The AIGP (IAPP AI Governance Professional) certification is quickly becoming the go-to credential for professionals who need to understand, implement, and oversee responsible AI programs. The exam is organized into four official domains that together cover everything from foundational AI concepts to hands-on governance of AI deployment—and knowing how much weight each domain carries is the single most powerful thing you can do before you open a study guide.
Why Domain Weightings Matter for Your Study Plan
Before diving into the content of each domain, it's worth pausing on why the weightings exist in the first place. The IAPP publishes domain weightings to signal where the exam places the most emphasis. A domain worth 29% of your score deserves roughly three times the study time of a domain worth 10%. When you map your calendar to the actual distribution of exam questions, you stop over-preparing for topics that barely appear and start building real depth where it counts.
Here's a quick snapshot of the four AIGP domains and their approximate weightings:
| # | Domain | Approx. Weight |
|---|---|---|
| 1 | Understanding the Foundations of AI Governance | ~23% |
| 2 | Understanding How Laws, Standards, and Frameworks Apply to AI | ~20% |
| 3 | Understanding How to Govern AI Development | ~29% |
| 4 | Understanding How to Govern AI Deployment and Use | ~28% |
Domains 3 and 4 together account for roughly 57% of the exam. That doesn't mean you can skip Domains 1 and 2—they provide the conceptual scaffolding that makes the governance domains make sense—but it does mean your heaviest lifting should happen in the second half of your study plan.
Domain 1: Understanding the Foundations of AI Governance (~23%)
Every governance framework has to start somewhere, and for the AIGP that starting point is a solid grounding in what AI actually is, how it works at a conceptual level, and why governing it is both necessary and uniquely challenging.
What This Domain Covers
Domain 1 is the broadest in scope and the most conceptual. Expect questions that test your ability to:
- Define AI and its subfields. You should be comfortable distinguishing machine learning from deep learning, understanding what large language models (LLMs) do, and explaining concepts like training data, model outputs, and inference without getting lost in the math.
- Identify AI risks and harms. Governance exists because AI can cause real harm—bias and discrimination, privacy violations, safety failures, erosion of human autonomy, and more. Domain 1 asks you to recognize these risk categories and understand why they arise.
- Explain the principles of responsible AI. Terms like fairness, transparency, accountability, explainability, and human oversight appear throughout the AIGP body of knowledge. Domain 1 is where you build the vocabulary that the rest of the exam assumes you already have.
- Understand the AI lifecycle. AI systems are not static products. They are designed, trained, tested, deployed, monitored, and eventually retired. A governance professional needs to understand each stage because risks and controls differ at every point.
Study Tips for Domain 1
Because this domain is foundational, it rewards breadth over depth. Read widely across IAPP's published resources, the NIST AI Risk Management Framework (AI RMF) conceptual sections, and introductory AI ethics literature. If you have a technical background, resist the urge to go deep on algorithms—the exam tests governance awareness, not engineering skill. If you have a legal or compliance background, invest time in understanding the technical vocabulary so that later domains feel grounded rather than abstract.
Domain 2: Understanding How Laws, Standards, and Frameworks Apply to AI (~20%)
At 20%, Domain 2 is the lightest of the four domains by weight, but don't let that fool you into treating it as optional. The regulatory and standards landscape for AI is evolving faster than almost any other area of technology law, and the AIGP exam expects you to navigate it confidently.
What This Domain Covers
- Key AI regulations and legislation. The EU AI Act is the most significant piece of AI-specific legislation in the world right now, and it features prominently in AIGP content. You should understand its risk-based tiering (unacceptable risk, high risk, limited risk, minimal risk), the obligations it places on providers and deployers, and its conformity assessment requirements. Beyond the EU, you should have awareness of AI-related executive orders, sector-specific guidance (financial services, healthcare, etc.), and emerging legislation in other jurisdictions.
- Voluntary frameworks and standards. The NIST AI RMF is central here. You should understand its four core functions—GOVERN, MAP, MEASURE, MANAGE—and how organizations use it to structure their AI risk programs. ISO/IEC 42001 (the AI management system standard) is also increasingly relevant. The OECD AI Principles and UNESCO Recommendation on the Ethics of AI round out the international standards picture.
- How existing laws extend to AI. AI doesn't exist in a legal vacuum. Data protection laws like the GDPR and CCPA apply when AI systems process personal data. Anti-discrimination laws apply when AI makes consequential decisions about people. Consumer protection, product liability, and intellectual property law all intersect with AI in ways a governance professional must understand.
- Sector-specific considerations. Healthcare AI, financial services AI, and hiring AI each carry their own regulatory overlays. Domain 2 tests whether you can identify which rules apply in which contexts.
Study Tips for Domain 2
Build a comparison table of the major frameworks and regulations—what they require, who they apply to, and how they relate to each other. The NIST AI RMF deserves its own dedicated study session; read the full document, not just summaries. For the EU AI Act, focus on the high-risk AI system categories and the obligations they trigger. Don't try to memorize every article number—understand the structure and logic instead.
Domain 3: Understanding How to Govern AI Development (~29%)
With the highest weighting of any single domain, Domain 3 is where the AIGP exam gets practical. This domain moves from "what is AI" and "what rules apply" to "how do you actually build governance into the process of creating AI systems."
What This Domain Covers
- AI governance program design. You should be able to describe what a mature AI governance program looks like: policies, procedures, roles and responsibilities, oversight committees, escalation paths, and documentation requirements. The exam tests whether you can design these structures, not just describe them in the abstract.
- Risk assessment for AI systems. Before an AI system is built or procured, a governance professional needs to assess its risk profile. Domain 3 covers how to conduct AI impact assessments, how to classify AI systems by risk level, and how to document findings in a way that supports accountability.
- Data governance in AI development. AI systems are only as good as the data they're trained on, and data governance is a core part of AI governance. Expect questions on data quality, data lineage, bias in training data, consent and lawful basis for data use, and data minimization.
- Model development controls. This includes testing and validation practices, bias and fairness evaluations, explainability requirements, and the documentation that should accompany a model through its development lifecycle (think model cards and datasheets for datasets).
- Third-party and vendor governance. Most organizations don't build AI from scratch—they procure it from vendors or use foundation models via APIs. Domain 3 tests your ability to govern these third-party relationships: due diligence, contractual protections, ongoing monitoring, and understanding where accountability sits when something goes wrong.
- Human oversight and human-in-the-loop design. A recurring theme in AI governance is the question of how much autonomy to give an AI system and when humans must remain in the decision loop. Domain 3 asks you to apply this thinking to development decisions.
Study Tips for Domain 3
This is your highest-value domain, so give it proportional time. Work through the NIST AI RMF Playbook, which provides concrete practices for each of the four functions. Study real-world AI governance policy templates and model cards. Practice applying risk assessment frameworks to hypothetical AI use cases—the exam is likely to present scenarios and ask you to identify the right governance response. If you work in privacy or compliance, draw parallels to DPIA (Data Protection Impact Assessment) processes you already know; AI impact assessments follow similar logic.
Domain 4: Understanding How to Govern AI Deployment and Use (~28%)
Domain 4 is nearly as heavy as Domain 3, and together they form the operational core of the AIGP exam. Where Domain 3 focuses on building AI responsibly, Domain 4 focuses on deploying it responsibly and keeping it governed over time.
What This Domain Covers
- Pre-deployment review and approval. Before an AI system goes live, governance processes should verify that it has been properly assessed, tested, and documented. Domain 4 covers the gates and checklists that responsible organizations use before deployment.
- Monitoring and ongoing oversight. AI systems can drift—their performance can degrade, their outputs can become biased over time, and the world they operate in can change in ways that make their original training data obsolete. Domain 4 tests your knowledge of monitoring strategies, performance metrics, and the triggers that should prompt re-evaluation or shutdown.
- Incident response for AI. When an AI system causes harm or behaves unexpectedly, organizations need a response plan. This includes detecting the incident, containing the harm, investigating the root cause, remediating the system, and communicating with affected parties and regulators.
- Transparency and communication. Stakeholders—customers, employees, regulators, the public—have legitimate interests in knowing when AI is being used to make decisions that affect them. Domain 4 covers disclosure obligations, explainability to end users, and how to communicate about AI in ways that are honest without being misleading.
- AI use policies and acceptable use. Organizations that deploy AI need internal policies governing how employees and systems may use AI tools. This is especially relevant in the era of generative AI, where employees may be using AI assistants in ways that create data, IP, or compliance risks.
- Decommissioning and end-of-life governance. AI systems eventually need to be retired. Domain 4 asks you to think about what happens to the data, the model, and the documentation when a system is shut down.
- Accountability and governance culture. Ultimately, AI governance is a people problem as much as a technical one. Domain 4 touches on how to build a culture of responsible AI use, how to train employees, and how to assign and enforce accountability.
Study Tips for Domain 4
Pair your Domain 4 study with real-world case studies of AI failures and how organizations responded. The EU AI Act's post-market monitoring requirements are directly relevant here. Think about how existing compliance disciplines—vendor management, incident response, change management—translate into the AI context. Practice scenario-based questions that ask you to identify what a governance professional should do when an AI system produces unexpected outputs or when a regulator asks for documentation.
Putting It All Together: A Suggested Study Allocation
Based on the domain weightings, here's a rough guide to how you might allocate your study hours across a typical 8-week preparation period:
| Domain | Weight | Suggested % of Study Time |
|---|---|---|
| Domain 1: Foundations | ~23% | ~20% |
| Domain 2: Laws, Standards & Frameworks | ~20% | ~20% |
| Domain 3: Governing AI Development | ~29% | ~32% |
| Domain 4: Governing AI Deployment & Use | ~28% | ~28% |
Note that Domain 1 gets slightly less time than its weight suggests because much of its content will feel intuitive once you've studied the other domains—it's the vocabulary layer that everything else builds on. Domains 3 and 4 get the most time because they are the most scenario-heavy and require the deepest applied understanding.
Cross-Domain Themes to Watch
Several themes cut across all four domains and are worth tracking as you study:
- The AI lifecycle — Every domain references it. Make sure you can describe each stage fluently.
- Risk-based thinking — The AIGP exam consistently rewards candidates who can identify, assess, and prioritize AI risks rather than applying one-size-fits-all rules.
- Accountability and documentation — Who is responsible, and how do you prove it? These questions appear in every domain.
- Human oversight — When should humans be in the loop, and what does meaningful oversight actually look like?
- Intersection with data protection — AI governance and privacy governance overlap significantly. If you hold a CIPP or CIPM credential, lean into that knowledge.
Final Thoughts
The AIGP certification is designed for professionals who need to do real governance work in a world where AI is increasingly consequential. The four domains reflect that practical orientation: they move from foundational understanding through regulatory awareness to hands-on governance of both development and deployment. Candidates who study with the domain weightings in mind—spending the most time on Domains 3 and 4 while building a solid base in Domains 1 and 2—will be well-positioned to pass the exam and, more importantly, to do the job the credential represents.
Ready to Test Your Knowledge?
Reading about the AIGP exam domains is a great start—but the fastest way to find your gaps is to answer real practice questions. LearnZapp offers free AIGP practice tests that map directly to the four official domains, so you can see exactly where you're strong and where you need more work before exam day. Download the LearnZapp app and take your first free practice test today. Your future self—the one holding an AIGP certificate—will thank you.