Quick Answer

In your last 7 days before the AIGP: run a full timed mock exam on Day 7 to identify gaps, then spend Days 5–6 on EU AI Act key articles and NIST AI RMF function precision, Days 3–4 on weak-domain gap-fill and Singapore/ISO 42001, Day 2 on active recall only (no new material), and Day 1 on a light warm-up only. The cram phase is about consolidation and pattern recognition — not adding new content.

You have 7 days before the AIGP. This guide tells you exactly what to do each day, what the highest-yield content zones are, what to stop doing, and includes 6 real exam-style practice questions representative of what you'll see on the actual test. If you're at this stage, you've done the main study phase — this is the finishing sprint.

AIGP Exam Domain Weights — Where to Focus Your Last 7 Days D1 Foundations 20% D2 Governance Program 25% D3 AI Risk Mgmt 22% D4 Laws & Regs 18% D5 Ethics 15% 20% 25% ★ Highest 22% 18% 15% 0% 10% 20% 25% Last-Week Priority Order: ① D2 Governance ② D3 Risk Mgmt ③ D1 Foundations ④ D4 Laws ⑤ D5 Ethics Focus first where point density is highest (D2 + D3 = 47% of exam)

Figure 1 — AIGP domain weight distribution and recommended last-week priority order

The 7-Day AIGP Cram Schedule

7-Day AIGP Pre-Exam Timeline D7 Full Mock D6 EU AI Act Articles D5 NIST AI RMF Drills D4 Weak Domain D3 Singapore + ISO 42001 D2 Active Recall Only D1 Exam Day Diagnose High-density review Gap-fill Consolidate Execute

Figure 2 — Day-by-day cram timeline: diagnose → high-density review → gap-fill → consolidate → execute

Day 7 — Full Timed Mock Exam

Sit a full 90-question timed mock exam under real conditions: 150 minutes, no pauses, no reference materials, no phone. Treat it as the real exam. When it's done, review every wrong answer explanation immediately — not just whether you got it right, but why the wrong options were wrong. This session is the most valuable diagnostic you can run in your final week. It identifies your specific gaps with 6 days left to address them.

After your review, categorize your wrong answers by domain. If you got 8 Domain 2 questions wrong and 2 Domain 4 questions wrong, those numbers tell you exactly where to spend Days 4 and 3. Don't let the domain breakdown be a guess — track it precisely.

Day 6 — EU AI Act Key Articles (Deep Review)

The EU AI Act appears across Domain 1 (definitions), Domain 3 (risk management), and Domain 4 (regulatory landscape). In your last week, stop reading the full text of the regulation and drill the specific articles the exam tests. These are the ones that appear most frequently in AIGP exam questions:

  • Article 5 — Prohibited AI Practices: Know the full list: real-time remote biometric identification in public spaces (with narrow law enforcement exceptions), social scoring by public authorities, subliminal manipulation, exploitation of vulnerabilities, and emotion recognition in workplace/educational contexts. Know what's prohibited vs. what requires safeguards.
  • Article 6 + Annex III — High-Risk Classification: Two-track classification: AI systems that are safety components of products already subject to EU harmonization legislation (track 1), and AI systems in the 8 Annex III categories (track 2). Know all 8 Annex III categories.
  • Article 9 — Risk Management System: Requires a continuous, iterative risk management process for high-risk AI — identification and analysis of known and foreseeable risks, estimation and evaluation, adoption of risk management measures, and residual risk assessment. Know it applies to providers of high-risk AI.
  • Article 11 — Technical Documentation: Providers must prepare technical documentation before placing a high-risk AI system on the market. Know what it must contain (model description, design choices, training data info, performance metrics, risk mitigation measures).
  • Article 13 — Transparency for High-Risk AI: High-risk AI systems must be sufficiently transparent that deployers can interpret the system's output and use it appropriately. The transparency obligation runs to the deployer, not the end user.
  • Article 17 — Quality Management System: Providers must put in place a QMS covering design control, testing, risk management, data governance, post-market monitoring, and incident management. Must be documented and proportionate to the size of the organization.
  • Article 26 — Deployer Obligations: Deployers must: use high-risk AI systems as instructed, implement human oversight measures, monitor system performance, inform providers of incidents, and (if an employer) inform workers when AI systems affecting them are deployed. Key distinction: Article 26 = deployers; Article 16 = providers.
  • Article 27 — Fundamental Rights Impact Assessment (FRIA): Required for deployers who are public authorities (or bodies acting on their behalf) and for private entities deploying high-risk AI in specific Annex III contexts (credit, insurance, employment). Know who is required to perform it and what it must address.
  • Article 43 — Conformity Assessment: How high-risk AI systems demonstrate compliance. Most Annex III systems self-assess (internal control procedure). Some — biometric identification, certain critical infrastructure and law enforcement uses — require third-party conformity assessment by a notified body.
  • Article 73 — Serious Incident Reporting: Providers and deployers must report serious incidents to national market surveillance authorities without undue delay. The specific timeline for serious incidents (15 days for unexpected death or serious harm; 3 days where it constitutes a risk to public security) is exam-tested.
  • Article 86 — Right of Explanation: Individuals affected by decisions made with the assistance of high-risk AI systems listed in Annex III have the right to obtain an explanation of the role of the AI system in the decision-making procedure and the main elements of the decision taken.

For each article: know WHO the obligation runs to (provider, deployer, or both) and WHAT specifically it requires. The exam regularly tests provider vs. deployer distinctions.

Day 5 — NIST AI RMF Function Precision

The NIST AI RMF's four core functions — Govern, Map, Measure, Manage — appear across multiple AIGP domains. Candidates who fail the AIGP often confuse these functions in scenario-based questions. In your last week, the goal is precision on what distinguishes each function.

  • Govern establishes the organizational policies, accountability structures, roles, and culture that underpin all other AI risk management activities. It's not a lifecycle stage — it runs across the other three functions. Think: board-level AI policy, executive accountability assignment, culture of responsible AI.
  • Map identifies and categorizes the AI risks, context, and characteristics of the specific AI system. It's discovery-phase work — who are the stakeholders, what data is used, what could go wrong, what's the intended use vs. actual use. Think: risk taxonomy, use-case documentation, impact assessment scoping.
  • Measure evaluates the AI risks identified in Map using quantitative and qualitative methods. It's assessment-phase work — how severe is this risk, how likely, how does the system actually perform against defined metrics. Think: bias testing, performance benchmarking, fairness metric evaluation, red-teaming.
  • Manage implements and monitors specific risk response decisions made based on Measure outputs. It's treatment-phase work — deploying risk mitigation controls, documenting residual risk acceptance, responding to incidents, updating models. Think: corrective action plans, monitoring dashboards, incident response.

Common exam confusions to drill:

  • Map vs. Measure: Map discovers that a risk exists. Measure evaluates how bad it is. If a question asks about identifying which populations might be harmed → Map. If it asks about quantifying disparate impact rates → Measure.
  • Govern vs. Manage: Govern creates the framework. Manage executes within it. If a question asks about establishing an AI oversight policy → Govern. If it asks about responding to a specific detected model drift → Manage.
  • Govern is not the "first step" in a lifecycle sense — it's always active. It operates simultaneously with Map, Measure, and Manage.

Complete 20–25 NIST AI RMF targeted practice questions. Read every explanation — don't just tally scores.

Day 4 — Weak-Domain Gap Fill

Go back to your Day 7 mock exam domain breakdown. Which domain had the worst hit rate? Spend today entirely on that domain. If your mock exam didn't break down by domain (or you scored evenly across all), default to Domain 2 (AI Governance Program Design — 25%) and Domain 3 (AI Risk Management — 22%), since together they represent 47% of the exam. A 5-point improvement in those two domains is worth more than a 10-point improvement in Domain 5.

Format for today: read the BOK section → do 20–25 practice questions in that domain only → read every wrong-answer explanation → note the specific concept that was tested → verify your understanding of that concept from the BOK. Targeted, not broad.

Day 3 — Singapore Framework + ISO/IEC 42001 + Ethics Definitions

Three content areas that candidates under-review and lose easy points on. They're lower volume on the exam but often appear in 2–4 questions each — questions that well-prepared candidates get right and under-prepared candidates guess on.

  • Singapore Model AI Governance Framework (2nd Edition): Published by IMDA. Know the two pillars: (1) Internal Governance Structures and Measures, and (2) Operations Management. Under Pillar 1: senior management responsibility and human oversight, understanding of AI system operation and risk. Under Pillar 2: decision-making model selection, stakeholder interaction, explainability. The exam may ask which pillar a described action falls under.
  • ISO/IEC 42001:2023: An AI management system (AIMS) standard — analogous to ISO 27001 for information security, ISO 9001 for quality. It certifies an organization's AI management processes, not a specific AI system or model. Published by ISO/IEC. Organizations can be certified to it by an accredited certification body. Know this in contrast to EU AI Act conformity assessment (regulatory) vs. ISO 42001 certification (voluntary management system standard).
  • Domain 5 BOK Definitions (memorize the exact framing):
    • Explainability: The degree to which an explanation of how an AI system arrived at a specific output or decision can be provided in terms that are understandable to the audience.
    • Transparency: Disclosure of information about an AI system's capabilities, limitations, and use of data — to relevant stakeholders.
    • Accountability: Clear assignment of responsibility for AI systems' behavior and for addressing harms caused.
    • Human Oversight: The ability of humans to monitor, audit, intervene in, and shut down AI system operations when needed.
    • Redress: Mechanisms that allow individuals affected by AI decisions to seek review, correction, or remedy.
Day 2 — Active Recall Only. No New Material.

Stop adding content. Today is for retrieval practice only. Without looking at your notes, write down: the 5 AIGP domain names and approximate percentages. The EU AI Act risk tiers (unacceptable, high, limited, minimal). The NIST AI RMF four functions and one sentence on each. The 5 OECD AI Principles. The 8 Annex III categories from the EU AI Act. Then check each one against your notes. Any gap you find: read it once and move on. Don't drill. Don't add new content. If you're testing via OnVUE, confirm your workspace setup today: check that your ID is accessible, your room is clear, your internet is stable, and you've done the system check.

Day 1 — Exam Day: Light Warm-Up Only

Read your cram list once — the condensed definitions and key provisions, not the full BOK. Log in 15 minutes early. Read the full question stem before looking at answer choices. Eliminate obviously wrong options first. Flag uncertain questions and return to them at the end. Do not change answers without a specific, articulable reason. Trust the preparation already done — your score is determined by the hours you've put in, not by what you read in the final hour.

What to Stop Doing in Your Last Week

Stop doing thisWhy it hurtsDo this instead
Starting a new BOK section you haven't readNew material at this stage creates confusion — you can't process it with the depth needed to answer questions correctlyDeepen mastery of material you've already studied
Doing practice questions without reading explanationsVolume without comprehension is wasted time. 20 questions reviewed thoroughly beats 60 skimmed for right/wrongRead every explanation, including for correct answers
Studying more than 3 hours in a single sessionRetention drops after 90–120 minutes of focused study. Fatigue creates false confidence in material you haven't retainedThree 45-minute focused blocks with 10-minute breaks
Memorizing the EU AI Act verbatimThe exam tests application, not recitation. You need to know what Article 9 requires when applied to a scenario — not its exact wordingPractice applying article requirements to scenarios
Staying up past midnight the night beforeSleep consolidates memory. 8 hours of sleep contributes more to exam performance than 4 hours of late-night reviewingFinish by 9pm, sleep by 10pm. Non-negotiable.
Relying only on passive readingReading feels like studying but doesn't build retrieval ability. The exam requires active recall under time pressurePractice questions and active recall exercises (write-it-from-memory)

6 Exam-Style AIGP Practice Questions for Your Last Week

These questions are representative of actual AIGP exam format and difficulty. Work through each one before reading the answer.

Practice Question 1 — EU AI Act / Provider vs. Deployer

A company purchases a high-risk AI system from a third-party vendor and deploys it to screen job applicants. Under the EU AI Act, which of the following obligations falls specifically on the deploying company rather than the vendor who built the system?

  • A. Preparing and maintaining technical documentation for the AI system
  • B. Conducting a pre-deployment conformity assessment of the AI system
  • C. Informing workers' representatives before the AI system is put into use
  • D. Registering the AI system in the EU database of high-risk AI systems
Answer: C. Article 26 of the EU AI Act specifies obligations for deployers of high-risk AI. Among these: informing workers (or their representatives) before deployment of AI systems that affect them. Technical documentation (A) and conformity assessment (B) are provider obligations under Articles 11 and 43. Registration in the EU database (D) is primarily a provider obligation under Article 49, with deployers having registration obligations only for certain public authority uses.
Practice Question 2 — NIST AI RMF Function Classification

An organization's AI risk team is conducting statistical analysis to determine the rate at which their loan approval model produces disparate outcomes for applicants from different demographic groups. According to the NIST AI RMF, which function does this activity primarily correspond to?

  • A. Govern
  • B. Map
  • C. Measure
  • D. Manage
Answer: C — Measure. Measure involves analyzing and assessing AI risk using quantitative and qualitative methods. Evaluating the rate of disparate outcomes is a measurement activity — it quantifies a risk that was previously identified. Map (B) would be the function where the team first identifies that disparate outcomes could be a risk. Govern (A) would be the policies requiring the organization to perform bias testing at all. Manage (D) would be the actions taken to address the disparate outcome rates once measured.
Practice Question 3 — EU AI Act Article 5 / Prohibited Practices

Which of the following AI system uses is NOT listed as a prohibited practice under Article 5 of the EU AI Act?

  • A. Subliminal manipulation below the threshold of consciousness that distorts behaviour and causes harm
  • B. Exploitation of specific vulnerabilities of persons due to age or disability to distort their behaviour in a way that causes harm
  • C. Employer monitoring of employee productivity through tracking of work outputs and task completion rates
  • D. Public authority evaluation of individuals' trustworthiness based on their social behaviour over time (social scoring)
Answer: C. Productivity monitoring AI that assesses work outputs and task completion is not listed as a prohibited practice under Article 5 — it may be subject to other requirements (transparency to workers under Article 26) but is not categorically prohibited. A and B describe prohibited manipulation and exploitation practices. D describes social scoring by public authorities, which is explicitly prohibited under Article 5(1)(c).
Practice Question 4 — AI Governance Program Design

A technology company is building its first enterprise AI governance program. The Chief AI Officer asks what should be established first before implementing AI-specific policies and procedures. Which of the following represents the most appropriate first step?

  • A. Conduct a comprehensive inventory of all AI systems currently in use across the organization
  • B. Draft an AI ethics policy and distribute it to all employees for review
  • C. Establish the organizational accountability structure: who is responsible for AI governance decisions
  • D. Select and deploy an AI risk management software platform to track AI systems
Answer: C. Establishing accountability structures — who owns AI governance, who approves AI system deployments, who is responsible for incidents — is foundational to everything that follows. You cannot conduct a meaningful AI inventory (A) without knowing who owns the process or who decisions escalate to. An ethics policy (B) without defined accountability is unenforceable. A software platform (D) without a governance structure to operate it is premature. The NIST AI RMF's Govern function and CIPM program design principles both identify accountability assignment as a prerequisite step.
Practice Question 5 — Serious Incident Reporting

Under the EU AI Act, a deployer of a high-risk AI system used in a medical device context discovers that an AI-assisted diagnostic recommendation led to a patient receiving incorrect treatment, resulting in serious injury. What is the deployer's primary reporting obligation?

  • A. Notify the provider of the AI system within 3 working days
  • B. Report the serious incident to the relevant national market surveillance authority without undue delay
  • C. Submit a mandatory DPIA to the competent supervisory authority within 72 hours
  • D. Register the incident in the EU high-risk AI system database within 15 days
Answer: B. Article 73 of the EU AI Act requires providers and deployers to report serious incidents to the relevant national market surveillance authority without undue delay. The 15-day timeline (Article 73(3)) applies specifically to incidents involving unexpected death or serious harm — but the reporting obligation itself goes to the market surveillance authority, not the provider or the EU database. A DPIA (C) is a GDPR-origin instrument, not an EU AI Act incident reporting mechanism. Notifying the provider (A) may also be required but is not the primary regulatory reporting obligation.
Practice Question 6 — Ethics / Explainability vs. Transparency

An individual is denied a loan based on an AI-assisted credit assessment. They ask the lending institution to explain why they were denied. The institution provides a general statement that "AI was used in the decision process" but does not describe how the AI system evaluated their application or what factors influenced the outcome. Which AI ethics principle has most directly been undermined?

  • A. Accountability
  • B. Human oversight
  • C. Explainability
  • D. Transparency
Answer: C — Explainability. Explainability is the ability to describe how an AI system arrived at a specific output in terms understandable to the recipient. The institution disclosed that AI was used (minimal transparency — D) but failed to explain how it produced the outcome for this individual's application. Explainability is the more specific principle at issue — and under Article 86 of the EU AI Act, affected individuals have a right to an explanation in this context. Accountability (A) concerns responsibility assignment. Human oversight (B) concerns the ability to intervene in AI decisions — not the right to an explanation.

Highest-Yield Last-Week Content by Domain

DomainWeightLast-week priority contentCommon loss areas
D1: AI Technology Foundations~20%EU AI Act risk tiers; definitions of AI system vs. GPAI model; OECD AI Principles (5); AI types; prohibited practice categoriesConfusing AI system vs. GPAI model definition; missing the nuance in Article 5 prohibited vs. restricted uses
D2: AI Governance Program~25%AI inventory scope and maintenance; accountability structure design; board reporting; integration with existing risk and privacy frameworks; third-party AI due diligenceSequencing errors (what to do first vs. second); confusing governance design (D2) with risk measurement (D3)
D3: AI Risk Management~22%NIST AI RMF Govern/Map/Measure/Manage distinctions; FRIA triggers and scope; bias metrics (disparate impact vs. disparate treatment); model drift definition and response; AI incident classificationMap vs. Measure confusion; Govern vs. Manage confusion; not knowing FRIA triggers precisely
D4: Laws and Regulations~18%EU AI Act Articles 5, 6, 9, 11, 13, 26, 27, 43, 73, 86; Singapore Model AI Governance Framework two pillars; ISO/IEC 42001 purpose; OECD 5 AI PrinciplesProvider vs. deployer obligation confusion; not knowing Article 73 timeline details; ISO 42001 vs. EU AI Act conformity assessment distinction
D5: Ethics and Accountability~15%BOK definitions: explainability, transparency, accountability, human oversight, redress; human rights + AI intersection; audit trail governance purposeConflating explainability and transparency; not knowing the Article 86 right of explanation applies to high-risk AI in Annex III contexts

Everything you need to prep for the 2026 AIGP, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →

Bottom Line for Your Last 7 Days

Don't add new material. Deepen what you already know. The candidates who fail the AIGP in their final week typically made one of two mistakes: they spent their last days reading new BOK sections they'd never covered, or they did practice questions without reading explanations. The candidates who pass spend their last 7 days consolidating, simulating, and recalling. Follow this schedule and you are not leaving points on the table in your final stretch.

Frequently Asked Questions

Can you pass the AIGP with only one week of preparation remaining?

If you've completed your primary study phase — 60–100+ hours with the BOK and practice questions — then one week is a consolidation and simulation sprint, not a full preparation period. It absolutely matters and can make the difference between pass and fail. If you haven't done your primary study yet, one week is not enough to prepare from scratch. The AIGP draws on detailed knowledge of the EU AI Act, NIST AI RMF, and organizational governance frameworks that takes weeks to build.

How many practice questions should you complete in your last week?

Quality matters more than volume in the final week. Aim for 150–200 questions total over the 7 days — but with full explanation review for every question. That's 20–30 questions per day on study days. Doing 500 questions without reading explanations in the final week is worse than doing 150 questions with thorough review. The Archuz question bank includes 300 questions calibrated to AIGP BOK v2.1 domain weights, with detailed explanations for both correct and incorrect options.

What is the AIGP passing score?

The AIGP uses a scaled scoring system. The passing score is 300 on a scale of 100–500. Because of scaled scoring, you cannot calculate the passing percentage directly from number of questions correct — it depends on the difficulty calibration of the specific exam form you receive. The general estimate is that scoring correctly on approximately 65–70% of questions is sufficient to pass, but this varies.

What is allowed on your desk during the AIGP OnVUE online exam?

For OnVUE proctored exams: typically one piece of scratch paper and one pen/pencil (check the current IAPP policy before exam day, as this can change). No notes, no study materials, no second monitor. Your desk must be clear except for your ID and any permitted items. Water in a clear glass is generally permitted but verify with IAPP's current OnVUE policy.

Is the AIGP cram guide from Archuz part of the prep pack?

Yes. The Archuz AIGP Complete Pack includes a structured cram guide condensing the highest-density exam content — EU AI Act key provisions with provider/deployer distinctions, NIST AI RMF function breakdowns, OECD principles, Singapore framework pillars, ISO 42001 positioning, and BOK definition precision — into a reviewable format for your final week. It's designed to work alongside the 300-question bank for the last 7 days of preparation.