AIGP Artificial Intelligence Governance Professional Exam Topics and Questions
These IAPP Artificial Intelligence Governance Professional (AIGP) exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise AIGP sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the IAPP Artificial Intelligence Governance Professional certification exam.
Let's Practice Free IAPP AIGP Questions Aligned with Official Exam Topics
This topic establishes the technical baseline you need to govern what you may not have built yourself. You face definitions, taxonomies and lifecycle stages that sound basic but trip candidates who assume common usage matches the exam's precision. The cost comes when a question hinges on distinguishing supervised from unsupervised learning or identifying which lifecycle phase owns a given control. How Foundations of artificial intelligence is tested Questions present a scenario involving an AI system and ask you to classify...
This topic establishes the technical baseline you need to govern what you may not have built yourself. You face definitions, taxonomies and lifecycle stages that sound basic but trip candidates who assume common usage matches the exam's precision. The cost comes when a question hinges on distinguishing supervised from unsupervised learning or identifying which lifecycle phase owns a given control.
How Foundations of artificial intelligence is tested
Questions present a scenario involving an AI system and ask you to classify it, identify its learning paradigm, or pinpoint where in the development lifecycle a described activity belongs. The demand is definitional accuracy under pressure. Candidates lose marks by conflating reinforcement learning with supervised learning, by misidentifying generative models as discriminative ones, or by placing data validation in the wrong lifecycle phase. The exam expects you to apply taxonomy correctly to unfamiliar fact patterns, not recite definitions in isolation. Another common trap is assuming that any system processing language must be a large language model, when the scenario describes something narrower. Read the stem for the technical detail that disambiguates, then match it to the precise term the outline uses.
The practice test gives you volume across all three sub-topics, so you can identify whether your misses cluster in model types, learning paradigms or lifecycle stages. The PDF demo lets you check the item style before committing.
The question below asks you to apply lifecycle terminology to a governance activity described in operational terms.
All of the following areunique characteristics of AIthat require a comprehensive approach to governanceEXCEPT?
Where the first topic dealt with what AI is, this one deals with what it does to people and how principle frameworks respond. You move from taxonomy into consequence and aspiration. The challenge is that every framework uses slightly different language for overlapping ideas, and the exam expects you to recognise the concept behind the label rather than memorising one vendor's list. How AI impacts and responsible principles is tested Items describe a harm, a system characteristic or an ethical...
Where the first topic dealt with what AI is, this one deals with what it does to people and how principle frameworks respond. You move from taxonomy into consequence and aspiration. The challenge is that every framework uses slightly different language for overlapping ideas, and the exam expects you to recognise the concept behind the label rather than memorising one vendor's list.
How AI impacts and responsible principles is tested
Items describe a harm, a system characteristic or an ethical tension, then ask you to name it or propose a principle that addresses it. You are tested on your ability to map a real-world impact to the category the outline uses, and to distinguish harms that sound similar but differ in mechanism. Candidates lose marks by confusing bias with discrimination, or by selecting a principle that sounds responsible but does not match the harm described. Another frequent error is choosing the principle that feels most important rather than the one the scenario actually requires. The exam rewards close reading of the fact pattern and matching it to the specific trustworthy AI characteristic or ethical guidance that applies. Vague answers that gesture at fairness or transparency without precision will not score.
Principle and impact questions are easy to misread under time pressure. The question bank lets you work through enough variations to spot when the stem is pointing at explainability versus accountability, or at individual harm versus systemic risk.
What follows turns on distinguishing between two harms that share a symptom but differ in their root cause and remedy.
Which type of existing assessment could best be leveraged to create an Al impact assessment?
Now you apply the principles from topic two to the structures and processes that operationalise them. This topic is where governance moves from aspiration to implementation. You need to know what an AI governance function looks like, how risk identification differs from risk assessment, and which frameworks and standards exist to scaffold the work. Candidates often underestimate the specificity required when naming a framework or describing the sequencing of risk activities. How AI governance and risk management is tested Questions...
Now you apply the principles from topic two to the structures and processes that operationalise them. This topic is where governance moves from aspiration to implementation. You need to know what an AI governance function looks like, how risk identification differs from risk assessment, and which frameworks and standards exist to scaffold the work. Candidates often underestimate the specificity required when naming a framework or describing the sequencing of risk activities.
How AI governance and risk management is tested
Questions give you a governance gap or a risk scenario and ask you to identify the missing structure, the appropriate framework, or the next step in the risk process. You are expected to distinguish strategy from governance, and to sequence identification, assessment and treatment correctly. Candidates lose marks by selecting a framework that is well-known but not suited to the context described, or by conflating risk identification with impact assessment. Another trap is assuming that any mention of risk means you should reach for a privacy framework, when the scenario calls for a broader AI risk standard. The exam tests whether you can match the governance need to the right tool and whether you understand the dependencies between strategy, structure and process. Generic answers about oversight or accountability will not suffice.
Governance and risk questions demand that you hold multiple frameworks in mind and choose the right one for the scenario. Practising under timed conditions helps you make that call quickly and correctly, rather than second-guessing mid-exam.
The scenario that follows requires you to select the governance structure that addresses a described gap, not the one that sounds most comprehensive.
This is the heaviest topic by question count and the one where precision matters most. You face AI-specific regulation, existing laws that now apply to AI systems, the points where GDPR intersects with algorithmic processing, intellectual property questions raised by training data and generated output, and liability reform proposals. Each sub-topic has its own vocabulary and its own traps. โ AI-specific regulation and GDPR intersections The EU AI Act is the primary AI-specific instrument you need to know, including its...
This is the heaviest topic by question count and the one where precision matters most. You face AI-specific regulation, existing laws that now apply to AI systems, the points where GDPR intersects with algorithmic processing, intellectual property questions raised by training data and generated output, and liability reform proposals. Each sub-topic has its own vocabulary and its own traps.
โ AI-specific regulation and GDPR intersections
The EU AI Act is the primary AI-specific instrument you need to know, including its risk classification, prohibited practices and obligations by risk tier. Candidates often confuse the thresholds that trigger each tier or misapply the transparency requirements. GDPR intersections focus on automated decision-making under Article 22, data subject rights in the face of algorithmic processing, and the interplay between GDPR's lawfulness conditions and the AI Act's requirements. The exam expects you to recognise when both regimes apply and which obligation comes from which instrument. Do not assume that every AI system triggers Article 22, and do not assume that high-risk under the AI Act means the same thing as high-risk under a data protection impact assessment.
โ Existing law, intellectual property and liability
Existing laws include employment law, consumer protection, anti-discrimination statutes and sector-specific regulation, all of which apply to AI systems when those systems make or inform decisions in scope. The exam tests whether you can identify which existing law governs a described use case. IP questions centre on whether training data use infringes copyright, whether generated output can be protected, and who owns what when an AI system produces something new. Liability reform addresses the gap between traditional fault-based liability and the opacity or autonomy of AI systems. You need to know the arguments for strict liability, the proposals for algorithmic accountability, and the jurisdictions moving toward reform. Candidates lose marks by applying IP or liability rules from one jurisdiction to a scenario set in another, or by assuming that existing law always has an answer when the question is about the gap that reform seeks to fill.
How Laws and standards related to AI is tested
Items present a system, a use case or a legal question and ask you to name the applicable law, identify the obligation, or spot the compliance gap. You must distinguish AI-specific rules from general law, know when GDPR and the AI Act overlap, and recognise the limits of current IP and liability frameworks. The demand is jurisdictional accuracy and the ability to apply the right rule to the right fact pattern. Candidates lose marks by selecting the law that feels most relevant rather than the one the scenario actually triggers, by confusing high-risk categories across regimes, or by stating that generated output is always protected or never protected when the answer depends on originality and jurisdiction. Another trap is assuming that transparency obligations are identical across GDPR, the AI Act and sector rules when each has different triggers and content. Read for the jurisdiction, the risk tier and the specific obligation before choosing your answer.
Legal questions require you to hold multiple regimes in mind and apply the right one to the scenario. The question bank gives you enough coverage across all five sub-topics to reveal whether your weak area is AI-specific regulation, GDPR intersections, existing law, IP or liability.
The item below asks you to apply a legal rule to a fact pattern where two regimes appear relevant but only one governs the issue described.
Development is where technical choices become governance obligations. This topic covers how you govern design and development decisions, and how you govern the collection and use of data for training and testing. Both sub-topics demand that you connect lifecycle activities from topic one to the controls and principles from topics two and three, then apply the legal constraints from topic four. How Governing AI development is tested Questions describe a development activity or a data practice and ask you to...
Development is where technical choices become governance obligations. This topic covers how you govern design and development decisions, and how you govern the collection and use of data for training and testing. Both sub-topics demand that you connect lifecycle activities from topic one to the controls and principles from topics two and three, then apply the legal constraints from topic four.
How Governing AI development is tested
Questions describe a development activity or a data practice and ask you to identify the governance control that applies, the risk that should be assessed, or the legal obligation that constrains the choice. You are tested on whether you can spot when a design decision creates a downstream risk, when a data source raises a rights issue, and when a testing approach is insufficient for the intended deployment. Candidates lose marks by recommending a control that sounds rigorous but does not address the risk described, or by assuming that any data used for training must be personal data when the scenario involves synthetic or publicly available datasets. Another trap is treating all testing as equivalent when the exam expects you to distinguish validation from verification and to know which is required at which stage. The demand is specificity about which control applies to which activity, not a general statement that governance matters.
Development questions often turn on fine distinctions between controls that sound similar. Practising enough items helps you see the pattern of how the exam differentiates design governance from data governance, and when each is the answer the question wants.
The scenario that follows describes a data practice during training and asks you to identify the governance control that addresses the risk created.
Deployment is the point of no return. This topic covers the factors and risks that inform the decision to deploy, the activities that assess whether the model is ready, and the governance that applies once the system is live. You are tested on whether you can distinguish pre-deployment assessment from post-deployment monitoring, and whether you know what triggers a decision to halt or withdraw. How Governing AI deployment is tested Questions present a deployment decision, a model assessment activity or...
Deployment is the point of no return. This topic covers the factors and risks that inform the decision to deploy, the activities that assess whether the model is ready, and the governance that applies once the system is live. You are tested on whether you can distinguish pre-deployment assessment from post-deployment monitoring, and whether you know what triggers a decision to halt or withdraw.
How Governing AI deployment is tested
Questions present a deployment decision, a model assessment activity or a live-system issue and ask you to identify the factor that should inform the decision, the assessment that is missing, or the governance response required. The demand is sequencing and judgment. Candidates lose marks by recommending post-deployment monitoring when the scenario describes a pre-deployment red flag that should stop the launch, or by selecting a technical assessment when the question is about a legal or ethical factor. Another trap is assuming that passing technical validation means the system is ready to deploy, when the scenario includes a context or stakeholder consideration that has not been addressed. The exam expects you to integrate technical readiness, legal compliance, ethical review and operational context into a single deployment judgment. Partial answers that address only one dimension will not score.
Deployment questions test judgment under incomplete information. The practice test lets you work through enough scenarios to build confidence in distinguishing a pre-deployment showstopper from a risk you can monitor and mitigate post-launch.
What follows asks you to identify the missing assessment activity that should precede deployment, given the system characteristics and intended use described.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full AIGP Exam Questions ๐