⭐ Trusted by 700+ Buyers  ·  4.7★ Star Seller on Etsy  ·  $9.99/exam  ·  Grab it now →
Home › IAPP › AIGP study guide

IAPP AIGP (Artificial Intelligence Governance Professional) Practice Test & Study Guide

Everything you need to plan your AIGP prep: the exam format, what each domain covers, a week-by-week study plan, original practice questions, and what thousands of study-group comments reveal about where candidates slip up.

Last updated · By the NotJustExam team

About the IAPP AIGP (Artificial Intelligence Governance Professional) exam

The IAPP AIGP credential validates that you can help an organization build, deploy, and oversee AI systems responsibly. Rather than testing how to engineer models, it focuses on governance: understanding what AI and machine learning actually do, recognizing their legal and ethical risks, and putting controls in place across the full AI lifecycle. It sits alongside IAPP's privacy certifications (CIPP, CIPM) but targets the distinct discipline of AI accountability.

The exam suits privacy professionals expanding into AI oversight, risk and compliance staff, legal and policy specialists, product and program managers shipping AI features, and security professionals asked to evaluate AI risk. It assumes you work with AI governance in some capacity, but it does not require a data-science background.

AIGP matters because regulation is moving quickly. With frameworks such as the EU AI Act and the NIST AI Risk Management Framework shaping expectations, organizations need people who can translate principles into repeatable controls. AIGP is one of the first vendor-neutral certifications built specifically for that role.

IAPP AIGP (Artificial Intelligence Governance Professional) exam format at a glance

The figures below reflect the exam as of 2026; always verify the current details on the official IAPP AIGP page before you register.

AttributeDetail (verify on official page)
Exam nameArtificial Intelligence Governance Professional (AIGP)
QuestionsApproximately 100 total questions, including a small number of unscored pretest items (roughly 90 scored)
Question typesMultiple choice (single best answer)
DurationAbout 2.5 hours (roughly 150 minutes)
Passing scoreScaled score of 300 on a 100–500 scale
CostAround USD 799 non-member (IAPP members typically pay less; bundle pricing varies)
LanguagesEnglish
DeliveryPearson VUE test center or online proctored
Validity / recertificationMaintained via annual maintenance fee plus continuing-education (CPE) credits over a two-year cycle

IAPP AIGP (Artificial Intelligence Governance Professional) domains & what they cover

The body of knowledge is organized into several domains. Weightings below are approximate and may be revised, so confirm on the official IAPP page.

  • Foundations of AI (roughly 15–20%) — Core concepts behind AI and machine learning, common model types, and the basic vocabulary you need to discuss systems credibly with technical teams.
  • AI impacts and responsible AI principles (roughly 20–25%) — How AI affects people and society, including fairness, transparency, accountability, and the principles that underpin trustworthy AI.
  • AI governance and the law (roughly 20%) — The regulatory and policy landscape, such as risk-based frameworks and major legal instruments shaping how AI may be built and used.
  • Implementing AI governance across the lifecycle (roughly 20–25%) — Embedding controls from planning and data sourcing through design, testing, deployment, and decommissioning.
  • Ongoing oversight and risk management (roughly 15–20%) — Monitoring deployed systems, managing third-party and supply-chain risk, incident response, and continuous improvement of governance programs.

How hard is IAPP AIGP (Artificial Intelligence Governance Professional)?

AIGP is moderately challenging. Most of the difficulty comes from breadth rather than depth: you move between technical fundamentals, ethics, law, and operational process, and the questions reward people who can connect those threads instead of memorizing definitions.

Common sticking points are the distinctions between similar governance frameworks, applying a risk-based mindset to scenario questions, and keeping technical concepts straight if you come from a pure policy or legal background. Conversely, engineers often underestimate the regulatory and ethics material.

A realistic preparation window is four to six weeks of part-time study for someone already working near AI or privacy, and closer to eight weeks for a newcomer to the field.

How to prepare for IAPP AIGP (Artificial Intelligence Governance Professional): a study plan

  1. Week 1 — Map the territory. Read the official body of knowledge and build a one-page outline of every domain. Note which areas are unfamiliar so you can budget time accordingly.
  2. Week 2 — Foundations and principles. Lock in AI/ML basics and responsible-AI concepts. Summarize each principle in a sentence of your own; if you cannot, you do not understand it yet.
  3. Week 3 — Law and frameworks. Study the major regulatory instruments and risk frameworks side by side. Build a comparison table so overlapping concepts stop blurring together.
  4. Week 4 — Lifecycle and operations. Walk through how governance controls attach to each lifecycle stage, and how monitoring and incident response work after deployment.
  5. Weeks 5–6 — Practice and review. Take timed practice questions, then study every miss until you can explain why the right answer is right and the others are wrong.

Use practice questions diagnostically, not as a memorization shortcut. Track which domain each miss belongs to, return to the source material for that topic, and re-test. Treat full-length timed sets in the final week as rehearsals for the 2.5-hour sitting.

IAPP AIGP (Artificial Intelligence Governance Professional) FAQ

Are there prerequisites for the AIGP?

No formal prerequisites are required. IAPP assumes some exposure to AI governance, privacy, or risk work, but you do not need a prior certification or a technical degree to sit the exam.

How much does the AIGP cost?

As of 2026 the exam is around USD 799, with different rates for IAPP members and for bundles that include training. Verify current pricing on the official IAPP page before registering.

How long is the certification valid?

AIGP is maintained rather than expiring outright. You keep it active by paying an annual maintenance fee and earning continuing-education (CPE) credits within a two-year cycle. Confirm the exact requirements with IAPP.

What is the retake policy if I fail?

Candidates who do not pass may retest after a waiting period and by paying a retake fee. The specific interval and fee are set by IAPP, so check the current policy before booking a second attempt.

Can I take the exam online?

Yes. The exam is delivered through Pearson VUE either at a test center or via online proctoring, so you can choose the format that suits your setup.

Is the AIGP worth it?

For people whose roles touch AI compliance, risk, product, or policy, AIGP is a strong signal because it is purpose-built and vendor-neutral at a time when AI governance demand is rising. Its value is lower if your work never intersects with AI oversight.

Free AIGP practice questions

5 original questions written for NotJustExam from the public AIGP exam objectives and independently answer-checked. Try answering before you open the explanation.

Question 1

A governance professional is briefed that a new fraud-detection model was trained on a large set of past transactions that were each already labeled 'fraud' or 'not fraud' by human reviewers. Which type of machine learning approach was used to train this model?

  1. Unsupervised learning
  2. Supervised learning
  3. Reinforcement learning
  4. Federated learning
Show answer & explanation

Answer: B. Supervised learning trains a model on labeled examples, where each input already has a known correct output, which matches training on transactions pre-labeled as fraud or not fraud. Unsupervised learning is a common wrong pick because it also processes historical data, but it works on unlabeled data to find patterns or clusters, without any pre-assigned correct answers to learn from.

Source: official documentation

Question 2

An AI-powered hiring tool is found to systematically rank candidates from a particular demographic group lower, even though that attribute was never included in the input data. What is the most likely explanation for this outcome?

  1. The model is using a proxy variable correlated with the protected attribute
  2. The model is experiencing normal statistical variance with no underlying pattern
  3. The model's outputs are encrypted and cannot reflect bias
  4. The model was not deployed to production yet
Show answer & explanation

Answer: A. Even when a protected attribute is excluded, a model can learn a proxy variable, such as a zip code or a school name, that correlates strongly with that attribute, reproducing discriminatory outcomes indirectly. Attributing it to normal statistical variance is a common but incorrect assumption, because a systematic, consistent disadvantage for one group is a hallmark of bias, not random noise.

Source: official documentation

Question 3

Under the EU AI Act's risk-based approach, which category of AI systems is subject to the strictest requirements, including conformity assessments before being placed on the market?

  1. Minimal-risk AI systems
  2. Limited-risk AI systems with transparency obligations only
  3. High-risk AI systems
  4. AI systems used purely for internal research with no deployment
Show answer & explanation

Answer: C. The EU AI Act's risk-based framework imposes the strictest obligations, including mandatory conformity assessments, on high-risk AI systems, such as those used in employment, credit scoring, or critical infrastructure. Limited-risk systems are a tempting distractor because they do carry some obligations, but those are narrower transparency requirements (like disclosing that content is AI-generated), not full conformity assessments.

Source: official documentation

Question 4

Before deploying a new AI system that will make automated decisions affecting individuals, an organization wants to systematically evaluate potential harms to those individuals and identify mitigation steps. Which activity best accomplishes this?

  1. A financial cost-benefit analysis
  2. An algorithmic or AI impact assessment
  3. A marketing readiness review
  4. A code style and linting review
Show answer & explanation

Answer: B. An algorithmic or AI impact assessment is specifically designed to evaluate the potential effects of an AI system on individuals and society before deployment, and to surface mitigations for identified risks. A financial cost-benefit analysis is a plausible-sounding distractor because it is also a pre-deployment evaluation, but it focuses on monetary trade-offs rather than harms to individuals.

Source: official documentation

Question 5

An organization notices that a deployed AI model's accuracy on real-world data has gradually declined over several months, even though the model itself has not been changed. What is this phenomenon typically called?

  1. Model drift
  2. Overfitting
  3. Data minimization
  4. Model interpretability
Show answer & explanation

Answer: A. Model drift (including data drift and concept drift) occurs when the real-world data or relationships a model encounters change over time, causing its performance to degrade even without any change to the model itself. Overfitting is a common mix-up because it also affects accuracy, but it describes a model that performs well on training data yet poorly on new data from the start, not a gradual decline after deployment.

Source: official documentation

What 154 study-group comments reveal about AIGP

We summarised the public study-group discussion behind every question in our AIGP bank and compared it with an independent AI review. Where they disagree, a posted answer key alone is not enough to trust — which is why every question in the full bank shows the community vote, a discussion summary and a reasoned explanation side by side.

126practice questions reviewed
154study-group comments summarised
6%of questions where the answer commonly posted online is disputed
0%of single-answer questions where the community vote is split

The AIGP traps that come up most

  • Robustness, reliability, and resilience are distinct — Robustness means performing well under adversarial or challenging conditions, reliability means consistent performance under normal conditions, and resilience means recovering after a failure — treat these as separate concepts, not synonyms.
  • Validation set tunes; test set gives a final check — The validation set is used during development to tune parameters and catch overfitting, while the test set gives one final, unbiased performance check on unseen data right before deployment.
  • Removing a protected attribute alone doesn't remove bias — Deleting a protected attribute such as gender from training data often fails to eliminate bias, because correlated proxy variables can let the model infer that attribute indirectly.
  • AI provider and deployer carry different obligations — Under risk-based AI frameworks, the party that builds or trains a model typically carries different compliance duties than the party that deploys it operationally — accountability is shared, not held by one side alone.
  • General-purpose model duties differ from high-risk system duties — Providers of general-purpose AI models face documentation and training-data-summary obligations, while operators of high-risk AI systems face separate duties like conformity assessments and retained logs — the two obligation sets are not interchangeable.

Inside the full AIGP practice bank

  • 126 practice questions in an interactive web app, plus a printable PDF
  • The community-voted answer and a summary of the study-group discussion for each question
  • A step-by-step AI explanation of why the right answer is right — and why the others are not
  • One-time $9.99, lifetime access, no subscription

More certification study guides

Independent study material. NotJustExam is not affiliated with, endorsed by, or sponsored by any certification body; all certification names, trademarks and exam codes belong to their owners and are used for descriptive purposes only. The sample questions on this page are original items written for NotJustExam from the publicly available exam objectives. Exam facts change — always confirm details on the official exam page before you register.