AIGP blueprint to source map
The AIGP Body of Knowledge tells you what you are expected to know. It does not tell you where that knowledge comes from. This page maps all four domains and thirteen competencies to the primary sources the exam actually draws on — EU AI Act articles, NIST AI RMF functions, and ISO/IEC 42001 clauses.
⚠️ This is an editorial mapping
The IAPP does not publish an official crosswalk between the Body of Knowledge and these frameworks. What follows is our reading of where each competency’s material originates, built to make study efficient. It is a navigation aid, not an authority — when the BoK and a framework appear to disagree, the BoK governs the exam.
4
domains
13
competencies
58
performance indicators
100
questions on the exam
Domain I
16–20 of 100 questionsUnderstanding the foundations of AI governance
I.A
4–6 questions · 4 performance indicatorsUnderstand what AI is and why it needs governance.
- EU AI Act
- Art. 3 (definitions, incl. the OECD-derived AI system definition) · Art. 4 (AI literacy) · Recitals 1–7
- NIST AI RMF
- GOVERN 1 · MAP 1 (context) · the seven trustworthy-AI characteristics
- ISO/IEC
- ISO/IEC 22989 (concepts and terminology) · 42001 Clause 4 (context)
- Also draws on
- OECD AI Principles · NIST SP 1270 (bias categories)
I.B
5–7 questions · 5 performance indicatorsEstablish and communicate organizational expectations for AI governance.
- EU AI Act
- Art. 3(3)–(8) operator roles: provider, deployer, importer, distributor · Art. 4 (AI literacy) · Art. 22 (authorised representatives)
- NIST AI RMF
- GOVERN 2 (accountability structures) · GOVERN 3 (workforce diversity and competence) · GOVERN 4 (culture)
- ISO/IEC
- 42001 Clause 5 (leadership) · Clause 7.2–7.3 (competence, awareness) · Annex A.3 (internal organisation)
I.C
6–8 questions · 3 performance indicatorsEstablish policies and procedures to apply throughout the AI life cycle.
- EU AI Act
- Art. 9 (risk management system) · Art. 17 (quality management system)
- NIST AI RMF
- GOVERN 1 (policies and procedures) · GOVERN 6 (third-party risk)
- ISO/IEC
- 42001 Clause 6 (planning) · Clause 8 (operation) · Annex A.2 (AI policy) · Annex A.10 (suppliers)
Domain II
19–23 of 100 questionsUnderstanding how laws, standards and frameworks apply to AI
II.A
4–6 questions · 4 performance indicatorsUnderstand how existing data privacy laws apply to AI.
- EU AI Act
- Art. 10(5) (special categories for bias detection) · Art. 4a (2026 amendment) · Art. 26(9) (deployer DPIA input)
- NIST AI RMF
- MEASURE 2.10 (privacy) · the “privacy-enhanced” characteristic
- ISO/IEC
- 42001 Annex A.7 (data for AI systems) · ISO/IEC 27701 (privacy information management)
- Also draws on
- GDPR Arts. 5, 6, 9, 12–22, 25, 28, 30, 32–36, 44–49
II.B
4–6 questions · 4 performance indicatorsUnderstand how other types of existing laws apply to AI.
- EU AI Act
- Art. 10 (data governance, incl. lawful rights to data) · Annex III(4)–(5) (employment, credit, essential services)
- NIST AI RMF
- GOVERN 1.1 (legal and regulatory requirements) · MEASURE 2.11 (fairness and bias)
- ISO/IEC
- 42001 Clause 4.2 (interested parties, incl. legal requirements)
- Also draws on
- Product Liability Directive (EU) 2024/2853 · Title VII, ADA, ECOA, FCRA · FTC Act §5
II.C
6–8 questions · 6 performance indicatorsUnderstand the main elements of AI-specific laws.
- EU AI Act
- The core of the Act: Art. 5 (prohibited) · Art. 6 + Annex III (high-risk) · Arts. 8–15 (requirements) · Arts. 16–27 (operator obligations) · Art. 25 (role shifts) · Arts. 40–43 (standards, conformity) · Art. 50 (transparency) · Arts. 51–56 (GPAI) · Arts. 99–101 (penalties)
- NIST AI RMF
- MAP 1.1 (context and legal landscape) · GOVERN 1.1
- ISO/IEC
- 42001 Clause 4.2 · Annex A.5 (impact assessment) · Annex A.6 (life cycle)
- Also draws on
- South Korean AI Basic Act · Colorado SB 24-205 (as amended) · Texas TRAIGA
II.D
3–5 questions · 3 performance indicatorsUnderstand the main industry standards and tools that apply to AI.
- EU AI Act
- Arts. 40–42 (harmonised standards, common specifications, presumption of conformity) · Art. 56 (GPAI codes of practice)
- NIST AI RMF
- The whole framework — GOVERN, MAP, MEASURE, MANAGE — plus the Playbook and the Generative AI Profile
- ISO/IEC
- ISO/IEC 22989 (terminology) · 42001 (AI management system) · 42005 (impact assessment) · 23894 (risk management)
- Also draws on
- OECD AI Principles and the OECD definition of an AI system
Domain III
21–25 of 100 questionsUnderstanding how to govern AI development
III.A
6–8 questions · 5 performance indicatorsGovern the designing and building of the AI system.
- EU AI Act
- Art. 9 (risk management across the life cycle) · Art. 11 + Annex IV (technical documentation) · Art. 13 (transparency to deployers) · Art. 14 (human oversight)
- NIST AI RMF
- MAP 1–5 (context, categorisation, benefits and costs, risks, impacts) · GOVERN 4
- ISO/IEC
- 42001 Clause 8.2–8.3 · Annex A.5 (impact assessment) · Annex A.6 (life cycle) · ISO/IEC 42005
III.B
6–8 questions · 5 performance indicatorsGovern the collection and use of data in training and testing the AI model and system.
- EU AI Act
- Art. 10 (data and data governance — relevance, representativeness, error-freeness, bias examination) · Art. 15 (accuracy, robustness, cybersecurity)
- NIST AI RMF
- MAP 2 (categorisation) · MEASURE 1–2 (methods, evaluation, bias, robustness, security)
- ISO/IEC
- 42001 Annex A.7 (data for AI systems: provenance, quality, preparation)
III.C
8–10 questions · 6 performance indicatorsGovern the release, monitoring and maintenance of the AI system.
- EU AI Act
- Art. 12 (logging) · Art. 16 (provider obligations) · Art. 17 (QMS) · Art. 43 (conformity assessment) · Arts. 47–49 (declaration, CE marking, registration) · Art. 72 (post-market monitoring) · Art. 73 (serious incident reporting)
- NIST AI RMF
- MANAGE 1–4 (prioritise, respond, third-party, monitor and communicate) · MEASURE 4 (feedback)
- ISO/IEC
- 42001 Clause 9 (performance evaluation) · Clause 10 (improvement) · Annex A.6.2 · Annex A.8 (information for interested parties)
Domain IV
21–25 of 100 questionsUnderstanding how to govern AI deployment and use
IV.A
6–8 questions · 3 performance indicatorsEvaluate key factors and risks relevant to the decision to deploy the AI system.
- EU AI Act
- Art. 26 (deployer obligations) · Art. 25 (when a deployer becomes a provider) · Art. 3(1) (system definition applied to model choice)
- NIST AI RMF
- MAP 1 (context) · MAP 3 (benefits and costs) · MAP 4 (risks of third-party components)
- ISO/IEC
- 42001 Clause 6.1 (risks and opportunities) · Annex A.6 (life cycle) · Annex A.9 (use of AI systems)
IV.B
5–7 questions · 3 performance indicatorsPerform key activities to assess the AI system.
- EU AI Act
- Art. 27 (fundamental rights impact assessment) · Art. 25(4) (upstream information duties) · Art. 26(1) (use per instructions)
- NIST AI RMF
- MAP 5 (impacts on individuals and society) · GOVERN 6 (third-party risk and contracts)
- ISO/IEC
- 42001 Annex A.5 (impact assessment) · Annex A.10 (third parties and customers) · ISO/IEC 42005
- Also draws on
- GDPR Art. 35 (DPIA) · GDPR Art. 28 (processor terms)
IV.C
9–11 questions · 7 performance indicatorsGovern the deployment and use of the AI system.
- EU AI Act
- Art. 26 (instructions, human oversight, input data, log retention, informing workers and affected persons) · Art. 50 (transparency and deepfake disclosure) · Art. 73 (incident reporting via provider) · Art. 86 (explanation of individual decision-making)
- NIST AI RMF
- MANAGE 1–4 · MEASURE 3 (tracking emergent risks)
- ISO/IEC
- 42001 Clause 8–10 · Annex A.8 (information for interested parties) · Annex A.9 (responsible use)
- Also draws on
- GDPR Art. 22 (solely automated decisions)
How to use this map
- Don’t read the sources cover to cover. Domain II is the only one that rewards close reading of the AI Act text. Elsewhere the exam tests governance judgement, and the articles are context.
- Weight your time by the blueprint. Domains III and IV are 21–25 questions each — nearly half the exam between them — and are mostly application, not recall.
- Notice the overlaps. Impact assessments appear in I.C, III.A, IV.B and again under GDPR Art. 35 and AI Act Art. 27. Learning the differences between them once pays across three domains.
- ISO standards are paid. You do not need to buy them to pass. Know what each covers — 22989 terminology, 42001 management system, 42005 impact assessment, 23894 risk — and that 42001 is the certifiable one.