governance stakes. AI drives the need for PETs; blockchain is not universally…

Lesson · AIGP

Use cases and benefits

The course groups AI uses into 7 buckets: Recognition, Event detection, Forecasting, Personalisation, Interaction support, Goal-driven optimisation and…

Lesson · AIGP

What is AI

There is no single definition of AI; the exam wants the common elements that recur across definitions. AI is not a specific technology, but a branch of…

Lesson · AIGP

Why AI needs a comprehensive governance approach

Seven unique characteristics (mnemonic A COD SHiP) make AI harder to govern than ordinary software. The central governance challenge is balancing…

Lesson · AIGP

Three AI harms taxonomies

AI-specific frameworks. The Sociotechnical Harms taxonomy has five themes; the CSET AI Harm Taxonomy defines AI harm with four elements, all four must be…

Lesson · AIGP

Environmental harms

Four quantified facts - the numbers are the exam bait. Training a large model can emit over 626,000 pounds of CO₂ (~five times the lifetime emissions of…

Lesson · AIGP

Creating ethical AI in practice

The operational checklist for deciding which use cases meet an organisation's ethical principles - spanning legal review, equitable design, transparency…

Lesson · AIGP

Seven ethical issues and three foundational controls

The Seven ethical issues responsible AI must address - lawfulness, safety, bias protection, transparency, choice, human intervention, security - and the…

Lesson · AIGP

Ethics by design

Ethics by design is the sibling of privacy by design: ethical issues are resolved at the start and reassessed during deployment because risks change. The…

Lesson · AIGP

The FIPs: where all of this started

AI ethics frameworks descend from the FIPs (Fair Information Practices), originated in 1980 by the OECD Guidelines on the Protection of Privacy and…

Lesson · AIGP

Who gets harmed: the five targets

The exam frames every harm question around who is affected. The Five harm targets are individuals, groups, society, organisations and ecosystems - and…

Lesson · AIGP

Group and societal harms

Group harm is discrimination against a population subgroup; societal harm is damage to the democratic process and participation. Examples include group…

Lesson · AIGP

Harms taxonomies 101

A Harms taxonomy is a list of negative consequences that could befall a data subject or organisation - an ontological map breaking harms into constituent…

Lesson · AIGP

Individual harms and the anatomy of bias

Individual harms hit civil liberties, safety or economic opportunity, and bias is the engine. Know Implicit bias, Sampling bias and Temporal bias on…

Lesson · AIGP

AI impacts and responsible AI

Before deploying AI, governance professionals must grasp the harms it can cause. AI poses risks already understood in existing sectors, but the scale…

Lesson · AIGP

The five OECD AI Principles

The OECD AI Principles are the base layer many organisations copy into their governance frameworks. Know all five (mnemonic: Inclusive Humans Trust Robust…

Lesson · AIGP

Organisational harms

Five harm types every organisation deploying AI must price in: reputational, cultural, economic, Acceleration risk and legal. Acceleration risk is the odd…

Lesson · AIGP

Three privacy harms taxonomies

Match the name to the structure. MITRE PANOPTIC combines contextual domains and privacy activities; the Ryan Calo taxonomy splits harm into subjective vs…

Lesson · AIGP

Trustworthy AI: the HAT test

The HAT test characterises trustworthy AI as Human-centric, Accountable, Transparent, operating in an expected, legal and fair manner. Explainability and…

Lesson · AIGP

AI impact assessments and ISO 42005

The AI impact assessment (AIIA) is the severity lens: it gauges how bad mapped risks are, while a risk assessment flags which systems need extra…

Lesson · AIGP

Aligning risk strategies

New AI risk processes must slot into existing risk machinery. Determine whether AI increases existing risks or introduces new ones, decide who is…

Lesson · AIGP

Business, regulatory and legal risks

Six direct business risks: bias & discrimination, job displacement, vendor dependence, liability & accountability, lack of transparency, IP infringement…

Lesson · AIGP

Calculating risk

The working Risk formula is probability × severity. High: avoid or change; medium: explore and mitigate. Plus the four technical assessment categories and…

Lesson · AIGP

Culture and operationalising responsible AI

Six culture moves (customer value, cultural variation, responsible AI as a discipline, HR engagement, common taxonomy, knowledge resources), then the…

Lesson · AIGP

The four AI risk categories

Operational, legal, security, privacy. The Security risk card carries the most testable vocabulary: Adversarial attacks, Hallucinations, Deepfakes and…

Lesson · AIGP

The four roles: developers, providers, deployers, users

Governance responsibilities shift across the AI life cycle. Know each role's signature duties: and the terminology trap that the Colorado AI Act says…

Lesson · AIGP

Governance structure: build it, then pick a model

Five build principles (leverage existing structures, foster community, clear roles, incentivise responsible AI, evolve the programme), then the three…

Lesson · AIGP

ISO 42001 and HUDERIA

Two frameworks with different DNA: ISO/IEC 42001:2023 is an AI management system standard for any size and industry, while HUDERIA is the Council of…

Lesson · AIGP

Life cycle policies and the use case assessment

Policies must create oversight across nine areas of the AI life cycle. The Use case assessment is the front door, running NIST's Map (NIST), Measure…

Lesson · AIGP

NIST AI RMF: the full kit

The NIST AI RMF has four pieces (framework, Core, Playbook, GenAI Profile) plus NIST ARIA. Keep the two quartets separate: the NIST Core functions are…

Lesson · AIGP

Risk assessment mechanics

Greatest resources go to the highest-risk areas. The 3×3 harms matrix multiplies severity × probability for a score, tolerances vary by organisation, and…

Lesson · AIGP

Stakeholders: who sits at the table

Cross-functional collaboration is a tested performance indicator. Privacy, security, accessibility and digital safety personnel are crucial first…

Lesson · AIGP

Tailoring governance: six differentiators

There is no universal AI governance design. Six organisational factors drive the differences: company size, maturity, industry/sector, products &…

Lesson · AIGP

Training, awareness and AI literacy

Training targets the organisation's own AI use and governance, not general AI expertise, across three focus areas. AI literacy is a legal obligation under…

Lesson · AIGP

What AI governance actually is

AI governance is an organisation's approach to using laws, policies, frameworks, practices and processes at international, national and organisational…

Lesson · AIGP

Winning leadership support

Gain leadership support at the earliest opportunity. The course gives a five-step path: understand context, find champions, frame responsible AI as a…

Lesson · AIGP

China, Japan and the rest of the world

China runs a multi-layered, use-case-specific network overseen by the CAC, requiring security reviews and algorithm registration. Japan takes…

Lesson · AIGP

Conformity assessments, registration and notification

The Conformity assessment (CA) is how compliance is demonstrated for high-risk AI, underpinned by technical documentation. CAs borrow from DPIAs and…

Lesson · AIGP

Deployers, importers and distributors

Deployer obligations are fewer than a provider's but broader, centred on transparency and monitoring (EU six-month minimum log retention; FRIA in the EU…

Lesson · AIGP

The eight requirements for high-risk AI

Major AI laws converge on eight obligations for high-risk AI: risk management, data governance, technical documentation, record-keeping, transparency…

Lesson · AIGP

Enforcement and penalties

Enforcement runs through central authorities (EU AI Office, SK Ministry of Science & ICT, China's CAC), sectoral regulators and advisory bodies, using…

Lesson · AIGP

The EU AI Act and the Digital Omnibus

The EU AI Act is a risk-based regulation with extraterritorial reach. The AI Omnibus entered into force on 27 July 2026. Most of the Act applied from 2…

Lesson · AIGP

The four regulated roles

Regulation distributes duties across the supply chain: a Provider builds the system, an Importer brings it in, a Distributor passes it on, and a Deployer…

Lesson · AIGP

General-purpose AI models

General-Purpose AI (GPAI) models are trained for broad tasks and adapt into many downstream systems. EU AI Act Chapter V sets two tiers: baseline duties…

Lesson · AIGP

High risk - where most regulation lives

High risk / high-impact AI significantly affects rights, safety or access to essential services. It is allowed but under strict obligations, and the…

Lesson · AIGP

AI regulation across jurisdictions

Global AI laws share a common regulatory DNA of risk-based classification, role-based responsibilities and transparency requirements; what differs is how…

Lesson · AIGP

Limited risk and minimal risk

Limited / transparency risk means disclosure or labelling duties only - inform users they are interacting with AI, label or watermark generated content…

Lesson · AIGP

Prohibited risk and the banned list

Prohibited risk AI is inherently harmful and restricted or banned in many jurisdictions. Six categories recur, including social scoring, manipulation…

Lesson · AIGP

High-risk provider obligations

Providers carry the heaviest load because they build the system and put it on the market, so duties span the whole life cycle. Eight converging global…

Lesson · AIGP

The risk classification framework

Risk-based legislation classifies AI into four tiers - Prohibited, High, Limited, Minimal (mnemonic 'Please Handle Laws Mindfully') - and scales the…

Lesson · AIGP

South Korea's AI Basic Act

The AI Basic Act is the second comprehensive national AI law, effective January 2026. It applies duties uniformly to Business operators (Development and…

Lesson · AIGP

The United States - orders, guidance and state laws

There is no single federal AI statute. Instead: executive orders (EO 14179 replaced the rescinded EO 14110, then America's AI Action Plan), federal…

Lesson · AIGP

Anonymisation, Pseudonymisation and PETs

Recital 26 territory: anonymisation removes data from the GDPR entirely, while pseudonymisation is still personal information so GDPR obligations apply…

Lesson · AIGP

Article 22 and Automated Decision-Making

Article 22 is a general prohibition with three exceptions, never an outright ban: automated decision-making is allowed only when necessary for a Contract…

Lesson · AIGP

Consumer Protection Laws and AI

The FTC's broad authority over "unfair or deceptive" practices already covers algorithms, and the agency will keep applying it to AI. Several US laws…

Lesson · AIGP

Obligations on Data Controllers

Controllers decide what and how personal data is processed - whether a human or an AI does the processing, the GDPR still applies. Nine duty areas span…

Lesson · AIGP

The EDPB Opinion on AI Models (2024)

Prompted by the Irish DPA, the European Data Protection Board harmonised how the GDPR treats AI models in three answers: when a model is anonymous, when…

Lesson · AIGP

The GDPR and AI

In effect since 2018, the GDPR is the global baseline for data protection, deliberately technology-agnostic so it can evolve alongside AI. Three…

Lesson · AIGP

Intellectual Property and AI

IP is creations of the human mind protected by patents, copyright and trademarks - and generative AI stretches every part of that definition. Key anchors…

Lesson · AIGP

The Lay of the Land

AI may dodge a dedicated statute, but it lives in the same legal context as every other technology: ALL existing laws for a sector or jurisdiction still…

Lesson · AIGP

Licensing AI Models and Data

The contract is where IP risk gets managed. Traditional IP indemnities break down for AI because they exclude modifications, combinations and out-of-scope…

Lesson · AIGP

Nondiscrimination Laws Across Five Sectors

Sector nondiscrimination laws still apply to AI across healthcare, insurance, hiring, credit and housing. Key anchors: Section 1557 (healthcare), NYC…

Lesson · AIGP

Privacy Principles That Govern AI

GDPR, CCPA/CPRA, US state privacy laws, biometrics laws like Illinois BIPA and breach laws all reach consumer-facing AI. Seven principles do the heavy…

Lesson · AIGP

Product Liability Foundations

Who answers when AI causes harm? Two regimes: fault liability (prove an action/inaction caused harm) and strict liability (no-fault - prove only defect…

Lesson · AIGP

The Revised Product Liability Directive

Directive 2024/2853, effective December 2026, makes it easier for victims of AI-caused harm to prove liability and get compensated. It expands "products"…

Lesson · AIGP

Sensitive and Special Categories of Data

Special categories of data need extra protection under the GDPR and Brazil's LGPD - eight types captured by the mnemonic "Really Private Records Take…

Lesson · AIGP

Building, Training and the Three Lines of Defence

Development is iterative - train, test, fine-tune, then prove the model generalises on new data beyond the training set. Human oversight uses the 3LOD…

Lesson · AIGP

Data Formats and the Five V's

Know the three structure types (structured, unstructured, semi-structured), the static/streaming split, and the five V's of data preparation: Volume…

Lesson · AIGP

Governing the AI Data Life Cycle

Data governance spans ingestion to decommissioning with cross-functional stewardship. The data life cycle runs Collection: Use: Disclosure: Retention…

Lesson · AIGP

Data Questions, Quality, Jurisdiction and Lineage

Without the right, enough and accurate data the system won't perform - garbage in, garbage out. Anticipate jurisdiction (data localisation laws, KYC), and…

Lesson · AIGP

Documentation, Communication and Decommissioning

Document every decision with model cards, counterfactual explanations and remediation owners; communicate by audience; and retire systems via ten…

Lesson · AIGP

Features and Feature Engineering

A feature is a specific measurable aspect or characteristic. Feature engineering decides which ones matter, with three purposes - improve performance (the…

Lesson · AIGP

Impact Assessments in the Design Phase

An impact assessment is a risk management tool assessing an AI system's benefits, risks and limitations across the life cycle. The AIA covers data issues…

Lesson · AIGP

The AI Development Life Cycle Revisited

AI development mirrors the software life cycle plus a data obsession and continuous monitoring. Policies, procedures, best practices and ethics apply at…

Lesson · AIGP

Metrics, Thresholds, Audits and Monitoring

Establish measures (e.g. the Adverse Impact Ratio), set thresholds, baseline, then monitor over time. Audits assess performance, reliability and safety…

Lesson · AIGP

Operational Controls - Five Owners to Name

Controls are only real when someone owns them. The memorable owner is the kill switch - a named person with authority to shut the system down when an AI…

Lesson · AIGP

Planning Essentials - The Five Moves

Define objectives, pick use cases, scope, check the data, stand up governance - in that order. Scope is prioritised via Impact, Effort and Fit, and…

Lesson · AIGP

The Six Risk Assessment Strategies, In Order

A repeatable sequence - Use Smart Methods, Handle Big Projects - to identify, evaluate, treat and mitigate risk: use case evaluation, stakeholder mapping…

Lesson · AIGP

Stakeholders - Who, What, and the Hard Calls

Engage stakeholders early, agree the goal, and decide who owns the failures. When values clash - e.g. more accuracy than privacy - the organisation must…

Lesson · AIGP

Testing and Validation

Testing is continuous, risk-tailored and documented - test for accuracy, robustness, reliability, privacy, interpretability, safety, security and bias…

Lesson · AIGP

Wrangling the Data

Five considerations turn raw data into model-ready data without trampling privacy: cleansing, labelling, anonymisation and minimisation. Master the two…

Lesson · AIGP

Adapting existing policies for AI

Review the current policy framework for gaps first, then tailor what exists and add what's missing across five areas - data privacy, security…

Lesson · AIGP

Agentic AI - what it is

Agentic systems engage, interact and influence rather than sit passively. AI agents focus on specific tasks with simple workflows; Agentic AI involves…

Lesson · AIGP

The agentic risk landscape

Autonomy brings four new risk families: goal misalignment (right goal, wrong way), compounded systemic impact (errors spread across departments and…

Lesson · AIGP

Where the model lives - three environments

The deployment environment depends on budget, IT expertise, model purpose and data type. Cloud scales, on-prem controls, edge localises - each buys one…

Lesson · AIGP

GenAI choices and the pre-launch checklist

Generative deployments add their own questions - fine-tuning, retrieval-augmented generation, vector/graph databases and agentic architectures…

Lesson · AIGP

Incidents, consequences and accountability

Treat every occurrence as an incident, keep records in an AI registrar, and know the five usual causes - brittleness, lack of robustness, lack of quality…

Lesson · AIGP

Governing AI deployment

Whatever was built, bought or customised, every organisation deploys AI as the final step before use. Deployment is the transition from a development and…

Lesson · AIGP

Monitoring, maintenance and drift

Watch for deviations in accuracy and model drift - when the relationship between input data and output predictions changes over time. Model cards document…

Lesson · AIGP

Periodic assessment - performance, reliability, safety

Three assessment lanes keep an ageing model in check: performance, reliability and safety. Four definitions recur: red teaming (simulated adversarial…

Lesson · AIGP

Deploying a proprietary model

Developing AND deploying your own model creates a dual role with heightened liability from both providing and using the technology. It brings five…

Lesson · AIGP

Public disclosures and transparency obligations

One notice never fits all, but one rule is near-universal: almost all AI laws worldwide require disclosure that AI is in place, treated by the FTC as a…

Lesson · AIGP

Release readiness

A readiness assessment decides whether the system goes to production. Well-Tested Code Deserves Model-cards - Works as intended, Testing turned out well…

Lesson · AIGP

Third-party products and risk

Less visibility never means less responsibility. Third-party AI splits into two contexts - integrated into business operations (needs the more…

Lesson · AIGP

The three-tier guardrail framework

Guardrails scale with use-case risk: Foundation: Risk: Society. Tier 1 foundational guardrails apply to every system and follow ISO/IEC 42001 and the NIST…

Lesson · AIGP

The vendor / open-source agreement checklist

Eight areas to evaluate before signing a vendor or open-source agreement: data considerations, security/safety, bias metrics, product type, technical…

Lesson · AIGP

Core AI concepts

The foundation layer of the AIGP vocabulary: what AI is, what it runs on, and its classic forms. Artificial intelligence is defined as machine-based…

Lesson · AIGP

Data terms

Everything the model eats, before and after cooking. Know which dataset does which job: training data teaches, validation data tunes and checks…

Lesson · AIGP

Generative AI

The GenAI stack from foundation model to prompt - architecture names matter here. RAG is defined by retrieving from a knowledge base beyond the training…

Lesson · AIGP

Governance, assurance and oversight

The accountability vocabulary - who answers, who checks, who can challenge. Conformity assessment is the EU AI Act gate for high-risk systems before…

Lesson · AIGP

Learning techniques and methods

The named techniques and model types that show up as one-line scenario answers - including federated learning (data never leaves the site), transfer…

Lesson · AIGP

Machine learning families

The four learning paradigms plus the architecture they run on. Label availability is the sorting key: supervised uses labelled pairs, unsupervised finds…

Lesson · AIGP

Model mechanics and performance

What is inside the model and how its behaviour is measured and goes wrong. Variables live in the data; parameters and weights live in the model - and…

Lesson · AIGP

Risks, security and harms

The attack surface and the falsehood family. Intent is the dividing line: disinformation is deliberate, misinformation is not - and data poisoning is an…

Lesson · AIGP

Trust attributes and safeguards

The qualities systems must show and the artifacts and controls that prove or protect them. Reliability is consistency over time; robustness is resilience…

Looking for AI governance? Explore the AIGP study guide.