The AIGP exam is scenario-heavy — you are rarely asked to recall a definition. You are asked what a governance professional should do in a specific situation, which requires a different kind of preparation than memorizing frameworks.

Below are 10 AIGP-style questions covering the highest-frequency exam domains. Each includes the correct answer and a detailed explanation of why the other options are wrong.

Before You Start

Try each question cold before reading the explanation. Your instinctive first answer reveals where your mental model needs work better than re-reading correct answers does.

Sample Questions

Question 1 — EU AI Act
A company deploys an AI system that evaluates job applications and ranks candidates for human reviewers, who make all final hiring decisions. Under the EU AI Act, this system is best classified as:
  • A) Prohibited — AI may not be used in employment decisions
  • B) High-risk — employment and workers management is an Annex III use case
  • C) Limited risk — the system must carry a transparency notice only
  • D) Minimal risk — human oversight removes the AI Act classification
Why B is correct: The EU AI Act Annex III explicitly lists AI systems used for recruitment, CV screening, and employee evaluation as high-risk — regardless of whether a human makes the final decision. Human oversight affects compliance obligations, not the risk classification itself. Option D is the most common wrong answer.
Question 2 — Governance Accountability
An organization discovers its AI credit-scoring model produces significantly lower approval rates for applicants from one geographic region. The first governance action the AI team should take is:
  • A) Suspend the model immediately and notify regulators
  • B) Retrain the model on a more balanced dataset
  • C) Document the finding and escalate to the AI risk committee for impact assessment
  • D) Adjust the threshold for that region to equalize approval rates
Why C is correct: The governance-first answer always involves documentation and escalation through the appropriate accountability structure before action. Immediate suspension (A) may be warranted later but is not the first step. Retraining (B) and threshold adjustment (D) are technical interventions that require governance approval, not unilateral action.
Question 3 — NIST AI RMF
The NIST AI Risk Management Framework's "Govern" function is primarily concerned with:
  • A) Identifying AI risks and categorizing AI systems by impact level
  • B) Measuring AI performance through testing and evaluation
  • C) Applying risk controls and mitigation strategies in production
  • D) Establishing policies, organizational roles, and culture for responsible AI
Why D is correct: In the NIST AI RMF, Govern is the foundation function that establishes the organizational infrastructure — policies, roles, accountability, and culture — enabling the other three functions (Map, Measure, Manage) to operate. Candidates frequently confuse Govern with Manage, which is the function focused on operational risk controls.
Question 4 — AI Systems & Data
A model trained on five years of historical loan approval data performs well on historical test sets but shows unexpected failure patterns six months after deployment. This is most likely caused by:
  • A) Representation bias in the original training dataset
  • B) Measurement bias in the loan outcome labels
  • C) Data drift — the real-world distribution has shifted since training
  • D) Overfitting to the training data
Why C is correct: The key signal is "unexpected failure patterns after deployment" in a model that performed well at launch. Data drift (also called distribution shift or concept drift) occurs when real-world conditions change after training. Overfitting (D) would show poor generalization immediately, not months later. Representation and measurement bias (A, B) would have produced poor initial performance.
Question 5 — Regulatory Frameworks
An organization subject to the EU AI Act deploys a high-risk AI system. Before placing the system on the market, it must:
  • A) Obtain prior authorization from the national competent authority
  • B) Conduct a conformity assessment and register the system in the EU database
  • C) Publish an algorithmic transparency report accessible to the public
  • D) Appoint a dedicated AI compliance officer with direct board access
Why B is correct: For most high-risk AI systems under the EU AI Act, the conformity assessment can be conducted internally (self-assessment) without prior regulatory authorization — this distinguishes the EU AI Act from some product safety regimes. Registration in the EU AI database is required for high-risk systems listed in Annex III. Option A overstates the requirement; C and D are real obligations in other contexts but not the primary pre-market requirement.

These are just 5 of the scenario patterns that appear on the actual exam.

Get 300 AIGP-Style Practice Questions — With Full Explanations AIGP Complete Pack — $180
Question 6 — Ethics & Responsible AI
A governance professional reviewing an AI system used for parole recommendations finds it has a 92% overall accuracy rate but disproportionately misclassifies one demographic group. The most appropriate response is to:
  • A) Accept the system — 92% accuracy exceeds typical human decision-making
  • B) Retrain using synthetic data to balance demographic representation
  • C) Conduct a disaggregated performance analysis and present findings to decision-makers before continued deployment
  • D) Add a human reviewer to all decisions involving the affected group
Why C is correct: High overall accuracy can mask severe group-level harm — this is the core insight behind disaggregated evaluation. The correct governance action is to document and escalate, not to immediately implement a technical fix (B) or oversight workaround (D). Option A reflects a common error: aggregate metrics do not justify disparate harm in high-stakes contexts.
Question 7 — AI Risk Management
During a third-party AI vendor assessment, you discover the vendor's model was trained on data that included personal information scraped without consent. Your organization's most important immediate obligation is to:
  • A) Terminate the vendor contract immediately
  • B) Notify affected individuals of the data collection
  • C) Assess whether your organization's use of the system creates liability exposure and escalate to legal counsel
  • D) Request the vendor retrain the model on compliant data before continued use
Why C is correct: The AIGP exam consistently rewards the answer that reflects governance process — assess risk, document, and involve appropriate stakeholders — before action. Immediate termination (A) and retraining demands (D) may follow, but legal assessment comes first. Notifying individuals (B) may not be your organization's obligation if you are a downstream user rather than the original data controller.
Question 8 — Transparency & Explainability
A bank uses an AI model to make credit decisions. A customer is denied credit and requests an explanation. Under the EU AI Act and GDPR together, the bank is required to:
  • A) Provide the full model architecture and feature weights to the customer
  • B) Provide meaningful information about the logic involved, the significance, and the envisaged consequences
  • C) Switch to a human decision-maker if the customer contests the automated decision
  • D) Refer the customer to the model provider for technical documentation
Why B is correct: GDPR Article 22 and Recital 71 require "meaningful information about the logic involved" in automated individual decision-making — this is a deliberately flexible standard, not a requirement for full technical disclosure (A). Option C describes the right to human review, which is a separate right the customer may invoke, but it is not the bank's proactive obligation upon denial.
Question 9 — Organizational Accountability
An organization is building its AI governance program from scratch. The most effective first step is to:
  • A) Hire a Chief AI Officer with P&L responsibility
  • B) Implement an AI incident reporting system
  • C) Conduct an inventory of existing AI systems and classify them by risk level
  • D) Draft an AI ethics policy and publish it on the company website
Why C is correct: You cannot govern what you have not mapped. NIST AI RMF's Map function — and the EU AI Act's conformity assessment requirements — both begin with inventory. Publishing an ethics policy (D) without knowing what systems exist is governance theater. An incident reporting system (B) is critical but requires a risk-classified inventory to function meaningfully.
Question 10 — EU AI Act: Prohibited Practices
Which of the following AI applications is explicitly prohibited under the EU AI Act?
  • A) AI that recommends content to users based on past behavior
  • B) AI that assesses job candidate suitability based on interview performance
  • C) AI that uses subliminal techniques to influence individuals without their awareness
  • D) AI that monitors employee productivity in call center environments
Why C is correct: Article 5 of the EU AI Act explicitly prohibits AI systems that deploy subliminal techniques to manipulate individuals in ways they cannot perceive, particularly when this could cause harm. Options A and D are not prohibited — they may be regulated as high-risk or require transparency notices depending on context. Option B is high-risk (employment use case, Annex III) but not prohibited.
AIGP Exam: Time Management Strategy 90 Questions 150 min ≈100 sec/question Pass 1: Quick Answers Flag uncertain Qs Target: 60–70 min Pass 2: Flagged Qs Review, don't second-guess Remaining time archuz.com — AIGP Exam Strategy
AIGP exam time management: two-pass strategy. First pass for confident answers, second pass for flagged questions. Never change an answer without a clear reason. Free to use with attribution to archuz.com.

Exam-Day Strategy

Time is not the problem on the AIGP — 150 minutes for 90 questions gives you roughly 100 seconds each, which is adequate. The real risk is overthinking scenario questions where two options both seem defensible.

  • Pass 1, move fast: Answer what you know quickly. Flag anything where you are genuinely unsure between two options. Aim to finish Pass 1 in 60–70 minutes.
  • Pass 2, review flagged: Return to flagged questions with fresh eyes. Read the question stem again — not just the answers. The distinction usually clarifies.
  • The governance answer usually wins: When stuck between a technical fix and a process/escalation answer, the process answer is usually correct. The AIGP tests governance judgment, not technical implementation.
  • Do not change answers without a reason: If your second read of a question produces the same gut answer, keep it. Random answer-changing degrades performance.

Frequently Asked Questions

How many questions are on the AIGP exam?

The AIGP exam has 90 multiple-choice questions with a 2.5-hour time limit. That works out to approximately 100 seconds per question.

Are there official AIGP practice tests from IAPP?

IAPP provides a small number of sample questions through its official study guide. These are not sufficient on their own — most candidates supplement with third-party question banks to get the volume needed for exam confidence.

What is a passing score on the AIGP exam?

IAPP uses scaled scoring. The passing threshold varies by exam form and is not published. Most candidates report that scoring consistently above 70% on practice exams correlates with passing the actual exam.

Ready to go beyond 10 questions?

300 AIGP Practice Questions — Cram Guide + Question Bank + Career Guide Get the AIGP Complete Pack — $180

Related Reading