AIGP blueprint to source map

The AIGP Body of Knowledge tells you what you are expected to know. It does not tell you where that knowledge comes from. This page maps all four domains and thirteen competencies to the primary sources the exam actually draws on — EU AI Act articles, NIST AI RMF functions, and ISO/IEC 42001 clauses.

⚠️ This is an editorial mapping

The IAPP does not publish an official crosswalk between the Body of Knowledge and these frameworks. What follows is our reading of where each competency’s material originates, built to make study efficient. It is a navigation aid, not an authority — when the BoK and a framework appear to disagree, the BoK governs the exam.

4

domains

13

competencies

58

performance indicators

100

questions on the exam

Domain I

16–20 of 100 questions

Understanding the foundations of AI governance

I.A

4–6 questions · 4 performance indicators

Understand what AI is and why it needs governance.

EU AI Act
Art. 3 (definitions, incl. the OECD-derived AI system definition) · Art. 4 (AI literacy) · Recitals 1–7
NIST AI RMF
GOVERN 1 · MAP 1 (context) · the seven trustworthy-AI characteristics
ISO/IEC
ISO/IEC 22989 (concepts and terminology) · 42001 Clause 4 (context)
Also draws on
OECD AI Principles · NIST SP 1270 (bias categories)

I.B

5–7 questions · 5 performance indicators

Establish and communicate organizational expectations for AI governance.

EU AI Act
Art. 3(3)–(8) operator roles: provider, deployer, importer, distributor · Art. 4 (AI literacy) · Art. 22 (authorised representatives)
NIST AI RMF
GOVERN 2 (accountability structures) · GOVERN 3 (workforce diversity and competence) · GOVERN 4 (culture)
ISO/IEC
42001 Clause 5 (leadership) · Clause 7.2–7.3 (competence, awareness) · Annex A.3 (internal organisation)

I.C

6–8 questions · 3 performance indicators

Establish policies and procedures to apply throughout the AI life cycle.

EU AI Act
Art. 9 (risk management system) · Art. 17 (quality management system)
NIST AI RMF
GOVERN 1 (policies and procedures) · GOVERN 6 (third-party risk)
ISO/IEC
42001 Clause 6 (planning) · Clause 8 (operation) · Annex A.2 (AI policy) · Annex A.10 (suppliers)

Domain II

19–23 of 100 questions

Understanding how laws, standards and frameworks apply to AI

II.A

4–6 questions · 4 performance indicators

Understand how existing data privacy laws apply to AI.

EU AI Act
Art. 10(5) (special categories for bias detection) · Art. 4a (2026 amendment) · Art. 26(9) (deployer DPIA input)
NIST AI RMF
MEASURE 2.10 (privacy) · the “privacy-enhanced” characteristic
ISO/IEC
42001 Annex A.7 (data for AI systems) · ISO/IEC 27701 (privacy information management)
Also draws on
GDPR Arts. 5, 6, 9, 12–22, 25, 28, 30, 32–36, 44–49

II.B

4–6 questions · 4 performance indicators

Understand how other types of existing laws apply to AI.

EU AI Act
Art. 10 (data governance, incl. lawful rights to data) · Annex III(4)–(5) (employment, credit, essential services)
NIST AI RMF
GOVERN 1.1 (legal and regulatory requirements) · MEASURE 2.11 (fairness and bias)
ISO/IEC
42001 Clause 4.2 (interested parties, incl. legal requirements)
Also draws on
Product Liability Directive (EU) 2024/2853 · Title VII, ADA, ECOA, FCRA · FTC Act §5

II.C

6–8 questions · 6 performance indicators

Understand the main elements of AI-specific laws.

EU AI Act
The core of the Act: Art. 5 (prohibited) · Art. 6 + Annex III (high-risk) · Arts. 8–15 (requirements) · Arts. 16–27 (operator obligations) · Art. 25 (role shifts) · Arts. 40–43 (standards, conformity) · Art. 50 (transparency) · Arts. 51–56 (GPAI) · Arts. 99–101 (penalties)
NIST AI RMF
MAP 1.1 (context and legal landscape) · GOVERN 1.1
ISO/IEC
42001 Clause 4.2 · Annex A.5 (impact assessment) · Annex A.6 (life cycle)
Also draws on
South Korean AI Basic Act · Colorado SB 24-205 (as amended) · Texas TRAIGA

II.D

3–5 questions · 3 performance indicators

Understand the main industry standards and tools that apply to AI.

EU AI Act
Arts. 40–42 (harmonised standards, common specifications, presumption of conformity) · Art. 56 (GPAI codes of practice)
NIST AI RMF
The whole framework — GOVERN, MAP, MEASURE, MANAGE — plus the Playbook and the Generative AI Profile
ISO/IEC
ISO/IEC 22989 (terminology) · 42001 (AI management system) · 42005 (impact assessment) · 23894 (risk management)
Also draws on
OECD AI Principles and the OECD definition of an AI system

Domain III

21–25 of 100 questions

Understanding how to govern AI development

III.A

6–8 questions · 5 performance indicators

Govern the designing and building of the AI system.

EU AI Act
Art. 9 (risk management across the life cycle) · Art. 11 + Annex IV (technical documentation) · Art. 13 (transparency to deployers) · Art. 14 (human oversight)
NIST AI RMF
MAP 1–5 (context, categorisation, benefits and costs, risks, impacts) · GOVERN 4
ISO/IEC
42001 Clause 8.2–8.3 · Annex A.5 (impact assessment) · Annex A.6 (life cycle) · ISO/IEC 42005

III.B

6–8 questions · 5 performance indicators

Govern the collection and use of data in training and testing the AI model and system.

EU AI Act
Art. 10 (data and data governance — relevance, representativeness, error-freeness, bias examination) · Art. 15 (accuracy, robustness, cybersecurity)
NIST AI RMF
MAP 2 (categorisation) · MEASURE 1–2 (methods, evaluation, bias, robustness, security)
ISO/IEC
42001 Annex A.7 (data for AI systems: provenance, quality, preparation)

III.C

8–10 questions · 6 performance indicators

Govern the release, monitoring and maintenance of the AI system.

EU AI Act
Art. 12 (logging) · Art. 16 (provider obligations) · Art. 17 (QMS) · Art. 43 (conformity assessment) · Arts. 47–49 (declaration, CE marking, registration) · Art. 72 (post-market monitoring) · Art. 73 (serious incident reporting)
NIST AI RMF
MANAGE 1–4 (prioritise, respond, third-party, monitor and communicate) · MEASURE 4 (feedback)
ISO/IEC
42001 Clause 9 (performance evaluation) · Clause 10 (improvement) · Annex A.6.2 · Annex A.8 (information for interested parties)

Domain IV

21–25 of 100 questions

Understanding how to govern AI deployment and use

IV.A

6–8 questions · 3 performance indicators

Evaluate key factors and risks relevant to the decision to deploy the AI system.

EU AI Act
Art. 26 (deployer obligations) · Art. 25 (when a deployer becomes a provider) · Art. 3(1) (system definition applied to model choice)
NIST AI RMF
MAP 1 (context) · MAP 3 (benefits and costs) · MAP 4 (risks of third-party components)
ISO/IEC
42001 Clause 6.1 (risks and opportunities) · Annex A.6 (life cycle) · Annex A.9 (use of AI systems)

IV.B

5–7 questions · 3 performance indicators

Perform key activities to assess the AI system.

EU AI Act
Art. 27 (fundamental rights impact assessment) · Art. 25(4) (upstream information duties) · Art. 26(1) (use per instructions)
NIST AI RMF
MAP 5 (impacts on individuals and society) · GOVERN 6 (third-party risk and contracts)
ISO/IEC
42001 Annex A.5 (impact assessment) · Annex A.10 (third parties and customers) · ISO/IEC 42005
Also draws on
GDPR Art. 35 (DPIA) · GDPR Art. 28 (processor terms)

IV.C

9–11 questions · 7 performance indicators

Govern the deployment and use of the AI system.

EU AI Act
Art. 26 (instructions, human oversight, input data, log retention, informing workers and affected persons) · Art. 50 (transparency and deepfake disclosure) · Art. 73 (incident reporting via provider) · Art. 86 (explanation of individual decision-making)
NIST AI RMF
MANAGE 1–4 · MEASURE 3 (tracking emergent risks)
ISO/IEC
42001 Clause 8–10 · Annex A.8 (information for interested parties) · Annex A.9 (responsible use)
Also draws on
GDPR Art. 22 (solely automated decisions)

How to use this map

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →