AI Governance Certification Landscape
AI governance emerged as a distinct discipline in 2023-2024, driven by the EU AI Act, executive orders, and high-profile AI incidents. Unlike AI security (which focuses on protecting AI systems), AI governance addresses the responsible development, deployment, and oversight of AI across legal, ethical, and operational dimensions.
Why Governance Certifications Matter Now
Article 4 of the EU AI Act requires providers and deployers to take measures that support the development of AI literacy for staff and other people operating or using AI systems on their behalf. The measures should take account of knowledge, experience, education, training, use context, and affected people; the amended Article 4 does not require a guaranteed level for any individual. It is not limited to high-risk systems, and holding a credential does not by itself establish compliance.[2]
Major Certification Programs
IAPP AIGP
AI Governance Professional
A well-known individual credential focused on AI governance. Covers the EU AI Act, NIST AI RMF, and responsible AI implementation.
ISO 42001 Lead Implementer
Individual implementation training credential
Provider-issued training or personnel credential focused on implementing ISO/IEC 42001. It is distinct from an independent certification body certifying an organization’s AI management system.
IAPP AI + Privacy Certificate
AI and Data Privacy Integration
Focused on the intersection of AI systems and data privacy requirements. Ideal for privacy professionals expanding into AI governance.
IAPP AIGP: The Leading AI Governance Credential
IAPP announced the AI Governance Professional (AIGP) certification in March 2024 and framed it as a dedicated credential for professionals working across privacy, legal, compliance, and technical AI governance. In its launch materials, IAPP said more than 4,000 professionals had already signed up for the related training curriculum.[1]
AIGP at a Glance
Prerequisites
- No formal prerequisites
- Privacy/compliance experience recommended
- CIPP/CIPM holders have advantage
Exam Domains
- Understanding the foundations of AI governance
- Understanding how laws, standards and frameworks apply to AI
- Understanding how to govern AI development
- Understanding how to govern AI deployment and use
AIGP Exam Structure
As of August 26, 2026, the official IAPP AIGP Body of Knowledge v2.1, effective February 2, 2026, defines four domains and publishes a minimum-to-maximum question range for each. The ranges are not fixed percentage weights.
| Domain | Question Range | Key Topics |
|---|---|---|
| I. Understanding the foundations of AI governance | 16 to 20 | AI concepts, responsible-AI principles, governance roles, policies, and lifecycle oversight |
| II. Understanding how laws, standards and frameworks apply to AI | 19 to 23 | Privacy and other existing laws, AI-specific laws, NIST, OECD, and ISO standards |
| III. Understanding how to govern AI development | 21 to 25 | Design and build, training and testing data, release, monitoring, and maintenance |
| IV. Understanding how to govern AI deployment and use | 21 to 25 | Deployment selection and assessment, use controls, monitoring, maintenance, and communications |
No Prerequisites = Accessibility
Unlike ISACA’s AAISM which requires CISM/CISSP, AIGP has no prerequisites. This makes it accessible to privacy professionals, lawyers, compliance officers, and technologists looking to establish AI governance credentials.
ISO/IEC 42001: Organizational AI Governance
ISO/IEC 42001 is the international standard for AI management systems, published in December 2023. While AIGP certifies individual professionals, ISO 42001 provides a framework for organizational AI governance. Professionals can become certified Lead Implementers or Lead Auditors.[3]
ISO 42001 Certification Paths
Lead Implementer
Training providers market this path for professionals implementing ISO 42001 AI management systems. Course duration and exams vary by provider.
Lead Auditor
Training providers market this path for professionals auditing organizations against ISO 42001 requirements. Duration and exams vary by provider.
Foundation
Entry-level training on ISO 42001 concepts is widely available, but duration and provider-specific credentialing are not set by ISO itself.
ISO 42001 Key Requirements
- AI policy and objectives
- Risk assessment processes
- AI system impact assessment
- Data governance controls
- Continuous monitoring
Training Providers
- BSI Group
- PECB
- SGS Academy
- DNV
- TUV
Certification Comparison
| Factor | IAPP AIGP | ISO 42001 LI | ISACA AAISM |
|---|---|---|---|
| Focus | AI Governance & Ethics | AI Management Systems | AI Security Management |
| Prerequisites | None | Foundation recommended | CISM or CISSP |
| Cost | $649 member / $799 non-member | Provider-specific; verify current quote | $459 member / $599 non-member exam + $50 application |
| Duration | Self-paced exam | Provider-specific training and assessment | Self-paced exam |
| Best For | Privacy/compliance pros | Consultants/implementers | Security managers |
| Regulatory Coverage | Extensive | Extensive | Moderate |
Recommended Combinations
- Governance Specialists: AIGP + ISO 42001 Lead Implementer = comprehensive governance portfolio
- Security + Governance: AAISM + AIGP = security management with governance context
- Privacy + AI: CIPP/E + AIGP = privacy expertise extended to AI systems
Career Paths
AI governance roles are spreading across legal, privacy, product, security, and risk teams. Titles and compensation vary widely by sector, so this section focuses on role patterns rather than a single salary benchmark.
Common Role Patterns
Role design and compensation vary significantly by organization, sector, and geography.
AI Governance Roles
- Chief AI Ethics Officer
- Head of AI Governance
- AI Risk Manager
- Responsible AI Lead
- AI Policy Director
Industry Demand
- Technology (AI product companies)
- Financial services (algorithmic trading)
- Healthcare (AI diagnostics)
- Consulting (Big 4, boutiques)
- Government & regulators
Regulatory Context
Individual credentials and organizational management-system certifications answer different questions. This section separates those credentials from legal conformity and product certification.
EU AI Act
First prohibitions: February 2025
An EU-wide, risk-based legal framework with different obligations and dates by system, role, and use. A professional credential is not evidence that an organization or product conforms. See our EU AI Act guide.
NIST AI Risk Management Framework
Voluntary US risk-management framework
The primary US framework for AI governance. Covers Map, Measure, Manage, and Govern functions. Referenced in federal procurement and executive orders. See our NIST AI RMF guide.
Colorado ADMT Law (SB 26-189)
Compliance from January 1, 2027
Colorado’s first comprehensive AI law (SB 24-205) was repealed and replaced by SB 26-189, “Automated Decision-Making Technology,” signed May 14, 2026. The new framework centers on transparency and consumer-notice duties for covered automated decision-making technology (ADMT), with substantive compliance beginning January 1, 2027. See our Colorado AI Act analysis.
Preparation Strategy
AIGP Preparation Path
Foundation: AI Fundamentals
Understand ML concepts, model types, training data, and AI lifecycle. IAPP provides foundational materials.
Frameworks: NIST AI RMF & ISO 42001
Master the NIST AI Risk Management Framework and ISO 42001 requirements.
Regulation: EU AI Act Deep Dive
Study risk categories, prohibited practices, high-risk requirements, and compliance timelines within Domain II; the official blueprint publishes a 19 to 23 question range rather than a fixed percentage.
Practice: Impact Assessments
Learn to conduct AI impact assessments. Practice with the AI security questionnaire framework.
Exam: Take AIGP
100 multiple-choice questions, 2.75 hours. Can take remotely or at a testing center.
Study Tips
- • EU AI Act risk categorization is heavily tested: know the four risk levels
- • Understand prohibited AI practices (social scoring, real-time biometric)
- • NIST AI RMF four functions: Map, Measure, Manage, Govern
- • Know the difference between governance, risk, and compliance
References
- [1] IAPP. “IAPP Launches New AI Governance Professional Certification.” March 2024. Launch materials noted 4,000+ professionals had signed up for the related training curriculum.
- [2] European Commission. “EU AI Act.” 2024.
- [3] ISO. “ISO/IEC 42001:2023 - AI Management System.” December 2023.
- [4] NIST. “AI Risk Management Framework.” January 2023.
- [5] IAPP. “AIGP Body of Knowledge, Version 2.1.” Effective February 2, 2026.
Disclaimer: Certification requirements, pricing, and exam content may change. Verify current details with IAPP and training providers directly. Salary data represents general market ranges and may vary by location and experience. This guide is for informational purposes only.
