The whole syllabus, in notes
One page per competency, covering all four domains and every performance indicator in the IAPP Body of Knowledge v2.1 — 158 defined terms, each note citing the primary sources it draws on. Free, and no account needed to read them.
13
competency notes
305
practice questions behind them
128
flashcards
Domain I — Understanding the foundations of AI governance
15–21 questionsWhat AI governance is, including the common principles and pillars to build an AI governance program. Covers best practices regardless of industry, sector or size.
I.A Understand what AI is and why it needs governance
Generally accepted definitions and types of AI, the risks and harms it can cause, the characteristics that make it hard to govern, and the common principles of responsible AI.
12 key terms · 4–6 exam questions
I.B Establish and communicate organizational expectations for AI governance
How an organization sets up the people side of AI governance — roles and responsibilities, cross-functional collaboration, training and awareness, right-sizing the program, and the developer/provider/deployer/user distinction.
12 key terms · 5–7 exam questions
I.C Establish policies and procedures to apply throughout the AI life cycle
Building the policy layer of an AI governance program — lifecycle policies for oversight and accountability, updating existing policies (privacy, security, data governance, IP) for AI, and managing third-party and procurement risk with assessments, contracts and acceptable-use rules.
11 key terms · 6–8 exam questions
Domain II — Understanding how laws, standards and frameworks apply to AI
17–25 questionsExisting laws that apply to AI, as well as AI-specific laws, standards and frameworks — including the major elements of current AI laws (e.g., the EU AI Act, the South Korean AI Basic Law, federal and state AI laws that apply to private sector organizations).
II.A Understand how existing data privacy laws apply to AI
How established data-protection law — anchored in the GDPR — already governs AI: transparency, choice, lawful basis and purpose limitation; data minimization and privacy by design; controller obligations (DPIAs, processors, transfers, DSRs, Art. 22 ADM, breach notification, records); and special-category data including biometrics.
12 key terms · 4–6 exam questions
II.B Understand how other existing laws apply to AI
Beyond privacy: how intellectual-property, nondiscrimination, consumer-protection and product-liability law already reach AI — from training-data copyright and the human-authorship rule, through Title VII / ECOA / FHA disparate-impact liability, to FTC Act §5 UDAP and design/manufacturing/warning defects under product-liability regimes.
11 key terms · 4–6 exam questions
II.C Understand the main elements of AI-specific laws
The architecture of purpose-built AI law, anchored in the EU AI Act (Regulation (EU) 2024/1689): the four risk tiers and what falls in each; core requirements (risk management, data governance, technical documentation, conformity/impact assessment, record keeping); human oversight, transparency and quality management; GPAI model obligations and the systemic-risk threshold; enforcement and penalties; and role-based duties for providers, deployers, importers and distributors — contrasted with the South Korean AI Basic Act and the Colorado AI Act.
12 key terms · 6–8 exam questions
II.D Understand the main industry standards and tools that apply to AI
The voluntary, non-binding scaffolding that complements AI law: the OECD AI Principles and AI-system definition; the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), its Playbook and trustworthiness characteristics; and the core ISO/IEC AI standards — 22989 (terminology), 42001 (AI management system) and 42005 (AI impact assessment).
12 key terms · 3–5 exam questions
Domain III — Understanding how to govern AI development
20–26 questionsThe responsibilities of AI governance professionals with respect to designing, building, training, testing and maintaining AI systems.
III.A Govern the designing and building of the AI system
Define the business context and use case, run or review an impact assessment, apply policies/ethics to design and build, identify and manage internal/external risks, and document the whole process.
13 key terms · 6–8 exam questions
III.B Govern the collection and use of data in training and testing
Establish data governance (lawful rights, quality, integrity, fit-for-purpose), capture data lineage and provenance, plan and perform training and testing, manage issues and risks that arise, and document the process.
12 key terms · 6–8 exam questions
III.C Govern the release, monitoring and maintenance of the AI system
Assess release readiness (model card, conformity), monitor continuously and schedule maintenance/retraining, run periodic assessments (audits, red teaming, threat modeling, security testing), manage and document incidents, root-cause them cross-functionally, and make required public disclosures.
13 key terms · 8–10 exam questions
Domain IV — Understanding how to govern AI deployment and use
20–26 questionsThe responsibilities of AI governance professionals with respect to selecting an AI model, then deploying and using it responsibly through ongoing monitoring, maintenance and other key obligations. Applies whether deploying a proprietary model or one from a third party.
IV.A Evaluate key factors and risks for the decision to deploy
How a deployer weighs the use-case context, chooses among AI model types (classic vs. generative, proprietary vs. open, small vs. large, language vs. multimodal), and picks a deployment option (cloud vs. on-premise vs. edge; as-is vs. fine-tuning vs. RAG vs. agentic) before committing to deploy.
13 key terms · 6–8 exam questions
IV.B Perform key activities to assess the AI system
The assessment work a deployer does before and during deployment: performing or reviewing an impact assessment on the selected system, identifying and evaluating the key terms and risks in the vendor/licensing agreement, and recognizing the heightened obligations and liability of deploying your own proprietary model.
12 key terms · 5–7 exam questions
IV.C Govern the deployment and use of the AI system
The ongoing, operational governance of a deployed system: applying policies and ethics at deployment, continuous monitoring and a maintenance/retraining schedule, periodic assessment (audits, red teaming, threat modeling, security testing), documenting incidents and post-market monitoring, forecasting and reducing secondary/downstream harms, external communication plans, and controls to deactivate or localize the system.
13 key terms · 9–11 exam questions
Notes are free; the practice needs an account
Reading is the easy half. The 305 practice questions, the flashcard decks, the timed mock exams and the progress tracking sit behind a Google sign-in, which is what lets your progress follow you between devices.
Start practising freeRelated: How to pass the AIGP · Blueprint to source map · Cheat sheet · What is the AIGP?