Quick Answer

Allocate your AIGP study time in proportion to domain weights: Domain 2 (25%) gets the most time — approximately 20 hours in an 80-hour plan. Domain 3 (22%) gets ~18 hours. Domain 1 (20%) gets ~16 hours. Domain 4 (18%) gets ~14 hours. Domain 5 (15%) gets ~12 hours. The candidates who fail the AIGP typically study each domain equally (20% each) rather than front-loading the highest-weight domains. Domain-weighted study is not just strategy — it is the correct reflection of where exam questions actually come from.

The AIGP exam draws its 90 questions from five domains in proportion to their published weights. If you study each domain equally, you're misallocating your time — you're spending 20% of study hours on Domain 5 (which accounts for only 15% of the exam) and only 20% on Domain 2 (which accounts for 25% of the exam). Over 80 study hours, that's a 4-hour misallocation per domain — material at this level. This guide covers the domain weights, what each domain actually tests, a study hour allocation formula, and 5 practice questions representative of the domains where time allocation matters most.

AIGP Exam Domain Weights (BOK v2.1)

AIGP BOK v2.1 — Domain Structure Domain 1 AI Technology Foundations AI types, ML, LLMs, data ops Domain 2 ★ AI Governance Program Design Accountability, AI inventory, policy Domain 3 AI Risk Management NIST AI RMF, FRIA, bias, drift Domain 4 Laws & Regulations EU AI Act, Singapore, ISO 42001 Domain 5 Ethics & Accountab. Explain., oversight ~20% ~25% ~22% ~18% ~15% BOK v2.1 — current version as of 2026 AIGP examinations ★ = Highest weight domain; receive proportionally more study time

Figure 1 — AIGP BOK v2.1 domain structure with exam weight proportions

DomainWeightAt 60hAt 80hAt 100h
D1: AI Technology Foundations~20%12h16h20h
D2: AI Governance Program Design~25%15h20h25h
D3: AI Risk Management~22%13h18h22h
D4: Laws and Regulations~18%11h14h18h
D5: Ethics and Accountability~15%9h12h15h

The allocation formula: Domain weight × Total study hours = Hours to allocate to that domain. Simple. The mistake most candidates make is not using it.

Everything you need to prep for the 2026 AIGP, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →

Domain 1: AI Technology Foundations (~20%)

Domain 1 establishes the technical literacy foundation that the rest of the AIGP builds on. This is not a deep technical domain — the AIGP is a governance certification, not an AI engineering certification. You need to understand AI concepts well enough to govern systems that use them, not to build them.

Core content:

  • Types of AI systems: Narrow AI (task-specific) vs. General AI (hypothetical broad capability). Supervised, unsupervised, and reinforcement learning at a conceptual level. Neural networks, deep learning, large language models (LLMs) — what they are, not how to build them.
  • AI system vs. GPAI model: A critical EU AI Act distinction. An AI system is designed to operate with a degree of autonomy and produce outputs (recommendations, decisions, predictions, content). A General Purpose AI (GPAI) model is a model trained on large data that can perform a wide range of tasks — the underlying model that AI systems may be built upon. The EU AI Act treats GPAI models (like foundation models) separately from AI systems.
  • Data pipeline concepts: Training data, validation data, test data. Data quality dimensions: accuracy, completeness, consistency, timeliness. How training data quality affects model output quality.
  • OECD AI Principles (2019): The five principles — Inclusive Growth and Well-Being; Human-Centred Values and Fairness; Transparency and Explainability; Robustness, Security and Safety; Accountability. These are the foundational international AI ethics principles referenced throughout the BOK.
  • EU AI Act risk tiers: Unacceptable risk (prohibited); High risk (Annex III); Limited risk (transparency obligations); Minimal risk (no specific requirements). Know which tier each category falls into and why.

Common exam patterns in Domain 1: Scenario questions that test whether you can identify what type of AI system is described, which EU AI Act risk tier applies to a described use case, or which OECD principle is most relevant to a described situation.

Domain 2: AI Governance Program Design (~25% — Highest Weight)

Domain 2 is the largest domain and the one where candidates who've worked in privacy or risk management have the strongest advantage. It tests whether you can design an organizational AI governance program — the structures, policies, processes, and accountability mechanisms.

AI Governance Accountability Structure

The exam tests who owns AI governance in an organization. The correct answer is: the board and executive leadership own it, with day-to-day management delegated to a designated AI governance role (Chief AI Officer, AI Risk Officer, or similar). The key AIGP BOK principle: AI governance accountability cannot be effectively delegated entirely to a technical team. Business leaders who approve AI use cases must be accountable for governance outcomes.

What the exam tests on accountability:

  • The distinction between responsibility (doing the work) and accountability (owning the outcome). An AI ethics team can be responsible for risk assessments; a business unit VP is accountable for the AI system deployed in their function.
  • Who approves high-risk AI deployments? (Should require executive and governance committee sign-off, not just technical sign-off)
  • How AI governance integrates with existing privacy, security, and risk frameworks — not as a separate silo but as an extension of existing enterprise risk management

AI Inventory and Risk Classification

An AI inventory is the foundational operational tool of an AI governance program — analogous to the ROPA in a privacy program. For the AIGP exam, know:

  • What an AI inventory must capture: System name and description; business owner; intended purpose and use cases; data sources; vendor or build (internal vs. third-party); risk classification; current governance status (approved, under review, decommissioned)
  • Risk classification criteria: Impact on individuals; scale of deployment; reversibility of decisions; use of sensitive data; degree of human oversight in the loop; regulatory classification under the EU AI Act
  • Inventory maintenance triggers: New AI deployment; change in purpose or data inputs; change in vendor; regulatory reclassification; post-incident review
  • The "shadow AI" problem: Employees deploying AI tools (generative AI, productivity AI) without organizational awareness or approval. Effective AI governance programs have a process for discovering and governing shadow AI use.

Third-Party AI Due Diligence

Many organizations procure AI systems from vendors rather than building them internally. Domain 2 tests whether you know the governance obligations that procurement creates:

  • Pre-procurement: risk classification of the intended use; assessment of the vendor's AI governance and ethics practices; review of training data provenance claims
  • Contractual protections: audit rights; incident notification obligations; change notification (if the model is updated); data use restrictions; indemnification for AI-caused harm
  • Ongoing monitoring: post-deployment performance monitoring; ongoing vendor assessment; exit planning (what happens to the organization's data and dependencies if the vendor relationship ends?)

Domain 3: AI Risk Management (~22%)

Domain 3 covers the operational practice of identifying, assessing, and managing AI-specific risks. The NIST AI RMF is the primary framework tested in this domain, alongside FRIA, bias assessment, and model monitoring.

NIST AI RMF Functions — Deep Exam Detail

The four NIST AI RMF functions (Govern, Map, Measure, Manage) are tested in application, not just definition. The exam presents scenarios and asks which function is being performed or which function should be applied next.

Govern function — key exam content:

  • Organizational policies and procedures for AI risk management
  • Roles and responsibilities assignment for AI trustworthiness
  • Culture of AI risk awareness and responsible development/deployment
  • Governance is continuous — not a phase. It underpins Map, Measure, and Manage simultaneously.

Map function — key exam content:

  • Context establishment: what is the intended use of the AI system? Who are the stakeholders?
  • Risk identification: what could go wrong? Who could be harmed? What are the failure modes?
  • AI system categorization: what type of system is it, what data does it use, what decisions does it support?
  • Interdependencies: how does this AI system interact with other systems and processes?

Measure function — key exam content:

  • Quantitative and qualitative risk evaluation: how likely is the risk, how severe are the impacts?
  • Bias and fairness metrics: disparate impact rate, equal opportunity rate, demographic parity — what they measure and when each is appropriate
  • Performance benchmarking: accuracy, precision, recall, F1 score — not deep statistics, but understanding what these metrics reveal about model performance
  • Red teaming: structured adversarial testing of AI systems to discover failure modes before deployment

Manage function — key exam content:

  • Risk treatment decisions: accept, mitigate, transfer, avoid
  • Model monitoring: post-deployment performance tracking; detecting model drift (when model performance degrades because real-world data distribution has shifted from training data)
  • Incident response: how to respond when an AI system produces a harmful output or fails in a way that affects individuals
  • Model updates and retraining: governance process for when and how to update a deployed model

Domain 4: Laws and Regulations (~18%)

Domain 4 is consistently under-studied relative to its exam weight. Candidates who come from a governance or privacy background often assume they know the regulatory content — but the AIGP tests article-level precision on the EU AI Act that most candidates haven't drilled.

The EU AI Act provisions you must know at article level: Articles 5, 6, 9, 11, 13, 17, 26, 27, 43, 73, and 86. For each: know who it applies to (provider, deployer, or both) and what it specifically requires — not just that it exists.

Other frameworks with lower but real exam presence:

  • OECD AI Principles: 5 recommendations (inclusive growth; human-centred values; transparency/explainability; robustness/security/safety; accountability) + 5 recommendations for governments (investing in AI R&D; fostering a digital ecosystem; enabling policy environment; capacity building; international cooperation)
  • Singapore Model AI Governance Framework (2nd Ed.): Two pillars — Internal Governance and Stakeholder Management. Used in Domain 4 scenario questions as an example of national AI governance framework.
  • ISO/IEC 42001:2023: AI management system standard. Know its purpose (AIMS certification), its positioning relative to EU AI Act (voluntary vs. regulatory), and who can be certified (organizations, not AI systems).

Domain 5: Ethics and Accountability (~15%)

Domain 5 is the smallest domain and covers the ethical principles that underpin the entire AI governance framework. For the exam, the primary risk is conflating definitions that sound similar.

ConceptBOK Definition (simplified)Common confusion
ExplainabilityThe ability to describe how an AI system produced a specific output in terms understandable to the audienceConfused with transparency — explainability is about the how of a specific output; transparency is about disclosure of general capabilities and limitations
TransparencyDisclosure of what an AI system does, how it works in general terms, and what data it uses — to relevant stakeholdersConfused with explainability — transparency is a general disclosure obligation; explainability is a specific output-level right
AccountabilityClear assignment of responsibility for AI system behavior and for addressing harmsConfused with governance — accountability is about who is answerable; governance is about the structures that ensure accountability
Human OversightThe ability of humans to monitor, audit, intervene in, and shut down AI system operations when neededConfused with human-in-the-loop — human oversight doesn't require a human reviewing every decision; it requires the capability to intervene when needed
RedressMechanisms allowing individuals affected by AI decisions to seek review, correction, or remedyConfused with the right of access — redress is about challenging decisions and seeking remedy, not just obtaining information about the decision

5 Exam-Style AIGP Domain Weight Practice Questions

Practice Question 1 — Domain 2 / AI Inventory

A company's AI governance team discovers that three business units have deployed generative AI writing tools purchased directly by team managers without going through the technology procurement process. What is the most appropriate initial governance response?

  • A. Immediately shut down all three AI tools pending a full security review
  • B. Add the three AI tools to the AI inventory, classify their risk level, and determine whether the deployment meets current governance requirements
  • C. Require the three business units to obtain formal approval before using the tools at next budget cycle
  • D. Issue a company-wide policy prohibiting the use of any AI tools not pre-approved by the AI governance committee
Answer: B. The correct first response to discovering shadow AI deployments is to bring them into the governance program — not immediately shut them down (A, which is disproportionate and disruptive), wait for budget cycle (C, which leaves unreviewed tools in operation), or issue a blanket prohibition (D, which doesn't address the already-deployed tools). Adding to the inventory and conducting risk classification is the foundational step that enables all subsequent governance decisions — including whether to shut down, restrict, or formally approve the tools.
Practice Question 2 — Domain 3 / NIST AI RMF

An organization is deploying a new AI system for employee performance evaluation. The AI governance team completes an exercise documenting: who will be affected (employees); what data the model uses (productivity metrics, manager ratings); what could go wrong (disparate impact on certain demographic groups); and what the AI system's intended vs. potential actual uses are. Which NIST AI RMF function does this activity primarily correspond to?

  • A. Govern
  • B. Map
  • C. Measure
  • D. Manage
Answer: B — Map. The Map function involves categorizing the AI system's context: who is affected, what data is used, what the intended purpose is, and what risks could arise. The activity described — stakeholder identification, data source documentation, risk identification (what could go wrong), and use-case analysis — is classic Map work. It's discovery and categorization, not assessment or quantification (that would be Measure) and not policy establishment (Govern) or risk treatment (Manage).
Practice Question 3 — Domain 1 / EU AI Act Risk Classification

A company wants to deploy an AI system that assesses job applicants' CVs to rank candidates for interview selection at scale. Under the EU AI Act, which risk classification most accurately applies to this system?

  • A. Unacceptable risk — prohibited under Article 5
  • B. High risk — listed in Annex III, Category 4 (Employment)
  • C. Limited risk — transparency obligations only, no other specific requirements
  • D. Minimal risk — no specific regulatory requirements
Answer: B. Annex III, Category 4 of the EU AI Act lists AI systems used for recruitment, CV sorting, and evaluation of persons in the employment context as high-risk AI. An AI system that ranks job applicants at scale falls squarely in this category. It is not prohibited (A) — there is no general prohibition on employment-screening AI; it is subject to the high-risk obligations (technical documentation, risk management system, transparency to deployers, FRIA for certain deployers). C and D are incorrect — this is not a transparency-only or minimal-risk system.
Practice Question 4 — Domain 4 / EU AI Act Article 27

A municipality (public authority) in Germany plans to deploy an AI system listed in Annex III of the EU AI Act to assist in determining eligibility for social welfare benefits. Which obligation under the EU AI Act is specifically triggered for the municipality as a deployer in this context?

  • A. Preparing technical documentation for the AI system (Article 11)
  • B. Conducting a conformity assessment before deployment (Article 43)
  • C. Conducting a Fundamental Rights Impact Assessment before deployment (Article 27)
  • D. Registering as a provider of high-risk AI systems in the EU database (Article 49)
Answer: C. Article 27 requires deployers who are public authorities — or private entities carrying out public functions — to conduct a Fundamental Rights Impact Assessment (FRIA) before deploying high-risk AI systems in certain Annex III contexts. A social welfare eligibility determination by a municipality is exactly this scenario. Technical documentation (A) and conformity assessment (B) are provider obligations. EU database registration (D) is primarily a provider obligation under Article 49, with some deployer registration obligations in specific public authority contexts — but the specifically triggered deployer obligation here is the FRIA.
Practice Question 5 — Domain 5 / Ethics Definitions

An AI-assisted credit scoring system denies a loan to an individual without providing any explanation of how the AI system's output influenced the decision. The financial institution argues that providing such an explanation would reveal proprietary model information. Under the EU AI Act, which right most directly addresses the individual's entitlement to information about the AI's role in the decision?

  • A. Data portability (GDPR Article 20)
  • B. Explanation of AI-assisted decisions (EU AI Act Article 86)
  • C. Objection to automated decision-making with significant effects (GDPR Article 22)
  • D. Access to personal data being processed (GDPR Article 15)
Answer: B. Article 86 of the EU AI Act gives individuals affected by high-risk AI system decisions the right to obtain an explanation of the role of the AI system in the decision-making procedure and the main elements of the decision. A credit scoring AI system is a high-risk AI system (Annex III, Category 5 — creditworthiness assessment). The financial institution cannot use commercial confidentiality as a blanket reason to deny explanation — Article 86 creates an affirmative entitlement. GDPR Article 22 (C) covers automated decision-making but applies to solely automated decisions with significant effects — where human review occurs, Article 22 may not apply. Article 86 is the more specific and direct provision here. A (data portability) and D (access rights) are data access rights, not explanation rights about AI decision-making.

Everything you need to prep for the 2026 AIGP, in one place.

Cram guide, 300 practice questions, and a career guide — put together so you're not hunting across five different resources.

Get the Complete Pack →

The Domain Weight Allocation Principle in One Sentence

Study where the exam points are. If you spend equal time on all five domains, you're voluntarily leaving the highest-weight domains under-prepared. Domain-weight-proportional study is not a study tip — it's a basic optimization that passing candidates apply and underperforming candidates skip.

Frequently Asked Questions

Are AIGP domain weights published by IAPP?

Yes. IAPP publishes the AIGP exam blueprint with domain weights as part of the official exam preparation resources. The weights in this article reflect the BOK v2.1 exam blueprint. Always verify against the current IAPP exam blueprint before beginning your study — weights can be adjusted when the BOK is updated.

Has the AIGP BOK been updated recently?

The AIGP BOK reached v2.1 reflecting updates to the EU AI Act (which entered into force in August 2024 and has phased implementation through 2026–2027) and the maturation of AI governance frameworks like NIST AI RMF v1.0. If you purchased study materials before mid-2024, verify that your materials reflect BOK v2.1 — particularly for Domain 4 content on the EU AI Act's final text.

How many total hours should I study for the AIGP?

Candidate reports cluster around 60–100 hours for candidates with existing privacy, risk, or AI backgrounds. Candidates without prior exposure to AI governance concepts or EU regulatory frameworks typically report 80–120 hours. IAPP's official preparation guidance recommends completing the AIGP training course (approximately 14 hours) plus supplementary practice questions. Most candidates who pass without additional coaching report 40–60 hours beyond the official training materials.