Certification Course · Professional Track

Certified AI Governance Professional (CAIGP).

The professional credential for practitioners who implement AI governance day-to-day. Delivered through Authorized Training Partners, assessed independently by AICA, and issued with a verifiable digital badge.

Exam Specification

The Specification, on the Record.

Certifying a team instead? Explore workforce certification →

CredentialCertified AI Governance Professional (CAIGP)
TrackProfessional Track
Assessment formatExamination (50%) and an applied governance portfolio (50%)
Contact hours40 contact hours across 5 days
Certification feeUSD 2,400
Validity3 years from award date
Renewal45 CPD hours per 3-year cycle, logged with AICA
Retake policyReattempt after a 14 day waiting period, up to 3 attempts in any 12 months
DeliveryThrough Authorized Training Partners, online or center-based
VerificationCryptographic registry entry, QR-verifiable digital badge, Open Badges 3.0

Exam duration and question counts are set in the Candidate Handbook and are not published here. The full proctoring, retake, appeals, renewal and revocation terms are on the exam policies page.

Course Overview

Governance That Works in Practice.

The CAIGP certification course prepares governance, risk, compliance and audit professionals for the Certified AI Governance Professional credential, AICA's professional certification for those who implement AI governance day-to-day. It validates the practical capability to operationalize policy, document model risk, and keep an organization audit-ready.

Most AI governance failures are not failures of intent. Policies exist; what is missing is the practitioner who turns them into inventories, impact assessments, evidence trails and workable compliance routines. The CAIGP certifies exactly that layer of competence: the person a governance leader relies on to make the framework real, and the person an auditor hopes to find on the other side of the table.

The CAIGP is part of the Professional Track in the AICA certification portfolio. Like every AICA credential, it follows a governed process in which standards, training and assessment are deliberately separated. The full model is set out on the How It Works page.

Who It Is For

  • Governance, risk and compliance officers extending into AI
  • Internal auditors and assurance professionals covering AI systems
  • Data protection and privacy professionals with AI responsibilities
  • Consultants operationalizing AI governance for client organizations

The Mandate It Validates

Day-to-day ownership of AI governance in practice: implementing policy, documenting model risk, running compliance workflows and keeping the organization audit-ready.

Competency Domains

Six Domains. One Standard of Competence.

The CAIGP competency framework is built on six domains. Certification confirms demonstrated capability in each, assessed against predefined benchmarks rather than attendance.

01

AI Policy Implementation

Certified professionals can take an approved AI policy and make it operational: translating principles into procedures, controls and checklists that teams actually follow. They can spot where policy and practice have drifted apart, and close the gap.

02

Model Risk Documentation & Impact Assessments

Holders can produce the core governance artifacts for an AI system: model documentation, risk registers and impact assessments that are accurate, proportionate and useful. They can tailor depth to risk rather than drowning every project in paperwork.

03

Regulatory Mapping & Compliance Workflows

Holders can map which obligations apply to which systems, and build the recurring workflows that keep the organization compliant: reviews, attestations, renewals and reporting. They can maintain the map as regulation and the AI estate both change.

04

AI Inventory & Lifecycle Controls

Holders can build and maintain a complete inventory of AI systems, including the ones nobody registered. They can attach lifecycle controls at each stage, from approval and deployment through change management to retirement.

05

Audit Preparation & Evidence Management

Holders can keep evidence organized, current and retrievable, so an audit is a walkthrough rather than a reconstruction. They can run pre-audit readiness checks, manage findings to closure, and brief auditors with confidence.

06

Incident Response for AI Systems

Holders can run the response when an AI system misbehaves: triaging severity, containing impact, notifying the right stakeholders, and documenting the incident. They can turn each incident into a control improvement rather than a repeat.

Course Curriculum

Forty Hours. Six Learning Units. One Working Portfolio.

The CAIGP curriculum turns the six competency domains into six learning units, delivered as a practitioner workshop rather than a lecture series. Each unit is built around applied exercises, and each exercise produces a working governance artifact the candidate carries into the applied governance portfolio.

Duration

40 contact hours across 5 days of structured delivery through an Authorized Training Partner.

Format

Practitioner workshop with applied exercises. Candidates work on realistic organizational scenarios, producing artifacts they refine across the week.

Assessment

Examination (50%) plus an applied governance portfolio (50%): a set of working artifacts including an AI inventory record, an impact assessment, a model risk documentation pack and an incident response runbook.

Entry Profile

Governance, risk, compliance and audit professionals implementing AI governance day-to-day. Prior GRC or audit exposure is recommended.

Course-Level Learning Objectives

On completion, candidates are able to:

  1. CLO1
    Operationalize an approved AI policy into procedures, control checklists and evidence outputs that named owners can execute.Traces to Domain 1
  2. CLO2
    Document model risk and construct impact assessments that are accurate, proportionate to the risk tier of each system, and defensible before a risk committee.Traces to Domain 2
  3. CLO3
    Construct a regulatory obligations register that maps requirements from the EU AI Act, the NIST AI RMF and ISO/IEC 42001 to specific systems, and operationalize it as recurring compliance workflows.Traces to Domain 3
  4. CLO4
    Construct and maintain a complete AI inventory, including discovered shadow AI, with lifecycle controls attached at every stage from approval to retirement.Traces to Domain 4
  5. CLO5
    Assemble and maintain an audit evidence library, assess audit readiness against the applicable framework, and manage findings to verified closure.Traces to Domain 5
  6. CLO6
    Construct and rehearse an incident response runbook for AI systems, and document incidents to a standard that supports regulatory notification and later audit.Traces to Domain 6
  7. CLO7
    Assess drift between documented governance and actual practice, and maintain the full artifact set as regulation and the organization's AI estate change.Traces to Domains 1, 3 and 4
Learning Unit 01 · 6 Contact Hours

AI Policy Implementation

Delivery:Applied workshop with a template walkthrough of the policy-to-procedure pack, followed by a gap-review exercise on a case organization.

Learning Outcomes

  • LO 1.1Translate an approved AI policy into operating procedures, control activities and checklists that named owners can execute on a defined cycle.Traces to CLO1
    Assessment criteria:
    • Produces a policy-to-procedure pack in which each policy clause is traced to a control activity with a named owner, a defined frequency and a specified evidence output.
    • Drafts a control checklist that a process owner outside the governance team can execute without further interpretation.
  • LO 1.2Detect drift between documented policy and actual practice, and construct a remediation plan prioritized by risk.Traces to CLO1 and CLO7
    Assessment criteria:
    • Completes a policy-to-practice gap review in which each point of drift is identified and supported by recorded evidence.
    • Produces a remediation plan in which actions are prioritized by risk and assigned to named owners with target dates.
ComponentStatements
Attitude
  • Treats policy as something to be executed and evidenced, not filed.
  • Works with process owners rather than around them when embedding controls.
  • Prefers continuous compliance over pre-audit clean-up.
Skills
  • Decompose policy clauses into procedures, control activities and acceptance criteria.
  • Draft control checklists with named owners, defined frequencies and specified evidence outputs.
  • Run a policy-to-practice gap review and prioritize remediation by risk.
  • Write implementation guidance that non-specialist teams can follow without interpretation.
Knowledge
  • The structure of an AI policy suite: policy, standards, procedures and guidance, and how the layers relate.
  • Common failure points between approved policy and operational practice.
  • Control design fundamentals: preventive, detective and corrective controls, and where each fits.
  • How management-system frameworks such as ISO/IEC 42001 and the NIST AI RMF describe the governance functions a policy must serve.
Learning Unit 02 · 8 Contact Hours

Model Risk Documentation & Impact Assessments

Delivery:Documentation lab: candidates complete an impact assessment and a model documentation pack for a case system, with structured facilitator review.

Learning Outcomes

  • LO 2.1Produce a model risk documentation pack for an AI system covering purpose, data, performance, limitations and known failure modes.Traces to CLO2
    Assessment criteria:
    • Completes a model documentation pack covering purpose, data, performance, limitations and known failure modes, at a depth proportionate to the system's risk tier.
    • Records the system's weaknesses and open questions factually, in language a risk committee can act on, without advocating for the system.
  • LO 2.2Conduct an AI impact assessment using a structured template, scaled to the risk of the system being assessed.Traces to CLO2
    Assessment criteria:
    • Completes an impact assessment in which affected parties, harms, mitigations and residual risk are documented and traceable to the system's intended use.
    • Scales the depth of the assessment to the risk tier of the system and records the rationale for that scaling.
  • LO 2.3Maintain a model risk register that stays current as systems and their uses change.Traces to CLO2 and CLO7
    Assessment criteria:
    • Maintains a model risk register in which ratings follow the defined scale and treatment decisions are logged with rationale.
    • Records against each system the change triggers that require its register entry and impact assessment to be revisited.
ComponentStatements
Attitude
  • Applies proportionality: documentation depth matches system risk, not template length.
  • Records what a model actually does, including its weaknesses, rather than advocating for it.
Skills
  • Complete a model documentation pack from structured interviews with technical and business owners.
  • Apply an impact assessment template covering affected persons, potential harms, likelihood, severity and mitigations.
  • Rate and record risk consistently against a defined scale, and log treatment decisions with rationale.
  • Translate technical model detail into language a risk committee can act on.
Knowledge
  • The standard contents of model documentation and impact assessment artifacts.
  • Risk-tiering approaches, including the risk-based structure of the EU AI Act, which regulates systems by risk category and places the heaviest obligations on high-risk uses.
  • Common AI harm categories, including bias and discrimination, privacy intrusion, safety failures and lack of robustness.
  • Where impact assessments sit in the system lifecycle and the triggers that require them to be revisited.
Learning Unit 03 · 7 Contact Hours

Regulatory Mapping & Compliance Workflows

Delivery:Regulatory mapping workshop: candidates build an obligations register and compliance calendar for a case organization, working from primary-source extracts.

Learning Outcomes

  • LO 3.1Construct a regulatory obligations register mapping applicable requirements to specific AI systems and named owners.Traces to CLO3
    Assessment criteria:
    • Constructs an obligations register in which each applicable requirement from the EU AI Act, the NIST AI RMF and ISO/IEC 42001 is mapped to a specific system and a named owner.
    • Documents the applicability analysis for each obligation, recording the organizational role, sector and jurisdiction on which it depends.
  • LO 3.2Build the recurring compliance workflows, reviews, attestations, renewals and reporting, with a maintenance routine that keeps the register current as regulation and the AI estate change.Traces to CLO3 and CLO7
    Assessment criteria:
    • Builds a compliance calendar of recurring reviews, attestations, renewals and reporting in which each entry has a named owner and a specified evidence output.
    • Documents a maintenance routine with a defined review cycle that keeps the register current as regulation and the AI estate change.
ComponentStatements
Attitude
  • Reads the primary source before the commentary.
  • Treats the obligations register as a living record with an owner and a review cycle, not a one-off deliverable.
Skills
  • Determine which obligations apply to which systems based on organizational role, sector and jurisdiction.
  • Map obligations across the EU AI Act, the NIST AI RMF and ISO/IEC 42001 without duplicating controls.
  • Design a compliance calendar of recurring reviews, attestations, renewals and reporting with named owners.
  • Brief system owners on their obligations in plain language.
Knowledge
  • The general structure and intent of the EU AI Act: a risk-based law that prohibits certain practices, imposes obligations on high-risk systems and sets transparency duties, with distinct roles for providers and deployers.
  • The general structure of the NIST AI RMF: a voluntary framework organized around the Govern, Map, Measure and Manage functions.
  • The general structure of ISO/IEC 42001: a certifiable management system standard for AI that follows the same plan-do-check-act pattern as other ISO management system standards.
  • How a single control can satisfy requirements across multiple frameworks, and how to evidence that mapping.
Learning Unit 04 · 6 Contact Hours

AI Inventory & Lifecycle Controls

Delivery:Discovery and inventory lab: candidates run a discovery exercise on a case estate, then build the inventory record and attach lifecycle stage gates.

Learning Outcomes

  • LO 4.1Construct an AI inventory record capturing systems, owners, data, risk tier and status, including discovery of unregistered systems.Traces to CLO4
    Assessment criteria:
    • Produces an AI inventory record in which systems, owners, data, risk tier and status are captured in fields that support risk tiering, regulatory mapping and audit retrieval.
    • Documents a discovery exercise across procurement records, the IT estate and business units, and records the unregistered systems it surfaced.
  • LO 4.2Attach lifecycle controls at each stage, from approval and deployment through change management to retirement.Traces to CLO4 and CLO7
    Assessment criteria:
    • Attaches lifecycle controls to each inventory entry, with approval criteria, deployment checks, change triggers for reassessment and retirement steps recorded per stage.
    • Documents how the inventory stays synchronized with change management records, naming who updates it and on what trigger.
ComponentStatements
Attitude
  • Assumes the inventory is incomplete until discovery work proves otherwise.
  • Registers systems at intake, not retrospectively when an audit is announced.
Skills
  • Run a discovery exercise across procurement records, IT estate and business units to surface unregistered AI use.
  • Define inventory fields that support risk tiering, regulatory mapping and audit retrieval.
  • Set stage gates for the lifecycle: approval criteria, deployment checks, change triggers for reassessment and retirement steps.
  • Keep the inventory synchronized with change management records.
Knowledge
  • What a complete AI inventory record contains and which governance processes consume it.
  • The AI system lifecycle and the control objectives at each stage.
  • Common sources of unregistered AI: embedded vendor features, individual subscriptions and internal experiments.
  • How inventory data feeds impact assessments, the obligations register and the audit evidence library.
Learning Unit 05 · 7 Contact Hours

Audit Preparation & Evidence Management

Delivery:Evidence lab with a mock audit walkthrough: candidates build the evidence index, then respond to auditor requests in a fieldwork simulation.

Learning Outcomes

  • LO 5.1Assemble and maintain an audit evidence library that is organized, current and retrievable on request.Traces to CLO5
    Assessment criteria:
    • Builds an evidence index in which each control is mapped to its evidence source, owner and refresh cycle, and retrieves sampled evidence on request.
    • Maintains evidence that meets the quality attributes of completeness, accuracy, timeliness and provenance, produced by the process as it runs rather than reconstructed.
  • LO 5.2Run a pre-audit readiness check against the applicable framework and manage findings to verified closure with documented remediation.Traces to CLO5
    Assessment criteria:
    • Completes a readiness review against the applicable framework in which each gap is rated by severity and supported by cited evidence.
    • Manages a findings log to verified closure, with root cause, remediation and verification recorded for each finding.
ComponentStatements
Attitude
  • Evidence-first documentation discipline: evidence is produced by the process as it runs, not reconstructed for the auditor.
  • Owns findings through to verified closure rather than negotiating them down.
Skills
  • Build an evidence index mapping each control to its evidence source, owner and refresh cycle.
  • Run a readiness review against the applicable framework and rate gaps by severity.
  • Prepare walkthrough briefings for auditors and manage evidence requests during fieldwork.
  • Track findings to closure with root cause, remediation and verification recorded.
Knowledge
  • What auditors accept as evidence: sampled records, system logs, signed approvals and meeting records.
  • Evidence quality attributes: completeness, accuracy, timeliness and provenance.
  • The difference between the design effectiveness and the operating effectiveness of a control.
  • Certification audit patterns under management system standards such as ISO/IEC 42001, including staged initial audits and surveillance cycles.
Learning Unit 06 · 6 Contact Hours

Incident Response for AI Systems

Delivery:Tabletop incident exercise: candidates draft the runbook, rehearse it against an unfolding AI incident scenario, then record the post-incident review.

Learning Outcomes

  • LO 6.1Construct an AI incident response runbook covering triage, severity rating, containment, notification and documentation.Traces to CLO6
    Assessment criteria:
    • Produces an incident response runbook in which AI-specific incident categories, severity thresholds, containment measures and notification duties are defined and assigned to named roles.
    • Writes an incident record to a standard that supports regulatory notification and later audit, with timeline, decisions and evidence preserved.
  • LO 6.2Run a tabletop exercise of the runbook and convert the lessons into control improvements.Traces to CLO6 and CLO7
    Assessment criteria:
    • Runs a tabletop exercise of the runbook and documents the decisions taken at each escalation point.
    • Converts the lessons from the exercise into recorded changes to policy, inventory or risk records, or a documented decision not to change.
ComponentStatements
Attitude
  • Reports early and factually, including when the incident is uncomfortable for the organization.
  • Closes the loop: every incident ends in a control change or a documented decision not to change.
Skills
  • Define AI-specific incident categories, including harmful or incorrect outputs, performance drift, misuse, data leakage through prompts and unannounced vendor model changes.
  • Triage incidents and rate severity against predefined thresholds, escalating on defined triggers.
  • Coordinate containment measures such as suspending a system, restricting its use or adding human review of outputs.
  • Write an incident record to a standard that supports regulatory notification and later audit.
  • Run a post-incident review and feed the outcomes into policy, inventory and risk records.
Knowledge
  • How AI incidents differ from conventional IT incidents, including gradual degradation and probabilistic behavior rather than clean outages.
  • Notification duties in general terms, including that regulation such as the EU AI Act requires reporting of serious incidents for certain systems.
  • Severity models and escalation design for AI-specific incident types.
  • How incident data feeds the risk register and triggers impact assessment reviews.
Assessment Blueprint

How Each Learning Unit Is Assessed.

Assessment is split evenly between the examination (50%) and the applied governance portfolio (50%). Every learning unit contributes to both: the examination tests judgment against realistic scenarios, and the portfolio assesses the working artifacts produced during the course.

Learning UnitExamination FocusPortfolio ArtifactEvidence AssessedWeighting
LU1 · AI Policy ImplementationPolicy implementation scenarios and control design decisionsPolicy-to-procedure pack with control checklistTraceability from policy clause to executable control with named owner and evidence outputExam 8% · Portfolio 7%
LU2 · Model Risk Documentation & Impact AssessmentsRisk documentation method and impact assessment judgmentImpact assessment and model risk documentation pack for a selected systemCompleteness, proportionality to risk tier and defensibility of risk ratingsExam 9% · Portfolio 11%
LU3 · Regulatory Mapping & Compliance WorkflowsApplicability analysis across the EU AI Act, the NIST AI RMF and ISO/IEC 42001Regulatory obligations register with compliance calendarCorrect applicability analysis and a workable recurring workflow with named ownersExam 9% · Portfolio 6%
LU4 · AI Inventory & Lifecycle ControlsInventory design and lifecycle control pointsAI inventory record with lifecycle stage gatesCoverage including discovered unregistered systems, field quality and control attachmentExam 7% · Portfolio 8%
LU5 · Audit Preparation & Evidence ManagementEvidence standards and audit readiness judgmentAudit evidence index with readiness check and findings logRetrievability, evidence quality and closure of identified gapsExam 9% · Portfolio 9%
LU6 · Incident Response for AI SystemsIncident triage, severity rating and notification dutiesAI incident response runbook with tabletop exercise recordOperability of the runbook and quality of the incident documentationExam 8% · Portfolio 9%
TotalExam 50% · Portfolio 50%

Weightings are indicative of emphasis across the two assessment components. Certification decisions are made independently by the AICA Certification and Standards Authority against the published competency benchmarks, separate from training delivery.

Credential Terms

Validity, Renewal and Conduct.

TermProvision
Credential validity3 years from award date.
RenewalVia Continuing Professional Development: 45 CPD hours per 3-year cycle, logged with AICA.
RetakeReattempt after a 14 day waiting period, with a maximum of 3 attempts in any 12 months.
AppealsAssessment and certification decisions may be appealed to AICA's Certification and Standards Authority.
ProctoringExaminations are proctored, online or center-based through Authorized Training Partners.
ConductCertification requires agreement to the AICA Code of Professional Conduct.

Curriculum Standard v1.0. Published 10 July 2026. Reviewed annually by the AICA Certification and Standards Authority.

Assessment & Credential

Independently Assessed. Verifiably Credentialed.

01

Assessment Format

The CAIGP is assessed through an examination and an applied governance portfolio. Both are designed to test practical governance capability against realistic organizational situations, not recall.

02

Delivery Through Authorized Training Partners

Preparation is delivered worldwide by AICA Authorized Training Partners: approved organizations that teach to the AICA competency framework under consistent quality requirements.

03

Independent Certification Decision

Certification decisions are made by the AICA Certification and Standards Authority, separate from training delivery. The governed, seven-stage process is set out on the How It Works page.

04

Digital Badge & Registry

Successful candidates receive the official CAIGP digital badge with a unique credential identifier, recorded in the AICA verification registry. Any employer can verify the credential against its live registry record.

Frequently Asked Questions

CAIGP Course FAQs.

What is the CAIGP certification course?
The CAIGP certification course prepares governance, risk, compliance and audit professionals for the Certified AI Governance Professional credential, awarded by the Artificial Intelligence Certification Authority (AICA). It covers AI policy implementation, model risk documentation, regulatory mapping, AI inventory controls, audit preparation and incident response.
Who should pursue the CAIGP?
The CAIGP is designed for practitioners who implement AI governance day-to-day, including governance and compliance officers, risk analysts, internal auditors, data protection professionals and consultants operationalizing AI policy for clients.
How is the CAIGP assessed?
The CAIGP is assessed through an examination and an applied governance portfolio. All certification decisions are made independently by the AICA Certification and Standards Authority, separate from training delivery.
How does the CAIGP differ from the CCAIGO?
The CCAIGO is an executive credential for leaders who own AI governance at enterprise level, while the CAIGP is the professional credential for the practitioners who make that governance work in practice: writing the documentation, running the workflows and keeping the evidence audit-ready.

Ready to Earn the CAIGP?

The Certified AI Governance Professional program is delivered worldwide through AICA Authorized Training Partners.